
The most expensive PSUR mistake is rarely a dramatic scientific failure. More often, it is a calendar failure dressed up as an administrative inconvenience: the wrong Data Lock Point, an outdated EURD list entry, a submission routed through the wrong channel, or a team that discovers the 70-day deadline only after the internal review cycle has consumed half of it.
That is the less glamorous reality of the PSUR submission strategy for EURD list alignment. The EURD list is not a planning suggestion, and it is not a useful reference document to consult when someone remembers it exists. For Marketing Authorisation Holders, it is a legally binding framework that determines reference dates, reporting frequency and Data Lock Points across the European Union. Local marketing authorisations do not get to improvise around it.
I have watched organisations build elaborate pharmacovigilance operating models and then leave one monthly EMA update sitting unread in a shared mailbox. The optics are reassuring right up until the regulatory clock starts running.
The EURD list is the schedule — not a background document
The European Union Reference Dates list establishes the operational rhythm for PSURs covering active substances in the EU. It sets:
- the EU reference date;
- the frequency of PSUR submissions;
- the relevant Data Lock Point;
- the timetable that applies across products containing the same active substance or combination.
Where an active substance appears on the EURD list, that schedule overrides any standard PSUR timetable stated in a local marketing authorisation. This is the first point at which many otherwise competent systems begin to wobble. A local licence may contain a familiar periodic reporting obligation, but the EURD list governs the EU-level schedule where its entry applies. Regulatory memory is not a control mechanism; it is merely how organisations end up arguing about which spreadsheet was current.
The European Medicines Agency updates the EURD list monthly following adoption by the CHMP and CMDh. Changes to PSUR frequencies or submission dates take effect six months after publication. That lead time is helpful, but only if someone actively monitors the changes, assesses their impact and updates the operating plan. Six months sounds generous in a board presentation. In a multi-product portfolio with several active substances, shared safety teams, outsourced case processing and overlapping PSUSA procedures, it becomes a surprisingly short period.
A functioning EURD list governance process should answer four practical questions every month:
1. Which active substances in the portfolio appear on the current EURD list?
The answer should cover the entire EU portfolio, not merely products managed by the central safety team.
2. Have any reference dates, DLPs or reporting frequencies changed?
A change may affect future planning rather than the next immediate report, but it still belongs in the controlled regulatory calendar.
3. Which products, licences and internal teams are affected?
The impact assessment should connect the active substance to actual products, licence holders, affiliates, vendors and submission responsibilities.
4. Who approved the resulting action?
Monitoring without documented ownership is just regulatory theatre with better formatting.
The EURD list Data Lock Point synchronization exercise should therefore sit inside the pharmacovigilance quality system. It should not depend on an individual regulatory affairs specialist remembering to forward an email before a holiday.
The EURD list is not a forecast. It is the legal clock; your internal plan is merely the attempt to keep up.
Build the calendar around the DLP, not around the submission date
A PSUR calendar often begins with a submission deadline because that is the date everyone can see. That is backwards. The Data Lock Point comes first, and the submission window follows from the length of the reporting interval.
For reporting intervals of 12 months or less, the PSUR must be submitted within 70 calendar days of the DLP. For intervals longer than 12 months, the submission window is 90 calendar days. These are calendar days, not working days conveniently converted into whatever the project plan would prefer.
That distinction changes the preparation model. A report with a 12-month interval does not offer a comfortable ten-week drafting cycle in any meaningful operational sense. The clock begins at the DLP, while the work required to produce a defensible report begins much earlier: case reconciliation, data extraction, signal review, exposure assessment, literature surveillance, cumulative analysis, benefit–risk evaluation, authoring, medical review, quality control, affiliate input and final technical submission.
The DLP is therefore a fixed anchor around which the entire PSUR production cycle should be designed. A practical calendar will include, at minimum:
- a confirmed DLP and reporting interval;
- an agreed data extraction plan;
- cut-off dates for case and source-data reconciliation;
- timelines for signal detection and signal evaluation;
- a defined period for medical and cross-functional review;
- document finalisation and quality control;
- XML delivery-file preparation;
- repository submission testing and confirmation;
- contingency time for technical rejection or a material late change.
The last item is where corporate optimism tends to enter the room. Teams often plan to the deadline, then describe the remaining hours as contingency. That is not contingency; it is unallocated risk. A technical issue in the submission package, an unexpected inconsistency between tables, or a late safety interpretation can consume the remaining margin without asking permission.
PSUR preparation is an evidence chain, not a writing assignment
The periodic safety update report preparation steps are sometimes described as if the central task were drafting nineteen standardised sections. The ICH E2C(R2) / PBRER format does contain 19 standardised sections, but the presence of a template does not create an analysis. It only creates more places for weak analysis to become visible.
The quality of a PSUR depends on whether its conclusions can be traced through a coherent evidence chain:
- the data are complete enough for the intended analysis;
- the reporting period is clearly defined;
- cases and sources have been reconciled;
- signals have been evaluated in context;
- exposure assumptions are stated and proportionate;
- important changes in the safety profile are distinguished from routine noise;
- the benefit–risk assessment reflects the evidence rather than the preferred corporate narrative.
This is where medical affairs and pharmacovigilance should stop pretending they are adjacent departments that exchange documents at the end. The PSUR is not a compliance parcel passed from safety to medical review. It is a cross-functional assessment of whether the product’s known and emerging risks remain compatible with its benefits.
A strong preparation model begins with a scope map. For each active substance or combination governed by the EURD list, the MAH should know which products fall into the assessment, which reporting period applies and whether any regulatory or safety developments require specific treatment. The map should remain intelligible to someone who did not build it. If the logic depends on a single expert’s memory of historical licence transfers, it is not a robust process; it is an echo chamber with a succession plan problem.
Reconcile before you interpret
Signal detection performed on unstable data creates a familiar kind of false confidence. The analysis looks sophisticated because the charts are polished, while the underlying case population remains unresolved.
Before the medical narrative takes shape, the team should reconcile the datasets that feed the report. That includes the individual case safety report population, serious and non-serious cases, cases from spontaneous and solicited sources, product exposure information, literature findings and relevant post-authorisation data. The exact data sources will vary by product and programme, but the governing principle does not: interpretation should follow reconciliation, not substitute for it.
A useful internal review asks:
- Does the case count align across the report sections and appendices?
- Are duplicate cases or follow-up reports handled consistently?
- Do the reporting period and cumulative period use the same product scope?
- Are relevant indications, populations and routes of administration represented?
- Can the team explain material changes from the previous PSUR without resorting to vague references to data refreshes?
- Does the signal discussion distinguish a new signal from a known risk receiving additional evidence?
The final question matters more than the language used to describe it. A known risk may become more clinically significant because of a change in frequency, severity, affected population, reversibility or management requirements. Conversely, a numerical increase in reports may reflect increased exposure, greater reporting activity or a change in case ascertainment rather than a new causal concern. The report must show that the team understands the difference.
The 70-day and 90-day windows require a controlled production line
The 70-day submission window for reporting intervals up to 12 months and the 90-day window for longer intervals are often treated as regulatory deadlines in isolation. They are better understood as the final segment of a production line. If every upstream activity waits for the DLP, the deadline becomes an exercise in managed panic.
A controlled PSUR workflow separates activities that require final data from activities that can be prepared in advance. The report cannot be finalised before the DLP, but its architecture, evidence plan, responsibilities, data specifications and review pathway can be agreed earlier. Waiting for the DLP to decide who owns which section is not caution. It is poor choreography.
I would structure the work in five linked phases.
1. Lock the regulatory scope
Confirm the applicable EURD list entry, active substance, reporting frequency, DLP and submission window. Resolve product and licence scope before authoring begins. If a product is excluded from the EURD list, do not casually transfer assumptions from another product or active substance; the applicable national guidance and schedule require separate confirmation.
2. Prepare the data environment
Set the extraction specifications, reconcile relevant sources and establish how exposure, cases, literature and risk-management information will feed the report. The point is not to create another procedural document that nobody reads. The point is to make sure the author receives a stable evidence package rather than a succession of incompatible exports.
3. Run the safety evaluation
Assess new information against the established safety profile. Review signals, important risks, missing information, regulatory actions and relevant changes in clinical practice. The evaluation should lead to a defensible benefit–risk conclusion, not merely a catalogue of events.
4. Conduct integrated review
Medical, safety, regulatory and quality reviewers should work from the same controlled version. Affiliate and vendor input should arrive according to a defined timetable. Late comments should trigger a documented impact assessment rather than disappearing into the document as unexplained edits.
5. Finalise and submit through the required channel
The final package needs both content control and technical control. A report can be medically sound and still fail operationally if its delivery file is incomplete, the repository submission is mishandled or the package does not meet the current submission requirements.
This sequence is not revolutionary. That is precisely why it is useful. Pharmacovigilance programmes do not usually fail because nobody has heard of planning. They fail because planning remains a slogan while ownership, deadlines and escalation routes remain ambiguous.
A PSUR deadline cannot be rescued by heroic authoring. Once the DLP arrives, preparation has already become execution.
The PSUSA procedure changes the meaning of “our product”
PSURs governed by the EURD list enter the Single Assessment procedure, known as PSUSA. The procedure enables a harmonised benefit–risk evaluation across EU Member States for products containing the same active substance or combination.
That harmonisation is operationally significant. The MAH is not preparing a report for a series of disconnected national conversations. The assessment has an EU-wide frame, and the submission needs to support a coherent understanding of the active substance across the relevant products and Member States.
This is where fragmented product ownership becomes visible. One affiliate may describe a risk-management action differently from another. One product team may use a different indication label or exposure denominator. A vendor may deliver a case overview that does not map cleanly to the central safety database. Each discrepancy can look minor when viewed locally. In a PSUSA context, the collection of minor discrepancies creates avoidable friction and weakens confidence in the assessment.
The PSUR single assessment procedure workflow should therefore include a deliberate alignment review before submission. The goal is not to manufacture artificial uniformity. Genuine differences between products, indications or populations may matter. The goal is to distinguish meaningful clinical differences from inconsistent internal language.
A practical alignment review examines:
- the active substance and combination scope;
- product presentations and relevant indications;
- the relationship between cumulative and interval data;
- the description of important identified and potential risks;
- risk-minimisation measures and their implementation;
- missing information and ongoing studies;
- the interpretation of signals across the portfolio;
- the proposed benefit–risk conclusion.
The conclusion should remain clinically intelligible. A PSUR that lists every development but never explains its effect on the benefit–risk balance has complied with the shape of the process while avoiding its purpose. Regulators do not need another inventory of corporate activity. They need a reasoned assessment of whether the safety profile has changed and what should follow.
Use the repository as a controlled submission system
Since 13 June 2016, MAHs have been required to use the central EMA PSUR Repository for EU PSUR submissions. The submission route operates through the eSubmission Gateway or Web Client with an XML delivery file. For PSURs governed by the EURD list, submitting directly to individual National Competent Authorities by email or local portal is not the correct route.
This sounds straightforward until technical ownership is examined. Who prepares the delivery file? Who validates the package? Who has access to the Gateway or Web Client? Who confirms successful transmission? Who responds if the package is rejected? Who retains the evidence of submission? If the answer to any of these questions is simply “regulatory operations,” the process may be under-specified.
The repository workflow should have a named operational owner and a named deputy. It should also include a pre-submission verification that covers:
- the correct active substance and procedure context;
- the appropriate reporting interval and DLP;
- the final approved PSUR package;
- the XML delivery file;
- document naming and technical requirements;
- user access and authorisation;
- confirmation of successful submission;
- retention of the submission record and relevant correspondence.
The repository is not a mailbox with a more expensive interface. It is part of the regulatory control environment. A submission confirmation should be treated as evidence that the package entered the system, not as an invitation to stop thinking about it. Internal records should preserve the version submitted, the timing, the delivery details and any subsequent technical communication.
New submission expectations should reach the SOP before they reach the crisis meeting
The operational environment continues to evolve. The fact base for this planning cycle includes a requirement, effective 16 April 2025, to provide Word versions of PSURs and RSI responses. Whether a team experiences that requirement as a minor document-format adjustment or an avoidable scramble depends on how early the change reaches its procedures, templates and technical checks.
This is the unremarkable work that prevents dramatic work later. Regulatory intelligence should flow into controlled documents, submission checklists, vendor statements of work, authoring templates and training. A monthly EURD list review without a corresponding change-management process is only half a system.
The same applies to the relationship between the EURD list and wider global reporting obligations. The EU schedule should not be assumed to align automatically with FDA periodic reporting under 21 CFR 314.80 or with other jurisdiction-specific requirements. A single global safety calendar may be convenient for portfolio management, but convenience is not evidence of regulatory equivalence. The MAH needs jurisdiction-specific planning where the obligations diverge.
A sensible global model can still coordinate work around a common data cut-off strategy, shared signal review and an integrated benefit–risk narrative. It cannot erase different legal schedules by placing them in the same project tracker. Alignment is useful; false alignment is how deadlines acquire legal consequences.
Where governance tends to fail
In practice, recurring failures usually cluster around a few familiar habits:
- treating the EURD list as a static document rather than a monthly regulatory input;
- allowing local authorisation schedules to compete with the binding EURD schedule;
- calculating the 70-day or 90-day window from an internal milestone rather than the DLP;
- assuming a short reporting interval creates a simple report;
- beginning medical review only after the full draft exists;
- treating PSUSA as a submission event rather than a harmonised EU assessment;
- leaving repository access and XML delivery responsibility to the final week;
- copying the previous PSUR’s benefit–risk language forward without testing whether the evidence still supports it;
- allowing a vendor or affiliate to own a critical activity without an explicit escalation path;
- confusing a successful transmission with a completed quality process.
None of these failures requires bad intent. They are usually products of distributed accountability, optimistic project plans and the belief that regulatory work becomes safer when more people are copied on an email. It does not. It becomes safer when decisions, ownership and evidence are visible.
What an MAH should do next
A practical PSUR submission strategy for EURD list alignment begins with a small number of non-negotiable controls:
1. Create a controlled monthly EURD list review.
Record the current list, identify changes and document their effect on active substances, products, DLPs and frequencies.
2. Anchor every PSUR plan to the DLP.
Calculate the applicable 70-day or 90-day submission window from the DLP, then work backwards through data, analysis, review and technical submission.
3. Separate regulatory scope from authoring convenience.
Confirm which products and active substances belong in the assessment. Do not allow a familiar template or inherited calendar to decide the scope.
4. Reconcile evidence before drafting conclusions.
Case counts, exposure information, signal evaluations and risk-management data need a traceable relationship. A fluent narrative cannot repair an unstable dataset.
5. Align the portfolio before PSUSA.
Identify genuine product differences, correct accidental inconsistencies and ensure the benefit–risk assessment speaks clearly across the relevant EU context.
6. Make repository submission a governed activity.
Assign primary and backup owners for the eSubmission Gateway or Web Client, XML delivery file, technical validation and submission evidence.
7. Feed new requirements into the operating model.
The Word-version requirement for PSURs and RSI responses is a reminder that submission standards change. Procedures, templates and vendor controls must change with them.
The status quo usually survives because it is familiar, not because it is defensible. Monthly EURD monitoring, DLP-based planning and disciplined repository submission are not glamorous. They are also considerably more reliable than discovering a compliance gap through a regulator’s question.
The sharpest PSUR strategy is therefore not the one with the most elaborate dashboard or the most enthusiastic alignment language. It is the one that knows exactly which clock applies, which evidence supports the conclusion and who owns the next action — before the deadline starts counting.