Information Security

ISO/IEC 19770-1: The Complete Guide to IT Asset Management Certification

By AGS Compliance Team March 20, 2026 5 min read
ISO/IEC 19770-1: The Complete Guide to IT Asset Management Certification

Ask most organizations how many software licenses they own, which laptops hold sensitive data, or what happens to servers at end of life, and the answers arrive slowly — if at all. Yet technology assets typically represent one of the largest controllable spend categories in the business, and one of its least-governed risk surfaces. ISO/IEC 19770-1 exists to fix that. This guide explains what the standard requires, who benefits, what an IT Asset Management system contains, and how certification works. It is written for IT asset managers, procurement and finance leaders, security and compliance teams, and executives accountable for technology spend and risk.

What is ISO/IEC 19770-1?

ISO/IEC 19770-1:2017, including Amendment 1:2024, specifies the requirements for an IT Asset Management (ITAM) system — a framework for the effective governance and control of software, hardware, and related technology assets throughout their life cycle. Its purpose is to enable organizations to demonstrate responsible management of IT assets, support compliance with licensing and contractual obligations, optimize costs, and reduce risk.

The standard is a full management system standard built on the Annex SL high-level structure, which means it shares the clause architecture — and the Plan-Do-Check-Act improvement cycle — of standards like ISO/IEC 27001 and ISO/IEC 20000-1. Amendment 1:2024 refreshes and clarifies certain requirements to keep the standard aligned with contemporary practice, ensuring implementations remain current as technology estates evolve toward cloud subscriptions, SaaS, and hybrid infrastructure.

ISO/IEC 19770-1 anchors the wider ISO/IEC 19770 family, which also includes tagging and identification specifications such as software identification (SWID) tags — the technical building blocks that make automated asset discovery and verification possible.

Who needs an ITAM system?

The scope covers organizations of all types and sizes that acquire, deploy, manage, and dispose of IT assets — in other words, virtually every organization. The pressure points that drive adoption are familiar:

  • Software licensing exposure — enterprises facing vendor audits from major software publishers, where unmanaged entitlements can translate into unbudgeted seven-figure settlements.
  • Finance and procurement functions seeking visibility and control over technology spend, subscriptions, and renewals.
  • Security teams who know a simple truth: you cannot protect an asset you do not know you have.
  • Regulated industries where asset traceability underpins data protection and operational resilience obligations.
  • Sustainability and ESG programs, which depend on disciplined asset disposal and life cycle accounting.

The audience includes IT asset managers, procurement and finance professionals, security and compliance teams, auditors, and executives who answer for technology cost and risk.

The benefits of disciplined IT asset management

  • Reduced software licensing and audit exposure — accurate entitlement and deployment records turn vendor audits from crises into routine correspondence.
  • Improved cost control — eliminating shelfware, duplicate purchases, and forgotten subscriptions.
  • Better security through visibility — a trustworthy asset inventory is the foundation of vulnerability management and incident response.
  • Stronger data for decision-making — refresh planning, budgeting, and vendor negotiations grounded in fact.
  • Support for sustainability and disposal obligations — verifiable, responsible retirement of equipment and data.

What's inside the ITAM management system?

Like every Annex SL management system, an ITAM system runs on the standard governance machinery: an asset management policy and objectives, defined roles and responsibilities, risk-based planning, competence and awareness, documented information, internal audit, management review, and continual improvement. Around that core, ISO/IEC 19770-1 requires life cycle asset management processes covering:

  • Acquisition — controlled requesting, procurement, and receipt of hardware and software, with entitlements captured at the source.
  • Deployment — assignment, installation, and recording of assets into the live estate.
  • Operation and maintenance — tracking usage, changes, moves, and license consumption throughout service life.
  • Retirement and disposal — secure data sanitization, environmentally responsible disposal, and license harvesting.
  • Data, records, and controls — maintaining the asset registers, entitlement records, and verification routines that make everything above auditable.

The system integrates naturally with adjacent management systems — ISO/IEC 27001 for information security and ISO/IEC 20000-1 for service management — thanks to the shared Annex SL foundation. Many organizations run all three as an integrated system, with the asset register serving as a common backbone.

How the standard is structured

The clause structure follows the familiar Annex SL sequence: context of the organization, leadership, planning, support, operation, performance evaluation, and improvement. Clause 8 carries the operational weight, addressing the asset management processes across the life cycle, while Clauses 9 and 10 keep the system honest through measurement, audit, review, and corrective action. Amendment 1:2024's clarifications apply within this same structure, so organizations already aligned to the 2017 edition can absorb the update without re-architecting their system.

The road to certification

  1. Gap analysis — compare current asset practices, registers, and controls against the standard, and confront the state of your data honestly.
  2. Implementation — establish the policy and objectives, define life cycle processes, consolidate asset and entitlement records, and deploy the documentation set.
  3. Operation — run the system and build evidence: verified inventories, reconciliation results, disposal records, internal audits, and management review.
  4. Stage 1 audit — the certification body reviews documentation and readiness.
  5. Stage 2 audit — auditors verify the ITAM system in operation, sampling records and processes across the asset life cycle.
  6. Surveillance and recertification — certificates are typically valid for three years, sustained through surveillance audits and recertification.

Certification demonstrates disciplined and defensible management of IT assets — a message that resonates with software vendors, regulators, insurers, and boards alike.

How AGS can help

An ITAM implementation stands or falls on its documentation: the policies, procedures, registers, and matrices that turn asset management intent into auditable practice. The AGS ISO/IEC 19770-1:2017 + Amd.1:2024 IT Asset Management System toolkit, a Standard-tier kit, delivers that foundation complete.

The kit provides editable manuals, procedures, forms, and compliance matrices spanning the full asset life cycle — acquisition, deployment, operation, and disposal — together with the governance layer of objectives, audits, and reviews, all aligned to the 2017 edition as amended in 2024. Because every document is fully editable, you can adapt the structures to your estate, your tooling, and your vendor landscape without starting from zero. The compliance matrices map requirements to documents and records, giving auditors the traceability they expect and giving you an always-current view of readiness.

If it is time to bring your technology estate under real control — and to prove it — the AGS toolkit is the shortest path from scattered spreadsheets to certifiable asset management. Visit the AGS online store to learn more.

View the toolkit →

The toolkit for this standard
ISO-IEC 19770-1-2017 + Amd.1-2024-IT Asset Management System
75 ready-to-use documentsEditable Word and Excel Instant download
AGS Compliance Team

Our toolkits and guides are written by practising auditors who assess management systems against ISO, BRCGS, HACCP and Halal schemes. Every document reflects what assessors actually look for.