An IT asset audit does not have to be a quarter-long project. Five days produces a register you can defend, provided you reconcile against three sources rather than trying to physically verify everything.

TL;DR

  • Aim for a usable register rather than a perfect one. Perfection is what turns a week into a quarter and then into nothing.
  • Three reconciliation sources do most of the work: your management console, your purchase records and your leaver list.
  • None of the three is complete on its own. The gaps between them are the findings.
  • Physical verification is for the exceptions the reconciliation cannot resolve, not for the whole fleet.
  • Record which source found each discrepancy, because that tells you which process is leaking.
  • Finish with a short unaccounted list owned by somebody, rather than leaving the audit formally open.

Why audits usually fail

Because they are scoped as a physical inventory. Somebody decides to lay eyes on every machine, which for a distributed fleet means contacting several hundred people individually, and the exercise dies somewhere around the fortieth non-reply.

The alternative is reconciliation. Compare your register against systems that already know things, resolve the differences, and physically chase only what remains. For most fleets that reduces the human effort by an order of magnitude and produces a better result, because the automated sources do not get bored.

An audit that finishes at 95 per cent in a week beats one that is still at 60 per cent after three months.

The three sources

Management consoleDevices checked in recentlyFinds machines you own and never recorded. Blind to anything switched off or in storage
Purchase recordsEverything bought in the periodFinds the procurement handoff failing, which is the most common cause of missing rows
Leaver listEverybody who left, joined to assignmentsFinds devices that should have come back. The most uncomfortable output and the most actionable

Run all three and the overlaps resolve most rows automatically. A device in the register, checked in last week, assigned to somebody still employed needs no further attention, and that will be the large majority.

The five days

Day one, export everything. The register, the management console check-ins for the last ninety days, hardware purchases for the period you are auditing, and the leaver list. Four files, all obtainable without anybody’s permission.

Day two, match on serial. Join the files and sort into buckets: matched and consistent, in the register but not seen, seen but not in the register, purchased but never registered, assigned to a leaver. Most rows fall into the first bucket.

Day three, resolve the easy buckets. Seen but not registered is a data entry job. Purchased but never registered is the same, with a note about where the handoff failed. Both can be closed without contacting anybody.

Day four, chase the people. Devices assigned to leavers, and devices in the register that have not checked in for ninety days. One message each, asking for the serial from the underside of the machine rather than a yes or no.

Day five, close out. Update the register, write the accuracy figure down, and produce the unaccounted list with an owner and a review date.

A worked example

A company with 480 register rows ran this. Day two produced 412 matched and consistent, which needed nothing further.

Of the remaining 68: nineteen were devices seen on the network and absent from the register, all bought during a six-month period when one person had been covering procurement. Twenty-three were in the register and unseen for ninety days, of which most turned out to be in storage. Fourteen were assigned to people who had left. The last twelve were genuinely unclear.

The nineteen were the most useful finding, because they pointed at a specific broken handoff rather than at a general accuracy problem, and fixing it stopped the register degrading further.

Running it

What to do:

  • Match on serial number, never on asset tag or model, since the serial is the only identifier that survives a reimage.
  • Record which source surfaced each discrepancy, so the output names a process rather than a count.
  • Ask people for the serial rather than confirmation, because a yes confirms they have a laptop and not which one.
  • Expect roughly a fifth not to reply, and treat non-response as a finding rather than a failure.
  • Do not physically verify anything the three sources already agree on.
  • Close with a dated unaccounted list owned by a named person, reviewed monthly until empty.

The last point is what separates an audit that improves things from one that produces a document. An audit left formally open becomes an archive, and the devices on it are quietly written off two years later by nobody in particular.

What the tooling contributes

The audit itself needs a spreadsheet and four exports. Where tooling helps is in not having to repeat it from scratch next year.

Snipe-IT holds purchase dates, costs, assignment and custom fields, and its self-hosted edition is free and open source, with hosted tiers published at $39.99 monthly or $399.99 annually for Basic.

AssetTiger is the hosted option, priced by asset count at $20 a month for 500 assets and $40 for 2,500, reducing to $18 and $37 annually, with unlimited users. Its 250-asset tier is a 30-day trial rather than a permanent free plan.

Disclosure: RemoAsset is owned by the same people who publish PeopleOpsHQ. Relevant to audits because the record is created at despatch rather than typed later, which removes the handoff that produced nineteen of the discrepancies above. It publishes no price and requires a demo, it is weaker for hardware it did not supply, and it is not a certified disposal vendor. Retrieval options sit in our laptop retrieval comparison.

Final thoughts

The reason asset audits have a bad reputation is that they get scoped as physical inventories, which for a distributed fleet is a task nobody can finish. Reconciliation against three systems you already have gets you most of the way in a few days, and leaves a short list of genuinely unclear devices rather than an abandoned spreadsheet.

Record which source found each problem, fix the process it points at, and close with an owned unaccounted list. Then repeat it as a twenty-row quarterly sample rather than a five-day exercise, which is the version that actually keeps happening.

Frequently asked questions

How long should an IT asset audit take?

About five days for a fleet of a few hundred devices, if you scope it as a reconciliation rather than a physical inventory. Exporting four files and matching them on serial resolves the large majority of rows automatically, leaving a short list that needs human contact. Audits that run for months are almost always ones that set out to lay eyes on every machine, which is not achievable when the machines are in people’s homes across several countries.

What should we reconcile the register against?

Three sources, none of which is complete on its own. Your management console, where anything checked in but unregistered is a device you own and never recorded. Your purchase records, where anything bought and never registered shows the procurement handoff failing. And your leaver list joined to assignments, which produces the devices that should have come back. The gaps between the three are the findings, which is why all three are needed.

Should we match on serial number or asset tag?

Serial number, always. It is the only identifier that survives a reimage, a rename or a change of asset tagging scheme, and it is the one your management console and your supplier both know. Asset tags are useful internally and they fall off, get reused and differ between the systems that hold them, so matching on them produces false mismatches that waste the time you saved by reconciling rather than inventorying.

How should we ask people to confirm they have a device?

Ask for the serial number from the underside of the machine rather than asking whether they have it. A yes confirms the person holds a laptop and not that they hold the laptop in your record, which is precisely the ambiguity an audit exists to remove. Expect around a fifth not to reply at all, and treat the non-responders as a finding in their own right, since they correlate strongly with the devices that later turn out to be missing.

What do we do with devices we cannot account for?

Put them on a dated unaccounted list with a named owner and a monthly review, rather than leaving the audit formally open or quietly adjusting the register to match. An open audit becomes an archive and the devices on it get written off two years later by nobody in particular, which loses both the hardware and the chance to learn which process lost it. Work the list down until it is empty or everything remaining has been deliberately written off.

How often should this be repeated?

The full five-day reconciliation once a year is plenty, with a twenty-row random sample each quarter in between. The sample is the part that actually keeps happening, because it takes twenty minutes and produces a percentage you can track, while a five-day exercise competes with everything else for a week of somebody’s time. Record which handoff each quarterly failure came from, and the annual audit mostly confirms what the samples already told you.