Regulation of private companies and enforcement of same aren't really the way things work in America. And even the most highly regulated companies struggle with reality practicalities of tamper evident audit trails, for example designating a subset of systems in-scope of SOX or PCI controls where such trails are required.
You could require third party audits on an annual basis and discrepancies and violations addressed and or investigated. Failures need consequences like increased insurance rates, dismissals, etc. if it continues then the Feds get to take over the department/precinct, whatever.