RAAL Logo

Preparing for an ISO 27001 or SOC 2 Audit When Your Devices Are in 15 Countries

Andres KõivaSeptember 22, 2026
7 MIN READ
Audit Readiness
Preparing for an ISO 27001 or SOC 2 Audit When Your Devices Are in 15 Countries

TL;DR

An ISO 27001 or SOC 2 audit does not just ask whether you have an asset inventory, it asks whether you can prove it is current, and prove what happened to devices that left the company. For distributed teams, that proof is harder to produce than most people expect: it means chain-of-custody evidence for every shipment, wipe verification for every returned device, and a register that reflects reality today, not a spreadsheet last updated in March. This guide covers what auditors actually ask for and how to have it ready without a scramble the week before the review.

An auditor does not ask "do you have an asset inventory." They ask you to prove it. Pull up the record for this specific laptop. Show me when it was assigned, to whom, and where it is now. Show me what happened to the device this person had before they left. Show me the wipe confirmation.

For an office-based company, most of that is a walk to a locked cabinet. For a distributed team with devices in fifteen countries, it is a genuinely different exercise, and it is the part most IT teams have not actually built a process for.

Why Distributed IT Assets Complicate Audits

Audit frameworks like ISO 27001 and SOC 2 were not written with distributed hardware specifically in mind, but their underlying requirement, demonstrable, current, verifiable control over company assets, applies just as much to a laptop in Lisbon as one on an office desk. The difficulty is not the requirement itself. It is that most of the systems distributed teams already have were not built to produce that evidence on demand.

A spreadsheet someone updates when they remember to is not evidence, it is a claim. A shipment that happened six months ago with no surviving tracking record is not evidence either, once the courier's own retention window has passed. The gap between "we generally know where our devices are" and "here is the specific, timestamped record for this device" is exactly where audits go wrong.

What Auditors Actually Ask For

EVIDENCE TYPE WHAT'S TYPICALLY REQUESTED WHERE DISTRIBUTED TEAMS STRUGGLE
Asset inventory Full list of company-owned devices, current holder, and location Manually maintained lists go stale within weeks of the last update
Assignment history Who has held a specific device, and when it changed hands Reassignments are rarely logged with a timestamp unless the system enforces it
Offboarding evidence Proof a departing employee's device was retrieved Retrieval status often lives in an email thread, not a structured record
Data destruction proof Certificate confirming a returned or retired device was wiped Wipe confirmation is easy to skip when a device is quietly redeployed
Chain of custody Continuous record of a device's location during shipping Courier tracking numbers expire; nothing is kept in the company's own system

Notice the pattern: auditors are not asking for a policy document that says you do these things. They are asking for the specific record proving you did, for a specific device, on a specific date.

Building an Audit-Ready Asset Register

WHAT AN AUDIT-READY RECORD ACTUALLY REQUIRES

  1. Every device has one canonical record. Not a spreadsheet row that gets copied and drifts, a single live entry that updates when the device's status changes.
  2. Assignment changes are logged automatically. When a device moves from one employee to another, the record updates itself as part of that workflow, not as a separate manual task someone might forget.
  3. Shipping events are retained, not just tracked in the moment. A courier's tracking page disappearing after 90 days is fine for the courier. It is not fine as your only audit evidence a year later.
  4. Wipe and destruction events are certificated, not assumed. A returned device should have a specific, dated confirmation that it was wiped, redeployed, or disposed of, tied to that device's serial number.
  5. Someone outside your team can verify it without asking you first. If producing evidence for an auditor requires a scramble to reconstruct records from email and Slack, the system is not actually audit-ready, regardless of how good the underlying process is.

This is what "100% of operations auditable" means on Raal's own homepage. Every shipment, every reassignment, and every retrieval logged automatically, with delivery confirmation and wipe verification tied to the specific device, viewable directly by an auditor if you choose to give them access. Get a live estimate.

Common Findings for Distributed Teams, and How to Avoid Them

The most common audit finding for distributed IT fleets is not fraud or negligence, it is simply staleness. A device the register says is "with Employee X" who left the company four months ago. A retrieval marked "complete" with no delivery confirmation attached. A wipe that was performed but never documented. None of these are dramatic failures. All of them are exactly the kind of gap an auditor is trained to find, and exactly the kind of gap that is cheap to close if the underlying process logs things automatically instead of relying on someone remembering to update a sheet.

Related: IT Asset Disposal and ITAD for Remote Teams in Europe

Related: IT Device Security for Remote Employees: A Practical Guide for 2026

Related: Remote Employee Laptop Return Policy: What EU and UK Law Actually Allows

FAQ

What does ISO 27001 actually require for hardware asset management?

ISO 27001's Annex A controls require organisations to maintain an inventory of assets, including hardware, with clear ownership and handling requirements throughout the asset's lifecycle, from acquisition to disposal. In practice, this means being able to show current, accurate records of what devices exist, who holds them, and what happened to them at end of life, not just a policy stating that this is done.

Does SOC 2 require the same kind of asset evidence?

SOC 2's security and confidentiality criteria expect organisations to demonstrate control over assets that could affect the security of customer data, which includes employee laptops. Auditors typically request evidence of device provisioning, assignment tracking, and secure decommissioning, similar in substance to ISO 27001, even though the frameworks are structured differently.

What's the fastest way to fix a stale asset register before an audit?

There is rarely a fast fix, which is exactly the problem with treating this as a pre-audit task. A register reconstructed from email threads and best guesses in the two weeks before a review is fragile under questioning. The reliable fix is a system that logs assignment changes, shipments, and wipes automatically as they happen, so there's nothing to reconstruct when the audit request arrives.

Can an auditor be given direct access to a device register instead of receiving exports?

Yes, and it is generally a stronger position than providing periodic exports. Direct, read-only access to a live system demonstrates the record is current and not curated for the audit specifically. Whether this is practical depends on the platform, some are built for it, others only produce static reports on request.


About Raal: Raal maintains a live, automatically updated asset register for every device it ships or retrieves, holder, location, condition, and history, with chain-of-custody and wipe verification built in. Direct auditor access available on request. Get a live estimate.

Andres Kõiva

What auditors actually ask for when your device fleet is spread across countries, and how to have the evidence ready before they ask, not after.

Keep Reading