Deploy · NYS Systems & Compliance Audit
A person-led review of your systems and records, graded and fingerprinted.
The NYS Systems & Compliance Audit is a New York-focused review of how a dispensary’s systems, records and controls actually run, across fifteen categories. An auditor, a person, does the work; the software gathers the evidence and lays the report out.
It is not an OCM inspection and not legal advice. It is designed to reduce compliance exposure by showing you, with evidence, where your records and controls stand.
Starting price for one location. A Smoke Alarm audit is not an OCM inspection and is not legal or regulatory advice.
- Categories
- 15
- Grades
- REDYELLOWGREENBLUE
Fifteen categories.
Each finding is filed under one category and cites the public source it was tested against. A category with nothing to report says so; it is not left out.
- 01Metrc workflow
- 02Receiving
- 03Manifests
- 04Inventory
- 05Point of sale
- 06Retail IDs and barcodes
- 07Reconciliation
- 08Returns
- 09Expirations
- 10Vendor workflow
- 11Delivery readiness
- 12Security
- 13User permissions
- 14Operational controls
- 15Automation opportunities
Four grades, each a word as well as a colour.
Every finding carries one grade. RED and YELLOW findings get a remediation plan; GREEN records what was tested and met; BLUE points at something the software could do for you.
- RED
- Violation or immediate risk
- YELLOW
- Weakness
- GREEN
- Meets the requirement
- BLUE
- Information or best practice
A person does the audit. The software does the gathering.
- 01
Request
You ask for an audit of one location or the whole organisation over a period. Nothing is written to Metrc or your POS at any point.
- 02
Pre-audit scan
An automated pass over your own records in Smoke Alarm for the period proposes findings with the evidence behind each: sales and ID checks, dock and register decisions, package states, lab results, recalls, expiry, adjustments, reconciliation findings, the Metrc queue, tax rules, roles and the audit history.
- 03
The auditor works
A person accepts, edits or discards every proposal and adds findings of their own from interviews, walkthroughs and documents. Only findings a person accepted are in the report. No finding is written by AI.
- 04
Review and delivery
The report is reviewed, then rendered as a PDF, fingerprinted with its SHA-256 and stored. After delivery it cannot change.
- 05
Remediation
Your owner or compliance manager tracks each RED and YELLOW finding to done in the app, with evidence attached to each fix.
A fingerprinted PDF report you own.
What is in it
A cover with the scope and period, the method statement, every finding numbered F-01 onward with its grade, category, evidence and cited source, the remediation plan for RED and YELLOW findings, and the list of evidence files with their SHA-256s.
Its fingerprint
A PDF cannot carry its own hash, so the SHA-256 of the delivered file is stored with the audit, shown on its page and written to the audit history. Anyone with the file can compute it and compare.
Its limits, stated inside
The report says on its own pages that it is Smoke Alarm's review of your records against cited public sources, not a government inspection, not an approval or certification by any agency, and not legal advice.
A person-led audit across fifteen categories, findings graded red, amber, green and blue, delivered as a fingerprinted report.
Starting price for one location. A Smoke Alarm audit is not an OCM inspection and is not legal or regulatory advice. Confirm any requirement with the cited source and your counsel before relying on it. The audit does not require a Smoke Alarm subscription; the report is yours to use with or without one.
Ask for an audit.
Tell us the location and the period. We come back with the scope, the schedule and a price from the starting figure above.