Guides & Checklists
What is an IT audit? What it checks, what it usually finds and how often to do one
What a business IT audit covers, the risks it typically finds (untested backups, leavers with access, ageing kit) and how often UK SMEs should audit their IT.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
An IT audit is a structured review of a business's hardware, software, network, security controls, backups, user accounts, cloud services and IT spend, producing a written list of risks and recommendations ranked by urgency. Most organisations of up to 250 people benefit from a full audit once a year, plus a lighter review after major changes.
Most businesses only look hard at their IT after something breaks: a server fails, a backup turns out to be empty, or an ex-employee is found to still have access to email. An IT audit is the way to find those problems while they are still cheap to fix. This guide explains what a good audit covers, what it typically uncovers in businesses of up to 250 people, and how often to repeat it.
What an IT audit actually covers
An audit is not a sales visit or a quick look at the server cupboard. It is a systematic inventory and assessment across every layer of the environment. A useful audit for a UK SME checks:
- Devices: every laptop, desktop, server and mobile device, with age, warranty status, operating system version and whether it is still receiving security updates.
- Network: firewall model and firmware, switches, Wi-Fi access points, cabling condition, internet connections and any site-to-site links.
- Security controls: patch status across all devices, endpoint detection and response (EDR) coverage, multi-factor authentication (MFA) on every account, email filtering, admin rights and password practice.
- Backup and recovery: what is backed up, where it goes, how often it succeeds, when a restore was last tested and how long a full recovery would take.
- Identity and access: active accounts versus current staff, shared logins, leavers who still have access, and whether permissions match roles.
- Microsoft 365 and cloud: tenant security settings, licensing versus actual usage, SharePoint and OneDrive structure, retention and sharing settings.
- Spend: subscriptions, support contracts and licences the business pays for but no longer uses.
- Documentation: whether anyone could rebuild or take over the environment from what is written down.
The output should be a plain-English report with each finding rated by risk and effort, so the business can decide what to do first.
What audits usually find
The pattern across small and mid-sized businesses is consistent. The most common findings, roughly in order of how often they appear, are:
- Backups that have not been tested. Backup jobs run, but nobody has restored a file or a server in years. Sometimes jobs have been silently failing for months, or key folders were never included.
- Leavers with live accounts. Former staff still able to sign in to email or a file share because offboarding is informal. This is the single most common access-control failure.
- Missing MFA. MFA enabled for some users but not all, or not on admin accounts, or not on the firewall or remote access.
- Out-of-support equipment. Firewalls and switches no longer receiving firmware, servers past their warranty, and PCs that cannot run Windows 11 now that Windows 10 is unsupported.
- Excess admin rights. Everyday users running as local administrators, or several people sharing one global admin account in Microsoft 365.
- Unmanaged Wi-Fi and guest networks. Guest devices on the same network as servers and printers, or a consumer router doing the job of a business firewall.
- Shadow IT. Personal cloud storage, unapproved apps connected to Microsoft 365 and department spreadsheets doing the job of a proper system. See what shadow IT is and how to find it.
- Paying for things nobody uses. Duplicate licences, lapsed staff still assigned Microsoft 365 seats, and maintenance contracts on kit that was retired.
None of these show up in daily work. Email sends and files open, so the business assumes all is well until an incident proves otherwise.
An audit is not a penetration test
The two are often confused. A penetration test is an offensive exercise where a tester actively tries to break into your systems, usually against a defined scope. It is valuable when a client contract or a standard such as Cyber Essentials Plus demands it, but it says nothing about whether your backups work or whether you are paying for 20 licences you do not use.
An IT audit is broader and comes first. It establishes the baseline: what you have, what state it is in and where the risk sits. If you are aiming for the Cyber Essentials certification, an audit will show you the gaps against the five controls before you self-assess. The NCSC publishes the scheme requirements at ncsc.gov.uk/cyberessentials.
How a professional audit runs
A typical engagement for a single-office business follows four steps.
Discovery. A lightweight agent or network scan inventories devices, operating systems, patch status and installed software. Firewall and Microsoft 365 configurations are exported and reviewed. This is where most of the hard data comes from.
Conversations. Short sessions with the owner or ops lead and with a couple of staff. The questions are practical: what slows you down, what do you work around, who do you call when something breaks, what would you do if the office was inaccessible tomorrow.
Verification. Where it matters, findings are tested rather than assumed. A test restore from backup, a check that the guest Wi-Fi really is isolated, a login attempt with a leaver's credentials.
Report and priorities. Findings are written up with a risk rating and an indication of effort and cost. The best reports fit on a few pages and end with a 30-day, 90-day and 12-month list, not a shopping list of everything the auditor could sell you.
How often to audit, and what should trigger one
For most organisations a full audit once a year is the right cadence, ideally aligned with budget planning so that findings can be funded rather than filed. Between audits, a quarterly check-in on support ticket trends, patch compliance and backup success catches drift early.
Certain events should trigger a review regardless of the calendar:
| Trigger | Why it matters |
|---|---|
| Office move or second site | Connectivity, cabling, Wi-Fi and physical security all change. See the [office move IT checklist](/insights/office-move-it-checklist/). |
| Headcount jump or merger | More accounts, more devices, more permissions, and two sets of systems to reconcile. |
| Move to hybrid working | Identity, device management and remote access become the security perimeter. |
| Security incident or near miss | Even a caught phishing email usually exposes a gap in training, filtering or MFA. |
| Regulatory or contract change | A new client questionnaire or an insurer's requirements often demand evidence you do not yet have. |
| Major vendor deadline | Windows 10 end of support and the PSTN switch-off in January 2027 are current examples. |
Regulated sectors such as law firms and accountancy practices tend to need the annual audit to be more formal, because insurers, regulators and clients ask for evidence.
Audit findings should lead to refinement, not upheaval
One caution. An audit is not a mandate to replace everything. Stability has value: staff need time to settle into systems, and hardware needs time to earn back its cost. A good audit separates what is genuinely risky (an unsupported firewall, an untested backup) from what is merely imperfect. Often the highest-value actions are configuration changes and policy fixes that cost very little: enforcing MFA, removing stale accounts, segmenting guest Wi-Fi, scheduling a monthly test restore.
Treat the report as the start of a plan. Fix the urgent items, budget the rest across the year, and repeat the audit twelve months later to measure progress. That rhythm is what turns IT from a series of surprises into something you can manage. IT consultancy and vCIO services exist to run exactly that cycle for businesses without an internal IT lead.
What to do next
If you cannot confidently say when your backups were last restored, who has admin rights, or which of your devices are out of support, an audit will answer those questions in a couple of weeks. Dig IT runs an IT health check for organisations across Hertfordshire, west Essex and London that covers the areas above and ends with a prioritised, plain-English report.

