Compliance & Controls

Cannabis Compliance & Internal Audit Controls: Metrc Tracking Systems

Cannabis operations carry two risks most businesses do not face simultaneously: substantial cash on premises and a state-mandated obligation to account for every gram of a high-value, diversion-prone product. Internal controls are what convert those risks from existential to managed. This page sets out the control framework we design, implement, and test for Maryland licensees.

Cash management and handling security protocols

Cash controls begin with the principle of dual custody: no single individual should ever have unobserved, unreconciled access to cash. Every count, every transfer, and every deposit preparation is performed by two people, documented on a form both sign, and recorded on camera with retention that exceeds the reconciliation cycle. Where an operator has banking access, deposits are made on a fixed schedule by armored transport with sealed, numbered bags logged at both ends.

The register cycle is the operational heart of the system. Each drawer starts with a counted and signed opening balance from a controlled float. Mid-shift drops move cash above a stated threshold into a drop safe that cashiers cannot open. At close, drawers are counted in a secured area by a person other than the cashier who used them, compared to the point-of-sale expected total, and any variance beyond a small tolerance is documented, investigated, and escalated. Tolerances are set in advance and tracked by employee over time, because a persistent small variance pattern is more diagnostic than a single large one.

The vault is treated as a separate custody environment with its own access log, its own dual-control requirement, and a count performed by someone independent of daily cash handling. Vault-to-deposit and deposit-to-bank movements are reconciled to bank records within days, not weeks. Cash on hand is reconciled to the general ledger cash account every period, and unreconciled differences are treated as control exceptions rather than rounding.

Segregation of duties is enforced across the accounting cycle as well: the person who has custody of cash does not record cash transactions, the person who records does not reconcile, and the person who reconciles does not approve adjustments. In smaller operations where full segregation is impractical, we install compensating controls — owner review of specific reports, independent bank reconciliation, mandatory vacation and cross-training, and periodic surprise counts — and document why those compensating controls address the specific risk.

Every element of this framework is written down. A control that lives only in an experienced manager's habits disappears the day that manager leaves. We produce a cash handling manual, train to it, test against it, and revise it when operations change.

  • Dual custody with signed documentation and camera coverage for every count
  • Controlled floats, mid-shift drops, and blind close-out counts by a second party
  • Independent vault counts, access logs, and rapid bank reconciliation
  • Enforced segregation of custody, recording, reconciliation, and approval
  • Written cash handling manual with training records and surprise testing

Anti-diversion software audits and access governance

Diversion is the risk that regulated product leaves the licensed system without being recorded as a compliant sale or destruction. It is detected through data patterns far more often than through direct observation, which makes the audit of point-of-sale, inventory, and seed-to-trace software a core internal audit function rather than an IT matter.

Access governance comes first. Each user account is tied to a named individual, permissions follow the minimum necessary to perform the role, and administrative rights are restricted to a documented short list with a second approver required for changes. Shared logins are eliminated, because a shared login makes every subsequent forensic question unanswerable. Offboarding revokes access same-day, and we run a quarterly recertification in which managers affirm each account and permission level in writing.

Audit logging must be enabled and preserved. We test that the system records inventory adjustments, price overrides, discount applications, void and refund transactions, package manipulations, and permission changes, each with user, timestamp, and prior value. We then review those logs on a schedule against exception criteria: adjustments outside business hours, repeated overrides by the same user, high-value discounts, voids concentrated at particular times or terminals, and package edits close to a reporting deadline.

Analytical review adds a second detection layer. We compare shrink rates by location, category, employee, and shift; measure yield ratios in cultivation and conversion ratios in processing against historical and peer ranges; test package weights against expected values; and examine destruction events for pattern and documentation quality. Outliers do not prove diversion, but every outlier gets an explanation supported by evidence, and the discipline of requiring that explanation is itself a deterrent.

Findings are reported with a severity rating, an owner, a remediation date, and a follow-up test. An internal audit function that identifies issues without closing them provides documentation of a known problem, which is worse than no audit at all.

  • Named user accounts, least-privilege permissions, no shared logins
  • Quarterly written access recertification and same-day offboarding
  • Preserved audit logs for adjustments, overrides, voids, and package edits
  • Scheduled exception review against defined analytical criteria
  • Findings tracked with owner, remediation date, and verification test

Metrc track-and-trace reconciliation: matching ledger assets to live weights

Metrc is Maryland's state-mandated track-and-trace system, and it is the regulator's version of the truth. The accounting records are the operator's version. Reconciling them is not optional housekeeping — a persistent divergence between the two is simultaneously a licensing exposure, a tax exposure, and a signal of an operational control failure.

The reconciliation runs at package level. We extract the Metrc package inventory for the licensed premises as of the cutoff, extract the inventory subledger for the same cutoff, and match on package identifier. Four categories result: matched with agreeing quantity, matched with quantity variance, present in Metrc but not in the ledger, and present in the ledger but not in Metrc. Each of the last three is an exception with a required resolution, and none is closed with an unexplained adjusting entry.

Quantity variances in plant-touching inventory frequently trace to legitimate operational causes: moisture loss during drying and curing, sampling for required laboratory testing, quality-control holds, waste generated during trimming, and rounding at repackaging. These are expected and must be recorded, with the operational reason, at the time they occur. Variances that appear only at reconciliation, with no contemporaneous operational record, are the ones that matter, and we treat them as control exceptions requiring investigation and management sign-off.

Live weight reconciliation in cultivation deserves its own procedure. Plants are counted and tagged by stage, harvest wet weight is captured at the point of cut, drying loss is measured and recorded as a percentage against historical norms, and cured finished weight is reconciled back to wet weight through the recorded loss. When the moisture loss percentage drifts outside the established band, the cause is identified — environmental conditions, strain characteristics, scale calibration, or recording error — before the batch is closed. Scales are calibrated on a documented schedule, because an uncalibrated scale generates variances that look like diversion and consume investigation resources.

Transfers between licensed entities are reconciled at both ends: manifest, physical receipt, Metrc acceptance, and ledger entry must all agree, and discrepancies are raised with the counterparty within the reconciliation cycle rather than at year end. Destruction events require the manifest, the required hold period documentation, witness signatures, and the corresponding ledger write-off, filed together.

The deliverable for each cycle is a reconciliation package: the Metrc extract, the subledger extract, the match report, the exception log with resolutions and approvals, the variance analysis with commentary, and a sign-off by a reviewer independent of inventory custody. Maintained monthly, that package answers the MCA, the auditor, and the tax examiner from the same file — and it makes an ownership transfer or a financing diligence process substantially faster.

  • Package-level match between Metrc extract and inventory subledger each cycle
  • Four-category exception classification with mandatory documented resolution
  • Contemporaneous recording of moisture loss, sampling, holds, and trim waste
  • Wet-to-cured weight reconciliation with monitored loss bands and calibrated scales
  • Two-sided transfer reconciliation and complete destruction event files
  • Independent reviewer sign-off on every reconciliation package

Talk to a Maryland cannabis CPA

Every engagement starts with a working conversation about your license type, your systems, and where your reporting currently breaks down.