Technology audit · IT audit · Led by a senior CTO or CIO
Technology audit · what to fix, in what order, and who should lead it
A technology audit is an independent review of how a business builds, runs and pays for its technology: architecture, code and delivery, infrastructure and cloud cost, security, data, suppliers and contracts, the team and the roadmap. It ends in a prioritised list of what to fix, in what order, and who should lead the work.
We deliver it by placing a senior practitioner, a fractional or interim CTO or CIO, who runs the audit inside your business and writes the findings. If the findings say you need a technology leader, you can hire a fractional CTO or CIO to carry them out. Before anyone starts, we send a shortlist of 3–5, each with day rate, availability and IR35 position set out, after five-stage vetting.
How a brief runswhat we undertake
- 01Brief30-MINUTE SCOPING CALLDay 0
- 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
- 03InterviewsYOU MEET THE SHORTLISTYour diary
- 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
- 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief
Shortlist3–5
15 minutes · video or phone
Book 15 minutes to hire a fractional CTO or CIO
Tell us the scope and the days a week. We come back with CTO and CIO candidates, their day rates and availability.
- 0115 minutes, video or phone
- 02We scope the role and the days a week
- 03A shortlist of 3–5 after the call
- 04Fractional, interim and permanent briefs
Pick a day that suits · live availability
Live roles · last 3 months
Live Technology leadership jobs
Live CTO, CIO and CISO roles
How fractional recruitment agencies compare is set out in one place, including how we work: a CTO and CIO brief and a shortlist of three to five.
01/ the role
Technology audit: what it covers
A technology audit looks at the whole of a business’s technology, not one system. It asks whether what you have can support the plan, what it really costs, where the risks sit, and whether the right people are in charge of it. The person who runs it should have held the seat: a CTO for a product or software business, a CIO or IT Director where technology supports the operation.
Architecture
How the systems fit together, where they depend on each other, and what breaks first as usage grows. The audit names the parts that are hard to change and the parts that only one person understands.
Code and delivery
How work gets from an idea to production: code quality, testing, release process, and how often changes fail. It also checks who owns the code. Under UK law a contractor or agency usually keeps the copyright in what it writes unless the contract says otherwise, so the Intellectual Property Office’s guide to ownership of copyright works is worth reading before the audit asks for the contracts.
Infrastructure and cloud cost
Hosting, environments, monitoring and the monthly bill: what is running, who uses it and what could be switched off or resized. The NCSC’s cloud security guidance sets out how to choose, configure and use cloud services securely, and the audit checks your set-up against it.
Security
Access, patching, configuration, incident response and supplier risk. The NCSC’s 10 Steps to Cyber Security is a sound frame for a medium or large organisation. For a smaller one, Cyber Essentials is the minimum standard the government recommends, and a growing number of organisations require it of suppliers bidding for work.
Data
What personal and business data you hold, where it lives, who can reach it and how long you keep it. The ICO’s guide to accountability and governance expects you to be able to show how you comply with UK GDPR, with records of processing, written contracts with processors and a record of breaches. The audit checks whether that evidence exists.
Suppliers, contracts, team and roadmap
Which suppliers you depend on, when their contracts renew and how hard they are to leave. Whether the team has the skills the plan needs, and where one person holds knowledge nobody else has. Finally, whether the roadmap is realistic for the team and the budget you have.
02/ scope
IT audit: the operations view
An IT audit is the part of a technology audit that looks at how the business runs day to day, rather than what it builds. It suits a business whose technology is mostly bought in: offices, staff laptops, business applications and the suppliers who look after them. A CIO or IT Director usually runs it.
Systems and licences
A list of every system and application in use, who owns each one, and what the business pays for it. Licences are checked against real users, so seats nobody uses and tools that overlap show up.
Backups and recovery
Whether the important data is backed up, whether a backup has ever been restored, and how long the business could run without each system. The NCSC’s guide on backing up your data for small organisations is a practical checklist to start from.
Access and joiners and leavers
Who has access to what, whether admin rights are limited to the people who need them, and whether leavers lose access on their last day. Multi-factor authentication is checked on every system that supports it.
Service desk and suppliers
How staff get help, how long problems take to fix, and what the managed service provider has actually agreed to deliver. Contracts are read for notice periods, exit terms and who holds the passwords and the data at the end.
Who runs the audit
We place the practitioner who runs it. Every candidate goes through our five-stage vetting first: qualification, mandate fit, references, shortlist and kick-off. If the practitioner works through their own company, the off-payroll working rules (IR35) may apply. Status is decided by how the engagement runs, and a medium or large client makes the determination; our IR35 guide sets out the tests.
03/ comparison
Technology audit vs IT audit vs technology due diligence
Three reviews that overlap. Choose by the question you need answered and who will read the answer.
04/ vetting
How we vet fractional CTOs and CIOs
What we undertake on every brief, before a candidate reaches you.
- 01
Qualification screen
Verify CTO and CIO tenure, sector context and stage fit.
SOURCING - 02
Mandate fit
Match to your situation — stage, board dynamics, timing.
MATCHING - 03
Reference deep-dive
We take references ourselves, from recent past clients — real outcomes, not titles.
VERIFY - 04
Shortlist
Three to five candidates with day rate, availability and IR35 position set out.
SHORTLIST OF 3–5
05/ what you get from a technology audit
What you get from a technology audit: findings in order, and a leadership recommendation
The main output is a prioritised findings report. Each finding says what the practitioner found, the evidence, the risk or cost of leaving it, and what to do about it. Findings are ranked so the first page tells the board what to fix now, what can wait and what to stop spending on.
The second output is a leadership recommendation: who should own the work that follows. Sometimes the answer is the current team with a clearer brief. Often it is a senior technology leader, and the report says which route fits. A fractional CTO or CIO suits a business that needs senior judgement for part of the week. An interim leader suits a large programme or an empty seat. A permanent hire suits a business that needs an owner every day; see our CTO headhunter page for that route.
The report should also be something the board can use. The NCSC’s Cyber Security Toolkit for Boards helps a board ask the right questions about cyber risk, and a good audit answers them in plain English. If the audit is a step towards a raise or a sale, read our page on technology due diligence as well.
06/ hire a fractional CTO or CIO
Hire a fractional CTO or CIO after the audit
An audit that nobody acts on changes nothing. The practitioner who ran it already knows the systems and the people, so the simplest next step is often to keep them on for a few days a week to lead the fixes. You are not obliged to: the findings are yours, and you can hire someone else to carry them out.
For a product or software business, hire a fractional CTO to own architecture, engineering and the roadmap. Where technology supports the operation, hire a fractional CIO to own systems, suppliers and data. For hands-on IT operations in a smaller business, a fractional IT Director may be the better fit. If security is the main finding, look at a fractional CISO.
We send a shortlist of 3–5, each with day rate, availability and IR35 position set out. Sourced day-rate bands for each seat are on our day rates page.
07/ questions
Technology audit FAQ
The questions people ask before bringing in a fractional CTO or CIO.

Book 15 minutes · shortlist of 3–5
Bring the brief. We architect the team.
A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.
