Skip to main content
Back to Blog
Regulatory Compliance9 min read

Electronic Signatures for Pharmacovigilance: What Part 11 Requires for Safety Report Sign-Off

IND and postmarketing safety reports don't name a signature requirement, but Part 11 still applies. Why the PSUR requires one and the DSUR does not.

K
Klyverity Team

Most Part 11 guidance is written around documents that move at a predictable pace: a batch record gets reviewed on a schedule, a protocol amendment gets routed for approval when it's ready. Pharmacovigilance safety reporting doesn't work that way. A serious adverse event report has a regulatory clock running from the moment someone becomes aware of it, and the sign-off has to happen inside that window, not around it.

That timing pressure is exactly where electronic signature gaps get expensive. A safety physician who can't get attributable sign-off on a case narrative fast enough, or a QPPV who can't confirm a signature was actually executed by the person named on a report, isn't just creating a data integrity problem. They're creating a missed-deadline problem on top of it. This guide covers what 21 CFR Part 11 actually requires for pharmacovigilance safety reporting electronic signatures, where the individual component and expedited reporting regulations do and don't touch signatures directly, and where a common report type, the periodic safety update report, has an explicit signature requirement that a lot of teams don't realize is that specific.

Key Takeaways

  • 21 CFR 312.32 (IND safety reporting) and 21 CFR 314.80 (postmarketing adverse drug experience reporting) set the reporting deadlines, 7 and 15 calendar days depending on the finding, but neither section itself specifies a signature requirement.
  • Part 11's general signature controls still apply the moment a safety report is created, reviewed, or approved in an electronic system: signature manifestation (11.50), signature-to-record linking (11.70), unique-per-individual credentials (11.100), and two-component authentication at signing (11.200).
  • The EU's periodic safety update report has an explicit, named signature requirement. EMA's GVP Module VII guideline states plainly that the PSUR title page "shall also contain the signature," with the Qualified Person for Pharmacovigilance responsible for designating who signs.
  • The development safety update report doesn't carry the same explicit language. ICH E2F assigns preparation and submission responsibility to the sponsor but doesn't specify a signature step the way GVP Module VII does for the PSUR.
  • Multi-party sign-off, investigator to safety physician to QPPV or sponsor delegate, is where attribution most often breaks down in practice, especially when a CRO is handling case processing on the sponsor's behalf.

The Reporting Clock Starts Before Anyone Signs Anything

21 CFR 312.32 governs IND safety reporting, and it's built around two triggers. An adverse event or suspected adverse reaction is "serious" if, in the judgment of the investigator or sponsor, it results in death, is life-threatening, requires hospitalization, causes persistent incapacity, or involves a congenital anomaly. It's "unexpected" if it isn't listed in the investigator's brochure, or differs from what's already documented there in nature, severity, or specificity.

Once a finding qualifies as both, the clock starts. A sponsor has to notify FDA and all participating investigators of a serious and unexpected suspected adverse reaction "in no case later than 15 calendar days after the sponsor determines that the information qualifies for reporting." For an unexpected fatal or life-threatening reaction, that window compresses to "no case later than 7 calendar days after the sponsor's initial receipt of the information." Neither of those deadlines is written around a signature requirement. 312.32 tells you when the report has to go out, not who has to sign it or how. That's the regulation most PV teams already know well. The part that gets missed is that the signature obligation for the report still comes from somewhere, and that somewhere is Part 11, applied to whatever electronic system is generating and routing the report.

Postmarketing Safety Reports Run on a Similar Deadline Structure

21 CFR 314.80 covers postmarketing adverse drug experience reporting for approved products, and it follows the same pattern: strict deadlines, no signature language. An applicant "must report each adverse drug experience that is both serious and unexpected, whether foreign or domestic, as soon as possible but no later than 15 calendar days from initial receipt of the information." Adverse drug experiences that don't meet the 15-day alert threshold still have to be reported, on a schedule: quarterly for the first three years after approval, then annually, with quarterly reports due within 30 days of the close of the quarter and annual reports due within 60 days of the approval anniversary.

Read next to 312.32, the pattern is consistent across the pre- and post-approval safety reporting regulations. FDA specifies the timeline and the severity threshold that triggers it. It leaves the signature and attribution mechanics of how that report gets created, reviewed, and finalized to whatever system the sponsor is using, which is where Part 11's general controls take over.

What Part 11 Actually Requires When a Safety Report Gets Signed

Once a case narrative, an aggregate report, or a submission package moves through electronic review and approval, the applicable rules are the same ones that apply to any other GxP electronic record. 21 CFR 11.50 requires that a signed electronic record contain the printed name of the signer, the date and time the signature was executed, and the meaning associated with the signature, such as review, approval, responsibility, or authorship. That last element matters specifically for PV: a safety physician's signature on a case narrative and a QPPV's signature designating a PSUR aren't the same act, and the system has to be able to show which one happened.

21 CFR 11.70 requires that the signature be linked to its record "to ensure that the signatures cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means." For a safety report that gets amended after initial submission, a common event when follow-up information arrives, that linkage has to survive the amendment without letting the original signature appear attached to content it never actually approved.

21 CFR 11.100 sets the identity side of the requirement: "each electronic signature shall be unique to one individual and shall not be reused by, or reassigned to, anyone else," and an organization has to verify identity before assigning that signature credential. 21 CFR 11.200 adds the mechanics at the moment of signing, requiring "at least two distinct identification components such as an identification code and password" for a non-biometric signature, with a tighter rule for signing sessions that aren't continuous. And 21 CFR 11.10(e) and (g) round it out at the system level: a secure, computer-generated, time-stamped audit trail that independently records who created, modified, or deleted a record, and authority checks that limit who can sign at all. None of this is PV-specific. It's the same Part 11 backbone covered in our guide on electronic signature audit trail requirements. What's specific to PV is how fast these controls have to hold up under a reporting deadline that doesn't pause for a signature workflow to catch up.

The PSUR Has an Explicit Signature Requirement. The DSUR Doesn't.

This is where the two major periodic safety report formats diverge in a way that's easy to miss if you're only working from summaries. The periodic safety update report, governed in the EU by EMA's Guideline on Good Pharmacovigilance Practices, Module VII (EMA/816292/2011 Rev 1), states directly: "The title page shall also contain the signature." It also specifies who decides who signs: "it is at the discretion of the QPPV to determine the most appropriate person to sign the document according to the marketing authorisation holder structure and responsibilities. A statement confirming the designation by the QPPV should be included." The same guideline assigns the Qualified Person for Pharmacovigilance broader ownership of the report, stating the QPPV "shall be responsible for the establishment and maintenance of the pharmacovigilance system" and lists PSUR-specific duties including ensuring the quality, correctness, and completeness of the data submitted.

The development safety update report, governed by ICH E2F, is built differently. The guideline states plainly that "the sponsor of a clinical trial is considered responsible for the preparation, content and submission of a DSUR," and that the sponsor "can delegate the preparation of the DSUR to a third party (e.g., a contract research organisation)." That's a clear responsibility assignment. What it isn't is a signature mandate. ICH E2F doesn't contain language requiring a named signature on the DSUR the way GVP Module VII does for the PSUR title page.

That difference doesn't mean a DSUR should go out unsigned in practice. Most sponsors apply their own internal Part 11 controls, the same 11.50/11.70/11.100 requirements covered above, to a DSUR's review and approval regardless of what the ICH guideline itself mandates. But it does mean the compliance argument for DSUR sign-off rests on the sponsor's own quality system and Part 11 obligations as an electronic-records controller, not on an explicit signature clause in the ICH text the way it does for a PSUR under GVP Module VII. Confusing the two is an easy way to answer an inspector's question about who signed a DSUR with a citation that doesn't actually say what you think it says.

Where Multi-Party Sign-Off Chains Break

Safety reporting rarely involves one signer. A typical chain runs from the investigator or reporter who first identifies the event, through a safety physician who assesses seriousness and causality, to a QPPV or sponsor-designated signer who takes final responsibility for the report going out the door. When a CRO is handling case processing under a services agreement, that chain crosses a company boundary the same way it does for the clinical trial signature chains we cover in our guide on electronic signatures for CROs. The CRO's case processor signs off on the initial assessment; the sponsor's safety team or QPPV still has to sign off on the report that actually gets submitted.

The break usually isn't a missing signature. It's an unverifiable one. A safety report that moves from a CRO's case management system into a sponsor's regulatory submission platform as a static PDF carries the appearance of a signature without carrying the signature-to-record link, the audit trail, or the identity verification that produced it. If the receiving system can't independently confirm who signed, when, and under what authenticated session, the sponsor is relying on a signature it can't actually stand behind if FDA or EMA asks. A sponsor that needs to certify its own electronic signatures as legally binding under 21 CFR 11.100(c), the certification we cover in our guide on the Part 11 non-repudiation letter, can't extend that certification to a signature it never actually verified.

What a Compliant PV Signature Workflow Needs

Given the deadline pressure and the multi-party structure, a pharmacovigilance sign-off workflow should be able to show, for any safety report:

  • Who signed, with a printed name, timestamp, and stated meaning of the signature (review, approval, or authorship) captured per 21 CFR 11.50.
  • That the signature is unique to that individual and was executed under two-component authentication at the time of signing, per 11.100 and 11.200.
  • A signature-to-record link that survives any subsequent amendment, so a follow-up update to a case narrative can't be mistaken for something the original signer approved.
  • For a PSUR, a documented statement of QPPV designation naming who is authorized to sign on the QPPV's behalf, since GVP Module VII explicitly requires that designation to be recorded, not assumed.
  • For any report processed in whole or in part by a CRO, a verifiable chain from the CRO's signing system into the sponsor's, not a flattened PDF that drops the underlying signature metadata.
  • An audit trail that can reconstruct the full sequence, from initial case identification through final sign-off, fast enough to support the 7- or 15-day reporting window without the review step becoming the bottleneck.

None of that is a special PV-only standard. It's the same attribution and audit trail discipline that applies across GxP electronic records, applied to a report type where the deadline doesn't leave room for a signature gap to get quietly fixed later. Klyverity's signing architecture captures the printed name, timestamp, and signature meaning on every safety report signature, links each signature to its record so a later amendment can't be mistaken for the original approval, and preserves the full chain when a report moves between a CRO's system and a sponsor's. If your PV sign-off process needs to hold up under both a regulatory deadline and an inspection, request a demo to see how attribution works across a multi-party safety reporting workflow.

FAQ

Does 21 CFR Part 11 apply to pharmacovigilance safety reports?

Yes. 312.32 and 314.80 set the reporting deadlines and severity thresholds for safety reporting, but neither section specifies signature requirements. Once a safety report is created, reviewed, or approved in an electronic system, Part 11's general signature controls, including 11.50, 11.70, 11.100, and 11.200, apply the same way they do to any other electronic GxP record.

Does the PSUR require a specific signature?

Yes. EMA's GVP Module VII guideline (EMA/816292/2011 Rev 1) states that the PSUR title page "shall also contain the signature," and that the Qualified Person for Pharmacovigilance determines who is authorized to sign on the marketing authorisation holder's behalf, with that designation documented in the report.

Does the DSUR have the same signature requirement as the PSUR?

Not according to the ICH E2F guideline text itself. E2F assigns responsibility for preparation, content, and submission to the sponsor and allows delegation to a CRO, but it doesn't include a named signature requirement the way GVP Module VII does for the PSUR. Sponsors typically still apply their own Part 11 sign-off controls to a DSUR, but that's a sponsor-level quality decision, not an explicit requirement in the ICH text.

How does CRO involvement affect safety report signature attribution?

When a CRO handles case processing, the signature chain crosses a company boundary. The risk isn't usually a missing signature, it's a signature that can't be independently verified once the record moves from the CRO's system into the sponsor's, especially if it arrives as a flattened document without the underlying signature-to-record link and audit trail intact.

Ready for Compliant E-Signatures?

Start your free trial and see how Klyverity meets compliance requirements for your regulated industry.