ClinicOps
Free tool · Pharmacovigilance agreements

SDEA / PV agreement clause checker

From 12 February 2026, Commission Implementing Regulation (EU) 2025/1466 requires every pharmacovigilance subcontract to contain a defined clause set (Regulation (EU) No 520/2012 as amended, Article 6(3)–(4)). It also makes risk-based audit of third parties mandatory (Article 13) — "even if the obligation pursuant to Article 6(3) has not yet been included in the subcontract". Paste an agreement, upload the signed PDF, or answer the checklist, and get a gap report where every rule carries its citation. Runs in your browser, including reading an uploaded PDF; nothing is sent to ClinicOps.

Boundary. This is a structuring aid for the QPPV office and contract owner, not legal advice and not a substitute for reading the agreement. Keyword detection finds words, not meaning: a detected clause can still be inadequate, and an undetected one can exist under different wording. Confirm every line manually before relying on the report. QPPV, deputy and national contact-person responsibilities are assumed by ClinicOps only where explicitly appointed.

1. Agreement details

2. Rule-by-rule review

Severity: CRITICAL explicit legal requirement in force (IR 520/2012 as amended, Directive 2001/83/EC, GDPR) · MAJOR GVP expectation or a legal MAH duty the contract must enable · MINOR inspection good practice without explicit GVP text. Set each rule to present, missing or n/a; "auto" uses the keyword scan.

3. Gap report

No report built yet.

4. Reconciliation log template

Article 6(3)(b) requires the safety-data exchange obligation and method to be written down; inspectors then expect evidence that the exchange actually happened. A periodic reconciliation — cases sent versus cases received, discrepancies and their closure — is that evidence. Fill a period and download the log.

PartnerPeriodCases sentCases receivedDiscrepanciesResolution / closure dateOwner

Tool assessment (documented-tool record)

Purpose, requirements, test evidence, limitations, change log

Purpose. Screen a pharmacovigilance agreement against the clause set required or expected under Regulation (EU) No 520/2012 as amended by Implementing Regulation (EU) 2025/1466, Directive 2001/83/EC and GVP, and produce a cited gap report and a reconciliation-log template. The tool is a structuring aid; the agreement owner and QPPV decide.

Requirements. R1 Every rule carries a citation to an article or GVP section and a severity. R2 Keyword detection never overrides a manual "present/missing/n/a" choice. R3 The gap report separates confirmed-missing (manual) from not-detected (keyword scan) so absence of a keyword is never reported as absence of a clause; counts present / missing / not detected / n/a / undetermined. R4 Rules are filtered by relationship type; "all" shows every rule. R5 All processing is local; no network calls after page load, including reading an uploaded PDF (self-hosted pdf.js, vendored locally — no CDN). R6 Version and change log are shown; rule wording changes are versioned. R7 A PDF upload only ever fills the same paste box a person could fill by hand; it never runs the scan on its own and never overwrites text already in the box without the person choosing to upload.

Test evidence (v1.0, 2026-09-24). T1 Text containing "roles and responsibilities", "shall not subcontract … written consent", "agrees to be audited by or on behalf of the MAH and inspected by competent authorities" → R01, R04, R05 detected as present; all other rules reported as "not detected — confirm manually", never as missing. Pass. T2 Manual "n/a" on R31 with type SP → R31 counted as not applicable. Pass. T3 No scan, build report → every applicable rule undetermined; counts sum to the applicable total. Pass.

Test evidence (v1.1, 2026-09-27). T4 Uploading a text-layer PDF fills the paste box with its extracted text and the existing scan runs over it unchanged, with the same present/not-detected split as pasted text. Pass. T5 Uploading a scanned (image-only) PDF reports "no extractable text found" and leaves the paste box untouched rather than showing an empty scan as if nothing were wrong. Pass. T6 Uploading a malformed or non-PDF file reports a clear local error and leaves the paste box untouched. Pass. T7 Zero console errors and zero requests to any host other than clinicops.dk across all of T4–T6. Pass. Automated with Playwright against representative fictional PDF fixtures; no real client agreement was used to build or test this.

Known limitations. English keyword detection only. Quotations are abridged (≤30 words) and must be read in the source text. Rules R17 and R27 rest on inspectorate guidance rather than explicit GVP wording. Sections VI.C.2.2.x of GVP Module VI were not re-verified on the review date; timelines are cited to Directive 2001/83/EC Article 107(3), which was. EMA's Q&A on 2025/1466 (Rev 2, Jan 2026) addresses EudraVigilance monitoring only and is not a source for the contract provisions. PDF upload reads an existing text layer only (200-page / 40MB local guardrails); a scanned or image-only agreement still needs pasted or manually typed text.

Change log. v1.1 (2026-09-27): added an optional local PDF-upload path that fills the same paste box as pasted text; no change to the rule set or scan logic. v1.0 (2026-09-24): first release, 35 rules.

When the gap report needs a Danish counterpart

ClinicOps' own engagement terms are drafted to Article 6(3) — defined roles, stated exchange method and timeline, audit and inspection access, no onward subcontracting without written consent — because that is what this checker looks for. If the missing clauses concern a Danish distributor, parallel importer or local-language safety work, ClinicOps can scope that work. See the Danish pharmacovigilance capability →

Scope Danish PV capacityOpen the literature registerOpen the DHPC checker