Skip to content
Investigator organizing audit binder and evidence

CJIS Compliance: What Agencies Must Do Before the Audit

CJIS compliance means meeting the FBI CJIS Security Policy baseline and being prepared for periodic audits that combine a written questionnaire with a possible onsite visit. The current policy sets the minimum controls every agency handling Criminal Justice Information must have in place, no exceptions. Start this week by confirming who serves as your LASO and TAC, pulling together your core documents (SOPs, security addenda, network diagrams), and verifying your FIPS certificates and log retention actually match what the policy requires.


TL;DR:

  • Auditors focus heavily on technical controls such as FIPS certificates, multi-factor authentication, and encryption validation for CJI, which require verifiable evidence.
  • Background checks, personnel sanctions, and training records must be continuously documented and easily retrievable to avoid common audit failures.
  • Physical security gaps around server rooms and outdated system patches frequently trigger findings that are preventable with regular reviews and updates.
  • Building and maintaining an organized audit binder by questionnaire section streamlines onsite verification and reduces review time.
  • Agencies should treat compliance as an ongoing operational culture, not just a pre-audit task, ensuring evidence collection is integrated into daily practices.

Table of Contents

What Is CJIS Compliance and Who Does It Cover?

CJIS compliance is adherence to the FBI CJIS Security Policy, which sets the minimum security controls for protecting Criminal Justice Information (CJI) across its entire lifecycle, from collection to storage to disposal. The policy operates on a shared-management philosophy: the FBI sets the baseline, state CJIS Systems Agencies (CSAs) enforce it locally, and individual agencies implement it day to day. As of the current release, version 6.1, published in June 2026, these requirements apply broadly.

Coverage extends beyond sworn officers and dispatchers. The policy reaches:

  • Criminal justice agencies (CJAs) like police departments, sheriff’s offices, and courts
  • Noncriminal justice agencies (NCJAs) that touch CJI for licensing, background checks, or regulatory work
  • Contractors and vendors, including cloud providers and software vendors, once they store, process, or transmit CJI on an agency’s behalf

Any vendor relationship involving CJI triggers CJIS obligations regardless of how the data moves.

Which CJIS Policy Areas Do Auditors Check Most?

The CJIS Security Policy organizes its controls into distinct policy areas, and auditors do not weigh them equally. Expect close attention on:

  • Information exchange agreements between agencies and third parties
  • Security awareness and training documentation
  • Auditing and accountability, meaning logs that prove controls are actually working
  • Physical and environmental protection around CJI storage
  • Personnel security, including background checks and access sanctions
  • Technical requirements covering encryption, authentication, and system access
  • Incident response planning and documented procedures

The policy is written almost entirely in “shall” statements, more than 500 of them, and each one is a binding requirement rather than a suggestion. Section 5’s technical controls generate the most audit friction because they demand hard evidence, not policy language. A written encryption policy means nothing if you can’t produce the certificate proving the module is FIPS-validated. Auditors weight information exchange agreements, technical controls, and personnel security heaviest, so prioritize evidence gathering there first.

How Does the CJIS Audit Process Actually Work?

CJIS audits run on roughly a three-year cycle, performed by your state CSA or, in some cases, directly by the FBI, and they unfold in two distinct phases according to the DOJ CJIN Audit Policy.

  1. Online questionnaire. Your agency logs into a state audit portal and answers detailed questions mapped to specific policy sections, uploading supporting documents as you go.
  2. Onsite verification (if triggered). Auditors visit in person to review policies firsthand, interview personnel including your LASO, walk the facility to check physical security, and cross-check the evidence you submitted online.
  3. Findings and closeout. Auditors document gaps, and agencies typically get a defined window to submit a corrective action plan before the file closes.

Out-of-cycle audits can happen after a reported breach, a formal complaint, or major system changes that alter how CJI flows through your agency. Notification usually arrives weeks in advance of the online phase, giving agencies a real runway if the groundwork is already done. Waiting until notification arrives is where most agencies lose that runway entirely.

What Documents Do You Need for a CJIS Audit?

Texas DPS’s own technical audit guidance names the exact artifacts examiners request, and it’s a useful blueprint regardless of which state runs your audit. Build toward this list now, not the week notification lands:

  • Standard operating procedures covering access control, incident response, and account management
  • Signed vendor security addenda and Management Control Agreements (MCAs)
  • Current network diagrams showing where CJI flows and where it’s stored
  • FIPS-validated cryptographic module certificates
  • Training logs tied to individual personnel, not a generic roster
  • Proof of fingerprint-based background checks for every person with unescorted CJI access
  • Access logs, patch records, and encryption certificate exports

Pro Tip: Assign a single evidence owner per document category before the questionnaire opens. Auditors move faster when one person, not a committee, can produce the exact file on request.

Build an “audit binder,” physical or digital, that pairs every questionnaire item with the artifact answering it. When the onsite team asks about account deactivation procedures, you point to a tab instead of searching a shared drive live in front of them.

What Technical Controls Does CJIS Require?

Technical evidence is where audits are won or lost, because policy statements alone don’t satisfy Section 5. Auditors expect to see:

  • FIPS-validated cryptographic modules encrypting CJI both in transit and at rest, verifiable against the NIST CMVP validated modules list
  • Advanced authentication, meaning multi-factor authentication, for any remote or mobile access to CJI
  • Documented password complexity, session lock timing, and account lockout thresholds
  • Audit logs retained long enough to demonstrate ongoing monitoring, not just a policy stating retention periods

Cloud services can sit in scope, but the provider’s compliance claims don’t cover your agency automatically. Vendors like Microsoft describe how their cloud offerings support CJIS requirements, but the customer still needs a signed security addendum and its own configuration review before that CJIS-compliant cloud environment counts toward your audit.

What Personnel Security Rules Apply Under CJIS?

Personnel security decides more audit outcomes than agencies expect, largely because the paperwork trail is easy to let slide. Anyone with unescorted access to CJI, sworn or civilian, needs a fingerprint-based background check completed before that access is granted, not after.

  • Document each background check with date, method, and disposition, not just a pass/fail note
  • Track personnel sanctions and access revocations tied to specific policy violations
  • Keep training records tied to individuals: completion certificates, LMS exports, and signed attendance logs

CJIS requires security awareness training at onboarding and annually after that. A binder full of blank certificate templates convinces no one. Auditors want names, dates, and a paper trail that matches your personnel roster exactly.

Who Is Responsible for CJIS Compliance at Your Agency?

Governance gaps show up fast in an audit, mostly because agencies assume roles are understood rather than documenting them. Four roles matter most:

  • CSA (CJIS Systems Agency): the state-level body enforcing the policy and running most audits
  • CSO (CJIS Systems Officer): the state’s accountable executive; this responsibility cannot be outsourced to a vendor
  • LASO (Local Agency Security Officer): your agency’s on-the-ground point person for CJIS compliance
  • TAC (Terminal Agency Coordinator): manages system access and user accounts

Vendor relationships need signed Security Addenda and, where applicable, Management Control Agreements spelling out exactly what data the vendor touches. Some state CSAs layer stricter requirements on top of the federal baseline, so confirm local variance before assuming the national policy is your ceiling.

What Are the Most Common CJIS Audit Findings?

Certain gaps show up across agencies of every size, and they’re almost all preventable with earlier evidence gathering.

  • Missing or expired FIPS certificates for encryption modules actually in use
  • Standard operating procedures that exist but were never updated to match current systems
  • Outdated patches on systems that touch CJI
  • Account management evidence that’s thin, meaning no proof of periodic access reviews
  • Physical security gaps around server rooms or evidence storage

Pro Tip: When a finding lands, assign an owner within 48 hours, document the corrective action plan in writing, and request a follow-up verification date rather than waiting for the auditor to schedule one. Agencies that move fast on remediation typically close findings within the timeframe the CSA sets, and auditors generally treat corrective action plans as collaborative rather than punitive, according to FBI audit guidance.

Building an Audit Binder Agencies Can Actually Use

An audit binder works best organized by questionnaire section, with each tab holding the specific artifact, its owner, and its storage location. That structure alone saves hours during an onsite visit.

  • Personnel security tab: background check records, sanction logs, unescorted-access approvals
  • Technical controls tab: FIPS certificates, MFA configuration screenshots, password policy documents
  • Governance tab: LASO/TAC appointment letters, vendor Security Addenda, MCAs
  • Training tab: completion certificates, LMS exports, annual refresher logs

Export formats matter here. Auditors move faster with PDF exports carrying timestamps and named owners than with raw spreadsheet dumps. Role-based views, where a LASO sees personnel records and a TAC sees access logs without wading through unrelated files, cut review time during interviews significantly.

What Agencies Get Wrong About Audit Readiness

Access control device in evidence room

Most agencies treat CJIS compliance as a paperwork exercise finished once policies are written and filed. That assumption is where audits go sideways. Auditors are explicitly trained to look for a culture of compliance, meaning evidence that policies are enforced day to day, not just documented on paper. A password policy nobody enforces and a training program nobody completes are functionally the same as having no policy at all.

Diagram of culture of compliance enforcement components

The conventional advice tells agencies to “start preparing a few months before the audit.” That’s backward. The agencies that sail through audits treat evidence collection as a continuous operational habit, not a pre-audit sprint. Background checks get logged the day they’re completed. Training completions get exported monthly, not scavenged from an LMS the week before the questionnaire opens.

If there’s one place agencies underinvest, it’s personnel security. Technical controls get budget attention because they sound sophisticated. Background-check documentation and training logs get treated as clerical work, right up until an auditor asks for a specific record and nobody can produce it in under ten minutes. Fix that gap first. It’s the cheapest fix on this entire list, and it’s the one auditors flag most often.

— Matt

How OMNI Intel Keeps Personnel Records Audit-Ready

Personnel security findings are avoidable, and they’re avoidable specifically because the evidence, background checks, sanctions, access approvals, is data your agency already generates. The gap is usually retrieval, not collection.

OMNI Intel

OMNI Intel is built around that exact problem for public safety agencies. Every fingerprint-based background check, sanction record, and access approval processed through the platform is stored with a timestamp and an owner attached, so when a LASO needs to hand an auditor proof of a specific hire’s screening history, it’s a search, not a scavenger hunt. That’s a real difference from managing personnel files across shared drives and paper folders scattered between HR and the LASO’s desk. OMNI Intel’s screening workflows are built around the same evidentiary standard CJIS audits expect, exportable records, clear ownership, and a defensible chain from application to hire.

If your agency is heading into an audit cycle, start with your pre-employment screening process and confirm your background-check records would hold up if an auditor asked for them tomorrow. Request a demo to see how OMNI Intel’s background check platform maps directly to CJIS personnel-security requirements.

Key CJIS Resources Worth Bookmarking

Sources

FAQ

What Are the Compliance Requirements for CJIS?

Agencies must implement the technical, physical, and personnel controls in the FBI CJIS Security Policy, covering encryption, authentication, background checks, training, and incident response, and be prepared to prove those controls work through an audit.

What Are the CJIS Compliance Requirements for 2026?

The requirements follow CJIS Security Policy version 6.1, published in June 2026, which keeps the core structure of prior versions while refining technical and personnel security expectations across the policy areas.

Is Google Docs CJIS Compliant?

A cloud tool is never CJIS compliant on its own; compliance depends on the provider offering a CJIS compliant cloud environment with a signed security addendum and the customer configuring access, encryption, and logging correctly.

What Is the Current Version of the CJIS Security Policy?

The current version is 6.1, published June 25, 2026, and it serves as the FBI’s baseline security standard for all agencies and vendors handling Criminal Justice Information.

How Often Do CJIS Audits Happen?

CSAs audit user agencies at least once every few years, though a breach, complaint, or major system change can trigger an audit outside that normal cycle.