top of page

What is a Cannabis Compliance gap Analysis?

Sep 11
11 min read

Updated: Sep 12

By: Drew Duffy, MHHA, FACHE Founder & Managing Director CannaPath Regulatory Solutions Last reviewed: September 3, 2026

SHORT ANSWER

A gap analysis compares what your business is required to do against what your documents, training, records, and daily practice actually do. It is not a document audit. It is a test of whether the system behind the documents works.

 

There is a big difference between having compliance documents and knowing whether those documents actually cover everything your business is required to do.

That difference is where a compliance gap analysis comes in.

A gap analysis is a structured review that compares the requirements applicable to a business against the policies, procedures, training, records, controls, and practices the business currently has in place.

The goal isn’t simply to find mistakes.

The goal is to answer a much more useful question: 

Where are the weaknesses in our compliance program, and what should we do about them?

 For Minnesota cannabis businesses, that question has become more important as operators move out of licensing and opening and into the much harder work of staying compliant as an actual operating business.

Minnesota rules require cannabis and hemp businesses to keep written, up-to-date standard operating procedures covering operations, worker training, worker safety, and the statewide monitoring system. The rules also set recordkeeping requirements and require you to make applicable records available to the Office of Cannabis Management for inspection.

A gap analysis helps determine whether the system behind those documents is actually doing what it is supposed to do.

A gap is not always a missing document

When people hear “compliance gap,” they often assume the problem is obvious.

There is a requirement. There is no SOP. Gap found. 

Sometimes it really is that simple.

More often, the problem is buried inside documentation that looks perfectly acceptable at first glance.

A business may have an SOP that addresses a requirement but leaves out an important step. It may identify a process but not the person responsible for carrying it out. It may describe a procedure that no longer reflects how the business operates.

Training may teach a process that differs from the current SOP. A form may not document the activity the SOP says it documents. Or the business performs a required activity every single day and has no reliable record showing that it happened.

All of those are compliance gaps.

They just aren’t the same kind of gap.


Four common categories of compliance gaps

A useful gap analysis distinguishes between different kinds of weakness rather than treating every finding as the same deficiency.

CannaPath table showing the 4 common categories of a compliance gap

Missing is the obvious one. There is no corresponding policy, procedure, control, training, form, or record where one is needed. A requirement calls for a written procedure and the business cannot produce it.

Incomplete is more common. The business has a procedure, but important elements are missing. Imagine an SOP that says: 

“Employees will reconcile inventory and correct discrepancies.”

 It sounds reasonable.

But who performs the reconciliation? How often? What information is reviewed? What qualifies as a discrepancy? Who investigates it? Who documents the investigation? Who verifies the correction?

Minnesota’s rules require businesses to keep accurate inventory in the statewide monitoring system, update it at the end of each business day, maintain a written procedure and schedule for verifying inventory accuracy, and keep records showing compliance with that procedure.

The one-sentence SOP may be directionally correct and still be operationally incomplete.


Inconsistent is the category a checklist will never catch. Your SOP says one thing. Your employee training says another. Your form reflects a third process. Your Final Plan of Record describes something slightly different. Each document might look acceptable on its own. The compliance problem exists in the relationship between them.


Unsupported is the one that costs operators the most. The business performs a required activity, and there is not adequate evidence that it actually occurred. That distinction matters in Minnesota because records have to be maintained and made available for inspection, kept in a uniform manner and accessible enough that you can produce them within 24 hours of a request.

A procedure that says an activity occurs is not the same thing as a record showing that it occurred.


The compliance document isn’t the compliance program

This may be the most important concept in this entire article. A compliance program isn’t a folder of PDFs. It is a system, and every link in it has to hold.

CannaPath a compliance program is a chain  not a folder

Consider employee training. Minnesota requires annual training that applies to the worker’s role, authority, and responsibilities. It has to cover your required SOPs along with cannabis laws, privacy and confidentiality, security controls, emergency procedures, and product recall. And you have to keep records showing that workers completed it.

That is three obligations, not one.

The training has to connect to what the employee actually does. It has to reflect your real SOPs. And the records have to exist. A business does not have a complete training control simply because it has a training manual.


What you have to keep, and for how long

Retention is where good operators get surprised. The requirements aren’t uniform, and “we keep everything for a couple of years” isn’t a compliant answer.

CannaPath compliance showing a table of how long record retention is

The 24-hour clock is the part worth sitting with. Twenty-four hours isn’t enough time to reconstruct a record. It’s only enough time to go find one you already have.


A gap analysis should be specific to the business

There is no universal cannabis compliance checklist that can replace a business-specific assessment.

Minnesota has different license types, and the applicable Final Plans of Record and related requirements vary depending on the license and the activities involved. OCM’s current materials identify different required submissions for retailers, cultivators, manufacturers, testing facilities, delivery services, transporters, wholesalers, and other categories.

A retailer should not assume that a compliance framework designed for a cultivator applies to its operation.

The question isn’t “what does a cannabis business need?”

The question is what does this cannabis business need.

That’s an important distinction.


What should be reviewed?

The scope depends on the license and the business activities. A meaningful review usually covers this ground:

CannaPath shows what a gap analysis should actually show

A checklist tells you that a topic exists.

A gap analysis asks whether the control actually works.


The Final Plans of Record problem

Here is the part that catches licensed businesses.

OCM requires applicable applicants to submit Site, Security, and Operations Final Plans of Record, along with Inventory Control and Diversion Prevention, Quality Assurance, and Accounting and Tax Compliance SOP submissions, with additional requirements for transportation, manufacturing, and testing operations.

But businesses change after licensing.

People leave. New people take over.

Equipment gets replaced. A room gets repurposed.

Responsibilities move between employees. 

Your plan of record does not move with it unless somebody makes it move.

And this isn’t only internal housekeeping. Material changes to your Final Plans of Record have to be reported to OCM, and a change to a cultivation plan has to be submitted at least ten business days before you implement it. Square footage. A room repurposed. New equipment. A security system change. New product categories. Those are ordinary improvements, and each one carries a filing obligation.

A business might be operating perfectly well while its documentation slowly becomes a historical description of how the company used to work.

That is compliance drift.

And it is one reason compliance needs to be evaluated periodically rather than only when something goes wrong.

What should a good gap analysis actually produce?

This is where we believe compliance reviews can fall short.

Finding 37 problems isn’t particularly useful if the business doesn’t know which one to fix first.

A useful finding explains what was identified, where the issue exists, what requirement is involved, why it matters, what needs to change, how it can be corrected, and what evidence should exist afterward. Something like this:

 

EXAMPLE FINDING

Finding: The written inventory verification procedure does not clearly identify the responsible role or establish the required verification schedule.

Why it matters: Minnesota rules require a written procedure and schedule for verifying system inventory accuracy, and records showing compliance with that procedure.

Recommended correction: Identify the responsible role, establish the verification frequency, define discrepancy escalation, identify required documentation, and establish supervisory verification.

 

That gives an operator somewhere to go.

Findings also have to be ranked, because you have a finite number of hours and some gaps hurt more than others. Two questions sort them quickly. How likely is this to be asked for, and how bad is it if you can’t answer.

CannaPath shows the order of which gaps to fix first



And this is exactly why we're building CannaPath Sentinel™

CannaPath Compliance Sentinel is a cannabis compliance and business operating platform designed to bring compliance management, documents, employee and training records, inventory, point-of-sale and Metrc information, security, reporting, and compliance deadlines into one system, with The Watch providing an at-a-glance view of items requiring attention.

The more time we spend working with cannabis operators, the more obvious one thing becomes. Compliance does not live in one document. It lives in the relationship between your policies, your procedures, your employees, your training, your records, your inventory, your security, your deadlines, and the way all of those pieces actually work together.

That is a lot to keep track of, and when something changes, the question is rarely just "where is that requirement written?" The better question, and the harder one, is what the change means for the way the business actually operates day to day. That is the problem we are building Sentinel to solve.


What Sentinel is

CannaPath Sentinel™ is a business operating platform for a regulated cannabis business. It holds compliance, sales, inventory, security, people and HR, training, and your compliance calendar in one place, instead of spreading them across six different systems, a pile of spreadsheets, a shared folder, and eleven browser tabs.

The calendar deserves its own sentence, because it is the piece operators tend to react to first. It carries every compliance deadline you have, business and employee both, in one view. Not the license renewal sitting on one calendar while the annual refresher due dates live in somebody's notebook. All of it, in the order it comes due.

There are two systems inside Sentinel worth naming now, because between them they do the work operators ask us about most. Scout runs the compliance gap analysis. The Watch keeps an eye on what is moving.


Scout looks at the whole picture

Scout is the gap-analysis system inside Sentinel, and it runs a structured review in three stages.

The first stage asks what your documents actually say. Scout reads your policies, procedures, forms, and related documentation looking for missing information, conflicting instructions, unclear responsibilities, outdated references, incomplete procedures, and places where two documents disagree with each other. At this stage we are not yet asking whether you are compliant. We are asking whether the documentation makes sense on its own terms.

The second stage asks what you are actually required to do. Your documentation gets evaluated against the requirements in the CannaPath regulatory knowledge base that apply to your specific business and license type. The question shifts from what the document says to whether what the business says it does actually addresses what it is required to do.

The third stage is where it gets interesting, because this is where most compliance programs quietly come apart. Does the training match the SOP? Does the SOP assign responsibility to an actual person? Does the procedure create the record it is supposed to create, and does that record demonstrate the control really happened? Do the related documents agree with each other? A business can hold every required document and still have a compliance system that does not work. That is the difference between locating a document and evaluating a system.

CannaPath Compliance Sentinel is a cannabis compliance and business operating platform designed to bring compliance management, documents, employee and training records, inventory, point-of-sale and Metrc information, security, reporting, and compliance deadlines into one system, with The Watch providing an at-a-glance view of items requiring attention.

Technology does the heavy lifting. People make the judgment.

We are not building a button that says upload your SOPs and congratulations, you are compliant. That would be irresponsible, and anyone selling you that should worry you.

Scout handles the repetitive analytical work that comes with reviewing large volumes of documentation and regulatory material. It identifies potential weaknesses, connects related information, surfaces questions, and organizes what needs attention. Then it hands all of that to a person. A CannaPath compliance professional reviews the findings, challenges the analysis, looks for what the system missed, decides what actually matters, and evaluates the proposed remediation. Where it is warranted, legal review gets folded in as well.

There is one more distinction worth making, and it is the one operators feel most. A document can tell you what your employees are supposed to do. It cannot tell you what they actually do when nobody is watching. Compliance has never been only a document problem, which is why the review is one system inside Sentinel rather than the whole of it.


Finding the gap is only half the job

A deficiency list has its uses. But every operator who has ever received one arrives at the same question about ninety seconds later. Okay, how do I fix it?

That is where Scout is designed to go next. Rather than telling you something is missing and leaving you there, the goal is to show you what was found, why it matters, where it shows up, and what should change. And yes, it actually tells you the fix. It wont do it for you, but it will tell you how to do it. If it is something you would rather not fix, it will also show you how much it would cost to have CannaPath fix the issue for you, and our store policy holds true here. One thing we have heard you all say is something to the effect of how many times will i have to pay for this problem. We agree, so if you decide to have CannaPath fix it for you, the cost of the the review is deducted from the cost of remediation. You may decide to handle it in house, or you may decide to hand it to us. Either way you should know what the problem is and what your choices are before you spend a dollar.


Find it. Understand it. Fix it.


A gap analysis should make you stronger, not more nervous

Compliance gets presented too often as a hunt for reasons a business might fail. That is not how we see it. A good gap analysis hands you your own weaknesses while you are still in control of the outcome, on your own schedule, before anybody else is asking. In an industry where an inspection can arrive without notice, that timing is the entire point. The worst possible moment to learn that a procedure is incomplete is while somebody is standing in front of you asking you to demonstrate it.

So Sentinel is not about replacing compliance professionals, and it is certainly not about letting a computer declare a business compliant. It exists to make four questions easier to answer. What are we required to do? What do we say we do? What do we actually do? And where are the gaps, and how do we close them?


And then there is The Watch

Scout tells you where you stand right now. The Watch is the part of Sentinel that keeps telling you, on an ongoing basis, what is coming and what has slipped. Deadlines, requirements, documentation, training, operational issues, the things that have a habit of staying quiet right up until they do not.

The Watch is not there to run your business. It is there to help you see it.

CannaPath Compliance Sentinel cannabis business operating platform dashboard showing compliance, documents, people and HR, training, inventory, POS, Metrc, security, reports, compliance calendar, and The Watch monitoring the operational and compliance items that need attention.

Scout is available now, ahead of the rest

The original plan was to keep all of Sentinel behind the curtain until the whole platform was ready to show. Then we kept talking to owner-operators, and we kept hearing a version of the same thing. They understand compliance. They have built their policies. They believe they are doing what they are supposed to be doing. They just do not know whether what they have is actually right. And for a business already juggling payroll, taxes, inventory, and rent, bringing in a full compliance engagement is not always a realistic answer to that question.

So we changed our minds. Scout is open now, before the rest of the suite, as a standalone review you can use without a contract.

It gives your compliance documentation a second set of eyes, looking for missing requirements, inconsistencies, unclear instructions, and the areas that deserve a closer look. It is not a magic compliance button and it is not a substitute for professional judgment, which is exactly why a CannaPath compliance professional reviews every finding before it reaches you.

A word about what Sentinel is, since the question comes up. Sentinel is a platform, built around compliance, operations, and the real work of running a cannabis business. There will be an AI assistant inside it, and its job is to help you work with your own information, answer questions, find things, and make the system easier to use. It does not make compliance decisions and it does not issue findings. A person does that, every time. We built Sentinel on the belief that technology should make a good operator better at the job, not convince them they have stopped needing to think.

We are so very excited to introduce everyone to Sentinel, its been a long journey, and its really exciting to see this dream actually working in stores. We are almost complete with our testing and hope to officialy launch this in March of 2027. We have included the email list to be notified about Sentinel. As always, we do not have time to email market, so you will only ever recieve updates on Sentinel not anything else. We dont have time for that and neither do you.


-Drew


Want to take a look?

Scout is live now as the first publicly available piece of Sentinel. If you have a compliance document sitting in front of you and you want to know whether it would hold up if someone inspected you tomorrow, that is the exact question Scout was built to help you answer.











Initial Compliance Consultation
30min
Book Now

bottom of page