The minimum scope
A hotel data audit should cover eight connected areas: decision inventory, system inventory, metric definitions, data lineage, reconciliation and quality, access and security, ownership and operating rhythm, and a prioritised implementation plan. For an independent hotel or a two-to-ten-property group, depth matters more than breadth. It is better to prove one pricing or staffing decision end to end than to list hundreds of reports without testing how they are used.
1. Decision inventory
Begin with recurring decisions that affect room revenue, food and beverage margin, labour, purchasing, and cash. For each decision, record the accountable person, frequency, deadline, evidence reviewed, threshold for action, and what action is available. Examples include changing rates for a high-demand date, adjusting a roster, investigating channel cost, approving a purchase order, or challenging a property forecast.
Ask whether the decision is delayed, disputed, repeated manually, or made from competing numbers. This prevents the audit from becoming a technology exercise detached from operating value.
2. Source-system and report inventory
List PMS, POS, CRS, channel manager, revenue system, finance, payroll, purchasing, guest feedback, and material spreadsheets.
Record direction, frequency, owner, failure alert, retry process, and whether transfers are totals or transaction-level records.
Name the report, version, filters, extraction time, timezone, recipient, and downstream spreadsheet transformations.
Rank each asset by the decisions it supports and the cost or risk of lateness, incompleteness, or misinterpretation.
3. Metric dictionary
Document the formula and business meaning of every metric used in the selected decisions. Include period boundary, currency, tax basis, inclusions, exclusions, treatment of cancellations and no-shows, complimentary rooms, out-of-order inventory, packages, service charges, and owner adjustments. A metric is not governed merely because it has a familiar label: two departments can use “revenue,” “occupancy,” or “labour cost” to mean different things.
4. Lineage and transformation test
Choose a small sample and trace it from source transaction to management report. Capture exports, queries, spreadsheet formulas, manual copy-paste steps, mappings, and journals. Note where transaction detail becomes an aggregate and where a person can alter the number without an approval trail. The aim is not to eliminate every spreadsheet; it is to know which steps are material, repeatable, reviewable, and owned.
5. Reconciliation and quality controls
Test completeness, validity, uniqueness, consistency, timeliness, and traceability. Reconcile PMS room revenue to finance, POS outlet sales to PMS postings, channel reservations to PMS reservations, labour hours to payroll cost, and purchase activity to finance where those flows support the chosen decisions. Record exceptions as named categories rather than burying them in an unexplained variance.
The PMS and POS reconciliation guide shows how to construct one such bridge. A control should state the expected result, tolerance, reviewer, evidence retained, escalation point, and closure status.
6. Access, privacy, and resilience
Review who can view, export, change, approve, and administer each critical system. Check whether leavers are removed, shared accounts exist, privileged access is reviewed, backups are tested, and sensitive guest or employee data is copied into unmanaged files. For AI use cases, document whether personal or confidential data leaves an approved environment and whether a human reviews consequential output.
7. Ownership and meeting rhythm
For every critical metric and control, name a business owner and a technical or system custodian. Define where exceptions are reviewed, who can decide, and how the outcome is recorded. A dashboard without a decision right is only a display. The related guide on why hotel dashboards fail explains this operating gap.
8. Prioritised 90-day plan
Score findings by decision impact, control risk, effort, dependency, and reversibility. Separate quick definition or process fixes from interface changes and larger platform work. A useful plan identifies one executive sponsor, one decision to improve, a baseline measure, weekly milestones, acceptance evidence, and a stop-or-adjust checkpoint.
Select decisions, agree metric definitions, inventory evidence, and capture the current workflow.
Test lineage, quantify named exceptions, and identify the smallest controllable causes.
Change one definition, mapping, control, or decision routine and retain acceptance evidence.
Review recurrence, document ownership, and choose the next move based on observed results.
Audit deliverables
- A one-page decision inventory with named owners and thresholds.
- A critical-system and interface map.
- A metric dictionary for the selected decisions.
- One reproducible source-to-report lineage trace.
- A reconciliation bridge and exception log.
- An access and data-handling review.
- A ranked opportunity backlog with dependencies and acceptance criteria.
- A board-ready 90-day action plan stating limitations and unresolved evidence.
Methodology and limitations
This checklist combines decision-led analytics, data-lineage, control-design, and AI-risk-management principles. It is a scoping guide, not an audit opinion, cybersecurity assessment, tax review, or assurance engagement. The exact evidence depends on the hotel’s systems, contractual access, accounting policy, operating model, and local regulation. Findings should distinguish observed evidence, staff explanation, inference, and untested assumption.
For the service approach, see the Hotel Profit Decision Audit. If the immediate question is automation or AI, continue with the hotel AI readiness assessment and the 90-day readiness paper.