Technology audit · IT audit · Led by a senior CTO or CIO

Technology audit · what to fix, in what order, and who should lead it

A technology audit is an independent review of how a business builds, runs and pays for its technology: architecture, code and delivery, infrastructure and cloud cost, security, data, suppliers and contracts, the team and the roadmap. It ends in a prioritised list of what to fix, in what order, and who should lead the work.

We deliver it by placing a senior practitioner, a fractional or interim CTO or CIO, who runs the audit inside your business and writes the findings. If the findings say you need a technology leader, you can hire a fractional CTO or CIO to carry them out. Before anyone starts, we send a shortlist of 3–5, each with day rate, availability and IR35 position set out, after five-stage vetting.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

3–5
Shortlist · with day rate, availability and IR35 set out
5
Vetting · stages before a practitioner reaches you

15 minutes · video or phone

Book 15 minutes to hire a fractional CTO or CIO

Tell us the scope and the days a week. We come back with CTO and CIO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

Live CTO, CIO and CISO roles

How fractional recruitment agencies compare is set out in one place, including how we work: a CTO and CIO brief and a shortlist of three to five.

01/ the role

Technology audit: what it covers

A technology audit looks at the whole of a business’s technology, not one system. It asks whether what you have can support the plan, what it really costs, where the risks sit, and whether the right people are in charge of it. The person who runs it should have held the seat: a CTO for a product or software business, a CIO or IT Director where technology supports the operation.

Architecture

How the systems fit together, where they depend on each other, and what breaks first as usage grows. The audit names the parts that are hard to change and the parts that only one person understands.

Code and delivery

How work gets from an idea to production: code quality, testing, release process, and how often changes fail. It also checks who owns the code. Under UK law a contractor or agency usually keeps the copyright in what it writes unless the contract says otherwise, so the Intellectual Property Office’s guide to ownership of copyright works is worth reading before the audit asks for the contracts.

Infrastructure and cloud cost

Hosting, environments, monitoring and the monthly bill: what is running, who uses it and what could be switched off or resized. The NCSC’s cloud security guidance sets out how to choose, configure and use cloud services securely, and the audit checks your set-up against it.

Security

Access, patching, configuration, incident response and supplier risk. The NCSC’s 10 Steps to Cyber Security is a sound frame for a medium or large organisation. For a smaller one, Cyber Essentials is the minimum standard the government recommends, and a growing number of organisations require it of suppliers bidding for work.

Data

What personal and business data you hold, where it lives, who can reach it and how long you keep it. The ICO’s guide to accountability and governance expects you to be able to show how you comply with UK GDPR, with records of processing, written contracts with processors and a record of breaches. The audit checks whether that evidence exists.

Suppliers, contracts, team and roadmap

Which suppliers you depend on, when their contracts renew and how hard they are to leave. Whether the team has the skills the plan needs, and where one person holds knowledge nobody else has. Finally, whether the roadmap is realistic for the team and the budget you have.

02/ scope

IT audit: the operations view

An IT audit is the part of a technology audit that looks at how the business runs day to day, rather than what it builds. It suits a business whose technology is mostly bought in: offices, staff laptops, business applications and the suppliers who look after them. A CIO or IT Director usually runs it.

Systems and licences

A list of every system and application in use, who owns each one, and what the business pays for it. Licences are checked against real users, so seats nobody uses and tools that overlap show up.

Backups and recovery

Whether the important data is backed up, whether a backup has ever been restored, and how long the business could run without each system. The NCSC’s guide on backing up your data for small organisations is a practical checklist to start from.

Access and joiners and leavers

Who has access to what, whether admin rights are limited to the people who need them, and whether leavers lose access on their last day. Multi-factor authentication is checked on every system that supports it.

Service desk and suppliers

How staff get help, how long problems take to fix, and what the managed service provider has actually agreed to deliver. Contracts are read for notice periods, exit terms and who holds the passwords and the data at the end.

Who runs the audit

We place the practitioner who runs it. Every candidate goes through our five-stage vetting first: qualification, mandate fit, references, shortlist and kick-off. If the practitioner works through their own company, the off-payroll working rules (IR35) may apply. Status is decided by how the engagement runs, and a medium or large client makes the determination; our IR35 guide sets out the tests.

03/ comparison

Technology audit vs IT audit vs technology due diligence

Three reviews that overlap. Choose by the question you need answered and who will read the answer.

Technology auditIT auditTechnology due diligence
QuestionCan our technology support the plan, and what should we fix first?Is our day-to-day IT safe, sound and good value?What are we buying or investing in, and what could go wrong?
CoversArchitecture, code, cloud, security, data, suppliers, team, roadmapSystems, licences, backups, access, service desk, suppliersThe same ground, read for risk, value and the deal terms
Usually led byA fractional or interim CTO or CIOA CIO or IT DirectorAn interim or fractional CTO
Read byThe CEO and the boardThe COO, finance lead or boardThe investor or buyer, or the seller preparing for them

04/ vetting

How we vet fractional CTOs and CIOs

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify CTO and CIO tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

05/ what you get from a technology audit

What you get from a technology audit: findings in order, and a leadership recommendation

The main output is a prioritised findings report. Each finding says what the practitioner found, the evidence, the risk or cost of leaving it, and what to do about it. Findings are ranked so the first page tells the board what to fix now, what can wait and what to stop spending on.

The second output is a leadership recommendation: who should own the work that follows. Sometimes the answer is the current team with a clearer brief. Often it is a senior technology leader, and the report says which route fits. A fractional CTO or CIO suits a business that needs senior judgement for part of the week. An interim leader suits a large programme or an empty seat. A permanent hire suits a business that needs an owner every day; see our CTO headhunter page for that route.

The report should also be something the board can use. The NCSC’s Cyber Security Toolkit for Boards helps a board ask the right questions about cyber risk, and a good audit answers them in plain English. If the audit is a step towards a raise or a sale, read our page on technology due diligence as well.

06/ hire a fractional CTO or CIO

Hire a fractional CTO or CIO after the audit

An audit that nobody acts on changes nothing. The practitioner who ran it already knows the systems and the people, so the simplest next step is often to keep them on for a few days a week to lead the fixes. You are not obliged to: the findings are yours, and you can hire someone else to carry them out.

For a product or software business, hire a fractional CTO to own architecture, engineering and the roadmap. Where technology supports the operation, hire a fractional CIO to own systems, suppliers and data. For hands-on IT operations in a smaller business, a fractional IT Director may be the better fit. If security is the main finding, look at a fractional CISO.

We send a shortlist of 3–5, each with day rate, availability and IR35 position set out. Sourced day-rate bands for each seat are on our day rates page.

07/ questions

Technology audit FAQ

The questions people ask before bringing in a fractional CTO or CIO.

An independent review of a business’s technology: architecture, code and delivery, infrastructure and cloud cost, security, data, suppliers and contracts, the team and the roadmap. It ends in a prioritised findings report and a recommendation on who should lead the work that follows.

The operations side of a technology audit: systems and licences, backups and recovery, access, the service desk and the suppliers who run your IT. It suits a business whose technology is mostly bought in. A CIO or IT Director usually leads it.

A prioritised findings report, each finding with its evidence, its risk or cost and the fix, ranked so the board knows what to do first. And a leadership recommendation: whether the work needs a fractional, interim or permanent technology leader, or the current team with a clearer brief.

A senior practitioner we place: a fractional or interim CTO or CIO who has held the seat. They work inside your business, speak to your team and suppliers, and write the findings. Every candidate goes through our five-stage vetting first.

Decide which findings the leader will own and how many days a week that needs. Then brief us: we send a shortlist of 3–5, each with day rate, availability and IR35 position set out. See the hubs for a fractional CTO, a fractional CIO or a fractional IT Director.

It depends on the scope, the size of the estate and the practitioner’s day rate. We set out each candidate’s day rate on the shortlist, and our rate calculator multiplies a day rate by the days you need. Sourced bands by seat are on our day rates page.

They cover similar ground. An audit is for the business itself and asks what to fix. Due diligence is read by an investor or buyer and asks what could affect the deal. See technology due diligence.

Neither by default. Status is decided by how the engagement runs, contract by contract. If they work through their own company, a medium or large client makes the determination (HMRC). Our IR35 guide sets out the tests.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

Fractional Quest logo — how to hire a fractional CTO, technology audit