Preparation
What belongs in an application inventory before auditors arrive
An audit of applications rarely collapses because someone forgot a fancy framework diagram. It stalls when nobody can agree which systems are in scope, who owns them, or whether “production” includes the plant-floor terminal that still posts to the ledger.
Start with names people use
List applications the way operators refer to them on the floor, then map vendor product names beside them. Auditors will ask both. Include batch jobs and reporting layers that change financial or inventory figures even if nobody calls them “applications” in the budget binder.
Owners must be humans
Assign a named owner and a deputy. “IT department” is not an owner. When leave schedules hit Golden Week, deputies keep evidence moving.
Environments that matter
Note production, standby, and any plant-specific configuration. If two plants share a vendor instance but keep separate role catalogues, say so. That distinction drives sample sizes later.
Fields worth keeping current
Criticality (why the business needs it), data classes handled, last restore test date, and the vendor support contact. Skip decorative columns that nobody updates.
Bring this inventory to your first scoping call with Software Hub Audit Co. It shortens the path to a clean scope letter.