Preparation

What belongs in an application inventory before auditors arrive

Spreadsheet and handwritten notes for an application inventory

An audit of applications rarely collapses because someone forgot a fancy framework diagram. It stalls when nobody can agree which systems are in scope, who owns them, or whether “production” includes the plant-floor terminal that still posts to the ledger.

Start with names people use

List applications the way operators refer to them on the floor, then map vendor product names beside them. Auditors will ask both. Include batch jobs and reporting layers that change financial or inventory figures even if nobody calls them “applications” in the budget binder.

Owners must be humans

Assign a named owner and a deputy. “IT department” is not an owner. When leave schedules hit Golden Week, deputies keep evidence moving.

Environments that matter

Note production, standby, and any plant-specific configuration. If two plants share a vendor instance but keep separate role catalogues, say so. That distinction drives sample sizes later.

Fields worth keeping current

Criticality (why the business needs it), data classes handled, last restore test date, and the vendor support contact. Skip decorative columns that nobody updates.

Bring this inventory to your first scoping call with Software Hub Audit Co. It shortens the path to a clean scope letter.