IT AuditChecklist, Process, and Independent IT Audit Services for Regulated Businesses

An IT audit is an independent, evidence-based examination of a business's technology environment: its infrastructure, access controls, backups, change and patch processes, documentation, vendors, and policies, measured against a defined standard to show what works, what does not, and what to fix first. Petronella Technology Group has audited, built, and managed IT environments for regulated businesses in Raleigh and across North Carolina since 2002. This page explains what an IT audit covers, the checklist we use, the process from scoping to remediation, and how an IT audit differs from a cybersecurity audit, a penetration test, and a SOC 2 report.

Founded 2002|BBB A+ Since 2003|CyberAB RPO #1449|Raleigh, NC and Nationwide
Key Takeaways
  • An IT audit tests evidence, not opinions. Every finding should trace to something the auditor saw: a configuration export, an access list, a restore log, a missing ticket. An audit built on interviews alone is an assessment with a more expensive name.
  • Scope decides the value. The same business can commission an IT general controls audit, an infrastructure audit, a security controls audit, or a compliance readiness audit. Each answers a different question, and mixing them without saying so produces a report nobody can act on.
  • The checklist has ten domains. Governance, asset inventory, identity and access, network and perimeter, endpoints and servers, patching and vulnerabilities, backup and recovery, change management, logging and monitoring, and vendors. A gap in any one usually shows up as a finding in two or three others.
  • Frameworks already require periodic review. NIST SP 800-171 control 3.12.1, the HIPAA Security Rule evaluation standard at 45 CFR 164.308(a)(8), ISO/IEC 27001 clause 9.2, and the FTC Safeguards Rule at 16 CFR 314.4(d) each expect an organization to test whether its controls work.
  • The report is not the deliverable; the remediation plan is. A good IT audit ends with ranked findings, an owner and a date for each, and a re-test. That is the part most audits skip.
Definition

What Is an IT Audit?

An IT audit, also called an information technology audit or an IT infrastructure audit, is a structured review of how a business's technology is configured, operated, and governed, performed by someone who did not build it. The auditor defines a scope, selects the criteria the environment will be measured against, collects evidence, tests whether controls are designed correctly and operating as designed, and reports findings ranked by risk. The criteria can be a regulatory framework such as NIST SP 800-171 or the HIPAA Security Rule, a control framework such as COBIT or the CIS Critical Security Controls, or the business's own written policies.

The word "audit" is used loosely in IT, and it helps to be precise. In the accounting profession, an IT audit often means an IT general controls review performed by a CPA firm in support of a financial statement audit or a SOX Section 404 attestation. For most small and mid-sized businesses, the question is different and more practical: is our environment sound, is it documented, would it survive a failure or an attack, and would it satisfy the assessor or insurer who is going to ask? That is the kind of IT audit this page describes, and it is the kind Petronella Technology Group performs.

We have run IT environments for businesses in the Research Triangle since 2002, which means our auditors have also been the engineers who inherit an environment after someone else's audit. That experience shapes the method. We look for the things that fail in real incidents and real assessments: backups nobody has restored, administrator accounts nobody owns, firewall rules nobody can explain, and policies that describe a company that no longer exists.

What an IT Audit Is
  • An independent review against stated criteria, with the criteria named in the report
  • Testing of both control design (is the control the right one) and operating effectiveness (does it actually run)
  • Evidence collected from systems, not only from interviews and questionnaires
  • Findings ranked by risk, each with a recommended fix, an owner, and a target date
  • A baseline you can re-test against next year, so progress is measurable
What It Is Not
  • Not a penetration test, which tries to break in rather than review how the environment is run
  • Not a SOC 2 report, which only a licensed CPA firm can issue under AICPA attestation standards
  • Not a vulnerability scan, which is one input to an audit rather than the audit itself
  • Not a sales assessment that ends in a hardware quote
  • Not a one-time event; controls drift, and an audit is a point-in-time reading of a moving system
Audit Types

Types of IT Audits and the Question Each One Answers

Before any evidence is collected, the business and the auditor should agree which of these audits is being performed. Most engagements combine two, and saying so in the scope statement prevents the most common complaint about audit reports: that they answered a question nobody asked.

Audit Type Question It Answers Typical Criteria Who Usually Asks
IT infrastructure auditIs the environment sound, supportable, documented, and recoverable?Vendor best practice, CIS Benchmarks, the business's own standardsOwners, new IT leadership, a business changing providers
IT general controls (ITGC) reviewAre access, change, operations, and development controls reliable enough to trust the systems that produce financial data?COBIT, COSO, the four ITGC domainsExternal financial auditors, lenders, boards
Security controls auditDo the security controls exist and work as described?CIS Controls, NIST CSF 2.0, NIST SP 800-53Cyber insurers, customers sending security questionnaires
Compliance readiness auditWould we pass the formal assessment if it happened next month?NIST SP 800-171 and CMMC, HIPAA Security Rule, PCI DSS, SOC 2 criteria, ISO/IEC 27001Defense contractors, healthcare, payment and SaaS businesses
Operational or process auditAre IT processes such as onboarding, offboarding, change, and patching followed every time?Written procedures, ITIL practices, service agreementsOperations leaders, businesses evaluating an existing IT provider

If the question is specifically about cyber risk, including threat exposure, attack paths, and security posture scoring, our cybersecurity audit and risk assessment is the better starting point. If a customer or contract requires a SOC 2 report, the audit on this page prepares you for it, and the SOC 2 compliance page explains how the readiness work hands off to the CPA firm that issues the report.

The Checklist

The IT Audit Checklist: Ten Domains and What to Examine in Each

This is the working checklist our auditors carry into an engagement. Each item is phrased as a test, and each test names the evidence that answers it. Use it to run a self-audit, to scope a formal one, or to check whether a report you already received actually looked at these things.

1. Governance and Policy

Is there a current, approved information security policy and an acceptable use policy that staff have acknowledged? Is someone accountable for IT risk by name? Is there a risk register, and was it reviewed in the last year? Do written procedures match what the team actually does? Evidence: signed policies with dates, acknowledgment records, the risk register and its review minutes.

2. Asset Inventory

Does a complete inventory exist for hardware, software, cloud services, and data stores, with an owner and a location for each? Do the inventory, the endpoint management console, and the network scan agree? Are unsupported operating systems and applications identified? Evidence: the inventory export reconciled against RMM and discovery scan results.

3. Identity and Access

Is every account tied to a person or a documented service? Is multi-factor authentication enforced for email, remote access, and administrative roles? Are privileged accounts separate from daily-use accounts? Were access rights reviewed in the last quarter, and were leavers removed on their last day? Evidence: directory and tenant exports, MFA registration reports, access review sign-offs, a sample of offboarding tickets.

4. Network and Perimeter

Is the firewall firmware supported and current? Does every inbound rule have a documented business reason and an owner? Are guest, user, server, and management traffic segmented? Is remote access limited to a VPN or zero trust gateway with MFA? Evidence: firewall configuration export, rule review notes, network diagram, external port scan.

5. Endpoints and Servers

Are workstations and servers built from a documented, hardened baseline? Is endpoint detection and response installed and reporting on every device? Is full-disk encryption enabled on laptops? Are local administrator rights removed from standard users? Evidence: baseline documents, EDR console coverage report, encryption status report, local group membership sample.

6. Patching and Vulnerabilities

Are operating system and third-party patches applied within a defined window? Is authenticated vulnerability scanning performed on a schedule, and are critical findings closed within the policy timeline? Are exceptions documented with compensating controls? Evidence: patch compliance reports for the last three months, scan results with remediation dates, the exception register.

7. Backup and Recovery

Are backups taken for every system that matters, including cloud tenants? Is at least one copy offline or immutable? When was a restore last tested, how long did it take, and does that meet the recovery time the business expects? Is there a written disaster recovery plan that names people and steps? Evidence: backup job history, the most recent restore test record, the DR plan.

8. Change Management

Are production changes requested, assessed, approved, and recorded before they happen? Can the team say what changed on a given date? Do emergency changes get reviewed afterward? Evidence: a sample of change records compared against firewall and server change history for the same period.

9. Logging and Monitoring

Are security-relevant logs from identity, email, firewall, endpoints, and servers collected centrally and retained for the period the business or its framework requires? Does someone review alerts, and is there a record that they did? Evidence: log source inventory, retention settings, alert tickets with response times.

10. Vendors and Third Parties

Is there a list of vendors with access to systems or data? Were high-risk vendors reviewed, and do contracts include security and breach notification terms? Are business associate agreements in place where protected health information is shared? Evidence: vendor register, completed questionnaires, contract excerpts, signed BAAs.

Two domains produce the most findings in the environments we review. Asset inventory fails quietly: an inventory that is ninety percent complete feels finished, but the missing ten percent is usually the unmanaged laptop, the forgotten cloud storage account, or the old server under a desk, and those are where incidents start. Our IT asset management page describes how to keep the inventory reconciled continuously. Identity and access fails through accumulation: people change roles, contractors finish projects, and permissions are added but never removed. A quarterly user access review and a disciplined employee offboarding checklist close most of those findings before an auditor sees them.

Free Consultation

Want to Know Which of the Ten Domains Would Produce Findings in Your Environment?

In a short scoping call we will walk the checklist with you, identify the domains most likely to produce findings, and recommend the audit type and criteria that match the question you actually need answered, whether that is an insurer's questionnaire, a CMMC assessment, a HIPAA risk analysis, or a change of IT provider.

The Process

How to Conduct an IT Audit in Eight Steps

These are the steps Petronella Technology Group follows. They are the same whether the audit covers a twenty-person professional services firm or a multi-site manufacturer; what changes is the sample size and the number of systems in scope.

1

Scope: agree the audit type, the systems, sites, and cloud services in scope, the period under review, and the question the report must answer

2

Criteria: select the standard each control will be measured against and write it into the engagement letter

3

Document request: collect policies, diagrams, inventories, prior reports, and vendor contracts before fieldwork begins

4

Fieldwork: interview owners, pull configuration and log evidence from systems, and run discovery and vulnerability scans

5

Testing: check each control for design and for operating effectiveness, using samples across the review period

6

Findings: rate each gap by likelihood and impact, tie it to the evidence, and write a specific recommendation

7

Report and readout: deliver an executive summary, detailed findings, and a ranked remediation plan, then walk leadership through it

8

Remediate and re-test: assign an owner and date to each finding, fix, and verify the fix with fresh evidence

Step 1 is where most audits go wrong. A vague scope such as "review our IT" produces a vague report. A useful scope names the systems (the Microsoft 365 tenant, the two office networks, the ERP server, the three SaaS applications that hold customer data), the period (for operating-effectiveness testing, usually the last three to twelve months), and the decision the report will inform (renewing a cyber insurance policy, preparing for a CMMC Level 2 assessment, deciding whether to keep the current IT provider).

Step 5 is what separates an audit from an assessment. Design testing asks whether the control, as written, would address the risk. Operating effectiveness testing asks whether it ran. A policy requiring quarterly access reviews is well designed; if the auditor asks for the last four quarters of review sign-offs and receives one, the control is not operating. We sample across the review period rather than accepting the most recent example, because the most recent example is often the one prepared for the audit.

Step 8 is the one that justifies the cost. A findings report that sits in a shared drive changes nothing. Our remediation plans rank findings so the first month addresses the risks most likely to cause an outage or a breach, the next quarter addresses the findings an assessor would cite, and the remainder are scheduled into normal operations. Each finding is re-tested with new evidence before it is closed, and the closure evidence is kept for the next audit.

Rating Findings

How IT Audit Findings Are Rated and Prioritized

A report with sixty findings and no ranking is a to-do list nobody finishes. We rate every finding on two axes, likelihood that the gap is exploited or causes a failure, and impact on the business if it does, and we state the rating logic in the report so leadership can challenge it.

Rating What It Means Example Finding Target to Remediate
CriticalLikely to be exploited or to fail soon, with severe business impactNo MFA on email or remote access; backups never restore-tested; internet-facing system with a known exploited vulnerabilityDays, not weeks
HighSignificant gap in a control a framework or insurer requiresShared administrator accounts; no central logging; departed staff still enabledWithin 30 days
MediumControl exists but is inconsistent or undocumentedPatching done but no records kept; firewall rules without owners; incomplete inventoryWithin 90 days
LowImprovement opportunity with limited direct riskOutdated diagram; policy overdue for annual review; naming inconsistenciesNext planning cycle

The targets above are the defaults we propose, not rules; your framework or insurer may set shorter windows for specific findings, and some remediation depends on budget or vendor lead times. What matters is that every finding has a target that someone agreed to, and that the plan distinguishes the three things that must happen this week from the thirty that can wait for the next quarterly review with your virtual CIO.

Regulatory Drivers

Which Frameworks Require a Periodic IT Audit

Few regulations use the phrase "IT audit," but most require an organization to evaluate whether its controls are effective on a recurring basis. An IT audit is the most direct way to produce that evidence.

NIST SP 800-171 and CMMC

Control 3.12.1 (CMMC practice CA.L2-3.12.1) requires periodically assessing security controls to determine whether they are effective, and 3.12.2 requires plans of action to correct deficiencies. An IT audit scoped to the 110 requirements is the natural input to both, and to the SPRS score a defense contractor reports.

HIPAA Security Rule

The evaluation standard at 45 CFR 164.308(a)(8) requires periodic technical and nontechnical evaluation of security safeguards, and the risk analysis at 164.308(a)(1)(ii)(A) must be accurate and thorough. The audit controls standard at 164.312(b) requires mechanisms that record and examine system activity.

SOC 2

A SOC 2 report is issued by a licensed CPA firm. The readiness audit that comes first tests the same Trust Services Criteria, including CC4.1 on monitoring activities and CC8.1 on change management, so the formal examination does not become the first time controls are tested. Between examinations, the same evidence supports the SOC 2 bridge letter customers request.

PCI DSS v4.0

Requirement 11.3 calls for internal and external vulnerability scans at least once every three months, requirement 12.4 assigns executive responsibility for compliance, and the annual scope confirmation in 12.5.2 depends on an accurate inventory of systems that touch cardholder data.

FTC Safeguards Rule

Financial institutions under the FTC's jurisdiction, including many tax preparers, auto dealers, and mortgage brokers, must regularly test or monitor safeguards. Without continuous monitoring, 16 CFR 314.4(d)(2) requires annual penetration testing and vulnerability assessments at least every six months.

ISO/IEC 27001 and NIST CSF 2.0

ISO/IEC 27001:2022 clause 9.2 requires planned internal audits of the information security management system. NIST CSF 2.0 added a Govern function and places control assessment and improvement in its Identify function, which makes a recurring audit the evidence behind a current and target profile.

For regulated clients, we map every audit finding to the specific control it affects inside ComplianceArmor®, our compliance documentation platform, so the remediation plan becomes the plan of action and milestones an assessor expects to see. Craig Petronella lays out the defense contractor side of this in his book CMMC 2.0 Certification Guide, including how self-assessment evidence feeds the SPRS score.

Before and After

What Changes After a Well-Run IT Audit

The value of an audit shows up in how the business answers questions it could not answer before. These are the shifts we see most often once findings are remediated and the controls are running.

Before the Audit

"We think backups are working"

Jobs report success, but nobody has restored a full server, and nobody knows how long it would take.

The insurer's questionnaire takes a week

Answers come from memory, and several are optimistic guesses about MFA coverage and patch timelines.

Access grew with the company

Former staff, old contractors, and shared admin accounts remain, and nobody owns the cleanup.

Policies describe an older business

The security policy predates the move to the cloud and references systems that were retired years ago.

Compliance is a future project

Nobody knows how far the business is from a passing CMMC, HIPAA, or SOC 2 result.

After Remediation

Restores are timed and recorded

A quarterly restore test proves recovery within the time the business agreed, and the record is on file.

Questionnaires are answered from evidence

Coverage reports and policy documents answer the questions, and the answers are defensible if a claim is filed.

Access is reviewed and owned

Every account maps to a person or documented service, privileged access is separate, and reviews are signed quarterly.

Documentation matches reality

Policies, diagrams, and runbooks are current and tied to the controls they support.

Compliance has a measured gap

Findings map to framework controls with owners and dates, so the distance to a passing result is known.

Common Failures

Six Reasons IT Audits Fail to Improve Anything

We are often brought in after a previous audit, and the same patterns explain why the earlier report did not change the environment.

The auditor audited their own work

An IT provider reviewing the environment it built has every incentive to find it sound. Independence does not require a new provider, but it does require that someone other than the builder performs the tests.

Questionnaire in, report out

If the evidence was a spreadsheet the business filled in, the report reflects what the business believes, not what is true. Configuration exports and sampled records are the difference.

No stated criteria

A finding means nothing without the standard it was measured against. "Weak password policy" is an opinion; "does not meet the organization's own policy of 14 characters with MFA" is a finding.

Every finding is urgent

When sixty findings are all marked high, leadership cannot tell which three matter this week, and nothing gets fixed first.

No owner, no date

A recommendation without an accountable person and a target date is a suggestion. The remediation plan has to be agreed, not just delivered.

No re-test

Findings get marked closed because someone said they were fixed. Without fresh evidence, the next audit finds the same gaps and the business pays twice.

How We Work

How Petronella Technology Group Performs IT Audits

Our IT audits are performed by engineers who run production environments every day, supported by the same compliance team that prepares clients for CMMC, HIPAA, and SOC 2 assessments. That combination matters: the findings are ones an operator would recognize, and the remediation steps are ones an operator can actually carry out.

What You Receive

  • A written scope and criteria statement agreed before fieldwork, so the report answers your question
  • Evidence-based testing across all ten checklist domains, or the subset your scope requires
  • Authenticated vulnerability scanning and an external exposure review as inputs to the patching and perimeter domains
  • An executive summary for leadership and a detailed findings register for the technical team
  • Findings rated by likelihood and impact, each mapped to CMMC, HIPAA, SOC 2, PCI DSS, or ISO 27001 controls where relevant
  • A ranked remediation plan with owners and target dates, and a re-test of closed findings
  • Optional remediation by our team, or support for your internal staff or current provider as they fix

Why Clients Choose Us

  • Craig Petronella, founder and CEO, is a CMMC Registered Practitioner, holds a CCNA, is an NC Licensed Digital Forensics Examiner (License 604180-DFE), and is MIT-certified in cybersecurity. Forensic investigations are where audit gaps become concrete: missing logs and unowned accounts are exactly what make an incident impossible to reconstruct.
  • Craig's book IT Buyers Guide sets out sixteen questions to ask before signing an IT contract, and his book How Hackers Can Crush Your Business describes how attackers exploit the same small-business gaps this checklist is built to find.
  • "Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals." (Daniel Lee, verified TrustIndex review)
  • Rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews
  • Founded 2002, BBB A+ since 2003, CyberAB Registered Provider Organization #1449
  • We are not a CPA firm and do not issue SOC 1 or SOC 2 attestation reports; we say so up front and prepare you for the firm that does

Many audits start because a business is deciding whether its current IT arrangement is working. If the answer is to change, the audit becomes the transition plan: the IT documentation it produces is the handover package, the change and patch findings shape how the new provider operates, and the IT change management and patch management disciplines described on those pages are what keep the environment from drifting back. For businesses in the Triangle that want us to run the environment after the audit, the managed IT services Raleigh page describes that service; for businesses with internal IT staff, co-managed IT keeps your team in charge while we supply the process and tooling.

Comparison

Self-Audit vs. Provider Self-Review vs. an Independent IT Audit

All three have a place. A self-audit with the checklist above is a good first step; the table shows what each option can and cannot tell you.

Question Internal Self-Audit Current Provider Reviews Itself Independent IT Audit (Petronella Technology Group)
Is it independent?NoNo, the reviewer built the environmentYes, testers did not build or operate what they test
Is evidence pulled from systems?Sometimes, depending on staff skillsUsually, but selectivelyYes, with samples across the review period
Are findings mapped to a framework?RarelyRarelyYes, to CMMC, HIPAA, SOC 2, PCI DSS, or ISO 27001 controls
Will an insurer or assessor credit it?LimitedLimitedAs supporting evidence of periodic control assessment
Is there a ranked remediation plan?Often a listOften a quoteYes, with owners, dates, and a re-test
Best useEarly awareness and preparationRoutine operational checksDecisions, assessments, insurance, and provider changes
Next Step

Get an IT Audit Scoped to the Decision You Are Making

Tell us what prompted the question: an insurance renewal, an assessment date, a new IT leader, or doubts about your current provider. We will recommend the audit type, criteria, and scope that answer it, and explain what the report and remediation plan will contain before you commit.

FAQ

IT Audit: Frequently Asked Questions

What is an IT audit?

An IT audit is an independent examination of a business's technology environment, including infrastructure, access controls, backups, change and patch processes, logging, vendors, and policies, measured against defined criteria. The auditor collects evidence from systems, tests whether controls are designed correctly and operating as designed, and reports findings ranked by risk with a recommended fix for each.

What does an IT audit checklist include?

A complete IT audit checklist covers ten domains: governance and policy, asset inventory, identity and access, network and perimeter, endpoints and servers, patching and vulnerabilities, backup and recovery, change management, logging and monitoring, and vendors and third parties. Each item should be written as a test and name the evidence that answers it, such as an access review sign-off or a restore test record.

How is an IT audit different from a cybersecurity audit or a penetration test?

An IT audit reviews how the whole environment is configured, operated, and governed. A cybersecurity audit focuses on security posture and threat exposure. A penetration test actively tries to break in to show what an attacker could reach. They complement each other: the audit finds process and control gaps, and the penetration test proves whether those gaps can be exploited.

How often should a business have an IT audit?

At least annually, and whenever something significant changes: a new IT provider, a merger or new site, a move to the cloud, a new compliance obligation, or a security incident. Regulated businesses often need more frequent testing of specific controls; for example, PCI DSS requires quarterly vulnerability scans and the FTC Safeguards Rule requires vulnerability assessments every six months without continuous monitoring.

How long does an IT audit take?

It depends on scope. A focused audit of a single-site business with a cloud email tenant and a handful of servers can move from scoping to readout in a few weeks, most of which is document collection and evidence gathering. Multi-site environments, operating effectiveness testing across a long review period, and framework mapping add time. We give a schedule in the scope statement before work starts.

Can Petronella Technology Group issue a SOC 2 report?

No. SOC 2 reports are attestation engagements that only a licensed CPA firm can perform under AICPA standards. We perform SOC 2 readiness audits against the Trust Services Criteria, remediate the gaps, and prepare the evidence so the CPA firm's examination goes smoothly. We are clear about this distinction at the start of every engagement.

What should we prepare before an IT audit?

Gather your current policies, a network diagram, any asset inventory, a list of cloud services and vendors with access to your systems, prior audit or assessment reports, and contact details for the people who own each system. Administrative read access to the systems in scope will be needed during fieldwork. Do not tidy up beforehand; an audit of the real environment is the one that helps.

Does Petronella Technology Group fix the findings too?

Yes, if you want us to. Remediation can be delivered by our engineers, by your internal IT staff with our guidance, or by your current provider with our re-testing. For clients who choose managed or co-managed IT afterward, audit findings become the first items in the operating plan, and compliance findings are tracked to closure in ComplianceArmor®. Call 919-348-4912 or schedule a free consultation to discuss your environment.

Related Services

Related Managed IT and Compliance Pages

Last Updated: September 12, 2026 (first published September 12, 2026). This page references NIST SP 800-171 Rev. 2 controls 3.12.1 and 3.12.2, CMMC 2.0 Level 2 practice CA.L2-3.12.1, the HIPAA Security Rule at 45 CFR 164.308(a)(1)(ii)(A), 164.308(a)(8), and 164.312(b), SOC 2 Trust Services Criteria CC4.1 and CC8.1, PCI DSS v4.0 requirements 11.3, 12.4, and 12.5.2, the FTC Safeguards Rule at 16 CFR 314.4(d), ISO/IEC 27001:2022 clause 9.2, and NIST CSF 2.0. Confirm current requirement text with the issuing body before relying on it for an assessment.

Find the Gaps Before an Auditor, Insurer, or Attacker Does

Petronella Technology Group has audited and managed IT environments for regulated businesses since 2002, holds a BBB A+ rating dating to 2003, and is a CyberAB Registered Provider Organization. Tell us what decision the audit needs to support, and we will scope an IT audit that answers it.