
An IT audit checklist for a small business covers who holds admin access, what devices and software you own and whether they are still supported, whether backups actually restore, what you pay for against what you use, which vendors hold your data, whether anyone would notice an attack, and whether evidence exists for each answer. Work through it with read-only access, write down what you saw and where, and turn every gap into a dated fix with an owner.
This is the checklist behind our IT audit services, where findings are grouped under the six functions of NIST CSF 2.0 so anyone can check the report against a public framework. It is an operational review, not a SOC 2 report, a certification or a financial audit. If you want a shorter list of security basics to fix this month, start with our small business cybersecurity checklist.
Which areas does an IT audit checklist cover?
Seven areas, each answering a question an owner should be able to answer without calling the IT provider:
| Area | NIST CSF 2.0 function | The question it answers |
|---|---|---|
| Admin access and accounts | Govern, Protect | Who controls the accounts the business runs on? |
| Devices, software and lifecycle | Identify | What do we have, and is it still supported? |
| Backup and recovery | Recover | Can we get our data back, and how fast? |
| Licensing and subscriptions | Identify, Govern | Are we paying for what we use? |
| Vendors and contracts | Govern | Who holds our data, and on what terms? |
| Monitoring and incident response | Detect, Respond | Would we notice an attack, and what happens next? |
| Documentation and evidence | All six | Could someone else run this tomorrow? |
How do you audit admin access and accounts?
| Check | How to verify it | Evidence to save |
|---|---|---|
| Every administrator in Microsoft 365 or Google Workspace is a named person, with no shared admin logins | Export the admin role assignments | The dated role export |
| Multifactor authentication is enforced for every account, administrators first | Run the MFA registration and enforcement report | The report |
| Emergency access accounts exist, and their credentials are stored offline | Confirm the accounts and where the credentials are kept | A note of the storage location, never the password |
| Former employees cannot sign in | Compare enabled accounts with the staff list | The reconciled list |
| Domain registrar, DNS and firewall logins belong to the company, not to a person or a provider | Check the account owner on each portal | Screenshots showing the owner |
| Vendor portals and licensing accounts are registered to the company | Review each portal's account details | A list of portals and owners |
| Shared mailboxes and service accounts have a named owner | List them with their owners | The list |
How do you audit devices, software and lifecycle?
| Check | How to verify it | Evidence to save |
|---|---|---|
| The device inventory matches what you are billed for | Compare the management console with invoices | The reconciled inventory |
| No computer runs an unsupported operating system | Report operating system versions; Windows 10 reached end of support on October 14, 2025 | The version report |
| Laptops are encrypted | Run the disk encryption report | The report |
| Every device has endpoint protection that is reporting in | Compare the protection console with the inventory | The coverage report |
| Security updates are current | Run patch compliance for computers, servers and network devices | Patch reports with dates |
| Warranty and replacement dates are recorded for servers, firewalls and laptops | Check the asset records | The lifecycle list |
How do you audit backups and recovery?
| Check | How to verify it | Evidence to save |
|---|---|---|
| Everything important is backed up, including Microsoft 365 or Google Workspace data | Compare backup job scope with the system list | The scope list |
| At least one copy is offline or immutable | Inspect where each copy lives and who can delete it | Backup configuration |
| A restore has been tested recently and worked | Restore a file, a mailbox or a server you authorize | The test record with the time taken |
| The recovery order and target times for critical systems are written down | Read the recovery plan | The plan's version and date |
| Someone reviews failed backup jobs | Check alert routing and recent tickets | Alert settings and tickets |
CISA's ransomware guide sets the standard to measure against: keep offline, encrypted backups of critical data and regularly test their availability and integrity in a disaster recovery scenario. A backup job that reports success is not a tested restore.
How do you audit licensing, vendors and contracts?
| Check | How to verify it | Evidence to save |
|---|---|---|
| Paid seats match active users | Compare license counts with sign-in activity and the staff list | The license report |
| Renewal dates and automatic renewal terms are known | Review subscriptions and contracts | A renewal calendar |
| Every vendor with access to your data or systems is listed | Combine invoices, admin consoles and contracts | The vendor list |
| IT contracts state the notice period, what is included and who owns the documentation | Read the agreements | A summary of terms |
| Key vendors provide security evidence, such as a SOC 2 report | Request and read the reports | Reports with review notes |
| Contracts say how your data comes back when you leave | Read the exit and deletion clauses | The clause references |
How do you audit monitoring, response and documentation?
| Check | How to verify it | Evidence to save |
|---|---|---|
| Security alerts reach a person who acts on them | Trace one recent alert from detection to ticket | The alert and its ticket |
| Logs are kept long enough to investigate an incident | Check retention settings | The settings |
| A written incident response plan exists, with a printed or offline copy | Read it and find the offline copy | The plan's version and date |
| Cyber insurance requirements are met and the claims contact is known | Compare the policy's requirements with the controls found | A gap note |
| A current network diagram, password vault and runbooks exist | Ask for each and check the dates | Copies or locations |
| Ticket history shows how support really works | Review volume, repeat problems and time to resolution | A ticket summary |
Which framework should an IT audit follow?
For a small business, NIST CSF 2.0 is the most practical frame. It groups outcomes into six functions, Govern, Identify, Protect, Detect, Respond and Recover, and its categories map neatly onto the checklist: asset management (ID.AM) for inventory, identity management, authentication and access control (PR.AA) for accounts, cybersecurity supply chain risk management (GV.SC) for vendors, and incident recovery plan execution (RC.RP) for restores. CISA's Cross-Sector Cybersecurity Performance Goals, now in version 2.0 and aligned to the same functions, offer a short set of high-impact practices that small and medium-sized organizations can start with.
If you run an ISO 27001 management system, its internal audit under clause 9.2 covers the whole system, and ISO 19011:2026 gives guidance on managing audit programmes; our ISO 27001 checklist includes an internal audit checklist.
What goes in an IT audit report?
A report that cannot be acted on is a filing exercise. Use this structure:
| Section | What it contains |
|---|---|
| Executive summary | The handful of findings that matter most, in business terms, with the cost of leaving them |
| Scope and method | What was reviewed, the access used, the dates, and what was out of scope |
| Findings | One row per finding: ID, area, what was seen and where, the evidence, the risk, the recommendation, the effort, the owner and the target date |
| Remediation plan | The findings in priority order, grouped into this month, this quarter and this year |
| Appendices | Inventories, exports and screenshots behind the findings |
Here is an illustrative findings table for a fictional 30-person office. It describes no client and no real result.
| ID | Finding | Evidence | Risk | Fix and owner |
|---|---|---|---|---|
| F-01 | A former bookkeeper still holds a global admin role in Microsoft 365 | Admin role export | High | Remove the role this week and review admins monthly; office manager |
| F-02 | Server backups report success, but no restore has been tested and the only copy sits on a share user PCs can reach | Backup console and job history | High | Add an immutable copy and test a restore within 30 days; IT provider |
| F-03 | Six PCs still run Windows 10 after its October 14, 2025 end of support | Device inventory | High | Upgrade or replace within 60 days; operations manager |
| F-04 | 46 paid seats for 31 active users | License report and staff list | Medium | Remove unused seats at renewal; controller |
How do findings become a remediation plan?
- Rank by risk, then effort. Fix high-risk, low-effort items first, such as a former employee's admin role.
- Give every finding one owner and a date. A finding owned by everyone is owned by no one.
- Group the work into 30, 90 and 365 days, so the budget for larger items can be planned.
- Retest each fix and save the new evidence next to the original finding.
- Run the checklist again each year, and after a provider change, an office move or a major system change.
What does NetSys review in an IT audit?
With your written authorization we ask for read-only administrator access, or a supervised screen-share, to your Microsoft 365 or Google Workspace tenant, firewall, backup console, device management tools and ticketing system. We review consoles, logs and exports, interview staff, and test a restore where you authorize one. Draft findings come to you for a fact check before the report is final, and the report is yours, written so your current provider, your staff or NetSys can act on it. There is no obligation to move your support to us. NetSys is not a CPA firm or a certification body, and this audit does not replace a formal audit or certification. A security risk assessment, which asks how an attacker would get in, is a separate scope.
Want a second opinion on what you pay for? Book a call and tell us your user count, locations and what prompted the question.
Frequently asked questions
What does an IT audit checklist cover?
Admin access and accounts, devices and software lifecycle, backup and recovery, licensing, vendors and contracts, monitoring and incident response, and documentation. Each check names how to verify it and the evidence to keep, so another person can confirm the result later.
Who should maintain the IT audit checklist?
A named owner in the business, usually the owner, the operations lead or a controller, keeps the checklist and the findings log. The IT provider supplies evidence and carries out fixes, but the business should own the list, because some findings are about the provider.
How do we validate the result of an IT audit?
Every finding should point to evidence someone else can re-check: a dated export, a report or a screenshot from the system itself. Retest each fix and save the new evidence beside the finding. Where it matters most, such as backups, prove it by restoring data, not by reading a status page.
How often should a small business do an IT audit?
Once a year is a sensible baseline, plus whenever something big changes: a new IT provider, a contract renewal, an office move, a cyber insurance application or the departure of the one person who knew how everything connects.
Is an IT audit the same as a SOC 2 audit?
No. A SOC 2 report is an attestation issued by a CPA firm. An IT audit is an operational review of your environment and your provider's work. It can help you prepare for formal audits, but it does not replace one.
Can we use this as an IT audit template in Excel?
Yes. Copy each checklist table into its own tab, add columns for status, owner and date, and use the findings table as the first tab. Keep the evidence files in a folder named by finding ID so the spreadsheet stays light.
Sources and further reading
- NIST: The Cybersecurity Framework (CSF) 2.0, February 26, 2024: the six functions and their categories, checked October 2026.
- CISA: Cross-Sector Cybersecurity Performance Goals 2.0: voluntary baseline practices aligned to CSF 2.0, checked October 2026.
- CISA #StopRansomware Guide (September 2023): offline, encrypted backups and restore testing, checked October 2026.
- Microsoft Lifecycle: Windows 10 Home and Pro: end of support on October 14, 2025, checked October 2026.
- ISO 19011:2026, Guidelines for auditing management systems, checked October 2026.
Related reading
Managed ITNew-Hire IT Onboarding Checklist for Small Business
Read Article
CybersecurityNIST Cybersecurity Framework 2.0: A Small Business Guide
Read Article
Managed ITWhat Does IT Support Do for a Business?
Read ArticleAlso on this topic: SharePoint Permissions Best Practices: Groups, Sharing Links and an Audit Checklist
Discuss it audit services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
