Controlled Substance Audit Checklist
- kagonzalez444
- Jul 10
- 8 min read
During my years with DEA, I could usually tell early in an inspection whether an organization truly understood controlled substance compliance. It wasn't because of their policies. It was because of their audit process.
A good audit tells you far more than whether the paperwork exists. It tells you whether the organization's controls actually work.
More than once, I found that what looked like a simple documentation issue turned out to be something much larger. A missing invoice. An unresolved discrepancy. A perpetual inventory that didn't reconcile. Those were rarely the actual problem - they were usually the first clue that a control had already failed.
That’s why a controlled substance audit checklist shouldn’t just help you prepare for an inspection. It should help you identify weaknesses before an investigator ever walks through the door.
What should your audit checklist accomplish?
A strong audit checklist is not just a list of documents to pull for an inspector. It should help your organization answer a more serious question: can you demonstrate accountability for every controlled substance you receive, store, dispense, administer, transfer, waste, and destroy?
Hospitals, pharmacies, manufacturers, distributors - they all have different operational risks. But they're all trying to answer the same question: Can we account for every controlled substance under our registration?
A good audit also helps distinguish between a simple documentation mistake and evidence of a broader control weakness. A late signature might point to a training issue. Repeated inventory discrepancies or weak access controls usually deserve a much closer look.
Is your DEA registration and authority in order?
Before reviewing transactions, confirm the legal and operational foundation of the site. The audit should verify that DEA registration information is current, business activity aligns with the registration, and all controlled substance handling occurs within the scope of authorized operations.
This is also the stage to identify who holds responsibility for oversight. Many organizations have policies that mention accountability but do not clearly assign it. During an audit, that gap matters. If no one owns ordering oversight, discrepancy review, vault access review, or biennial inventory completion, the control structure is weaker than it appears.
For multi-site organizations, be careful about assuming standardization. Central policies often look strong, while execution varies from site to site. An effective checklist tests local practice, not just enterprise intent.
Can your inventory withstand scrutiny?
If I wanted to get a feel for an organization’s compliance program, inventory was often one of the first places I’d look. If an investigator asked you to account for every bottle of Oxycodone that entered your facility over the last six months, could you do it? Could you produce the records? Could you explain every discrepancy? Those are the questions a good audit should answer long before DEA ever arrives.
The real question is not whether inventories exist. It is whether they are accurate, traceable, and performed consistently. Dates, drug names, dosage forms, package sizes, and exact or estimated counts should be documented correctly where required. If the organization relies on a perpetual inventory for selected schedules or high-risk drugs, the audit should test whether the record matches actual stock.
Pay close attention to adjustments. I’ve seen organizations spend hours trying to explain inventory adjustments they didn’t fully document. By that point, the issue wasn’t just the discrepancy – it was the inability to explain how it happened or what was done to investigate it. Manual corrections, unexplained count changes, undocumented breakage, and repeated variances deserve closer review. A checklist should require validation of how discrepancies are identified, escalated, investigated, resolved, and trended over time.
Once I had a sense of whether inventory controls were reliable, I would naturally shift my focus to how controlled substances entered the organization. That's where ordering and receiving controls become so important. Strong controls at the receiving dock create the foundation for every record that follows.
How strong are your purchasing and receiving controls?
Ordering and receiving controls often reveal whether accountability begins at the front end or only after a problem is discovered. One thing I learned during my years with DEA is that problems at the receiving dock rarely stay at the receiving dock. If accountability breaks down when controlled substances first enter the building, every record that follows becomes harder to trust. That's why your audit should verify that orders are authorized, records are complete, and receiving staff confirm quantities and products against what was ordered and delivered.
In practice, stronger programs separate duties where possible. The person placing orders should not have unchecked authority to receive, reconcile, adjust, and resolve discrepancies alone. Smaller organizations may not be able to fully separate every function, but they still need compensating controls such as management review, exception reporting, and periodic independent audits.
Once controlled substances are inside the facility, the next question becomes who has access to them. Even the strongest ordering process can be undermined if access controls are weak. That's why physical security deserves just as much attention as recordkeeping.
Who really has access to your controlled substances?
A controlled substance audit checklist should examine physical security and access management in detail. This includes vaults, safes, cages, automated dispensing cabinets, locked medication rooms, after-hours access, key control, badge access, and alarm or surveillance practices where applicable.
In my experience, organizations often focus on whether the vault is locked while overlooking who actually has access to it. That's backwards. A secure lock means very little if too many people have the keys.
It also helps to compare policy to workflow. A facility may require dual verification for specific transactions, but if staff routinely bypass that step to keep operations moving, the written control is not functioning. Audit work should account for real behavior, not ideal behavior.
Access controls are only part of the picture. Once controlled substances leave secure storage, organizations also need to demonstrate that every dose is properly documented from dispensing or administration through its final disposition.
Can you account for every dose?
For pharmacies and clinical settings, this is where diversion vulnerabilities often become visible. The checklist should test whether dispensing and administration records are complete, timely, and reconcilable to inventory movement. Prescriber information, patient records, dispensing logs, administration documentation, returns, and waste records should align.
Waste deserves special attention. Organizations often have written waste procedures, but actual practice may be inconsistent across shifts, units, or facilities. Witnessed waste that is not truly witnessed, late documentation, and repeated waste patterns tied to specific users are all warning signs. A good audit checklist requires targeted sampling in this area rather than a general confirmation that waste documentation exists.
If automated systems are used, the audit should compare system data to physical counts and supporting records. Reports are helpful, but they are not self-validating. Exception reports, override reports, canceled transactions, reversals, and user activity logs should be reviewed with enough depth to identify unusual patterns. None of that information has much value, however, if it can't be reconstructed later. That's where complete, organized recordkeeping becomes essential.
Can your records tell the whole story?
Many organizations underestimate how quickly recordkeeping problems become enforcement problems. Your checklist should confirm that all required records are readily retrievable, organized, complete, and retained for the applicable period. If records exist but cannot be produced promptly, that is still a control concern.
Focus on whether records can tell a complete story. Can the organization trace a controlled substance from receipt through final disposition? Can it explain transfers, reverse distribution, destruction, theft reporting, or significant loss analysis with supporting documentation? If the answer depends on piecing together emails, handwritten notes, and partial system entries, the process is too fragile.
This is also where inconsistency across departments becomes costly. Pharmacy may maintain one standard while nursing units, clinics, or satellite locations follow another. A checklist should test the full chain, not only the department that sees itself as compliance owner.
Even organizations with strong documentation will occasionally encounter discrepancies. What often separates an effective compliance program from a struggling one is how those discrepancies are investigated and resolved.
How do you investigate discrepancies?
A checklist that does not address investigations is incomplete. Every registrant should be able to show how discrepancies are identified, who reviews them, what timelines apply, how findings are documented, and when escalation occurs.
This is one of the clearest distinctions between a mature compliance program and a reactive one. Mature programs investigate variances promptly, document the outcome, identify trends, and strengthen controls. Reactive programs clear exceptions without root cause analysis or allow unresolved discrepancies to age until they become normal.
The audit should also test whether the organization understands reporting thresholds and response expectations for theft or significant loss. The exact determination can be fact-specific, and that is where experienced judgment matters. A checklist should not force simplistic conclusions, but it should require a documented decision process supported by facts.
Strong investigations don't happen by accident. They depend on clear policies, effective training, and leadership that reinforces accountability throughout the organization.
Are your policies, training, and oversight working together?
Documents alone do not prevent diversion. The checklist should evaluate whether policies are current, operationally realistic, and aligned with actual regulatory obligations. Procedures that are copied from another setting or written so broadly that staff cannot follow them create false comfort.
Training should be role-based. Staff who receive controlled substances need different instruction than staff who administer them, investigate discrepancies, or oversee compliance. The audit should verify not only that training occurred, but that it addressed site-specific risks and was reinforced through supervision and monitoring.
Oversight is the final test. Leaders should review controlled substance metrics, discrepancy trends, access changes, high-risk transactions, and recurring exceptions on a regular schedule. If oversight happens only before an inspection or after an incident, the control environment is already behind.
By this point, you've evaluated every major component of a controlled substance compliance program. The final step is understanding how to put those pieces together into an audit process that actually strengthens your organization rather than simply preparing it for an inspection.
How can you audit without creating blind spots?
The best checklist is not the longest one. It is the one your organization can apply consistently, document clearly, and use to trigger corrective action. Overly broad checklists often produce superficial reviews. Narrower, risk-based checklists usually produce better findings because they force closer testing of the areas most likely to fail.
That said, a checklist should never replace judgment. If data shows unusual ordering patterns, repeated wasting by the same employee, or inventory adjustments concentrated in one location, the audit should expand beyond the form. Enforcement risk rarely announces itself in neat categories.
For that reason, many organizations benefit from an outside perspective, especially when they want to pressure-test internal assumptions before a DEA inspection or after a known control concern. An outside review can be valuable because fresh eyes often spot assumptions, blind spots, and control weaknesses that internal teams no longer see.
One of the biggest misconceptions I see is that organizations prepare for a DEA inspection by organizing paperwork. That's certainly part of it, but it's not what gives an investigator confidence. Confidence comes from consistency. It comes from being able to explain how your controls work, demonstrate that they're followed, and show how discrepancies are identified and resolved.
During my years with DEA, I wasn't looking for perfection. I was looking for accountability. Organizations that understood their risks, investigated problems promptly, and strengthened their controls were almost always in a much better position than those that assumed everything was fine because no one had complained.
A good audit isn't about checking boxes. It's about challenging your own assumptions before someone else does. That's what turns compliance from a yearly exercise into an everyday practice.
Compliance isn't built during a DEA inspection. It's demonstrated during one. It's built every day before the investigator ever arrives.



Comments