The Complete IT Audit Checklist for Mid-Sized African Enterprises (2026)
A structured 47-point IT audit framework covering physical security, cloud, cybersecurity, software, and data — built from hundreds of engagements across 10 African countries. Download the PDF checklist to run it yourself.
- The average 50-employee Nairobi business has 60+ distinct hardware items on its network — most IT managers can name fewer than 20.
- Undiscovered IT spend averages KES 280 K/month above what the finance director thinks the company pays.
- A hardware and software asset registry is the single most impactful IT governance document — without it, you cannot enforce security policy or plan capacity.
- ODPC compliance under Kenya's Data Protection Act requires a documented data inventory and retention schedule — most businesses have neither.
- 912's 47-point audit covers physical security, cloud, cybersecurity, software licences, and data governance in a single structured workbook.
Executive Briefing: Most mid-sized African enterprises are overspending on IT by 20–40% — and still exposed on the basics. Fragmented vendors, undocumented infrastructure, and shadow spend add up quietly. This guide gives you the same 47-point IT audit framework 912 runs on the first day of every engagement, across Kenya, Senegal, Rwanda, Ghana, DR Congo, Angola, Burkina Faso, Benin, Mali, and Burundi. Read it through, download the PDF, and run it on your own stack in a weekend.
For the full service architecture, see our IT Audit Services offering or explore the broader Managed IT, Cloud & Cybersecurity pillar.
Why Most IT Audits in Africa Miss the Point
The typical "IT audit" in Nairobi, Lagos, Accra, or Dakar is really an asset audit — someone walks through the server room, tags boxes, counts licenses, and writes a PDF. It tells you what you own. It does not tell you whether you're secure, whether your cloud spend makes sense, whether your CCTV is admissible as legal evidence, or whether your ERP will survive a ransomware attack.
A real IT audit answers four questions the board actually cares about:
- Are we exposed? Where can an attacker, disgruntled employee, or natural disaster take us down?
- Are we overspending? Which contracts, licenses, and vendors are duplicative, underused, or out of market?
- Are we compliant? Kenya Data Protection Act, ODPC notifications, industry regulators (CBK, IRA, CAK) — are we defensible if audited?
- Are we ready? If we grow 30% in the next 18 months, does the stack scale or does it break?
The 47-point checklist below is organised to answer those four questions across five domains: physical security, cloud and core IT, cybersecurity, applications and software, and data and intelligence. It's the same framework 912 uses on the first day of every engagement, refined across hundreds of client environments since 2013.
Domain 1 — Physical Security & Infrastructure (9 checks)
This is the domain most auditors skip, and it's the one that burns enterprises most often. A compromised CCTV server is a compromised network. An unaccounted-for server room key is a compliance violation. Start here.
- 1.1 CCTV coverage map: Every entry, exit, server room, cash office, and loading bay covered. No blind spots. Retention ≥ 30 days.
- 1.2 CCTV admissibility: Timestamp, resolution (≥2MP), and storage integrity sufficient to stand up in a Kenyan court. Hashes on archived footage.
- 1.3 Access control register: Every badge/biometric enrolment tied to an active employee. Former staff deactivated within 24 hours of exit.
- 1.4 Server-room physical access: Dual-factor (badge + PIN or biometric). Access log reviewed monthly. No shared keys.
- 1.5 Perimeter (electric fence, gates): Tested monthly. Integrated with alarm + CCTV, not a standalone island.
- 1.6 UPS + generator test log: Load-tested quarterly. Runtime validated against actual server draw, not sticker rating.
- 1.7 Environmental monitoring: Temperature, humidity, water leak sensors in the server room. Alerts routed to a real human, not a dead inbox.
- 1.8 Structured cabling audit: Labels, patch panel documentation, no "mystery cables." Category 6A minimum for new runs.
- 1.9 KDPA compliance for biometric/CCTV data: Data Protection Impact Assessment (DPIA) on file. Signage at camera locations. ODPC registration current.
Domain 2 — Cloud & Core IT (10 checks)
Cloud spend is the single largest line item most African enterprises can't explain. AWS, Azure, and GCP bills grow quietly — test environments nobody shuts down, oversized instances, forgotten snapshots, retired staff with active IAM credentials.
- 2.1 Cloud cost attribution: Every resource tagged by business unit, project, and owner. Orphaned resources flagged and deleted monthly.
- 2.2 Right-sizing review: EC2/VM utilisation under 20% for 30+ days → downsize. Over 80% sustained → right-size up or autoscale.
- 2.3 Reserved / Savings Plan coverage: Stable workloads on 1-year RIs or Savings Plans. Target ≥ 60% coverage for production.
- 2.4 Multi-region / availability-zone design: Critical workloads have failover tested at least annually.
- 2.5 Backup policy validated by restore test: A backup you haven't restored from is not a backup. Quarterly restore drill documented.
- 2.6 Disaster recovery RTO / RPO: Written, signed off by business owners, and tested. Recovery Time Objective ≤ 4 hours for tier-1 systems.
- 2.7 Patch cadence: OS and hypervisor patches applied within 30 days of vendor release. Emergency patches within 72 hours.
- 2.8 Network segmentation: VLANs separate guest Wi-Fi, production, CCTV, IoT, and management traffic. No flat networks.
- 2.9 VoIP / IP telephony uptime: Call quality (MOS) ≥ 4.0. Redundant SIP trunks. E911/emergency-call paths tested.
- 2.10 Vendor contract library: Every cloud, ISP, and SaaS contract scanned, dated, with renewal dates calendared 90 days ahead.
Domain 3 — Cybersecurity (12 checks)
If you only have time for one domain, do this one. Ransomware against African SMBs grew 76% year-over-year in 2025, and most incidents exploited failures in the first four items below.
- 3.1 MFA on all privileged accounts: Non-negotiable. Email, VPN, cloud console, domain admin, financial systems. Hardware keys preferred for admins.
- 3.2 Email security gateway: SPF, DKIM, and DMARC all configured, DMARC at enforce. Inbound phishing protection running.
- 3.3 Endpoint detection and response (EDR): Not legacy antivirus. EDR deployed on 100% of endpoints, with central console monitored.
- 3.4 Admin account hygiene: No shared admin accounts. Break-glass accounts stored offline. Audit trail on all privileged actions.
- 3.5 Vulnerability scan cadence: Authenticated scans monthly on servers, weekly on internet-facing assets. Remediation SLA tied to CVSS score.
- 3.6 Penetration test: Independent pen test at least annually. Findings tracked to closure with owner and date.
- 3.7 Security awareness training: Every employee, annually. Phishing simulation ≥ quarterly. Click rate trending down, not up.
- 3.8 Data loss prevention (DLP): Policies on email and cloud storage for PII, financials, source code, and customer data.
- 3.9 Incident response plan: Written, tested via tabletop at least annually. Contact tree current. External IR retainer in place.
- 3.10 Firewall rule review: Rule base reviewed every 6 months. "Any-any" rules justified or removed. Change log maintained.
- 3.11 SIEM / log retention: Central log aggregation with ≥ 90 days online, 1 year archive. Alerting on privileged-access anomalies.
- 3.12 Third-party / supply-chain risk: Security questionnaire on file for every vendor touching production data. Reviewed annually.
Domain 4 — Applications & Software (8 checks)
Custom-built software and ERPs are the most under-audited part of most stacks. If the engineer who built your payroll integration left in 2022 and nobody has touched it since, you have a problem.
- 4.1 Application inventory: Every custom app, SaaS subscription, and ERP module documented with owner, business purpose, and criticality.
- 4.2 Source code escrow / repo access: For custom software, source code is in a repo you control (not on a former developer's laptop). Access audited.
- 4.3 ERP user access review: Segregation of duties verified. Dormant accounts disabled. Quarterly review signed off by business owner.
- 4.4 Integration map: All API integrations between systems documented. Credentials rotated on schedule. Webhook security verified.
- 4.5 Release / change management: No direct-to-production changes. PR review and rollback plan required. Change advisory board for tier-1 systems.
- 4.6 Dependency and licence audit: Open-source dependencies scanned for CVEs and licence compliance (no GPL contamination in proprietary code).
- 4.7 Mobile / web app SSL and headers: HTTPS enforced, HSTS enabled, security headers (CSP, X-Frame-Options) graded ≥ A on Mozilla Observatory.
- 4.8 End-user device management (MDM): Corporate laptops and phones enrolled in MDM. Encryption enforced. Remote wipe tested.
Domain 5 — Data & Intelligence (8 checks)
Data is where quiet value leaks — reports nobody uses, dashboards nobody trusts, PII sitting in Excel files on shared drives. This domain is also where KDPA enforcement actions hit hardest.
- 5.1 Data inventory: Every database, warehouse, and analytics workspace catalogued. Classification applied (public, internal, confidential, restricted).
- 5.2 Data owner assigned: Every dataset has a named business owner accountable for accuracy and access decisions.
- 5.3 PII mapping: All personal data locations mapped. DPIA on file for high-risk processing. ODPC registration current.
- 5.4 Dashboard usage analytics: Power BI / Tableau workspaces measured for actual usage. Dashboards with zero views in 90 days retired.
- 5.5 ETL pipeline observability: Every pipeline has monitoring, alerting, and a named on-call owner. Failures escalate, not silently fail.
- 5.6 Data lineage: Any number on a board report traceable back to source transaction within 5 minutes of being asked.
- 5.7 Retention policy enforced: Old data deleted according to policy, not kept "just in case." Legal and compliance hold process defined.
- 5.8 Backup + DR for analytical systems: Data warehouse has its own RPO/RTO. Power BI workspace exports tested.
How to Run This Checklist in a Weekend
You don't need an external firm to run the first pass. Block a Friday afternoon and a Saturday, and work through it with your IT lead and one business stakeholder per domain. For each item, score: Green (in place and verified), Amber (partial or undocumented), Red (missing or unknown). A first audit typically returns 40–60% Green, 20–30% Amber, 10–20% Red — that's normal and actionable.
The 47 items compound. Three Ambers on MFA, EDR, and patch cadence is a single coherent programme of work — it's not three separate problems. Most African mid-sized enterprises can close 60% of the gaps in 90 days with focused effort and the right partner.
The Regional Context: Why This Framework Is African-First
Generic IT audit checklists imported from North American frameworks (NIST CSF, CIS Controls) miss the realities of operating in Kenya, Ghana, Senegal, or DRC. Power stability, last-mile connectivity, regulatory particularities (ODPC in Kenya, NITA-U in Uganda, NDPB in Nigeria), skilled-labour availability, and the prevalence of converged physical-and-digital threats all shift the weighting. This 47-point framework is adapted from the ISO 27001, NIST CSF, and COBIT 2019 control families, with African-specific additions in domains 1 (physical security integration) and 3 (supply-chain and connectivity resilience).
Download the PDF Checklist
The full 47-point checklist with scoring rubric, severity weighting, and a one-page executive summary template is available as a downloadable PDF. No email gate for the executive summary — sign up with a work email only if you want the scoring spreadsheet.
Download the 47-point IT audit checklist
Get the printable PDF + Google Sheets scoring template. Run it yourself, or book a free 30-minute audit review where our engineers walk through your scores and prioritise the top 5 fixes.
Want 912 to run the audit for you? Book a free discovery call — we deliver a written audit report with prioritised remediation in 5 business days.
Frequently Asked Questions
What is an IT audit and why does a Kenyan business need one?
How much does an IT audit cost in Kenya?
How do I download 912 Limited's IT audit checklist?
About the Author
912 Expert Team
Managed IT Strategy Practice
The 912 Expert Team consists of certified infrastructure, security, and data architects designing resilient technology frameworks across 10 African countries.



