The short answer
I'm Hugo Acurio, and I designed and built Iris Global Ecuador's pharmacovigilance system ahead of ARCSA's new standard, which takes full effect November 4, 2026. It's a regional platform under Iris LLC, launching first in Ecuador under that November 4, 2026 standard, with Iris Mexico next. It runs on the company's existing Odoo ERP: public intake, a case record with the regulatory clock built in, a seven-stage workflow with role-gated sign-off, MedDRA and WHODrug coding, and one append-only record. Everything here is built and tested end to end; no live adverse-event cases have been processed yet, since the first live cases follow the November 4 go-live.
The board I saw
ARCSA published its substitute pharmacovigilance standard in February 2026. It names a responsible pharmacovigilance officer who must sign every submission, specifies the causality algorithms allowed, requires duplicate detection as a system function, and moves reporting onto WHO's e-Reporting platform. Ecuador is not moving alone: Brazil's ANVISA RDC 967/2025 took force in March 2026 with VigiMed, E2B(R3), MedDRA and WHODrug all mandatory, and Mexico's COFEPRIS received 82,993 notifications in 2025.
The 15 and 30 day clocks (serious and non-serious cases) run from the moment any employee becomes aware of the event (a sales rep, a phone assistant, whoever reads the comment on social media), not from when a case is opened. A system that starts the clock at case creation is already late.
Most AI-in-pharmacovigilance pitches cannot survive an auditor. A language model is probabilistic, and a regulator asking how a case was coded wants a reproducible answer. Compliance is a systems problem, not a knowledge problem: I cannot audit how a model thinks any more than I can audit how a person thinks, so the audit happens outside the model, in the middleware. Every model call gets an input hash, a version, a confidence score, and a human on the transmission trigger.
The system I invented
Everything runs on the ERP the company already operates, so pharmacovigilance lives next to the products, lots and customers it reports on. Each stage writes to the same append-only log, and every stage has a named human owner.
- Report in. Public web form, email alias, staff reporting from the field. LOPDP consent, 45 questions.
- Intake ticket. Helpdesk team, first-touch timestamp, acknowledgment to the reporter. The clock starts at awareness.
- Case record. Case ID, seriousness criteria, the 15/30-day clock, product and patient. Seven-stage workflow, four roles.
- Coding. MedDRA for the event, WHODrug for the product, version pinned per case.
- AI assist. Prepares, suggests and follows up; a human confirms every call.
- Evaluation and sign-off. Causality, expectedness, officer signature before release.
- Submission. Package for ARCSA's portal now, E2B(R3) XML by August 2027.
One append-only event log underlies all seven stages: every action, human or system, written once with who, what, when and why, nothing edited or deleted. The audit trail, the compliance evidence pack, the inspection response, and data-subject requests are all one log, viewed differently; the evidence pack is a query, built on demand for any regulator.
The next layer
The AI layer is designed to sit on top of the native automation instead of replacing it. It is sequenced after go-live, not before, and is gated behind an open architecture decision (Bucket B, liability L-015) before it builds. Each piece is designed to take follow-up work that falls on the analyst today and close it in the background, ranked by how much human time it would return. Every case is designed to store the MedDRA and WHODrug versions used to code it, so a disputed code could be reproduced exactly as it was submitted.
- Scheduling over WhatsApp (Stage II). When a case needs the reporter, an agent will offer three or four open slots from the team calendar, read the reply, book the call and log it on the case. It is designed to save 15 to 30 minutes per case, on the WhatsApp integration already running in the group.
- Seriousness pre-classification (Stage II). A model will read the event description when the case is created and propose serious or non-serious with a confidence level. A person will confirm at triage, so the right clock starts hours earlier.
- MedDRA and WHODrug suggestions (Stage IV). Spanish free text in, ranked MedDRA lowest-level terms and WHODrug entries out, designed for the biggest time sink in manual work. The person will verify and decide; the system will keep the model, the prompt and the decision for audit.
- Recontact before auto-close (Stage III). Before a case closes after three unanswered attempts, an agent will try other channels (WhatsApp, SMS, a second email), so fewer reachable cases get written off as not reportable.
The model will be allowed to prepare (schedule, draft, gather), suggest with a confidence score, and follow up across channels, with every action logged next to the human call. The model will never be allowed to decide seriousness, choose the causality result, sign for the officer, or transmit anything to the regulator. Seriousness, causality, the officer's signature and transmission to ARCSA stay as traceable human decisions by design; an inspector will not accept "the model decided" as an answer, so the design does not ask one to.
What is running today
The case-handling spine runs on the production instance, built to the workflow our pharmacovigilance lead designed. Her rule was simple and non-negotiable: the regulatory clock does not stop. The days remaining render on every case and every kanban card, including while the team waits on a reporter or a lab result.
Role-gated access covers four groups (analyst, pharmacovigilance officer, regulatory manager, general manager), with case data visible only to them and no administrator back door. Automated follow-through covers acknowledgment to the reporter, reminders on missed follow-ups, a causality deadline, and a day-10 escalation to management if a case is stalling. Reporter data is protected, with consent captured at intake and a published privacy section built for the standard's data-protection article.
This is tested end to end on the live instance with test records. No live adverse-event cases have been processed yet; the first live cases follow the November 4 go-live.
The result
Seven stages, with a human gate before submission. Four role groups, access by role, no back door. Seven automated escalations, on Ecuador business hours. One append-only record, audit trail and evidence pack.
I presented this architecture at Seton Hall Law's Latin America Healthcare Compliance program in Bogotá in September 2026, to compliance officers, regulatory counsel and pharma in-house teams from across the region, who read it as an immediate risk rather than a topic.
It is built to travel. A second company gets its own scoped space on the same system (setup, not a rebuild). The evidence pack is a query, so one append-only log answers any regulator: ARCSA, ANVISA or COFEPRIS. And it covers a segment others skip: Spanish-language regulated pharma, on the same clock everywhere, with no global vendor built for it.
What this proves
Put the audit outside the model. Log every call with input hash, version, confidence and the human decision, so the model can change without the record changing.
Build the regulator's clock into the record. Start it where the law starts it, show it where people work, and escalate before the deadline instead of reporting after it.
Let the model suggest, keep a person on the trigger. Map which steps a regulator cares about and keep every one of them with a named human role.
See the board, invent the system, build it.