Segregation Of Duties: Drug Accountability Needs Three Separate Roles
By Eshaan Jain, Senior Consultant, Mphasis

At many trial sites, one person orders investigational product (IP) from the sponsor or depot, signs for it upon arrival, and later reconciles what was dispensed with what came back. The same login, badge, and person are involved throughout the process. A records review of investigational product accountability is a standard part of how the FDA evaluates a clinical investigator's site during an inspection, which makes that one-person setup exactly the combination an inspector is trained to notice.1
I have spent 15 years moving between two disciplines that both treat this kind of role overlap as a defined risk rather than a judgment call. At PwC, I worked inside IT general controls (ITGC) engagements built around segregation of duties (SoD): the principle that no single person should authorize a transaction, take custody of the resulting asset, and record or review the outcome without another person checking the work. At T-Mobile, engaged through Mphasis, I am lead product owner for Salesforce/Vlocity CPQ (configure, price, quote), where I design the permission sets and role hierarchies that decide who in a CPQ/CLM (contract lifecycle management) system can create a quote, approve it, or execute the resulting contract. Those two lanes point at the same finding when I look at a clinical trial site: segregation of duties is usually written into a standard operating procedure (SOP), but it is rarely built into whatever system actually tracks the inventory.
The specific combination that matters in drug accountability is ordering IP, receiving it, and reconciling the log against what was dispensed and returned. When one person can do all three without a second signature or a system-level block, the check that is supposed to catch a mismatched count, a missing dose, or a fabricated return never fires. Regulators have cited this pattern when a site's own accountability numbers no longer matched.
Ordering, Custody, And Reconciling Are Three Separate Functions
The internal controls framework most auditors use, developed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), splits a transaction into three functions that belong with three different people: authorizing it, holding custody of the resulting asset, and recording or reviewing the transaction afterward.2 Applied to a drug supply cycle, ordering IP is the authorization step, receiving and storing it is custody, and reconciling the accountability log against dispensing and return records is the recording and review step. A site that assigns all three to one coordinator or one unblinded pharmacist has collapsed a three-person control into a single task, whether or not anyone set out to create a shortcut.
The same logic governs IT systems, not just financial ones. An auditor checking segregation of duties in an application looks at whether the person who can request a change is also the person who approves and deploys it, because that pairing removes the independent check that the control is meant to provide.3 A drug accountability log is a system of record in exactly that sense, even when it is a paper binder rather than software. The person entering "50 tablets received" and the person later confirming "50 tablets accounted for" need to be two different signatures, the same reason a single engineer should not write and approve their production change.
What GCP Requires For Investigational Product Records
International Council for Harmonization (ICH) E6(R3), the current GCP guideline, is specific about what a site must record for investigational product: delivery, inventory, use by each trial participant, and the return or destruction of unused product, with dates, quantities, and lot or batch numbers documented throughout.4 It says far less about who is allowed to perform each of those steps. A site can satisfy the requirement by having one person keep a complete, well-organized log that no one else has independently checked.
That gap between records existing and records being checked is where accountability breaks down in practice. A 2017 FDA warning letter to a clinical investigator laid out the failure mode directly: the site's own accountability records showed drug dispensed to two subjects that did not reconcile against the quantity subjects reportedly took, the amount that should have remained by calculation, and what was actually returned, with mismatches large enough that the FDA cited a failure to maintain adequate disposition records under 21 CFR 312.62(a).5 Nothing in the letter suggests the discrepancy surfaced before the inspection found it. That is the outcome: a working segregation of duties control exists to catch it early at the site, rather than leaving it for an inspector to count.
Map Roles To Actions In A Control Matrix
Most site-level SOPs handle this control with one sentence: the person receiving IP should not also perform reconciliation. A control matrix does more work than a policy sentence, because it maps specific people to specific permitted actions and applies one rule against that map: no single role should hold every action for the same product.
Building that matrix for a site takes three columns and one rule. The columns are the roles that interact with the investigational product: the principal investigator (PI), any sub-investigator, the unblinded pharmacist or designated dispenser, the study coordinator, and the monitor or clinical research associate (CRA) who reviews the site on a periodic basis. The rows are the three actions: ordering or requesting resupply, receiving and logging inventory into the accountability record, and reconciling that record against dispensing and return data. Run the rule against every row: if the coordinator both logs receipt and performs reconciliation, that pairing needs a second name attached to the reconciliation, even if the CRA does it on a monthly visit rather than in real time.
Permission Sets Enforce Segregation Of Duties Better Than A Policy Sentence
This is the same exercise I run when designing permission sets for a Salesforce CPQ/CLM environment. A user profile that can both create a quote and approve that same quote at any discount level is a segregation of duties finding waiting to happen, so the platform's permission architecture is designed to prevent such a profile from existing, rather than relying on a manager to notice it during a later review. An interactive response technology (IRT) system, which already tracks randomization and drug supply at most trial sites, can be configured the same way: give the user role that logs receipt of IP a different login than the user role that closes out a reconciliation record so the system itself blocks one account from completing the full cycle. A monitor no longer has to catch the overlap weeks later during a site visit because the system prevents it from happening.
Most Site Accountability Still Runs On Paper, And That Is Exactly The Risk
This control gap persists mainly because most site-level drug accountability still lives on paper logs or in a spreadsheet a coordinator maintains locally, rather than in a permissioned system that can enforce role separation the way an IRT platform or an enterprise resource planning (ERP) system can. A spreadsheet has no concept of a permission set. Anyone with the file can enter a receipt and later edit the same row to reconcile it, and the tool itself does nothing to stop that.
Where a site already runs an electronic inventory or IRT module for IP tracking, closing the gap does not require new procurement. This process requires configuring the existing roles so that receipt and reconciliation are handled by different logins, following the same permission-set discipline that prevents a quote creator from also being the quote approver. Where a site is still on paper, the practical version of the same control is a second, named signature on every reconciliation entry, from someone who did not log the corresponding receipt, written on the same page as the original entry rather than added later in a separate audit memo.
Before the next monitoring visit, pull the site's current IP accountability log and check one thing for each entry: do the same initials appear on both the receipt and reconciliation lines for the same lot? Wherever they do, treat it as a role assignment that needs a second name attached, through a system permission change where the site has one or a second signature requirement where it does not, before the next batch of product arrives.
References:
- FDA and HHS, "FDA Inspections of Clinical Investigators: Information Sheet," describing investigational product accountability, including shipping records and disposition of unused product, as a standard area FDA reviews under 21 CFR 312.62(a) during clinical investigator inspections: HHS / FDA information sheet (PDF)
- Samantha Schmitt, CPA (Withum), "Why Segregation of Duties Is Essential for Internal Control," New Jersey Society of CPAs, September 23, 2024, describing the COSO-based principle that no individual should initiate, authorize, record, and review a transaction without another person's involvement: NJCPA
- ISACA Journal, "What Every IT Auditor Should Know About Proper Segregation of Incompatible IT Activities," 2012, on segregation of duties as a risk-reduction control in IT environments and how auditors test for incompatible role combinations: ISACA Journal
- ICH E6(R3) Good Clinical Practice, FDA guidance for industry, Section 2.10.4, on investigational product delivery, inventory, participant-level use, and return or disposition record requirements: FDA guidance (PDF)
- FDA Warning Letter, Cassandra E. Curtis, MD (ref. 17-HFD-45-01-02), issued January 27, 2017, citing failure to maintain adequate investigational product disposition records under 21 CFR 312.62(a) after site accountability records did not reconcile against subject-reported use and returned quantities: FDA Warning Letters database
About The Author:
Eshaan Jain is a senior product consultant at Mphasis and serves as the lead product owner for Salesforce/Vlocity CPQ and CLM at T-Mobile, engaged through Mphasis’s consulting services. He previously worked as a senior technical program manager at Amazon, where he co-built a machine learning system that extracted clause-level data across a $40 billion annual supply chain contract portfolio with 95% accuracy. He is an IEEE senior member and holds professional membership with Forbes Tech Council, ACM, IEEE, Isaca, and AAAI.