Skip to main content
Published on

Checklist: auditing a smaller company's IT estate in 10 points

A practical 10-point checklist for auditing the IT estate of a smaller company and quickly identifying where to improve.

Before transforming anything, you need to know your starting point. Auditing an IT estate does not take six months of consulting: with this 10-point checklist, the owner of a smaller company can already reach a reliable assessment.

The 10 points to check

1. Hardware inventory

List every piece of equipment: workstations, servers, peripherals, network equipment. Record the age, the condition and the warranty end date of each item.

2. Software mapping

Catalogue every application in use, its version and its vendor. Identify any software that is obsolete or no longer maintained.

3. Vendor and supplier contracts

Gather every contract in force: hosting, maintenance, support, licences. Check the expiry dates, the automatic renewal clauses and the exit terms.

4. Backup policy

Check that backups exist, that they are automated, held off-site and tested regularly. A backup that has never been tested is a backup that does not exist.

5. Security and access

Review how passwords are managed, whether MFA (multi-factor authentication) is in place, and whether access rights are reviewed regularly. Who has access to what, and why?

6. Existing documentation

Is there an up-to-date network diagram? Written procedures for critical operations? In most smaller companies the answer is no – and that is a major risk.

7. Total cost of the IT estate

Consolidate every category of IT spending: hardware, licences, suppliers, telecoms, cloud. Express that cost as a share of revenue to get a comparable ratio.

8. User satisfaction

Ask the teams: which tools cause problems day to day? Where do they lose time? This point often reveals quick wins.

9. Regulatory compliance

Check GDPR compliance (record of processing activities, a designated DPO, privacy notices). Review any sector-specific obligations that apply.

10. Continuity and recovery planning

Does the company have a business continuity plan or a disaster recovery plan? If the main server goes down tomorrow morning, what actually happens?

In short

This audit is no substitute for an in-depth analysis, but it does expose the most critical weaknesses in a few hours. The expected deliverable: a summary table giving, for each point, a status (compliant / at risk / critical) and a prioritised corrective action.

To go further than a technical checklist — processes, operational friction, a 90-day plan — see the digital maturity assessment.

Go further