SummarySmPC compliance is the discipline of keeping every authorised text for a product accurate, current and traceable across every market where it is marketed. In practice this means managing variations under Regulation (EC) No 1234/2008, controlling the chain from company core data sheet to reference safety information to national SmPC, absorbing safety-driven label changes from referral procedures, and knowing at any moment which SmPC version legally governs which market.
Most published material on this subject explains what an SmPC is and stops there. That is a useful starting point, and if you need the definitional groundwork, the sections, the legal basis, the difference between an SmPC and a package leaflet, read our companion piece on what an SmPC is first. This article assumes you already know all of that and are responsible for the harder problem: the same molecule authorised in eleven countries, with eleven texts that are similar but not identical, each on its own revision clock.
We maintain product information as structured data across 50+ countries, so this is written from the vantage point of the people who have to reconcile those texts every day, not from the vantage point of a regulatory textbook.
The SmPC stops being a document the moment a product exists in more than one market. A single centrally authorised medicine carries one Annex I in 24 languages. A nationally authorised or mutually recognised portfolio carries genuinely different texts: different indications approved at different times, different excipient warnings, different pack sizes, different local pharmacovigilance addresses in section 4.4 or 6, and different revision dates in section 10.
Companies routinely manage this in document systems, which are excellent at version control for one file and poor at answering questions across files. The operationally important questions are all cross-file:
None of these are answerable by opening a PDF. They are answerable only if product information is held as data with market, version, date and section as queryable attributes.
Every change to an authorised SmPC is a variation, governed by Commission Regulation (EC) No 1234/2008. That regulation was substantially amended by Commission Regulation (EU) 2024/1701 of 11 March 2024, which entered into force on 7 July 2024 and applied from 1 January 2025. The accompanying revised Variations Guidelines apply from 15 January 2026, and the European Medicines Agency has published guidance on the application of the revised variations framework covering the transition, including the rule that Type IB and Type II variations submitted from 15 January 2026 follow the new guidelines while earlier submissions run to completion under the old ones.
The classification matters operationally because it determines when the text on the market actually changes, which is rarely the same date as the approval.
| Variation category | Nature of change | Procedural logic | What it means for the live SmPC |
|---|---|---|---|
| Type IA | Minor, no impact on quality, safety or efficacy | Do and tell: implement first, notify within 12 months | Text can change before the authority has processed it, so the internal record leads the regulator record |
| Type IA IN | Minor, immediate notification required | Implement, notify immediately | Same as IA but with a shorter notification window, common for administrative and manufacturing details |
| Type IB | Minor, but not IA and not major | Tell and wait: notify, then wait the review period before implementing | A defined gap between submission and lawful use of the new text |
| Type II | Major, may affect quality, safety or efficacy | Prior approval required | New indications, new contraindications, significant section 4.4 or 4.8 changes; often triggers leaflet and labelling rework |
| Line extension | New strength, form or route | Full application annex procedure | Usually produces a new SmPC rather than an edit to an existing one |
| Worksharing / grouping | One change across several authorisations | Single procedure, multiple products | The main lever for keeping a multi-market portfolio aligned rather than drifting |
The practical trap is the Type IA category. Because it is implemented before it is notified, teams that reconcile their internal library against the regulator's published text will find legitimate mismatches. If your tracking system treats every mismatch as an error, it will generate noise until people stop reading the alerts.
Multinational companies do not write each national SmPC from scratch. They maintain a company core data sheet (CCDS), an internally owned document that states the company position on safety, indications, dosing and other core content. The safety subset of the CCDS is the company core safety information. From that, the reference safety information (RSI) is derived: the list of expected adverse reactions used to assess expectedness in periodic safety reporting and in development safety update reports. National SmPCs are then the authorised, market-specific expressions of that core.
| Layer | Owner | Legal status | Typical change trigger | Failure mode |
|---|---|---|---|---|
| CCDS | Company (global regulatory and safety) | Internal governance document, not authorised | New signal, new study data, portfolio decision | Updated but never cascaded into local variation filings |
| RSI | Company (pharmacovigilance) | Internal reference for expectedness assessment | CCDS safety update, PSUR outcome | Version used for coding does not match the version in force during the reporting period |
| Local SmPC | Marketing authorisation holder, approved by the competent authority | Legally binding text in that market | Approved variation, referral outcome, national requirement | Divergence from CCDS that nobody recorded as a deliberate local deviation |
Divergence between these layers is not automatically a compliance failure. Some of it is unavoidable: a national authority may refuse wording the company proposed, or may impose additional wording, or the local text may lag simply because the variation is still under review. What turns acceptable divergence into a finding is the absence of a controlled record explaining why each difference exists and when it is expected to close. Inspectors ask that question. Document systems answer it badly; a data model with a per-market delta view answers it well.
Not all SmPC changes originate with the company. Referral procedures allow regulators to force a coordinated change across every product containing a substance or class. The mechanisms most likely to hit a portfolio are:
The EMA publishes the full set of active and concluded procedures on its referral procedures pages. The operational consequence of a referral is that a single Commission decision propagates into dozens or hundreds of national SmPCs, each of which then has its own implementation deadline and its own translated wording. Generic manufacturers feel this hardest: an originator-driven referral outcome obliges every generic holder of the same substance to file matching changes, on a clock set by someone else.
This is precisely the scenario where document-centric tracking fails. The question "have all 43 of our authorisations for this substance implemented the referral wording, and in which of them is it already visible in the published text" is a data query, not a filing task.
Electronic product information (ePI) is the move from SmPC as a formatted document to SmPC as structured, machine-readable content. The EU has adopted the EU ePI Common Standard, based on HL7 FHIR, and the EMA maintains the initiative through the Product Lifecycle Management Portal following a pilot that ran from July 2023 to August 2024 with Denmark, the Netherlands, Spain and Sweden.
On 20 March 2026 the EMA published a draft roadmap to coordinate delivery of ePI across the regulatory network and to align with the requirements of the new pharmaceutical legislation. The shape of the rollout is phased and, critically, voluntary at this stage:
ePI is not mandatory in 2026. During the voluntary phase, applicants author and upload ePI through the portal as an additional step alongside the existing Word and PDF submissions, which means the near-term effect for regulatory teams is more work, not less. The payoff arrives later, and only for companies that treat ePI as a genuine content model rather than as an export format bolted onto the end of a document workflow. Current status and documentation sit on the EMA's electronic product information pages.
General-purpose language models are not a reliable source of drug information. The best-known evidence is a Long Island University study, first presented at the American Society of Health-System Pharmacists Midyear Clinical Meeting in December 2023 and subsequently published in the British Journal of Clinical Pharmacology in 2024. Researchers put 39 real medication questions, drawn from the university's own drug information service, to the free version of ChatGPT. Pharmacist review judged only 10 of the 39 answers satisfactory, meaning 29 of them, or 74 percent, were not. The citation behaviour is the more instructive finding: references were requested for every question but supplied with only 8 answers, and every one of those 8 contained fabricated references.
That result is not an argument against AI in regulatory work. It is an argument about architecture. A model generating text from general training data will produce fluent, plausible, unverifiable statements. A system that retrieves the actual authorised text and answers only from it behaves differently, because every answer can be traced back to a specific section of a specific SmPC version.
This distinction is the first thing regulatory professionals raise when we demonstrate AI features. One put the condition plainly:
AI-generated answers are usable only on condition that the source is document-grade and that the source is actually there. (Manager at a pharmaceutical manufacturer, translated from German)
That is the design constraint our ChatSmPC® and ChatPIL® features are built around: the query runs against full SmPC and package leaflet texts held in the platform, and the answer points back to the source text rather than paraphrasing from a general model. It does not remove the need for human review, and no serious team should let it. It removes the need to open fourteen PDFs to establish whether a warning exists in a given market.
Ask a regulatory affairs team what actually consumes their time and the answer is rarely the drafting. It is reconciliation: establishing, at a given moment and for a given market, which text is in force. That question sits behind medical information responses, promotional material approval, artwork sign-off, pharmacovigilance expectedness assessment, tender documentation and due diligence.
Making it answerable requires a few things that document management alone does not provide:
This is where consolidated product information data earns its keep. pharmazie.com holds 25+ databases in one search layer, covering 50,000+ German products and 120,000+ international products across 50+ countries, and DACON GmbH has been maintaining pharmaceutical reference data since 1989. For cross-market and cross-layer questions about which text applies where, that consolidated view is the most complete single answer available to regulatory and pharmacovigilance teams working across DACH and internationally. It does not replace your regulatory information management system, which owns your submissions and your internal history. It answers the complementary question that RIM systems typically cannot: what does the authorised text look like right now, everywhere, including for products that are not yours.
If you are building or repairing an SmPC compliance process, the following controls address the failure modes described above:
None of this is exotic. It is ordinary discipline applied to content that most organisations still treat as documents when it has long since become data.
This content is intended for healthcare professionals and does not constitute medical advice. Last reviewed: July 2026.
SmPC compliance is the ongoing obligation of a marketing authorisation holder to keep the summary of product characteristics accurate, current and consistent with the authorisation in every market where the product is placed. It covers filing variations for every change, implementing safety-driven changes from referral procedures, keeping local texts aligned with the company core data sheet, and being able to evidence which version is in force where. It is a lifecycle activity, not a one-off submission task.
No, ePI is voluntary in 2026. The EU ePI Common Standard is based on HL7 FHIR, and the draft roadmap published by the EMA on 20 March 2026 sets a phased voluntary rollout starting with vaccines (ATC group J07) in Q3 2026 and oncology and immunomodulating products (ATC groups L01 and L04) in Q4 2026. ePI becomes mandatory for newly authorised medicines only once the revised EU pharmaceutical legislation enters into application.
Type IA, IB and II are the categories of post-authorisation change defined under Regulation (EC) No 1234/2008. Type IA variations are minor changes with no impact on quality, safety or efficacy and can be implemented before notification, within a 12-month window, with Type IA IN requiring immediate notification. Type IB variations are minor changes that must be notified and reviewed before implementation. Type II variations are major changes, such as a new indication or a new contraindication, requiring prior approval.
A referral procedure allows regulators to impose a coordinated label change on every product containing a given substance or belonging to a given class. The main routes are Article 31 of Directive 2001/83/EC for referrals in the interest of the Union, Article 20 of Regulation (EC) No 726/2004 for centrally authorised medicines, and Article 107i of Directive 2001/83/EC as the urgent Union procedure. The outcome cascades into every affected national SmPC, each with its own implementation deadline and translated wording.
The company core data sheet (CCDS) is an internal company document stating the global position on safety, indications and dosing, and it has no legal authorisation status. The reference safety information (RSI) is the list of expected adverse reactions derived from the CCDS and used to assess expectedness in periodic and development safety reporting. The local SmPC is the legally binding text approved by the competent authority in a specific market, and it may deliberately differ from the CCDS.
General-purpose language models are not a reliable source of drug information. A Long Island University study presented at the ASHP Midyear Clinical Meeting in December 2023 put 39 real medication questions to the free version of ChatGPT and found that pharmacist review judged roughly three quarters of the answers incomplete or incorrect, with fabricated citations when references were requested. Retrieval-based tools that query actual SmPC full texts and cite the source section behave differently, but human review remains necessary.