Iurii RoguliaIurii Rogulia
AboutServicesPricingProjectsStackReviewsPhrasesBlog
Contact
Iuriiย ships.

Iurii Rogulia, IT partner for business & fractional CTO. Professionally building software since 2001.

Think of a number
PricingQuality checklistPrivacy PolicyCookie Policy

Business

TMI Iurii Rogulia
VAT ID: FI29845875
DUNS: 368664211
Lappeenranta, Finland ๐Ÿ‡ซ๐Ÿ‡ฎ

[email protected]
  1. Home
  2. /
  3. Blog
  4. /
  5. IT Audit Checklist: What to Expect in Week One

Iuriiย Audits: IT Audit Checklist: What to Expect in Week One

What I Look at in the First Week

March 25, 2026ยท 5 min read

IT audit first week checklist: what I map before fixing anything for a new business client โ€” usually different from what anyone in the company thinks.

Topics

BusinessIT StrategyProcessCTO
IT Audit Checklist: What to Expect in Week One

On this page

  • The Systems People Actually Use vs. the Official List
  • Load-Bearing Workarounds
  • Passwords and Access
  • Data That Lives Nowhere Formal
  • What Surprises Me Every Time
  • What the First Week Produces

When I start working with a new business client, I don't open a laptop and start fixing things.

I spend the first week listening and looking. In my experience, the gap between "what the company thinks its IT looks like" and "what it actually looks like" is the most important thing to understand before anything else. That gap is where the real problems hide โ€” and it's almost always larger than the client expects.

Here is what I look at.

The Systems People Actually Use vs. the Official List

Every company I've worked with has a list of their IT systems somewhere. It might be a spreadsheet, a contract folder, a note in someone's head. It is never accurate.

What I find instead: subscriptions to tools nobody has opened in fourteen months, still being charged. And on the other side, critical work happening in tools that were never designed for it โ€” Excel files emailed back and forth as a de facto database, WhatsApp threads functioning as a ticketing system, someone's personal Google Drive hosting documents the whole company depends on.

The gap between the official list and reality is not a management failure. It's how companies work. People solve problems with whatever is available. But that gap needs to be mapped before you can make any sensible decisions about what to change.

Load-Bearing Workarounds

A workaround is a process someone invented to compensate for something the official system can't do.

Most workarounds are harmless. But some of them have become load-bearing โ€” they have been running so long, and so many things depend on them, that removing them would cause immediate breakage. I look for these first, because they tell me where the real system boundaries are.

The dangerous ones are the workarounds nobody documents because everyone considers them obvious. "Oh, we always export that report on Fridays and paste it into the accounting system manually before the weekend" โ€” that is a critical dependency masquerading as a routine task. If the one person who does it is sick on Friday, the accounting system is wrong on Monday.

I find at least one of these in almost every company I audit. Usually more.

Passwords and Access

Who has access to what? Who left the company two years ago but still has an active login to your CRM? Which shared passwords live in a WhatsApp thread from 2021 that's been forwarded to seventeen people?

These are not small things.

In roughly 80% of companies I've audited, there are active credentials belonging to people who no longer work there. Not because anyone was negligent โ€” but because revoking access is nobody's job until something goes wrong. Setting up access is urgent; cleaning it up never is.

I document every access point I can find in the first week. It is not exciting work. It is consistently one of the most valuable things I produce. This access audit is one part of a broader technical due diligence engagement โ€” the kind of structured look that surfaces risks before they become emergencies.

Related service

Technical Due Diligence

Need a clear picture of what you actually have before spending on new software or hiring? A structured first-week audit maps systems, risks, and priorities โ€” so you fix the right things first.

More about this service โ†’

Data That Lives Nowhere Formal

Critical business information โ€” customer contacts built up over years, pricing agreements, the specific way to handle a particular category of order โ€” often lives in one person's email inbox. Or in a shared folder with no backup. Or in a spreadsheet on a laptop that has never been connected to any company system.

When I find this, I mark it immediately. Not to criticize anyone, but because it is fragile in a specific way: if the person who owns that inbox leaves, or the laptop breaks, or the shared folder gets accidentally deleted, the information is gone. There is no recovery procedure because nobody thought of it as data that needed one.

What Surprises Me Every Time

Almost always, it's the manual work.

Not the obvious manual tasks that everyone knows about. The normalized ones โ€” the ones nobody mentions because they have been doing them for three years and stopped thinking of them as a problem. Hours per week, per person, compensating for systems that don't talk to each other. Data copied from one screen to another. Reports assembled by hand because the two systems involved have no integration. Approvals tracked in an email thread because no one has set up a workflow.

When I add it up across a team, the number is usually surprising โ€” sometimes to the point of discomfort. Not because the work is unusual, but because it has become invisible.

What the First Week Produces

Not a solution. A map.

A clear picture of what exists, what's fragile, what's redundant, and where the highest-leverage improvements are. A list of risks that need addressing urgently, separated from improvements that can wait. An honest answer to the question: what is actually here, and what would it cost to fix it?

That map is worth having before anyone spends a euro on new software or a month building something new. In my experience, it changes the priorities significantly in almost every case. The five patterns that typically show up โ€” and what they cost when left unaddressed โ€” are mapped out in detail in what happens when nobody owns your IT. And if you're wondering what comes after the audit, one IT partner instead of a department describes what ongoing ownership actually looks like for a growing business.


If you've never had someone look at your IT this way, it's worth doing once. The findings are usually actionable within weeks, not months. Get in touch โ€” the first conversation is always free.

Iurii Rogulia

Working on something like this?

Technical Due Diligence

If you've never had someone look at your IT this way, a structured first-week audit surfaces more opportunity than risk โ€” and changes priorities almost every time.

More about this service

Relevant client work

View all projects
Pikkuna โ€” AI-Powered Localization Pipeline
Pikkuna โ€” AI-Powered Localization Pipeline
July 30, 2026
Pikkuna โ€” AI-Powered Localization Pipeline

A production localization pipeline built entirely on the OpenAI API: one English source of truth, SEO-aware translation prompts, cross-model verification with

Pikkuna โ€” i18n RAG AI System
Pikkuna โ€” i18n RAG AI System
December 15, 2025
Pikkuna โ€” i18n RAG AI System

RAG system on OpenAI and Upstash Vector with 30 language support. Includes streaming chatbot, hybrid search (semantic + keyword), AI ticket classifier, and

Pikkuna โ€” Real-time SVG Product Configurator
Pikkuna โ€” Real-time SVG Product Configurator
March 10, 2025
Pikkuna โ€” Real-time SVG Product Configurator

Client-side SVG configurator with live preview for designing vinyl curtains and roofing panels.

What clients say

โ€œ

We'd just raised and needed to double the engineering team fast, but nobody internally had hired at that scale or owned the architecture decisions that came with it. A full-time CTO was a six-month search we didn't have time for. Iurii held the role two days a week in the meantime โ€” he set up the interview loop, sat in on the senior candidates, killed a rewrite the team was quietly drifting toward, and made the infrastructure call before it turned into a fire. When we finally hired someone permanent the handover took a week because everything was already documented. He ran it like an owner, not a consultant billing hours.

Kasper Holm ๐Ÿ‡ฉ๐Ÿ‡ฐ

CEO

Topics

LeadershipCTOHiringArchitectureStrategy
โ€œ

Our app had slowed to a crawl and the previous developer had left no documentation. Customers were starting to churn over load times. Iurii profiled it instead of guessing, found a handful of unindexed queries and a runaway N+1 that were doing most of the damage, and had page loads back under a second within the first week. He fixed the actual causes rather than throwing more server at it, and wrote up what he changed so we wouldn't repeat the same mistakes.

Owen Pritchard ๐Ÿ‡ฌ๐Ÿ‡ง

CTO

Databases

PostgreSQL

Topics

Technical DebtPerformanceProcess
โ€œ

I'm a non-technical founder and I'd been making technology decisions by guessing, which was getting expensive. Iurii joined as a fractional CTO one day a week and the difference was immediate โ€” he set up a sane roadmap, vetted two contractors I was about to overpay, and translated what the dev team was telling me into plain language so I could actually make calls. He's not there to write all the code; he's there so I stop making the wrong bets.

Matteo Conti ๐Ÿ‡ฎ๐Ÿ‡น

Founder

Topics

LeadershipCTOHiringStrategy

Related articles

Fractional CTO: What They Do, Cost, and When to Hire One
April 30, 2026ยท 11 min
Fractional CTO: What They Do, Cost, and When to Hire One

Fractional CTO is one of the most misused titles in tech consulting. Here's what the role actually covers, what it doesn't, and how to spot the real thing.

Topics

LeadershipIT StrategyBusinessFreelanceCTO
Freelance Developer vs IT Partner: What's the Difference?
April 8, 2026ยท 4 min
Freelance Developer vs IT Partner: What's the Difference?

A developer builds what you ask for. An IT partner asks what you actually need. The difference is the difference between wasted budget and a result that works.

Topics

BusinessIT StrategyLeadershipCTO
Fractional IT Partner vs In-House IT Department: Cost Breakdown
March 30, 2026ยท 5 min
Fractional IT Partner vs In-House IT Department: Cost Breakdown

Fractional IT partner vs in-house IT department: most growing businesses don't need a full team. One experienced partner covers the same scope for less.

Topics

BusinessIT StrategyAutomationCTO
5 Signs Your Business IT Setup Is Costing You Money
March 23, 2026ยท 5 min
5 Signs Your Business IT Setup Is Costing You Money

5 signs your business IT is holding you back: a self-diagnostic for founders and managers. If three of these apply, your IT setup is costing you money.

Topics

BusinessIT StrategyCTO
No IT Manager? The Hidden Cost of Unmanaged IT for SMBs
March 18, 2026ยท 5 min
No IT Manager? The Hidden Cost of Unmanaged IT for SMBs

Who is responsible for your business IT? Most growing companies have IT no one actually owns. What that costs in wasted hours, unmanaged risk, and the fix.

Topics

BusinessIT StrategyLeadershipCTO