IT Asset Audit Checklist: Free Download

An IT asset audit confirms that what you think you own matches what actually exists on your network, in your cloud tenants, and in your software estate. The gap between the two is where overspend, security holes, and compliance findings live. This free IT asset audit checklist walks you through every category you need to cover, and explains how to keep the work manageable.

Use this checklist before a formal audit, ahead of a compliance review, or as part of a regular asset health check. Tick each item as you confirm it. Where you cannot confirm an item, record the reason and follow it up.

Hardware audit checklist

  • List every endpoint device, including laptops, desktops, and workstations, with hostname and serial number.
  • Record every mobile device, including company-owned phones and tablets, with IMEI where applicable.
  • Capture peripherals: monitors, docks, printers, scanners, and external drives.
  • Confirm the physical location of each device, including remote and home-working locations.
  • Match each device to an assigned user or a shared pool, and flag unassigned equipment.
  • Identify devices that have not checked in to any management system in the last 90 days.
  • Check for devices recorded in the register that no longer physically exist, and for devices that exist but are not in the register.
  • Record purchase date and current book value for depreciation reporting.

Software audit checklist

  • Inventory installed applications across all endpoints, including version numbers.
  • List all purchased software licences with entitlement counts and renewal dates.
  • Compare installed software against licensed software to find unauthorised or unlicensed installs.
  • Identify unused licences, where seats are paid for but not assigned or not used.
  • Check for duplicate applications serving the same purpose, such as two PDF editors or two backup tools.
  • Confirm operating system versions and patch levels across the estate.
  • Review end-of-life software that no longer receives security updates.
  • Record the evidence source for each licence claim, such as a vendor portal, procurement order, or reseller invoice.

Cloud and SaaS audit checklist

  • List all cloud subscriptions across AWS, Microsoft Azure, and Google Cloud, including dormant accounts.
  • Identify idle or oversized cloud instances that incur cost without delivering value.
  • Inventory all SaaS subscriptions, including tools bought on individual or departmental credit cards, known as shadow IT.
  • Confirm the number of active seats against the number of paid seats for each SaaS product.
  • Check auto-renewal settings and flag subscriptions due for renewal in the next 90 days.
  • Review administrative and global admin accounts in each cloud tenant.
  • Identify orphaned cloud resources, such as unattached storage volumes and unused load balancers.

Network audit checklist

  • Inventory all network devices, including switches, routers, access points, and firewalls.
  • Record IP addresses, subnets, and VLAN assignments for each device.
  • Check firmware versions and flag any devices running unsupported firmware.
  • Identify unmanaged or rogue devices connected to the network.
  • Confirm switch and access point locations against the physical asset register.
  • Review open ports and unused network segments that could expose the estate.

Security audit checklist

  • Confirm every endpoint has an active endpoint detection and response, or EDR, agent installed and reporting.
  • Check disk encryption status on all laptops and mobiles.
  • Review device compliance policies in your mobile device management platform.
  • Identify devices that are enrolled but failing compliance, such as missing patches or disabled controls.
  • Check for privileged user accounts with no multi-factor authentication enforced.
  • Review user-to-device assignments for accounts belonging to leavers or contractors whose engagement has ended.
  • Confirm the audit trail of state changes is complete and timestamped for the review period.
  • Validate that access to asset data itself is restricted to authorised roles.

How often should you run an IT asset audit?

Frequency depends on how fast your estate changes and what compliance frameworks you are working towards.

  • Quarterly – for fast-moving estates with frequent joiners, leavers, and device churn. Focus on high-value hardware and SaaS licences.
  • Half-yearly – a sensible default for most UK SMEs. Covers drift in assignments, software versions, and cloud spend.
  • Annually – a full audit ahead of year-end accounts and any compliance certification or recertification, such as ISO 27001 stage audits.
  • Event-driven – run a targeted audit after a round of redundancies, an office move, a merger or acquisition, or a security incident.

The problem with any fixed schedule is that the data goes stale between audits. A quarterly audit feels thorough, but the register is only accurate on the day you finish it. Between audits, devices move, licences renew, and people leave without anyone recording the change.

How AssetGraph automates audit data collection

AssetGraph collects the data on this checklist automatically, so an audit becomes a review of evidence that already exists rather than a scramble to gather it. The platform ingests asset data passively from the management tools you already use, including Microsoft Graph for Entra ID devices and Intune managed devices, Jamf Pro and Intune for mobile device management, network discovery via SNMP and LLDP, cloud provider APIs, EDR agents, and procurement systems.

  • Hardware – endpoints and mobiles are discovered from Microsoft Graph and your MDM, with serial numbers, hostnames, and user assignments populated automatically.
  • Software – installed applications and patch status are pulled from management planes, so version drift and end-of-life software are visible without a manual sweep.
  • Cloud and SaaS – cloud instances and SaaS seats are tracked at seat level, surfacing unused licences and idle resources before they cost another month of fees.
  • Network – network devices are discovered via SNMP and LLDP, with locations reconciled against the register.
  • Security – compliance policies and device compliance status come from your MDM, with violations flagged minutes after a policy breach rather than weeks later during an audit.

The platform normalises records from every source into one canonical schema, deduplicates across sources, and reconciles the same device when it appears in more than one system. Every state change is recorded in a timestamped audit trail, so you have the evidence an auditor asks for without rebuilding it from scratch.

AssetGraph is designed to support ISO 27001, SOC 2, and ITIL workflows. All traffic is encrypted in transit over HTTPS, API credentials are stored server-side and never in the browser, read-only connector scopes are used where supported by the API, and your data is hosted in the EU on Supabase in eu-west-1. AssetGraph is not itself ISO 27001 or SOC 2 certified.

Start a free trial and audit with live data

This checklist is free to use and adapt. When you want to run an audit against data that is already collected and reconciled, start a 7-day free trial of AssetGraph. No card is needed to sign up, and you can pay by direct debit.

Pricing is simple: Starter at £29/mo, Professional at £99/mo, and Enterprise at £299/mo. Pay annually and get 50% off. Prices exclude VAT.

Start your free trial

Run this checklist once by hand and you will see exactly where the manual gaps are. The next step is to close those gaps with automated collection, so your next audit takes hours instead of weeks.

Get your free Audit Checklist (Printable)

Enter your email and we’ll send you the download link. We won’t spam you – just one email with your resource.

Already have AssetGraph? Go to dashboard