The short version
What teams need to understand
- Pharmacovigilance responsibilities shared between companies or service providers must be governed by a defined Safety Data Exchange Agreement.
- SDEAs must clearly allocate roles, responsibilities, and timelines for all relevant pharmacovigilance activities.
- Agreements should cover ICSR exchange, aggregate reporting, signal management, literature monitoring, regulatory communication, and escalation pathways.
- Data exchange processes must support timely, complete, and traceable transfer of safety information.
- Oversight, reconciliation, audit rights, and record retention requirements must be documented.
- Inspection-ready evidence should demonstrate that shared PV responsibilities are controlled through an active and current agreement.
Regulatory expectation
What regulators expect
Each expectation should be supported by controlled documentation, traceable records, clear ownership, and evidence that the process works in practice.
- Shared pharmacovigilance activities must be governed by a defined written agreement.
- Responsibilities and timelines must be allocated clearly and without ambiguity.
- Case exchange and follow-up processes must support timely reporting compliance.
- Reconciliation, escalation, and oversight mechanisms must be documented.
- The MAH must retain oversight of outsourced or shared pharmacovigilance obligations.
Why it matters
What this means in practice
Inspectors assess whether shared pharmacovigilance responsibilities are governed by a clear and current Safety Data Exchange Agreement. They typically review responsibility allocation, exchange timelines, reconciliation processes, escalation routes, audit provisions, and evidence that the agreement reflects actual operational practice.
Questions this page answers
Inspection evidence
Evidence teams should be able to show
Safety Data Exchange Agreement
- Signed agreement between MAH and partner or service provider
- Defined scope, product, and territory coverage
- Allocation of pharmacovigilance roles and responsibilities
- Defined timelines for case exchange and follow-up
- Version control and effective date
Responsibility Matrix
- Allocation of ICSR intake, processing, submission, and follow-up
- Ownership of aggregate reporting activities
- Responsibility for literature screening and signal management
- Defined roles for regulatory communication and label updates
ICSR Exchange and Reporting Process
- Agreed timelines for forwarding valid cases and follow-up information
- Defined use of day zero across parties
- Secure transfer mechanisms for case data
- Acknowledgement and duplicate prevention controls
Reconciliation and Oversight Records
- Periodic case reconciliation outputs
- Documentation of discrepancy investigation and resolution
- Joint safety committee or governance meeting records
- Escalation logs for critical safety issues
Audit, Inspection, and Retention Provisions
- Audit rights covering partner or vendor PV activities
- Inspection notification obligations
- Document retention requirements
- Evidence of current contact lists and 24/7 safety coverage
Regulatory Basis (Primary Sources)
- GVP Module I - MAH responsibility for pharmacovigilance systems and quality oversight
- GVP Module VI - requirements for ICSR collection, exchange, and reporting responsibilities
- ICH E2D - post-approval safety data management and reporting expectations
- MHRA GPvP guidance - expectations for pharmacovigilance systems under shared responsibilities
- FDA postmarketing safety reporting guidance - requirements for compliant safety reporting and partner coordination
Typical Inspection Questions (What Inspectors Ask)
- Show me your current SDEA for this product or partner.
- How are responsibilities allocated between the parties?
- What timeline applies for forwarding valid ICSRs?
- How do you reconcile cases between systems?
- How do you ensure the agreement reflects actual practice?
Common failure patterns
What good looks like
- A current, signed SDEA covering all relevant pharmacovigilance activities.
- Clear allocation of responsibilities for case handling, reporting, and oversight.
- Defined timelines for exchanging valid cases and follow-up information.
- Routine reconciliation and documented discrepancy resolution.
- Demonstrable MAH oversight of shared or outsourced PV activities.
How teams operationalise it
- Establish an SDEA before shared pharmacovigilance activities begin.
- Define product scope, territories, contact points, and role allocation clearly.
- Document ICSR exchange timelines, day zero rules, and submission responsibilities.
- Implement reconciliation routines and escalation pathways.
- Review and update the agreement when responsibilities, territories, or regulations change.
- Maintain active oversight of partner or vendor performance against the agreement.
From expectation to working control
Find the documentation that supports this work
Review the related toolkit to understand its purpose, included files, and how it supports this regulatory expectation.
Frequently asked questions
What is a Safety Data Exchange Agreement in pharmacovigilance?
A Safety Data Exchange Agreement is a written agreement that defines how pharmacovigilance responsibilities and safety information are managed between two parties, such as a marketing authorisation holder and a partner or service provider.
When is an SDEA required?
An SDEA is required whenever pharmacovigilance responsibilities or safety data handling activities are shared, delegated, or exchanged between separate organisations.
What should a pharmacovigilance SDEA include?
An SDEA should include scope, product and territory coverage, roles and responsibilities, ICSR exchange timelines, aggregate reporting responsibilities, signal management, reconciliation, escalation, audit rights, and document retention requirements.
What is the difference between a Safety Data Exchange Agreement and a Pharmacovigilance Agreement?
A Safety Data Exchange Agreement focuses on how safety data is exchanged between parties, including timelines and responsibilities, while a Pharmacovigilance Agreement defines the broader pharmacovigilance system framework, including oversight, processes, and compliance responsibilities.
Does the MAH remain responsible if PV activities are outsourced?
Yes. The MAH retains ultimate responsibility for pharmacovigilance compliance even where activities are outsourced or shared with a partner.
Do inspectors review Safety Data Exchange Agreements?
Yes. Inspectors frequently review SDEAs to confirm that shared pharmacovigilance responsibilities are controlled, current, and aligned with actual operational practice.
What are common SDEA inspection failures?
Common failures include missing agreements, unclear role allocation, missing timelines, poor reconciliation controls, and weak MAH oversight of the partner or vendor.
Source boundary
Regulatory sources
These primary sources inform this structured interpretation. Always confirm current requirements against the original source and the requirements applicable to your organisation, product, and jurisdiction.
European Medicines Agency (EMA)
Guideline on good pharmacovigilance practices (GVP) - Module I
View sourceGuideline on good pharmacovigilance practices (GVP) - Module VI
View source
International Council for Harmonisation (ICH)
Post-Approval Safety Data Management: Definitions and Standards for Expedited Reporting (E2D)
View source
U.S. Food and Drug Administration (FDA)
Postmarketing Safety Reporting for Human Drug and Biological Products
View source
UK MHRA
Good Pharmacovigilance Practice (GPvP)
View source