Everything you need to run a real IT asset inventory audit - what to include, what fields to track, the 9-step process, and how to verify laptops for remote employees. Built as a complete IT asset inventory checklist you can copy, print, and put to work today.
What’s in this checklist
- Why growing teams lose control of IT assets
- What goes in an IT asset inventory (categories)
- The hardware inventory template - required fields
- The 9-step IT asset audit checklist
- How to audit company laptops (incl. remote employees)
- Audit frequency: monthly, quarterly, or annual?
- 7 common pitfalls (and how to avoid them)
- Tools that make this 10× easier
- FAQ
Why growing teams lose control of IT assets
There is a point - usually somewhere between 30 and 100 employees - where IT asset management quietly stops working. Up until then, you know every laptop by name. Past that, things get fuzzy. A device is “with someone in the Berlin office.” A monitor is “probably in storage.” Two people are pretty sure they returned the same docking station. A laptop appears on a procurement report but nowhere in your asset register.
None of this looks dangerous on its own. Then a security audit, an insurance claim, an offboarding gone wrong, or a SOC 2 review forces you to produce a definitive list - and the gap between what you think you own and what you can prove you own turns into a budget hit.
The fix isn’t more spreadsheets or panic. It’s a repeatable IT asset inventory checklist that runs on a schedule, captures the right fields, reconciles physical, MDM, and identity data, and produces a clean record at the end. That’s exactly what this guide is.
What goes in an IT asset inventory (categories)
Before you build the template, decide what counts as an IT asset. The right answer for most growing teams is: anything with a serial number that costs more than a coffee, plus anything that touches company data.
End-user hardware
- Laptops (company-issued and loaner pool)
- Desktops and workstations
- Monitors and external displays
- Smartphones and tablets (company-owned)
- Docking stations and port replicators
- Keyboards, mice, webcams, headsets (above a value threshold)
- Printers and scanners
- Security keys (YubiKey, Titan) and hardware tokens
Networking and infrastructure
- Routers, switches, access points
- Firewalls and VPN appliances
- On-premise servers (if any)
- NAS and external storage devices
- UPS and battery backups
Specialised and shared equipment
- Conference room hardware (cameras, speakers, displays)
- Loaner devices and spares
- Test devices (for QA, support, dev)
- Field hardware (POS terminals, mobile printers, etc.)
Tip: If you also track software licenses, SaaS subscriptions, and cloud resources, keep them in the same system as your hardware. Splitting them across separate tools is one of the most common reasons audits drift out of sync.
The hardware inventory template - required fields
Every device in your asset register should have these fields populated. This is the minimum useful hardware inventory template - anything less and your audit will leave gaps.
| Field | What it is | Required? |
|---|---|---|
| Asset ID | Unique internal ID (e.g. LAP-0142). Printed on the asset tag. | Yes |
| Asset tag / barcode | The physical QR or barcode label stuck on the device. | Yes |
| Category | Laptop, monitor, phone, peripheral, etc. | Yes |
| Make & model | e.g. MacBook Pro 14” M3, Dell Latitude 7440. | Yes |
| Serial number | Manufacturer serial. Source of truth when asset tags fall off. | Yes |
| Status | In use, in stock, in repair, retired, lost. | Yes |
| Assigned to | Person currently holding the device. | Yes |
| Location | Office, home address (or country, for privacy), warehouse. | Yes |
| Purchase date | Used for warranty and depreciation calculations. | Yes |
| Purchase cost | Asset value for insurance and finance. | Yes |
| Supplier / vendor | Who you bought it from. Useful for warranty claims. | Recommended |
| Warranty expiry | The date support coverage ends. | Recommended |
| MDM enrollment | Intune / Jamf / Kandji / Workspace ID for the device. | For laptops/phones |
| Encryption status | BitLocker / FileVault enabled? Required for compliance. | For laptops |
| Last seen | Last MDM or identity provider check-in timestamp. | For laptops/phones |
| Notes / history | Free-text log of repairs, reassignments, incidents. | Optional |
The fields marked “For laptops” are the ones that turn a basic asset list into a real ITAM record. Without MDM enrollment status and encryption confirmation, you cannot answer “is this laptop secure?” - which is the single question every SOC 2, ISO 27001, or HIPAA auditor will ask.
The 9-step IT asset audit checklist
This is the heart of the guide. Run these nine steps every quarter and your asset register will stay clean. Skip them and it will drift, no matter how good your tool is.
1. Define scope and goal
Decide before you start: which categories, which sites, which people. A focused 100-laptop audit beats a sprawling “audit everything” project that never finishes. Write a one-line goal - e.g. “Verify all 247 company laptops are accounted for and MDM-enrolled by end of Q2.”
- Categories in scope listed
- Sites / regions in scope listed
- One-line goal written and shared with stakeholders
- Audit owner assigned (single person)
- Target completion date set
2. Pull your current asset register
Export everything you currently have - from your ITAM tool, your spreadsheet, your procurement records, whatever counts as “the list” today. This is your baseline. Do not clean it yet. Audits verify reality against the baseline; if you clean the baseline first, you lose the ability to measure your error rate.
- Asset register exported (CSV or in-tool snapshot)
- Baseline count recorded by category
- Snapshot dated and stored read-only
3. Cross-reference your discovery data
Pull device lists from every system that already knows about your hardware. Each of these is a source of truth for something, and reconciling them is how you catch ghost assets and untracked devices.
- MDM export (Microsoft Intune, Jamf, Kandji, Mosyle, etc.)
- Identity provider export (Entra ID / Azure AD, Okta, Google Workspace)
- Procurement / finance records for the last 24 months
- HRIS active employee list (so you know who should have a device)
- Last 12 months of helpdesk tickets mentioning new or replaced hardware
Watch for: devices in MDM but not in your asset register (untracked hardware), devices in your register but not in MDM (possible lost or never-enrolled), and active employees with no assigned device (procurement gap or an off-the-books loaner).
4. Physically verify on-site assets
For everything in the office: walk the floor with a phone or barcode scanner and scan every asset tag. Confirm condition, location, and current assignee. Photo evidence is your friend when something is later disputed.
- Every desk and workstation scanned
- Conference rooms and shared spaces checked
- Storage / IT closet inventory scanned
- Loaner pool reconciled (count vs register)
- Damaged or end-of-life items photographed
5. Verify remote employee laptops
Remote devices are where audits leak. Use a three-signal verification - no single signal is enough on its own.
- MDM last check-in is within the last 14 days
- Identity provider shows a recent sign-in
- Employee returns a short confirmation form (photo of serial label + condition note)
- Encryption status verified via MDM (BitLocker / FileVault on)
- Devices failing any signal flagged for follow-up before audit close
6. Flag discrepancies (don’t delete)
Every mismatch gets a status, not a delete. “Missing” and “unconfirmed” are real audit states - they tell you what needs investigation. Quietly erasing the row destroys the evidence you need to fix the underlying process.
- Physical present, not in register → tag and add
- In register, not found physically → status = “unconfirmed”, investigate
- In MDM, not in register → add and assign
- In register, not in MDM → check enrollment; if missing, that’s a security finding
- Wrong assignee → update with date and source
7. Reconcile and update
Now you fix the register. Every change carries a timestamp, a source, and a person. This is the audit trail that turns next quarter’s audit from a panic project into a 30-minute confirmation.
- All confirmed devices updated with verified data
- Missing devices investigated (helpdesk tickets, employee follow-up, return tracking)
- Lost/written-off assets formally retired with reason recorded
- Warranty expirations flagged for renewal or replacement planning
- End-of-life devices queued for secure disposal
8. Report and act
Produce a one-page audit report with the numbers your CFO and CISO actually want. Don’t bury the headline in 30 tabs.
- Total assets in scope, total verified, total flagged
- Discrepancy rate as a percentage
- Lost / written-off count and total value
- Devices out of MDM compliance
- Devices past warranty / approaching end-of-life
- Top 3 action items for the next quarter
9. Schedule the next audit
Audits that aren’t on the calendar don’t happen. Book the next one before you close this one.
- Next audit date scheduled (calendar invite sent)
- Owner confirmed for next cycle
- Process improvements from this audit documented
- Asset register snapshot archived for compliance evidence
Save this section. Copy the nine steps into your team’s wiki or print this page. Run through it as a literal checklist - that’s the whole point of having one.
How to audit company laptops (incl. remote employees)
Laptops are the highest-risk, highest-volume, most-mobile category in any IT asset inventory - they deserve their own playbook. Here is how to audit company laptops specifically, without bringing every remote worker into the office.
The three-signal verification
No single data source is enough to confirm a laptop is accounted for. Use three, and require at least two to match:
- MDM signal: Last check-in within 14 days, encryption on, OS patched, compliance policy passing.
- Identity signal: The assigned user signed in to email, chat, or SSO within the last 14 days from that device.
- Human signal: The employee responds to a short form (one minute) confirming they have the device, with a photo of the serial label and any visible damage.
If all three match → laptop confirmed. If two match → confirmed with note. If only one (or none) match → flag for follow-up before closing the audit.
Special cases
Laptops on extended leave
Devices assigned to people on parental leave, sabbatical, or long-term medical leave often go silent in MDM. Move them to a “held” status, set a calendar reminder for their expected return date, and document the reason - don’t flag them as missing.
Departing employees
Offboarding is where most “lost” laptops actually originate. Tie the audit to your offboarding checklist:
- Return ship-kit sent within 24 hours of termination notice (with tracking)
- Device wiped remotely once received OR remote-wipe scheduled if not
- Asset register status changed to “in-transit” then “returned” then “redeployed/retired”
- Final paycheck hold (where legally permitted) for non-returns
BYOD and personal devices
If you allow BYOD, audit the access, not the device. Use MDM or MAM policies, conditional access, and a documented BYOD agreement. The device is not your asset, but the data on it is your problem.
Audit frequency: monthly, quarterly, or annual?
The “right” cadence depends on your size, your risk profile, and your compliance obligations. Here’s the practical guide:
| Team size | Full audit | Spot checks |
|---|---|---|
| Under 25 employees | Twice a year | Monthly: high-value items, loaners |
| 25–100 employees | Quarterly | Monthly: laptops, phones, security keys |
| 100–500 employees | Quarterly (rolling, by region) | Continuous via MDM monitoring + monthly reconciliation |
| 500+ employees | Continuous (rolling audits, never “done”) | Automated, alerting-driven |
If you’re operating under SOC 2, ISO 27001, HIPAA, or GDPR, the regulator doesn’t dictate a frequency - they expect a documented, repeatable process that you actually follow. Quarterly is the answer that survives every audit.
7 common pitfalls (and how to avoid them)
- Auditing without a goal. “We’re doing an audit” is not a goal. “Verify all 247 laptops by June 30” is. Without a target, the audit drifts and never closes.
- Cleaning the register before measuring. If you tidy up first, you lose the error rate - and the error rate is the metric that tells you whether your process is improving.
- Skipping the human-signal step for remote workers. MDM tells you the device is online; it does not tell you who has it. Ask the human.
- Treating “missing” as “delete.” A missing asset is a finding, not a janitorial task. Keep the row, change the status, log the follow-up.
- No single owner. Audits with three co-owners have zero owners. One person runs it; others contribute.
- Doing it in a spreadsheet at scale. Past ~100 devices, the reconciliation step alone takes longer than the rest of the audit combined. (More on this in Why Excel Fails for Asset Tracking.)
- Not scheduling the next audit. If the next audit isn’t on a calendar before you close this one, it won’t happen. Watch.
Tools that make this 10× easier
You can run this checklist with a spreadsheet, a clipboard, and a lot of patience. You can also run it with a dedicated asset tracking platform that holds a single source of truth, captures every check-in/check-out, and produces audit-ready reports on demand.
The categories of tools you’ll want in the stack:
- ITAM / asset tracking platform - a single source of truth for your asset register, with mobile scanning, check-in/check-out, and audit trail. AMPthilly is built for exactly this workflow.
- MDM / device management - Microsoft Intune, Jamf, Kandji, Mosyle, or Google Workspace device management.
- Identity provider - Microsoft Entra ID, Okta, or Google Workspace.
- HRIS integration - so the asset register knows when an employee starts and leaves.
- Asset tags & mobile scanner - printed QR or barcode tags on every device, scannable from a phone.
Want this checklist as a working asset register, not a static doc?
AMP turns your asset register into a single, scannable, mobile-friendly system - with a real audit trail, check-in/check-out, and reporting built in, so reconciliation happens in the platform instead of on a clipboard.
FAQ
How often should you audit IT assets?
Quarterly full audits with monthly spot checks on high-risk categories (laptops, phones, security keys) is the right cadence for most growing teams. Twice-yearly works under 25 employees; continuous rolling audits become necessary past 500.
What should be included in an IT asset inventory checklist?
Categories (end-user hardware, networking, specialised equipment), required fields per asset (Asset ID, serial, model, assignee, location, status, purchase date, warranty, MDM enrollment, encryption status, last-seen), verification steps (physical scan, MDM cross-reference, identity-provider cross-reference, employee confirmation), and a documented reconciliation + reporting process.
How do you audit company laptops for remote employees?
Use three signals: (1) MDM check-in and compliance status within the last 14 days, (2) identity-provider sign-in from the device within the last 14 days, and (3) a short employee confirmation form with a photo of the serial label. Require at least two to match; flag everything else for follow-up.
What is the difference between an IT asset audit and an IT audit?
An IT asset audit verifies that the hardware and software you think you own actually exists, is where you think it is, and is recorded correctly. An IT audit is a broader review of your IT controls and security posture. The asset audit is a subset of the IT audit - and a clean one is almost always a prerequisite for passing the broader review.
Can you do an IT asset audit in a spreadsheet?
For very small teams (under ~50 devices, no remote workers, no compliance obligations), yes. Past that, the reconciliation step becomes the bottleneck - version conflicts, no audit trail, no MDM integration, no real-time updates. A dedicated tool pays back its cost within the first or second audit cycle.
What’s the cheapest way to start?
Start with the field template in this article, populate it from your existing data sources (MDM, identity provider, procurement), and import it into a tool with a usable free tier - like AMPthilly, AssetTiger, or self-hosted Snipe-IT. The cost is mostly your time, and the saving is one prevented lost laptop.
Do we need asset tags on every device?
Yes - for anything that moves. The asset tag is what makes audits fast: a 5-second scan beats a 30-second serial-number type-in, every time. Without tags, audits take 6× longer and accuracy drops sharply.
The takeaway
A great IT asset inventory checklist is not about being thorough - it’s about being repeatable. The first time you run this 9-step process, it will surface gaps you didn’t know you had. The second time, it’ll be 40% faster. The fourth time, it’ll feel boring. That’s the goal. Boring audits are audits you actually finish.
Print this page, copy the checklist into your team’s wiki, or run it directly inside an asset management platform. The format matters less than the cadence. Quarterly, owned by one person, signed off in writing.