Why Spreadsheet-Based PV Oversight Breaks Down

July 20, 2026 · Kevin Fetterman

Share
Why Spreadsheet-Based PV Oversight Breaks Down

Ask any pharmacovigilance or drug safety lead how their team tracks process obligations, like risk management commitments, signal management lifecycles, aggregate report timelines, and document versions, and there’s a good chance the honest answer involves at least one spreadsheet. Sometimes several, maintained by different people, updated on different schedules, and cross-referenced by memory more than by design.

It’s not that PV teams don’t know better. Spreadsheets are what’s available. They’re flexible, familiar, and don’t require a procurement cycle to start using. But flexibility is exactly what makes them dangerous in a regulated environment where oversight, not just tracking, is the actual job.

The gap between “tracked” and “overseen”

A spreadsheet can hold a due date. What it can’t do is tell you, reliably, whether that due date is at risk before it’s missed. It can’t flag that the person who owns a task has been out for two weeks. It can’t show a QPPV, at a glance, which risk minimization commitments across a portfolio are on track versus slipping. It can’t preserve a defensible audit trail of who changed what, and when, unless someone builds and maintains that discipline manually.

That distinction matters more than it sounds. Tracking is passive — it’s a record that exists. Oversight is active: someone can see status, risk, and accountability in time to act. Most PV teams using spreadsheets have built the first without realizing they’ve substituted it for the second.

Where the breakdown actually shows up

The failure mode is rarely dramatic. It’s cumulative, and it tends to show up in a few predictable places:

Version control. When a risk management plan or safety data exchange agreement lives in a spreadsheet plus a shared drive, “final” becomes a matter of interpretation. Multiple people editing the same tracker, in different tabs, on different days, is how commitments get double-counted, or worse, silently dropped.

Cross-functional visibility. Signal management, regulatory affairs, and clinical safety often work from separate trackers because no single system was built to serve all of them. That means status updates get relayed in meetings and emails instead of surfaced automatically, and relayed information decays.

Inspection readiness. Inspectors and auditors don’t ask, “Do you have a spreadsheet?” They ask for evidence: who was responsible for a commitment, when it was due, what happened when it slipped, and who approved the resolution. Reconstructing that history from spreadsheet version history and email threads after the fact is exactly the kind of scramble that turns a routine inspection into a stressful one.

Scale. A spreadsheet that works for five open risk management plans doesn’t work for fifty. The manual effort to keep it accurate doesn’t scale linearly; it gets worse over time because the number of cross-references and dependencies grows faster than the row count.

Why this isn’t a “get better at spreadsheets” problem

The instinct when a tracker starts failing is to add structure: more tabs, more conditional formatting, a naming convention, a second reviewer. Those are reasonable patches, and PV teams are good at building them because they’re good at process discipline generally. But every patch adds maintenance burden to a tool that was never designed to enforce process. Rather, it was designed to hold numbers and let you calculate on them.

The underlying issue is that oversight requires the system itself to carry the logic: who owns what, what’s overdue, what’s connected to what, and what the history looks like. A spreadsheet can be made to approximate that, at a real, growing cost — in people-hours and in risk. A system built for PV process tracking carries that logic natively.

What teams should be asking

Instead of “how do we manage our spreadsheets better,” the more useful question is: where would we find out first that a commitment is at risk — and would that be in time to act? For most teams running risk management commitments, signal triage, or aggregate reporting schedules out of spreadsheets, the honest answer is “later than we’d like, and usually not until someone goes looking.”

That’s the gap Orbit is built to close: purpose-built process tracking for pharmacovigilance and drug safety teams, so oversight isn’t something you reconstruct after the fact — it’s something you can see in real time. In our next post, we’ll dig into one of the sharpest examples of this: the specific compliance gaps that manual tracking creates around Risk Management commitments.

You’re passionate about patient safety, not spreadsheets. It shouldn’t take a spreadsheet to prove it.

KF
Kevin Fetterman