IT Audit Checklist: What Every UK Business Should Check

Table of Contents

Quick answer: An IT audit checklist covers seven areas: hardware and devices, network and firewall, user access, software and patching, backup and recovery, security settings, and documentation. Below is a working 33-point checklist you can use yourself or hand to whoever manages your IT, followed by what each item actually means and why it matters.

Most businesses only think about an IT audit once something has already gone wrong, an old starter’s account still had access, a backup turned out not to work, or a client asked for proof of security that nobody could produce. This checklist is built to be used before that happens, whether you’re running the check yourself, briefing an IT provider, or getting ready for Cyber Essentials.

33checklist items across 7 core areas
50%of UK small organisations suffer a cyber incident every year
1–3 daystypical time to work through it for a small business
Annuallyrecommended minimum frequency, or after major IT changes

The National Cyber Security Centre reports that around 1 in 2 small organisations in the UK experience a cyber incident every year (NCSC, Small organisations guide to cyber security). Almost every item below exists because it closes a gap that’s led to a real incident somewhere else.

The IT Audit Checklist

Work through each section in order. A tick against every item means that area is in reasonable shape; anything you can’t confidently tick is worth flagging for your IT provider, whoever that is.

1Hardware & Devices

  • A current inventory exists of every laptop, desktop, server, printer and piece of network equipment in use
  • No device is still running an operating system that has reached end-of-life and no longer receives security updates
  • Every device is assigned to a named individual rather than shared under one generic login
  • Ageing or failing hardware has been flagged for replacement before it fails, not after
  • Servers and network cabinets are physically secure, locked and reasonably ventilated

2Network & Firewall

  • The firewall configuration has been reviewed against how the business actually works, not left on default settings
  • Wi-Fi uses WPA2 or WPA3 encryption with a strong, non-default password
  • Guest Wi-Fi is kept on a separate network from business systems and devices
  • Remote access, VPN or RDP, requires multi-factor authentication and is limited to those who genuinely need it
  • Router and firewall firmware is up to date, and someone is responsible for checking it

3User Access & Permissions

  • The full list of user accounts has been checked against who currently works at the business
  • Every leaver’s account was disabled or removed on or before their last working day
  • Admin rights are limited to the people who need them, not handed out by default
  • Shared or generic logins have been eliminated or kept to an absolute minimum
  • A password policy is enforced across the business, covering length, complexity and reuse

4Software & Patching

  • Operating systems and business applications have been checked against the latest available updates
  • Automatic updates are enabled where it’s appropriate to do so
  • Unsupported, unlicensed or “shadow IT” software has been identified and dealt with
  • Firmware on network devices and key peripherals has been checked, not just device operating systems

5Backup & Recovery

  • What’s backed up, how often, and where it’s stored is documented and understood, not assumed
  • At least one backup copy is stored offsite or in the cloud, separate from the main network
  • Backups have been tested with an actual restore in the last twelve months, not just marked as “completed”
  • A recovery time has been agreed for the systems the business genuinely can’t operate without
  • Microsoft 365 or other cloud data is confirmed as backed up, rather than assumed to be Microsoft’s responsibility

6Security Settings

  • Multi-factor authentication is enabled on email, admin accounts and remote access
  • Antivirus or endpoint protection is installed, active and up to date on every device
  • Email filtering or anti-phishing controls are in place on the business mailbox
  • Laptops and mobile devices holding business data have encryption enabled
  • An incident response plan exists and the people who’d need to act on it know it’s there

7Documentation & Compliance

  • An IT asset register, network diagram and password policy exist and are kept up to date
  • Cyber Essentials status is known: certified, lapsed, or not yet started
  • Basic data protection checks have been done: who can access personal data, and for how long it’s kept
  • Findings from the last audit have been closed off, or there’s a clear reason why they’re still open

The Information Commissioner’s Office specifically advises limiting access to those who need it and suspending a leaver’s access as soon as they go, which is exactly what items 8 and 9 above are checking for (ICO, Practical ways to keep your IT systems safe and secure). If you already run Microsoft 365, don’t skip the admin centre and licensing settings when you go through this list; they’re easy to overlook because nothing there feels like “hardware.”

Where to start if you’re short on time: Section 3, user access. It’s the area most likely to have quietly drifted since the business last checked it, and it’s usually the fastest thing to put right once a gap is found.

How to Use This Checklist

Go through it section by section rather than jumping straight to the parts that feel most urgent. A device inventory that’s out of date usually points to gaps further down the list too, so working through it in order tends to surface the full picture rather than just the obvious issues. If you manage IT yourself, block out an afternoon and work through each item with whoever holds the relevant passwords and admin access. If you use an IT provider, this list is a fair basis for asking them to show you the evidence behind each tick, not just take their word for it.

Anything you can’t confidently tick isn’t necessarily a crisis, but it is a gap worth closing, and it’s worth writing down rather than leaving as a mental note.

What Is an IT Audit, and Why Use a Checklist Rather Than Just “Having a Look”?

An IT audit is an independent review of the systems, devices and processes a business relies on, carried out to identify risk rather than to fix anything on the spot. A checklist matters because an informal look round tends to catch whatever’s most visible, a slow laptop, an old sticky note with a password on it, and miss what isn’t: an admin account nobody remembers creating, or a backup that’s never actually been restored. Working through a fixed list of areas is what stops those quieter gaps slipping through.

How Long Does It Take, and Does It Disrupt Work?

For most small and mid-sized UK businesses, working through a checklist like this and turning it into a proper report takes one to three days, depending on how many devices, users and systems there are to review. Most of it, checking configurations, patch levels and backup logs, can be done remotely without anyone needing to stop what they’re doing. A short onsite visit is sometimes useful for physically inspecting network hardware or talking through how the team actually works day to day, but it’s rarely a full day of disruption.

What Does an IT Audit Cost?

Costs vary with scope and business size. Many IT support providers, including UK IT Services, offer a free introductory IT audit, which is genuinely free because the value to the provider is starting a conversation, not the audit itself. A more formal, certified audit is a different matter: Cyber Essentials certification, the UK government’s baseline cyber security scheme, starts from £320 +VAT for self-assessed certification, priced according to the size of the organisation (NCSC, Cyber Essentials overview). If a client, insurer or supplier is asking for proof of certification rather than an internal review, that’s the route that applies, not a checklist like this one.

When to Run This Checklist Sooner Than Your Next Scheduled Review

An annual pass through this checklist is a reasonable default, but some situations are worth acting on sooner. Run it now, rather than waiting, if any of the following apply:

  • A member of staff has left and you’re not confident every account and device was fully offboarded.
  • Nobody can say with certainty when your backups were last tested by actually restoring something from them.
  • You’re bidding for work or renewing insurance and have been asked to prove your security setup.
  • The business has grown, moved office, or changed core systems significantly since IT was last reviewed.
  • You’ve noticed devices running slowly, unexpected pop-ups, or software that hasn’t been updated in a long time.

If any of this sounds familiar, our guide on signs your business needs managed IT support covers the wider picture beyond a single audit.

What Happens After You’ve Worked Through It?

A checklist on its own is a starting point, not a finished job. The unticked items need turning into a plain-English list of what’s at risk, ranked by how much it matters rather than by how obvious it was to spot, with a realistic timeline and cost for putting each one right. A good IT provider will walk you through that list, agree which fixes matter most to your business specifically, and help you decide what’s handled in-house and what’s better suited to ongoing managed IT support.

How Often Should You Run This Checklist?

Once a year is a sensible minimum for most small and mid-sized businesses, in the same way an annual accounts review or insurance renewal keeps other parts of the business on track. It’s also worth repeating after any significant change, a move to new premises, a merger, a large round of hiring, or a shift to new core software, since each of these can quietly introduce risks that weren’t there at the last review. Businesses working towards or maintaining Cyber Essentials certification will need a fresh assessment at each annual renewal in any case.

IT Audit Checklist vs Cyber Essentials: What’s the Difference?

The two are related but answer different questions, and it’s a common point of confusion.

This checklist

  • Covers your whole IT setup: hardware, network, backups, access and security
  • Is flexible, and can be tailored to your business
  • Produces an internal picture and a list of what to fix
  • Is not a certification you can show to clients or insurers

!Cyber Essentials

  • Assesses five specific technical controls set by the NCSC
  • Follows a fixed, standardised question set
  • Results in a certificate valid for 12 months
  • Is often required by clients, insurers or government contracts

In practice, many businesses work through a checklist like this one to find out where they stand and fix the basics, then use Cyber Essentials certification as the formal proof once those basics are in place.

Frequently Asked Questions

Do I need to run this checklist if I already have an IT support contract?

Yes, it’s still worth it. Ongoing IT support usually focuses on keeping day-to-day systems running and responding to issues as they come up, while a full checklist takes a step back and checks the wider setup against current risks, which can surface things routine support hasn’t flagged.

Can this checklist be worked through remotely?

Most of it, yes. Reviewing configurations, patch levels, backup logs and user accounts doesn’t require anyone onsite. A short physical visit is sometimes useful for checking network hardware or talking through how the office actually works, but a full pass rarely needs more than that.

What if I can’t tick every item myself?

That’s normal, and it’s the point of the exercise. Note down anything you’re unsure of or can’t verify, and treat that list as the brief for whoever handles your IT, whether that’s an internal team or an external provider.

Want an Expert to Run This Checklist For You?

Get a free IT audit and a plain-English report of what’s working, what’s at risk, and what to fix first, in order of priority.

Get a Free IT Audit

An IT audit checklist isn’t about catching your business out. It’s a straightforward way to find out what’s actually going on inside your systems before a small gap turns into downtime, a data breach or an insurance claim you can’t support. Work through it, note what you can’t confidently tick, and use that list to decide what genuinely needs fixing first.

Table of Contents