Skip to main content
PVgenix logo
Guide

Quality Management in Pharmacovigilance: CAPA, Deviations & Change Control Explained

A pharmacovigilance system is only as reliable as the quality processes behind it. This guide explains CAPA, deviation management, and change control in a PV context, and what a regulator expects to see when they inspect your quality system.

PVgenix9 min read

Case processing, signal detection, and aggregate reporting get most of the attention in pharmacovigilance. But none of it holds up during an inspection without a working quality management system behind it. When a case is processed late, a validation rule fails silently, or a process changes without documentation, it is your CAPA, deviation, and change control records that show whether your organisation caught it, understood why it happened, and fixed it properly.

Quality management in pharmacovigilance is the set of processes that detect when something in your safety system has gone wrong, document it, investigate the cause, and prevent it from happening again. It sits alongside case processing and reporting rather than after it — every PV process should be feeding data into it continuously. Good Vigilance Practice (GVP) Module I specifically requires sponsors and marketing authorisation holders to maintain a documented quality system covering these activities.

Deviation management

Deviation management is how you record an event where a process did not go as defined: a case reported one day past its regulatory deadline, a literature search missed a database for a week, a field mapped incorrectly during an E2B transmission. A deviation is a fact — something departed from the SOP.

CAPA (Corrective and Preventive Action)

CAPA is what you do about a deviation, or a pattern of deviations. Corrective action fixes the immediate problem. Preventive action changes the process so it cannot recur. Regulators generally care less about the fact that an error happened, and much more about whether your CAPA shows real root-cause analysis rather than a superficial fix.

Change control

Change control governs how you modify a validated system or process in the first place: a new reporting rule, an updated MedDRA version, a workflow change in case triage. Anything that could affect the accuracy, timeliness, or compliance of your PV output should go through change control before it goes live, not after.

ElementTriggerOutputRegulatory focus
DeviationProcess departs from SOPDocumented event recordWas it detected and logged?
CAPAA deviation, or a pattern of deviationsRoot-cause analysis + corrective/preventive actionWas the actual cause addressed?
Change controlA planned modification to system or processApproved, validated, documented changeWas the change tested and controlled before release?
How a deviation, its CAPA, and any resulting change fit together.

A well-run quality system treats these as one connected loop, not three separate logs. A recurring deviation should trigger a CAPA. A CAPA's preventive action often results in a change request. That change, once approved, goes through change control before it is released back into the live system.

Many small-to-mid pharma teams and CROs still run CAPA and deviation tracking in spreadsheets or shared documents. This works at low volume, but it creates real inspection risk as case volume grows:

  • No automatic linkage between a deviation and the CAPA it triggered
  • No enforced timelines, so CAPA closure dates get missed without anyone noticing
  • No audit trail of who approved a change and when it went live
  • No easy way to show a regulator the full chain from root cause to resolution
  • Duplicate or conflicting deviation records across teams working the same product

An inspector reconstructing this chain from disconnected spreadsheets is one of the more common ways a routine inspection turns into a finding.

  • Log deviations directly from the workflow where they occurred, not as a separate manual step
  • Link every CAPA to its source deviation(s) automatically, preserving the audit trail
  • Enforce due dates and escalate overdue CAPAs before they become inspection findings
  • Route change requests through defined approval steps before anything goes live
  • Keep a single, exportable record for inspection readiness, with no reconstruction under pressure

PVgenix includes a dedicated Quality Management module alongside case processing, signal detection, aggregate reporting, and literature monitoring, so deviations, CAPAs, and change control live in the same audit trail as the cases and processes they relate to.

CAPA, deviations, and change control are not paperwork on top of pharmacovigilance. They are the evidence that your PV system is actually being watched. Teams that treat them as one connected loop, with clear ownership and enforced timelines, walk into an inspection with a story to tell. Teams tracking them in disconnected spreadsheets are usually still trying to reconstruct that story when the inspector asks for it.

CAPA in pharmacovigilancedeviation management in pharmacovigilancechange control pharmacovigilance softwarequality management system pharmacovigilancepharmacovigilance QMS GxP compliance

Frequently asked questions

Common questions

See PVgenix on your case types

Request a demo to walk through intake, AI-assisted processing, and human-in-the-loop review on your own scenarios.