

Who Has
Your CJI?
TM
You Think You Know Who Has Access to Your Criminal Justice Information. You Probably Don't.
This is not a hypothetical. It is not a worst-case scenario. It is the single most consistent finding across every CJIS compliance engagement conducted in the field — inside agencies, inside vendors, inside every organization that touches Criminal Justice Information. The wrong people have access. Too many people have access. And in most cases, nobody has ever formally verified who those people are, whether they should have access at all, or whether the access they have matches any legitimate, documented, policy-compliant need.
WHO THIS SERVICE IS FOR
Criminal Justice Agencies (CJA), Noncriminal Justice Agencies (NCJA), Interface Agencies (IA), vendors, and any organization that processes, stores, or transmits Criminal Justice Information.
THE PROBLEM YOU'RE FACING
Criminal Justice Information is among the most sensitive, most regulated, and most consequential data in the country. It carries the weight of law enforcement investigations, criminal histories, biometric records, and intelligence that directly affects public safety. The FBI CJIS Security Policy exists precisely because unauthorized access to CJI is not an abstract compliance risk — it is a real-world threat with real-world consequences.
And yet in practice, CJI access sprawls. It sprawls inside agencies — to staff who were granted access years ago and never had it reviewed, to personnel whose roles changed but whose access didn't, to contractors who finished their engagement and somehow retained system credentials. It sprawls outside agencies — to vendors whose employees were never properly vetted, to subcontractors nobody knew existed, to managed service providers whose technicians access CJI-adjacent systems without a signed Security Addendum or a background check on record.
The FBI CJIS Security Policy is explicit. Every individual who accesses CJI must be properly vetted, authorized, and operating within a defined and documented scope of need. Not most individuals. Not the ones you know about. Every individual.
Sound Familiar?
No Complete Access Inventory: You cannot produce a current, complete list of every individual — internal and external — with access to CJI in your environment right now
Unreviewed Access Authorizations: Access authorizations were granted years ago and have never been formally reviewed or revalidated
Unverified Vendor Personnel Access: Vendor and contractor personnel are accessing CJI-adjacent systems without verified background screening status on record
Improper Access After Personnel Changes: Personnel have changed roles, departments, or employment status, and their CJI access was never adjusted or terminated accordingly
Unassessed Third-Party Access Exposure: Subcontractors and downstream vendor relationships exist that your agency or organization has never formally assessed for CJI access scope
Unknown CJI Access Universe: Nobody in your organization can answer the question with certainty: Who has your CJI?

If you cannot answer that question, you have a problem. Unauthorized access cannot be managed, justified, or remediated if it has never been identified in the first place. Before you can protect Criminal Justice Information, you must establish absolute certainty about who has access, why they have it, and whether that access remains authorized today. This is where it stops.
OUR METHODOLOGY
Who Has Your CJI?™ is a comprehensive, individual-level audit of every person — internal and external — with access to Criminal Justice Information in your environment. Every individual is assessed against FBI CJIS Security Policy personnel security requirements. Unauthorized access is terminated. Controls are built to prevent it from recurring.

PHASE 1:
CJI Access Universe Mapping
We build a complete, verified inventory of every individual with access to CJI in your environment — sworn personnel, civilian staff, contractors, vendors, subcontractors, managed service providers, and any other third party whose role, system access, or physical presence puts them in contact with Criminal Justice Information. Most organizations have never done this. The results are almost always surprising.

PHASE 2:
dividual-Level Personnel Security Verification
Every individual in the access universe is assessed against FBI CJIS Security Policy personnel security requirements — background screening status, security awareness training completion, need-to-know justification, access authorization documentation, and scope boundaries. Each individual is assessed independently. There are no assumptions, no blanket approvals, and no exceptions without documented justification.

PHASE 3:
Unauthorized Access Identification & Termination
Every individual whose access cannot be justified against FBI CJIS Security Policy requirements is identified and flagged for immediate access termination. This includes internal personnel whose roles no longer require CJI access, former employees or contractors whose access was never revoked, and vendor or subcontractor personnel who were never properly vetted or authorized in the first place.

PHASE 4:
Access Control Remediation
The structural gaps that allowed unauthorized access to exist are identified and closed — access provisioning processes, offboarding procedures, vendor onboarding controls, periodic access review cadences, and the documentation infrastructure required to keep CJI access authorized, current, and auditable on an ongoing basis.

PHASE 5:
Ongoing Access Governance Framework
Who Has Your CJI?™ doesn't end with the initial audit. A formal access governance framework is established — defining how CJI access is requested, approved, documented, reviewed, and terminated on a structured, recurring basis. The goal is not just to answer the question today. It is to make sure you can answer it accurately at any point in the future.

In every engagement I conduct, the answer to 'who has your CJI?' is always the same — more people than you think, many of whom have no business having it. This isn't a technology problem. It's a people problem. And it requires an expert to go through every individual, one by one, and verify whether their access is legitimate, documented, and policy-compliant.
— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

Who Has Your CJI PACKAGE
™
Our WHO HAS YOUR CJI engagment produces the most operationally consequential deliverable package in the CJIS Academy portfolio.

All documents are delivered in editable format, formatted for professional presentation, and built to be maintained by your team without ongoing outside support.
WHAT YOU RECEIVE
Complete CJI Access Universe Inventory: A verified, documented registry of every individual with CJI access across your entire environment — internal and external
Individual-Level Personnel Security Assessment Report: A finding-by-finding accounting of every individual assessed, their compliance status against FBI CJIS Security Policy personnel security requirements, and the specific gaps identified
Unauthorized Access Termination Log: A documented record of every individual whose access was identified as unauthorized and the termination actions taken
Access Control Remediation Plan: A structured remediation of every process, procedure, and system gap that allowed unauthorized access to exist
CJI Access Governance Framework: Formal policies, procedures, and tracking tools governing how CJI access is requested, approved, reviewed, and terminated on an ongoing basis
Audit-Ready Personnel Security Evidence Package: Complete documentation formatted for CSA auditor review, evidencing the current authorized access universe and the controls governing it
WHY THIS ENGAGEMENT PAYS FOR ITSELF
Unauthorized CJI Access is not a Documentation Finding — it is a Policy Violation with Consequences that Extend Well Beyond an Audit Report.

Eliminate Unauthorized Access Risk
Unauthorized CJI access is the most common and most serious compliance failure in the field. This engagement identifies, removes, and prevents unauthorized access on a permanent basis.

Satisfy Auditor Scrutiny on Personnel Security
Personnel security is one of the most heavily examined areas in a CSA audit, and a verified, documented, current access universe removes an auditor's most productive line of questioning.

Protect Against Internal and External Threats
Internal personnel with unnecessary access, along with unvetted vendors and subcontractors, represent significant and often overlooked sources of compliance and security risk.

Build a Defensible Access Record
In the event of a CJI breach, the first question asked is who had access. This engagement ensures you can answer that question completely, accurately, and immediately with supporting documentation in hand.
Frequently Asked Questions
Do you need access to CJI to conduct this audit?
No. Who Has Your CJI?™ is conducted entirely against your access control systems, personnel records, vendor documentation, and the infrastructure that stores, processes, or transmits CJI — not the data itself. In rare instances where CJI access is necessary for sensitive consultative engagements, we will execute the required CJIS Security Addendum documentation to authorize it in full compliance with FBI CJIS Security Policy requirements.
What if we discover that a large number of individuals have unauthorized access?
That is exactly what this engagement is designed to find — and it is more common than most organizations expect. Unauthorized access identified through a proactive audit is a compliance problem you control. Unauthorized access discovered by an auditor or during a breach investigation is a compliance failure you explain. The engagement is built to handle findings at any scale.
Does this cover vendors and subcontractors as well as internal staff?
Yes. The CJI access universe mapped in Phase 1 includes every individual — internal and external — whose role, system access, or physical presence puts them in contact with Criminal Justice Information. Vendors, subcontractors, managed service providers, and any downstream third-party relationships are included in scope.
How is this different from a standard gap assessment?
A gap assessment evaluates your compliance posture across all 18 FBI CJIS Security Policy control families at a program level. Who Has Your CJI?™ is an individual-level audit focused exclusively on personnel security — going person by person through your entire CJI access universe to verify that every individual with access is authorized, vetted, and operating within a documented and policy-compliant scope.
What happens after unauthorized access is terminated?
The access control remediation in Phase 4 closes the structural gaps that allowed unauthorized access to exist in the first place — so terminating today's unauthorized access doesn't simply open the door for tomorrow's. The governance framework established in Phase 5 keeps your access universe current, authorized, and auditable on an ongoing basis.
How long does this engagement take?
Most engagements are completed within four to eight weeks, depending on the size of your organization, the complexity of your vendor relationships, and the depth of your existing access control documentation. A firm timeline is established during scoping.

