Audits that test what happens, not only what is written.
Eunomia carries out commercial compliance audits and gap analyses for pharmaceutical and biotech companies in the UK. We test selected activities against the ABPI Code, anti-bribery expectations and your own procedures, and deliver risk-rated findings with a practical remediation roadmap and CAPA support.
For compliance leaders and leadership teams in pharmaceutical and biotech companies in the UK: a baseline audit for a growing company, a pre-inspection or pre-launch review, or independent testing after a complaint or Code ruling.
Find the gaps before someone else does
Policies can exist on paper while contracts, payments and approvals tell a different story. A useful audit tests whether the purpose was recorded, the right people reviewed the activity, the contract, payment and evidence agree, and exceptions were escalated.
From requirements to action
How Eunomia can help
We agree the scope and sample, review documents, test selected activities end to end, interview process owners and walk through systems. Findings are risk-rated and linked to evidence, then turned into a remediation roadmap and CAPA with effectiveness checks.
We audit as practitioners who design and run these processes. Findings come with practical fixes, and we can support remediation through programme design, training and shared-service capacity if you need it.
HCP engagement, hospitality and fair market value audits
04
Materials review and certification audits
05
Transparency and disclosure data audits
06
PMCPA audit readiness and remediation support
07
CAPA design and effectiveness checks
08
Internal audit programme design
What this gives you
Risk-rated findings linked to specific activities and evidence
A remediation roadmap with owners, dates and dependencies
Follow-up checks that show whether corrective actions worked
The rules in the UK
What shapes compliance audits in the UK…
UK compliance audits are usually tested against the industry code, UK enforcement guidance and your own procedures. These are the main external references. Each summary links to its official source below.
PMCPA audits of company procedures
Under paragraph 12.4 of the PMCPA Constitution and Procedure, where the Code of Practice Appeal Board rules that there is a breach of the Code, it may require an audit of the company’s procedures in relation to the Code, carried out by the Authority.
SFO guidance on compliance programmes
Explains how the UK Serious Fraud Office assesses whether a corporate compliance programme works in practice. It is enforcement guidance, not a pharmaceutical certification standard.
Bribery Act guidance, Principle 3
A commercial organisation assesses the nature and extent of its exposure to potential external and internal risks of bribery by persons associated with it. The guidance describes the assessment as periodic, informed and documented.
How gap analysis improves a healthcare compliance internal audit. Our article explains how to test selected activities, examine evidence and prioritise weaknesses rather than only confirm that policies exist, with findings connected to a risk, an owner and a follow-up check.
This overview is informational and does not constitute legal advice. Scope and application should be confirmed for the organisation, activity and counterparty in question. Sources checked September 2026.
Scope may include document review, operational testing, interviews, system walkthroughs, risk-rated findings and a practical remediation roadmap.
Can the PMCPA require an audit?
Yes. Under paragraph 12.4 of the PMCPA Constitution and Procedure, where the Code of Practice Appeal Board rules that there is a breach of the Code, it may require an audit of the company’s procedures in relation to the Code, carried out by the Authority.
Can you support PMCPA audit readiness and remediation?
Yes. Support can assess governance, procedures, approvals, training, HCP engagement, FMV, transparency, monitoring and certification against relevant expectations.
What is the difference between an audit and a gap analysis?
An audit validates past adherence by testing what happened. A gap analysis compares obligations with how the business operates now, to assess current effectiveness and future readiness. We often use both.
How is an effective CAPA plan structured?
It identifies root causes, actions, accountable owners, due dates, dependencies and effectiveness checks, with progress tracked through governance.
Do you carry out GxP inspections?
No. Our audits cover commercial healthcare compliance, such as promotion, HCP engagement, anti-bribery and disclosure. They are not a substitute for a GxP inspection programme.
Tell us what is on your desk.
We will listen, ask a few questions and recommend the right scope—without obligation or pressure.