VerifiedEvidence: highv1.0.0

Risk Evaluation

A formal assessment of a drug's potential safety risks, sometimes resulting in a required mitigation strategy such as restricted distribution or mandatory counselling.

Last reviewedDarrin Baines IP Ltd

Concept Architecture

How medicine-safety risk evaluation supports decisions

Risk evaluation is the structured assessment of a medicine's potential harms, the uncertainty around them, and the measures needed to use the medicine safely. It brings together pre-authorisation evidence, pharmacovigilance, benefit-risk reasoning, and risk-minimisation planning. This page explains how a safety signal becomes a characterised risk, how mitigation is selected, and how effectiveness and unintended burdens are evaluated over the medicine's lifecycle.

Hazard, risk, and uncertainty are different

A hazard is a potential source of harm, while risk combines the probability and consequences of that harm in a defined population and use context. Uncertainty describes what is not known about either component. Separating these ideas prevents a serious but extremely rare event from being discussed in the same way as a common, less severe event.

TermMeaning in medicine safetyExample question
HazardA type of harm that the medicine could causeCan the medicine cause severe liver injury?
RiskThe likelihood and severity of harm under specified conditionsHow often does severe liver injury occur at the approved dose?
Safety signalInformation suggesting a new or changed causal association that warrants investigationDoes a cluster of reports exceed what would be expected?
Identified riskA harmful occurrence supported by sufficient evidence of associationIs the causal relationship adequately established?
Potential riskA suspected association for which evidence remains insufficientWhat evidence would confirm or refute the concern?
Missing informationA safety-relevant evidence gap in a population or settingWhat is known about use during pregnancy?

The evaluation is specific to how a medicine is used

Risk is not a fixed property of a product in isolation. Dose, duration, indication, co-medication, comorbidity, age, pregnancy, monitoring, adherence, and care setting can all change the probability or consequences of harm. The assessment must therefore define the population, exposure, comparator, outcome, time horizon, and clinical pathway.

  • Intrinsic factors include age, genetics, organ function, pregnancy, frailty, and disease severity.
  • Extrinsic factors include interacting medicines, prescribing practices, monitoring capacity, health literacy, and access to care.
  • Product factors include formulation, route, dose, administration requirements, and packaging.
  • System factors include diagnostic delay, fragmented records, staffing, and the availability of specialist services.

Evidence comes from complementary sources

No single source provides a complete safety profile. Randomised trials offer controlled comparisons but may be too small, short, or selective to detect rare or delayed harms. Observational data and spontaneous reports extend surveillance to routine practice but introduce confounding, reporting bias, missingness, and exposure-measurement problems.

Useful evidence includes:

  • Non-clinical studies and pharmacological mechanisms.
  • Randomised trials, extensions, and pooled safety analyses.
  • Spontaneous adverse-event reports and case series.
  • Registries, electronic health records, claims, dispensing data, and linked datasets.
  • Epidemiological studies using active comparators and appropriate causal methods.
  • Product-quality investigations, medication-error reports, and patient experience.
  • Evidence from related medicines when class effects are biologically credible.

From a signal to a characterised risk

A safety signal is a prompt for investigation, not proof that a medicine caused an event. Evaluation examines the quality, consistency, timing, biological plausibility, dechallenge or rechallenge, dose response, alternative explanations, and comparative frequency. The result should state whether the concern is confirmed, refuted, or still uncertain.

  1. Detect the signal. Identify new or changing information from surveillance, studies, literature, or product use.
  2. Validate the signal. Check case quality, duplication, exposure, outcome definitions, and whether the information is genuinely new.
  3. Prioritise the signal. Consider seriousness, preventability, public-health impact, exposure, and strength of evidence.
  4. Assess causality and frequency. Integrate clinical review, epidemiology, pharmacology, and comparative evidence.
  5. Characterise the risk. Define affected populations, severity, timing, reversibility, dose relationship, and modifiable factors.
  6. Select and test action. Update information, introduce proportionate mitigation, and specify how its effectiveness will be measured.

Quantifying adverse-event risk

Absolute measures show the expected number of additional events and are often easier to use in clinical decisions than relative measures alone. Relative measures remain useful for causal comparison and for understanding whether an event rate differs materially between treatments. Both require uncertainty intervals and a clearly defined follow-up period.

If (p_T) is the event risk with treatment and (p_C) is the comparator risk, the absolute risk increase is:

$$ ARI = p_T - p_C $$

When (ARI>0), the number needed to harm is:

$$ NNH = \frac{1}{ARI} $$

If the event risk is 3% with treatment and 1% with the comparator, the absolute increase is 2 percentage points and the NNH is 50 over the stated period. This estimate does not show severity, reversibility, subgroup variation, or causal certainty and should not be interpreted alone.

Rare-event evidence needs careful denominators

Counts of spontaneous reports cannot usually estimate incidence because reporting is incomplete and the number of exposed patients is uncertain. Disproportionality analyses can detect reporting patterns but do not establish causality or quantify clinical risk. When possible, active surveillance should use validated outcomes, measurable exposure time, and an appropriate comparator.

An incidence rate can be written as:

$$ Incidence\ rate = \frac{Number\ of\ new\ events}{Total\ person\ time\ at\ risk} $$

The risk window, treatment discontinuation, latency, recurrent events, competing risks, and ascertainment must match the suspected mechanism.

Benefit-risk evaluation keeps harms in clinical context

Risk evaluation informs but does not replace benefit-risk assessment. A serious risk may be acceptable for a treatment of a life-threatening disease with substantial benefit and no good alternative, yet unacceptable for a mild condition with safer options. The judgment should make the magnitude, certainty, timing, and distribution of both benefits and harms explicit.

Decision makers should examine:

  • The treated condition's severity, prognosis, and unmet need.
  • The magnitude and certainty of clinically relevant benefits.
  • The frequency, seriousness, preventability, and reversibility of harms.
  • Alternative treatments and the risks of delayed or absent treatment.
  • Patient preferences and variation in how outcomes are valued.
  • Whether mitigation can reduce risk without undermining access or benefit.

Routine and additional risk minimisation

Routine measures include approved product information, labelling, packaging, prescription status, and ordinary pharmacovigilance. Additional measures are used when routine communication is insufficient for a specific serious risk. The intervention should target a defined cause or behaviour and impose the least burden consistent with safe use.

Additional measures can include:

  • Targeted educational materials for patients or healthcare professionals.
  • Prescriber, pharmacy, or healthcare-setting certification.
  • Laboratory testing or clinical monitoring before or during treatment.
  • Documented safe-use conditions before prescribing or dispensing.
  • Controlled or restricted distribution.
  • Pregnancy-prevention programmes or patient registries.
  • Limited dispensing quantities or requirements for specialist initiation.

Regulatory programmes differ by jurisdiction

The United States Food and Drug Administration may require a Risk Evaluation and Mitigation Strategy, or REMS, for certain medicines with serious safety concerns when additional measures are needed to ensure benefits outweigh risks. European Union risk management plans describe important risks, missing information, pharmacovigilance activities, and risk-minimisation measures for authorised medicines. Similar objectives may be implemented through different legal terms, documents, and responsibilities elsewhere.

REMS should not be used as a generic label for every safety plan. A report should name the jurisdiction, legal programme, product, indication, current status, required participants, and applicable version or date.

Elements to assure safe use

Some US REMS include elements to assure safe use when specific serious risks require actions beyond communication. Requirements can apply to prescribers, pharmacies, healthcare settings, patients, or monitoring processes. These controls may include certification, restricted dispensing settings, evidence of safe-use conditions, monitoring, or enrolment in a registry.

The design must connect each element to the mechanism of harm. A burdensome restriction without a credible pathway to risk reduction can delay treatment without improving safety.

Measuring whether mitigation works

Implementation is not the same as effectiveness. Process measures show whether required actions occurred, while outcome measures show whether knowledge, behaviour, exposure, or adverse outcomes changed. Evaluation should also test burden, access, disparities, workarounds, and unintended clinical consequences.

Evaluation levelExample measureWhat it answers
ReachProportion of intended participants receiving materialsDid the programme reach its audience?
KnowledgeProportion correctly identifying the key risk and actionWas the message understood?
BehaviourProportion completing required testing before treatmentDid practice change as intended?
Clinical outcomeRate or severity of the targeted adverse eventWas the risk reduced?
Access and burdenDelays, abandonment, travel, workload, or unequal completionDid the programme create harmful barriers?

Access and equity are safety outcomes too

Risk controls can protect patients while also creating delays, administrative cost, geographic barriers, or unequal access. Patients with limited transport, digital access, language support, insurance, specialist availability, or time may be disproportionately excluded. A complete evaluation therefore treats access, burden, and equity as part of programme performance.

Mitigation should be redesigned when equally safe alternatives can reduce burden. Exemptions or streamlined processes must not weaken the control needed for the specific serious risk.

Economic consequences of risk and mitigation

Adverse events generate treatment costs, monitoring costs, productivity losses, reduced quality of life, and mortality. Mitigation programmes also consume patient, provider, manufacturer, and health-system resources. Pharmacoeconomic analysis should include both avoided harms and programme costs, along with the health consequences of delayed or forgone treatment.

A simplified incremental net cost of mitigation can be expressed as:

$$ Incremental\ cost = Programme\ cost + Access\ consequences - Avoided\ adverse\ event\ cost $$

Cost-effectiveness analysis should additionally include quality-adjusted life-years or other health outcomes. It should not treat reduced medicine use as a safety success if eligible patients lose beneficial treatment.

Updating the assessment over the product lifecycle

Risk evaluation continues after authorisation because exposure expands, use changes, and rare or delayed harms become observable. New evidence can strengthen, narrow, or refute an earlier concern. Risk measures should be modified or removed when evidence shows that a different approach better protects patients.

Triggers for reassessment include a new safety signal, expanded indication, new formulation, major utilisation change, class warning, confirmatory study, mitigation failure, or evidence of access burden. Every change should preserve the rationale, evidence date, version, and responsibilities.

Common mistakes

Medication-safety decisions can be distorted when signals, risks, and regulatory tools are treated as interchangeable. The following errors commonly overstate certainty or overlook the consequences of intervention. Avoiding them makes the assessment both safer and more proportionate.

  • A spontaneous-report count is not an incidence rate.
  • A statistical association does not by itself establish causality.
  • A labelled adverse event does not automatically require an additional mitigation programme.
  • A REMS is a specific US regulatory programme, not a generic synonym for risk management.
  • Completion of programme steps does not prove that the targeted clinical harm decreased.
  • Reduced prescribing does not demonstrate successful mitigation if appropriate access also fell.
  • Average programme performance can conceal unequal burden across populations and locations.
  • Risk evaluation should not discuss harm without the treatment's benefits and alternatives.

Reporting a risk evaluation transparently

A transparent report connects each risk claim to its evidence and each mitigation measure to a testable objective. It separates known risks, suspected risks, missing information, and residual uncertainty. It also identifies who bears programme responsibilities and how new evidence will change the plan.

  • Define the medicine, indication, population, dose, comparator, outcome, and time at risk.
  • Report absolute and relative measures with uncertainty and evidence limitations.
  • Distinguish signals, identified risks, potential risks, and missing information.
  • State the rationale, mechanism, and proportionality of each mitigation measure.
  • Pre-specify process, knowledge, behaviour, clinical, access, burden, and equity outcomes.
  • Name the regulatory jurisdiction, programme, current version, and review date.
  • Record the decision rule for maintaining, modifying, or retiring the measure.

The decision standard

A high-quality risk evaluation does not attempt to eliminate every possible adverse event. It determines which risks are sufficiently credible and consequential to require action, selects proportionate controls, and tests whether those controls improve safe use without causing avoidable loss of benefit or access. The conclusion should remain revisable as the medicine, evidence, and conditions of use change.

Frequently Asked Questions (6)

  • What is risk evaluation?

    A formal assessment of a drug's potential safety risks, sometimes resulting in a required mitigation strategy such as restricted distribution or mandatory counselling.

    Source: FDA, Risk Evaluation and Mitigation Strategies

  • What does risk evaluation assess about a drug's safety?

    Risk evaluation is a formal assessment of the safety risks a drug carries, judging what harms it may cause and how serious and likely they are. Where the risks are significant, it can lead to a required mitigation strategy, such as restricting who may prescribe or dispense the drug, mandatory patient counselling, or monitoring, so that the drug can be used safely despite its dangers. This is how a drug whose benefits outweigh serious risks can still reach the patients who need it. Judging a drug's risks to manage them is its purpose. The FDA's Risk Evaluation and Mitigation Strategy framework describes this.

    Source: FDA, Risk Evaluation and Mitigation Strategy

  • Why is risk evaluation conducted?

    Risk evaluation is conducted to assess a drug's potential safety risks and determine whether measures are needed to manage them, so that a drug whose risks are significant can still be used safely if its benefits outweigh those risks with appropriate safeguards. So risk evaluation is conducted to enable the safe use of drugs with notable risks, which is why it can lead to required measures, since some drugs carry serious risks that must be actively managed, and assessing these risks and putting in place safeguards such as restricted distribution or counselling allows such drugs to be used while protecting patients, balancing the drug's benefits against its risks.

    Source: FDA, Risk Evaluation and Mitigation Strategies

  • What measures can result from risk evaluation?

    Measures resulting from risk evaluation can include restricted distribution, limiting who may prescribe or dispense the drug; mandatory counselling or education for prescribers or patients; monitoring requirements; or other safeguards designed to manage the identified risks and ensure the drug's safe use. So risk evaluation can lead to a range of risk-management measures, which is why it addresses serious safety concerns, since managing a drug's risks may require controlling how it is distributed and used and ensuring those involved understand the risks, and these measures aim to ensure that the drug's benefits outweigh its risks in practice by actively managing the potential for harm.

    Source: FDA, Risk Evaluation and Mitigation Strategies

  • How does risk evaluation support safe drug use?

    Risk evaluation supports safe drug use by identifying a drug's potential safety risks and, where needed, requiring measures to manage them, so that a drug with significant risks can be used with safeguards that reduce the potential for harm. So risk evaluation supports safe use by managing identified risks, which is why it can require mitigation measures, since some beneficial drugs carry risks that must be controlled for their safe use, and assessing these risks and implementing appropriate safeguards allows such drugs to remain available while protecting patients, ensuring that the benefits can be obtained without unacceptable harm from the risks the drug carries.

    Source: FDA, Risk Evaluation and Mitigation Strategies

  • How does risk evaluation relate to a risk mitigation strategy?

    Risk evaluation relates to a risk mitigation strategy in that the evaluation assesses a drug's risks and may result in a required mitigation strategy, a formal plan of measures such as restricted distribution or counselling to manage those risks. So risk evaluation can lead to a mitigation strategy, which is why the two are connected, since assessing that a drug's risks require active management leads to the measures that constitute the strategy, and together they ensure that a drug with significant risks is used safely, with the evaluation identifying the concern and the mitigation strategy providing the safeguards to address it in practice.

    Source: FDA, Risk Evaluation and Mitigation Strategies

Trust Record

Verified by Dr Darrin Baines

British health economist

Professional identity: darrinbaines.org

Verification date: 22 Sep 2026

Content version: 1.0.0

Canonical Identity

Term code
HE-PE-DD-065

Stable URI · Machine-readable · Resolvable · CC BY 4.0