HomeBlogBest Practices

IT Audit Checklist for Small Business, With a Report Template

Pixel-art illustration of a robot holding a tablet on a busy city sidewalk, with yellow taxis and pedestrians at a crosswalk behind it

An IT audit checklist for a small business covers who holds admin access, what devices and software you own and whether they are still supported, whether backups actually restore, what you pay for against what you use, which vendors hold your data, whether anyone would notice an attack, and whether evidence exists for each answer. Work through it with read-only access, write down what you saw and where, and turn every gap into a dated fix with an owner.

This is the checklist behind our IT audit services, where findings are grouped under the six functions of NIST CSF 2.0 so anyone can check the report against a public framework. It is an operational review, not a SOC 2 report, a certification or a financial audit. If you want a shorter list of security basics to fix this month, start with our small business cybersecurity checklist.

Which areas does an IT audit checklist cover?

Seven areas, each answering a question an owner should be able to answer without calling the IT provider:

AreaNIST CSF 2.0 functionThe question it answers
Admin access and accountsGovern, ProtectWho controls the accounts the business runs on?
Devices, software and lifecycleIdentifyWhat do we have, and is it still supported?
Backup and recoveryRecoverCan we get our data back, and how fast?
Licensing and subscriptionsIdentify, GovernAre we paying for what we use?
Vendors and contractsGovernWho holds our data, and on what terms?
Monitoring and incident responseDetect, RespondWould we notice an attack, and what happens next?
Documentation and evidenceAll sixCould someone else run this tomorrow?

How do you audit admin access and accounts?

CheckHow to verify itEvidence to save
Every administrator in Microsoft 365 or Google Workspace is a named person, with no shared admin loginsExport the admin role assignmentsThe dated role export
Multifactor authentication is enforced for every account, administrators firstRun the MFA registration and enforcement reportThe report
Emergency access accounts exist, and their credentials are stored offlineConfirm the accounts and where the credentials are keptA note of the storage location, never the password
Former employees cannot sign inCompare enabled accounts with the staff listThe reconciled list
Domain registrar, DNS and firewall logins belong to the company, not to a person or a providerCheck the account owner on each portalScreenshots showing the owner
Vendor portals and licensing accounts are registered to the companyReview each portal's account detailsA list of portals and owners
Shared mailboxes and service accounts have a named ownerList them with their ownersThe list

How do you audit devices, software and lifecycle?

CheckHow to verify itEvidence to save
The device inventory matches what you are billed forCompare the management console with invoicesThe reconciled inventory
No computer runs an unsupported operating systemReport operating system versions; Windows 10 reached end of support on October 14, 2025The version report
Laptops are encryptedRun the disk encryption reportThe report
Every device has endpoint protection that is reporting inCompare the protection console with the inventoryThe coverage report
Security updates are currentRun patch compliance for computers, servers and network devicesPatch reports with dates
Warranty and replacement dates are recorded for servers, firewalls and laptopsCheck the asset recordsThe lifecycle list

How do you audit backups and recovery?

CheckHow to verify itEvidence to save
Everything important is backed up, including Microsoft 365 or Google Workspace dataCompare backup job scope with the system listThe scope list
At least one copy is offline or immutableInspect where each copy lives and who can delete itBackup configuration
A restore has been tested recently and workedRestore a file, a mailbox or a server you authorizeThe test record with the time taken
The recovery order and target times for critical systems are written downRead the recovery planThe plan's version and date
Someone reviews failed backup jobsCheck alert routing and recent ticketsAlert settings and tickets

CISA's ransomware guide sets the standard to measure against: keep offline, encrypted backups of critical data and regularly test their availability and integrity in a disaster recovery scenario. A backup job that reports success is not a tested restore.

How do you audit licensing, vendors and contracts?

CheckHow to verify itEvidence to save
Paid seats match active usersCompare license counts with sign-in activity and the staff listThe license report
Renewal dates and automatic renewal terms are knownReview subscriptions and contractsA renewal calendar
Every vendor with access to your data or systems is listedCombine invoices, admin consoles and contractsThe vendor list
IT contracts state the notice period, what is included and who owns the documentationRead the agreementsA summary of terms
Key vendors provide security evidence, such as a SOC 2 reportRequest and read the reportsReports with review notes
Contracts say how your data comes back when you leaveRead the exit and deletion clausesThe clause references

How do you audit monitoring, response and documentation?

CheckHow to verify itEvidence to save
Security alerts reach a person who acts on themTrace one recent alert from detection to ticketThe alert and its ticket
Logs are kept long enough to investigate an incidentCheck retention settingsThe settings
A written incident response plan exists, with a printed or offline copyRead it and find the offline copyThe plan's version and date
Cyber insurance requirements are met and the claims contact is knownCompare the policy's requirements with the controls foundA gap note
A current network diagram, password vault and runbooks existAsk for each and check the datesCopies or locations
Ticket history shows how support really worksReview volume, repeat problems and time to resolutionA ticket summary

Which framework should an IT audit follow?

For a small business, NIST CSF 2.0 is the most practical frame. It groups outcomes into six functions, Govern, Identify, Protect, Detect, Respond and Recover, and its categories map neatly onto the checklist: asset management (ID.AM) for inventory, identity management, authentication and access control (PR.AA) for accounts, cybersecurity supply chain risk management (GV.SC) for vendors, and incident recovery plan execution (RC.RP) for restores. CISA's Cross-Sector Cybersecurity Performance Goals, now in version 2.0 and aligned to the same functions, offer a short set of high-impact practices that small and medium-sized organizations can start with.

If you run an ISO 27001 management system, its internal audit under clause 9.2 covers the whole system, and ISO 19011:2026 gives guidance on managing audit programmes; our ISO 27001 checklist includes an internal audit checklist.

What goes in an IT audit report?

A report that cannot be acted on is a filing exercise. Use this structure:

SectionWhat it contains
Executive summaryThe handful of findings that matter most, in business terms, with the cost of leaving them
Scope and methodWhat was reviewed, the access used, the dates, and what was out of scope
FindingsOne row per finding: ID, area, what was seen and where, the evidence, the risk, the recommendation, the effort, the owner and the target date
Remediation planThe findings in priority order, grouped into this month, this quarter and this year
AppendicesInventories, exports and screenshots behind the findings

Here is an illustrative findings table for a fictional 30-person office. It describes no client and no real result.

IDFindingEvidenceRiskFix and owner
F-01A former bookkeeper still holds a global admin role in Microsoft 365Admin role exportHighRemove the role this week and review admins monthly; office manager
F-02Server backups report success, but no restore has been tested and the only copy sits on a share user PCs can reachBackup console and job historyHighAdd an immutable copy and test a restore within 30 days; IT provider
F-03Six PCs still run Windows 10 after its October 14, 2025 end of supportDevice inventoryHighUpgrade or replace within 60 days; operations manager
F-0446 paid seats for 31 active usersLicense report and staff listMediumRemove unused seats at renewal; controller

How do findings become a remediation plan?

  1. Rank by risk, then effort. Fix high-risk, low-effort items first, such as a former employee's admin role.
  2. Give every finding one owner and a date. A finding owned by everyone is owned by no one.
  3. Group the work into 30, 90 and 365 days, so the budget for larger items can be planned.
  4. Retest each fix and save the new evidence next to the original finding.
  5. Run the checklist again each year, and after a provider change, an office move or a major system change.

What does NetSys review in an IT audit?

With your written authorization we ask for read-only administrator access, or a supervised screen-share, to your Microsoft 365 or Google Workspace tenant, firewall, backup console, device management tools and ticketing system. We review consoles, logs and exports, interview staff, and test a restore where you authorize one. Draft findings come to you for a fact check before the report is final, and the report is yours, written so your current provider, your staff or NetSys can act on it. There is no obligation to move your support to us. NetSys is not a CPA firm or a certification body, and this audit does not replace a formal audit or certification. A security risk assessment, which asks how an attacker would get in, is a separate scope.

Want a second opinion on what you pay for? Book a call and tell us your user count, locations and what prompted the question.

Frequently asked questions

What does an IT audit checklist cover?

Admin access and accounts, devices and software lifecycle, backup and recovery, licensing, vendors and contracts, monitoring and incident response, and documentation. Each check names how to verify it and the evidence to keep, so another person can confirm the result later.

Who should maintain the IT audit checklist?

A named owner in the business, usually the owner, the operations lead or a controller, keeps the checklist and the findings log. The IT provider supplies evidence and carries out fixes, but the business should own the list, because some findings are about the provider.

How do we validate the result of an IT audit?

Every finding should point to evidence someone else can re-check: a dated export, a report or a screenshot from the system itself. Retest each fix and save the new evidence beside the finding. Where it matters most, such as backups, prove it by restoring data, not by reading a status page.

How often should a small business do an IT audit?

Once a year is a sensible baseline, plus whenever something big changes: a new IT provider, a contract renewal, an office move, a cyber insurance application or the departure of the one person who knew how everything connects.

Is an IT audit the same as a SOC 2 audit?

No. A SOC 2 report is an attestation issued by a CPA firm. An IT audit is an operational review of your environment and your provider's work. It can help you prepare for formal audits, but it does not replace one.

Can we use this as an IT audit template in Excel?

Yes. Copy each checklist table into its own tab, add columns for status, owner and date, and use the findings table as the first tab. Keep the evidence files in a folder named by finding ID so the spreadsheet stays light.

Sources and further reading

IT Audit Services

Discuss it audit services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.