Home / Services / Audit Services / IT Systems & Security Audits
Audit Services

IT Systems & Security Audits

Your POS, your seed-to-sale system, and your accounting platform hold everything a regulator or examiner would want to see.

Your POS, your seed-to-sale system, and your accounting platform hold everything a regulator or examiner would want to see. If access controls are weak or the systems do not reconcile, both your compliance position and your financial records are exposed.

What's Included

โœ“POS configuration โ€” and integrity review
โœ“Seed-to-sale access โ€” controls and audit trail
โœ“Accounting permissions โ€” and segregation
โœ“Integration integrity โ€” between systems
โœ“Backup and retention โ€” adequacy
โœ“User access review โ€” and privilege audit

Why This Differs In Cannabis

Your state tracking system is a regulatory record. Who can modify it, whether modifications are logged, and whether it reconciles to your ledger are compliance questions, not just IT ones. An employee with unnecessary edit privileges in METRC is a licensing risk, and an unlogged override is an evidentiary hole.

An unlogged override is an evidentiary hole.

Why MCA

We have served licensed cannabis operators since 2015 โ€” one of the first firms in the country to build a practice around it โ€” and we have worked with more than 100 operators across 30+ states. Cannabis is all we do, and all we have ever done.

Frequently Asked

Is this a cybersecurity audit?

Partly. Our focus is the integrity of financial and compliance data rather than network security broadly.

Which systems?

METRC, BioTrack, major cannabis POS platforms, and standard accounting systems.

How long?

Typically two to three weeks.