Skip to content
TSCM Audit

TSCM audit checklist

Use this checklist to scope an audit properly: which spaces and systems to include, how often each should be inspected, and the questions that quickly reveal whether a provider is professional.

1. What to include in scope

Devices are placed where valuable conversations happen and where access is easy. A well-scoped corporate audit covers:

  • Boardrooms, meeting rooms, and executive offices
  • Deal rooms, legal war rooms, and HR interview rooms
  • Executive assistants' desks and adjacent circulation areas
  • Video-conferencing and AV equipment, including installed microphones
  • Telephone systems, VoIP infrastructure, and conference phones
  • Wi-Fi environment: authorised access points versus what is actually broadcasting
  • Network cupboards, patch panels, and unexplained devices on switches
  • Power sockets, extension leads, chargers, and desktop peripherals
  • Ceiling voids, raised floors, and service ducts in sensitive rooms
  • Furniture, fittings, plants, and gifts or awards introduced by third parties
  • Executive vehicles and, where relevant, home offices
  • Hotel suites and off-site venues before sensitive meetings

For private engagements, translate the same logic to living spaces, bedrooms, home offices, vehicles, and any recently gifted or serviced electronics — details in the private TSCM audit overview.

2. How often to audit

Frequency should track risk, not the calendar alone. These are the working defaults used across the industry:

SpaceRecommended frequency
Boardroom / deal roomQuarterly, plus pre-meeting sweeps before sensitive sessions
Executive suite and officesQuarterly to bi-annually, based on threat profile
General corporate officesAnnually as a baseline
R&D and IP-sensitive areasQuarterly, and after any contractor access
Executive vehiclesBi-annually, and after servicing or valeting by new suppliers
Private residenceAnnually, or immediately on specific suspicion
Any space after building worksOne-off audit before returning to sensitive use

On top of the schedule, audit immediately after: a suspected leak, a departure of personnel with access to sensitive areas, building or fit-out works, and before mergers, acquisitions, results announcements, or litigation.

3. Questions to ask any provider

  • What equipment do you operate? (Expect broadband spectrum analysers, NLJD, and thermal imaging — not handheld consumer detectors.)
  • Do you detect dormant and hard-wired devices, or only active transmitters?
  • Do Wi-Fi and network checks form part of the audit?
  • What does the written report include, and can it support legal or insurance processes?
  • Who performs the work, and what is their background and training?
  • How do you handle a live find — removal, evidence preservation, law enforcement?
  • Can you operate out of hours and without alerting staff?
  • Do you provide indicative pricing before engagement?

If a provider stumbles on equipment, dormant-device detection, or reporting, you are looking at a bug sweep dressed up as an audit. Pricing context is in the cost guide.

4. Before the team arrives

  • Keep knowledge of the audit to the minimum number of people.
  • Do not discuss the audit in the spaces being audited or on potentially compromised systems.
  • Prepare floor plans, a list of authorised Wi-Fi networks and AV equipment, and access arrangements for out-of-hours work.
  • Nominate a single point of contact to receive findings.

Ready to commission a TSCM audit?

Tell us about your site and concern. You will receive indicative pricing and a named follow-up from TSCM Partners, in confidence.