Audits → DEA Audit Preparation
Purpose
Prepare for a real DEA inspection by working through an 8-category readiness checklist tied to the records the DEA Diversion Investigator will actually ask to see. The DEA prep audit is not a regulated filing — it's an internal pre-flight that turns "the inspector is coming Friday" from a panic into a managed checklist.
This is general product information about CS Logbook, not legal advice. CS Logbook's checklist is a preparation aid; it does not certify compliance or define inspection scope, which is set by the inspecting authority. Verify current requirements with the DEA Diversion Control Division and your state veterinary/pharmacy board.
This prep audit is not itself a regulated filing — the DEA does the inspecting; you don't pre-register your readiness. The records an inspector reviews are governed by Title 21 CFR — see records maintenance & availability (incl. retention), recordkeeping content, theft/loss rules, disposal under Part 1307 + DEA Form 41, and security rules and the inventory rule. Verify the specific requirements — and any retrieval-time expectations — directly with the DEA.
When to use it
- A DEA visit has been scheduled — the standard case. Diversion offices typically schedule 1-4 weeks ahead; use the prep audit as your shared work plan during that window.
- An unannounced visit happened and you want a post-mortem — run the prep audit retrospectively, mark items as "had-it" or "missing", and use the result to build an action plan against the next visit.
- A follow-up inspection is required — if a previous DEA visit ended with a Memorandum of Understanding (MOU) or a finding, a follow-up is likely. Run the prep audit with extra rigor on the previously-flagged categories.
- Annual readiness drill — even with no visit pending, an annual prep audit catches drift in records-availability that the periodic biennial alone won't.
- State-board parallel — many state veterinary boards conduct similar inspections; the same 8 categories cover most state-board scopes (with state-specific additions handled in a custom internal-audit template).
The DEA prep audit is conducted by clinic staff — not an inspector. Its value is finding gaps before they show up to the DEA. A clinic that runs the prep audit and discovers a missing 90-day spot-check log has 5 days to find it (or document why it's missing); the same clinic discovering it 30 minutes into a real inspection has 30 minutes.
Walkthrough
The DEA audit prep flow has three pages:
/audits/dea → List of prep audits (current + historical)
/audits/dea/new → Create-prep wizard (audit metadata + auto-generated checklist)
/audits/dea/[auditId] → Prep detail (8-category checklist + document requests + findings)Step 1 — Open the DEA audits list
Navigate to /home/<your-clinic>/audits/dea. The page shows historical and current DEA prep audits, sorted by scheduled_date descending. Each row shows the audit name, type (scheduled / unannounced / follow_up / routine), status (preparing / in_progress / completed / follow_up_required), and the assigned DEA inspector (if known).
Screenshot of the DEA audits list landing page coming in a 15d-2 follow-up — this guide ships ahead of the audit-history-table data-test instrumentation.
Click Create Audit Prep in the top-right. The wizard opens at /audits/dea/new.
Step 2 — Fill the create-prep wizard
The create-prep wizard collects the audit metadata:
- Audit name — clinic-internal label (e.g., "DEA Prep — Spring 2026"). Required, max 255 chars.
- Audit type —
scheduled(most common — DEA called and named a date),unannounced(record after the fact),follow_up(post-MOU), orroutine(annual drill, no visit pending) - Scheduled date — when the DEA inspector is expected (or the date you're targeting for an internal drill)
- Actual date — leave blank if the visit hasn't happened; fill in after the fact
- Inspector name + badge number + DEA office + inspector contact — all optional; fill in if known. Some Diversion offices share these in the scheduling call; others share them only at the door.
Click Create Audit Prep. The action:
- Inserts a row into
dea_audit_preparations - Auto-generates the 24-item, 8-category checklist (
dea_audit_checklistsrows) — the canonical list the Diversion office will work through. The categories are:- Inventory records — biennial PDF, spot-check audits, perpetual-inventory reconciliation, container logs
- Prescription records — patient dispensing logs (90-day sample), prescription copies, patient consent forms (if required)
- Acquisition records — supplier invoices, receipt documentation
- Disposal records — DEA Form 41 records, waste logs, disposal method documentation
- Theft/loss reports — DEA Form 106 filings, investigation reports, law-enforcement coordination
- DEA registrations — current DEA registration certificate, state controlled-substance license, DEA-registered veterinarian credentials
- Security measures — storage security documentation, access-control logs, security-camera footage (if applicable)
- Training documentation — staff training records, controlled-substance handling policies, signature/staff-identification log
The wizard redirects to the prep detail page.
Step 3 — Work the 8-category checklist
The detail page renders each category as an expandable section showing its items + a completion-progress indicator. For each item:
- Click the checkbox to mark complete
- Type completion notes describing what record you have / where it lives / who pulled it
- Notes are required on completion — "found it" is not enough. The point is establishing custody-of-record.
Screenshot of the 8-category checklist (collapsed view + one expanded category with item checkboxes and completion-notes textarea) coming in a 15d-2 follow-up.
Common completion-note patterns:
- Have the record —
"Biennial 2024-10-07; PDF in clinic safe + cloud backup; signed by Dr. Reed (DEA reg AB1234567)" - Have the record but it's incomplete —
"Spot-check log present 2026-01-15 through 2026-04-30; Q1 2026 entry is missing — see CAPA #47" - Don't have the record (yet) —
"Form 41 records: none on file — clinic has had no formal disposals since registration. Verified with practice manager." - Substituting an alternate record —
"Patient consent forms not used; surgery records cover the dispense events. Will produce surgery records as substitute on request."
Items can be uncompleted (toggle the checkbox) — the completion notes are preserved as audit trail.
Step 4 — Manage document requests
The DEA inspector typically requests specific documents during the visit. The Document Requests card on the prep detail page tracks each request:
- Document type — short label (e.g., "Form 41", "Biennial PDF", "Q1 2026 spot check")
- Document name — the specific filename or label of what was provided
- Date range — what time period the document covers (start + end)
- Description — context (who pulled it, where it lives, any caveats)
- Received date — when the inspector confirmed receipt
Screenshot of the document-request management section coming in a 15d-2 follow-up.
Use this card during the visit to track what's been handed over. The post-visit retention copy of the dea_audit_preparations record + linked dea_audit_documents rows IS your record of what the inspector saw.
Step 5 — Record findings
If the inspector raises any concerns or makes any observations, record each one as a finding via the Findings card. Each finding captures:
- Category —
violation(regulatory finding requiring response),recommendation(best-practice suggestion),observation(informational),commendation(positive note) - Severity —
critical/major/minor/informational - Description — what the inspector said, in detail
- Regulation citation — the specific regulation section the inspector cited, if known
- Finding date — when the inspector raised it
- Response required — boolean; flips on automatic deadline tracking
- Response deadline — when your written response is due (the DEA sets this; confirm the date on the notice you receive)
- Corrective action required — boolean; pairs with a CAPA in the discrepancies queue
- Corrective action description — what you'll do to address it
The prep audit's violations_found boolean and violations_description + corrective_actions_required + findings_summary capture the audit-level rollup.
Step 6 — Export the document package
When the visit is complete (or in flight, if you need to hand the inspector a packet), use Export Document Package to produce a PDF bundle of:
- The cover page with audit metadata (inspector + date + audit type)
- The 8-category checklist with completion status + notes
- The document-request log
- Findings (if any)
- Linked CAPAs (if any)
The package can be exported as a single PDF (pdf_bundle) or a ZIP archive containing each component (zip). Both formats include the same data — pick PDF for handing the inspector a single file, ZIP for an internal archive copy.
Step 7 — Update the prep status + transition to follow-up
After the visit, update the audit:
- Status →
completedif no follow-up is required - Status →
follow_up_requiredif the DEA's response indicates a follow-up visit - Findings summary — narrative summary of what came up
- Violations found / description — fill if any violations were cited
- Corrective actions required — flip on if CAPA work is needed; create the CAPAs via the discrepancies queue and link back
If follow_up_required, schedule the follow-up audit prep with audit_type='follow_up' referencing this audit's findings.
Field reference
Create-prep wizard inputs
| Field | Label | Type | Required | Validation / Notes |
|---|---|---|---|---|
auditName |
Audit name | text | ✓ | min 1 char, max 255 |
auditType |
Audit type | select | ✓ | enum: scheduled / unannounced / follow_up / routine |
scheduledDate |
Scheduled date | date | optional | nullable; ISO date |
actualDate |
Actual date | date | optional | nullable; ISO date; usually filled post-visit |
inspectorName |
Inspector name | text | optional | max 255 |
inspectorBadgeNumber |
Inspector badge number | text | optional | max 50 |
deaOffice |
DEA office | text | optional | max 255 |
inspectorContact |
Inspector contact (email) | optional | RFC-valid email; max 320 |
Per-category checklist item
Each item is auto-generated by generate8CategoryChecklist (24 items across 8 categories — see Step 2 list).
| Field | Description |
|---|---|
checklistItemId |
UUID; system-set on auto-generation |
completionNotes |
Required when marking complete; describes the record + custody chain |
Document request
| Field | Label | Type | Required | Validation / Notes |
|---|---|---|---|---|
documentType |
Document type | text | ✓ | min 1, max 100; short label |
documentName |
Document name | text | ✓ | min 1, max 255 |
documentDescription |
Description | textarea | optional | nullable |
dateRangeStart |
Date range start | date | optional | nullable; ISO date |
dateRangeEnd |
Date range end | date | optional | nullable; ISO date |
Finding
| Field | Label | Type | Required | Validation / Notes |
|---|---|---|---|---|
findingCategory |
Category | select | ✓ | violation / recommendation / observation / commendation |
severity |
Severity | select | ✓ | critical / major / minor / informational |
description |
Description | textarea | ✓ | min 1 char |
regulationCitation |
Regulation citation | text | optional | max 100; the regulation section the inspector cited |
findingDate |
Finding date | date | ✓ | ISO date |
responseRequired |
Response required | boolean | default false | flips on response-deadline tracking |
responseDeadline |
Response deadline | date | optional | required if responseRequired=true |
correctiveActionRequired |
Corrective action required | boolean | default false | pairs with a CAPA |
correctiveActionDescription |
Corrective action description | textarea | optional | required if correctiveActionRequired=true |
Resulting database rows
| Table | Columns set | When |
|---|---|---|
dea_audit_preparations |
account_id, audit_name, audit_type, scheduled_date, inspector_*, status='preparing', created_by | wizard submit |
dea_audit_checklists |
audit_id, category, item_description, item_order (24 rows × 8 categories) | wizard submit (auto) |
dea_audit_checklists |
completed=true, completion_notes, completed_at, completed_by | each item check |
dea_audit_documents |
audit_id, document_type, document_name, document_description, date_range_*, received_date | each request |
dea_audit_findings |
audit_id, finding_category, severity, description, regulation_citation, response_required, response_deadline, corrective_action_required | each finding |
dea_audit_preparations |
status, findings_summary, violations_found, violations_description, corrective_actions_required | post-visit update |
Edge cases
Inspector identity unknown until day-of
Sometimes the Diversion office shares the inspector name only at the door. Fill inspectorName and inspectorBadgeNumber retroactively from the prep detail page; the wizard accepts blank values at create time. The prep can be in_progress without inspector details — the checklist is independent of identity.
A category genuinely doesn't apply
A clinic that has never had a theft/loss event has no Form 106 to surface. Mark the items in that category complete with a note like "No theft/loss events on record since DEA registration; verified via theft_loss_incidents table query 2026-04-30". The DEA expects the non-existence to be confirmed too — silence is worse than "we checked, there's nothing".
Unannounced visit + no time to create prep
For an unannounced inspection, there's no prep window. After the visit, create the prep audit retrospectively with audit_type='unannounced' and actualDate populated. The 24-item checklist still applies; mark each item with a post-visit completion note describing what the inspector saw + how the record was located. This becomes your audit trail.
Follow-up inspection that revisits prior findings
When DEA returns for a follow-up, create a new prep audit with audit_type='follow_up' and reference the prior dea_audit_preparations.id in the audit name (e.g., "Follow-up to DEA Prep — Spring 2026"). The 24-item checklist is regenerated; the prior audit's findings + CAPAs are accessible via the discrepancies queue, but the follow-up prep gets a fresh checklist of records to surface.
Soft warning: clinic has no biennial on file
If the clinic's most recent biennial is more than 2 years old (or absent entirely), the prep detail page surfaces a soft warning at the top: "Most recent biennial inventory is 27 months old — DEA expects a biennial within 24 months. Consider running a biennial before the inspection." The user can dismiss; the warning is informational, and the underlying requirement is the DEA's (see the DEA inventory rule). (dea_audit_preparations.violations_found is available for tracking any finding the inspector cites.)
Hard block: CAPA on a finalized audit
Once the prep audit's status='completed' and the prep is finalized via the standard finalize flow, no new findings or CAPAs can be added. The audit-trail integrity is preserved per the same audits_finalize_lock migration that covers internal audits. New work goes into a new follow-up prep audit.
Common mistakes
- Creating the prep audit only after the visit ends. The whole point is the prep window; without it, the audit is just a record of what happened. Schedule the prep when DEA calls.
- Marking items complete without notes. "Found it" is the same as "didn't find it" 6 months from now when you can't remember. Notes are the audit trail.
- Treating the 8 categories as exhaustive. State boards add categories (CA's BAH inspection, IL's controlled-substance program). Build a custom internal-audit template for state-specific additions; use the DEA prep for federal scope only.
- Not exporting the document package. The package is your record of what the inspector saw. Export it before closing the audit.
- Skipping the post-visit update. An audit stuck at
preparingafter the visit is a phantom — it suggests the visit didn't happen. Update status, fill findings, close the loop. - Forgetting the post-MOU follow-up. If DEA issued a Memorandum of Understanding with corrective actions and a follow-up date, schedule the follow-up prep audit at
audit_type='follow_up'immediately. Six months later is too late to start preparing. - Conflating the prep audit with a real DEA filing. The prep audit is internal — it's never sent to the DEA. The records the prep audit collects are what the DEA inspects. Don't conflate the two.
Related
- Audits — overview — full audit lifecycle and where DEA prep fits
- Biennial inventory — the DEA's periodic inventory count that's the headline record inspectors ask for
- Internal audit — the quarterly checklist-driven internal review (use the DEA Compliance Pre-Audit template for a state-board-style readiness drill independent of an actual inspection)
- Theft/loss reporting — the Form 106 flow whose records DEA inspects under category 5 of the prep checklist
- Discrepancies & CAPA — where post-visit corrective actions land
- Sprint 16 DEA audit prep feature plan — internal architecture reference (8-category template generator, document-package export, finding lifecycle)
- Glossary § DEA CFR citations — quick reference to the regulations DEA inspectors cite