Regulatory Compliance

PMCPA complaint handling: internal oversight versus external audit

PMCPA complaint handling is governed by two different control environments. Internal compliance review is designed to identify, document, and escalate a potential breach within the company.

PMCPA complaint handling: internal oversight versus external audit

PMCPA Complaint Handling: Internal Oversight vs External Audit

PMCPA adjudication is an external, adversarial process in which the complainant carries the burden of proof. The two mechanisms are not interchangeable.

The distinction is operational, not semantic. Internal review can control evidence, assess exposure, preserve procedural integrity, and determine whether corrective action is required. It cannot remove PMCPA jurisdiction. A company that conducts a comprehensive internal investigation can still face external sanctions, including a mandatory audit of its compliance procedures, pre-vetting of promotional material, public reprimand, or suspension from the ABPI.

The central risk in the PMCPA complaint handling internal vs external review analysis is therefore false equivalence. Internal oversight manages the company’s response. External review determines the Code position.

The architecture of internal independence: separation of duties

The first control question is not whether a complaint has been assigned to compliance. It is whether the person preparing the case can influence the person deciding it.

The PMCPA Constitution and Procedure establishes a strict separation between case preparation and adjudication. Under paragraph 5.1, the case preparation manager who processes a complaint and prepares the case papers must not sit on the Code of Practice Panel that adjudicates the case.

This is a narrow rule with a broad compliance implication. Complaint handling requires at least two distinct functions:

1. Case preparation

The complaint is processed, the relevant materials are assembled, and the case papers are prepared.

2. Adjudication

The Code of Practice Panel evaluates the case and determines whether a breach has occurred.

3. Conflict control

Individuals with a relevant conflict must be excluded from participation.

4. Evidence-based determination

The adjudicating body assesses the evidence rather than relying on the authority of the person who prepared the file.

The same logic should exist inside a pharmaceutical company, even where the ABPI Code does not prescribe the company’s internal organisational chart. A medical signatory, compliance officer, legal adviser, commercial function, and pharmacovigilance representative may each hold different information or authority. The risk increases when one person controls the promotional material, evaluates the complaint, determines the response, and approves the final corrective action.

That structure creates variance in judgment and weakens the audit trail. It also makes later scrutiny more difficult. A defensible internal process must show where the initial concern arose, who assessed it, which evidence was considered, who approved the conclusion, and whether any conflict was identified.

Conflict of interest is a control threshold

PMCPA members must declare conflicts of interest. Former pharmaceutical company employees are restricted from involvement in a case relating to their former employer for a minimum period of three years.

The three-year restriction is not a statement about personal integrity. It is a procedural mitigation. The objective is to reduce the probability that prior employment affects access, interpretation, or adjudication. Regulatory systems depend on visible independence as well as actual independence. A decision can be technically sound and still attract procedural criticism if the independence threshold is unclear.

For pharmaceutical companies, the equivalent internal control is a documented conflict assessment at the beginning of the complaint process. A conflict review performed only after the substantive assessment has started has limited value. By that stage, the person may already have shaped the evidence file or influenced the classification of the issue.

A workable internal record should establish:

  • the identity and function of each person involved;
  • prior employment or direct involvement with the product, campaign, agency, or complainant;
  • any commercial interest connected with the material under review;
  • the decision-maker responsible for the final internal position;
  • the reason an individual was included or excluded from the process.

This is not administrative surplus. It is evidence of process integrity.

Internal review is a control mechanism. It is not a substitute for independent adjudication.

The adversarial nature of PMCPA adjudication

The PMCPA is not a government regulatory agency and does not operate as a proactive investigative law-enforcement body. It is a self-regulatory body operating independently within the ABPI. Its complaint system is adversarial.

That distinction determines the shape of the ABPI Code breach investigation process. The PMCPA does not conduct an open-ended investigation into every aspect of a company’s compliance programme. The complainant must establish the alleged breach on the balance of probabilities, using the evidence provided by the parties.

The burden of proof therefore remains central. A complaint is not converted into a breach merely because a concern appears plausible. The evidential record must support the allegation to the applicable standard.

The process creates two separate questions:

1. Was the alleged conduct within the scope of the Code?

2. Does the available evidence establish a breach on the balance of probabilities?

Internal company review may address a wider set of questions. It may examine whether approval controls operated correctly, whether the medical signatory had sufficient information, whether training was adequate, or whether similar materials remain in circulation. Those questions can be operationally important even if the specific PMCPA complaint does not result in a breach finding.

This is where internal compliance teams often misclassify exposure. A complaint with weak evidence may not satisfy the PMCPA burden of proof. That does not establish that the underlying control environment is adequate. Conversely, a company may identify an internal control failure without that failure being the same as a Code breach.

Evidence is not equivalent to volume

The PMCPA’s adversarial model does not reward indiscriminate document production. Evidence must be relevant to the alleged breach and capable of supporting or refuting the claim.

A larger file can increase variance rather than reduce it. Unindexed emails, multiple versions of promotional material, incomplete approval records, and retrospective explanations can obscure the decisive facts. The internal review should isolate the material issue:

  • What claim, statement, image, comparison, or activity is challenged?
  • Which version was used?
  • Where and when was it disseminated?
  • Who approved it?
  • What evidence supported the claim at the time?
  • Did the context alter the meaning?
  • Was the material withdrawn, amended, or continued after the concern arose?

The medical signatory role is relevant at this point, but it should not be reduced to a signature on a final approval page. The signatory’s compliance value depends on the quality of the information available for review, the traceability of the evidence, and the ability to identify material changes between approved and distributed content.

If the approval record shows only a final sign-off without the supporting evidence or version history, the signature has limited mitigation value. It demonstrates authorisation. It does not, by itself, demonstrate a controlled review.

The 2024 Abridged Complaints Procedure

The 2024 ABPI Code introduced an Abridged Complaints Procedure. It allows simpler complaints to be resolved more quickly where the central facts are undisputed and a likely breach is apparent. Serious or disputed complaints continue through the full procedure.

The distinction is procedural. It does not create a lower standard of compliance for simpler cases. Nor does it allow a company to classify a materially disputed issue as simple merely because rapid closure is commercially preferable.

A complaint is more suitable for an abridged route where the factual basis is clear and the principal issue is not contested. A complaint requires the full procedure where the facts are disputed, the allegation is serious, the evidence is incomplete, or the applicable Code interpretation requires detailed adjudication.

Abridged versus full procedure

ParameterAbridged complaints procedureFull complaints procedure
Central factsUndisputedDisputed, incomplete, or materially complex
Likely outcomeA likely breach can be identified without full Panel reviewThe allegation requires full consideration
Procedural objectiveFaster resolution of a simpler matterFormal adjudication of a serious or contested complaint
Evidence burdenStill requires an evidential basisRequires detailed assessment of submissions and evidence
Internal responseRapid containment and accurate factual confirmationControlled evidence preservation and structured defence or remediation
Principal riskMisclassification of a complex issue as simpleDelay, inconsistent submissions, or uncontrolled document production

The operational hazard is not speed. It is premature simplification.

A company that receives a complaint should first determine whether the central facts are genuinely undisputed. Agreement that a material was distributed does not mean agreement about its meaning, context, audience, substantiation, or compliance status. A dispute can exist beneath apparently simple facts.

For internal teams managing PMCPA Code of Practice complaints, the classification decision should be documented. The record should state which facts are accepted, which are disputed, and why the chosen procedure is proportionate. That record becomes part of the company’s risk history even if the complaint is resolved without a full Panel review.

The abridged route reduces procedural length. It does not reduce the requirement for factual control.

Internal audit versus external review

Internal audit and external review answer different questions.

Internal audit tests whether the company’s control system operated as designed. It can examine approval pathways, segregation of duties, training records, signatory review, vendor oversight, version control, escalation thresholds, and corrective action. It is a management tool.

External PMCPA review determines whether the evidence establishes a breach of the ABPI Code. It is an independent adjudicative mechanism within the self-regulatory system. Its jurisdiction is not displaced by an internal conclusion.

The distinction can be expressed directly:

Control environmentPrimary questionEvidence baseResult
Internal compliance reviewDid the company identify, assess, escalate, and control the issue appropriately?Company records, approvals, correspondence, training, procedures, and corrective actionsInternal finding and mitigation plan
PMCPA complaint processHas a breach of the ABPI Code been established on the balance of probabilities?Evidence submitted by the partiesPanel or procedural determination
External audit ordered after a breachAre the company’s compliance procedures sufficiently controlled and effective?Procedures, implementation records, governance, monitoring, and operational evidenceAudit findings and required remediation
Appeal reviewWas the decision or sanction subject to proper independent review?Case record, submissions, and appeal groundsAppeal determination

The phrase pharmaceutical compliance internal audit vs external counsel can also produce confusion. External legal counsel may advise the company. That does not make counsel equivalent to the PMCPA, nor does legal advice constitute an external compliance audit. Counsel supports the company’s response. The PMCPA assesses the complaint within its own procedural framework. A third-party auditor may examine the company’s procedures after a sanction. Each function has a different mandate.

What internal review can achieve

A disciplined internal review can:

1. Preserve the original promotional material and all relevant versions.

2. Identify the exact communication channel, audience, and distribution period.

3. Reconstruct the approval pathway.

4. Test the evidence supporting each challenged claim.

5. Determine whether the medical signatory reviewed the material in its final form.

6. Identify related materials with the same claim or risk profile.

7. Suspend or amend material where continued use creates avoidable exposure.

8. Prepare a coherent factual submission if the complaint proceeds externally.

9. Define corrective and preventive actions.

10. Establish whether the issue indicates isolated variance or systemic control failure.

None of these actions guarantees that the PMCPA will find no breach. They reduce uncertainty and improve the quality of the company’s response.

External oversight and the Appeal Board mechanism

The PMCPA complaint system includes external review mechanisms beyond the initial Panel process. These include independent Appeal Board oversight, referee reviews, and external audits of company procedures.

The composition of the Code of Practice Appeal Board is a material safeguard. It consists of an independent, legally qualified Chair, eight independent members, and eight industry members. The Appeal Board must sit with an independent majority of at least seven members plus the Chair.

The structure is designed to prevent industry representation from becoming the controlling influence in an appeal. The independent majority is not a symbolic feature. It is a governance threshold.

This has two consequences for pharmaceutical companies.

First, an appeal is not an opportunity to repeat an internal position without addressing the procedural and evidential basis of the decision. The response must engage with the grounds of appeal and the record supporting the original finding.

Second, the existence of industry members does not convert the process into internal peer review. The independent majority and legally qualified Chair preserve a distinct external function.

Referee reviews and procedural scrutiny

Referee reviews provide another external mechanism for examining aspects of a complaint process. The relevant issue is not whether external review is hostile to the company. The issue is whether the company’s procedural position remains defensible when tested outside its own governance structure.

Internal documentation should therefore be prepared on the assumption that the following may be examined:

  • the point at which the company became aware of the complaint;
  • the time taken to preserve records;
  • the identity of the initial reviewer;
  • conflict assessments;
  • the scope of the internal review;
  • the evidence used to support the company’s position;
  • the handling of adverse evidence;
  • the decision to continue, amend, or withdraw material;
  • the approval of the final submission;
  • the implementation of corrective action.

A process that cannot answer these questions has a traceability deficit. That deficit may be more significant than the original complaint, particularly where the complaint exposes repeated weaknesses.

When compliance fails: mandatory external audits

A breach of the ABPI Code can lead to sanctions ordered by the Appeal Board or the ABPI Board. These sanctions can include a mandatory external audit of the company’s compliance procedures by the PMCPA, pre-vetting of promotional material, a public reprimand, or suspension from the ABPI.

The mandatory external audit is the most direct answer to the question of internal versus external review. It confirms that the company’s own compliance assessment does not close the matter. If the external body determines that the control environment requires scrutiny, the company must submit to a review that is separate from its ordinary internal assurance activity.

An external audit may expose variance between documented procedure and operational practice. Common control failures in this category include:

  • a written approval pathway that is not followed in practice;
  • incomplete evidence supporting promotional claims;
  • unclear accountability between medical, regulatory, compliance, and commercial functions;
  • inadequate control over agency-created material;
  • multiple live versions of the same promotional asset;
  • insufficient monitoring after approval;
  • corrective actions that address one item but not the underlying process;
  • signatory review that is formal rather than substantive.

The exact audit turnaround metrics across individual companies are not uniform. No general operational benchmark should be assumed. The relevant issue is whether the company can demonstrate controlled implementation, not whether it can report a preferred completion interval.

Pre-vetting changes the risk profile

Pre-vetting of promotional material imposes an additional control layer. It also signals that the organisation’s ordinary compliance system has not been accepted as sufficient for unrestricted operation.

The consequence is operational. Launch timelines become dependent on external review. Promotional flexibility decreases. The cost of variance increases because an issue that might previously have been corrected internally can now affect the release pathway for subsequent material.

A company should not treat pre-vetting as a replacement for internal quality control. It is an external mitigation imposed in response to identified risk. If internal review becomes less rigorous because pre-vetting exists, the control environment deteriorates further.

Public reprimand and suspension from the ABPI create separate exposure. They affect the visibility and status of the compliance failure. The reputational dimension is secondary to the regulatory signal: the organisation has failed to demonstrate adequate adherence to the Code or adequate control of its compliance procedures.

The practical sequence for managing a complaint

A defensible complaint response follows a strict cause-and-effect sequence.

1. Contain the evidence

The company should preserve the challenged material in the form in which it was used. Later amendments must not overwrite the original record. Distribution data, approval records, supporting references, and correspondence should remain identifiable.

2. Define the allegation

The issue should be reduced to the specific claim or conduct under review. Broad labels such as non-compliant promotion or medical concern are insufficient for a reliable assessment.

3. Separate accepted facts from disputed facts

This determines whether an abridged procedure may be appropriate and prevents the internal team from presenting assumptions as established evidence.

4. Test conflicts and independence

The company should identify who prepared the internal assessment, who reviewed it, who approved the response, and whether any person had a relevant interest or prior involvement.

5. Assess the Code position

The assessment should address the applicable Code requirements and the evidence supporting each conclusion. Unsupported confidence has no mitigation value.

6. Determine immediate corrective action

Withdrawal, amendment, suspension, additional medical review, or communication to affected stakeholders may be appropriate. The action should be linked to the identified risk, not selected as a generic gesture.

7. Prepare for external scrutiny

The internal file should remain intelligible to a reviewer who was not involved in the original decision. If the reasoning depends on undocumented discussions or institutional memory, the control is weak.

8. Track systemic implications

The complaint may reveal a broader problem involving the same claim, product, agency, signatory process, or approval pathway. Closure of the individual complaint does not automatically close the systemic risk.

The decisive distinction

PMCPA complaint handling internal vs external review is not a choice between two competing methods. It is a sequence of controls with separate mandates.

Internal oversight establishes whether the company acted with procedural discipline. PMCPA adjudication establishes whether the evidence supports a Code breach. Appeal mechanisms test the external decision through independent governance. Mandatory external audit tests whether the company’s compliance system is capable of preventing recurrence.

The 2024 Abridged Complaints Procedure may reduce the time required for simpler, undisputed matters. It does not change the need for evidence control, conflict management, or accurate classification. The external system remains adversarial. The burden of proof remains with the complainant. A company’s internal conclusion remains only an internal conclusion.

The risk assessment is therefore definitive: a mature compliance function does not attempt to replace external oversight. It produces a record that can withstand it. A failure to separate preparation from adjudication, preserve evidence, control conflicts, or identify systemic variance increases the probability that a single complaint will become a broader examination of the organisation’s compliance architecture.

FAQ

What is the difference between internal compliance review and PMCPA adjudication?
Internal review is a management tool used to identify, document, and control potential issues within a company. PMCPA adjudication is an independent, adversarial process that determines whether a breach of the ABPI Code has occurred based on the evidence provided.
Can a company avoid external sanctions by conducting its own internal investigation?
No. A comprehensive internal investigation does not remove PMCPA jurisdiction, and a company can still face external sanctions such as mandatory audits, public reprimands, or suspension from the ABPI regardless of its internal findings.
What is the purpose of the 2024 Abridged Complaints Procedure?
The abridged procedure allows for faster resolution of simpler complaints where the central facts are undisputed and a likely breach is apparent. It does not lower compliance standards or allow companies to bypass full procedures for complex or disputed matters.
Why is the separation of duties important in complaint handling?
Separation of duties prevents individuals who prepare a case from influencing those who adjudicate it. This structure reduces the risk of biased judgment and ensures that the decision-making process is based on evidence rather than the authority of the person who prepared the file.
What happens if a company is subjected to a mandatory external audit?
A mandatory external audit is an independent review of a company's compliance procedures ordered by the Appeal Board or ABPI Board. It assesses whether the company's governance, monitoring, and operational practices are sufficiently controlled and effective.

Read also