Skip to content
AMPthilly home
Get started
Compliance & audit

What Is an Asset Management Policy?

What an asset management policy is, the sections it should contain, how to write one step by step, a template you can copy, and the ISO standards behind it.

AMPthilly Updated

An asset management policy is a document that sets the rules for how an organisation acquires, tracks, uses, maintains, and disposes of its assets.

An asset management policy is a document that sets the rules for how an organisation acquires, records, uses, maintains, and disposes of its assets - from laptops and tools to vehicles and machinery. It is the rulebook behind the asset register: the register says what you own, the policy says how owning it is supposed to work. Day-to-day usage rules for staff usually live in a companion acceptable use policy, while end-of-life handling for IT kit hands over to an ITAD process.

What you will learn

What the policy should contain

A workable policy covers the whole lifecycle, briefly:

  • Purpose and intent - one or two lines on why the policy exists and what it is meant to achieve. This is usually section one, and it anchors everything below it.
  • Scope - what counts as a trackable asset (often a value threshold plus categories like data-bearing or safety-critical kit), and what is deliberately out of scope.
  • Definitions - plain meanings for the terms you use (“asset”, “custodian”, “disposal”, “capitalisation”), so two readers cannot interpret the same rule two ways.
  • Acquisition - who can approve purchases, how new items get registered, tagged, and assigned.
  • Custody and use - how assets are checked out, transferred, and returned; who is responsible for an item between handovers.
  • Maintenance - inspection and service expectations, and how faults get reported.
  • Disposal - when an asset is retired, who approves it, how data sanitization is handled for anything that stores data, and what evidence is kept, such as a certificate of destruction.
  • Roles and exceptions - who owns the policy, who enforces it, and how deviations are approved rather than improvised.

How to write an asset management policy (step by step)

You do not need a consultant to write the first version. Work down this list and you will have a usable draft in an afternoon:

  1. Tie it to a purpose. Write the objective first - “keep an accurate record of what we own, control who holds it, and dispose of it safely”. Every rule below should serve that goal.
  2. Define the scope and a value threshold. State which asset types are in (and out), and set a monetary threshold so people know whether a 30 euro keyboard is tracked.
  3. Write the definitions. Pin down ambiguous terms before they cause arguments. A shared vocabulary is what keeps the policy enforceable.
  4. Assign roles and a single owner. Name who approves purchases, who holds custody, who disposes - and one person who owns the policy itself.
  5. Cover the lifecycle. Walk an asset from acquisition and registration through custody, maintenance, and disposal, with a rule at each stage.
  6. Name the compliance and standards you follow. Point to ISO 55001, ISO 27001, or whatever your auditors map against, so the policy reads as deliberate rather than improvised.
  7. Get senior sign-off and version it. Add an approver, a version number, and a dated review cycle. An unsigned, undated policy is a draft, not a control.

Asset management policy template

There is no single official format, but the skeleton below covers what most auditors and frameworks expect. Lift it as an inline outline and write a line or two under each heading - no downloadable file required.

  • 1. Purpose / intent - why the policy exists and what it governs.
  • 2. Scope - asset types covered, the value threshold, and exclusions.
  • 3. Definitions - the terms used in the document, defined plainly.
  • 4. Roles and responsibilities - owner, approvers, custodians, disposers.
  • 5. Acquisition and registration - approval, recording, and assignment of new assets.
  • 6. Tagging and identification - how each asset is labelled and uniquely identified; many teams use an asset tag or QR label tied to the register.
  • 7. Custody and use - checkout, transfer, and return rules.
  • 8. Maintenance - inspection, servicing, and fault reporting.
  • 9. Disposal and data handling - retirement approval, data sanitization, and disposal evidence.
  • 10. Compliance and standards - the frameworks the policy maps to.
  • 11. Exceptions - how deviations are requested and approved.
  • 12. Review and version control - owner, version number, approval, and review date.

Policy vs strategy vs procedure

These words get used interchangeably, but in a mature asset programme they are four different documents:

  • Policy - the high-level rulebook: what you manage and why. It is short, stable, and signed off by senior management.
  • Strategy - how you execute the policy over time: priorities, budgets, lifecycle planning. In ISO 55001 terms this is close to the Strategic Asset Management Plan.
  • Procedure - the step-by-step how for individual tasks (“how to register a new laptop”, “how to retire a server”). Procedures change far more often than the policy.
  • Register - the live record the other three act on - the actual list of assets, owners, and histories.

Small organisations often merge the policy, strategy, and plan into one document and keep procedures as short checklists. That is fine, as long as the rules and the records stay in step.

The standards behind it: ISO 55001 and ISO 27001

A policy in the “Compliance & audit” world usually maps to a named framework. Two come up most:

  • ISO 55001 is the international standard for asset management systems, aimed at physical and operational assets across their lifecycle. It expects a documented asset management policy plus a Strategic Asset Management Plan (SAMP) that turns organisational objectives into asset decisions.
  • ISO 27001 governs information security. Its Annex A asset management controls cover the inventory of information and IT assets, ownership, acceptable use, and secure disposal - which is why an IT asset policy so often sits alongside a security policy.

You do not have to be certified to use these as a checklist. Naming the standard your policy follows is what lets an auditor map your rules against an external benchmark instead of taking your word for it.

Fixed asset and IT asset policies: what changes

The same core structure splits into two flavours depending on who the policy serves.

A fixed asset policy is the finance reader’s version. Its defining rule is a capitalisation threshold: an item above a set monetary value, with a useful life of more than one year, is capitalised on the balance sheet and depreciated over time, rather than expensed immediately. That single test drives depreciation schedules, physical verification counts, and write-off approvals, so the threshold and the useful-life rule belong front and centre.

An IT asset management policy keeps the lifecycle but adds the concerns that come with technology: software licensing and software asset management to stay compliant, BYOD rules for personal devices, cloud and SaaS subscriptions that renew without a purchase order, and a stance on shadow IT - the unauthorised apps and devices staff adopt outside the policy. Secure disposal matters more here too, because retired IT kit is usually a data-bearing device.

Why it matters in practice

Without a written policy, asset handling is folklore: the person who has always ordered the laptops knows the process, and the process leaves with them. The policy turns habits into rules that survive staff turnover, and it gives managers something to point to when equipment goes missing - “the policy says returns are recorded at handover” is a far easier conversation than inventing a standard after the fact. In regulated settings the stakes are higher still: teams tracking hospital beds or infusion pumps need maintenance and custody rules they can show an inspector, not just good intentions.

How it supports audits

Auditors - financial, ISO, or internal - rarely test whether your assets are well managed directly. They test whether you do what your policy says. That makes the policy the audit’s anchor document: it defines what records should exist, and the audit checks they do. The pairing that holds up is a clear policy plus a register that captures the evidence automatically; in AMPthilly, checkouts, returns, transfers, and status changes are logged in each asset’s audit history, so demonstrating “we follow our own disposal and custody rules” is a filter and an export rather than a scramble.

Common mistakes

  • Writing for the auditor, not the staff. Ten pages of formal prose that nobody reads loses to one page of rules people actually follow.
  • No scope threshold. If the policy is silent on whether a 30 euro keyboard is an asset, people either track everything (and give up) or track nothing.
  • No definitions. Skip the definitions section and every other rule becomes negotiable, because two readers will interpret “asset” or “disposal” differently.
  • Disposal as an afterthought. Most policies are strong on buying and weak on retiring - which is exactly where data risk and write-off errors live.
  • Policy and register drift. If the policy demands records the register cannot hold, or the register tracks things the policy never mentions, both lose credibility.
  • No owner, sign-off, or review date. An unsigned, undated policy nobody owns is a document an auditor will not trust.

FAQ

How do you write an asset management policy?

Start from a clear purpose, then work down the lifecycle. State why the policy exists, set the scope and a value threshold, define your terms so nothing is ambiguous, assign one owner plus supporting roles, write the rules for acquisition, custody, maintenance, and disposal, name the standards you follow, and finish with senior sign-off, a version number, and a review date. Keep it to the rules people will actually follow, not ten pages written for an auditor.

What is the difference between an asset management policy and a strategy?

The policy is the high-level rulebook - what you track and why. The strategy is how you execute it over time (priorities, budgets, lifecycles), and procedures are the step-by-step “how” for individual tasks. The asset register is the live record that all three act on. Small organisations often merge the policy, strategy, and plan into a single document; larger ones keep them separate.

What is a fixed asset policy?

A fixed asset policy is the finance-focused version: it sets a capitalisation threshold (a monetary value) and a useful life of more than one year to decide what gets capitalised on the balance sheet and depreciated, versus what is expensed immediately. It governs tagging, verification counts, and write-offs for those higher-value items.

Which ISO standard covers asset management policy?

Two are commonly cited. ISO 55001 covers management systems for physical and operational assets, including the policy and the Strategic Asset Management Plan. ISO 27001, through its Annex A asset management controls, covers information and IT assets. An auditor maps your policy against whichever framework fits your asset base.

What should an IT asset management policy include?

Everything a general policy covers, plus IT-specific concerns: software licensing and software asset management, acceptable use, BYOD rules for personal devices, cloud and SaaS subscriptions, secure disposal and data sanitization for storage media, and a stance on shadow IT - the unauthorised apps and devices that bypass the policy.

Who should own the asset management policy?

One named role, not a committee. In smaller organisations that is usually the IT manager, operations manager, or finance lead; larger ones may split IT assets from fixed assets. The owner keeps the policy current, answers edge cases (“does a monitor under 100 euros count?”), and is the person an auditor talks to. A policy owned by everyone is enforced by no one.

What is the difference between an asset management policy and an asset register?

The policy is the rulebook; the register is the record. The policy says what counts as a trackable asset, who may approve purchases, how items are labelled, and how disposal works. The register is the live list of actual assets with owners, locations, and histories. Each is weak without the other - rules nobody records against, or records with no rules behind them.

How often should an asset management policy be reviewed?

Annually is the common rhythm, plus whenever something material changes: a new asset class (company phones, fleet vehicles), a regulation that touches your equipment, a merger, or an audit finding. The review should check the policy against reality - if staff routinely bypass a rule, fix the rule or fix the behaviour, but do not leave the gap in writing.

Tools that make this easier

A policy is only as good as the records behind it. AMPthilly gives you one register for IT and physical assets, with QR labels you scan from a phone browser - no app to install - and a full audit history on every asset that logs checkouts, returns, transfers, status changes, and disposal. That turns “we follow our own policy” from a claim into an export. You can start on the free plan (3 users, 25 assets, no card) at app.ampthilly.com.

The takeaway

An asset management policy is the rulebook that keeps asset handling from living in one person’s head. Write it from a clear purpose, give it a scope threshold, definitions, named roles, and a lifecycle from acquisition to disposal, then map it to a standard like ISO 55001 or ISO 27001 and have someone sign it off. Pair that policy with a register that records the evidence automatically, and audits become a filter rather than a fire drill.

Free to start, no card required

Put your register to work

AMPthilly gives every asset an owner, a location, and a history - checkouts, printable QR labels, service desk, and audit trail in one place. The free plan covers 3 users and 25 assets, with SSO and MFA included.