
An asset audit must produce a verified count: what was in scope, the date, who carried it out, which items were confirmed present, which were not, and a sign-off. A register export is not an audit, because nothing in it was physically checked.
There's a particular phone call I used to get as an auditor, usually about a week before a deadline. Someone has realised their asset register and an asset audit aren't the same thing, and they're hoping I'll tell them otherwise.
I can't, so let me save you the call.
A register is a belief. A count is a verification.
Your register records what you believe you own. It's assembled from purchases, imports and updates, and it's correct in proportion to how well it has been maintained.
A count records what somebody physically confirmed was present, on a specific date, having looked at it. Those are different claims, and only the second satisfies anyone external.
Exporting the register to a spreadsheet and calling it an inventory is the most common way this goes wrong, and it's obvious to anyone who has done this before — there's no date, no counter, and no discrepancies, because nothing was checked.
What the audit output must contain
|
Element |
Why it is required |
Common failure |
|---|---|---|
|
Scope |
Defines what the assurance covers — and what it does not |
Implied rather than stated, so coverage is unclear |
|
Date |
Assurance is a point-in-time claim |
Missing entirely on a register export |
|
Counter and sign-off |
Attributes the verification to a person |
No named individual, so nobody stands behind it |
|
Verified items |
The positive assurance |
Conflated with 'all records', which verifies nothing |
|
Discrepancies |
The finding — often the point of the exercise |
Omitted, leaving a suspiciously clean result |
|
Actions and outcomes |
Shows the finding was acted on |
Recorded nowhere, so the next audit repeats it |
If your system produces a number but not that document, somebody will build the document by hand, and that's where both the time and the errors come from.
*A count as a scoped exercise with a result: verified and missing tracked per item, closing with a sign-off.*
Scope it so it survives a working year
The instinct is an annual full count. It's also why audits get postponed: a full count needs a block of time nobody has, so it slips until it's urgent and then gets done badly.
Cycle counting scopes to one location, category or department and runs in an afternoon, repeatedly. Over twelve months the coverage is identical.
|
Approach |
Effort |
Discrepancy age when found |
Recoverability |
|---|---|---|---|
|
Annual full count |
A week, all at once |
Up to 12 months |
Low — the trail is cold |
|
Quarterly by department |
A day per quarter |
Up to 3 months |
Moderate |
|
Monthly by location |
An afternoon |
Weeks |
High — often still findable |
The real benefit isn't effort. It's that discrepancies surface while somebody still remembers what happened, which is the difference between a finding and a write-off.
Count live
Don't stop operations to do it. A count that requires the business to pause will be scheduled into a quiet week that never arrives, and reconciling the movements that happened during the count is a far smaller problem than the count never happening.
The discrepancies are the point
A count that produces a number and no actions has cost you a day and changed nothing. Each discrepancy should resolve into one of four outcomes:
- Found elsewhere — the register was wrong. Correct it, and ask why it drifted.
- In somebody's custody — issued and not recorded, or recorded and not scanned. A process gap worth understanding.
- Genuinely missing — write it off, and note where and when it was last seen. That pattern is data.
- Should never have been in scope — retired, sold or transferred, and never closed.
That fourth category is always larger than expected on a first audit, and clearing it makes every subsequent count faster.
Look at where discrepancies cluster rather than at the total. One location or one category accounting for most of them tells you where the process is broken, which is worth considerably more than the write-off figure.
Who should count, and why it matters more than you'd think
Wherever the organisation is large enough to allow it, the person counting shouldn't be the custodian of what they're counting. This isn't about suspicion. It's that a custodian counting their own area knows where everything is supposed to be, and knowing is exactly what you're trying not to rely on.
It's also the first thing a reviewer asks. Self-verification gets discounted, and you'll have spent the day for nothing.
In a small organisation, independence may genuinely not be available. If so, say so in the report rather than hoping nobody notices — a stated limitation is far better received than one that's discovered.
Handling the awkward categories
Every count runs into the same four edge cases, and deciding how to treat them before you start saves an argument at the end.
|
Category |
Treat as |
Evidence needed |
|---|---|---|
|
Issued to a named person |
Verified, if evidenced |
The custody record, ideally with a signature |
|
Out for repair |
Verified, if evidenced |
The maintenance record or a supplier note |
|
At another site in scope |
Verified where it is |
Scanned at its actual location |
|
At a site out of scope |
Excluded, stated explicitly |
Note it, don't count it as missing |
|
Loaned to a third party |
Verified, if evidenced |
The loan record; otherwise treat as not found |
The rule underneath all of those: something is verified when there's a record placing it somewhere specific, not when somebody believes it's fine.
How long a count actually takes
People overestimate this badly, which is why it gets deferred.
Scanning is roughly five to ten seconds per item including walking between them, so 200 items in a single location is well under an hour. What consumes the time isn't counting — it's reconciling afterwards, and reconciliation time is proportional to how wrong the register was, not to how many items you checked.
Which produces a useful feedback loop. The first count is slow because it surfaces years of accumulated drift. The third is quick because there's less to explain, and that improvement is itself evidence the process is working.
Evidence that stands up
- Each item recorded verified or missing at the point of checking, not reconstructed afterwards.
- The counter identified, and the count signed at close.
- Findings retained against the assets, so the next audit can see whether they were resolved.
- An export that can be filed by whoever asked, without reformatting.
Key takeaways
- An audit is a verified count, not a register export — the difference is that somebody physically looked.
- Required elements: scope, date, named counter and sign-off, verified items, discrepancies, and actions.
- Cycle counting gives the same annual coverage without losing a week, and finds discrepancies while they are still recoverable.
- Never pause operations for a count; reconcile the movements instead.
- Where discrepancies cluster matters more than the total — that is the broken process.
Frequently asked questions
What is the difference between an asset register and an asset audit?
The register is what you believe you own, assembled from records. The audit is what somebody physically verified was present, on a date, with the discrepancies recorded. Only the second constitutes assurance, which is why a register export doesn't satisfy an auditor.
How often should a physical asset audit be done?
At least annually for the estate as a whole, but far better achieved through cycle counts scoped by location or department through the year. The coverage is the same and discrepancies are found while they're recent enough to resolve.
What does an auditor look for in an asset audit?
That the scope was defined, the count was carried out on a stated date by an identified person, each item was individually verified or recorded missing, discrepancies were captured rather than smoothed over, and the findings were acted on afterwards.
Can asset audits be done from a mobile phone?
Yes, and it's the practical way to do one. Scanning each item where it stands records the verification at the moment of checking rather than transcribing a clipboard afterwards, which is where most counting errors are introduced.
What should happen to items found missing during an audit?
Each should resolve into one of four outcomes: found elsewhere, in someone's custody, genuinely missing, or out of scope because it was retired or sold. Record where and when a genuinely missing item was last seen — the pattern across audits is often more informative than the individual loss.