Back to all articles
Turning an IT Audit into an Achievable Improvement Plan
IT Strategy and Budgeting
6 August 20267 min read

Turning an IT Audit into an Achievable Improvement Plan

aS

asitplan Strategy Team

Author

RL

Rob Lloyd

Technical Reviewer

06 August 2026

Last Reviewed

Project managers, IT leads, and business leaders

Target Audience

The Context

It is common for schools to invest in comprehensive IT audits, receive a detailed report highlighting numerous vulnerabilities, and then fail to act on the findings. The gap between receiving an audit and executing a remediation plan is where most schools stall, often overwhelmed by the sheer volume of technical debt identified.

Who This Guide is For

Project managers, IT leads, and school business leaders tasked with executing post-audit improvements.

Why This Matters

An unactioned audit is a significant liability. If a school is breached or suffers a major outage, and an earlier audit report shows that the leadership team was aware of the specific vulnerability but did nothing, it represents a severe failure of governance.

What Good Looks Like

A structured improvement plan breaks down the monolithic audit report into manageable, sequenced phases. It assigns clear ownership, establishes realistic timelines based on available budget and staff capacity, and provides regular progress updates to the board.

Approach and Methodology

  1. Triage the Findings: Not everything is a priority one. Categorise the audit findings into: Critical (Immediate risk to safeguarding/security), High (Major operational impact), Medium (Best practice/efficiency), and Low (Cosmetic).
  2. Identify Dependencies: You cannot deploy a new cloud-based phone system if your core broadband is failing. Map the technical dependencies before sequencing the work.
  3. Phase the Delivery: Break the work into distinct phases (e.g., Phase 1: Security and Identity Foundation; Phase 2: Infrastructure Upgrades; Phase 3: Device Refresh).
  4. Assign Ownership: Every action must have a named owner. 'The IT Team' is not an owner; 'The Network Manager' is.
  5. Cost the Phases: Attach realistic capital and operational costs to each phase. If funding is unavailable for a critical phase, the board must formally accept the risk in the interim.
  6. Establish the Rhythm: Implement a monthly steering group meeting to track progress against the plan, unblock issues, and report back to the governors.

Evidence to Retain

  • The formal IT Improvement Project Plan (often a Gantt chart or Kanban board).
  • A documented Risk Register showing how audit risks are being mitigated over time.
  • Monthly steering group meeting minutes and status reports.

Questions Leadership Should Ask

  • "What are the specific technical dependencies preventing us from resolving our highest priority risks?"
  • "Do we have the internal capacity and skill sets to deliver this improvement plan, or do we need to procure external project management?"

Common Pitfalls

  • Trying to Do Everything at Once: Attempting to run a major network upgrade, a server migration, and a device rollout simultaneously, leading to project collapse and staff burnout.
  • Losing Momentum: The project starts strong but fizzles out after the first few 'easy wins' are completed, leaving the complex, critical issues unresolved.
  • Scope Creep: Adding new 'nice to have' features into the remediation project, delaying the resolution of the original audit findings.

How asitplan Can Help

asitplan allows you to directly import audit findings and map them as actionable tasks against your asset register. It provides a visual, trackable dashboard, transforming a static PDF audit into a live, manageable improvement project that leadership can monitor effortlessly.

Ready to simplify your school's IT compliance?

asitplan provides the unified dashboard and automated reporting you need to stay ahead of DfE standards and KCSIE updates.