TSCM audit checklist
Use this checklist to scope an audit properly: which spaces and systems to include, how often each should be inspected, and the questions that quickly reveal whether a provider is professional.
1. What to include in scope
Devices are placed where valuable conversations happen and where access is easy. A well-scoped corporate audit covers:
- Boardrooms, meeting rooms, and executive offices
- Deal rooms, legal war rooms, and HR interview rooms
- Executive assistants' desks and adjacent circulation areas
- Video-conferencing and AV equipment, including installed microphones
- Telephone systems, VoIP infrastructure, and conference phones
- Wi-Fi environment: authorised access points versus what is actually broadcasting
- Network cupboards, patch panels, and unexplained devices on switches
- Power sockets, extension leads, chargers, and desktop peripherals
- Ceiling voids, raised floors, and service ducts in sensitive rooms
- Furniture, fittings, plants, and gifts or awards introduced by third parties
- Executive vehicles and, where relevant, home offices
- Hotel suites and off-site venues before sensitive meetings
For private engagements, translate the same logic to living spaces, bedrooms, home offices, vehicles, and any recently gifted or serviced electronics — details in the private TSCM audit overview.
2. How often to audit
Frequency should track risk, not the calendar alone. These are the working defaults used across the industry:
| Space | Recommended frequency |
|---|---|
| Boardroom / deal room | Quarterly, plus pre-meeting sweeps before sensitive sessions |
| Executive suite and offices | Quarterly to bi-annually, based on threat profile |
| General corporate offices | Annually as a baseline |
| R&D and IP-sensitive areas | Quarterly, and after any contractor access |
| Executive vehicles | Bi-annually, and after servicing or valeting by new suppliers |
| Private residence | Annually, or immediately on specific suspicion |
| Any space after building works | One-off audit before returning to sensitive use |
On top of the schedule, audit immediately after: a suspected leak, a departure of personnel with access to sensitive areas, building or fit-out works, and before mergers, acquisitions, results announcements, or litigation.
3. Questions to ask any provider
- What equipment do you operate? (Expect broadband spectrum analysers, NLJD, and thermal imaging — not handheld consumer detectors.)
- Do you detect dormant and hard-wired devices, or only active transmitters?
- Do Wi-Fi and network checks form part of the audit?
- What does the written report include, and can it support legal or insurance processes?
- Who performs the work, and what is their background and training?
- How do you handle a live find — removal, evidence preservation, law enforcement?
- Can you operate out of hours and without alerting staff?
- Do you provide indicative pricing before engagement?
If a provider stumbles on equipment, dormant-device detection, or reporting, you are looking at a bug sweep dressed up as an audit. Pricing context is in the cost guide.
4. Before the team arrives
- Keep knowledge of the audit to the minimum number of people.
- Do not discuss the audit in the spaces being audited or on potentially compromised systems.
- Prepare floor plans, a list of authorised Wi-Fi networks and AV equipment, and access arrangements for out-of-hours work.
- Nominate a single point of contact to receive findings.