What Is a CJIS Compliance Audit? A Complete Guide

Written by: 
Team Knox
Published on: 
September 11, 2026

A compliance audit under the FBI's Criminal Justice Information Services (CJIS) program lets the FBI and designated state agencies verify that every organization accessing Criminal Justice Information (CJI) protects it as required by the FBI CJIS Security Policy. Agencies that do not remediate findings can lose access to the national systems they depend on.

Key Takeaways

  • Two Audit Tiers. The FBI's CJIS Audit Unit audits state-level CJIS agencies, and those state agencies audit the local agencies and contractors connected to their systems.  
  • Defined Policy Areas. Auditors work through the CJIS numbered policy areas and cover training records, access control, logging, personnel screening, physical security, and vendor agreements.  
  • Four Audit Phases. Notification begins about six months out, followed by an on-site review, an exit briefing with a formal report, and remediation tracked through a corrective action plan.  
  • Remediation Maintains Access. Resolving findings helps agencies maintain CJIS access, while prior noncompliance can lead to more frequent audits.

A CJIS Compliance Audit Verifies That Criminal Justice Information Is Protected Under FBI Security Policy

The FBI defines CJI as "all of the provided biometric, identity history, biographic, property, and case/incident history data necessary for law enforcement and civil agencies to perform their missions." The CJIS Security Policy sets the minimum standard for protecting that data across its full lifecycle and applies to everyone who touches it, including contractors and private entities.

The current release is version 6.1 (June 25, 2026), but version 5.9.5 remains the FBI audit standard through March 31, 2027, so audit preparation should track the version the auditing agency applies.

A compliance audit verifies that protection exists in practice. Auditors assess technical and organizational controls against the policy's requirements, including documentation, staff behavior, physical access, and vendor relationships. Both criminal justice agencies (CJAs), such as police departments and courts, and noncriminal justice agencies (NCJAs) that access CJI for purposes like employment screening or IT support are subject to audit; NCJAs operate under a Management Control Agreement (MCA) that puts a CJA in oversight of their work.

The FBI CJIS Audit Unit and State CJIS Systems Agencies Share Audit Authority

Audit authority runs through two tiers. At the federal level, the CJIS Audit Unit (CAU) within the FBI CJIS Division audits each CJIS Systems Agency (CSA), the single criminal justice agency per state or territory that provides statewide CJIS access. Each CAU audit of a CSA includes a sample of local CJAs and NCJAs.

At the state level, policy assigns each CSA three obligations:

  • Direct-access audits. Audit every CJA and NCJA with direct access to the state system, as the Michigan CJIS Compliance Unit does.  
  • Indirect-access audits. Periodically audit NCJAs with indirect CJI access.  
  • Contractor oversight. Have the authority to conduct unannounced security inspections and scheduled audits of contractor facilities.

Private contractors face the same extent of review as local user agencies, primarily through their contracting agency and CSA, while the FBI retains parallel authority to inspect contractor facilities. FBI cloud guidance applies the same rule to infrastructure: datacenters storing or processing CJI are audited like any other CJI datacenter.

The 13 Policy Areas Most CJIS Audits Still Examine

Policy versions through 5.9.x organize requirements into 13 policy areas, sections 5.1 through 5.13, which still define the evidence most audits examine. Version 6.0 reorganized these into 20 control families aligned with NIST SP 800-53 Rev5 and added families such as Supply Chain Risk Management that had no 5.9.x predecessor.

  1. Information Exchange Agreements (5.1). Auditors confirm a signed CJIS Security Addendum is on file for every private contractor accessing CJI, and that sharing agreements are current.  
  2. Security Awareness Training (5.2). Auditors review completion records maintained by the CJIS Systems Officer (CSO) or State Identification Bureau (SIB) Chief and verify required training completion within six months of assignment and every two years thereafter.  
  3. Incident Response (5.3). Auditors look for a documented plan that defines reportable incidents, assigns roles, and specifies recovery procedures, with evidence that events are reported to the CJIS Information Security Officer.  
  4. Auditing and Accountability (5.4). Auditors verify that all CJI access is logged, that logs are retained at least one year, and that someone reviews them for unauthorized activity.  
  5. Access Control (5.5). Auditors verify Role-Based Access Control (RBAC) restricts permissions to job-necessary functions and enforces least privilege.  
  6. Identification and Authentication (5.6). Auditors check that multi-factor authentication (MFA) combines two distinct factor types; the requirement has been sanctionable since October 1, 2024.  
  7. Configuration Management (5.7). Auditors ask for a current network topology diagram and documented baseline configurations.  
  8. Media Protection (5.8). Auditors verify CJI media is protected in storage and transport.  
  9. Physical Protection (5.9). Auditors tour facilities to verify badge or biometric access controls and review visitor access records.  
  10. Systems and Communications Protection and Information Integrity (5.10). Auditors verify CJI encryption in transit and at rest.  
  11. Formal Audits (5.11). Establishes the recurring audit cycle and the authority to audit more frequently once noncompliance is found.  
  12. Personnel Security (5.12). Auditors check that fingerprint-based background checks preceded unescorted access, that suitability is periodically re-evaluated, and that access is revoked upon departure or role change.  
  13. Mobile Devices (5.13). Auditors verify that devices accessing CJI run mobile device management (MDM) with the required security functions.

These 13 areas define what auditors look for; the next section covers when and how they look for it, moving through the four phases that structure every CJIS audit.

A CJIS Audit Moves Through Four Phases, From Notification to Remediation

An audit unfolds in four stages that review CJIS compliance.

1. Pre-Audit Notification

The audit manager contacts the agency point of contact about six months before the scheduled audit, then sends a pre-audit questionnaire and a document request: SOPs, the incident response plan, Security Addendums, MCAs, and a network diagram. Some CSAs set tight submission windows.

2. On-Site Review

Auditors interview the point of contact, tour the facility, review data quality, and examine technical evidence: access logs, MFA usage logs, RBAC configuration, background check documentation, and signed vendor addendums. They may request evidence of encryption and mobile-device controls.

3. Exit Briefing and Formal Report

The briefing occurs on the final on-site day with agency leadership, the CJIS coordinator, and IT staff. The formal report identifies compliance areas, deficiencies, required remediation steps, timelines, and recommendations. The CAU presents results to the CJIS Advisory Policy Board's Compliance Evaluation Subcommittee, which can recommend formal sanctions.

4. Remediation

Agencies address findings through a corrective action plan and submit evidence of corrective measures to the state CSO. The CAU tracks every recommendation until it is resolved. Unresolved deficiencies can lead to restricted access or removal of CJIS privileges. Because findings surface at the exit briefing, corrective work can begin before the written report arrives.

Across all four phases, the same categories of deficiencies tend to appear, and auditors expect agencies to recognize them and have corrective actions ready. The next section walks through the most common findings and the fixes that close them.

Common CJIS Audit Findings Have Defined Corrective Actions

Each recurring gap has a corresponding fix.

  • Incomplete or outdated audit logs. Use complete, automatic logging with an unbroken trail across system transitions and review it on a set schedule.  
  • Inadequate or undocumented background checks. Audits have caught agencies that never fingerprinted city IT staff. Submit the check, receive the results, and then grant access, including contractors and vendors.  
  • Incomplete security awareness training records. Complete scheduled training and maintain current records in one central location.  
  • Missing or unsigned Security Addendums. Maintain a full vendor inventory, require signature before any access, and review agreements periodically.  
  • Weak access controls and noncompliant MFA. Enforce MFA in the system itself, issue unique credentials to every user, and document periodic access reviews.  
  • Untested incident response plans. Test and update the plan after incidents and audit findings.

Michigan vendor guidance tells agencies to ask any vendor claiming CJIS compliance who determined that; if the vendor has not been through a CJIS audit, the contracting agency carries the verification burden.

Formal Audits Run on a Three-Year Cycle, With Self-Assessments Recommended in Between

CJIS Security Policy Section 5.11.1.1 authorizes the FBI to conduct audits "once every three (3) years as a minimum" and directs the CAU to audit each CSA on that cycle; CSAs have the same obligation for agencies with direct state system access. The cycle accelerates when a prior audit reveals noncompliance. An off-cycle review can also follow:

  • Security incidents.  
  • Newly connected agencies.  
  • Physical moves.  
  • Major system upgrades.

Between formal audits, agencies can conduct internal CJIS audit self-assessments to surface gaps before formal notification leaves less time to address them. Version 6.0 additionally introduces continuous compliance expectations and vulnerability scanning requirements that govern audits only once a CSA adopts the newer policy.

FedRAMP and CJIS Are Separate Frameworks That SaaS Vendors Serving Law Enforcement Need to Satisfy Together

FedRAMP and CJIS answer different questions. FedRAMP authorizes a cloud service to handle federal data at a defined impact level; a CJIS audit verifies that CJI is protected under the FBI CJIS Security Policy. FBI guidance is explicit that FedRAMP and other authorizations "do not guarantee compliance with the CJIS Security Policy."

SaaS vendors selling into law enforcement typically need both: FedRAMP opens federal procurement, while CJIS clearance lets agencies route CJI through the platform. Neither substitutes for the other.

Inheritance keeps that dual scope manageable. A SaaS product built inside a pre-authorized FedRAMP boundary inherits platform-level controls, physical protection, media protection, boundary protection, and much of configuration management, rather than rebuilding them. The vendor's team can then focus on the application-layer and CJIS-specific obligations the CSA audits directly: RBAC, MFA, incident response, Security Addendums, and training records.

CJIS Compliance Is an Operating Program, Not a One-Time Certification

CJIS compliance audit is a recurring test of an operating program. Agencies and vendors that treat the policy areas as ongoing obligations walk into notification with evidence already assembled. Those that wait for the six-month notice absorb the audit as a project.

Knox Systems' government cloud platform provides a pre-authorized FedRAMP boundary that SaaS vendors build inside of, inheriting platform-level controls and automated continuous monitoring while their teams focus on the application-layer and CJIS-specific work each CSA will audit.

Book a meeting to see how inheriting the boundary changes the timeline on federal deals.

FAQs About CJIS Compliance Audits

Which Policy Version Should Guide Audit Preparation?

Use the version identified by the applicable CSA. Version 5.9.5 remains the FBI audit standard through March 31, 2027; version 6.0 restructures the policy into 20 control families aligned to NIST SP 800-53; version 6.1 (June 25, 2026) is the current release but not yet used for audits.

Can a Local Agency Be Reviewed Through Both Audit Tiers?

Yes. A federal CAU audit of a CSA can include a sample of local CJAs and NCJAs, while the CSA separately audits agencies connected to the state system.

How Do Findings, Recommendations, and Sanctions Differ?

A finding identifies a deficiency; a recommendation specifies action tracked until resolution. Formal sanctions are a separate potential consequence and may be recommended through the CJIS Advisory Policy Board process.

When Is Remediation Considered Complete?

Implementing a corrective measure is only part of closure. The agency must submit evidence of the correction, and the recommendation remains tracked until the auditors recognize it as resolved.