Audit, monitoring, investigation, inspection

The four are often used as if they meant the same thing. They answer different questions and are done by different people.

ActivityQuestion it answersWho does it
MonitoringDoes anything in this week's transactions need a second look?The people who run the program
AuditDo the controls, and the monitoring itself, work the way the policy says?Someone who does not operate the control being tested
InvestigationWhat happened in this one event, and who was involved?The response team named in your protocol
DEA inspectionDo the registrant's records and security meet the regulations?The regulator

A white paper written for hospital internal auditors draws the same line: monitoring and surveillance are management's job, and the audit then tests them. In its words, “All ‘systems of control’ in the controlled substance lifecycle – from procurement to disposal – should be audited” (Ahlstrom, AHIA and Baker Tilly, 2018).

What to test at each step

1. Ordering and receiving

Test whether the person who places an order is ever the person who receives it, and whether each invoice can be matched to a purchase order and a receiving record. For Schedule II drugs that means the Form 222 or the CSOS record. In a 2024 survey of 66 hospital pharmacy respondents in 31 states, 86.7% of health systems and 88.9% of single facilities reported consistent segregation of duties for ordering and receiving, but only 53.4% and 63.9% said they had a process to audit it (Bastow et al., 2024). The figures are self-reported.

2. Inventory and counts

Confirm the required inventory is on file: after the initial inventory, a registrant must take a new one “at least every two years” (21 CFR 1304.11(c)). Then watch a count being done. The internal audit white paper describes vault counts where numbers written on the side of containers suggested that “true blind counts are not always being conducted” (Ahlstrom, 2018). In the hospital pharmacy survey, the most common interval for auditing vault inventory was monthly, reported by 73.3% of health systems and 61.1% of single facilities (Bastow et al., 2024).

3. Access

Compare the list of people who can open each cabinet, vault and compounding room with the current staff list and each person's role. Look for shared logins, access that outlived a transfer or a resignation, and override privileges nobody can explain.

4. Dispensing, waste and returns

Sample waste and return transactions and check each one for a witness, for the time between removal and waste, and for pairs of staff who always witness for each other. Then ask who reads the discrepancy reports. The same white paper gives the example of discrepancy reports for nursing unit dispensing cabinets that “are not routinely reviewed to assess unresolved discrepancies” (Ahlstrom, 2018).

5. Records

Ask for a specific record and time how long it takes to produce. Inventories and other required records must be kept and be available for inspection “for at least 2 years” (21 CFR 1304.04(a)), and a registrant must maintain “a complete and accurate record” of each substance received or otherwise disposed of (21 CFR 1304.21(a)). For hospitals, the Medicare conditions of participation add that “Current and accurate records must be kept of the receipt and disposition of all scheduled drugs” (42 CFR 482.25(a)(3)).

6. Investigations and reporting

Pull a sample of closed investigations. Check that each followed the written protocol, that the corrective actions were completed, and that the required reports went out on time. A theft or significant loss must be reported to the DEA Field Division Office in writing “within one business day of discovery”, with a complete and accurate DEA Form 106 filed “within 45 days after discovery” (21 CFR 1301.76(b)). In a hospital, abuses and losses of controlled substances must also be reported to the person responsible for the pharmaceutical service and, as appropriate, to the chief executive officer (42 CFR 482.25(b)(7)). State rules may add their own deadlines.

How often

The federal rules cited on this page fix a few intervals: the inventory at least every two years, records kept for at least two years, and the one-business-day and 45-day reporting deadlines above. Every other interval is set by your own policy, and the audit checks whether you kept to it.

These are the review intervals the hospital assessment asks about. They are the assessment's own items, not regulatory requirements:

  • Off-hour access to pharmacy logged and reviewed daily
  • Kit checkout and return logs reconciled within 24 hours
  • Controlled substance returns reconciled within 72 hours
  • Controlled substance overrides tracked and reviewed monthly
  • Periodic access audit — all ADC users reviewed quarterly
  • Interdisciplinary diversion prevention committee meets quarterly (or more frequently)
  • Annual program effectiveness review with documented improvements

How often to audit the program as a whole is also a local decision. The internal audit white paper says only that “The frequency of reviews, audits and responsibilities must also be determined” (Ahlstrom, 2018).

Who does it, and where a self-assessment fits

The value of an audit comes from independence: the reviewer does not operate the control being tested. In a hospital that is usually internal audit or compliance working with pharmacy and nursing. In a small pharmacy it may be an owner, a colleague from another site or an outside reviewer.

A self-assessment is not an audit. It records your own answers and nobody tests them. Its use is in scoping: the sections where you score lowest are where an audit should sample first.

Sources

Read on October 5, 2026. Educational content, not legal advice; check current federal and state rules before relying on a deadline.

What the public record shows

Counted from the DivertGuard case registry, which is compiled from board actions, court filings and press releases. It is a record of documented cases, not an estimate of how often diversion happens.

The guides, in order

13 guides on this topic.

Access audits

Who can open the cabinet, the vault and the compounding room, and whether each login still belongs to someone who needs it.

Waste, witness and count audits

Sampling waste and return transactions, witness pairs and counts.

Order and record audits

Comparing orders with what was documented, and checking that the inventory and the records behind it can be produced.

Pulling the data

Queries, measures and calculators for building the audit sample from data you already have.

When the audit finds something

Moving from a finding to a report and an investigation.

What the assessment checks

The hospital assessment has 8 sections. These are the 9 items it scores under Data Analytics & Surveillance:

  • Automated surveillance system (e.g., NarxCare, dispense cabinet analytics software, or equivalent)
  • Regular review of ADR (admin discrepancy report) patterns by unit and shift
  • Controlled substance usage benchmarking — outlier detection by practitioner
  • Waste rate analysis — practitioners with abnormally high waste flagged
  • Wasted medication reconciliation rate (wasted vs. documented)
  • After-hours controlled substance dispensing reviewed for unusual patterns
  • Patient-controlled analgesia (PCA) discrepancy monitoring
  • Controlled substance overrides tracked and reviewed monthly
  • DEA 106 reports tracked and trended over time

The other sections: Governance & Program Oversight (7), Controlled Substance Lifecycle Management (9), Perioperative & Procedural Areas (6), Personnel & Access Controls (8), Physical Security (7), Incident Reporting & Investigation (9), Regulatory Compliance (8). Each item is weighted, the score updates as you answer, and the result exports to PDF or CSV.

Other topics

Share: LinkedIn X Facebook

Last reviewed: September 2026 · Content is educational, not legal advice.