Research · 4 min read
How Fast a Theft Shows Up in the Data Depends on How It Was Discovered
Recent occurrence-date totals are structurally incomplete, offense-specific, and lack any published revision history.
Crime data looks like a census. It is a process, and it runs late. In three years of Seattle property records the median offense took 32.7 hours to surface — but a stolen car appeared in under a day, shoplifting in under four hours, and theft-from-building took nearly three days. The speed of a record is not about seriousness. It is about how the offense was discovered.
Our analysis of 116,754 valid intervals, reports published July 1, 2023–June 30, 2026.
Key takeaways
- The median offense-to-report lag is 32.7 hours, but it ranges from 3.15 hours for arson and 3.82 for shoplifting to 65.8 for all-other-larceny and 71.3 for theft-from-building.
- A Cox model confirms offense type predicts speed (motor-vehicle theft hazard 1.91, shoplifting 1.64) with a modest concordance of 0.567.
- The pattern tracks how an offense came to light — witnessed in the act versus found later — not how serious it is.
- The source keeps no row-level revision history, so the only record of how a number changed is the snapshot log we keep ourselves.
Why does offense-to-report lag differ so much by crime type?
Among 116,754 valid Seattle intervals, the median offense-to-report lag was 32.7 hours — but shoplifting surfaced in 3.82 and arson in 3.15, while all-other-larceny took 65.8 and theft-from-building 71.3. A Cox model confirms offense type predicts speed (motor-vehicle theft hazard 1.91, concordance 0.567). Lag tracks how an offense was discovered: witnessed, or found later.
The numbers behind the answer
Selected measures only. Denominators and interpretation stay attached so the headline cannot stand alone.
32.7 h
Median offense-to-report lag
Across 116,754 valid nonnegative intervals in 2023–2026.
44.2%
Published within 24 hours
Slightly fewer than half of records appeared within a day.
16.7 h vs 65.8 h
Fastest vs slowest offense
Motor-vehicle theft versus all other larceny median lag.
A median of a day and a half, with a long tail
Half of property-offense records surface within 32.7 hours of the recorded start; 44.2% within a day. But 16.3% take more than a week, the 90th percentile reaches 286 hours, and the 95th reaches 590. A weekly dashboard that treats recent days as final is reading an unfinished page.
The extract starts as 116,846 rows and yields 116,754 valid nonnegative intervals; 92 were negative and are reported as a quality check, and 10,168 offense starts are exact midnight. The gaps between offense types are far larger than those data-quality margins. Motor-vehicle theft has a median lag of 16.7 hours, while all-other-larceny runs to 65.8 — different events are discovered and reported on very different clocks.
Evidence visual
Median offense-to-report lag by offense type
Hours from recorded offense start to publication, 2023–2026.
Fast records are witnessed; slow records are discovered
Line the offense types up by speed and a mechanism appears. The fastest are the ones usually seen as they happen: arson at 3.15 hours and shoplifting at 3.82 are almost always witnessed or caught in the act, and a stolen car (16.7 hours) is typically reported the moment the owner finds the empty space. The slowest are found after the fact: theft-from-building (71.3 hours) and all-other-larceny (65.8) include losses noticed later, sometimes days later, by whoever reconciles inventory or opening checks.
This is why one “reporting lag” number misleads for planning. Lag is not a property of police work or of the data system; it is a property of the event and how it came to light. A parts theft (34.7 hours) is discovered when someone next uses the car; a burglary (32.4) is discovered at opening; shoplifting is often not discovered at all — it is observed. The clock starts at the recorded offense start, and for discovered-later crimes that start is frequently estimated backward.
The clock is offense-specific
Treating the interval as a survival process sharpens the same point. Relative to the baseline category, motor-vehicle theft shows a hazard ratio of 1.91 (95% interval 1.86–1.96) and shoplifting 1.64 (1.59–1.70) — they surface sooner, holding the others constant. Burglary and theft-from-vehicle sit near 1.30, and parts theft at 1.25. Offense type predicts speed even after the model accounts for everything else.
The concordance of 0.567 is the honest part. A model that ranked every interval perfectly would score 1.0; a coin flip scores 0.5. This one barely beats the coin flip, which means the wait is genuinely noisy and offense type is a real but partial explanation. That is the finding, not a flaw to hide.
Use it as
A freshness policy: label recent periods provisional and never compare them with settled history.
The source keeps no revision history, so we keep one
SPD’s crime dataset exposes no row-level revision history — the revisions endpoint returns 404. That means the only way to know how a published number changed is to snapshot the dataset yourself and diff it. We maintain that log in this program; it is the kind of record an open dataset does not publish about itself.
One caution throughout: this interval is not emergency-call, dispatch, arrival, or police response time. It is the gap between when an offense was recorded as starting and when its report was published.
- Show a data-as-of label on every map.
- Mark recent periods provisional.
- Never compare immature current periods to settled history.
- Keep offense-specific expectations, not one buffer.
- Snapshot the source if you need revision history.
The lag behaves like a survival curve, and the two date fields agree
Modeling the interval as a survival process ranks the speed by offense. Among 60,000 sampled intervals (concordance 0.5674), motor-vehicle theft surfaces fastest at a hazard ratio of 1.9071 (interval 1.8553–1.9604), shoplifting next at 1.6444 (1.5907–1.6999), then burglary 1.2962 and theft-from-vehicle 1.2963. The by-offense medians line up: 16.73 hours for motor-vehicle theft against 3.82 for shoplifting and 65.77 for all-other-larceny.
The interval is real, not a field artifact. Just 92 lags are negative, and the two date fields reconcile to a median difference of −0.02 hours — about a minute. What remains is the 10,168 exact-midnight offense times, the extreme of a known problem: aoristic analysis exists because offense times are often windows, not instants, and spreading an event across its possible span beats inventing a precise stamp.
The provenance problem is broader than offense times. Research on open police datasets documents how records are revised and re-geocoded after first publication, and a national victimization survey exists because much offending never enters police data at all. Label data age, expect offense-specific lag, and keep your own snapshot when the source publishes no history.
Method note
Estimated start times belong in the model, not hidden inside a precise-looking timestamp.
Questions property teams ask
Does a 32.7-hour median mean police took that long to respond?
No. It measures how long after the recorded offense start the report was published, not any response time.
Why do some offenses appear so much faster?
Discovery mechanism. Witnessed offenses like shoplifting and arson appear within hours, while losses found later — all-other-larceny and theft-from-building — take two to three days.
What does the Cox concordance of 0.567 mean?
It means the model ranks intervals only slightly better than chance. Offense type genuinely predicts speed, but the wait is noisy and many other factors are unmodeled.
Is a seven-day buffer enough?
It depends on the offense and the decision. 16.3% of records exceed seven days, and the discovered-later categories exceed it more often.
Why are some offense times exactly midnight?
They likely encode missing precision rather than a real midnight event; they are counted and handled as a sensitivity.
Why build a revision log?
The public dataset publishes no row-level revision history, so change over time is only visible if you snapshot it yourself.
How should unspecific offense times be handled?
Aoristic analysis spreads each event across its possible interval rather than assigning a single false-precise time. Exact-midnight timestamps are the extreme case of the same problem.
Our methods, limits, and sources
How we calculated this
This is original 911 Sentinel research — we gathered the records, ran every calculation below, and published the aggregate dataset.
We computed the interval between SPD offense_date and report_date_time for accepted property-offense records and modeled it with Kaplan–Meier, by-offense medians, and Cox proportional hazards.
- We pulled 116,846 property-offense records (2023–2026) and deduplicated by offense id.
- We flagged sentinel dates, negative intervals, and exact-midnight timestamps, retaining 116,754 valid intervals.
- We computed the lag distribution and the by-offense medians.
- We fit a Cox model with offense type on a 60,000-record sample and recorded a dataset revision-log baseline.
- We reconciled the summary measures against the earlier lag release to confirm they agree.
What this analysis cannot establish
- offense_date is an offense start and can be a broad or estimated window.
- Exact-midnight timestamps may be imprecise.
- Only finalized reports appear; recent weeks undercount.
- This is not emergency, dispatch, arrival, or police response time.
- Cox concordance is modest, so offense type explains only part of the variation in lag.
- Socrata exposes no row revision history, so our log is a snapshot diff, not an official record.
Sources
The raw records come from the sources below; the study design, analysis, charts, and conclusions are our own.
- Seattle Police Department — SPD Crime Data: 2008-Present
- Published aggregate result (JSON)
- Source manifest (JSON)
- Jerry H. Ratcliffe (International Journal of Geographical Information Science) — Aoristic analysis: the spatial interpretation of unspecific temporal events
- Matthew P. J. Ashby (Research Data Journal for the Humanities and Social Sciences) — Studying Crime and Place with the Crime Open Database
- Bureau of Justice Statistics — National Crime Victimization Survey (NCVS)
Related questions and practical guides
No obligation · free property walk
Treat freshness as part of the decision
A property review should use data with a visible as-of date and a provisional window for recent periods, not last week treated as final.