Safety Databases · Section 10.13
~6 min read · The Drug Safety Coach — Global PV Career Course
Key points
Full text
Module 10 so far has covered how a safety database works internally — case intake, workflow, E2B(R3) transmission. What it hasn’t covered is what happens at the boundary between two organizations working on the same product: a sponsor and its CRO, or two co-marketing partners. That boundary is governed by a document most new hires never see until they’re already working with one — the Safety Data Exchange Agreement, or SDEA.
An SDEA specifies, in contractual detail, who reports what to whom, on what timeline, and who’s ultimately responsible for the regulatory submission itself. It exists because GVP Module VI.B.7 requires it explicitly, precisely to prevent two failure modes: a case falling through the gap between organizations and never getting reported at all, or the same case getting reported twice by two different parties who didn’t know the other had already handled it.
Reconciliation is the recurring check that the SDEA is actually working as designed. On a schedule the agreement specifies — quarterly is common, and always before a database lock or a major data cutoff — someone compares case counts and identifiers across every database that could plausibly hold a record of the same events: the sponsor’s safety database, the CRO’s clinical/EDC system, sometimes a specialty pharmacy or vendor database as well. Discrepancies get investigated and resolved before they become missed or duplicated regulatory submissions. Common friction points include MedDRA version mismatches between systems, genuinely irresolvable disagreements about whether two records describe the same event, and slow site response when a query is needed to settle it.
The safety mailbox is a related, everyday version of the same boundary problem. A shared inbox that patients, HCPs, or partner organizations can email is a live reporting channel — anything arriving there has to be triaged on the same clock as a phone call, correctly sorted into AE, product quality complaint, or medical inquiry (they’re not interchangeable), and routed before the reporting timeline starts slipping. None of this shows up in a training environment built around a single database in isolation — which is exactly why it’s one of the most commonly cited gaps between what a course teaches and what the first weeks on a CRO safety team actually look like.
Important
GVP Module VI.B.7 states it directly: "explicit procedures and detailed agreements should exist between the marketing authorisation holder and the person/organisation… specifying the processes for the exchange of safety information, including the timelines and responsibilities for the regulatory submission of valid ICSRs," organised "to avoid the submission of duplicate ICSRs." That single requirement is the reason SDEAs and reconciliation exist as standing operational work, not optional housekeeping.
Quick check
Test yourself before moving on — no pressure, just click an answer.
1. What is the primary purpose of a Safety Data Exchange Agreement (SDEA) between a sponsor and a CRO?