How to run a physical audit of your IT kit

A step-by-step method for checking that the register matches the shelves, with a phone rather than a printout, and a trail you can show an auditor.

Every register drifts. Kit moves between desks, leaves with people and gets swapped under warranty, and not every move is recorded. A physical audit is how you find the drift and fix it, and the record of the audit is what an insurer, a finance team or a certification assessor asks for. Done with a printout it is an afternoon of ticking and an evening of typing. Done with labels and a phone it is a walk.

1. Decide the scope

Pick a unit you can finish in one session: a room, a floor, a site, or a single category such as laptops. A complete audit of a small area is worth more than a half-finished audit of everything. If your locations are arranged as a tree (site, floor, room), choose a branch and work down it.

2. Check the labels before you start

An audit runs on labels. Print QR label sheets for any assets that lack one, and a label for the room itself. In Tagaris the QR labels page takes a selection of assets or locations and produces a printable sheet, and each code opens that record. Set an audit interval on the categories you are about to check, so the register knows what is due. See QR labels and scanning.

3. Walk it with a phone

There are two ways, both on the free tier.

  • The iOS app. Open audit mode and scan each label. The app records an audit on that asset and tells you if a label belongs to a different server or is not found. See the iOS app.
  • A browser. The stock-take page lists every asset due for audit with its last audited date. Scan a label with the phone camera to open the asset and mark it audited, or search a tag, name or serial on the stock-take page and tap Audited.

Scanning the room's own label opens the location page, which lists everything the register expects to find there, grouped by category. That is your checklist for the room.

4. Record what is found, and what is not

Each confirmation updates the asset's last audited date and writes an audited entry to its history, with who did it and when. That is the found list, and it records itself as you go. Whatever is still on the stock-take list for that area after the walk is your exceptions list: assets the register expected and you did not find. Note anything you found that the register did not expect as well: a device with no label, or a label that scans as not found.

5. Resolve the differences

  • Moved. The device is somewhere else. Change its location from the phone when you find it, or select the strays on the assets list and bulk-move them to the right room in one action.
  • Missing. Nobody can find it. Change its status so it stops showing as in use. A custom status label such as "Missing", built on one of the base statuses, keeps it visible until it turns up or is written off. If it is written off, dispose it with the date and method, and it leaves the default lists with a trail.
  • Unlabelled. The device exists but has no label. Look it up by serial, print a label, and audit it on the spot. If the serial is unknown to the register, the app can create the asset from the scan.

6. Keep the trail

The history on each asset and its last audited date are the evidence. For a summary, export the assets list to CSV after the walk and file it with the date. On Team plans the organisation-wide audit log adds who changed what across the register. The working with assets guide in the documentation covers the audit and stock-take mechanics.

7. Set a cadence

Set an audit interval per category. The assets list then shows an "Audit due" badge on anything past its interval or never audited, and the stock-take page lists them, so the next walk plans itself. The first audit finds the most surprises; the second is quick.

Related guides: all guides, an asset register for Cyber Essentials and ISO 27001 and how to create an IT asset register.

Common questions

Do I need the iOS app to run an audit?

No. Any phone camera opens an asset from its QR label in the browser, and the stock-take page lists what is due with an Audited button on each asset. The app adds an audit mode that records each scan as you go, and it works on the free tier. Android is in development.

How often should we audit?

Set an audit interval per category and let the register list what is due. Kit that moves (laptops, phones, loan equipment) needs checking more often than kit that is racked or bolted down. A rolling schedule, one area at a time, is easier to keep up than an annual sweep of everything.

Try an audit on demo data

The live demo runs the current release with a realistic dataset and a stock-take page ready to work through. No sign-up, and it resets nightly.