Usage Examples
- The RMP update goes in with the type II variation, not as a standalone submission.
- Hepatotoxicity moved from important potential risk to important identified risk, so Part II module SVII and Part V both change.
- We still owe annex 1 in XML from the last Commission decision.
What is RMP (Risk Management Plan)?
RMP is the EU regulatory document that records a medicinal product's risk management system: the important identified risks, important potential risks, and missing information, plus the pharmacovigilance and risk-minimisation activities that address them.
The RMP exists because a medicinal product is authorised on evidence that is incomplete by design. Not all risks are identified when an initial marketing authorisation is granted; some are only discovered and characterised after launch. EU legislation therefore requires the applicant to state up front which risks matter, how each will be characterised further, and how each will be minimised in clinical use.
The RMP covers a product's important identified risks, important potential risks, and missing information, plus the pharmacovigilance and risk minimisation activities addressing them. The RMP does not cover every reported adverse reaction. GVP Module V Rev 2 narrowed it: an identified risk belongs in the RMP only where there is sufficient scientific evidence of causation, and only where it is likely to affect the risk-benefit balance.
The RMP is filed in practice as a single seven-part document, submitted as PDF inside the eCTD sequence for centrally authorised products, with annex 1 supplied separately in XML after the Commission decision. The RMP is version-controlled: a product can have only one current approved version, and an update submitted outside another regulatory procedure is handled as a variation.
Not to be confused with
- REMS
- REMS is the separate US risk-management instrument. No US filing discharges the EU obligation, because Directive 2001/83/EC requires an RMP with every new EU marketing authorisation application, whether or not the same product carries a REMS.
- PSUR
- a PSUR reports what happened over a defined interval; an RMP states what will be done about risks going forward. When PSUR data drives new safety concerns, the updated RMP is submitted at the same time and no stand-alone RMP variation is needed.
- Safety specification
- the safety specification is RMP part II, one of the seven parts, not a synonym for the RMP. The pharmacovigilance plan (part III) and the risk minimisation measures (part V) are separate parts built on top of it.
- Risk management system
- the risk management system is the set of activities a company actually runs; the RMP is the document that records that system for the regulator. GVP Module V defines the RMP by that documenting function.
The obligations below are the ones assessors check first.
What you must do
- 1Submit the RMP describing the risk management system, together with a summary, with every new marketing authorisation applicationDirective 2001/83/EC Art 8(3)(iaa)
- 2Follow the RMP template's seven-part structure, with part II (safety specification) subdivided into modules SI to SVIII so content can be tailored to the productGVP Module V, V.B.3; IR (EU) No 520/2012 Annex I
- 3Submit an RMP update whenever the list of safety concerns changes, or whenever an additional pharmacovigilance or additional risk minimisation activity is new, significantly changed, or removed, including changes to a study's objectives, population, or due dateGVP Module V, V.C.2.1
- 4Include a track-changes RMP document with every update, showing changes against the current approved version, unless the authority requests otherwiseGVP Module V, V.C.2.1
- 5For centrally authorised products, submit the RMP as PDF files within the eCTD submission, and file RMP annex 1 in XML within the specified timescale after the Commission decisionGVP Module V, V.C.2
Common mistakes
Listing every reported adverse reaction as a safety concern
GVP Module V Rev 2 exists partly to stop this, and it limits the RMP to risks with sufficient scientific evidence of causation that are likely to affect the risk-benefit balance. Each inflated safety concern drags pharmacovigilance and risk minimisation commitments behind it, and every one of those becomes a lifecycle obligation to maintain, study, and report against.
Treating the RMP as an application document that stops at approval
the update trigger is far lower than teams assume: a change in a study's objectives, population, or due date for final results is enough to require an updated RMP with the procedure that caused it. Missing the trigger converts a routine variation into a pharmacovigilance system finding.
Losing track of which version is current
a product can have only one current approved RMP, and where several updates are submitted during one procedure, the current version is the one filed with the closing sequence. Teams that track-change against the wrong baseline submit an update the assessor cannot reconcile, which costs a review cycle.
When This Matters
- The RMP update goes in with the type II variation, not as a standalone submission.
- Hepatotoxicity moved from important potential risk to important identified risk, so Part II module SVII and Part V both change.
- We still owe annex 1 in XML from the last Commission decision.
Frequently Asked Questions
No. The RMP is an EU requirement: Directive 2001/83/EC requires one with every new marketing authorisation application. The US uses REMS instead, a separate instrument with its own scope. The shared element is ICH E2E, whose safety specification headings the RMP's Part II modules generally follow.

