Employers routinely outsource testing administration to a consortium or third-party administrator, and most of that is entirely permissible. But a specific set of decisions belongs to the employer's Designated Employer Representative and cannot be handed off. Confusing the two categories is how a program that looks well-run fails an audit.
What a DER is
49 CFR § 40.3 defines the Designated Employer Representative as an individual identified by the employer as able to receive communications and test results from service agents, and who is authorized to take immediate action to remove employees from safety-sensitive duties and to make required decisions in the testing and evaluation process.
Two capabilities are named there, and they are the heart of the role: receive results and take immediate action.
The duties that stay with the employer
Removing an employee from safety-sensitive duty
This is the clearest one. The authority to pull someone out of a safety-sensitive function is the reason the DER exists. A service agent may notify, advise and document — but the removal decision is the employer's, exercised through the DER.
Receiving verified test results from the MRO
Under § 40.167, the MRO reports verified results to the DER. A C/TPA may be in the communication path in some configurations, but the employer must have a DER who is able to receive them and act.
Decisions in the testing and evaluation process
Determining whether a post-accident test is required, acting on a refusal, deciding what happens after a verified positive — these are employer decisions. A vendor can supply information and process; it cannot own the determination.
Selecting the SAP and directing the return-to-duty process
The employer decides. § 40.287 requires the employer to provide the employee with a list of SAPs; the employer, not the service agent, carries the obligation.
What a C/TPA may do
A C/TPA may legitimately handle a great deal:
- Administering the random-selection pool and generating selections
- Scheduling collections and managing collection-site relationships
- Maintaining records on the employer's behalf
- Coordinating with laboratories and MROs
- Providing program documentation and audit support
§ 40.347 sets out what service agents may do. It is a long list, and outsourcing the mechanics is normal and sensible.
The line that gets crossed most often
§ 40.355 is the section worth reading twice, because it lists what service agents must not do. Among them:
- A service agent must not act as a DER.
- A service agent must not make decisions the regulation assigns to the employer, including removal decisions and determinations about refusals.
- A service agent must not receive results in place of an employer that has no DER.
The practical failure looks like this: an employer signs with a C/TPA, names nobody internally, and treats the vendor's account manager as the DER. Everything runs smoothly until a verified positive arrives and there is no one at the employer authorized to remove the driver. The program was non-compliant from the day it started; the positive result is just when it became visible.
A checklist worth running
Ask these five questions about your own program:
- Is a specific person at our company named as DER, in writing?
- Does that person have actual authority to remove someone from safety-sensitive duty today, without waiting for approval?
- Is there a named backup for when they are unavailable?
- Can the MRO reach them directly?
- If a verified positive arrived at 4:55pm on a Friday, what happens next, and who does it?
If any answer is "the vendor handles that," the program has a gap.
Records are the employer's obligation
§ 382.401 places retention duties on the employer. A C/TPA may hold records physically, but the obligation does not transfer. That distinction matters most at exactly the wrong moment — when a vendor relationship ends, or when an auditor asks for something the vendor has archived.
Two practical consequences:
- Know how to get your records out, and how long that takes.
- Know what happens to them if you change vendors.
FAQ
Can a C/TPA serve as our DER?
No. Under 49 CFR 40.355, a service agent must not act as a Designated Employer Representative. The DER must be an individual identified by the employer who is authorized to take immediate action to remove employees from safety-sensitive duties.
Who decides whether a post-accident test is required?
The employer, acting through the DER. A service agent may supply information and process support, but the determination is the employer's.
Can we outsource the random-selection pool?
Yes. Administering a random-selection pool and generating selections is among the functions a C/TPA may perform under 49 CFR 40.347.
If our C/TPA keeps our records, are we still responsible for retention?
Yes. The retention duties under 49 CFR 382.401 sit with the employer. A service agent may hold records physically, but the obligation does not transfer, and it continues after the vendor relationship ends.
Does the DER need a backup?
The regulation does not prescribe a specific backup structure, but the DER must be able to receive results and take immediate action. In practice a program with a single DER and no alternate cannot meet that standard during absences.
This article describes federal requirements under 49 CFR Parts 40 and 382 and is provided for general information. It is not legal advice. Employers remain responsible for their own compliance decisions and should consult qualified counsel or a DOT specialist about their specific circumstances.