Drug Diversion Audit: What to Test, How Often, and Who Does It
A drug diversion audit is a periodic, independent test of whether the controls over controlled substances work the way your policy says they do, from the purchase order to the waste record. It is not the same as daily monitoring, an investigation or a DEA inspection. This page sets out what to test at each step, which intervals are fixed by rule, and the guides that cover each test.
Hospital version: 8 sections, 63 weighted items. No account or login.
Audit, monitoring, investigation, inspection
The four are often used as if they meant the same thing. They answer different questions and are done by different people.
| Activity | Question it answers | Who does it |
|---|---|---|
| Monitoring | Does anything in this week's transactions need a second look? | The people who run the program |
| Audit | Do the controls, and the monitoring itself, work the way the policy says? | Someone who does not operate the control being tested |
| Investigation | What happened in this one event, and who was involved? | The response team named in your protocol |
| DEA inspection | Do the registrant's records and security meet the regulations? | The regulator |
A white paper written for hospital internal auditors draws the same line: monitoring and surveillance are management's job, and the audit then tests them. In its words, “All ‘systems of control’ in the controlled substance lifecycle – from procurement to disposal – should be audited” (Ahlstrom, AHIA and Baker Tilly, 2018).
What to test at each step
1. Ordering and receiving
Test whether the person who places an order is ever the person who receives it, and whether each invoice can be matched to a purchase order and a receiving record. For Schedule II drugs that means the Form 222 or the CSOS record. In a 2024 survey of 66 hospital pharmacy respondents in 31 states, 86.7% of health systems and 88.9% of single facilities reported consistent segregation of duties for ordering and receiving, but only 53.4% and 63.9% said they had a process to audit it (Bastow et al., 2024). The figures are self-reported.
2. Inventory and counts
Confirm the required inventory is on file: after the initial inventory, a registrant must take a new one “at least every two years” (21 CFR 1304.11(c)). Then watch a count being done. The internal audit white paper describes vault counts where numbers written on the side of containers suggested that “true blind counts are not always being conducted” (Ahlstrom, 2018). In the hospital pharmacy survey, the most common interval for auditing vault inventory was monthly, reported by 73.3% of health systems and 61.1% of single facilities (Bastow et al., 2024).
3. Access
Compare the list of people who can open each cabinet, vault and compounding room with the current staff list and each person's role. Look for shared logins, access that outlived a transfer or a resignation, and override privileges nobody can explain.
4. Dispensing, waste and returns
Sample waste and return transactions and check each one for a witness, for the time between removal and waste, and for pairs of staff who always witness for each other. Then ask who reads the discrepancy reports. The same white paper gives the example of discrepancy reports for nursing unit dispensing cabinets that “are not routinely reviewed to assess unresolved discrepancies” (Ahlstrom, 2018).
5. Records
Ask for a specific record and time how long it takes to produce. Inventories and other required records must be kept and be available for inspection “for at least 2 years” (21 CFR 1304.04(a)), and a registrant must maintain “a complete and accurate record” of each substance received or otherwise disposed of (21 CFR 1304.21(a)). For hospitals, the Medicare conditions of participation add that “Current and accurate records must be kept of the receipt and disposition of all scheduled drugs” (42 CFR 482.25(a)(3)).
6. Investigations and reporting
Pull a sample of closed investigations. Check that each followed the written protocol, that the corrective actions were completed, and that the required reports went out on time. A theft or significant loss must be reported to the DEA Field Division Office in writing “within one business day of discovery”, with a complete and accurate DEA Form 106 filed “within 45 days after discovery” (21 CFR 1301.76(b)). In a hospital, abuses and losses of controlled substances must also be reported to the person responsible for the pharmaceutical service and, as appropriate, to the chief executive officer (42 CFR 482.25(b)(7)). State rules may add their own deadlines.
How often
The federal rules cited on this page fix a few intervals: the inventory at least every two years, records kept for at least two years, and the one-business-day and 45-day reporting deadlines above. Every other interval is set by your own policy, and the audit checks whether you kept to it.
These are the review intervals the hospital assessment asks about. They are the assessment's own items, not regulatory requirements:
- Off-hour access to pharmacy logged and reviewed daily
- Kit checkout and return logs reconciled within 24 hours
- Controlled substance returns reconciled within 72 hours
- Controlled substance overrides tracked and reviewed monthly
- Periodic access audit — all ADC users reviewed quarterly
- Interdisciplinary diversion prevention committee meets quarterly (or more frequently)
- Annual program effectiveness review with documented improvements
How often to audit the program as a whole is also a local decision. The internal audit white paper says only that “The frequency of reviews, audits and responsibilities must also be determined” (Ahlstrom, 2018).
Who does it, and where a self-assessment fits
The value of an audit comes from independence: the reviewer does not operate the control being tested. In a hospital that is usually internal audit or compliance working with pharmacy and nursing. In a small pharmacy it may be an owner, a colleague from another site or an outside reviewer.
A self-assessment is not an audit. It records your own answers and nobody tests them. Its use is in scoping: the sections where you score lowest are where an audit should sample first.
Sources
- Ahlstrom J. Drug diversion prevention and detection: using a comprehensive risk and internal audit approach. Association of Healthcare Internal Auditors and Baker Tilly, 2018.
- Bastow SS, Borrelli EP, Lucaci JD, Nelkin H, Graves A, Hays A. Insights from a National Survey on Controlled Substance Diversion Practices in U.S. Hospital Pharmacies. Pharmacy. 2024;12(6):183. doi:10.3390/pharmacy12060183
- 21 CFR 1301.76, 1304.04, 1304.11 and 1304.21, and 42 CFR 482.25, 2025 annual edition.
Read on October 5, 2026. Educational content, not legal advice; check current federal and state rules before relying on a deadline.
What the public record shows
Counted from the DivertGuard case registry, which is compiled from board actions, court filings and press releases. It is a record of documented cases, not an estimate of how often diversion happens.
The guides, in order
13 guides on this topic.
Access audits
Who can open the cabinet, the vault and the compounding room, and whether each login still belongs to someone who needs it.
-
Audit Pharmacy Tech Access Controls to Catch Diversion Early
Pharmacy techs should each have unique credentials scoped to their role — shared logins eliminate individual accountability and make it…
-
Auditing Pharmacy Tech Access to Controlled Substances
Review pharmacy tech system permissions regularly — access should match current job duties, and any override or unlock privilege beyond tha…
-
Compounding Room Access Needs a Real Audit Trail
If anyone can enter the compounding room without a logged badge swipe or witness signature, controlled substance waste and overfill are eff…
Waste, witness and count audits
Sampling waste and return transactions, witness pairs and counts.
-
Audit Witness Pairing Patterns to Close Waste Documentation Gaps
Collusion risk rises when the same two employees consistently pair for waste witnessing. Audit co-signer combinations routinely — identical…
-
Blind Witnessing: A Hidden Gap in Waste Documentation
Blind witnessing — when a colleague signs off on waste without observing the disposal — is a common diversion gap. Confirm your policy…
-
Controlled Substance Waste & Discrepancy Documentation: Policies That Pass Audits
How to document medication waste, partial doses, and discrepancies so your diversion prevention program survives an audit.
-
Why Controlled Substance Count Reconciliation Stops Diversion Early
Unexplained count discrepancies — even small ones — can signal diversion. Review controlled substance count records daily and investigate…
-
Closing the Loop on Return-to-Stock Discrepancies
When a returned dose is credited back to inventory without a second verifier confirming vial, quantity, and condition match the original di…
Order and record audits
Comparing orders with what was documented, and checking that the inventory and the records behind it can be produced.
-
Auditing Post-Op Analgesia Orders for Diversion Signals
Compare post-op opioid orders against documented pain scores and procedure type; frequent overrides, early refills, or standing PRN orders…
-
Controlled Substance Inventory Requirements: DEA Rules for Pharmacies Explained
DEA biennial inventory requirements, what must be counted, when to count, and how to keep the records audit-ready.
-
Controlled Substance Recordkeeping: Every Document a DEA Audit Checks
The complete recordkeeping framework for controlled substances — inventory records, receiving/dispensing logs, transfer records, and the two-year retention rule.
Pulling the data
Queries, measures and calculators for building the audit sample from data you already have.
-
Drug Diversion Surveillance Without Expensive Software: A SQL + Analytics Playbook
How to build practical diversion surveillance with the data you already have — SQL patterns for waste, overrides, and provider behavior.
-
Analytics Dashboard
KPIs, benchmarks, sample SQL, and Power BI/Tableau layout blueprint for surveillance
-
Tough Issues
High-risk scenarios with annotated SQL: PCA, multidose vials, overrides, waste lag
-
Using AI to Build Diversion Reports
Where a clinician starts: what to ask IT, what to do when IT says no, which data you already have, which AI capabilities matter, realistic timelines, and how to validate without exposing PHI
-
Compliance Tools & Calculators
DEA 106 deadline calculator, controlled substance discrepancy calculator, and waste percentage calculator
When the audit finds something
Moving from a finding to a report and an investigation.
-
How to Report Drug Diversion: A Step-by-Step Guide for Healthcare Staff
Who to tell, what to document, and when a report must reach the DEA — a practical reporting guide for pharmacy staff, nurses, and compliance officers.
-
Investigation Playbook
Step-by-step guide from initial report through resolution and corrective action
-
DEA 106 Filing Guide
When to file, step-by-step form completion, common mistakes, and sample scenarios
-
DEA Audit Readiness
Prepare for a DEA inspection: inventory, Form 222 and CSOS orders, Form 106 loss reports, Form 41 destruction and renewals, with a free self-assessment.
What the assessment checks
The hospital assessment has 8 sections. These are the 9 items it scores under Data Analytics & Surveillance:
- Automated surveillance system (e.g., NarxCare, dispense cabinet analytics software, or equivalent)
- Regular review of ADR (admin discrepancy report) patterns by unit and shift
- Controlled substance usage benchmarking — outlier detection by practitioner
- Waste rate analysis — practitioners with abnormally high waste flagged
- Wasted medication reconciliation rate (wasted vs. documented)
- After-hours controlled substance dispensing reviewed for unusual patterns
- Patient-controlled analgesia (PCA) discrepancy monitoring
- Controlled substance overrides tracked and reviewed monthly
- DEA 106 reports tracked and trended over time
The other sections: Governance & Program Oversight (7), Controlled Substance Lifecycle Management (9), Perioperative & Procedural Areas (6), Personnel & Access Controls (8), Physical Security (7), Incident Reporting & Investigation (9), Regulatory Compliance (8). Each item is weighted, the score updates as you answer, and the result exports to PDF or CSV.