08 Every comprehensive audit found violations. Every ten-item sample found none.
18 audits, Nov 2021 to Apr 2026. The three that reviewed every inquiry found 33 violations. The fourteen that sampled 10 found zero — including one quarter where both methods ran on the same data.
A follow-up records request (PR-2026-155) asked which outside agencies have received Benicia ALPR data, and whether compliance with Policy 470.9 has been audited. The city’s response answers both — and the answer is striking.
Eighty-eight signed acknowledgment letters were produced, covering 82 distinct agencies — six agencies (Colma PD, Napa PD, Pleasanton PD, Solano County DA, Marin County SO, and SFPD-NCRIC) appear twice, having signed on separate occasions. Each did so through the same one-page “Data Sharing Acknowledgment Letter,” in which a representative certifies the data “will only be used for law enforcement purposes ONLY, and not for other purposes such as immigration, personal use, harassment.” There is no MOU — consistent with the department’s own 2022 statement that “we don’t have a formal MOU agreement per se.”
Where the data flows: ~45 Bay Area agencies, 11 North Bay, 11 Sacramento/Central Valley, 10 in home Solano County, and — notably — eight Southern California agencies with no obvious tie to a city of ~28,000: Riverside County DA, Newport Beach PD, El Cajon PD, Santa Ana PD, Upland PD, West Covina PD, Murrieta PD, Irvine PD. Recipients also include the California Highway Patrol, the California Department of Corrections and Rehabilitation, an auto-theft task force (ACRATT), and NCRIC — the Northern California Regional Intelligence Center fusion center (via SFPD). By type: 63 police departments, 9 sheriffs, 8 district attorneys, plus state and regional bodies.
The audits exist — and the department’s own numbers show the sampling cannot find anything. A second production (PR-2024-93, released 2024-05-16 and collected 2026-07-26) supplies the earlier memoranda, completing an unbroken series of 18 quarterly audits from November 2021 to April 2026. Lt. Criado has run them throughout. But the method changed, and the change matters.
The first three audits were comprehensive — every inquiry in the period. Each one found violations:
| Audit | Period | Inquiries reviewed | Deficient found |
|---|---|---|---|
| 2021-11-11 | Oct–Nov 2021 | 895 (all) | 12 |
| 2022-06-22 | Q2 2022 | 4,539 (all) | 7 |
| 2022-10-06 | Q3 2022 | 6,073 (all) | 14 |
From January 2023 onward, every audit has instead drawn “a sampling of 10 randomly selected detection browsing inquiries.” Every one of those has found zero violations — fourteen consecutive clean audits through April 2026.
The department flagged the switch in advance and gave a reason: “Because this technology is new to our organization and employees, we are conducting a more comprehensive audit… As employees become more proficient… we will begin quarterly audits consisting of a sampling of 10.” It was planned, not concealed.
But the department itself has run the experiment that shows what sampling misses. In the audit dated 2025-10-02, Lt. Criado did both. He sampled 10 and found nothing:
“I found all ten (10) inquiries between 07/01/2025 and 9/30/2025 were appropriate and within policy.”
Then, “because of the recent influx of new employees,” he reviewed the whole quarter — 4,438 inquiries — and found four violations the sample had missed:
“Of the 4438 inquiries, I found four (4) inquiries where the reason for searching was unclear and insufficient… The employees entered ‘Investigation’, ‘Stolen Plate’ and ‘Dumping violation’ as the reason and did not provide the Police case number or incident number.”
Same quarter, same auditor, same data. Ten found nothing. All 4,438 found four.
That is the whole answer to what a 100% pass rate means here. At roughly 4,400 inquiries a quarter, a sample of 10 reviews about 0.2% of searches. Against the violation rates the comprehensive audits actually measured — between 0.15% and 1.3% — a ten-item sample would be expected to come back clean almost every time whether or not anything is wrong. Fourteen clean audits in a row is what that design predicts, not evidence that nothing was found because nothing was there.
The comprehensive audits also caught a systemic fault sampling would almost certainly miss: in Q3 2022, thirteen inquiries carried reasons that were “a series of symbols, number, and letters that did not make sense,” traced to an employee copy-pasting case numbers out of the RIMS system, which “does not transfer information correctly.”
Why it matters: Three gaps. First, the audits review only Benicia officers’ own searches — not what any of those outside agencies did with the data they pulled. The entire outbound side is unaudited. Second, once data reaches a fusion center (NCRIC), state corrections, or an out-of-region agency, Benicia no longer controls where it travels next — the exact concern a one-page self-certification does little to constrain. Third, the audit method itself was scaled down from every inquiry to ten, and the department’s own side-by-side test shows the smaller method does not detect the violations that are there.
Source: 88 signed acknowledgment letters + 8 quarterly audit memos (PR-2026-155); full list in
agency-roster.csv.
The documents behind this
Read them yourself — that is the point.
| Document | Request |
|---|---|
| ALPR audit memoranda 2021-2024.pdf | PR-2024-93 |
| audit-series.csv — multiple documents in this request | audit-series.csv |
| PR-2026-155/agency-roster.csv — multiple documents in this request | PR-2026-155 |
| PR-2026-155/text/ — multiple documents in this request | PR-2026-155 |
Full write-up source: BENICIA-FLOCK-FINDINGS.md in the records archive. Every
quotation is transcribed from a PDF the City produced under the California Public Records
Act. Redacted and image-only scans were run through OCR, so minor spacing artifacts may
remain; wording is unchanged.