Contact us
Illustration for ISO management-system services

ISO/IEC 19770-1

ISO/IEC 19770-1 IT asset management consulting

ISO/IEC 19770-1 consulting helps organisations manage software, hardware and related IT assets across departments, keeping asset records, usage and licence evidence aligned. Vosurein starts with the scope, existing processes and evidence, then helps assign responsibilities, implement the system and review it internally.

Discuss ISO/IEC 19770-1 IT Asset Management System consulting needs

For Your Business

Who this service is for and when to start

For companies with software licenses, cloud subscriptions, and hardware distributed across different units, you can start organizing data from procurement, deployment, and usage. When organizations merge or grow rapidly, or when software vendors require licensing review, it's best to establish a consistent management approach.

Define the scope around the organisation’s actual IT assets and responsibilities, including more than desktop computers. IT, procurement, finance and HR need a shared basis of information.

The Challenge

Common challenges faced by businesses

When purchased licences cannot be linked to contracts and installed software cannot be matched to usage rights, costs and risks are difficult to assess. Charges may continue after equipment handovers or staff departures if accounts, subscriptions and custody responsibilities are not updated.

Inventory tools can identify some deployment situations, but they will not interpret contracts for the enterprise or decide whether usage is legal. It is necessary to connect data, contracts, and management responsibilities.

Our Approach

Methods and applicable requirements

ISO/IEC 19770-1:2017 with Amd 1:2024 specifies IT asset management system requirements for all types of IT assets. It does not prescribe financial, accounting or technical rules for individual assets, and its main purpose is not to manage information independently of hardware and software. Conformity does not automatically establish conformity with ISO 55001.

Asset boundaries and responsibilities

Consulting identifies the hardware, software and associated rights in scope, along with data sources and those responsible for custody, use and management. The inventory should explain purposes and responsibilities, not simply list equipment.

Deployment and license reconciliation

Match procurement contracts and licence evidence to actual deployment and use, then identify discrepancies. Licensing metrics and restrictions vary by vendor. Ask appropriately qualified personnel to confirm terms where needed.

Lifecycle and retirement

Arrange processes for procurement, deployment, changes, transfers, and retirement, coordinating personnel changes and supplier management. Retirement must simultaneously check assets, data, permissions, and follow-up of ongoing costs.

Process

Consulting scope and process

  1. Define the asset inventory scope

    Confirm IT assets, usage responsibilities, and data sources, and organize initial gaps.

  2. Establish reconciliation and control

    Arrange methods for updating inventories, licensing, procurement, and deployment data.

  3. Pilot lifecycle management

    Select procurement, handover, or retirement cases and check execution evidence.

  4. Review data and cost risks

    Review reconciliation issues and improvements to assist audits and management reviews.

Preparation

What documents do companies need to prepare?

  • Assets and deployment: Hardware and software inventory, deployment data, and user units.
  • Rights and contracts: Procurement, licensing, subscription, and maintenance contracts.
  • Changes and retirement: Handover, transfer, recovery, and cancellation records.
  • Responsibilities and reconciliation: Management processes, financial interface, and inventory discrepancies.

For an initial discussion, provide a summary or de-identified sample. Share full records under the agreed scope, access permissions and confidentiality arrangements. Check whether existing records are still valid before filling gaps; there is no assumption that every document must be rewritten.

Project Planning

Estimating time and cost

Evaluate based on asset type, licensing model, location, and data reconciliation level. Automatic inventory tools, license audit support, or large-scale historical data cleanup need separate confirmation; terms from different vendors cannot be applied universally.

Each project specifies the number of on-site interviews, document revisions, training sessions, internal-audit support activities and improvement reviews, together with responsibilities. Third-party certification, specialist testing, engineering and legal services are not included in consulting fees by default. Confirm transition schedules for existing certificates with the certification body.

FAQ

Frequently asked questions

Does counting installed software establish licence compliance?

No. Contracts determine licensing metrics, permitted use and restrictions. Management system consulting does not replace vendor terms or legal judgement.

Can we manage only software licenses?

You can first clearly define the scope of work, but the purpose of this standard is IT asset management, not just software. Related hardware and other interfaces still need proper handling.

Is IT asset management the same as information security management?

No. Asset data can support information security, but managing usage rights and asset lifecycles does not by itself address information security risks and controls.

Do inventory tools replace management procedures?

Tools provide data. Management procedures define who updates it, how records are reconciled and how discrepancies are handled. Both are needed, and tool outputs must be checked for completeness.

Does compliance with 19770-1 automatically mean compliance with 55001?

Cannot assume automatically. The requirements and scope of the two standards must be confirmed separately; one certificate cannot be used as proof of another standard.

Does completing consulting guarantee a certificate?

No certificate is issued automatically. Vosurein helps establish and pilot the system and review evidence. An independent third party assesses and issues certificates under its applicable scheme. Before applying, check the certification scope, accreditation status and customer acceptance. We do not guarantee certification or fabricate records.

Related

Related services and enquiries

Please share your industry, activities and sites in scope, existing management systems and target completion date so we can define the scope of work.Contact Vosurein

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents