IT Assessment Checklist: What a Good Audit Covers
By ConsultingCrafts · 3 min read · Published
Why an IT assessment comes before any big decision
Before you switch providers, move to the cloud, or sign a managed IT contract, you need an honest picture of what you're actually running. An IT assessment is that picture — a structured audit of your systems, security, and risks that turns "we think things are fine" into a documented baseline. Skip it and every quote you receive is a guess; run it and you can hold every provider, project, and budget to the same evidence. The checklist below covers what a genuinely thorough assessment should examine.
1. Asset & infrastructure inventory
You can't secure or support what you haven't counted. A good assessment starts with a full inventory: servers, workstations, laptops, network gear, and the software and licences running on each. It flags devices that are unmanaged, out of warranty, or running end-of-life operating systems — the quiet liabilities that don't show up until they fail. The deliverable is a living asset register, not a one-off spreadsheet.
2. Security posture & access control
This is where most assessments earn their keep. Expect a review of endpoint protection, patch levels, multi-factor authentication coverage, firewall and network segmentation, and how administrative access is granted and revoked. A strong audit doesn't just note that a tool exists — it checks whether it's actually deployed everywhere it should be, because the gap between "we have MFA" and "MFA is enforced on every account" is where breaches happen.
3. Backup, recovery & business continuity
Backups fail silently, so an assessment should verify them, not assume them. It should confirm what's backed up, how often, where copies live, and — critically — whether a restore has ever been tested. Tie this to your recovery targets: how much data can you afford to lose (RPO) and how long can you be down (RTO)? An audit that reports "backups are running" without testing a restore hasn't finished the job.
4. Network, performance & reliability
The assessment should map how your network is put together and where it strains — internet links, VPN and remote-access setup, Wi-Fi coverage, and any single points of failure that could take the whole office offline. It should also surface the day-to-day drags: the slow application everyone tolerates, the server running hot, the aging switch. These are the issues that quietly cost productivity long before they cause an outage.
5. Compliance, documentation & risk
If you're regulated — HIPAA, GDPR, SOC 2, PCI — the audit should measure you against those requirements and name the gaps. Even if you're not, it should check that the basics are documented: network diagrams, admin credentials, vendor contacts, and runbooks. The final output is a prioritized risk register — issues ranked by likelihood and impact, each with a recommended fix — so you spend budget on what actually matters first.
What a good assessment covers
Assets & infrastructure
Full inventory of hardware, software, licences, and end-of-life risks.
Security & access
Endpoint, patching, MFA, firewall, and admin-access review.
Backup & recovery
Verified backups, tested restores, and RTO/RPO targets.
Compliance & risk
Regulatory gaps, documentation, and a prioritized risk register.
What you should get at the end
A real assessment ends with documents you can act on, not a sales pitch. Expect an asset register, a security and risk report, a prioritized remediation plan with rough effort and cost, and a clear roadmap for the next 6–12 months. That roadmap is what turns findings into strategy — it feeds directly into IT strategy and planning and into an accurate view of what ongoing support should cost (our managed IT cost guide shows where the numbers land).
How ConsultingCrafts runs assessments
ConsultingCrafts runs assessments remote-first, with on-site work only where the task genuinely needs hands on hardware. You get the full deliverable set — inventory, risk register, and a prioritized roadmap — in plain language, with no obligation to buy anything further. It's the cleanest way to get an independent baseline before you commit to a provider or a project. See the full IT assessment service, or book a free consultation to scope one.
Related service
IT Assessment Services
About the author
Written by
ConsultingCrafts


