Key takeaways
- Assign one trained point of contact for inspections
- Keep the approved plans and current SOPs reconciled
- Preserve privilege for internal compliance reviews
- Remediate and document findings promptly and verifiably
A Commission audit is not the same procedural event as a complaint-driven inspection, though licensees often treat them interchangeably. An audit is typically a planned, comprehensive review of a licensee's operational record against the approved application, the current SOPs, and the standards codified at N.J.A.C. 17:30. It can be triggered by renewal, by a pattern of prior findings, by a change-of-ownership filing, or simply by the Commission's own inspection cycle. Understanding which type of review is underway shapes the correct response, because a renewal-linked audit carries different timing pressure than a for-cause inspection following a complaint.
The core analytical question an auditor is answering is deceptively simple: does the facility as it actually operates match the facility as described in the license record. That comparison runs across security plans, standard operating procedures, personnel files, inventory reconciliation, waste disposal, and advertising materials. Because CREAMMA and its implementing regulations place the burden of demonstrating continued compliance on the licensee rather than the agency, an ambiguous record is read against the operator, not in its favor. Licensees who assume good-faith operation will be presumed compliant misunderstand the structure of the review.
This guide expands on the operational summary already provided and focuses on what happens procedurally once an audit is underway, including document production strategy, privilege boundaries for internal compliance work, the range of post-audit outcomes available to the Commission, and how audit findings interact with the contested-case process under N.J.A.C. 1:1 if the matter is not resolved informally. It does not restate the day-of-inspection guidance already covered elsewhere in this resource; it picks up from there.
The day of the inspection
Staff should know who greets inspectors, where records live, and what to say — which is generally to answer factual questions accurately and to route interpretive questions to counsel. Volunteered speculation becomes part of the record.
Records typically requested
- Seed-to-sale reports and inventory reconciliation history
- Surveillance footage retention and access logs
- Employee credential files and training records
- Waste destruction logs with witness signatures
- Standard operating procedures with revision history
After the findings
A findings letter starts a response window. A written remediation plan with evidence of completion frequently converts a penalty posture into a compliance resolution, particularly for first findings.
The legal basis for the audit power
The Commission's authority to inspect and audit licensed premises derives from CREAMMA itself, N.J.S.A. 24:6I-31 et seq., and from the operational rules at N.J.A.C. 17:30 that condition licensure on ongoing compliance rather than a one-time approval. A license is not a vested property right immune from further scrutiny; it is a continuing regulatory relationship, and the audit function is how the Commission tests whether that relationship remains justified.
Because the audit power attaches to the license itself, a licensee generally cannot refuse reasonable access to records or premises without independently jeopardizing the license. That does not mean a licensee has no rights during the process — it means those rights operate within the audit rather than as a basis to prevent it. The correct posture is full, organized cooperation paired with careful control over who speaks and what gets characterized as an admission.
Scoping a document production without waiving more than necessary
Auditors typically issue a document request that is broad by design, intended to surface inconsistencies the licensee has not yet noticed. A well-run response answers the request completely but does not volunteer categories of documents beyond its scope. Overproduction is a common and avoidable error: a licensee anxious to appear cooperative sends an entire shared drive rather than the specific records requested, and in doing so hands the auditor material that generates new lines of inquiry unrelated to the original audit trigger.
The better practice is to build a response index that maps each document produced to the specific request item it answers, retain a copy of exactly what was produced and when, and route any request that seems to exceed the stated scope through counsel for a scope discussion before producing it. This is not obstruction; agencies routinely narrow or clarify requests when asked, and a documented, professional record of that exchange protects the licensee if scope becomes an issue later.
Privilege and the internal compliance review
Licensees that run their own internal compliance audits before a Commission review creates a tension: the exercise is valuable precisely because it finds problems, but the resulting memo can become a roadmap for a regulator if it is not handled correctly. Structuring internal compliance reviews as privileged communications, initiated by counsel for the purpose of providing legal advice, is the standard approach to preserving the ability to conduct candid self-assessment without creating an unprotected admission.
Privilege protection is not automatic and depends on how the review is commissioned and who receives the output. A compliance review run entirely by operations staff, circulated broadly, and stored in a general shared folder is unlikely to be treated as privileged if the agency later seeks it. Counsel involvement at the outset, a narrow distribution list, and a clear description of the review's purpose as legal advice materially affect whether the analysis can later be withheld.
None of this substitutes for remediation. Privilege protects the analysis of a problem; it does not excuse the underlying noncompliance, and the goal of the internal review should always be to fix what it finds, not merely to insulate the finding from disclosure.
Reconciling the approved plans against current operations
Every licensee's file contains an approved security plan, an approved floor plan, and a set of SOPs submitted at application or at the most recent material modification. Operations drift from those documents over time as staffing changes, equipment is upgraded, or workflows are adjusted for efficiency. An audit tests that drift directly, and the gap between the approved plan and current practice is one of the most frequently cited findings regardless of license class.
A useful discipline is a standing reconciliation cycle — not merely at renewal — in which operations leadership and compliance staff walk the facility against the approved plan and either update practice to match the plan or file the appropriate amendment to update the plan to match practice. Both are acceptable outcomes from the Commission's perspective; an undocumented divergence is not.
This includes items that seem administrative rather than substantive: revised organizational charts, updated camera placement diagrams, and current vendor lists for waste disposal or transport. Auditors treat outdated ancillary documents as evidence of a broader recordkeeping weakness even when the underlying operation is sound.
- Security plan versus actual camera coverage and access-control points
- Approved floor plan versus current limited-access area boundaries
- SOP revision dates versus the last operational change of substance
- Organizational chart versus current management and TPI structure
- Vendor and contractor lists versus active service agreements
The range of post-audit outcomes
Not every audit finding results in formal enforcement. The Commission has a spectrum of available responses that includes informal correction with no formal notice, a corrective action plan negotiated with staff, a formal notice of violation with an associated penalty, and, for serious or repeated findings, license conditions or suspension proceedings. Where a matter sits on that spectrum depends heavily on whether the finding is a first occurrence, whether it reflects a systemic gap or an isolated lapse, and how the licensee responds once the finding is communicated.
A licensee's own conduct during the audit materially affects where the outcome lands. Prompt, verifiable remediation completed before a formal response is due, and a factual rather than defensive engagement with the findings, routinely converts what could have been a formal violation into a documented correction. Stonewalling, incomplete production, or minimization of a finding tends to move a matter in the opposite direction.
When an audit becomes a contested case
If the audit results in a formal notice of violation that the licensee disputes, the matter may be eligible for transmission to the Office of Administrative Law as a contested case under the Uniform Administrative Procedure Rules at N.J.A.C. 1:1. At that point the audit record — the requests, the productions, the correspondence, and any admissions made along the way — becomes the evidentiary foundation for the hearing. This is why the production strategy during the audit itself has consequences well beyond the audit's immediate resolution.
A licensee that treated the audit response casually, without preserving copies of what was produced or documenting remediation with dated evidence, arrives at a contested-case hearing missing exactly the exhibits that would have supported its position. Building the audit response with the possibility of later litigation in mind is not paranoia; it is ordinary administrative practice given how directly the two proceedings connect under New Jersey's regulatory structure.
Audit findings and the renewal cycle
Because licensure in New Jersey's cannabis program is subject to periodic renewal, unresolved or repeated audit findings do not exist in isolation from the renewal decision. A pattern of findings, even where each individual matter was resolved informally, can inform the Commission's assessment of a licensee's overall compliance posture at renewal. Licensees should treat every audit resolution as part of a cumulative compliance record rather than a closed, self-contained event.
This argues for maintaining a compliance history file that tracks every finding, the remediation completed, and the date it was verified, independent of whatever files the Commission itself maintains. That file becomes the licensee's own evidence of a good-faith trajectory if a renewal reviewer or a future auditor raises a pattern concern.
Working an audit from notice to closeout
This walkthrough picks up after the day-of-inspection guidance already covered and follows an audit through to final resolution.
Step 1
Phase 1 — Scope confirmation
A clear, written understanding of what the audit covers and what it does not.
- Confirm in writing the trigger for the audit and its stated scope
- Identify the applicable rule sections the audit appears to be testing
- Assign a single internal point of contact and a single external counsel contact
- Set an internal calendar for every deadline referenced in the audit notice
Step 2
Phase 2 — Controlled production
A complete, indexed response that does not exceed the request.
- Map each document produced to the specific item requested
- Route any ambiguous or overbroad request through counsel before responding
- Retain a complete internal copy of everything produced, dated and indexed
- Flag any request implicating privileged compliance work before producing it
Step 3
Phase 3 — Internal reconciliation
An accurate internal picture of exposure before the findings letter arrives.
- Walk the facility against the approved security and floor plans
- Compare current SOPs against actual practice on the floor
- Identify gaps proactively rather than waiting for the auditor to find them
- Begin remediation on anything correctable immediately
Step 4
Phase 4 — Findings response
A factual, documented response that supports a favorable resolution.
- Address each finding individually rather than with a general narrative
- Attach dated evidence of remediation already completed
- Avoid characterizations or admissions beyond the facts required
- Preserve any right to request further review of a disputed finding
Step 5
Phase 5 — Resolution or contested case
Either a documented informal closeout or a properly preserved hearing right.
- Obtain written confirmation of closeout where the matter resolves informally
- Request transmission to the OAL where a genuine factual dispute remains
- Prepare the audit record as a hearing exhibit set if litigation proceeds
- Update the internal compliance history file regardless of outcome
Step 6
Phase 6 — Renewal integration
A compliance record that supports rather than complicates renewal.
- Fold the audit outcome into the licensee's ongoing compliance file
- Update SOPs and plans to reflect any changes made during remediation
- Brief renewal counsel on the audit history well before the renewal window opens
Audit trigger types and typical posture
Different audit triggers call for different initial postures, though the underlying document discipline is the same.
| Trigger | Typical scope | Timing pressure | Recommended posture |
|---|---|---|---|
| Renewal cycle | Comprehensive, full operational review | Fixed by renewal deadline | Proactive self-audit well in advance |
| Routine inspection | Targeted operational spot-check | Same-day response expected | Trained staff, immediate document access |
| Complaint-driven | Focused on the complaint subject matter | Short response window once notice issues | Internal investigation before formal response |
| Ownership or control change | TPI and control documentation | Tied to the amendment filing | Coordinate audit response with corporate counsel |
| Pattern of prior findings | Broad, often revisits earlier findings | Compressed, elevated scrutiny | Full remediation history assembled before response |
Actual scope and timing are set by the Commission's notice and applicable rule in each matter; this table describes general tendencies, not fixed procedure.
Audit-readiness checklist
Organized by function, these are the categories a licensee should be able to produce on short notice at any time, not only when an audit is announced.
Document control
- Approved security plan and floor plan available in current form
- SOPs with revision history current to actual practice
- Organizational chart current to actual management structure
- Vendor and contractor agreements filed and indexed
- TPI disclosures current to the most recent ownership or control change
Operational records
- Inventory reconciliation history with variance explanations
- Surveillance retention logs and outage reports
- Waste destruction logs with witness signatures
- Employee credentialing and training completion records
- Cash handling and deposit documentation
Response infrastructure
- Designated point of contact trained on audit protocol
- Counsel contact information posted and known to management
- Production index template ready for use
- Prior findings history file maintained and current
- Calendar protocol for immediate deadline capture upon notice
Where these matters go wrong
The most common structural error is treating the audit as a single event rather than a snapshot of an ongoing compliance relationship. Licensees that pass an audit and then let SOPs, plans, and training records drift out of alignment again are simply waiting for the next audit to reveal the same category of gap, often in a less forgiving posture because it now looks like a repeat issue rather than an isolated one.
The second is overproduction driven by anxiety to appear cooperative. Sending unrequested material, entire email accounts, or full shared drives in response to a narrow document request routinely generates new lines of inquiry that would not otherwise have existed. Complete, accurate, and scoped production demonstrates cooperation; indiscriminate production demonstrates a lack of control over the record.
The third is allowing internal compliance work to be created and stored in a way that forfeits any privilege protection before it is ever needed. A candid self-assessment that identifies a serious gap is valuable precisely because it is candid, but if it is commissioned without counsel involvement, circulated broadly, and stored without any indication of its legal-advice purpose, it becomes discoverable exactly when its candor is most damaging.
Governing authority
- N.J.S.A. 24:6I-31 et seq. — CREAMMA, including Commission audit and inspection authority
- N.J.A.C. 17:30 — Commission operational, recordkeeping, and compliance standards
- N.J.A.C. 1:1 — Uniform Administrative Procedure Rules governing contested cases at the Office of Administrative Law
- N.J.S.A. 52:14B-1 et seq. — Administrative Procedure Act
Frequently asked questions
Can I refuse to produce a document I think is outside the audit's scope?
You generally cannot simply refuse, but you can raise a scope objection through counsel and request clarification or narrowing before producing it. Outright refusal without engaging the agency risks being treated as noncooperation, while a documented scope discussion preserves the objection without creating that risk.
Is an internal compliance review automatically privileged?
No. Privilege protection depends on how the review is commissioned, who conducts it, and how narrowly the output is distributed. Reviews initiated by counsel for the purpose of providing legal advice and kept within a limited distribution are far more likely to be protected than reviews run purely by operations staff and stored broadly.
What happens if the audit reveals a gap I did not know about?
Prompt, documented remediation is the standard response regardless of when the gap is discovered. A licensee that finds and fixes a problem itself, with dated evidence of the fix, is generally in a materially better position than one where the agency finds the same gap first.
Does an audit finding automatically affect my renewal?
Not automatically, but a pattern of unresolved or repeated findings can inform the Commission's overall assessment of a licensee's compliance posture at renewal. A single, promptly remediated finding documented as closed is treated very differently from an accumulating pattern.
Can I appeal an audit finding I disagree with?
Where the finding results in formal action that constitutes a contested case, the matter may be eligible for transmission to the Office of Administrative Law under N.J.A.C. 1:1, where an administrative law judge takes evidence and issues an initial decision subject to final agency review and possible Appellate Division review.
Should the same person who handles day-to-day operations also handle the audit response?
Operations staff are essential for factual accuracy, but the audit response itself should be coordinated by a designated point of contact working with counsel so that responses are consistent, complete, and do not include informal characterizations that later read as admissions.
How far back can an audit look?
The lookback period depends on the specific request and the trigger for the audit, and licensees should confirm the stated scope in writing rather than assume a fixed period. Retaining records for the full period required under N.J.A.C. 17:30 recordkeeping standards is the baseline expectation regardless of any particular audit's stated window.
What is the difference between a corrective action plan and a formal notice of violation?
A corrective action plan is typically a negotiated, less formal resolution in which the licensee commits to specific remediation steps and timelines, while a formal notice of violation carries a defined response process and potential penalty. Which path applies depends on the severity and history associated with the finding.
Do I need separate counsel for the tax and operational aspects of an audit?
Cannabis audits sometimes surface both operational compliance issues and financial recordkeeping questions that intersect with tax exposure, and coordinating operational counsel with tax counsel where both areas are implicated avoids inconsistent positions across the two workstreams.
How our practice handles this
This analysis supports our Administrative Enforcement, Audits & Regulatory Appeals practice. If the issue is live for your entity, we can review the file directly — reach the advisory unit at advisory@cannabislawyernj.com or (609) 256-6379.
Related practice work: CRC Licensing, Hemp Compliance, Tax Compliance.
This page is general information from the Cannabis Lawyer NJ regulatory advisory unit. It is not legal advice and does not create an attorney-client relationship.