Skip to content
Client login

Free Audit

IT consulting & support

IT audit: start by opening the cupboard

An audit is done standing up, on the premises, opening doors. What is found there decides everything else, and it is written down nowhere.

Published on 10 June 2026 — Algeria Agency

The article on the IT pillar asks the deciding question — what stops the business for a day — and observes that nobody has an inventory. This page covers making that inventory, and it starts with an unwelcome obvious point.

An IT audit is not done from a desk. It is done on the premises, opening the technical cupboard, following a cable to its socket, asking the person on the till what they do when the printer stops responding.

What that turns up is written in no document and regularly contradicts what management believes. A server thought to be backed up that has not been for a year. An unplugged power protector. A former employee still an administrator.

This article sets out what the audit has to produce — three lists, not a report — the access inventory nobody has, and the commercial refusal that defines the rest: our first deliverable is what not to buy.

The audit starts by opening the cupboard

The first hour of an audit is spent standing. The technical room or the cupboard standing in for one gets opened, the whole thing gets photographed before anything is touched, and the cables get followed.

What is being looked for is physical: how many devices are actually plugged in, which are running, which are hot, which carry a label and which do not. Equipment with no label is equipment nobody knows the purpose of, and there is always some.

Then you look at what is not supposed to be there: daisy-chained extension leads, a fan put there to compensate for heat, a cable leaving through a window, a machine on the floor. Each of those is a decision taken in a hurry long ago and never revisited.

The second hour is spent sitting, beside the people. Three of them are asked what blocks them most often and how long it lasts. The answers almost never match what the director would have cited, and they are what points at the real failures.

That physical part cannot be replaced by a questionnaire. A remote audit describes what the client believes they have; an on-site one describes what they have, and the gap between the two is the report’s useful content.

The five questions it has to answer

An audit succeeds if it lets five questions be answered in writing. Anything serving none of the five is padding, and forty-page reports consist mostly of it.

First question, the pillar’s: what stops the business for a day? Not what irritates — what stops. The answer is often a single machine, a single line, or a single person.

Second: where is the data, and who holds a second copy? The article on backup handles the subject in detail; the audit confines itself to locating it, dating the last tested restore, and saying who else has access.

Third: who holds the access? That is section 3, and it is the most valuable list in the whole pillar. Fourth: what is no longer covered — expired warranty, a system no longer receiving fixes, a maintenance contract that ended without anybody noticing.

Fifth: what exists in only one copy? One router, one server, one disk, one person who knows how. The pillar calls those single points of failure, and the inventory exists above all to count them.

The inventory is one line per item

The format that survives is a table, not a report. One line per piece of equipment, six columns, and nothing else. A thirty-page document is never updated; a forty-line table sometimes is.

The six columns: what it is, where it is, who uses it, what it is for, since when, and what happens if it dies today. The sixth turns an inventory into a decision tool, and it is the one downloaded templates do not have.

The "since when" column is not for calculating depreciation. It is for spotting equipment whose age exceeds the period in which parts can still be found, which is not the same as warranty and which decides the replacement strategy.

The inventory includes what nobody counts: the phones used for work, the accountant’s printer, the external drive in a drawer, the machine under the desk running an old package nobody remembers the name of.

And it includes subscriptions. The internet line, the hosting, the domain names, the annual licences, the monitoring. Those are equipment in this page’s sense: they stop, they renew, and they belong to somebody — which is the next section.

The access inventory, which is always missing

It is the most valuable list an audit produces and the one that never exists. For each system, two columns: who can get in, and who can remove everybody else.

The second column is the one that counts. On nearly every system there is a level above the others — owner, principal administrator, account holder — and whoever occupies it can exclude everybody, including the director. The articles on advertising accounts and on the business listing describe the same mechanism elsewhere.

The list has to cover the technical and the non-technical: the router, the server, the workstations, the mail, the hosting, the domain name, the accounting, the till, the cameras, and the account with the access provider.

What we find in most audits: a former employee still active, a previous supplier still an administrator, a password shared by four people, and at least one system whose password nobody in the company knows.

That last case is the most serious and it is surprisingly frequent. Equipment in service whose access has been lost can no longer be configured or updated, and gets replaced the day it fails — that is, at the worst moment and with no preparation.

The dependency map is drawn by hand

The most useful part of an audit fits on one sheet and is drawn in pen during the visit: what depends on what. It is not a network diagram; it is a map of consequences.

You start from each activity that earns money — taking payment, invoicing, preparing an order, answering the phone — and work back: what does it need in order to work this morning? The internet line, a workstation, a package, a server, a printer, a person.

The points where several arrows converge are the single points of failure, and they jump out the moment the drawing exists. In small organisations there are typically two or three, and they are not the ones anybody would have guessed.

The commonest result is mundane and worth all the rest: almost everything depends on the internet connection, including things believed to be local — the till that synchronises, the package that checks its licence, the internal messaging. The pillar article says it in a sentence; the drawing makes it undeniable.

Keep that drawing. It is dated, it fits on a page, it is redrawn in twenty minutes when something changes, and it is the document that gets pulled out on the day of a failure to decide where to start.

The person who is a single point of failure

It is the conclusion audits avoid writing and it is often the answer to the pillar’s question: what stops the business for a day is not a machine, it is somebody being away.

The standard case is unexotic: one person knows how to restart the server, knows the till password, knows where the invoices are, or is the only one the access provider will accept on the phone. When they are on leave, the business runs at half.

That is neither a reproach to the person nor a competence problem: it is a normal consequence of a small organisation that grew without writing its procedures down. The audit simply names it, which is already unusual.

The correction is written rather than human, and it is cheap. Three pages: how to restart, where the access details are, who to call at each supplier with the contract number. A second person reads them once, and that removes half the risk.

There is a counterpart to state to the director: formalising that knowledge makes the person less indispensable, and they know it. It is presented as protection for them — being able to take leave without being called — because that is also what it is.

Licences, and what actually gets found

An honest audit records the state of licensing, and what it finds in most small businesses has to be said: a mixture of purchased software, trial versions never regularised, and copies installed by a previous supplier.

We pass no moral judgement on this page, and nor do we pretend it is without consequence. The consequences are practical before they are legal: unregularised software receives no fixes, cannot be supported by the publisher, and breaks at the first system update.

The legal consequence exists nonetheless and it lands on the business, not on the supplier who installed it. It becomes real at an inspection, in a dispute with a former employee, or when bidding for work that requires documentation.

What the audit produces is a costed list: how many machines, which packages, what regularisation would cost, and what free alternatives exist for simple uses. That last column often halves the total and it is never in reports supplied by resellers.

The rule we apply: regularise first whatever touches accounting and customer data, because that is where legal and technical risk meet. The rest is planned across the year.

The free audit that ends in a quotation

This market’s dominant product has to be named: the audit offered by a reseller, which arrives at a shopping list. It is not dishonest in the strict sense — it is simply funded by what it recommends.

The mechanism shows in three signs. The report contains product references rather than needs. It contains no "do nothing" line. And it has no order of priority, because an order of priority defers part of the purchasing.

Our position is simple and it costs us: an audit’s first deliverable has to be what not to buy. In most cases we have seen, between a third and half of what was being considered was not necessary this year.

That does not mean a reseller is lying. It means an audit and a sale should not be billed by the same hand, and that if you only have one supplier, you should at least ask them for the list of what they advise against.

A useful test for any report you receive: look for the sentence saying what you can defer. If it is not there, the document is a commercial proposal with an audit cover.

It is dated, and it expires

An audit describes a state at a moment. Three months later two machines have changed, a package has been installed, somebody has left, and part of the document is wrong without anybody having noticed.

That is why every deliverable we hand over carries a date at the top and an explicit validity. An undated report gets reused for years and ends up supporting a decision it no longer justifies.

It is also why this page contains no chart. We could have opened with some share of businesses with no inventory, as half the documents in this market do; that figure comes from publishers’ surveys, in other countries, and it would serve to replace the work rather than direct it.

The only inventory that decides anything is yours, and it does not exist yet. So the useful figure is produced by the audit — how many items with no identified owner, how many uncontrolled accesses, how many single points of failure — and it is dated by construction.

The practical consequence is a routine rather than an engagement: an hour’s review every six months, done by somebody inside the company, updating the table and redrawing the map. That is what separates an inventory from a report.

Three lists: today, this quarter, this year

An audit’s output is not a report but three lists, and separating them is what makes the whole thing usable by a director with no budget available this month.

The first list is free and happens today: remove access for people who have left, change three shared passwords, enable two-step verification on the critical accounts, unplug what serves nothing, label the technical cupboard.

The second costs little and happens this quarter: a second copy of the data, a power protector for the machine that matters, replacing a dangling cable, a maintenance contract where there is none, regularising the accounting licences.

The third is capital and gets planned across the year: replacing a server, recabling, changing connection, installing video surveillance. Those are decisions that get prepared, and the audit’s only merit is that they get taken before the incident rather than after.

The proportion we observe is stable: the first list removes a significant share of the real risk, and it costs nothing. That is this page’s central argument and it does not help sell hardware.

What an audit cannot see

The limits have to be stated, because an audit handed over without them reads as a guarantee and is not one.

It does not see what does not happen on the day of the visit. An intermittent outage, saturation at peak hours, a disk beginning to fail: those are intermittent phenomena only revealed by measurement over several days, and a one-day audit does not do it.

It does not see inside the access provider’s network, nor the real quality of the link. The article on the IT pillar notes that you depend on a connection you do not control, and the audit can only observe and document, not correct.

It does not tell you whether you have been compromised. A state audit is not an intrusion search: they are two trades, two durations and two prices, and confusing them gives false assurance. The page on IT security handles the second.

And it does not replace testing. The only proof a backup works is a restore performed, as the article on the subject says; the only proof a power protector holds is a simulated outage. An audit records existence, it does not prove function.

What we do, and what we will refuse to do

What we will refuse: handing over an audit that contains no list of what not to buy. It is our position in this market and it costs us part of what the competition bills afterwards.

We will refuse to run an audit remotely only. What decides is on the premises, behind a door nobody has opened in two years, and no questionnaire replaces it.

We will refuse to present a state audit as a security check. They are two different services, and selling the first while implying the second produces exactly the false assurance this page exists to avoid.

What we do: the physical visit and photographs before touching anything; the table with one line per item, including the column "what happens if it dies today"; the access inventory with the column "who can remove the others"; the dependency map drawn by hand; the three separated lists; and a validity date on every page.

And what you can do this week without us: open your technical cupboard, photograph it, and try to name every device. Then write down, for each, who holds the password. The two missing answers you find are, in our experience, most of what an audit would have taught you.

Frequently asked questions

What should an IT audit produce?

Three lists rather than a report: what gets done today and costs nothing, what gets done this quarter and costs little, what gets planned across the year. Plus a table with one line per item and an access inventory.

Can an audit be done remotely?

Only partly. What decides is on the premises — an unplugged power protector, daisy-chained extension leads, unlabelled equipment — and a remote audit describes what the client believes they have rather than what they have.

Why does the access inventory matter so much?

Because on nearly every system there is a level that can remove all the others, including the director. We regularly find a former employee still active, a supplier still an administrator, and equipment whose password nobody knows.

Are free audits reliable?

They are funded by what they recommend. Three signs give it away: product references rather than needs, no "do nothing" line, and no order of priority. Look for the sentence saying what you can defer.

How often should an audit be redone?

An hour’s review every six months, done internally, is enough to maintain the table and the map. A full audit is redone when something structural changes: a move, a change of business software, a doubling of headcount.

Will an audit tell us whether we have been hacked?

No. A state audit records what exists; an intrusion search is another trade, with another duration and another price. Confusing them gives false assurance, and the IT security page handles the second subject.

Where we come in

The devices you could not name are already the finding. The rest of the exercise is working out which of them can stop you.

  • We come on site and photograph before touching anything.
  • We date the end of life of every object, including the ones still working.
  • We attach what is better left unbought, which fills half the report.

An audit done on documents alone is not worth what it costs: we do not offer one, and you should not buy one from anybody.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy