Pumpkin
    How to Audit Your Firm's Technology
    Technology

    How to Audit Your Firm's Technology

    By Aaron WatersFebruary 11, 2025Updated August 15, 20267 min read

    A firm technology audit is a complete inventory of every machine, application, and subscription you run, held up against five questions: whether it's current, secure, still necessary, worth what it costs, and compliant with the rules you practice under. That's the entire method. If you haven't run one in the past twelve months, you're overdue, because technology almost never announces its failures. It degrades in silence, one skipped patch and one forgotten license at a time, until the day it gets loud all at once.

    The nephew problem

    Anyone who runs these audits for a living has met the nephew. The details move around, the shape never does. A small firm, somewhere between six and twenty people, has an IT guy who is a partner's nephew, or a neighbor's kid, or the office manager's husband who's good with computers. He set up the wifi years ago. He comes by when the printer acts up. He's cheap, he's pleasant, and nobody has ever asked him about patch management, because nobody at the firm knows the phrase.

    Eventually something forces a real audit. An insurance renewal, a compliance questionnaire, a scare at the firm down the street. The auditor plugs in, starts scanning, and finds what these audits find, except this time it's fourteen machines that haven't seen a security patch in two years. Two years of publicly documented holes, sitting on the same network as every client's tax return. Not because anyone was negligent in a way they could feel. The nephew fixed what was broken. Nobody owned what wasn't broken yet, and that's a different job entirely.

    That's the real argument for auditing. Firms don't drift into risk through carelessness. They drift through unowned maintenance. A basic IT checklist for a growing firm would have surfaced the problem in month one, but a checklist needs an owner, and my nephew helps out is how a firm says it doesn't have one.

    What the audit actually covers

    Hardware first. How old are the computers, and are they running supported operating systems with room to breathe? Is the network gear, the router and firewall and access points, still receiving firmware updates from its manufacturer, or did support end quietly three years ago? Are laptops and phones managed devices, or mystery hardware that happens to hold client data?

    Software and cloud services next. Every application should be a supported, current version. Windows 10 stopped receiving security patches in October 2025, so a machine still running it today is a finding, full stop. Count the licenses too, and who they're assigned to, and then count the SaaS subscriptions with the same honesty. Unused seats are the most common audit finding there is.

    Then security posture, which deserves the most time. Who holds admin rights, and did that access accumulate over years without anyone reviewing it? Is MFA on everything, or on email while the practice management system sits behind a password from 2021? Are backups running, and here's the question that matters more: has anyone ever tested a restore? A backup you've never restored is a hope, not a backup. And is there an actual patching cadence, or do updates happen when someone notices the popup?

    Compliance last. Tax practices answer to IRS Publication 4557. Law firms answer to state bar rules. Nearly everyone has a data retention policy that says one thing while the archive does another, and keeping client data longer than your policy allows is a finding too, not a convenience.

    How to run one

    Start with the inventory, because you can't audit what you don't know you own. Shadow IT and forgotten subscriptions surface at this stage, and if you've already built a vendor inventory, you're halfway done before you start.

    Score each item against the five questions. Current, secure, necessary, cost-effective, compliant. Be literal about it. A spreadsheet with five columns beats a consultant's glossy deck you'll never reopen.

    Rank what you find. Critical findings, meaning active security exposure or a compliance violation, get fixed within days. High within a month. Medium within a quarter. Low goes on the roadmap without guilt. Not everything is urgent, and pretending it all is guarantees nothing gets finished.

    Then turn findings into a plan where every line has an owner and a date. A finding without an owner is a sticky note. And before you close this audit, book the next one. Annual is the floor. Firms holding especially sensitive data should look every six months, because the gap between audits is exactly how long a problem gets to grow unobserved.

    What these audits keep finding

    The same list, firm after firm. Hardware kept years past its useful life, saving hundreds in replacement cost while burning thousands in productivity. Security applied inconsistently, strong on email and absent everywhere else, which means strong nowhere, since attackers get to choose the door. Backups that run nightly and have never once been test-restored. License seats still assigned to people who left, which quietly tells you the offboarding process has holes in it too. And documentation that lives entirely in one person's head, which works right up until that person gives notice in the first week of March.

    One more finding hides in plain sight: a team quietly fighting its own tools every day. If the audit reveals machines and systems that make work harder, treat that as a real cost, and go after the friction with the same seriousness as the security gaps. It's usually the finding with the fastest payback.

    When to run it

    Timing matters more than firms expect. An audit delivered in mid-February helps nobody. The findings land on people with zero capacity to act, the remediation waits until May regardless, and everyone learns that audits are a thing you survive rather than use. Run it in the off-season, when the calendar has slack and a critical finding can be fixed the same week it's found.

    The off-season audit has a second advantage: whatever you fix in June gets a full shakedown before it matters. The new backup routine, the patched machines, the wider MFA rollout, all of it proven under light load before the season arrives to test it under heavy load. Firms that audit in the autumn walk into filing season knowing where they stand. Firms that skip it find out where they stand in real time, in front of clients.

    Who should hold the clipboard

    If you have internal IT, they can run the inventory and much of the assessment. But there's real value in outside eyes, because familiarity hides things. The person who built the network has reasons for every oddity in it, and reasons feel like explanations right up until they're vulnerabilities. An outsider also says the uncomfortable things an insider softens, which is a large part of what you're paying for. Plenty of firms land on a hybrid: internal staff keep the inventory current, an external reviewer checks security and compliance once a year. If you want that outside set of eyes, we're happy to be them.

    An audit isn't a hunt for someone to blame. It's how a firm finds out where its risk and waste actually live while both are still cheap to fix, and it's the natural first step of running a tighter operation generally, which is the territory our firm operations guide covers end to end. The firms that audit on a schedule rarely have technology emergencies. The firms that don't are the ones making a panicked phone call in the second week of March. Pick which one you'd rather be.