An Individual Case Safety Report (ICSR) is a structured document that captures information about a suspected adverse event linked to a medication, vaccine, or other regulated medical product. It is the fundamental unit of data in pharmacovigilance, the field dedicated to monitoring drug safety after products reach the market (and during clinical trials). Every time a patient experiences a side effect that gets formally documented and submitted to a regulatory authority, it travels as an ICSR.
What an ICSR Contains
At its core, an ICSR links four pieces of information: a patient, a reporter, a suspected product, and an adverse event. These four elements are also the minimum criteria for a report to be considered “valid” by regulators. For the patient, even a single identifier like age, sex, or initials is enough. For the reporter, a name, address, or professional qualification will do. The report must describe at least one adverse reaction or medical outcome, and it must name at least one suspect drug or interacting product.
Beyond these minimums, a complete ICSR typically includes much more: the patient’s medical history, lab results, surgical history, the clinical course of the event, what treatments were given, and how the patient ultimately fared. The richer the information, the more useful the report becomes for evaluating whether the drug actually caused the problem.
Where ICSRs Come From
Reports flow in from a surprisingly wide range of sources. The most common are healthcare professionals and consumers who contact a drug manufacturer or a regulatory authority directly. These are called spontaneous reports, and they form the backbone of post-market safety monitoring.
But ICSRs also originate from clinical trials, published medical literature, observational studies, and patient support programs run by pharmaceutical companies. Manufacturers are expected to routinely scan the scientific literature, including published abstracts and draft manuscripts, for adverse event information about their products. Digital platforms like social media, health apps, internet forums, and websites are also recognized as potential sources. Even reports surfacing through lawsuits or the lay press need to be captured and assessed.
How a Report Gets Processed
When an ICSR arrives at a pharmaceutical company or regulatory agency, it goes through a structured workflow. The first step is acknowledging receipt and checking whether the report meets the four minimum validity criteria. If it does, the case processor searches the database for duplicates, checking characteristics like the patient’s age, sex, country, and the reported reaction to see if the same event has already been logged. A match means the new information gets added as a follow-up to the existing case rather than creating a new entry.
Next comes triage. Cases are prioritized based on how recently they were received, how serious the event is, and whether the reaction was expected or unexpected for that drug. Serious and unexpected reactions jump to the front of the line because they carry the tightest reporting deadlines.
After triage, the case processor enters all available details from the source documents into the safety database. This includes coding the adverse event using a standardized medical dictionary, assessing whether the drug plausibly caused the reaction (causality assessment), determining whether the reaction is already listed in the drug’s labeling (expectedness), and writing a narrative summary of the case. A quality control review follows before the report is submitted to the relevant regulatory authority.
How Adverse Events Are Coded
To make ICSRs useful across countries and languages, adverse events are coded using a standardized terminology called MedDRA (Medical Dictionary for Regulatory Activities). This system translates a doctor’s free-text description of a side effect into a consistent, searchable code. MedDRA is mandatory for electronic reporting in the EU and Japan, and it serves as the standard in the United States as well.
The dictionary is organized into five levels, from broad organ system categories (27 total, like “cardiac disorders” or “skin disorders”) down to very specific low-level terms (over 75,000). This hierarchy lets regulators analyze safety data at whatever level of detail they need. A search for all cardiac events across thousands of reports, for instance, is only possible because every case was coded to the same system.
Reporting Deadlines
Regulators impose strict timelines for submitting ICSRs, and the clock starts the moment the company first becomes aware of the case. For serious and unexpected adverse reactions during clinical trials, sponsors in the US must submit reports to the FDA within 7 or 15 calendar days, depending on severity. Fatal or immediately life-threatening events fall into the 7-day window. The EU follows a similar structure, with 15-day expedited reporting for serious cases.
Non-serious cases generally have longer timelines, often 90 days. Missing a deadline is a compliance violation that regulators take seriously, which is why triage and prioritization happen so early in the processing workflow.
The Electronic Standard: ICH E2B(R3)
ICSRs are transmitted electronically using a format called ICH E2B(R3), an international standard developed to ensure that safety reports can be shared seamlessly between companies and regulatory agencies worldwide. The “R3” indicates the third revision, which uses a modern messaging framework and supports more detailed data fields than earlier versions. The FDA, the European Medicines Agency, and Japan’s regulatory authority all accept or require submissions in this format, though each region adds its own specific data elements on top of the shared international structure.
What Serious Means in an ICSR
Not all adverse events carry the same weight. An ICSR is classified as “serious” when the reported outcome meets any of several specific criteria: death, a life-threatening situation, hospitalization or prolonged hospital stay, significant disability or permanent damage, a congenital anomaly or birth defect, or a medical event that required intervention to prevent permanent harm. There is also a catch-all category for important medical events that don’t fit neatly into the other boxes but still jeopardize the patient’s health.
This seriousness classification directly affects how quickly the report must be submitted and how much attention it receives during review. A report describing mild, temporary nausea is processed differently from one describing liver failure requiring hospitalization.
How ICSRs Protect Public Health
The real power of ICSRs emerges when thousands of individual reports are analyzed together. A single report of an unusual side effect could be coincidence. But when regulators see the same reaction appearing repeatedly across reports from different countries and different reporters, that pattern becomes a safety signal.
Signal detection is the process of monitoring these evolving trends in cumulative ICSR data. When a potential signal is identified, regulators evaluate the evidence and decide whether action is needed. That action can range from updating a drug’s prescribing label to requiring a formal risk management program to, in extreme cases, pulling a product from the market. The FDA, for example, can require a Risk Evaluation and Mitigation Strategy (REMS) at any point when new safety information emerges for an approved product.
Once regulators confirm a signal as a genuine safety concern, the finding gets communicated to healthcare professionals, patients, the pharmaceutical industry, and clinical trial investigators. This feedback loop, from individual patient experience to global safety action, is what makes pharmacovigilance work. The ICSR is where that loop begins.

