How to Prepare for an OCM Inspection: The Records Every Minnesota Cannabis Business Should Have
PART 1 · CANNAPATH MINNESOTA CANNABIS COMPLIANCE SERIES · LAST REVIEWED AUGUST 2026
By: Drew Duffy, MHA, FACHE Founder & Managing Director, CannaPath Regulatory Solutions
THE SHORT VERSION An OCM inspection tests your evidence, not your intentions. Five things need to be current and easy to find on short notice: your SOPs, your training records, your employee screening files, your inventory and Metrc reconciliation, and your daily operational logs. If you can't produce them quickly, the gap is real, whether the work behind them actually got done. |
Most operators prepare for the wrong half of an inspection. They polish the policies. Then an inspector asks for the log that shows the policy was followed on a Tuesday in March, and the room goes quiet.
Having a written procedure is the easy half. Showing that people followed it is the half that gets written up.
So, this piece is about the records you should be able to put your hands on, and what each one is actually meant to prove.
The question worth asking now
“If an OCM inspector walked in tomorrow, could we produce the records that show how we actually operate?” |

If the honest answer is “probably, give me a few hours,” you have found your next project. Inspection readiness is a filing problem long before it becomes a compliance problem.
Five record sets to keep within reach
Your license type changes the details. The shape of the list doesn't change much.
Record set | What it has to prove | Where it usually falls apart |
Standard operating procedures | That the written procedure matches the way the business runs today | Version drift. The SOP still describes a process that got replaced months ago. |
Employee training records | That named people completed specific training on specific dates | The training happened. Nobody captured the roster, the topic, or the sign-off. |
Employee and screening files | That everyone who needed to clear a required step actually cleared it | The records exist, but they're spread across email, HR files, and a shared drive. |
Inventory and Metrc records | That your physical count, your internal records, and Metrc tell one story | Small discrepancies sit unexplained, then get reconstructed from memory later. |
Daily operational logs | That the steps in your SOPs are being performed on the schedule you set | Partial completion. Filled in Monday, signed Tuesday, blank by Thursday. |
Table 1. The five record sets that carry most of the weight in an OCM inspection.
Your SOPs describe today, not last year
An SOP that no longer matches the floor can be worse than no SOP at all, because now there's a documented gap between what you said you'd do and what you did.
Track the version in use, the effective date, who approved it, and what changed. Regulatory updates are the usual trigger. When the requirement moves, the document has to move with it, and so does anyone who was trained on the old version.
Version control gets its own installment later in this series. For now the test is short: can you say which version is current, and show it?

Training records are where good programs get caught
Running training and being able to prove you ran it are two different projects. Plenty of operators do the first one well and never get around to the second.
Field | Why it matters |
Employee name | Ties the training to a person rather than a headcount |
Training topic | Shows the content actually matched the requirement |
Date completed | Establishes the training was current at the time in question |
Trainer or provider | Identifies who delivered it, and whether they were qualified to |
Assessment or acknowledgment | Evidence the employee received and understood it, not just attended |
Linked SOP | Connects the training to the procedure that employee is expected to follow |
Table 2. What a training record needs to contain before it counts as evidence.
WORTH KNOWING Minnesota puts a clock on this one. Training records must be kept for three years and produced to OCM within 24 hours of a request (Minn. R. 9810.1100, subp. 3). Twenty-four hours is not enough time to reconstruct a year of sign-in sheets. Either the file is built or it isn't. |
Inventory should tell one story
Be ready to reconcile the physical count against your tracking records and be ready to explain the difference when there is one.
Discrepancies aren't automatically a finding. Unexplained discrepancies are a different matter. The explanation is far easier to give on the day it happens than six months later, which is an argument for writing it down at the time.
The logs that come up most
What applies to you depends on your license type and what you actually do on site. These are the ones that come up repeatedly:
Log or record | What it demonstrates |
Opening and closing | Security and access controls run on a fixed routine, every day |
Cleaning and sanitation | Sanitation happens on a schedule, not during inspection week |
Inventory reconciliation | Counts get checked at a set interval and differences get addressed |
Waste and disposal | Product left the building the way the rules require |
Product receiving | What came in, from whom, and in what condition |
Incident reports | Problems were identified, escalated, and closed out |
Equipment or monitoring checks | Conditions stayed inside the range your SOP requires |
Table 3. Common operational logs and the question each one answers.
A thick stack of forms isn't the point. The point is that the forms match the procedures and the procedures match what happened.
Documentation is a chain
An inspector doesn't read your records one at a time. They follow a sequence, and every link has to hold.

Figure 1. Requirement to record. An inspector reads this left to right, and the gaps show up underneath.
Here's why that sequence matters. Say your SOP requires a daily log, and the logs are half empty. The conclusion isn't that the log is sloppy. The conclusion is that the procedure may not be running at all.
That's a bigger finding, and it's the kind that spreads. Once one link looks unreliable, the rest of the chain gets a closer read.

Where programs fail
The dangerous quadrant isn't the obvious one. Very few licensed operators have neither a procedure nor a record. That's not the group that gets surprised.
The trap is the paper program. Everything is written, approved, and filed, and almost none of it is evidenced. It looks like the strongest quadrant right up until someone asks for the file.

Figure 2. Policy on one axis, proof on the other. Most write-ups live in the top left.
Run the drill on yourself
Pick an ordinary day. Not a day you prepared for. Then work the list and be honest about the answers.
Ask | You pass if |
Can we find the current SOP set? | Someone who didn't write them can locate them in a few minutes |
Can we prove required training happened? | Named employee, named topic, dated, signed |
Are the required logs complete? | Every required entry for the period, with no silent gaps |
Do the records match operations? | The written procedure describes what the floor actually does |
Can we explain our discrepancies? | The explanation was written at the time, not reconstructed now |
Are superseded versions controlled? | Old versions are archived and marked, not still sitting in the binder |
Could a new hire find any of this? | Yes, without asking the one person who knows where everything lives |
Table 4. A self-audit you can run in an afternoon, on a day nobody prepared for.
Anything that fails here is a finding you got to write yourself. That is a considerably better position than the alternative.
The bottom line
Good policies are the easy part. A program holds up when you can show that people know the policies and that the work is getting done the way the policies describe.
Documentation is how you show it. Nothing else does that job.
WHAT THIS MEANS FOR YOU Start with one record set, not all five. Pick the one you'd least like to be asked for tomorrow. Get it current, get it findable, then move to the next one. Readiness built in that order tends to hold. Readiness built the week before an inspection tends not to. |
-Drew
Coming up in this series
– Part 2: Corrective Action Plans. What to do when something goes wrong, and how to document the response so it closes the issue instead of recording the failure.
– Part 3: Internal Compliance Audits. How to run your own review and find the problem before OCM finds it for you.
– Part 4: Employee Training Records. Why completing the training is only half of the requirement.
More parts will follow as the series develops.
If you want a head start
There are free workbooks in the free resources section at cannapath.org. No email, no form, no drip campaign. Download them and go.
And if you get into something you'd rather not sort out alone, we're here. Reach out at hello@cannapath.org or (952) 649-2946.
Sources: Minnesota Office of Cannabis Management (mn.gov/ocm); Minnesota Rules chapter 9810 (revisor.mn.gov).
Rules change and requirements get revised. Verify anything you plan to rely on directly with OCM.
ABOUT CANNAPATH REGULATORY SOLUTIONS CannaPath Regulatory Solutions helps cannabis businesses handle compliance with practical tools, training, and plain-language guidance. The goal is simple: make compliance easier to understand, easier to run, and easier to demonstrate. This article is general compliance information. It does not replace applicable Minnesota law, OCM requirements, or professional legal advice. |



