top of page

How to Prepare for an OCM Inspection: The Records Every Minnesota Cannabis Business Should Have

Aug 26
6 min read

PART 1  ·  CANNAPATH MINNESOTA CANNABIS COMPLIANCE SERIES  ·  LAST REVIEWED AUGUST 2026

By: Drew Duffy, MHA, FACHE Founder & Managing Director, CannaPath Regulatory Solutions

THE SHORT VERSION

An OCM inspection tests your evidence, not your intentions. Five things need to be current and easy to find on short notice: your SOPs, your training records, your employee screening files, your inventory and Metrc reconciliation, and your daily operational logs.

If you can't produce them quickly, the gap is real, whether the work behind them actually got done.

 Most operators prepare for the wrong half of an inspection. They polish the policies. Then an inspector asks for the log that shows the policy was followed on a Tuesday in March, and the room goes quiet.

Having a written procedure is the easy half. Showing that people followed it is the half that gets written up.

So, this piece is about the records you should be able to put your hands on, and what each one is actually meant to prove.


The question worth asking now

“If an OCM inspector walked in tomorrow, could we produce the records that show how we actually operate?”

 

If the honest answer is “probably, give me a few hours,” you have found your next project. Inspection readiness is a filing problem long before it becomes a compliance problem.


Five record sets to keep within reach

Your license type changes the details. The shape of the list doesn't change much.

Record set

What it has to prove

Where it usually falls apart

Standard operating procedures

That the written procedure matches the way the business runs today

Version drift. The SOP still describes a process that got replaced months ago.

Employee training records

That named people completed specific training on specific dates

The training happened. Nobody captured the roster, the topic, or the sign-off.

Employee and screening files

That everyone who needed to clear a required step actually cleared it

The records exist, but they're spread across email, HR files, and a shared drive.

Inventory and Metrc records

That your physical count, your internal records, and Metrc tell one story

Small discrepancies sit unexplained, then get reconstructed from memory later.

Daily operational logs

That the steps in your SOPs are being performed on the schedule you set

Partial completion. Filled in Monday, signed Tuesday, blank by Thursday.

Table 1. The five record sets that carry most of the weight in an OCM inspection.


Your SOPs describe today, not last year

An SOP that no longer matches the floor can be worse than no SOP at all, because now there's a documented gap between what you said you'd do and what you did.

Track the version in use, the effective date, who approved it, and what changed. Regulatory updates are the usual trigger. When the requirement moves, the document has to move with it, and so does anyone who was trained on the old version.

Version control gets its own installment later in this series. For now the test is short: can you say which version is current, and show it?



Training records are where good programs get caught

Running training and being able to prove you ran it are two different projects. Plenty of operators do the first one well and never get around to the second.

Field

Why it matters

Employee name

Ties the training to a person rather than a headcount

Training topic

Shows the content actually matched the requirement

Date completed

Establishes the training was current at the time in question

Trainer or provider

Identifies who delivered it, and whether they were qualified to

Assessment or acknowledgment

Evidence the employee received and understood it, not just attended

Linked SOP

Connects the training to the procedure that employee is expected to follow

Table 2. What a training record needs to contain before it counts as evidence.

WORTH KNOWING

Minnesota puts a clock on this one. Training records must be kept for three years and produced to OCM within 24 hours of a request (Minn. R. 9810.1100, subp. 3).

Twenty-four hours is not enough time to reconstruct a year of sign-in sheets. Either the file is built or it isn't.

 

Inventory should tell one story

Be ready to reconcile the physical count against your tracking records and be ready to explain the difference when there is one.

Discrepancies aren't automatically a finding. Unexplained discrepancies are a different matter. The explanation is far easier to give on the day it happens than six months later, which is an argument for writing it down at the time.

The logs that come up most

What applies to you depends on your license type and what you actually do on site. These are the ones that come up repeatedly:

Log or record

What it demonstrates

Opening and closing

Security and access controls run on a fixed routine, every day

Cleaning and sanitation

Sanitation happens on a schedule, not during inspection week

Inventory reconciliation

Counts get checked at a set interval and differences get addressed

Waste and disposal

Product left the building the way the rules require

Product receiving

What came in, from whom, and in what condition

Incident reports

Problems were identified, escalated, and closed out

Equipment or monitoring checks

Conditions stayed inside the range your SOP requires

Table 3. Common operational logs and the question each one answers.


A thick stack of forms isn't the point. The point is that the forms match the procedures and the procedures match what happened.

Documentation is a chain

An inspector doesn't read your records one at a time. They follow a sequence, and every link has to hold.

Figure 1. Requirement to record. An inspector reads this left to right, and the gaps show up underneath.


Here's why that sequence matters. Say your SOP requires a daily log, and the logs are half empty. The conclusion isn't that the log is sloppy. The conclusion is that the procedure may not be running at all.

That's a bigger finding, and it's the kind that spreads. Once one link looks unreliable, the rest of the chain gets a closer read.



Where programs fail

The dangerous quadrant isn't the obvious one. Very few licensed operators have neither a procedure nor a record. That's not the group that gets surprised.

The trap is the paper program. Everything is written, approved, and filed, and almost none of it is evidenced. It looks like the strongest quadrant right up until someone asks for the file.

Figure 2. Policy on one axis, proof on the other. Most write-ups live in the top left.


Run the drill on yourself

Pick an ordinary day. Not a day you prepared for. Then work the list and be honest about the answers.

Ask

You pass if

Can we find the current SOP set?

Someone who didn't write them can locate them in a few minutes

Can we prove required training happened?

Named employee, named topic, dated, signed

Are the required logs complete?

Every required entry for the period, with no silent gaps

Do the records match operations?

The written procedure describes what the floor actually does

Can we explain our discrepancies?

The explanation was written at the time, not reconstructed now

Are superseded versions controlled?

Old versions are archived and marked, not still sitting in the binder

Could a new hire find any of this?

Yes, without asking the one person who knows where everything lives

Table 4. A self-audit you can run in an afternoon, on a day nobody prepared for.


Anything that fails here is a finding you got to write yourself. That is a considerably better position than the alternative.

The bottom line

Good policies are the easy part. A program holds up when you can show that people know the policies and that the work is getting done the way the policies describe.

Documentation is how you show it. Nothing else does that job.

WHAT THIS MEANS FOR YOU

Start with one record set, not all five. Pick the one you'd least like to be asked for tomorrow. Get it current, get it findable, then move to the next one.

Readiness built in that order tends to hold. Readiness built the week before an inspection tends not to.

 

-Drew

 

 

 

Coming up in this series

–    Part 2: Corrective Action Plans. What to do when something goes wrong, and how to document the response so it closes the issue instead of recording the failure.

–    Part 3: Internal Compliance Audits. How to run your own review and find the problem before OCM finds it for you.

–    Part 4: Employee Training Records. Why completing the training is only half of the requirement.

More parts will follow as the series develops.

If you want a head start

There are free workbooks in the free resources section at cannapath.org. No email, no form, no drip campaign. Download them and go.

And if you get into something you'd rather not sort out alone, we're here. Reach out at hello@cannapath.org or (952) 649-2946.

 

Sources: Minnesota Office of Cannabis Management (mn.gov/ocm); Minnesota Rules chapter 9810 (revisor.mn.gov).

Rules change and requirements get revised. Verify anything you plan to rely on directly with OCM.

ABOUT CANNAPATH REGULATORY SOLUTIONS

CannaPath Regulatory Solutions helps cannabis businesses handle compliance with practical tools, training, and plain-language guidance. The goal is simple: make compliance easier to understand, easier to run, and easier to demonstrate.

This article is general compliance information. It does not replace applicable Minnesota law, OCM requirements, or professional legal advice.

 

Initial Compliance Consultation
30min
Book Now

bottom of page