
IT Infrastructure Audit: What Auditors Check and How to Prepare
Most IT infrastructure audits start with the same question: "do you have up-to-date documentation?" And most end with the same conclusion: the documentation exists, but the last time anyone saw it was during the previous server room move.
What an audit is — and what it is not
An infrastructure audit is an inventory and an assessment of the actual state of things: what works, in what condition, who is responsible for it, and what happens when it stops working. It is not an inspection of employees or a hunt for someone to blame. A well-run audit gives the board the one thing usually missing: a complete picture of operational risk in a single document.
What the auditor looks at first
It starts with the physical layer, because that is where neglect shows fastest. Distribution racks and their condition (labelled patch cords are rare, and should be the norm), backup power and the age of UPS batteries, server room cooling, access control to technical rooms. Then the network: topology, switch age, configurations (is anyone backing them up?), segmentation, single points of failure. Then servers and services: what is covered by vendor support, what runs on out-of-warranty hardware, how backups are set up and — more importantly — whether anyone has ever tested a restore.
Licences and contracts deserve their own chapter: support that has expired or is tied to a vendor that no longer exists tends to surface only during an outage.
Typical findings
After several hundred projects the list repeats with striking regularity: a single switch carrying the entire company; a UPS with batteries from the previous decade; a backup that "runs", but nobody knows where to; administrative accounts belonging to former employees; server room air conditioning with no redundancy and no service contract. None of these findings is exotic — they are everyday reality in mid-sized and large organisations where infrastructure grew for years without a single owner.
How to prepare
Before the audit it pays to gather in one place: the network diagram (even an outdated one — it will serve as a starting point), the list of service contracts and licences, a hardware inventory with purchase dates, backup procedures, and a list of people holding administrative access. Gaps in these materials are themselves an audit finding — they show where the organisation relies on tribal knowledge instead of documentation.
What you get at the end
An audit report should contain three things: a description of the actual state, a list of risks ranked by business impact, and recommendations with cost estimates — from zero-cost changes (configuration, procedures) to investments. If the report ends with generalities along the lines of "modernisation is recommended", it was not an audit, it was a survey.
An audit is the natural first step before an external partner takes over infrastructure maintenance — both sides then know exactly what they are taking responsibility for.
IT Infrastructure
Enterprise-grade network design, server rooms, structured cabling and communication systems.
Related Articles

Outsourced Technical Maintenance or an In-House Team? Doing the Maths Honestly
Read full article
Infrastructure Maintenance SLAs: 7 Clauses Worth Reading Twice
Read full article
