Automated assembly of the periodic aggregate drug safety report — from data lock point through disproportionality signal detection to eCTD submission
The Periodic Benefit-Risk Evaluation Report (PBRER, the ICH E2C(R2) format that superseded the older PSUR) begins with a Data Lock Point (DLP): a fixed cutoff date, anchored to the product's International Birth Date (IBD), before which every case is in scope and after which nothing is. Spontaneous reports, literature, clinical trials, and registries are merged and deduplicated into a single ICSR pool before any medical or statistical review starts.
A DLP is not a soft cutoff — it is a contractual and regulatory boundary that determines what evidence a PBRER is legally required to reflect:
Sources merged at DLP: • Spontaneous ICSRs from company safety database (Argus, ArisGlobal LSMV) filed via E2B(R3) XML • Regulatory-received reports pulled back from FAERS (FDA), EudraVigilance/EVDAS (EMA), and other national databases • Published and unpublished literature hits from a validated Embase/MEDLINE search strategy re-run every interval • Serious adverse events (SAEs) from all ongoing company-sponsored and investigator-sponsored trials, reconciled against the DSUR (Development Safety Update Report) dataset • Patient registries, compassionate-use/named-patient programs, and non-interventional study safety data
Deduplication logic: • A composite fingerprint (patient identifiers or surrogate, event onset date, suspect drug, reporter) is used to collapse duplicate ICSRs arriving through more than one channel — e.g. a case reported to both the company and directly to a health authority • Industry duplicate rates typically run 3-6% of raw incoming case volume before reconciliation • Follow-up information received after the DLP but before report finalization is captured in a designated "late-breaking" addendum only if it materially changes the benefit-risk conclusion
International Birth Date (IBD) governs the reporting clock: 6-month intervals for the first 2 years after first global authorization, annual for the following 2 years, then aligned to the EU Union Reference Date (URD) list — typically every 3 years — unless PRAC imposes an ad hoc frequency.
A mid-size biologic with a 6-year-old IBD moving from annual to URD-aligned triennial reporting can see its single PBRER interval span >28,000 aggregated ICSRs pulled from FAERS, EudraVigilance, VigiBase, and 40+ national competent authority feeds — all reconciled to one dataset before a single disproportionality statistic is run.
Every ICSR entering the aggregate dataset is structured to the ICH E2B(R3) HL7-based XML schema, regardless of originating source:
• Message header (A.1): safety report identifier, report type, receipt/transmission dates • Patient characteristics (B.1): age, sex, weight, relevant medical history coded to MedDRA • Reaction/event (B.2): verbatim term mapped to a MedDRA Lowest Level Term (LLT), rolled to Preferred Term (PT), outcome, seriousness criteria (death, life-threatening, hospitalization, disability, congenital anomaly, other medically important) • Drug information (B.4): suspect vs. concomitant, dose, indication, action taken, dechallenge/rechallenge result • Narrative (B.5): free-text case summary used for medical review
MedDRA itself is a five-level hierarchy (SOC > HLGT > HLT > PT > LLT) containing roughly 24,000 Preferred Terms, versioned twice yearly (March and September); a PBRER must state which MedDRA version was used for coding so downstream disproportionality comparisons are apples-to-apples across reporting intervals.
Once the aggregate case pool is locked, every MedDRA Preferred Term is screened for a reporting-rate imbalance relative to the drug's overall reporting pattern (or, for regulator-side systems, relative to the entire database). No single statistic is authoritative — GVP Module IX and FDA practice both rely on a convergence of frequentist and Bayesian disproportionality methods before a term is escalated to formal signal status.
Proportional Reporting Ratio (PRR): PRR = [a/(a+b)] / [c/(c+d)], where a = reports of the event with the drug, b = other events with the drug, c = the event with all other drugs, d = other events with all other drugs. Signal criteria (Evans): PRR≥2, χ²≥4, and n≥3 cases — the "rule of three" that prevents single-case noise from triggering a statistical alarm.
Reporting Odds Ratio (ROR): ROR = (a×d)/(b×c). Behaves similarly to PRR at low background rates and is the preferred metric in EudraVigilance/EVDAS screening because its confidence interval has better statistical properties for rare events.
Empirical Bayes Geometric Mean (EBGM) via Multi-item Gamma Poisson Shrinker (MGPS): Used operationally by FDA on FAERS. Applies Bayesian shrinkage to pull noisy small-count ratios toward 1, reducing false positives from low-volume drug-event pairs. The lower bound of the 90% CI (EB05) ≥2 is the conventional escalation threshold.
Information Component (IC) via Bayesian Confidence Propagation Neural Network (BCPNN): IC = log2[ P(drug,event) / (P(drug)×P(event)) ]. This is the method underpinning WHO-UMC's vigiRank and VigiBase screening across 150+ national pharmacovigilance centers. A lower 95% credibility bound IC025 > 0 flags a statistically robust disproportionality independent of database size.
None of these four statistics establishes causality on its own — they only establish that a drug-event pair is reported more often than chance would predict. GVP Module IX explicitly requires triangulation: a PT must clear at least two independent methods and pass clinical plausibility review (biological mechanism, temporal relationship, dechallenge/rechallenge pattern, and absence of confounding by indication) before it is logged as a validated signal in the signal management tracking tool.
Disproportionality output feeds a triage funnel, not an automatic conclusion:
1. Statistical screen: ~1,100 MedDRA PTs with ≥3 cases in the interval dataset are run through PRR/ROR/EBGM/IC; typically 25-35 clear at least one threshold 2. Clinical plausibility review: a pharmacovigilance physician reviews case narratives for each flagged PT — assessing seriousness, positive dechallenge/rechallenge, alternative etiology, and consistency with known pharmacology 3. Signal validation: roughly a third to half of statistically flagged PTs survive clinical review and are logged as a "validated signal" requiring further evaluation (about 8-10 per interval is typical for an established product) 4. Signal prioritization: validated signals are scored by seriousness, strength of evidence, and public health impact (WHO-UMC and EMA both publish prioritization matrices) to sequence which get a full evaluation first 5. Signal closure or escalation: each validated signal is closed with "no further action," downgraded to routine monitoring, or escalated to a label change / RMP update / Direct Healthcare Professional Communication (DHPC)
A single interval's case counts mean little in isolation. The PBRER core analytical work is contextualizing interval data against cumulative exposure, prior reporting periods, and Standardised MedDRA Query (SMQ) clusters — the step that catches slow-building safety trends that no single disproportionality run would flag on its own.
Raw ICSR counts scale with prescription volume, media attention, and litigation activity — not necessarily with true incidence. Cumulative review normalizes for this:
• Cumulative patient-years exposure: derived from sales/shipment data (patient-years method) or, where available, pharmacy claims/registry-derived person-time — the denominator for any incidence estimate • Reporting rate per 100,000 patient-years: calculated per interval and trended across all prior PBRERs to detect drift, not just spikes • Expedited vs. non-expedited split: serious + unexpected cases requiring 15-calendar-day expedited reporting (per ICH E2A) are tracked separately from routine periodic-only cases, since expedited case velocity is itself an early-warning indicator • Under-reporting correction: spontaneous reporting systems classically capture an estimated 1-10% of actual adverse events (the "iceberg" phenomenon documented since the 1980s Rogers/Rawlins studies), so cumulative review always states raw counts as a floor, not a ceiling, on true incidence
A single MedDRA PT like "hepatic failure" can under-capture a hepatotoxicity signal that also manifests as "transaminases increased," "jaundice," or "hepatic enzyme abnormal." SMQs group clinically related PTs into a validated syndrome-level search:
• Narrow scope SMQ: high specificity, includes only PTs with strong positive predictive value for the syndrome (e.g., confirmed drug-induced liver injury cases) • Broad scope SMQ: high sensitivity, casts a wider net including PTs that are merely suggestive, to avoid missing atypical presentations • ~35 standard SMQs exist for hepatic, cardiac (QT prolongation/Torsade), hematologic, anaphylactic, and other high-priority syndrome categories maintained by the MedDRA MSSO • SMQ-level disproportionality is run in parallel to single-PT analysis specifically because syndrome dilution across multiple PTs can mask a real signal when each individual term is analyzed alone
A validated safety signal only matters in the context of what the product delivers. The PBRER's benefit-risk section — the section regulators scrutinize hardest — uses structured, semi-quantitative frameworks like BRAT (Benefit-Risk Action Team) to make the weighing explicit, auditable, and comparable across reporting intervals rather than a narrative judgment call.
BRAT structures benefit-risk assessment into an explicit value tree so the same criteria are re-scored, not re-invented, every interval:
1. Decision context: define the therapeutic area, comparator (standard of care, placebo, or no treatment), and patient population 2. Value tree construction: enumerate key benefits (e.g., response rate, progression-free survival, symptom reduction) and key risks (each validated signal plus previously known important risks) as parallel branches 3. Outcome data: for each branch, populate the best available quantitative estimate (effect size, incidence rate, confidence interval) from trials and now-cumulative real-world safety data 4. Visualization: benefit-risk is typically rendered as a forest plot or tornado diagram — plotting effect sizes for benefits and risks on a common scale so a reviewer can see the balance at a glance rather than read fifty pages of prose 5. Interval-over-interval delta: each PBRER explicitly states which value-tree branches changed since the prior report and why the overall benefit-risk conclusion did or did not shift
EMA's own PrOACT-URL and effects-table methodologies serve a parallel function on the regulator side, meaning company BRAT output and PRAC assessor review use structurally comparable — if not identical — frameworks, which shortens assessment cycles.
A validated signal already covered by a risk minimization measure (RMM) is treated differently from a genuinely new risk:
• Routine RMMs: standard label warnings/precautions, pack size limits, prescription-only status — assumed baseline-effective, rarely separately measured • Additional RMMs: Dear Healthcare Professional Communications (DHPCs), patient/prescriber guides, controlled distribution programs (comparable to US REMS with Elements to Assure Safe Use), pregnancy prevention programs • Effectiveness evaluation: measured via drug utilization studies, targeted follow-up questionnaires embedded in the ICSR intake, or dedicated post-authorization safety studies (PASS) — did prescribers actually receive and act on the guidance? • Typical finding: additional RMMs show partial effectiveness — awareness surveys commonly report 60-85% target-audience recall of key safety messaging, prompting refinement (simplified materials, mandatory training modules) rather than assuming the RMM "solved" the risk
Where an RMM is judged ineffective, the PBRER recommendation section feeds directly into an RMP (Risk Management Plan) update — closing the loop between periodic safety reporting and the living risk-management document.
Under EU pharmacovigilance legislation (Regulation (EU) No 1235/2010, GVP Module V), an RMP update is not optional once a PBRER concludes a risk minimization measure is inadequate — the marketing authorisation holder must submit a revised RMP to PRAC, and PRAC can impose additional conditions on the marketing authorisation independent of the PBRER assessment outcome itself.
The final stage compiles every upstream analysis into the ICH E2C(R2) 18-module structure, routes it through internal QC and medical sign-off, and submits it as eCTD to every applicable health authority — frequently entering the EU's PSUR Single Assessment Procedure (PSUSA), where one PRAC assessment covers every marketing authorisation holder for a given active substance simultaneously.
Every PBRER follows the same fixed module sequence regardless of therapeutic area, which is what makes automated assembly and cross-product benchmarking possible:
1. Introduction · 2. Worldwide marketing authorisation status · 3. Actions taken for safety reasons · 4. Changes to reference safety information · 5. Estimated exposure and use patterns · 6. Data in summary tabulations (cumulative + interval) · 7. Summaries of significant findings from clinical trials · 8. Findings from non-interventional studies · 9. Information from other clinical trials/sources · 10. Non-clinical data · 11. Literature · 12. Other periodic reports (e.g., DSUR cross-reference) · 13. Lack of efficacy in controlled trials · 14. Late-breaking information · 15. Overview of signals · 16. Signal and risk evaluation · 17. Benefit-risk analysis · 18. Conclusions and actions
Section 6 (summary tabulations) and Section 16 (signal/risk evaluation) are where the disproportionality and cumulative-review work products from earlier stages are formally tabulated with full case-listing appendices attached.
GVP Module VII sets the submission clock at 70 calendar days from DLP for reporting intervals up to 12 months, extending to 90 days for longer intervals — a deadline that, unlike most regulatory clocks, starts before the document exists and forces the entire pipeline (data lock → signal detection → cumulative review → benefit-risk → assembly) into a fixed compressed window.
Internal QC gate before submission typically checks: • Cross-module consistency: exposure figures in Module 5 must reconcile exactly with denominators used in Section 6 tabulations • Case-listing completeness: every case cited in the narrative sections must appear in the corresponding line-listing appendix • MedDRA version consistency: all PT/SOC coding traceable to the single version stated in the report • Medical sign-off: a qualified person for pharmacovigilance (EU QPPV) or equivalent signatory attests to the accuracy and completeness of the safety evaluation
Submission routing: • EU: submitted via the EMA PSUR repository; for substances on the EU Reference Date list, one assessment (PSUSA) is run by a single Rapporteur on behalf of all MAHs, with PRAC issuing one shared outcome — reducing duplicate assessment effort but requiring all MAHs to submit on the same URD-aligned schedule • US: PADER/PBRER-equivalent submissions to FDA via the electronic gateway, cross-referenced against FAERS' own signal detection (openFDA, Sentinel Initiative active surveillance) • Other markets: PMDA (Japan), Health Canada, and other ICH-aligned authorities generally accept the same E2C(R2) core document with local administrative wrappers
Because PSUSA consolidates review across every marketing authorisation holder for a shared active substance, a generic-heavy molecule can have 15-40 separate MAHs submitting PBRERs on the same URD-aligned data lock point, all assessed in one PRAC procedure — meaning a single missed 70-day deadline by one MAH can hold up the shared assessment timetable for every other company marketing that substance in the EU.