Industry guide · Custom Software

Anti-Doping Case Management Software: When Chain of Custody Has to Survive a Hearing Panel

Anti Doping Compliance software visual showing flask round, map pin check, and file lock 2.
The short answer

If you run a testing programme of more than roughly 500 samples a year and your test distribution plan, whereabouts strike register and evidence file live in three different places, build. A focused first release covering test planning, mission assignment, chain of custody capture and a defensible case file runs $80,000 to $170,000 and ships in 14 to 20 weeks in our delivery experience. A full platform adding an athlete whereabouts app, doping control officer scheduling and payment, therapeutic use exemption workflow, intelligence handling with proper separation and results management through to hearing runs $200,000 to $500,000 phased over 8 to 14 months. A federation testing a few dozen athletes a year should stay inside ADAMS and spend the budget on more tests.

Why anti-doping programmes break the tools they are given

The moment that decides whether your programme is credible happens two years after the test. A hearing panel is asked whether the sample in question was collected, sealed, stored and transported in a way that leaves no room for doubt. Your evidence is a paper doping control form, a courier tracking number in an email, a temperature log that someone photographed, and a chaperone's recollection of how long the athlete was observed before the notification was signed. If any link in that chain is missing, the science stops mattering.

ADAMS is the system of record for whereabouts filings, test results and results management data exchange, and it does that job because the Code requires it. What it is not is an operations platform for your organization. It does not plan your test distribution against a risk model you own, it does not schedule your doping control officers or pay them, it does not hold your intelligence with proper separation from case handling, and it does not assemble the evidence bundle you hand a panel. So programmes fill the gap with spreadsheets, a shared drive, WhatsApp for mission coordination, and a compliance manager who is the only person who understands how it all connects.

Across compliance and evidence heavy projects we have delivered, the failure pattern in this domain is consistent. Missions planned in a spreadsheet that nobody can reconstruct six months later. Whereabouts strikes issued late because a filing failure was noticed at quarter end. And an arbitration file assembled by hand over three weeks, from four sources, by the one person who cannot be replaced.

Problem 1: the test distribution plan is a risk model kept in a spreadsheet

Under the International Standard for Testing and Investigations, testing has to be planned rather than random, informed by an assessment of the doping risks in each sport and discipline. Which means somewhere in your organization there is a model: physiological demands of the discipline, competition calendar, historical adverse findings, athlete performance progression, intelligence, and the mix of in competition and out of competition, urine and blood, standard menu and specific analysis.

That model almost always lives in a spreadsheet built by a single analyst. It cannot be queried, it cannot be audited, and the reason a particular athlete was tested three times in a quarter while another was not tested at all exists only as a memory. When your programme is reviewed, or when an athlete's counsel asks whether the testing was targeted improperly, a spreadsheet is a weak answer.

What a build should include is the plan as a governed object. Risk factors are named and weighted, athletes carry a computed risk score with the inputs visible, coverage is tracked against plan by sport, discipline, testing pool and analysis type, and every deviation from the plan is recorded with a reason and an approver. Then a quarter's testing can be explained, on a screen, in a sentence. It also lets you see the thing spreadsheets hide, which is systematic under coverage: the discipline nobody has tested out of competition in 14 months because it never came up in a planning meeting.

Problem 2: whereabouts strikes are a legal clock, and you have to prove notice

Athletes in a registered testing pool file whereabouts including a daily 60 minute time slot, and under the Code three whereabouts failures within a 12 month period, whether filing failures or missed tests, constitute an anti-doping rule violation. That is a career level consequence built out of administrative steps, and every one of those steps has to be provable.

The proof burden is what software usually ignores. A missed test is not just a doping control officer reporting that nobody answered the door. It is the attempt itself, with time, location and what the officer did during the slot, followed by a notice to the athlete, an opportunity to respond, a review by someone who was not the officer, and a decision with reasons. The 12 month window rolls, so a strike expiring next Tuesday changes the athlete's status without anyone doing anything.

What a build must include: an attempt record captured in the field with a timestamp that the officer cannot backdate, a notification workflow with delivery evidence, a response window with a countdown, a reviewer separate from the collector, and a rolling window calculation that shows each athlete's live strike position and what expires when. Filing failures should be detected automatically at the deadline rather than found during a quarterly sweep. Every one of those artefacts is what makes the strike stand up later, and assembling them retrospectively from email is how strikes get abandoned.

Problem 3: chain of custody is evidence, and a log is not evidence

Between the athlete sealing a sample and the laboratory logging it in, the bottle passes through a collection officer, a transport container, a courier, sometimes a border, and a receiving desk. Each handover is a fact you may need to prove. Most programmes prove it with a paper form, a courier tracking screenshot and good faith.

The distinction that matters is between a log you can edit and a record you cannot. If a chain of custody entry can be amended without trace, opposing counsel will say so, and they will be right to. What the build needs is append only capture: each custody event written once with the actor, the timestamp, the location and the sealed kit codes, corrections made as new entries that supersede rather than overwrite, and the whole chain hashed so any alteration is detectable. Kit code and sample code scanning rather than typing, because a transposed digit is the kind of error that ends a case. Temperature and integrity observations captured at handover with photographic evidence attached to the event, not to a folder.

The payoff is concrete. When a hearing asks for the custody record, you produce a single sequence for that sample code, generated in seconds, with attachments in place. Programmes that can do this settle arguments that programmes with a folder of scans have to fight.

Problem 4: a testing mission is field logistics with a contract workforce

A no advance notice mission at an athlete's home at 6am is a small operation. Someone assigns an officer with the right accreditation and gender requirements for the collection, checks conflicts of interest with that athlete's club or region, gets the kit inventory to the right place, arranges a chaperone if the sport needs one, and confirms the officer actually went. Afterwards the officer submits expenses and gets paid, usually as a contractor, sometimes across borders.

This is workforce management with compliance attached, and it is normally run by email and phone. What it costs you is not only administration. It is coverage: the mission that did not happen because the only available officer was six hours away and nobody saw it in time to reassign.

A build should hold officer accreditation with expiry, sport and language capability, geographic base, conflict declarations, availability, and kit stock by location with lot numbers so a recall on a collection kit lot can be traced to every sample it touched. Assignment then respects constraints rather than relying on the coordinator remembering them. Officers work from a mobile interface that functions with no signal in a stairwell, because 6am at a residential address is exactly where connectivity fails, and the doping control form has to be completable and signable offline with sync afterwards.

Problem 5: intelligence and results management must be separated by design

Programmes increasingly act on information: a whistleblower, a customs referral, a pattern in an athlete biological passport, a tip from another organization. That material is sensitive, sometimes attributable to a person at real risk, and it must not leak into the case file of an unrelated athlete or into the hands of staff who have no need to see it.

A single shared case management inbox cannot express that. What is needed is compartmentalisation as a design feature: intelligence records held separately with their own access control and source protection, a controlled path by which intelligence informs the test distribution plan without exposing the source, and a results management workspace where only the case handlers, the reviewing panel and the athlete's disclosed material live. Access logging that shows who opened what, permanently, protects your staff as much as the athlete.

Therapeutic use exemptions belong in the same conversation. They contain medical records, they are decided by a panel that must be independent of the testing operation, and they have to be retrievable at the moment a laboratory reports a finding for the substance in question. A shared drive of PDFs fails that test in every direction.

What this costs and how long it takes

Across the 2,000-plus projects Digital Heroes has delivered, this shape prices as follows. A focused first release covering the test distribution plan with risk scoring, mission assignment and officer management, offline field capture of the doping control form, and append only chain of custody through to laboratory dispatch runs $80,000 to $170,000 and ships in 14 to 20 weeks. A full platform adding an athlete whereabouts application, officer scheduling and payment, therapeutic use exemption workflow with panel review, intelligence handling with compartmentalisation, results management through to hearing, and reporting into global systems runs $200,000 to $500,000 phased over 8 to 14 months.

What drives cost up in anti-doping specifically: multi jurisdiction operation, because sanction rules, privacy law and language requirements multiply. Integration and data exchange with global reporting systems, which is a specification exercise with a testing calendar you do not control. Laboratory interfaces, since each accredited laboratory has its own result delivery format. Athlete biological passport data handling, which is a different analytical shape from pass or fail results. And the athlete facing app, which sounds simple and is not, because whereabouts filing is the most legally consequential form your athletes will ever complete on a phone.

What keeps cost down: building the operations core first and leaving the athlete app to phase two, since athletes can continue filing in the mandated system while your internal workflow gets fixed.

Build versus buy, and when buying is the right call

Do not build if your programme is small. A federation testing a few dozen athletes a year, using an external service provider for collections, working almost entirely in competition, should operate inside ADAMS and a well kept set of procedures. The money buys more tests, and more tests is a better anti-doping programme than better software.

Build when two or more of these are true. You plan and justify your own test distribution rather than executing someone else's. You manage a network of collection personnel directly, with accreditation, conflicts and payment to control. You handle results management through to hearing and have had a case turn on documentation rather than science. You receive and act on intelligence and currently have no structural separation between that material and general case handling. Or you operate across sports and jurisdictions where rules genuinely differ and a single process cannot express both.

The tipping point is evidentiary. A programme whose credibility rests on paper forms and one person's institutional memory is carrying a risk that grows with every case it brings. That is the argument for a build, and it is a board level argument, not an IT one.

How to choose a developer

Ask them how they would make a custody record tamper evident. You want to hear append only storage, superseding corrections rather than edits, hashing, and a rendering that a non technical panel can read. If they describe an audit table that an administrator can update, they have not built evidence systems and your case file will be attackable.

Ask them to model the rolling 12 month whereabouts window on a whiteboard, including what happens when a strike expires overnight and when an athlete moves between testing pools. It is a small piece of logic that exposes immediately whether they understand the domain or are pattern matching on generic case management.

Ask what they have shipped that works offline with a signature and a photograph, and what happens when the device is lost before sync. A doping control officer at 6am has no tolerance for a spinning icon and neither does the eventual hearing.

Ask how they will separate intelligence from case handling in the permission model, and how source protection is enforced rather than promised. If the answer is user roles, keep looking.

Ask who owns the code and settle it in writing before kickoff. You should hold the repository, the hosting accounts and the right to bring in another firm. At Digital Heroes the client owns the code from the first commit, and for an organization whose independence is the product, being unable to leave a vendor is a governance problem, not just a commercial one.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
  2. Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
  3. In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
  4. Criteo's Global Commerce Review found retail apps convert at 18% versus 4% on mobile web (roughly 4.5x), and travel apps convert at 20% versus 6% on mobile web (about 3.3x). Source: Criteo (2017) →
Navya S. · Senior Project Manager · Lucknow

As a senior project manager, Navya holds the line between what a client signed off and what a development team can deliver in the time available. Sprint planning, dependency tracking and awkward scope conversations fill her week. Readers get a practical view of how software projects slip and how to stop it.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom anti-doping case management software cost?
A focused first release covering test distribution planning with risk scoring, mission and officer assignment, offline field capture and append only chain of custody runs $80,000 to $170,000 and ships in 14 to 20 weeks, based on Digital Heroes delivery experience. A full platform adding an athlete whereabouts app, therapeutic use exemption workflow, intelligence handling and results management through to hearing runs $200,000 to $500,000 over 8 to 14 months. Operating across multiple jurisdictions is the main cost multiplier.
Is ADAMS enough on its own for a national anti-doping organization?
ADAMS is the system of record required for whereabouts filings, results and results management data exchange, and nothing replaces it. What it does not do is run your organization: it does not plan test distribution against a risk model you own, schedule and pay your collection personnel, hold intelligence with proper separation, or assemble the evidence bundle for a hearing. Most programmes fill those gaps with spreadsheets, which is the gap a build closes.
How should whereabouts failures and missed tests be tracked?
As a legal clock with proof at every step. Under the Code, three whereabouts failures within a rolling 12 month period constitute an anti-doping rule violation, so the system needs the attempt record with a timestamp the collector cannot backdate, notification with delivery evidence, a response window, review by someone other than the collector, and a live rolling window showing what expires when. Filing failures should be detected automatically at the deadline rather than during a quarterly sweep.
What makes a chain of custody record defensible in arbitration?
That it cannot be quietly altered. Custody events should be written once with actor, timestamp, location and sealed kit codes, corrections recorded as new superseding entries rather than edits, and the sequence hashed so tampering is detectable. Kit and sample codes should be scanned rather than typed, and integrity or temperature observations should attach to the specific custody event, so the whole chain for a sample code can be produced in seconds.
Can doping control officers complete forms with no internet connection?
They have to, because a no advance notice mission at a residential address at 6am is exactly where connectivity fails. The field interface needs to work fully offline, including signature capture and photographs, with durable local storage that survives the app closing and identifiers generated on the device so sync cannot duplicate a mission. Sync state should be visible so the officer knows what has reached the server before leaving.
How do you keep intelligence separate from athlete case files?
By compartmentalising at the design level rather than with user roles alone. Intelligence records sit in their own store with independent access control and source protection, informing the test distribution plan through a controlled path that does not expose the source, while results management is a separate workspace limited to case handlers and the reviewing panel. Permanent access logging protects staff as much as athletes.
How long does it take to move off spreadsheets for test planning?
Expect 14 to 20 weeks for a first release covering planning, missions and custody. The usual schedule risk is not engineering but capturing the risk model itself, because the weighting logic that decides who gets tested typically exists only in one analyst's spreadsheet and head. Budget real time to write that down and get it approved, since the whole point is that the plan becomes explainable.
Should therapeutic use exemptions live in the same system?
Yes, with strict separation. They contain medical records, they are decided by a panel that must be independent of the testing operation, and they have to be retrievable the moment a laboratory reports a finding for that substance. A shared drive of PDFs fails on retrieval speed, on confidentiality and on proving who reviewed what, which is why this usually lands in phase two of a build rather than being left alone.
We test a few dozen athletes a year. Do we need this?
No, and we would say so plainly. A small federation working mostly in competition, using an external collection provider, should run inside ADAMS with well kept procedures and spend the money on more tests. The build case starts when you plan and justify your own test distribution, manage collection personnel directly, or handle results management through to hearing where documentation rather than science decides the outcome.
What does a $50,000 custom software budget actually buy?
One core workflow done properly: 10 to 15 screens, two or three user roles, a couple of integrations, an admin panel, and automated tests, delivered in roughly 12 to 14 weeks. What it does not buy is that workflow plus a mobile app plus AI features plus five more integrations. The discipline of picking the one workflow that matters is what separates $50,000 projects that ship from $50,000 projects that stall at 70% complete.
Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?
For validating an idea with real users, yes, and we tell clients that honestly. The walls come later: Bubble apps cannot be exported as code to run anywhere else, performance drops on complex data operations, and usage-based pricing climbs as you grow. A meaningful share of Digital Heroes custom builds are rebuilds of no-code MVPs that proved the business worked, which is the system operating as intended: validate cheap, then build the version that scales.
What is a discovery phase, and is it worth paying for separately?
Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
What should I have ready before I contact a development agency?
Three things, none of them technical: a one-page description of the problem in your own words, a list of the tools and spreadsheets the new system must replace or connect to, and a must-have versus nice-to-have split of features. Add a budget range, even a wide one, because it changes the conversation from fantasy to engineering. You do not need a formal specification; producing that is what a discovery phase is for.
How do I make sure custom software is secure and compliant with rules like HIPAA?
Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.
Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?