Case processing, signal detection, and aggregate reporting get most of the attention in pharmacovigilance. But none of it holds up during an inspection without a working quality management system behind it. When a case is processed late, a validation rule fails silently, or a process changes without documentation, it is your CAPA, deviation, and change control records that show whether your organisation caught it, understood why it happened, and fixed it properly.
Quality management in pharmacovigilance is the set of processes that detect when something in your safety system has gone wrong, document it, investigate the cause, and prevent it from happening again. It sits alongside case processing and reporting rather than after it — every PV process should be feeding data into it continuously. Good Vigilance Practice (GVP) Module I specifically requires sponsors and marketing authorisation holders to maintain a documented quality system covering these activities.
Deviation management
Deviation management is how you record an event where a process did not go as defined: a case reported one day past its regulatory deadline, a literature search missed a database for a week, a field mapped incorrectly during an E2B transmission. A deviation is a fact — something departed from the SOP.
CAPA (Corrective and Preventive Action)
CAPA is what you do about a deviation, or a pattern of deviations. Corrective action fixes the immediate problem. Preventive action changes the process so it cannot recur. Regulators generally care less about the fact that an error happened, and much more about whether your CAPA shows real root-cause analysis rather than a superficial fix.
Change control
Change control governs how you modify a validated system or process in the first place: a new reporting rule, an updated MedDRA version, a workflow change in case triage. Anything that could affect the accuracy, timeliness, or compliance of your PV output should go through change control before it goes live, not after.
| Element | Trigger | Output | Regulatory focus |
|---|---|---|---|
| Deviation | Process departs from SOP | Documented event record | Was it detected and logged? |
| CAPA | A deviation, or a pattern of deviations | Root-cause analysis + corrective/preventive action | Was the actual cause addressed? |
| Change control | A planned modification to system or process | Approved, validated, documented change | Was the change tested and controlled before release? |
A well-run quality system treats these as one connected loop, not three separate logs. A recurring deviation should trigger a CAPA. A CAPA's preventive action often results in a change request. That change, once approved, goes through change control before it is released back into the live system.
Many small-to-mid pharma teams and CROs still run CAPA and deviation tracking in spreadsheets or shared documents. This works at low volume, but it creates real inspection risk as case volume grows:
- No automatic linkage between a deviation and the CAPA it triggered
- No enforced timelines, so CAPA closure dates get missed without anyone noticing
- No audit trail of who approved a change and when it went live
- No easy way to show a regulator the full chain from root cause to resolution
- Duplicate or conflicting deviation records across teams working the same product
An inspector reconstructing this chain from disconnected spreadsheets is one of the more common ways a routine inspection turns into a finding.
- Log deviations directly from the workflow where they occurred, not as a separate manual step
- Link every CAPA to its source deviation(s) automatically, preserving the audit trail
- Enforce due dates and escalate overdue CAPAs before they become inspection findings
- Route change requests through defined approval steps before anything goes live
- Keep a single, exportable record for inspection readiness, with no reconstruction under pressure
PVgenix includes a dedicated Quality Management module alongside case processing, signal detection, aggregate reporting, and literature monitoring, so deviations, CAPAs, and change control live in the same audit trail as the cases and processes they relate to.
CAPA, deviations, and change control are not paperwork on top of pharmacovigilance. They are the evidence that your PV system is actually being watched. Teams that treat them as one connected loop, with clear ownership and enforced timelines, walk into an inspection with a story to tell. Teams tracking them in disconnected spreadsheets are usually still trying to reconstruct that story when the inspector asks for it.
Frequently asked questions
Common questions
A deviation is the record of an event that departed from your defined process. A CAPA is the investigation and action taken in response, either to a single significant deviation or a pattern of them.
Yes. GVP Module I requires marketing authorisation holders to maintain a documented PV quality system, including provisions for deviation handling, CAPA, and controlled change management.
An overdue or unclosed CAPA suggests a known problem was left unaddressed. Inspectors use closure timelines as a quick signal of how seriously an organisation manages its own quality system.
