XGene CMC IntelligenceXGene Intelligence

EMA SPOR PMS — Product Management Service and Variation Maintenance

SpecificationsSolid StateData Integrity / ALCOA+Container Closure / E&LIDMP / SPOR

EMA's Product Management Service assigns the EU product identifier that is required in electronic product information and variation submissions — and managing this identifier accurately across a complex product portfolio…

By Khaled Aamer, PhD · Founder, XGene LLC Aug 22, 2026 10 min read
On this pageArticle overview

    EMA’s Product Management Service assigns the EU product identifier that is required in electronic product information and variation submissions — and managing this identifier accurately across a complex product portfolio is a regulatory operations competency that most EU marketing authorisation holders have not yet systematically built.

    The consequence of that gap is no longer theoretical. As EMA advances SPOR-IDMP integration across the European medicines network, the EU product identifier — the EUPI — is becoming the structural anchor for electronic product information submissions, variation processing, and national health system data exchange. Marketing authorisation holders who have treated PMS registration as a one-time administrative event following initial approval are discovering that their product data has silently drifted out of alignment with their current marketing authorisation terms, and that this drift surfaces at the worst possible moment: during variation submission validation. A SPOR data integrity problem is not a cosmetic discrepancy — it is a blocking condition that stops a submission from being processed.

    What the Product Management Service Controls: Medicinal Product, Pack, and Pharmaceutical Product

    The SPOR Product Management Service is the authoritative registry for medicinal products authorised in the European Union, governed by the data model specified in ISO 11615:2017, Identification of Medicinal Products. ISO 11615:2017 defines the data elements that constitute a complete medicinal product record — and understanding this structure is the prerequisite for managing PMS accurately. The registry does not store a single undifferentiated product record. It organises product data across three hierarchical levels: the medicinal product (the authorised product as a whole), the pharmaceutical product (the dose form, route of administration, and strength, each coded using the controlled vocabularies maintained by EMA’s Referentials Management Service, RMS), and the packaged product (the container type, container size, and packaging material). Each level carries its own data integrity obligation, and a discrepancy at any level creates a structural mismatch with the approved marketing authorisation.

    The EU product identifier — the EUPI — sits at the top of this hierarchy. It is a unique alphanumeric code assigned by EMA to each authorised product at the point of initial marketing authorisation, and it is the key that links the product record to every downstream data system: the electronic Application Form, electronic product information submissions, and the SPOR-IDMP infrastructure that feeds national health data systems across EU member states. Under EU Regulation 726/2004, which governs the centralised authorisation procedure, and EU Directive 2001/83/EC, which governs national, mutual recognition, and decentralised procedures, the marketing authorisation holder is responsible for the accuracy of the product information on the authorisation. The EUPI operationalises that responsibility in the digital environment — it is the identifier through which the regulator and the health system recognise that a specific product with specific characteristics is authorised and marketed.

    The PMS record also contains two critical cross-service references that most MAHs do not actively manage. The PMS-to-OMS relationship links the product to the Organisation Management Service record for the marketing authorisation holder and the manufacturer. The PMS-to-SMS relationship links the product to the Substance Management Service record for the active substance. When an MAH transfer is approved — a Type II variation under the centralised procedure — the PMS OMS reference must be updated to reflect the new MAH. When a new salt form or polymorph is introduced, the SMS substance ID in the PMS record must correspond to the updated SMS entry. These cross-service linkages mean that a variation affecting organisational or substance data has PMS consequences beyond the product data elements themselves, and organisations that do not track these dependencies systematically will accumulate silent discrepancies across their portfolio.

    The PMS Data Requirements for Initial MAA Submission and Variation Maintenance

    For a new marketing authorisation application, the sequence is straightforward in principle: the MAA is submitted, EMA assigns the EUPI upon authorisation, and the MAH populates the PMS product data record — dose form coded against the RMS terminology, route of administration coded against RMS, strength, packaged product data including container type and material. What is less well understood is the ongoing obligation that begins from that point. EMA’s foundational SPOR programme document, “Introduction to ISO Identification of Medicinal Products, SPOR Programme” (EMA/732656/2015, published November 2016), together with the subsequent EU IDMP Implementation Guide chapters, established the framework for IDMP data integration across the European medicines network, and it makes explicit that PMS data is not static reference data — it is a living record that must reflect the current authorised state of the product at all times.

    The practical implication is this: any Type IA, Type IB, or Type II variation that affects a PMS data element requires a PMS update either before or concurrent with the variation submission. A Type IB variation changing a container closure from HDPE to glass — a change that affects the packaged product data element in PMS — requires that the PMS record be updated to reflect the new container type and material before the ePI submission referencing that presentation can be validated. A Type II variation adding a new strength requires that the new pharmaceutical product record be created in PMS, with the new strength coded in RMS, before the variation can proceed through to electronic product information update. The eAF technical specifications, which govern electronic application form submissions to EMA, require a valid EUPI for every submission that references an authorised product. If the PMS record does not yet reflect the variation outcome, the eAF validation will fail at the point of EUPI cross-reference, and the submission will not be accepted.

    The operational failure pattern that surfaces most frequently in practice involves the lag between a variation approval and PMS update. A company approves a Type IA variation — a minor change to container size — through its internal regulatory affairs workflow, files the change notification, receives the approval, and closes the variation record. Eighteen months later, the same product line requires a Type II variation to add a paediatric strength. The regulatory team populating the eAF discovers that the PMS packaged product record still shows the old container size from before the Type IA was filed. The variation was approved, but the PMS update was never triggered because no one in the workflow owned the PMS update step. The submission is delayed while the PMS discrepancy is investigated and corrected — a delay that is entirely avoidable but requires a workflow integration that most organisations have not built.

    How PMS Changes the Way EMA Processes CMC Variations and Renewals

    The SPOR-IDMP programme is fundamentally changing the processing architecture for CMC variations at EMA. Electronic product information — the structured, machine-readable product labelling that replaces the current PDF-based product information documents — requires a valid EUPI as its identifier and must be consistent with the PMS product record at the level of dose form, route, strength, and presentation. This means that the ePI update that accompanies a variation approval is not a standalone document — it is a data transaction that EMA’s systems validate against the PMS record in real time. An ePI submission that references a dose form coded differently in the PMS record than in the ePI XML will fail validation before it reaches a reviewer.

    Article 57 of EU Regulation 726/2004 requires MAHs to submit product information to EMA for all centrally authorised products. As the Article 57 reporting mechanism is integrated with SPOR infrastructure, the PMS record becomes the anchor for that statutory reporting obligation as well. An MAH that has allowed PMS data to drift out of alignment with the current marketing authorisation is not merely dealing with a submission technical issue — it is non-compliant with its statutory product information maintenance obligation. This is the data integrity dimension that most regulatory operations leaders have not fully internalised: SPOR PMS inaccuracy is not a system administration problem, it is a regulatory compliance problem with the same structural character as a gap in a pharmacovigilance database.

    For renewal submissions, which under EU Directive 2001/83/EC for nationally authorised products occur on a five-year cycle, the PMS record provides the baseline data against which the renewed marketing authorisation will be reflected in SPOR. An MAH that arrives at renewal with a PMS record carrying three years of unrecorded Type IA and IB variations faces a correction exercise that must be completed before or during the renewal process. The correction of historical PMS data — identifying each variation that should have triggered a PMS update, reconstructing the approved product characteristics at each stage, and sequentially updating the PMS record to reach the current authorised state — is a data archaeology task that consumes regulatory affairs capacity at exactly the moment that capacity is needed for the renewal submission itself.

    Preparing Your Product Data Infrastructure for SPOR PMS Integration

    The XGene SPOR PMS Portfolio Management Architecture is a structured programme for establishing and maintaining an accurate, current PMS product data record across the full EU marketing authorisation portfolio, integrated into the variation management workflow so that PMS updates are triggered systematically rather than discovered reactively.

    Step 1 — PMS Portfolio Audit Against Current Marketing Authorisation Terms. For each authorised product in the EU portfolio, retrieve the current SPOR PMS record and compare every data element — dose form, route of administration, strength, container type, container size, packaging material, MAH OMS reference, and SMS substance ID — against the current approved marketing authorisation terms, including all approved variations. Document every discrepancy with the variation number that should have triggered the PMS update that was not made. This audit produces a complete discrepancy register that quantifies the scope of the data integrity gap before any submission deadline creates urgency.

    Step 2 — Data Discrepancy Correction Protocol. For each identified discrepancy, execute the PMS update in sequence from the earliest unapplied variation through to the current authorisation state, maintaining an audit trail that maps each PMS update to the variation approval document that authorised the underlying product change. This sequenced correction approach is required because PMS data has a temporal dimension — the record must reflect the history of changes, not only the current state. Submitting a correction that jumps to the current state without recording intermediate steps creates a new data integrity gap.

    Step 3 — Variation Management Workflow Integration. Embed PMS update triggers into the variation management workflow at the point of variation approval, with designated data stewards per product family who are responsible for executing PMS updates within a defined timeframe following variation approval. The trigger must cover all three variation types — Type IA, IB, and II — because Type IA notifications, which do not require prior approval, are the category most frequently missed in PMS update workflows. The workflow integration must also address the cross-service dependencies: MAH transfer variations must trigger OMS reference updates; substance changes must trigger SMS cross-reference verification.

    Step 4 — EUPI Registry and ePI Readiness Assessment. Maintain a product-level EUPI registry that maps each EU authorised product to its EUPI, its current PMS record status, and its ePI readiness state — specifically, whether the PMS pharmaceutical product and packaged product data are coded in RMS terminology compatible with the ePI XML schema. As EMA advances ePI implementation, this registry becomes the operational foundation for ePI submissions across the portfolio.

    The output of the XGene SPOR PMS Portfolio Management Architecture is a verified, current, variation-synchronized PMS data record for every product in the EU portfolio — not a gap list to be resolved, but a maintained data infrastructure that supports every variation submission, ePI update, and Article 57 reporting obligation without the discovery delays that characterise reactive PMS management.

    Companies that manage SPOR PMS data reactively — updating records only when a submission failure forces the issue — are accepting a structural regulatory risk that compounds with portfolio size and variation frequency. Every Type IA notification that closes without a PMS update is a discrepancy that will surface at the least convenient moment. Every MAH transfer that is not reflected in the PMS OMS reference is a data integrity gap that exists at the statutory product information level, not merely at the system administration level. The cost of reactive PMS management is not a single delayed submission — it is a pattern of preventable delays across the product lifecycle, each one consuming regulatory affairs capacity that should be allocated to substantive CMC development and regulatory strategy. The EU medicines regulatory environment is moving toward full SPOR-IDMP integration, and MAHs that have not built the PMS data governance infrastructure to support that environment will face increasing submission friction as the integration deepens.

    Select five products from your EU portfolio and compare the product data in SPOR PMS against your current approved marketing authorisation terms — if any PMS data element (dose form, strength, MAH, presentation) does not match the current authorisation, you have a SPOR data integrity gap that will surface during your next variation submission.