
PMCPA Complaint Handling: Internal Oversight vs External Audit
PMCPA adjudication is an external, adversarial process in which the complainant carries the burden of proof. The two mechanisms are not interchangeable.
The distinction is operational, not semantic. Internal review can control evidence, assess exposure, preserve procedural integrity, and determine whether corrective action is required. It cannot remove PMCPA jurisdiction. A company that conducts a comprehensive internal investigation can still face external sanctions, including a mandatory audit of its compliance procedures, pre-vetting of promotional material, public reprimand, or suspension from the ABPI.
The central risk in the PMCPA complaint handling internal vs external review analysis is therefore false equivalence. Internal oversight manages the company’s response. External review determines the Code position.
The architecture of internal independence: separation of duties
The first control question is not whether a complaint has been assigned to compliance. It is whether the person preparing the case can influence the person deciding it.
The PMCPA Constitution and Procedure establishes a strict separation between case preparation and adjudication. Under paragraph 5.1, the case preparation manager who processes a complaint and prepares the case papers must not sit on the Code of Practice Panel that adjudicates the case.
This is a narrow rule with a broad compliance implication. Complaint handling requires at least two distinct functions:
1. Case preparation
The complaint is processed, the relevant materials are assembled, and the case papers are prepared.
2. Adjudication
The Code of Practice Panel evaluates the case and determines whether a breach has occurred.
3. Conflict control
Individuals with a relevant conflict must be excluded from participation.
4. Evidence-based determination
The adjudicating body assesses the evidence rather than relying on the authority of the person who prepared the file.
The same logic should exist inside a pharmaceutical company, even where the ABPI Code does not prescribe the company’s internal organisational chart. A medical signatory, compliance officer, legal adviser, commercial function, and pharmacovigilance representative may each hold different information or authority. The risk increases when one person controls the promotional material, evaluates the complaint, determines the response, and approves the final corrective action.
That structure creates variance in judgment and weakens the audit trail. It also makes later scrutiny more difficult. A defensible internal process must show where the initial concern arose, who assessed it, which evidence was considered, who approved the conclusion, and whether any conflict was identified.
Conflict of interest is a control threshold
PMCPA members must declare conflicts of interest. Former pharmaceutical company employees are restricted from involvement in a case relating to their former employer for a minimum period of three years.
The three-year restriction is not a statement about personal integrity. It is a procedural mitigation. The objective is to reduce the probability that prior employment affects access, interpretation, or adjudication. Regulatory systems depend on visible independence as well as actual independence. A decision can be technically sound and still attract procedural criticism if the independence threshold is unclear.
For pharmaceutical companies, the equivalent internal control is a documented conflict assessment at the beginning of the complaint process. A conflict review performed only after the substantive assessment has started has limited value. By that stage, the person may already have shaped the evidence file or influenced the classification of the issue.
A workable internal record should establish:
- the identity and function of each person involved;
- prior employment or direct involvement with the product, campaign, agency, or complainant;
- any commercial interest connected with the material under review;
- the decision-maker responsible for the final internal position;
- the reason an individual was included or excluded from the process.
This is not administrative surplus. It is evidence of process integrity.
Internal review is a control mechanism. It is not a substitute for independent adjudication.
The adversarial nature of PMCPA adjudication
The PMCPA is not a government regulatory agency and does not operate as a proactive investigative law-enforcement body. It is a self-regulatory body operating independently within the ABPI. Its complaint system is adversarial.
That distinction determines the shape of the ABPI Code breach investigation process. The PMCPA does not conduct an open-ended investigation into every aspect of a company’s compliance programme. The complainant must establish the alleged breach on the balance of probabilities, using the evidence provided by the parties.
The burden of proof therefore remains central. A complaint is not converted into a breach merely because a concern appears plausible. The evidential record must support the allegation to the applicable standard.
The process creates two separate questions:
1. Was the alleged conduct within the scope of the Code?
2. Does the available evidence establish a breach on the balance of probabilities?
Internal company review may address a wider set of questions. It may examine whether approval controls operated correctly, whether the medical signatory had sufficient information, whether training was adequate, or whether similar materials remain in circulation. Those questions can be operationally important even if the specific PMCPA complaint does not result in a breach finding.
This is where internal compliance teams often misclassify exposure. A complaint with weak evidence may not satisfy the PMCPA burden of proof. That does not establish that the underlying control environment is adequate. Conversely, a company may identify an internal control failure without that failure being the same as a Code breach.
Evidence is not equivalent to volume
The PMCPA’s adversarial model does not reward indiscriminate document production. Evidence must be relevant to the alleged breach and capable of supporting or refuting the claim.
A larger file can increase variance rather than reduce it. Unindexed emails, multiple versions of promotional material, incomplete approval records, and retrospective explanations can obscure the decisive facts. The internal review should isolate the material issue:
- What claim, statement, image, comparison, or activity is challenged?
- Which version was used?
- Where and when was it disseminated?
- Who approved it?
- What evidence supported the claim at the time?
- Did the context alter the meaning?
- Was the material withdrawn, amended, or continued after the concern arose?
The medical signatory role is relevant at this point, but it should not be reduced to a signature on a final approval page. The signatory’s compliance value depends on the quality of the information available for review, the traceability of the evidence, and the ability to identify material changes between approved and distributed content.
If the approval record shows only a final sign-off without the supporting evidence or version history, the signature has limited mitigation value. It demonstrates authorisation. It does not, by itself, demonstrate a controlled review.
The 2024 Abridged Complaints Procedure
The 2024 ABPI Code introduced an Abridged Complaints Procedure. It allows simpler complaints to be resolved more quickly where the central facts are undisputed and a likely breach is apparent. Serious or disputed complaints continue through the full procedure.
The distinction is procedural. It does not create a lower standard of compliance for simpler cases. Nor does it allow a company to classify a materially disputed issue as simple merely because rapid closure is commercially preferable.
A complaint is more suitable for an abridged route where the factual basis is clear and the principal issue is not contested. A complaint requires the full procedure where the facts are disputed, the allegation is serious, the evidence is incomplete, or the applicable Code interpretation requires detailed adjudication.
Abridged versus full procedure
| Parameter | Abridged complaints procedure | Full complaints procedure |
|---|---|---|
| Central facts | Undisputed | Disputed, incomplete, or materially complex |
| Likely outcome | A likely breach can be identified without full Panel review | The allegation requires full consideration |
| Procedural objective | Faster resolution of a simpler matter | Formal adjudication of a serious or contested complaint |
| Evidence burden | Still requires an evidential basis | Requires detailed assessment of submissions and evidence |
| Internal response | Rapid containment and accurate factual confirmation | Controlled evidence preservation and structured defence or remediation |
| Principal risk | Misclassification of a complex issue as simple | Delay, inconsistent submissions, or uncontrolled document production |
The operational hazard is not speed. It is premature simplification.
A company that receives a complaint should first determine whether the central facts are genuinely undisputed. Agreement that a material was distributed does not mean agreement about its meaning, context, audience, substantiation, or compliance status. A dispute can exist beneath apparently simple facts.
For internal teams managing PMCPA Code of Practice complaints, the classification decision should be documented. The record should state which facts are accepted, which are disputed, and why the chosen procedure is proportionate. That record becomes part of the company’s risk history even if the complaint is resolved without a full Panel review.
The abridged route reduces procedural length. It does not reduce the requirement for factual control.
Internal audit versus external review
Internal audit and external review answer different questions.
Internal audit tests whether the company’s control system operated as designed. It can examine approval pathways, segregation of duties, training records, signatory review, vendor oversight, version control, escalation thresholds, and corrective action. It is a management tool.
External PMCPA review determines whether the evidence establishes a breach of the ABPI Code. It is an independent adjudicative mechanism within the self-regulatory system. Its jurisdiction is not displaced by an internal conclusion.
The distinction can be expressed directly:
| Control environment | Primary question | Evidence base | Result |
|---|---|---|---|
| Internal compliance review | Did the company identify, assess, escalate, and control the issue appropriately? | Company records, approvals, correspondence, training, procedures, and corrective actions | Internal finding and mitigation plan |
| PMCPA complaint process | Has a breach of the ABPI Code been established on the balance of probabilities? | Evidence submitted by the parties | Panel or procedural determination |
| External audit ordered after a breach | Are the company’s compliance procedures sufficiently controlled and effective? | Procedures, implementation records, governance, monitoring, and operational evidence | Audit findings and required remediation |
| Appeal review | Was the decision or sanction subject to proper independent review? | Case record, submissions, and appeal grounds | Appeal determination |
The phrase pharmaceutical compliance internal audit vs external counsel can also produce confusion. External legal counsel may advise the company. That does not make counsel equivalent to the PMCPA, nor does legal advice constitute an external compliance audit. Counsel supports the company’s response. The PMCPA assesses the complaint within its own procedural framework. A third-party auditor may examine the company’s procedures after a sanction. Each function has a different mandate.
What internal review can achieve
A disciplined internal review can:
1. Preserve the original promotional material and all relevant versions.
2. Identify the exact communication channel, audience, and distribution period.
3. Reconstruct the approval pathway.
4. Test the evidence supporting each challenged claim.
5. Determine whether the medical signatory reviewed the material in its final form.
6. Identify related materials with the same claim or risk profile.
7. Suspend or amend material where continued use creates avoidable exposure.
8. Prepare a coherent factual submission if the complaint proceeds externally.
9. Define corrective and preventive actions.
10. Establish whether the issue indicates isolated variance or systemic control failure.
None of these actions guarantees that the PMCPA will find no breach. They reduce uncertainty and improve the quality of the company’s response.
External oversight and the Appeal Board mechanism
The PMCPA complaint system includes external review mechanisms beyond the initial Panel process. These include independent Appeal Board oversight, referee reviews, and external audits of company procedures.
The composition of the Code of Practice Appeal Board is a material safeguard. It consists of an independent, legally qualified Chair, eight independent members, and eight industry members. The Appeal Board must sit with an independent majority of at least seven members plus the Chair.
The structure is designed to prevent industry representation from becoming the controlling influence in an appeal. The independent majority is not a symbolic feature. It is a governance threshold.
This has two consequences for pharmaceutical companies.
First, an appeal is not an opportunity to repeat an internal position without addressing the procedural and evidential basis of the decision. The response must engage with the grounds of appeal and the record supporting the original finding.
Second, the existence of industry members does not convert the process into internal peer review. The independent majority and legally qualified Chair preserve a distinct external function.
Referee reviews and procedural scrutiny
Referee reviews provide another external mechanism for examining aspects of a complaint process. The relevant issue is not whether external review is hostile to the company. The issue is whether the company’s procedural position remains defensible when tested outside its own governance structure.
Internal documentation should therefore be prepared on the assumption that the following may be examined:
- the point at which the company became aware of the complaint;
- the time taken to preserve records;
- the identity of the initial reviewer;
- conflict assessments;
- the scope of the internal review;
- the evidence used to support the company’s position;
- the handling of adverse evidence;
- the decision to continue, amend, or withdraw material;
- the approval of the final submission;
- the implementation of corrective action.
A process that cannot answer these questions has a traceability deficit. That deficit may be more significant than the original complaint, particularly where the complaint exposes repeated weaknesses.
When compliance fails: mandatory external audits
A breach of the ABPI Code can lead to sanctions ordered by the Appeal Board or the ABPI Board. These sanctions can include a mandatory external audit of the company’s compliance procedures by the PMCPA, pre-vetting of promotional material, a public reprimand, or suspension from the ABPI.
The mandatory external audit is the most direct answer to the question of internal versus external review. It confirms that the company’s own compliance assessment does not close the matter. If the external body determines that the control environment requires scrutiny, the company must submit to a review that is separate from its ordinary internal assurance activity.
An external audit may expose variance between documented procedure and operational practice. Common control failures in this category include:
- a written approval pathway that is not followed in practice;
- incomplete evidence supporting promotional claims;
- unclear accountability between medical, regulatory, compliance, and commercial functions;
- inadequate control over agency-created material;
- multiple live versions of the same promotional asset;
- insufficient monitoring after approval;
- corrective actions that address one item but not the underlying process;
- signatory review that is formal rather than substantive.
The exact audit turnaround metrics across individual companies are not uniform. No general operational benchmark should be assumed. The relevant issue is whether the company can demonstrate controlled implementation, not whether it can report a preferred completion interval.
Pre-vetting changes the risk profile
Pre-vetting of promotional material imposes an additional control layer. It also signals that the organisation’s ordinary compliance system has not been accepted as sufficient for unrestricted operation.
The consequence is operational. Launch timelines become dependent on external review. Promotional flexibility decreases. The cost of variance increases because an issue that might previously have been corrected internally can now affect the release pathway for subsequent material.
A company should not treat pre-vetting as a replacement for internal quality control. It is an external mitigation imposed in response to identified risk. If internal review becomes less rigorous because pre-vetting exists, the control environment deteriorates further.
Public reprimand and suspension from the ABPI create separate exposure. They affect the visibility and status of the compliance failure. The reputational dimension is secondary to the regulatory signal: the organisation has failed to demonstrate adequate adherence to the Code or adequate control of its compliance procedures.
The practical sequence for managing a complaint
A defensible complaint response follows a strict cause-and-effect sequence.
1. Contain the evidence
The company should preserve the challenged material in the form in which it was used. Later amendments must not overwrite the original record. Distribution data, approval records, supporting references, and correspondence should remain identifiable.
2. Define the allegation
The issue should be reduced to the specific claim or conduct under review. Broad labels such as non-compliant promotion or medical concern are insufficient for a reliable assessment.
3. Separate accepted facts from disputed facts
This determines whether an abridged procedure may be appropriate and prevents the internal team from presenting assumptions as established evidence.
4. Test conflicts and independence
The company should identify who prepared the internal assessment, who reviewed it, who approved the response, and whether any person had a relevant interest or prior involvement.
5. Assess the Code position
The assessment should address the applicable Code requirements and the evidence supporting each conclusion. Unsupported confidence has no mitigation value.
6. Determine immediate corrective action
Withdrawal, amendment, suspension, additional medical review, or communication to affected stakeholders may be appropriate. The action should be linked to the identified risk, not selected as a generic gesture.
7. Prepare for external scrutiny
The internal file should remain intelligible to a reviewer who was not involved in the original decision. If the reasoning depends on undocumented discussions or institutional memory, the control is weak.
8. Track systemic implications
The complaint may reveal a broader problem involving the same claim, product, agency, signatory process, or approval pathway. Closure of the individual complaint does not automatically close the systemic risk.
The decisive distinction
PMCPA complaint handling internal vs external review is not a choice between two competing methods. It is a sequence of controls with separate mandates.
Internal oversight establishes whether the company acted with procedural discipline. PMCPA adjudication establishes whether the evidence supports a Code breach. Appeal mechanisms test the external decision through independent governance. Mandatory external audit tests whether the company’s compliance system is capable of preventing recurrence.
The 2024 Abridged Complaints Procedure may reduce the time required for simpler, undisputed matters. It does not change the need for evidence control, conflict management, or accurate classification. The external system remains adversarial. The burden of proof remains with the complainant. A company’s internal conclusion remains only an internal conclusion.
The risk assessment is therefore definitive: a mature compliance function does not attempt to replace external oversight. It produces a record that can withstand it. A failure to separate preparation from adjudication, preserve evidence, control conflicts, or identify systemic variance increases the probability that a single complaint will become a broader examination of the organisation’s compliance architecture.