JJC SystemsBook a Consultation
Microsoft Intune · Audit

BYOD and personal device audit

Twenty checks on whether client confidences are protected on devices your firm does not own or control.

Why run this

What this checklist is for

Every firm has a policy about personal devices, and in most firms the practice is that a partner in an airport reads a matter email on their own phone.

A control that depends on senior people behaving differently from how they demonstrably behave is not a control.

Run it with

Risk partner

And with

IT lead

And with

A partner who genuinely uses their own phone for work

0 of 0 complete · 0%
The checklist

20 checks, in the order we would run them

Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.

Section 1

Reality

What is actually happening, as opposed to what policy states.

Section 2

Protection

What is applied to firm data on a device you do not manage.

Section 3

Departure

The scenario the whole arrangement exists for.

Section 4

Assurance

Whether you could evidence any of this.

What your score means

Read this against the number above

These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.

0–59%Significant gaps

Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.

60–84%Mostly ready, with known gaps

Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.

85–100%Ready

The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.

Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.

Closing the gaps

If you could not tick these, start here

The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.

Personal devices unmanaged and uncounted

Start with app protection rather than enrolment. It achieves the security outcome without the fight and can be deployed in days.

Selective wipe untested

Test it on a real device. Discovering it does not work during a partner's departure is the worst possible timing.

Policy does not reflect practice

Rewrite the policy to match observed behaviour and then control it. An unfollowed policy is worse than none in a negligence context.

Status assumed rather than reported

Read the compliance report. The gap between policy and applied state is usually meaningful.

Want a second opinion on your score?

We will assess your current position against what your professional indemnity insurer asks, and demonstrate app protection working on a real personal phone.

Talk through your result Read the related guides We reply to every message within one business day.
Keep going

Related checklists

Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.