Public Utility IT Audit Checklist
Use this checklist to assess IT controls, operational readiness, and remediation needs across the public utility systems in scope.
Audit Metadata
Audit Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Auditor Name
*
Utility / Department Name
*
Audit Type
*
Internal
External
Follow-up
Spot Check
Audit Period Covered
*
Scope and Environment
Utility Service Area / Operation
*
Systems in Scope
*
Billing
SCADA/OT
GIS
Outage Management
Email/Collaboration
ERP
Identity Management
Network Infrastructure
Backups
Endpoints
Other
Environment Type
*
On-Premises
Cloud
Hybrid
OT/SCADA
Mixed
Other
Number of Sites or Locations in Scope
*
Primary Critical System(s)
Access Management
Is user access reviewed regularly?
*
Yes
No
Is multi-factor authentication required for privileged and remote access?
*
Yes
No
Are shared accounts in use?
*
Yes
No
Privileged account review status
*
Please Select
Compliant
Partial
Non-compliant
User access review evidence and exceptions
Security Operations and Technical Controls
Patch Management Status
*
Implemented
Partially implemented
Not implemented
Not applicable
Vulnerability Scanning Status
*
Implemented
Partially implemented
Not implemented
Not applicable
Endpoint Protection Status
*
Implemented
Partially implemented
Not implemented
Not applicable
Network Segmentation and Firewall Status
*
Implemented
Partially implemented
Not implemented
Not applicable
Logging and Monitoring Status
*
Implemented
Partially implemented
Not implemented
Not applicable
Remote Access Security Status
*
Implemented
Partially implemented
Not implemented
Not applicable
Evidence / Notes
Backup, Recovery, and Continuity
Backup Frequency
*
Daily
Weekly
Monthly
Ad hoc
Other
Backup Test Status
*
Passed
Failed
Pending
Not Tested
Other
Last Successful Restore Test Date
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Offsite or Immutable Backup Present
*
Yes
No
Recovery Time Objective Met
*
Yes
No
Partial
Not Assessed
Continuity Plan Available for Critical Systems
*
Yes
No
Incident Response and Change Management
Incident response plan available?
*
Yes
No
Date of last incident drill or tabletop
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Open security incidents affecting audit scope
Change management approval process followed?
*
Yes
No
Partially
Not applicable
Evidence or notes for emergency changes or unresolved incidents
Compliance Evidence and Findings
Audit findings
*
Overall IT audit posture
1
2
3
4
5
Follow-up Actions and Reviewer Sign-off
Corrective Actions Required
*
Responsible Team or Contact Role
*
Target Completion Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Follow-up Review Needed
*
Yes
No
Reviewer Comments
Final Audit Outcome
*
Please Select
Pass
Pass with Findings
Fail
Needs Re-audit
Submit Audit Checklist
Should be Empty: