How to Do an Information Audit

An information audit systematically inventories, assesses and scores the information assets, flows, controls and risks in an organisation. The objective is to understand what information exists, where it lives, how it is used, and whether it is fit for purpose and subject to appropriate protection and governance. The plan below is pragmatic, repeatable, and suitable for organisations of varying sizes.

Why Do an Information Audit?

Organisations  conduct information audits for two main reasons:

  • the necessity of risk mitigation and compliance ; and
  • operational efficiency and value maximisation.

First, an information audit is a key part of effective risk and compliance management. By systematically identifying, classifying, and mapping all information assets, an organisation gains a clear understanding of where its most sensitive data (like customer personal data or proprietary information) sits. This knowledge is essential for meeting rigorous regulatory obligations (e.g., GDPR), safeguarding against data breaches, and proving legal defensibility in the event of litigation (eDiscovery). Simply put, without knowing what information is held and where it is located, an organisation cannot properly protect it or demonstrate adherence to the law.

Second, organisations actively want to conduct audits because they unlock significant business value and cost savings. Audits reveal vast quantities of Redundant, Obsolete, or Trivial (ROT) data that can be safely deleted, drastically reducing expensive storage costs and lowering the “attack surface” for cyber threats. Furthermore, by clarifying information ownership and improving data quality, the audit enhances operational efficiency, ensuring employees can quickly find the right, trustworthy data, thereby supporting better, faster decision-making across all business functions. The audit transforms information from a potential liability into a usable asset.

So how do you do an information audit? Below is a step by step summary of a process you can adapt and use.

 

Phase 0 — Preparatory work (Initiation)

Step 0.1 — Define purpose and objectives

  • Articulate why the audit is being done (e.g., GDPR readiness, M&A due diligence, cost reduction, information risk reduction).
  • Set measurable objectives (e.g., complete inventory of all personal data stores; map 100% of customer data flows).
    Deliverable: Audit purpose statement and SMART objectives.

Step 0.2 — Secure sponsorship and governance

  • Obtain executive sponsor (CIO, CDO, CIO, or equivalent).
  • Establish an audit steering group with legal, security, IT, records, and business leads.
    Deliverable: Sponsor & steering group charter.

Step 0.3 — Define scope and boundaries

  • Decide organisational units, systems and information types in/out of scope (e.g., exclude legacy archive pre-1990 if not required).
  • Decide timebox (e.g., 8–12 weeks) and resource limits.
    Deliverable: Scope statement and timeline.

Step 0.4 — Assemble team and resources

  • Nominate Information Asset Owners (IAOs) or contacts for each business area.
  • Assign roles: lead auditor, data mapper, technical analyst, records specialist.
  • Select tools (spreadsheets, discovery tools, DLP, metadata catalogues).
  • Deliverable: Project resource plan and tool inventory.

Phase 1 — Planning & design

Step 1.1 — Create an audit framework, checklist and templates

  • Build templates for: asset inventory, data flow mapping, risk assessment, access review, retention mapping, remediation log.
  • Establish classification scheme and scoring criteria (sensitivity, criticality, legal exposure).
    Deliverable: Audit toolkit (templates + scoring rubric).

Step 1.2 — Stakeholder communications plan

  • Define communication cadence and channels.
  • Prepare briefing packs for IAOs and business leads explaining expectations and timelines.
  • Deliverable: Communications plan and briefing slide deck.

Phase 2 — Discovery and inventory

Step 2.1 — Identify information assets

  • Capture systems, databases, file shares, cloud stores, physical records, third-party repositories, email archives, applications.
  • For each asset record: owner, custodian, description, format, location, volume, business purpose.
    Deliverable: Master information asset register.

Step 2.2 — Catalog data elements (attribute-level inventory)

  • For high-value systems, record types of personal or sensitive data (PII, financial, health, IP) and key fields (e.g., name, DOB, ID, account number).
  • Deliverable: Data elements register per asset.

Step 2.3 — Metadata and provenance capture

  • Record metadata availability: creation date, author, version, retention tag, classification, lineage.
    Deliverable: Metadata maturity map.

Step 2.4 — Automated discovery (where feasible)

  • Run discovery tools: network scans, file analysis, DLP reports, database inventories, cloud posture scans.
  • Deliverable: Discovery output and reconciliation log.

Phase 3 — Data flow mapping and uses

Step 3.1 — Map information flows

  • Map inbound/outbound flows for each critical asset: who creates/ingests, who reads/updates, internal transfers, third-party sharing, cross-border flows. Use visuals.
  • Deliverable: Data flow diagrams for each business process/system.

Step 3.2 — Document purposes and legal bases

  • For personal data, record processing purposes and legal bases (consent, contract, legal obligation, legitimate interest).
  • Deliverable: Processing purpose register.

Phase 4 — Assessment (quality, security, retention, access)

Step 4.1 — Data quality assessment

  • Measure: completeness, accuracy, consistency, timeliness. Use sample checks or profiling tools.
  • KPIs: % records passing validation; duplication rate; missing required fields.
  • Deliverable: Data quality dashboard and issues list.

Step 4.2 — Classification and sensitivity assessment

  • Score assets by confidentiality, integrity, availability (CIA) impact and business criticality.
  • Deliverable: Asset risk matrix (heatmap).

Step 4.3 — Security and access control review

  • Evaluate encryption, access controls, authentication, logging, IAM role assignments.
  • Check privileged access, orphaned accounts, and admin rights.
  • Deliverable: Security control assessment and access anomalies list.

Step 4.4 — Retention and disposal assessment

  • Compare actual retention practices to policy/legislation. Flag over-retention or gaps in disposal procedures.
  • Deliverable: Retention compliance matrix and disposal backlog.

Step 4.5 — Compliance and legal exposure assessment

  • Identify data subject rights enforcement gaps, cross-border transfers without adequate safeguards, regulatory reporting weaknesses.
  • Deliverable: Compliance risk register.

Phase 5 — Synthesis and risk scoring

Step 5.1 — Consolidate findings

  • Aggregate findings across inventory, quality, flows, security, retention and compliance.
  • Deliverable: Consolidated findings log.

Step 5.2 — Prioritise risks

  • Apply risk scoring (likelihood × impact). Prioritise remediation by risk severity and business impact.
  • Deliverable: Prioritised remediation list (top risks / quick wins).

Step 5.3 — Root cause analysis

  • For major issues (e.g., pervasive duplication, uncontrolled sharing), identify root causes (process gaps, lack of training, system limitations).
  • Deliverable: RCA notes per major finding.

Phase 6 — Recommendations and remediation planning

Step 6.1 — Define remediation actions

  • For each priority item, define action, owner, target date, resources required, and acceptance criteria. (E.g., implement field validation in CRM; remove unneeded global share; encrypt backup tapes.)
  • Deliverable: Remediation plan with RACI.

Step 6.2 — Tactical quick wins and strategic investments

  • Separate short-term tactical fixes (30–90 days) from strategic investments (metadata catalogue, master data management, DLP rollout).
  • Deliverable: Two-tier action roadmap.

Step 6.3 — Estimate costs and benefits

  • Provide cost estimates, projected risk reduction and business benefits for key remediation items.
  • Deliverable: Business case briefs for major initiatives.

Phase 7 — Reporting and governance handover

Step 7.1 — Produce audit report

  • Executive summary with risk posture, top 10 findings, recommended actions and resource asks.
  • Appendices: full asset register, flows, detailed findings, raw data.
  • Deliverable: Formal audit report.

Step 7.2 — Present to steering group and executives

  • Provide concise slide deck and Q&A. Secure decisions on priorities and funding.
  • Deliverable: Presentation and governance minutes.

Step 7.3 — Hand over to operational owners

  • Transfer remediation responsibility to IAOs and relevant teams with agreed metrics and reporting cadence.
  • Deliverable: Handover pack and signed RACI.

Phase 8 — Implementation support, monitoring and assurance

Step 8.1 — Track remediation progress

  • Use a governance tracker (GRC tool, spreadsheet) to monitor status, dependencies, and risks. Weekly or fortnightly updates.
  • Deliverable: Live remediation dashboard.

Step 8.2 — Establish KPIs and ongoing monitoring

  • Define KPIs to monitor (e.g., % assets inventoried, % critical data encrypted, average time to fulfil DSAR). Set thresholds and escalation triggers.
  • Deliverable: Operational KPI dashboard and SLA definitions.

Step 8.3 — Schedule periodic re-audits and continuous improvement

  • Decide re-audit cadence (annual full audit; quarterly mini reviews). Integrate continuous discovery and automated controls where possible.
  • Deliverable: Audit schedule and continuous monitoring plan.

Practical Considerations & Best Practice for Information Audits

There are a number of key steps and approaches to consider that will enhance the effectiveness of your information audit. They include:

  • Engage early with business units. Their cooperation is essential. Frame the audit as enabling (risk reduction and efficiency), not policing.
  • Adopt a risk-based approach. Focus effort where impact is greatest—personal data, financial records, IP.
  • Use automation prudently. Discovery tools accelerate inventory but always validate with business owners.
  • Maintain evidence trails. For legal and regulatory assurance keep records of interviews, snapshots, and decisions.
  • Treat metadata as an asset. Good metadata reduces effort in future audits.
  • Address cultural factors. Training and incentives reduce reoccurrence of findings (e.g., poor retention practices).

Example Information Audit Timeline

This timeline might be suitable for a medium-sized organisation, with the information audit scoped to core systems

  • Weeks 0–1: Initiation and stakeholder alignment
  • Next: Weeks 2–3: Planning, templates and tool set-up
  • Then for Weeks 4–7: Discovery, inventory and automated scans
  • Weeks 8–10: Flow mapping and assessments (quality, security, retention)
  • Week 11: Synthesis, risk scoring and remediation planning
  • Week 12: Reporting, presentation and handover

information audit timelime

You should adjust the duration or timeline of your audit depending on your needs and according to scale and scope.


Success Criteria and Assurance Metrics

  • Coverage: % of critical systems & business units inventoried (target ≥ 95%).
  • Quality: % of records passing validation checks (improvement target agreed).
  • Risk Reduction: Reduction in high-severity IG risks within 6 months.
  • Compliance: % of assets with documented legal basis for processing.
  • Remediation: % of high-priority actions completed on time.
  • Governance: Regular executive reporting established and operational.

Common Pitfalls to Avoid in an Information Audit

Without careful planning there is a risk your information audit will not produce the results you need. Some of the reasons for this include:

  • Overly broad scope leading to paralysis by analysis.
  • Failing to secure cooperation across the organisation and from leadership teams.
  • Treating the audit as a one-off rather than establishing continuous processes.
  • Ignoring cultural change—technical fixes alone won’t fix poor data practices.
  • No follow-through on remediation; the audit is done and then forgotten.

This step-by-step plan gives you a structured, actionable approach to delivering an information audit that produces inventory, insight, risk prioritisation and a pragmatic remediation roadmap. The outcome should be a clear view of information assets, demonstrable risk reduction, and an embedded process for ongoing governance and assurance.