An asset register is accurate on the day it is built. After that, every laptop swapped at the service desk, every SaaS seat bought on a card and every lease that rolls over unnoticed makes it a little less true, until an audit or a licence review measures the gap.
IT asset management (ITAM) is not a one-off inventory. It is a cycle: find what is really out there, compare it with what the register says, fix the difference, and keep purchases, assignments, licences and contracts in step. This free IT asset management checklist gives IT managers, asset managers and service desk leads a monthly routine for hardware and software. It covers discovery reconciliation, goods-in and tagging, assignments and returns, licence compliance and reclaim, and a 90-day look-ahead at renewals, warranties and leases. A quarterly audit phase appears at each quarter end. Every run ends with a small set of KPIs and a signed-off register that finance, security and auditors can rely on.
Discovery Data vs the Asset Register: What Each One Knows
Discovery tools, endpoint management and SaaS admin consoles show what is connected and in use right now. They do not know what you paid, which contract it sits under, who signed for it or when the lease ends. The register knows all of that, but only what people remembered to record. ITAM happens in the gap between the two. A device seen on the network but missing from the register is either unrecorded or unauthorised. A register entry nobody has seen for a month is in a drawer, lost, stolen or waiting for disposal, and each answer leads somewhere different.
ITIL 4 frames the IT asset management practice as planning and managing the full lifecycle of IT assets to maximise value, control costs and manage risk. ISO/IEC 19770-1:2017 sets the requirements for running that as a management system, including core data management, licence management, internal audit and management review. This checklist is the operating rhythm inside that system. The end of the lifecycle is a separate process: once a device is marked for disposal it moves to the IT Asset Disposal (ITAD) Checklist, and returns to the register only as a closed record with a certificate reference.
Not everything belongs in the monthly run. Some checks need to happen weekly in operations, and some only make sense a few times a year. The matrix shows where each activity sits, who usually owns it and the reference behind it. Where a reference sets a minimum, many teams go faster.
Activity
Cadence
Typical owner
Reference
Deal with unauthorised devices on the network
Weekly
Service desk or security operations
CIS Controls v8.1, Safeguard 1.2
Check software support status and remove unauthorised software
Monthly
Asset manager with IT operations
CIS Safeguards 2.2 and 2.3
Reconcile discovery with the register
Monthly
Asset manager
Phase 1
Licence position and reclaim
Monthly for key products
Software asset manager
ISO/IEC 19770-1, clause 8.4
Renewal, warranty and lease look-ahead
Monthly, 90 days ahead
Contract owners
Phase 5
Floor-to-book and book-to-floor checks
Quarterly, sampled
Asset manager plus a second person
ICO data protection audit framework (periodic physical checks)
Full hardware and software inventory review
At least every six months
ITAM owner
CIS Safeguards 1.1 and 2.1
Internal audit and management review of the ITAM system
At planned intervals, usually yearly
ITAM owner and IT leadership
ISO/IEC 19770-1, clauses 9.2 and 9.3
If you hold ISO/IEC 27001:2022 certification, the same runs double as evidence for two Annex A controls: 5.9, an inventory of information and associated assets with named owners, which Phases 1 and 2 keep current; and 5.11, return of assets when people leave or change role, which Phase 3 checks every month.
Why Run IT Asset Management in CheckFlow?
1
The month starts without anyone remembering
A monthly schedule creates the run on the first working day, with dynamic due dates so reconciliation finishes before the renewal look-ahead needs its numbers. One yes/no answer at the start switches on the quarterly audit phase.
2
Your product list fills the licence review
Keep key software products, entitlement counts and renewal dates in a data set that fills the licence and renewal tasks. A discovery script can write its exceptions into the run through the REST API or Zapier instead of someone copying them by hand.
3
A year of evidence in twelve runs
Every task records who completed it and when, with exports, KPI summaries and audit samples attached. When an auditor or a software vendor asks how you know the register is right, you show twelve monthly reconciliations and four quarterly audits.
ITAM only works if the cycle actually runs every month. CheckFlow’s recurring checklist software explains how schedules, assignments and due dates keep a monthly process on track when the person who set it up is on leave.
IT asset management (ITAM) is the practice of tracking and managing hardware, software and related contracts across their whole lifecycle, from purchase to disposal. It answers four questions at any point: what you own, where it is, who is responsible for it and what it costs. In practice it is a recurring cycle of reconciliation, licence review, renewal decisions and audit, rather than a one-off inventory project.
What should an IT asset register include?
+
For hardware: asset tag, serial number, make and model, assigned user, accountable owner, department or cost centre, location, purchase date, supplier, warranty end and, for leased kit, the lease end date. CIS Safeguard 1.1 adds network and hardware addresses, machine name and whether the device is approved to connect. For software, CIS Safeguard 2.1 lists title, publisher, install date and business purpose, plus version and licence count where appropriate.
How often should IT assets be audited?
+
Reconcile monthly and audit physically at least quarterly. CIS Controls v8.1 asks for the full hardware and software inventories to be reviewed at least every six months and for unauthorised devices to be dealt with weekly. A sampled floor-to-book and book-to-floor check each quarter catches devices that never touch the network, such as spares in a cupboard, which discovery tools cannot see.
What is the difference between ITAM and a CMDB?
+
A CMDB records configuration items and how they relate to each other, so change and incident teams can see what a failure or a change will affect. An ITAM register records the financial and contractual side: cost, ownership, entitlements, warranties and leases. Many items appear in both, and the two should share identifiers, but they answer different questions. A spare laptop in stores matters to ITAM long before it matters to the CMDB.
How do you reclaim unused software licences?
+
Set a threshold, such as no use in 60 or 90 days, and pull the list of seats that cross it each month. Confirm with the user’s manager before removing anything, because some tools are used seasonally. Then remove the assignment and, most importantly, reduce the count at the next renewal. A seat returned to the pool saves money only if you stop buying it.
Does ISO 27001 require an asset inventory?
+
Yes, where the control applies to your risk treatment. ISO/IEC 27001:2022 Annex A 5.9 calls for an inventory of information and other associated assets, including owners, that is kept up to date, and 5.11 covers the return of assets when employment or a contract changes or ends. A monthly reconciliation with sign-off is a straightforward way to show an auditor the inventory is maintained, not just created.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
A Register You Can Trust at Every Audit, Not Just the Week Before
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more