A household can have many backups and still miss the one file that matters. Automatic phone upload may omit messages. A laptop backup may skip an external photo library. A cloud folder may retain only a short version history. An encrypted archive may be intact but unusable because its recovery key is stored on the failed computer.

This audit measures coverage, independence, and recoverability. It does not require opening every sensitive file or exposing passwords. Complete it from trusted devices during normal conditions. If ransomware, unknown access, or physical drive failure is suspected, stop attaching storage and use the ransomware stop rules.
Score the system by outcome
For each data set, assign:
- 0 - unknown: nobody can confirm where it is or whether it is backed up;
- 1 - fragile: one working copy or one unverified synchronized copy;
- 2 - partial: a second copy exists but off-site, isolation, retention, or access is weak;
- 3 - covered: independent local and off-site paths exist and recent status is known;
- 4 - recoverable: coverage is complete and a representative restore was tested.
Do not average away a critical zero. One missing medical-device record, only copy of a family archive, or lost disk key can be more important than ten well-backed-up replaceable folders.
Step 1: Inventory data sets
Use one row per meaningful group:
| Data set | Owner | Primary location | Change rate | Consequence if lost | Score |
|---|---|---|---|---|---|
| current household records | named adult | restricted laptop folder | monthly | claim and recovery delay | |
| new phone photos | account holder | phone/cloud library | daily | irreplaceable recent memory | |
| completed family archive | archive owner | computer library | occasional | permanent loss | |
| work or school files | organization/user | managed service | daily | income or deadline | |
| care information | caregiver | secure record | as needed | urgent continuity | |
| device recovery material | device owner | controlled separate location | rare | encrypted data lockout |
Add messages, scans, application data, shared folders, external drives, old computers, camera cards, website files, and financial or tax records where relevant. Do not copy employer-managed data into personal storage merely to improve the score.
Step 2: Verify inclusion
For each backup system, answer from its current settings or status:
- Which devices are enrolled?
- Which user accounts are included?
- Which folders and external drives are included or excluded?
- Are online-only files downloaded or represented in the backup?
- Are messages, contacts, health data, application data, and device settings included?
- Does phone-photo synchronization preserve originals at expected quality?
- Are shared folders owned by someone else retained if access disappears?
- Are failed jobs and storage-capacity alerts visible to a named person?
- What was the last successful date and time?
Do not infer inclusion because an application icon is present. Check the documented scope and a sample.
Step 3: Test independence
Mark which events can reach each copy:
| Failure | Working copy | Local backup | Off-site backup | Offline access record |
|---|---|---|---|---|
| device theft | affected? | same bag or separate? | independent account? | separate custodian? |
| home fire or flood | affected? | same room? | truly off-site? | portable or off-site? |
| account lockout | accessible? | requires account? | same account? | contains start path? |
| ransomware | writable? | connected? | versioned or isolated? | clean and separate? |
| prolonged outage | charged? | powered device required? | internet required? | paper or powered? |
| household role change | owner available? | authorized successor? | recovery contact current? | access revoked or transferred? |
The 3-2-1 method explains why two copies under one account, in one room, or continuously connected may share a failure domain.
Step 4: Review retention and version history
Record:
- how frequently new copies or snapshots are created;
- how long deleted files remain recoverable;
- how many historical versions are retained;
- what happens when storage is full;
- whether a device deletion synchronizes immediately;
- whether account closure or nonpayment removes backups;
- whether the service can export data in usable formats;
- how the household learns that backups stopped.
Retention can change with provider plans and settings. Verify current terms and product behavior; do not rely on memory or a marketing phrase such as “continuous backup.”
Also record the renewal date, storage quota, current plan owner, payment-failure notice path, and estimated cost of a full restore or mailed recovery device where the service offers one. Confirm that data can be exported in a usable form before account closure. A low monthly price is not continuity if the household cannot retrieve a complete, readable copy without the original account or device.
Step 5: Audit encryption and recovery
For every encrypted device, drive, archive, and backup:
- identify the legitimate unlock method;
- confirm recovery material is stored away from the protected device;
- verify the key or reference belongs to the correct asset without displaying it in the worksheet;
- confirm an authorized person knows how to start official recovery;
- record whether the provider can help or explicitly cannot recreate the key;
- review what happens after password, phone number, account, or organization changes;
- remove obsolete keys only after replacement is confirmed.
Use the photos, documents, and recovery-keys guide and offline credentials guide. Do not place secret values in the audit sheet.
Step 6: Restore representative samples
Choose low-risk samples from every priority data class:
- restore to a separate temporary folder;
- select the intended historical version;
- open the file with the expected application;
- compare content, date, and basic metadata;
- note time, connectivity, application, cable, account, and key dependencies;
- record pass, partial, or fail;
- remove temporary copies securely when appropriate.
Test local and off-site paths on different dates. A successful local restore does not prove cloud recovery, and a cloud download from an already signed-in laptop does not prove recovery after that laptop is lost.
Step 7: Audit the human system
Ask:
- Is one person the only one who understands every backup?
- Can an authorized adult start recovery if that person is unavailable?
- Are disability, language, dexterity, memory, and caregiving needs addressed?
- Is employer, school, estate, or provider authority required?
- Who receives failure alerts?
- Who rotates offline storage?
- Who documents changes after a new phone, computer, carrier, or cloud plan?
- Is access removed when a household or work role ends?
Recovery access should be sufficient, not universal. Use provider-supported family, delegate, recovery-contact, legacy, or organizational features where available.
Turn findings into a 30-day queue
Prioritize in this order:
- irreplaceable data with score 0 or 1;
- encryption keys with no independent recovery path;
- primary email or password-manager lockout risks;
- backups that have not succeeded recently;
- copies sharing one device, room, or account;
- untested high-priority restoration;
- obsolete people, devices, phone numbers, and recovery contacts;
- replaceable low-consequence data.
Assign one owner and due date to each fix. Re-run the affected row after completion rather than marking it solved because equipment was purchased.
Quarterly audit record
Keep a short log with date, scope, rows changed, sample restores, failures, owner, and next review. Never paste passwords, keys, codes, complete financial numbers, or sensitive file contents into the log.
After a major operating-system upgrade, new phone, storage migration, account change, or household move, run the affected rows immediately instead of waiting for the quarterly date.
Use the digital continuity hub to connect audit findings to account recovery, MFA, offline access, ransomware, and power planning. Compare storage roles in the home data equipment guide.
Sources reviewed
- CISA: How to Protect the Data Stored on Your Devices
- NIST: Data Integrity and Ransomware Recovery Guidance
- Federal Trade Commission: Five Ways to Keep Scammers and Hackers Away
Sources reviewed July 14, 2026. Provider scope, retention, encryption, authentication, and recovery features change. Verify current official documentation and organizational policy during every audit.