Checklist: auditing a smaller company's IT estate in 10 points
A practical 10-point checklist for auditing the IT estate of a smaller company and quickly identifying where to improve.
Before transforming anything, you need to know your starting point. Auditing an IT estate does not take six months of consulting: with this 10-point checklist, the owner of a smaller company can already reach a reliable assessment.
The 10 points to check
1. Hardware inventory
List every piece of equipment: workstations, servers, peripherals, network equipment. Record the age, the condition and the warranty end date of each item.
2. Software mapping
Catalogue every application in use, its version and its vendor. Identify any software that is obsolete or no longer maintained.
3. Vendor and supplier contracts
Gather every contract in force: hosting, maintenance, support, licences. Check the expiry dates, the automatic renewal clauses and the exit terms.
4. Backup policy
Check that backups exist, that they are automated, held off-site and tested regularly. A backup that has never been tested is a backup that does not exist.
5. Security and access
Review how passwords are managed, whether MFA (multi-factor authentication) is in place, and whether access rights are reviewed regularly. Who has access to what, and why?
6. Existing documentation
Is there an up-to-date network diagram? Written procedures for critical operations? In most smaller companies the answer is no – and that is a major risk.
7. Total cost of the IT estate
Consolidate every category of IT spending: hardware, licences, suppliers, telecoms, cloud. Express that cost as a share of revenue to get a comparable ratio.
8. User satisfaction
Ask the teams: which tools cause problems day to day? Where do they lose time? This point often reveals quick wins.
9. Regulatory compliance
Check GDPR compliance (record of processing activities, a designated DPO, privacy notices). Review any sector-specific obligations that apply.
10. Continuity and recovery planning
Does the company have a business continuity plan or a disaster recovery plan? If the main server goes down tomorrow morning, what actually happens?
In short
This audit is no substitute for an in-depth analysis, but it does expose the most critical weaknesses in a few hours. The expected deliverable: a summary table giving, for each point, a status (compliant / at risk / critical) and a prioritised corrective action.
To go further than a technical checklist — processes, operational friction, a 90-day plan — see the digital maturity assessment.
Go further
Browsing the notes 31 published