Skip to content
Client login

Free Audit

IT infrastructure

The second audit: what moved, and the findings that never will

A first audit describes. The second compares — and comparison says things about a business that no description can.

Published on 10 June 2026 — Algeria Agency

The article accompanying this one explains how to conduct an audit, from opening the cupboard to the three action lists. It gives a section to one sentence it has no room to unfold: the audit is dated, and it expires.

This page is the second audit, twelve months later. It rests on a property the first cannot have: it no longer describes, it compares.

Comparison is what makes the exercise useful a second time. It shows what was corrected, what changed with nobody deciding it, and — most instructive of all — the findings sitting in exactly the same place as a year ago.

Those are the article’s real subject. A finding that has not moved in twelve months will not move in twenty-four for the same reasons, and there are three of them. One leads to deleting the finding rather than carrying it forward.

An audit that is not repeated did not happen

It is a slightly harsh formulation and it describes faithfully what we see at businesses that paid for a serious audit.

The document exists, it is good, it is filed. Three months later two or three easy things have been done — the ones requiring nobody’s agreement — and the rest waits. Twelve months later nobody remembers what the rest was.

That is not negligence, it is a property of lists. A list with no deadline and no scheduled re-reading is a reference document, and a reference document has never made anybody do anything.

The dated re-reading is therefore the missing half of the exercise. It turns thirty findings into thirty questions asked out loud in front of somebody who has to answer, which is an entirely different situation.

The practical consequence is decided at the first audit rather than a year later: the date of the second goes in the calendar on the day the first report is handed over. Otherwise it never goes in at all.

Twelve months, and why neither six nor twenty-four

Six months is too short for most findings in this kind of report, and the second audit becomes a demoralising repetition.

Many corrections depend on an annual budget, a contract renewal, or a quiet moment in the business. Coming back after six months amounts to observing that nothing structural could have happened, which is true and teaches nothing.

Twenty-four months is too long for a different and more damaging reason: beyond a year the estate has changed enough that the comparison stops being one. You are no longer comparing two states of the same system, you are describing two systems.

Twelve months also falls in the right place administratively: the budget cycle, licence and contract renewals, and the warranty end of hardware bought together all arrive at that cadence.

One exception worth naming: after a serious incident — an intrusion, a data loss, a contentious departure — the second audit happens within the month rather than on the planned date. What changed that day is precisely what needs looking at.

The first described, the second compares

The difference in kind between the two exercises is not cosmetic and it changes how the day is run.

A first audit starts from nothing: you open the cupboard, you count, you ask what each thing is for, and the deliverable is a statement of the position. There is nothing to compare it against, so everything is equally interesting.

A second audit starts from the previous document, line by line, and the question put to each line is binary before it is detailed: is this still true?

That speeds the exercise up considerably — a second audit takes a fraction of the first’s time — and makes it more uncomfortable, because every unchanged line is a question addressed to somebody.

The deliverable changes shape accordingly: no longer a statement of position but two columns, last year and today, with a very short third for what has appeared since.

What changed with nobody deciding it

The most instructive column in the second audit is not the corrections. It is the changes nobody decided.

The recurring ones: two or three machines added to the network, an access granted to a provider and never withdrawn, an application installed by a department for its own use, a file share created for a project that finished long ago.

None of those changes is at fault taken on its own. Each was made by a reasonable person for a valid reason, and that is exactly what makes them invisible: there is nobody to blame for anything.

Their cumulative effect, on the other hand, is the principal mechanism by which a clean infrastructure stops being one. A year of small local decisions produces a system nobody describes correctly any more, and that is the definition of what an audit exists to correct.

The question to put to each is therefore not "who did this" but "are we keeping it". Most of the time the answer is yes, with a named owner this time — and a minority are removed in ten minutes.

The findings that did not move, and the three reasons

Here is the heart of the exercise. A finding motionless for twelve months is motionless for one of three reasons, and the remedy differs completely depending which.

The first is that it has no owner. It was in the report, everybody agreed, and nobody was named — so it belonged to the organisation in general, which is to say nobody. The remedy is a name and a date, and it works almost every time.

The second is that the finding is too large for the line carrying it. "Redo the cabling" or "migrate the mail" are not tasks, they are projects, and they will stay motionless as long as they are written as tasks. The remedy is to cut it up until the first step fits in half a day.

The third is the most interesting and the worst handled: it is not an IT decision. "Stop working with this supplier", "require one password per person at the counter", "stop using the manager’s personal phone for the shop" are management decisions disguised as technical findings.

A finding of that third kind will never move while it stays in an IT report, because the person who can settle it does not read that report. The remedy is not technical: it is to take it out of the list and put it to a management meeting, in one sentence, with its cost and its risk.

The finding to delete rather than defer

A list that only ever grows stops being read, and that is the mechanism by which an audit becomes decorative.

At the second pass, some findings therefore have to be withdrawn — not because they are resolved, but because the business has decided to live with them. That is a legitimate decision and it deserves a status rather than being allowed to happen through fatigue.

The form that makes it honest is one line in the report: the finding, the reason for not addressing it, and the name of the person accepting it. "The backup server is in the same room as the main server; accepted, for want of a second room; approved by the manager."

That line is worth infinitely more than a silent deferral, for three reasons. It is true, it is dated, and it gets reopened the day the constraint changes — a move, a new room, a client requirement.

The difference between an accepted risk and a forgotten one is invisible in a system and total in a business. The second audit is where the latter get converted into the former.

What fixed itself

Every second audit finds two or three findings resolved that nobody addressed, and they deserve a minute’s attention rather than a ticked box.

The usual causes are mechanical: the machine concerned was replaced for another reason, the software updated itself, the provider changed their configuration, the person who was working around the rule left.

What that teaches is useful for what follows: those findings did not need an action plan, they needed time. Recognising them in advance avoids spending attention on what normal renewal will settle.

It is however worth checking the correction is real rather than apparent. A symptom that disappeared because the machine showing it was set aside is not a correction, and it will come back with the next one.

Record them explicitly in a "resolved without action" column rather than among the corrections carried out. Conflating the two suggests an execution capacity the business has not demonstrated, which mis-sizes the next list.

The single points of failure the year created

The companion article gives a section to the person everything depends on. This one does not repeat it: it looks only at those that did not exist twelve months ago.

They are created in two ways and never by decision. Somebody leaves and their tasks are taken over by one person instead of being shared; or somebody takes on a new tool, masters it, and in six months becomes the only person who can use it.

The sign can be read in the first audit’s record without any investigation: look for the lines where the owner’s name has changed since last year, and see whether the same name now appears on several critical lines.

The remedy is not hiring, which is beyond most of the businesses concerned. It is writing: a one-page procedure, produced by the person themselves, and verified by somebody else executing it once.

It is the same act as the one described in the article on restore testing, and for the same reason: a competence never exercised by a second person is a competence nobody knows to be transferable.

Comparing the inventories: the line that vanished

The two inventories compare mechanically, and three discrepancies are to be sought rather than waited for.

Added lines are the easiest and least worrying: attach them to a decision, give them an owner, and they join the register.

Vanished lines are more interesting. A machine listed last year and no longer there has either left the fleet cleanly — in which case there is a trace — or it is somewhere without anybody knowing, which is the commoner and more awkward case.

Identical lines whose content has changed are the easiest to miss: same machine, same owner, but it now carries a production application where it used to be an ordinary desk. Nothing indicates that in a line-by-line comparison, which is the reason to ask "what is this machine for" again rather than to tick.

This work goes far better if the first inventory followed the discipline described in the article on the hardware register — one line per object, a serial number as identity. Without a stable identity, comparing two inventories is an exercise in interpretation.

The second audit report fits in two columns

It does not resemble the first and it should be shorter, not longer. That is the sign the exercise worked.

Two main columns, last year and today, and only four statuses: corrected, not addressed, accepted with a name, appeared since. Nothing else serves the conversation that follows.

Every "not addressed" line must carry which of the three reasons from section five, because that information rather than the finding itself decides what happens next.

The report ends with a page of three lists as in the first audit — the companion article describes their form — but it is built knowing the business’s real capacity, measured by the proportion of findings addressed over the year.

That proportion is the exercise’s only metric and it compares to no external norm. It compares to your own previous year, which is what makes it usable: a business that addressed six findings out of thirty will not be handed a list of thirty the next day.

When the second audit says to space them out

An annual audit is not a perpetual obligation, and knowing when to space them is part of the exercise’s honesty.

Three conditions together justify moving to eighteen or twenty-four months. The inventory barely moves year on year. The unaddressed findings are all accepted risks with a name. And a continuously kept register exists that makes part of the audit redundant.

The third is decisive and it is the real objective. An audit exists to make up for the absence of ongoing record-keeping; a business that keeps its fleet, its accounts and its change log no longer needs its system described to it every year.

Conversely, three signals require staying at twelve months: a change of provider, rapid growth in headcount, or a year in which more than half the findings stayed motionless.

The last signal is the most important and the least pleasant to say, because the conclusion is not "audit more". A business that addresses nothing does not need a third report; it needs to name one person and cut the list to three lines.

What we do, and what we refuse

What we do is short, because a second audit is short. We take the previous report line by line, we set the four statuses, we qualify every motionless line by its reason, and we come out with a list sized to what the past year shows of your real capacity.

We refuse to conduct the second audit if we carried out the corrections between the two. It is the same conflict as with restore testing: we would record as addressed what we did ourselves, and the one figure that matters — the proportion of findings actually corrected — would be produced by the party with an interest in it being good.

We also refuse to re-issue a finding a third time unless it has received either an owner or a signed acceptance. A finding appearing in three successive reports with no name is no longer a recommendation, it is decoration, and the whole list loses its credibility because of it.

And there is one thing to do today without us: take out your last audit report and count how many of its findings are addressed. If you cannot find the report, the answer is known — and the first act is not to order a new one, it is to put a re-reading date in the calendar.

Frequently asked questions

How long before repeating an audit?

Twelve months. Six is too short — most corrections depend on an annual budget or a contract renewal, and coming back earlier merely observes that nothing structural could have happened. Twenty-four is too long: the estate has changed enough that the comparison is no longer one. Exception: after an intrusion, a data loss or a contentious departure, within the month.

How does the second audit differ from the first?

The first describes, the second compares. You start from the previous document line by line, and the question on each is binary: is this still true? It is much faster and much more uncomfortable, because every unchanged line is a question addressed to somebody. The deliverable is no longer a statement of position but two columns and four statuses.

Why do some findings never move?

Three reasons, with entirely different remedies. No owner — the remedy is a name and a date. Too large for the line carrying it: "redo the cabling" is a project written as a task, so cut it up until the first step fits in half a day. Or it is not an IT decision at all, in which case it must leave the report and be put to a management meeting.

Should findings be deleted from an audit list?

Yes, when the business has decided to live with them. A list that only grows stops being read. The honest form is one line: the finding, the reason for not addressing it, and the name of whoever accepts it. The difference between an accepted risk and a forgotten one is invisible in a system and total in a business.

What about findings resolved with nobody intervening?

Record them in a "resolved without action" column rather than among corrections carried out. The machine was replaced for another reason, the software updated itself, the person working around the rule left. Conflating them with completed work suggests an execution capacity that was never demonstrated, and the next list will be mis-sized.

Can audits be spaced out?

When three conditions hold together: the inventory barely moves, the unaddressed findings are all accepted risks with a name, and a continuously kept register exists. The third is the real objective — an audit makes up for absent record-keeping. Conversely, stay at twelve months after a change of provider, or a year where more than half the findings did not move.

Where we come in

A report you cannot find has already answered the question, and the answer is unpleasant. A report you can find gets counted: how many findings were actually dealt with.

  • We reread the old document without rewriting a line of it, and tick.
  • We attach a name or a date to anything appearing a second time.
  • We book the next one at twelve months, in your diary rather than ours.

Us checking our own corrections would be worth nothing: ask somebody else for this second pass, and we will tell you what to ask them for.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy