Independent audit · ISO 19011:2018

Australia’s COVID-19 Vaccine Safety Monitoring: An Independent Audit

Did Australia’s drug regulator, the Therapeutic Goods Administration (TGA), carry out the enhanced vaccine safety monitoring it promised? A four-year documentary audit of its compliance, tested against the plan’s own commitments.

In November 2020, National Cabinet endorsed the Australian COVID-19 Vaccination Policy, which committed to enhanced vaccine safety monitoring and identified the TGA's COVID-19 Vaccine Pharmacovigilance Plan as part of that framework. In February 2021, the TGA published its COVID-19 Vaccine Safety Monitoring Plan, setting out the enhanced monitoring framework for the rollout. This is an independent audit and freedom-of-information investigation of whether that monitoring can be shown to have happened, assessing the TGA’s compliance against the plan’s own commitments using the international auditing standard ISO 19011:2018, Australian National Audit Office guidance, and open-source analysis of public records.

The audit is grounded in the fundamental principles of public accountability and transparency: when public institutions make significant commitments, their implementation should be capable of independent verification through an adequate documentary record.

The audit assesses 19 outputs, comprising the Plan's 17 numbered strategy items and two additional governance outputs, each evaluated for documentary evidence of implementation.

It examines 68.4 million doses (91.2% of Australia’s rollout) across four years. The question is narrow and verifiable: can the implementation of the vaccine safety monitoring plan, and the regulator’s compliance with its commitments, be independently confirmed through the documentary record, given the role enhanced monitoring was intended to play alongside provisional approval?

The audit did not identify documentary evidence that the TGA systematically implemented the enhanced vaccine safety monitoring framework described in its February 2021 plan, leaving compliance unverifiable from available records. Of 19 audited outputs, only 3 are fully documented; the remaining 16 are partially documented or undocumented from the available material.


Regulatory and accountability framework


The purpose of this audit is best understood in the context of how the enhanced monitoring promised under the Australian COVID-19 Vaccination Policy was operationalised through the TGA’s Safety Monitoring Plan. This diagram maps that policy commitment against the statutory framework for provisional registration and distinguishes sponsor obligations, the TGA’s operational commitments, Commonwealth accountability requirements and relevant non-statutory international guidance. View the diagram

What the audit found



Questions and answers


Each answer below is framed by the audit's evidentiary standard: what can be confirmed on the documentary record.

Did the TGA implement its COVID-19 vaccine safety monitoring plan?

The audit found that 16 of 19 outputs are partially documented or undocumented, and the regulator could produce no implementation records when directed to search for them.

Didn't Australia already have extensive vaccine safety monitoring?

Yes. The audit does not dispute that vaccine safety monitoring occurred; TGA officials themselves described this monitoring to the Senate as part of their routine “day-to-day processes”. It examines whether the enhanced monitoring promised under the National Cabinet-endorsed Australian COVID-19 Vaccination Policy, and subsequently set out in the TGA's February 2021 Plan, was implemented as committed and can be independently verified from the documentary record.

AusVaxSafety, for example, conducted 6.8 million post-vaccination surveys. Strategy 2.4 of the Plan committed to “Establish real-time collaboration with COVID-19 active surveillance activities for safety signal detection and analysis.” The question is therefore not whether AusVaxSafety existed or collected substantial data, but whether the documentary record demonstrates that collaboration and how active-surveillance data were integrated with TGA signal detection and analysis to deliver the commitment. The available record does not establish this.

The Plan gave operational form to a national commitment to enhanced safety monitoring for a mass vaccination rollout. Whether implementation was centralised or distributed, the record should be capable of establishing what was implemented and how performance was assessed, consistent with Commonwealth recordkeeping and performance requirements. Verifying the Plan as an integrated framework also requires evidence of how its elements worked together and how decisions were made.

Who conducted this research?

The audit was conducted independently by Paul Rekaris, a public policy analyst. It applies the international auditing standard ISO 19011:2018 to public and freedom-of-information records. The research has been cited in the Australian Senate and provided for consideration to the Senate Community Affairs Legislation Committee and the Australian National Audit Office. It is an independent citizen audit and invites a formal audit of its findings.

Can the findings be checked?

Yes. Every finding is traceable to a public or FOI-released source, and the full evidence base, methodology and dataset are openly published under a CC BY 4.0 licence for independent verification.

Can the audit be proven wrong?

Yes. The audit adopts a falsifiability principle: every finding can be tested against evidence and revised if the evidence requires. Any output classified as not documented can be overturned by the production of a single relevant record. The findings hold only while the documentary record remains absent, and any correcting evidence would be incorporated with transparent version history.


Permanent record


Audit report (SSRN) 10.2139/ssrn.6333058
Dataset and methodology paper (SSRN) 10.2139/ssrn.6610438
Archive (Zenodo) 10.5281/zenodo.17731054
Dataset (Harvard Dataverse) 10.7910/DVN/BDKZQJ
Dataset (Mendeley Data) 10.17632/y5wmt6f8j9
Preprint (SocArXiv) 10.31235/osf.io/sb4gz
National edeposit (NLA) NED476889S65171
Australian Web Archive (NLA) GitHub repository archive
Permanent archive (Arweave) retrieve via turbo or arweave.net · verify on-chain
Bitcoin timestamp point-in-time proof of the audit's existence and integrity · Block 942725 · 29 March 2026

Cited and corroborated


Australian Senate Hansard, 24 March 2026 — cited in the Senate · watch the speech.

Office of the Australian Information Commissioner, Decision [2025] AICmr 54 (26 March 2025).

TGA evidence to the Senate Community Affairs Legislation Committee, 9 October 2025.

TGA written answer to Senate Question on Notice 559 (DHDA SQ25-001584).

Read the full audit and evidence base →