Written and maintained by CASRAI Editorial Board
Last updated
What GVP Module VI covers
GVP (Good Pharmacovigilance Practices) is the European Medicines Agency’s module-based implementation of the EU’s pharmacovigilance legislation. Module VI — formally "Collection, management and submission of reports of suspected adverse reactions to medicinal products" — is the module that governs the individual case safety report (ICSR): what makes a single adverse-reaction report valid, how it is collected, and the deadlines for getting it into EudraVigilance. The current text is Revision 2, legally effective 22 November 2017, with two supplementary addenda since: Addendum I (2017) on duplicate detection and management, and Addendum II (2025) on personal-data masking in submitted reports.
Module VI sits in a specific place in the GVP framework, and it is worth being precise about what it does not cover, because the three topics get conflated constantly:
- Not the periodic aggregate report. The recurring safety summary covering many cases over a reporting interval is the PSUR/PBRER, built to ICH E2C(R2) — a completely different document, cadence, and regulatory purpose. Module VI is about the single case, not the rolled-up summary.
- Not EudraVigilance system mechanics. How to register, which submission channel to use (EVWEB versus gateway), and how the post-audit reporting rules and the EMA’s duplicate-detection/Medical Literature Monitoring (MLM) services work at the database level is EudraVigilance operations territory, not Module VI’s content. Module VI defines what a valid, complete ICSR looks like and when it is due; EudraVigilance is where it lands.
- Not the EU pharmacovigilance system as a whole. The organisational and quality-system requirements around who runs pharmacovigilance for a marketing authorisation holder (MAH) sit in the PSMF (GVP Module II) and the QPPV role (GVP Module I). Module VI assumes that system exists and tells it how to handle one case report correctly.
Module VI is also the EU’s regional layer on top of the internationally harmonised ICH E2 base: it states explicitly that its ICSR collection, recording, and submission approach is built on ICH E2A/E2B/E2D principles, then adds EU-specific obligations (EudraVigilance submission, specific EU timeframes, EU-specific special-situation handling) that ICH E2 compliance alone does not satisfy. A company that is fully ICH E2-compliant for FDA purposes is not automatically Module VI-compliant for EU purposes — the reporting destination and some of the deadlines differ.
ICSR validity: the four minimum criteria
Before Module VI’s timelines apply to a report at all, the report has to clear a validity threshold. A case is a valid ICSR only when all four of the following are present:
- An identifiable reporter — a person who can, in principle, be contacted to confirm or follow up on the information (a healthcare professional, a patient, a caregiver, a lawyer, or another identifiable source).
- An identifiable patient — enough to distinguish this individual case from another (initials, age or age group, sex, or a case reference are typically sufficient; the patient need not be named).
- At least one suspect medicinal product — the product the reporter associates with the reaction.
- At least one suspected adverse reaction — an untoward and unintended response to the product, described in enough detail to be assessed.
All four must be present for the case to be reportable under Module VI’s timeframes. Missing one of the four means the case is followed up for completeness rather than clocked and submitted as a valid ICSR on day one — which is itself a data-quality obligation Module VI places on the MAH: reasonable follow-up effort to close information gaps, not simply discarding an incomplete report.
Solicited versus spontaneous reports
Module VI draws a hard line between two report origins, because it changes how causality is treated downstream:
- Spontaneous reports arise unprompted — a healthcare professional or patient contacts the MAH, a regulator, or another organisation on their own initiative to describe a suspected reaction. Spontaneous reports carry an inherent implication of causality from the reporter and are the backbone of post-marketing signal detection.
- Solicited reports come from an organised data-collection system: patient support programmes, disease-management or market-research programmes, post-authorisation safety studies, registries, and similar structured mechanisms where the company is actively soliciting outcome information rather than waiting for it to arrive unprompted. Solicited reports still require a causality assessment before submission — unlike a spontaneous report, causality is not simply assumed from the fact of the reporter’s contact, because the collection method itself invites reporting regardless of suspected relatedness.
Getting this classification right at intake matters because it affects both the validity assessment and how the case reads once it reaches signal management — misclassifying a solicited case as spontaneous overstates its evidentiary weight in aggregate analysis.
Literature monitoring obligations
Module VI requires MAHs to monitor published medical literature for reports of suspected adverse reactions to their products, on top of monitoring their own direct-contact channels. For a defined list of active substances, the EMA’s Medical Literature Monitoring (MLM) service screens a set of literature databases centrally and makes relevant articles available to MAHs, which relieves those specific companies of duplicating that particular database search themselves — but MLM does not cover every active substance or every literature source, so an MAH still needs its own literature-monitoring process for anything MLM does not screen, and still needs to document its search strategy, screening criteria, and the "day zero" determination (the date the MAH becomes aware of a valid case) for whatever it does find. Day zero is the anchor date the Module VI timeframes below are measured from, so a documented, defensible day-zero determination is itself part of the compliance record an inspector will ask to see.
Special reporting situations
Module VI sets out handling rules for several case categories that do not fit the standard adverse-reaction pattern cleanly:
- Pregnancy exposure. Reports of exposure during pregnancy (with or without an adverse outcome) are collected and followed up through to outcome where possible — a report of exposure alone, with no adverse outcome yet known, is still tracked, since the outcome (including a normal birth) is itself safety-relevant information.
- Overdose, misuse, abuse, and medication error. These are reportable regardless of whether an adverse reaction resulted, because the pattern itself is a safety signal independent of any single case’s outcome.
- Off-label use. A suspected adverse reaction occurring during use outside the authorised terms (indication, dose, route, population) is still reportable and is specifically flagged as off-label, since it feeds both product-specific signal detection and, in aggregate, informs whether the authorised label needs to change.
- Lack of efficacy. Reports of a product simply not working are reportable for certain product categories — vaccines and other products where lack of efficacy has direct public-health consequences are treated with particular attention, and Module VI expects these to be assessed for possible expedited reporting in specific circumstances rather than folded silently into routine periodic reporting.
Each of these categories carries its own nuance for what counts as "serious" and therefore which timeframe below applies — an overdose with no adverse outcome is handled differently from an overdose that also meets seriousness criteria, for instance — so classification at intake needs to capture the special-situation flag alongside the standard seriousness assessment, not as an afterthought.
Reporting timeframes
Once a case clears the validity threshold above, Module VI sets two clocks, both measured from day zero (the date the MAH first becomes aware of the minimum information needed for a valid case):
- 15 calendar days for suspected serious adverse reactions.
- 90 calendar days for suspected non-serious adverse reactions.
Both clocks apply to submission into EudraVigilance. Meaningful new follow-up information on a case already submitted restarts the relevant clock for that follow-up — a case is not "done" once the initial report goes in if further clinically relevant information later becomes available. This structure mirrors the seriousness-based tiering that runs through the wider ICH E2 framework (the same 15-day standard appears for expedited SUSAR reporting in the clinical-trial context), but the 90-day non-serious deadline and the destination (EudraVigilance specifically) are the EU post-authorisation-specific pieces Module VI adds rather than inherits directly from ICH E2A.
Data quality and duplicate management
Module VI treats data quality as an ongoing obligation, not a one-time intake check. Addendum I (2017) sets out the MAH’s duplicate-detection and duplicate-management responsibilities — the same underlying case can arrive through more than one channel (a direct patient report and a literature article describing the same event, for example), and submitting it twice as though it were two separate cases distorts signal-detection statistics downstream. Addendum II (2025) addresses masking of personal data within submitted ICSRs, reflecting that EudraVigilance access extends to parties beyond the immediate reporting chain and that case reports routinely contain identifiable patient and reporter information that needs handling consistent with data-protection obligations even as the case itself remains fully traceable for pharmacovigilance purposes.
Practically, this means an ICSR management process needs a defined intake-to-submission workflow covering: case receipt and triage, the validity check against the four minimum criteria, causality assessment for solicited cases, seriousness and special-situation classification, duplicate search against existing cases, medical review, coding (typically to MedDRA), submission within the applicable clock, and a mechanism for capturing and re-clocking follow-up information. Each step is auditable, and each is exactly what an inspector reviewing ICSR management against Module VI will walk through.
Frequently asked questions
What is the difference between GVP Module VI and a PSUR/PBRER?
Module VI governs the individual case — how one suspected adverse reaction report is validated, classified, and submitted to EudraVigilance, and on what timeline. The PSUR/PBRER, built to ICH E2C(R2), is a periodic aggregate report that rolls up accumulated safety data across a defined interval into a benefit-risk evaluation. A well-run ICSR process under Module VI is one of the data sources a PSUR/PBRER later draws on, but the two are different documents with different triggers, cadences, and content requirements.
Does meeting ICH E2B mean a company is Module VI-compliant?
Not on its own. ICH E2B defines the electronic data-element and message standard an ICSR is transmitted in, and Module VI’s collection and submission approach is explicitly built on ICH E2A/E2B/E2D principles — but Module VI then layers EU-specific requirements on top: submission to EudraVigilance specifically, the EU’s own 15-day/90-day timeframes, and EU-specific special-situation and duplicate-management rules that ICH E2 compliance alone does not establish.
Are all pregnancy-exposure reports reportable under Module VI, even with no adverse outcome yet?
Yes. Exposure during pregnancy is collected and followed up through to outcome regardless of whether an adverse outcome has occurred or is even suspected at the time of the initial report, because the eventual outcome itself is safety-relevant information the module expects to be captured.
What happens if a case is missing one of the four validity criteria?
It is not treated as a submittable ICSR until the gap is addressed. The expectation under Module VI is reasonable follow-up effort to obtain the missing element (most often trying to make the reporter identifiable or obtaining a minimally identifiable patient reference) rather than either discarding the report outright or submitting it as though it met the minimum criteria when it does not.
This guide covers GVP Module VI (ICSR collection, validation, and EudraVigilance reporting timelines) specifically. For the periodic aggregate safety report built from accumulated case data, see PSUR and PBRER Format. For the EU pharmacovigilance system’s organisational backbone, see the PSMF and the QPPV role. For the foundational AE/SAE/SUSAR definitions this module builds on, see Pharmacovigilance in Clinical Research.








