
The practical consequence is broad: Marketing Authorisation Holders with products authorised in the European Economic Area must now account for EudraVigilance data within their own signal management systems.
That does not mean that every MAH must run the same reports at the same interval, or that an orphan medicine and a high-volume cardiovascular product can be managed through identical procedures. Universal coverage sets the perimeter of the obligation. It does not remove the need for product-specific judgement.
The end of the pilot also changes the reporting architecture. For signals detected through EudraVigilance, the former standalone notification route is no longer the default mechanism. Responsibility shifts more clearly towards the MAH’s internal process: data must be screened, a potential signal must be assessed, and the outcome must feed into the appropriate pharmacovigilance and regulatory activities.
For organisations still working from an infrastructure designed around the pilot or the earlier framework, this is not a matter of adding one more report to a calendar. It requires a defensible connection between EudraVigilance access, statistical screening, clinical review, signal tracking, PSUR preparation and, where necessary, regulatory action.
The Shift from Pilot to Universal Obligation: Implementing Regulation (EU) 2025/1466
The EudraVigilance signal detection pilot was built around selective participation. The extent of participation depended on the substances, products and MAHs involved, and the pilot context allowed organisations to develop processes within a more limited operating model.
Implementing Regulation (EU) 2025/1466 changes that starting point. The obligation is no longer confined to a selected group of active substances or participating companies. It applies across the relevant population of EEA-authorised products, with the marketing authorisation acting as the basis for inclusion.
That distinction matters. An MAH cannot decide that a product falls outside the process simply because it has low sales, a small patient population or a long-established safety profile. Nor can previous non-participation in the pilot be treated as a continuing exemption. EudraVigilance data must be considered within the MAH’s signal management framework.
At the same time, the regulation should not be read as imposing a single operating model on all products. A universal obligation to screen and assess relevant data is not the same as a universal obligation to use the same frequency, statistical methodology, review depth or escalation criteria. Those elements should reflect the product’s safety profile, lifecycle stage, available exposure information and other characteristics that affect the likelihood or consequences of an emerging risk.
Good Pharmacovigilance Practices (GVP) Module IX remains the central reference point for the sequence of signal management activities. In practical terms, the process moves through:
1. Signal detection, including the screening of relevant EudraVigilance data.
2. Signal validation, to determine whether the finding represents a new potential causal association or a new aspect of a known association.
3. Signal confirmation and analysis, where the finding is examined in greater depth.
4. Prioritisation and assessment, taking account of public health relevance and the product’s benefit-risk balance.
5. Recommendation for action, including decisions on further monitoring, risk minimisation, product information or other regulatory measures.
The MAH’s procedures should make this sequence visible. The evidence supporting a decision should be retrievable, and the handoffs between pharmacovigilance, medical review, safety governance and regulatory affairs should be clear. That documentation may be maintained across the relevant pharmacovigilance records and controlled procedures; the point is not that every individual analytical step must be reproduced inside the Pharmacovigilance System Master File itself. The point is that the MAH must be able to demonstrate how its signal management system operates and how decisions are governed.
Universal EudraVigilance coverage creates a common regulatory perimeter. It does not make product-specific risk assessment optional.
The January 2026 EMA Q&A provides operational clarification on the implementation of Regulation (EU) 2025/1466, including expectations around detection, validation and evaluation. It should be read as implementation guidance rather than as a replacement for the binding regulation or for the principles of GVP Module IX.
For MAHs, the immediate question is therefore not whether the product is important enough to justify monitoring. It is whether the existing system can show, in a controlled and proportionate way, how EudraVigilance information is incorporated into the decisions already required under the pharmacovigilance framework.
Integrating EudraVigilance Data into Internal Signal Management Frameworks
EudraVigilance data should not sit at the edge of the safety system as an occasional external check. It needs to connect to the MAH’s established signal management process, alongside spontaneous reports from other sources, clinical and epidemiological information, literature findings, company safety data and known risks described in the safety specification.
The integration has several practical layers.
Access is a controlled operational capability
Access to EudraVigilance case narratives for signal validation is not simply an IT permission. It is a controlled pharmacovigilance responsibility. The MAH should know which personnel require access, what they are authorised to do, how confidentiality obligations are managed and how changes in personnel are reflected in access records.
The relevant personnel are nominated through the appropriate pharmacovigilance governance arrangements, including the role of the EU Qualified Person for Pharmacovigilance. Each authorised individual must meet the applicable confidentiality and access requirements. A broad, informal delegation model creates avoidable weaknesses: it becomes difficult to show who reviewed a case, under what authority and with which version of the procedure.
The access model should also distinguish between routine statistical screening and case-level review. The people or systems generating a potential statistical finding may not be the same people who perform the clinical assessment. That is acceptable, provided the responsibilities and escalation route are defined.
The screening method must be explainable
An MAH should be able to describe how it uses EudraVigilance data, not merely confirm that someone has logged into the system. The description should cover, as applicable:
- the data sources and datasets used for screening;
- the statistical methods and disproportionality measures applied;
- the medical concepts or groupings used to identify relevant events;
- the treatment of duplicates, known risks and data-quality limitations;
- the thresholds or prompts that trigger human review;
- the process for recording a decision not to validate a potential signal;
- the circumstances in which a finding is escalated for full evaluation.
Statistical methods are useful because they help identify patterns that may not be visible through individual case review. They are not a substitute for medical assessment. A disproportionality result can be influenced by reporting behaviour, stimulated reporting, changes in exposure, missing denominators, duplicate cases or an event that is already well characterised. The method is therefore part of the evidence, not the conclusion.
The methodology should be controlled as a pharmacovigilance document and reviewed when the product, data environment or internal process changes. It should also be sufficiently clear for an inspector or auditor to understand how a raw finding became a documented decision.
The internal workflow must extend beyond detection
A potential signal that remains in an analytics dashboard has not been integrated into the MAH’s signal management system. It must enter a workflow with an owner, a defined status and a rationale for the next step.
Depending on the outcome, the workflow may lead to:
- additional case review or targeted follow-up;
- a documented decision not to validate the finding;
- inclusion in ongoing signal tracking;
- a formal signal evaluation;
- consideration in a PSUR;
- an update to the safety specification or risk management plan;
- a variation application or another regulatory action.
The exact route will depend on the nature of the finding. Not every statistical signal becomes a confirmed safety concern, and not every validated signal requires an immediate change to product information. The system must nevertheless show that the finding was considered and that the conclusion was proportionate to the evidence.
This is where many operating models become fragile. Detection may sit with a central analytics team, case review with a safety physician, PSUR drafting with another group and regulatory submissions with a separate function. That division of labour is workable only when the handoffs are explicit. A process that depends on personal memory or informal messages is difficult to defend when priorities change or staff move.
The MAH should define who can close a potential signal, who can approve the validation decision, when medical review is mandatory and how unresolved disagreements are escalated. The records should remain linked to the underlying analysis and case review, but they do not need to be forced into one document or one software module to be auditable.
Methodological Requirements for Screening Frequency and Risk-Based Monitoring
The regulation does not turn screening frequency into a universal calendar obligation. The appropriate interval and depth of monitoring should be justified through a documented, product-specific risk assessment.
That assessment should not be treated as a one-time exercise. A product’s monitoring needs can change as new information accumulates, as exposure changes, as a safety issue emerges or as the product moves through its lifecycle. The procedure should therefore explain both the initial rationale and the circumstances that trigger reassessment.
Several factors are especially relevant.
Safety profile
A product with known serious adverse reactions, important drug interactions, a narrow therapeutic index or unresolved safety questions may require more intensive monitoring than a product with a mature and well-characterised profile. The presence of an important identified risk does not automatically determine one particular screening interval, but it should influence the depth and urgency of the review.
The MAH should also consider whether the product has a safety profile that could make early recognition particularly important. A rare but medically serious event may justify a different approach from a common, mild and well-understood reaction, even where the volume of reports is similar.
Lifecycle stage
Lifecycle stage is relevant because the amount and quality of post-authorisation information change over time. A newly authorised product may have limited real-world exposure data and less opportunity for rare or delayed reactions to appear outside clinical development. That can support more intensive surveillance, particularly where the product has other risk factors.
However, GVP principles do not create a blanket rule that every product must receive heightened surveillance for a fixed two- or three-year period. The appropriate approach is risk-based. The MAH should document why a particular lifecycle stage changes, or does not change, its monitoring strategy.
A product that has been on the market for a longer period may still require increased attention after a new indication, a manufacturing change, a new formulation, a change in use pattern or the emergence of a previously unrecognised event. Conversely, a newer product with a clearly defined and closely monitored risk profile may have a different procedure from another recently authorised product.
Product characteristics and use context
The characteristics of the product and its use can alter the value and limitations of different screening methods. Relevant considerations may include:
- complex delivery systems or combination products;
- biosimilar or biological product characteristics;
- paediatric or elderly populations;
- oncology, rare disease or other settings with distinctive reporting patterns;
- medicines used in severely ill populations with substantial background morbidity;
- fixed-dose combinations where attribution may be difficult;
- products with limited exposure and therefore sparse data;
- products with high reporting volumes that require careful management of duplicates and stimulated reporting.
These factors should inform the methodology rather than serve as labels that automatically prescribe a result. A biosimilar, for example, may raise particular attribution and product-identification questions, while a high-volume generic may create a different set of challenges associated with large numbers of reports and background event rates.
Data volume and data quality
The number of reports is not a direct measure of safety risk. A low case volume may produce unstable statistical results, while a high volume may create apparent signals that require careful clinical interpretation. The MAH should consider the strength and completeness of the available evidence, not only the size of the dataset.
The rationale for monitoring may therefore include the expected sensitivity of the method, the limitations of the available denominators, the quality of case narratives and the ability of reviewers to investigate a finding. Screening frequency should be meaningful in relation to those factors. More frequent automated runs do not compensate for weak case review or an unclear decision process.
A proportionate monitoring model might be described in terms such as the following:
| Product or monitoring context | Possible implications for the procedure |
|---|---|
| New product with limited real-world exposure and serious potential risks | More frequent review, closer medical oversight and rapid escalation criteria may be justified |
| Established product with a well-characterised safety profile | Routine screening may be appropriate if the rationale, review scope and reassessment triggers are documented |
| Product with sparse reports in a rare disease | Statistical findings may be unstable, increasing the importance of case-level review and qualitative assessment |
| High-volume product with substantial reporting activity | The method may need stronger controls for duplicates, reporting stimulation, background morbidity and prioritisation |
| Product with a new indication or changed pattern of use | The monitoring approach may need to be reassessed even if the product has a long market history |
| Product with an emerging safety concern | The existing frequency and depth of monitoring may need to increase in response to the new information |
This is the practical meaning of risk-based monitoring: the same regulatory obligation applies, but the justification, frequency and review intensity are calibrated to the product and its circumstances.
A defensible screening interval is not the one that looks most intensive on paper. It is the one the MAH can explain, operate consistently and revise when the evidence changes.
The rationale should be approved through the MAH’s normal pharmacovigilance governance, reviewed at defined intervals and made available for regulatory inspection. A quarterly screen, a monthly review or another interval is not inherently compliant or non-compliant in isolation. The question is whether the choice is supported by the product-specific assessment and whether the process is actually followed.
Operationalizing Signal Validation: From Statistical Detection to Clinical Assessment
Signal validation is the point at which an analytical finding becomes a pharmacovigilance judgement. It is not a mechanical confirmation that a statistical threshold has been crossed.
The MAH must decide whether the finding represents a new potential causal association, or a new aspect of a known association, that warrants further analysis. That decision requires a structured review of the underlying information and the surrounding clinical context.
Start with the cases, not the number
Case-level review is central to validation. The reviewer should consider the medical history, indication, dose and treatment timing, relevant concomitant medicines, dechallenge or rechallenge information where available, alternative explanations and the seriousness of the outcome.
The quality of the narrative matters. A cluster of poorly documented cases may produce a statistical alert but provide little support for a causal hypothesis. Conversely, a small number of clinically coherent reports may justify further attention even when the statistical evidence is limited. The validation record should explain how the quality and limitations of the cases influenced the decision.
The review should also account for product identification and possible duplication. These issues are particularly important when information is drawn from multiple reporting channels or when a case has been updated over time. A statistical result that has not been checked against the underlying case structure may be misleading.
Put the finding into pharmacological context
The next question is whether the association is clinically and biologically plausible. That does not require a definitive mechanism at the validation stage. It does require the MAH to consider the product’s pharmacology, mechanism of action, known class effects, non-clinical findings, clinical trial information and relevant evidence from the wider medical literature or other safety sources available to the company.
The context may strengthen the case for further evaluation, weaken it or identify a more appropriate explanation. An event that is expected in the treated population may require a different assessment from an unexpected event with a plausible temporal and pharmacological relationship. Neither conclusion should be reduced to a single statistical score.
Define the escalation rule before the result arrives
The written methodology should explain what happens when a potential signal is detected. It should identify the factors that can move a finding from screening to validation, and from validation to full evaluation.
A fixed numerical threshold cannot carry the whole decision. Thresholds may be useful as prompts for review, but the escalation decision should also consider:
- seriousness and preventability of the event;
- novelty of the association;
- clinical coherence of the cases;
- strength of alternative explanations;
- consistency across data sources;
- plausibility in light of pharmacology and existing evidence;
- possible impact on the benefit-risk balance;
- the consequences of delayed action.
This is particularly important for rare events. A statistical method may not produce a stable result when the underlying data are sparse, but the absence of a strong disproportionality signal does not automatically resolve a clinically credible concern.
Record the decision, including decisions not to proceed
A mature signal management process records more than positive findings. It also records why a potential signal was not validated, why further evaluation was deferred or why monitoring continued without a regulatory recommendation.
The record should identify the information reviewed, the reviewers involved, the conclusion reached and any follow-up action. If the issue is retained for continued monitoring, that status should have a review point rather than becoming an indefinite holding category.
The documentation should be connected to the broader pharmacovigilance system, but it need not be represented by a claim that every stage is physically traceable within the PSMF. The more accurate requirement is that the MAH can demonstrate controlled governance, retrievable evidence and a coherent sequence of decisions across its relevant systems and records.
The January 2026 EMA Q&A reinforces the practical division of responsibility: the MAH is responsible for operating and documenting its signal management process. EMA and national competent authorities may assess that process, but they do not carry out the MAH’s validation work on its behalf.
Regulatory Reporting: Transitioning from Standalone Notifications to PSURs and Variations
The end of the pilot changes how an MAH should think about the output of signal detection. The process is not complete when a potential signal is listed, and it does not necessarily end with a separate notification to EMA or a national competent authority.
The former standalone signal notification mechanism for signals detected in EudraVigilance is no longer the normal route described in the post-pilot model. The relevant information must instead move through the MAH’s established safety and regulatory channels.
Internal records remain the foundation
The first reporting destination is the MAH’s own signal management record. It should show the path from the initial detection through validation, assessment and recommendation. It should also show the current status of the issue and the reasoning behind the decision.
This does not mean that every signal must result in a regulatory submission. It means that every relevant finding must be assessed through a process capable of producing a defensible conclusion. A decision that no action is required is still a pharmacovigilance decision and should be supported accordingly.
PSURs provide the periodic regulatory context
Where a signal is relevant to the reporting period or to the ongoing benefit-risk assessment, it should be reflected in the appropriate Periodic Safety Update Report. The PSUR should not merely reproduce a statistical output. It should explain the signal’s status, the evidence considered, the assessment performed and any implications for the product’s safety profile or risk management activities.
The level of detail will depend on the nature of the signal and its relevance to the product. A potential finding that was screened out after case review is different from a validated signal undergoing a full evaluation. A new concern that may affect the benefit-risk balance requires a different treatment again.
The connection between signal management and PSUR production should therefore be designed in advance. The safety team preparing the PSUR needs access to the relevant decisions, supporting analyses and current status. The signal record should make it possible to determine whether the issue is new, ongoing, closed, escalated or awaiting further evidence.
Variations are an action, not an automatic endpoint
If the assessment identifies a need to change the product information, risk management plan or conditions of authorisation, the MAH may need to submit the appropriate variation. The signal provides part of the evidentiary basis for that action; the variation is the regulatory mechanism for implementing the change.
Not every detected signal justifies a variation. Some findings will be disproved, remain inconclusive, require continued monitoring or lead to other risk management activities. The decision should be based on the overall evidence and benefit-risk assessment rather than on the fact that a statistical alert appeared in EudraVigilance.
This is why the link between pharmacovigilance and regulatory affairs cannot be left until the submission is being drafted. The relevant teams should understand the escalation criteria, the documentation required to support a regulatory decision and the circumstances in which emerging information must be considered outside the ordinary PSUR cycle.
Build handoffs that work under pressure
A post-pilot process is only as strong as its handoffs. At a minimum, the MAH should be able to answer:
- Who receives the output of routine EudraVigilance screening?
- Who decides whether a potential signal enters validation?
- Who performs or approves the clinical assessment?
- How is the issue tracked if additional information is needed?
- How is the signal considered for the next PSUR?
- Who determines whether a risk management update or variation is required?
- How are urgent concerns escalated outside ordinary reporting timelines?
These are operational questions, but they are also regulatory questions. A company may have an excellent statistical tool and still have a weak signal management system if no one owns the decision after the alert is generated.
Making the Post-Pilot Model Work
The post-July 2025 environment has a clear baseline: EEA-authorised products fall within the scope of the EudraVigilance signal management obligation, and MAHs must be able to show how relevant data are integrated into their pharmacovigilance processes.
The baseline does not dictate identical procedures for every product. A risk-based system should distinguish between products with different safety profiles, lifecycle stages, exposure patterns and data limitations. It should also be capable of changing when those conditions change.
For MAHs, the most useful implementation exercise is to test the complete chain rather than review the screening tool in isolation:
1. Confirm that the relevant personnel have controlled access and appropriate confidentiality arrangements.
2. Review the written screening methodology and the logic behind its statistical and medical triggers.
3. Check whether screening frequency is justified for each product or product group rather than inherited without explanation.
4. Test the route from an alert to case-level review, validation and documented closure or escalation.
5. Confirm that the signal record feeds into PSUR planning and benefit-risk assessment.
6. Check that regulatory affairs and risk management functions are involved when the assessment indicates a possible need for action.
7. Verify that records can be retrieved and understood without relying on undocumented institutional knowledge.
This exercise should be proportionate to the portfolio. A company managing several products may use common procedures, templates and systems, but it should still document where product-specific differences matter. Standardisation is useful for governance; it becomes a weakness when it conceals different risk profiles behind a single unexplained rule.
The strongest compliance posture is not the one with the most elaborate dashboard. It is the one in which the MAH can explain why it monitors a product in a particular way, how it evaluates the findings and what happens when the evidence changes.
The end of the pilot therefore marks more than a change in participation status. It places EudraVigilance signal detection within the ordinary accountability of the MAH’s pharmacovigilance system. Statistical screening is one component. Clinical assessment, documented reasoning, proportionate monitoring and timely regulatory follow-through complete the process.