Skip to content
AMPthilly home
Get started
IT Asset Management

The Ultimate IT Asset Inventory Checklist for Growing Teams (2026)

A step-by-step IT asset inventory checklist for growing teams. Covers hardware inventory template fields, how to audit company laptops, remote employees, and audit frequency.

Mathias Olsson Updated 14 min read
~30%
of IT assets are unaccounted for in organisations without a structured audit
Quarterly
audit cadence is the sweet spot for teams between 25 and 500 employees
9 steps
to a repeatable, audit-ready IT asset inventory process

Everything you need to run a real IT asset inventory audit - what to include, what fields to track, the 9-step process, and how to verify laptops for remote employees. Built as a complete IT asset inventory checklist you can copy, print, and put to work today.

What’s in this checklist

  1. Why growing teams lose control of IT assets
  2. What goes in an IT asset inventory (categories)
  3. The hardware inventory template - required fields
  4. The 9-step IT asset audit checklist
  5. How to audit company laptops (incl. remote employees)
  6. Audit frequency: monthly, quarterly, or annual?
  7. 7 common pitfalls (and how to avoid them)
  8. Tools that make this 10× easier
  9. FAQ

Why growing teams lose control of IT assets

There is a point - usually somewhere between 30 and 100 employees - where IT asset management quietly stops working. Up until then, you know every laptop by name. Past that, things get fuzzy. A device is “with someone in the Berlin office.” A monitor is “probably in storage.” Two people are pretty sure they returned the same docking station. A laptop appears on a procurement report but nowhere in your asset register.

None of this looks dangerous on its own. Then a security audit, an insurance claim, an offboarding gone wrong, or a SOC 2 review forces you to produce a definitive list - and the gap between what you think you own and what you can prove you own turns into a budget hit.

The fix isn’t more spreadsheets or panic. It’s a repeatable IT asset inventory checklist that runs on a schedule, captures the right fields, reconciles physical, MDM, and identity data, and produces a clean record at the end. That’s exactly what this guide is.

What goes in an IT asset inventory (categories)

Before you build the template, decide what counts as an IT asset. The right answer for most growing teams is: anything with a serial number that costs more than a coffee, plus anything that touches company data.

End-user hardware

  • Laptops (company-issued and loaner pool)
  • Desktops and workstations
  • Monitors and external displays
  • Smartphones and tablets (company-owned)
  • Docking stations and port replicators
  • Keyboards, mice, webcams, headsets (above a value threshold)
  • Printers and scanners
  • Security keys (YubiKey, Titan) and hardware tokens

Networking and infrastructure

  • Routers, switches, access points
  • Firewalls and VPN appliances
  • On-premise servers (if any)
  • NAS and external storage devices
  • UPS and battery backups

Specialised and shared equipment

  • Conference room hardware (cameras, speakers, displays)
  • Loaner devices and spares
  • Test devices (for QA, support, dev)
  • Field hardware (POS terminals, mobile printers, etc.)

Tip: If you also track software licenses, SaaS subscriptions, and cloud resources, keep them in the same system as your hardware. Splitting them across separate tools is one of the most common reasons audits drift out of sync.

The hardware inventory template - required fields

Every device in your asset register should have these fields populated. This is the minimum useful hardware inventory template - anything less and your audit will leave gaps.

FieldWhat it isRequired?
Asset IDUnique internal ID (e.g. LAP-0142). Printed on the asset tag.Yes
Asset tag / barcodeThe physical QR or barcode label stuck on the device.Yes
CategoryLaptop, monitor, phone, peripheral, etc.Yes
Make & modele.g. MacBook Pro 14” M3, Dell Latitude 7440.Yes
Serial numberManufacturer serial. Source of truth when asset tags fall off.Yes
StatusIn use, in stock, in repair, retired, lost.Yes
Assigned toPerson currently holding the device.Yes
LocationOffice, home address (or country, for privacy), warehouse.Yes
Purchase dateUsed for warranty and depreciation calculations.Yes
Purchase costAsset value for insurance and finance.Yes
Supplier / vendorWho you bought it from. Useful for warranty claims.Recommended
Warranty expiryThe date support coverage ends.Recommended
MDM enrollmentIntune / Jamf / Kandji / Workspace ID for the device.For laptops/phones
Encryption statusBitLocker / FileVault enabled? Required for compliance.For laptops
Last seenLast MDM or identity provider check-in timestamp.For laptops/phones
Notes / historyFree-text log of repairs, reassignments, incidents.Optional

The fields marked “For laptops” are the ones that turn a basic asset list into a real ITAM record. Without MDM enrollment status and encryption confirmation, you cannot answer “is this laptop secure?” - which is the single question every SOC 2, ISO 27001, or HIPAA auditor will ask.

The 9-step IT asset audit checklist

This is the heart of the guide. Run these nine steps every quarter and your asset register will stay clean. Skip them and it will drift, no matter how good your tool is.

1. Define scope and goal

Decide before you start: which categories, which sites, which people. A focused 100-laptop audit beats a sprawling “audit everything” project that never finishes. Write a one-line goal - e.g. “Verify all 247 company laptops are accounted for and MDM-enrolled by end of Q2.”

  • Categories in scope listed
  • Sites / regions in scope listed
  • One-line goal written and shared with stakeholders
  • Audit owner assigned (single person)
  • Target completion date set

2. Pull your current asset register

Export everything you currently have - from your ITAM tool, your spreadsheet, your procurement records, whatever counts as “the list” today. This is your baseline. Do not clean it yet. Audits verify reality against the baseline; if you clean the baseline first, you lose the ability to measure your error rate.

  • Asset register exported (CSV or in-tool snapshot)
  • Baseline count recorded by category
  • Snapshot dated and stored read-only

3. Cross-reference your discovery data

Pull device lists from every system that already knows about your hardware. Each of these is a source of truth for something, and reconciling them is how you catch ghost assets and untracked devices.

  • MDM export (Microsoft Intune, Jamf, Kandji, Mosyle, etc.)
  • Identity provider export (Entra ID / Azure AD, Okta, Google Workspace)
  • Procurement / finance records for the last 24 months
  • HRIS active employee list (so you know who should have a device)
  • Last 12 months of helpdesk tickets mentioning new or replaced hardware

Watch for: devices in MDM but not in your asset register (untracked hardware), devices in your register but not in MDM (possible lost or never-enrolled), and active employees with no assigned device (procurement gap or an off-the-books loaner).

4. Physically verify on-site assets

For everything in the office: walk the floor with a phone or barcode scanner and scan every asset tag. Confirm condition, location, and current assignee. Photo evidence is your friend when something is later disputed.

  • Every desk and workstation scanned
  • Conference rooms and shared spaces checked
  • Storage / IT closet inventory scanned
  • Loaner pool reconciled (count vs register)
  • Damaged or end-of-life items photographed

5. Verify remote employee laptops

Remote devices are where audits leak. Use a three-signal verification - no single signal is enough on its own.

  • MDM last check-in is within the last 14 days
  • Identity provider shows a recent sign-in
  • Employee returns a short confirmation form (photo of serial label + condition note)
  • Encryption status verified via MDM (BitLocker / FileVault on)
  • Devices failing any signal flagged for follow-up before audit close

6. Flag discrepancies (don’t delete)

Every mismatch gets a status, not a delete. “Missing” and “unconfirmed” are real audit states - they tell you what needs investigation. Quietly erasing the row destroys the evidence you need to fix the underlying process.

  • Physical present, not in register → tag and add
  • In register, not found physically → status = “unconfirmed”, investigate
  • In MDM, not in register → add and assign
  • In register, not in MDM → check enrollment; if missing, that’s a security finding
  • Wrong assignee → update with date and source

7. Reconcile and update

Now you fix the register. Every change carries a timestamp, a source, and a person. This is the audit trail that turns next quarter’s audit from a panic project into a 30-minute confirmation.

  • All confirmed devices updated with verified data
  • Missing devices investigated (helpdesk tickets, employee follow-up, return tracking)
  • Lost/written-off assets formally retired with reason recorded
  • Warranty expirations flagged for renewal or replacement planning
  • End-of-life devices queued for secure disposal

8. Report and act

Produce a one-page audit report with the numbers your CFO and CISO actually want. Don’t bury the headline in 30 tabs.

  • Total assets in scope, total verified, total flagged
  • Discrepancy rate as a percentage
  • Lost / written-off count and total value
  • Devices out of MDM compliance
  • Devices past warranty / approaching end-of-life
  • Top 3 action items for the next quarter

9. Schedule the next audit

Audits that aren’t on the calendar don’t happen. Book the next one before you close this one.

  • Next audit date scheduled (calendar invite sent)
  • Owner confirmed for next cycle
  • Process improvements from this audit documented
  • Asset register snapshot archived for compliance evidence

Save this section. Copy the nine steps into your team’s wiki or print this page. Run through it as a literal checklist - that’s the whole point of having one.

How to audit company laptops (incl. remote employees)

Laptops are the highest-risk, highest-volume, most-mobile category in any IT asset inventory - they deserve their own playbook. Here is how to audit company laptops specifically, without bringing every remote worker into the office.

The three-signal verification

No single data source is enough to confirm a laptop is accounted for. Use three, and require at least two to match:

  1. MDM signal: Last check-in within 14 days, encryption on, OS patched, compliance policy passing.
  2. Identity signal: The assigned user signed in to email, chat, or SSO within the last 14 days from that device.
  3. Human signal: The employee responds to a short form (one minute) confirming they have the device, with a photo of the serial label and any visible damage.

If all three match → laptop confirmed. If two match → confirmed with note. If only one (or none) match → flag for follow-up before closing the audit.

Special cases

Laptops on extended leave

Devices assigned to people on parental leave, sabbatical, or long-term medical leave often go silent in MDM. Move them to a “held” status, set a calendar reminder for their expected return date, and document the reason - don’t flag them as missing.

Departing employees

Offboarding is where most “lost” laptops actually originate. Tie the audit to your offboarding checklist:

  • Return ship-kit sent within 24 hours of termination notice (with tracking)
  • Device wiped remotely once received OR remote-wipe scheduled if not
  • Asset register status changed to “in-transit” then “returned” then “redeployed/retired”
  • Final paycheck hold (where legally permitted) for non-returns

BYOD and personal devices

If you allow BYOD, audit the access, not the device. Use MDM or MAM policies, conditional access, and a documented BYOD agreement. The device is not your asset, but the data on it is your problem.

Audit frequency: monthly, quarterly, or annual?

The “right” cadence depends on your size, your risk profile, and your compliance obligations. Here’s the practical guide:

Team sizeFull auditSpot checks
Under 25 employeesTwice a yearMonthly: high-value items, loaners
25–100 employeesQuarterlyMonthly: laptops, phones, security keys
100–500 employeesQuarterly (rolling, by region)Continuous via MDM monitoring + monthly reconciliation
500+ employeesContinuous (rolling audits, never “done”)Automated, alerting-driven

If you’re operating under SOC 2, ISO 27001, HIPAA, or GDPR, the regulator doesn’t dictate a frequency - they expect a documented, repeatable process that you actually follow. Quarterly is the answer that survives every audit.

7 common pitfalls (and how to avoid them)

  1. Auditing without a goal. “We’re doing an audit” is not a goal. “Verify all 247 laptops by June 30” is. Without a target, the audit drifts and never closes.
  2. Cleaning the register before measuring. If you tidy up first, you lose the error rate - and the error rate is the metric that tells you whether your process is improving.
  3. Skipping the human-signal step for remote workers. MDM tells you the device is online; it does not tell you who has it. Ask the human.
  4. Treating “missing” as “delete.” A missing asset is a finding, not a janitorial task. Keep the row, change the status, log the follow-up.
  5. No single owner. Audits with three co-owners have zero owners. One person runs it; others contribute.
  6. Doing it in a spreadsheet at scale. Past ~100 devices, the reconciliation step alone takes longer than the rest of the audit combined. (More on this in Why Excel Fails for Asset Tracking.)
  7. Not scheduling the next audit. If the next audit isn’t on a calendar before you close this one, it won’t happen. Watch.

Tools that make this 10× easier

You can run this checklist with a spreadsheet, a clipboard, and a lot of patience. You can also run it with a dedicated asset tracking platform that holds a single source of truth, captures every check-in/check-out, and produces audit-ready reports on demand.

The categories of tools you’ll want in the stack:

  • ITAM / asset tracking platform - a single source of truth for your asset register, with mobile scanning, check-in/check-out, and audit trail. AMPthilly is built for exactly this workflow.
  • MDM / device management - Microsoft Intune, Jamf, Kandji, Mosyle, or Google Workspace device management.
  • Identity provider - Microsoft Entra ID, Okta, or Google Workspace.
  • HRIS integration - so the asset register knows when an employee starts and leaves.
  • Asset tags & mobile scanner - printed QR or barcode tags on every device, scannable from a phone.

Want this checklist as a working asset register, not a static doc?

AMP turns your asset register into a single, scannable, mobile-friendly system - with a real audit trail, check-in/check-out, and reporting built in, so reconciliation happens in the platform instead of on a clipboard.

See how AMPthilly works →

FAQ

How often should you audit IT assets?

Quarterly full audits with monthly spot checks on high-risk categories (laptops, phones, security keys) is the right cadence for most growing teams. Twice-yearly works under 25 employees; continuous rolling audits become necessary past 500.

What should be included in an IT asset inventory checklist?

Categories (end-user hardware, networking, specialised equipment), required fields per asset (Asset ID, serial, model, assignee, location, status, purchase date, warranty, MDM enrollment, encryption status, last-seen), verification steps (physical scan, MDM cross-reference, identity-provider cross-reference, employee confirmation), and a documented reconciliation + reporting process.

How do you audit company laptops for remote employees?

Use three signals: (1) MDM check-in and compliance status within the last 14 days, (2) identity-provider sign-in from the device within the last 14 days, and (3) a short employee confirmation form with a photo of the serial label. Require at least two to match; flag everything else for follow-up.

What is the difference between an IT asset audit and an IT audit?

An IT asset audit verifies that the hardware and software you think you own actually exists, is where you think it is, and is recorded correctly. An IT audit is a broader review of your IT controls and security posture. The asset audit is a subset of the IT audit - and a clean one is almost always a prerequisite for passing the broader review.

Can you do an IT asset audit in a spreadsheet?

For very small teams (under ~50 devices, no remote workers, no compliance obligations), yes. Past that, the reconciliation step becomes the bottleneck - version conflicts, no audit trail, no MDM integration, no real-time updates. A dedicated tool pays back its cost within the first or second audit cycle.

What’s the cheapest way to start?

Start with the field template in this article, populate it from your existing data sources (MDM, identity provider, procurement), and import it into a tool with a usable free tier - like AMPthilly, AssetTiger, or self-hosted Snipe-IT. The cost is mostly your time, and the saving is one prevented lost laptop.

Do we need asset tags on every device?

Yes - for anything that moves. The asset tag is what makes audits fast: a 5-second scan beats a 30-second serial-number type-in, every time. Without tags, audits take 6× longer and accuracy drops sharply.

The takeaway

A great IT asset inventory checklist is not about being thorough - it’s about being repeatable. The first time you run this 9-step process, it will surface gaps you didn’t know you had. The second time, it’ll be 40% faster. The fourth time, it’ll feel boring. That’s the goal. Boring audits are audits you actually finish.

Print this page, copy the checklist into your team’s wiki, or run it directly inside an asset management platform. The format matters less than the cadence. Quarterly, owned by one person, signed off in writing.

Mathias Olsson

Mathias Olsson

Writes about IT asset management, operations, and the unglamorous work of keeping track of physical things at scale. He works at AMPthilly.

AMP in production

Put the register to work

When you are ready to move beyond spreadsheets, AMP is live for checkouts, QR labels, service desk, and ownership your team can defend in an audit.