Guides & Checklists • 11 August 2026 • 8 min

A Free IT Audit Checklist for Johannesburg SMEs

A free, practical IT audit checklist for Johannesburg SMEs: security, backups, licensing and cloud. Spot risks before they cost you. Download it today.

Organised server room with blue ethernet cabling, network switches and a wall monitor showing a network diagram

TL;DR

  • An IT audit is a structured look at what you have, what is at risk, and what it is costing you. You do not need a consultant to start.
  • Work eight areas: assets, security, backups (and restores), licensing, cloud/email, network, POPIA/data, and documentation.
  • Score each area green, amber, or red. Two or more reds means real, avoidable exposure.
  • A printable scorecard PDF is on this page (ungated).
  • Fix reds first. Perfection is not the goal. Knowing where you stand is.
  • Want a second pair of eyes? Book a free IT audit for Johannesburg and Gauteng businesses.

Most small and medium businesses in Johannesburg have never had a proper IT audit. Things “mostly work,” so nobody looks under the hood until a laptop is stolen, ransomware hits, or a software vendor sends a licensing bill nobody expected.

You do not need a consultant to start. Below is the same checklist framework our team uses on a first engagement. Work through it honestly and you will surface most of the issues that quietly drain money and create risk.

Download the 15-minute scorecard

The printable 12-page workbook covers the same eight areas as this page. Mark each area green, amber, or red at your desk. No email required.

Download the IT Audit Scorecard (PDF)

Do you have an asset inventory?

You cannot secure or budget for what you cannot see. List every device (laptops, desktops, servers, phones, network gear), who uses it, its age, and its warranty status.

Anything older than 4–5 years is a replacement risk. No inventory at all? That is your first finding.

Are your security basics actually in place?

Most SME breaches exploit basics, not exotic zero-days. Check endpoint protection on every device, not just “Windows Defender is probably on.”

Is multi-factor authentication (MFA) enabled on email and any admin accounts? Are staff local admins on their own machines (they should not be)? Is there a firewall, and does anyone check its logs?

Have you tested backups, not just configured them?

Backups that have never been test-restored are hope, not a plan. Confirm what is backed up, how often, where it lives (a second location or cloud, not just the same building), and when a restore was last tested.

If load-shedding or a fire took out your office tonight, how many days of data would you lose?

Is your software licensing under control?

List your key software and how it is licensed. Unlicensed or over-deployed software is a compliance and audit risk. Forgotten subscriptions are pure waste.

Note renewal dates so nothing auto-bills at a bad rate.

Where does your cloud and email actually live?

Know where email and file storage live (Microsoft 365, Google Workspace, on-prem), who has access to what, and whether ex-employees are fully deprovisioned.

Cloud sprawl and stale accounts are common, cheap-to-fix findings.

Is your network and connectivity business-grade?

Ask whether you have a business-grade connection with failover, or one line that takes the whole office down when it drops. Is your Wi-Fi segmented (guests separate from business systems)?

For Johannesburg businesses, factor in load-shedding: does critical gear have UPS/inverter backup?

Do you know what personal data you hold under POPIA?

List what personal information you hold (customers, staff), where it lives, and who can access it. POPIA compliance starts with knowing your data.

See our POPIA compliance checklist for SMEs for the detail.

Could someone else pick up if your IT person vanished?

Passwords, vendor contacts, network diagrams and licence records should live somewhere the business controls, not in one person’s head.

If your “IT person” (internal or external) vanished tomorrow, could someone else pick up?

How should you score the checklist?

For each area, mark green (fine), amber (needs attention) or red (urgent risk). Two or more reds means you are carrying real, avoidable exposure.

The point is not perfection. It is knowing where you stand and fixing the reds first.

What should you do next?

Download the IT Audit Scorecard (PDF) and work through all eight areas at your desk.

Book a free IT audit if you want a second pair of eyes on the gaps. African Vanilla offers a free IT audit for Johannesburg and Gauteng businesses. We run this checklist properly, then hand you a prioritised, no-obligation report. Book your free IT audit.

Explore our managed IT services and cybersecurity and POPIA compliance support to close the gaps your audit uncovers.

About the author
Jacques Joubert — Co-Founder & Automation Architect. 18+ years across ITSM, systems integration and automation; leads AI, Odoo ERP and digital transformation.
Meet the team

Need clarity on your IT environment?

Book a free, no-obligation IT audit. We will give you an honest assessment and practical recommendations tailored to Johannesburg businesses.