UNUS London  —  Compliance Architecture Division  |  UNCLASSIFIED // REGULATED INDUSTRIES
Home Solutions Legal & Professional Financial Services Manufacturing Healthcare Academy Blogs About Book Discovery Call UNUS Govern
Standard Reference // ISO/IEC 19770

IT Asset Management
Systems Compliance

The ISO/IEC 19770 family establishes internationally recognised requirements for IT Asset Management. UNUS London deploys database-first ITAM infrastructure that satisfies all five parts of the standard — from software identification to resource utilisation measurement.

Standard Metadata
Standard Family
ISO/IEC 19770
Current Edition — Part 1
19770-1:2017
Governing Body
ISO/IEC JTC 1/SC 7
Regulatory Scope
Hardware · Software · Licences
UNUS Readiness Score
91/100
Deployment Tier
Intermediate — £18,497
Aligns With
ITIL 4 · ISO/IEC 27001
🏛️
Standard Purpose
Establishes requirements for IT Asset Management Systems (ITAMS) to enable organisations to demonstrate accountable stewardship of IT assets across their full lifecycle.
📐
Regulatory Position
ISO/IEC 19770 is the primary international standard for ITAM. Part 1 is certifiable and integrates with ISO/IEC 27001 (Annex A.8 — Asset Management) and ITIL 4 Service Asset practices.
⚖️
UK Relevance
Required or strongly recommended for organisations subject to FCA operational resilience, NHS DSPT, MOD DEFSTAN, and SRA technology governance obligations. Essential for licence audit defence.

The Five-Part
Standard Architecture

ISO/IEC 19770 is a multi-part standard. Each part governs a distinct dimension of IT Asset Management. Together they form an integrated governance framework that regulators, auditors, and licence publishers recognise globally.

Part 02
ISO/IEC 19770-2:2015
Software Identification Tag
Defines the XML-based Software Identification (SWID) tag schema — a machine-readable identifier embedded in software packages. SWID tags enable automated discovery of installed software, making licence reconciliation tractable at scale. Adopted by NIST (NISTIR 8060) and the US government for federal software inventory.
XML Schema Auto-Discovery NIST Referenced
Core Elements
  • TagId — Globally unique identifier for the software product
  • Name / Version — Product name and version per publisher definition
  • Payload — Files and directories constituting the installed product
  • Evidence — Discovery artefacts when full installation cannot be confirmed
Part 03
ISO/IEC 19770-3:2016
Software Entitlement Schema
Defines the Software Entitlement Tag (SWEN) — a standardised machine-readable format for software licence entitlements issued by publishers. Enables automated matching of purchased rights against installed usage. Directly supports licence deficit and surplus identification without manual reconciliation.
Entitlement Matching Publisher Integration Automated Reconciliation
Core Elements
  • Entitlement Id — Unique identifier for the licence entitlement record
  • Quantity — Number of authorised units or seats
  • Metric — Unit of measure (per-device, per-user, per-core)
  • Constraints — Version rights, upgrade eligibility, geography limits
Part 04
ISO/IEC 19770-4:2017
Resource Utilisation Measurement
Specifies a standard schema for Resource Utilisation Measurement (RUM) data — telemetry gathered from deployed software to evidence actual usage. RUM data feeds entitlement optimisation, enabling organisations to reclaim unused licences and defend against publisher audit claims of over-deployment.
Usage Telemetry Licence Optimisation Audit Defence
Measurement Dimensions
  • Last-Used Date — Most recent execution timestamp per installation
  • Usage Duration — Total active use time within measurement period
  • User Identity — Attributed user for per-user licence metrics
  • Device Context — Hardware platform for per-device licence metrics
Part 05
ISO/IEC 19770-5:2015
Overview and Vocabulary
Establishes the definitional foundation for the entire 19770 family. Part 5 defines common terms including IT asset, software asset, licence entitlement, and asset register. It ensures terminological consistency across Parts 1–4 and provides the vocabulary for policy documentation, contractual instruments, and audit correspondence.
Definitions Terminology ISO 10241 Aligned
Key Defined Terms
  • IT Asset — Item, thing or entity that has potential or actual value to an organisation
  • Asset Register — Formal record of IT assets with attributes sufficient for management
  • Licence Entitlement — Right to use software within defined constraints
  • SAM — Software Asset Management: processes governing software throughout its lifecycle

Part 1 Compliance
Requirements Mapping

The table below maps key ISO/IEC 19770-1:2017 clauses to their mandatory requirements, prescriptive language, and UNUS London's fulfilment status. Conformance language follows ISO/IEC Directives, Part 2.

Clause Ref. Requirement (shall) ITAM Domain UNUS Status
Cl. 4.1 The organisation shall determine external and internal issues relevant to its purpose and that affect its ability to achieve the intended outcome of its ITAM system. Context Fully Met
Cl. 4.3 The organisation shall determine the boundaries and applicability of the ITAM system and shall document the scope. Scope Definition Fully Met
Cl. 5.1 Top management shall demonstrate leadership and commitment with respect to the ITAM system by ensuring that the ITAM policy and objectives are established. Leadership Fully Met
Cl. 6.1.2 The organisation shall plan how to address identified ITAM risks and opportunities, and shall maintain documented information as evidence of planning results. Risk Planning Fully Met
Cl. 6.2 The organisation shall establish ITAM objectives at relevant functions, levels, and processes. Objectives shall be measurable, monitored, and updated as appropriate. Objectives Fully Met
Cl. 7.5 The organisation shall maintain documented information required by the ITAM standard, including the IT asset register and associated lifecycle records. Documented Information Fully Met
Cl. 8.1 The organisation shall plan, implement, control, and review ITAM processes needed to meet requirements, and shall retain documented information to demonstrate conformance. Operational Control Fully Met
Cl. 8.2.3 The organisation shall maintain the IT asset register and shall ensure it reflects the current state of IT assets under management with sufficient detail for each tier of maturity targeted. Asset Register Fully Met
Cl. 8.3 The organisation shall identify and manage risks associated with IT assets, including unauthorised software, licence non-compliance, and end-of-life hardware. Risk Management Partial — Config Req.
Cl. 9.1 The organisation shall determine what needs to be monitored and measured, the methods for analysis and evaluation, and when results shall be analysed and reported. Performance Evaluation Fully Met
Cl. 9.2 The organisation shall conduct internal ITAM audits at planned intervals to determine whether the ITAM system conforms to the requirements of this standard. Internal Audit Fully Met
Cl. 10.1 The organisation shall continually improve the suitability, adequacy, and effectiveness of the ITAM system. Continual Improvement Advisory Review

How Our Systems Satisfy
ISO/IEC 19770

Each component of the UNUS London compliance infrastructure maps directly to one or more parts of the 19770 standard. The following cards detail exact system capabilities and the clauses they address.

Part 1 — §8.2.3
🗄️
IT Asset Register — PostgreSQL Layer

Structured Asset Register

A production PostgreSQL schema provides the formal IT asset register required under Clause 8.2.3. Every hardware and software asset is stored with complete lifecycle attributes, unique asset IDs, responsible owner, procurement date, and disposal records.

  • Immutable insert-only audit log via database triggers — no record can be altered without a logged change event
  • UUID-keyed asset records with FK relationships to supplier, location, and owner tables
  • Asset lifecycle status ENUM: active | retired | disposal | lost | stolen
  • Sub-30-second evidence retrieval for any asset at audit time
Part 2 — SWID
🏷️
Software Identification — SWID Integration

Software Discovery & Tagging

The software asset module ingests and stores SWID tag data via structured n8n workflows, creating a reconcilable record of all installed software titles against the asset register entries. This enables automated licence compliance checking.

  • SWID tag ingestion webhook — receives discovery payloads from endpoint agents
  • Software title normalisation against publisher canonical names
  • Version tracking with upgrade eligibility flags per entitlement constraints
  • Orphaned software alerts — installed titles with no matching entitlement record
Part 3 — SWEN
📜
Entitlement Ledger — Licence Compliance

Entitlement Management

A dedicated entitlements schema records all software licence rights, matching purchased quantities against installed deployments. The system surfaces licence deficits, surpluses, and constraint violations in real time.

  • Entitlement records store metric type: per-device, per-user, per-core, concurrent
  • Automated deficit calculation: entitlement_qty - deployed_qty with alert triggers
  • Contract expiry calendar with advance notification via n8n scheduled workflows
  • Publisher audit response pack generated on-demand from database views
Part 4 — RUM
📊
Usage Measurement — RUM Data Collection

Resource Utilisation Tracking

The RUM module captures last-used timestamps, usage duration, and attributed user data per software installation. This evidences actual consumption against purchased entitlements and supports licence reclamation decisions.

  • Usage telemetry ingestion via webhook → PostgreSQL time-series table
  • Zero-use identification: software with no activity in configurable lookback window
  • Per-user consumption reports for named-user licence reconciliation
  • Automated reclamation workflow: n8n triggers notification when licence is reclaimable
Part 1 — §9.2
🔍
Internal Audit — Automated Evidence Generation

ITAM Audit Readiness

Scheduled n8n workflows execute internal ITAM audit queries at configured intervals, generating compliance evidence packs that satisfy Clause 9.2 internal audit requirements. Every execution is logged with timestamp and outcome.

  • Weekly automated asset reconciliation report delivered to IT Asset Manager inbox
  • Audit trail of all asset status changes with approving user identity
  • Nonconformity register for assets that fail validation rules
  • Evidence pack generation: asset register snapshot + entitlement summary + RUM data
Part 1 — §6.1.2
⚠️
Risk Management — ITAM Risk Register

IT Asset Risk Register

A structured risk register captures ITAM-specific risks including unlicensed software, end-of-life assets, data-bearing assets without encryption, and missing maintenance contracts. Risk ratings follow a probability × impact matrix aligned to ISO 31000.

  • Risk record schema: asset_id, risk_type, likelihood, impact, risk_score, owner
  • Automated risk score recalculation on asset record changes
  • End-of-life hardware alerts: assets within 90 days of vendor support termination
  • Unlicensed software automatic risk creation on SWID/entitlement mismatch

The ISO 19770-1
Maturity Model

ISO/IEC 19770-1:2017 introduced a four-tier maturity architecture. Organisations progress through tiers sequentially. Certification is achievable at any tier. UNUS London deployments satisfy Tiers 1–3 at go-live, with Tier 4 supported through quarterly architecture reviews.

1
Trustworthy Data
Establishes foundational data quality. The organisation shall have accurate, complete, and current IT asset data as the basis for all subsequent management activity.
  • Asset register established
  • Data accuracy controls
  • Ownership assigned
  • Lifecycle status tracked
UNUS: Day 1
2
Practical Management
Operational ITAM processes are in place and producing value. Software licence positions are tracked and reconciled. Hardware is actively managed through its lifecycle.
  • Licence reconciliation
  • Procurement integration
  • Disposal processes
  • Contract management
UNUS: Day 14
3
Operational Integration
ITAM is integrated with other IT service management processes. Change management, incident management, and procurement are fed by and contribute to the ITAM system.
  • ITSM integration
  • Change management links
  • Automated discovery
  • RUM data in use
UNUS: Included
4
Strategic Conformance
ITAM drives strategic organisational decisions. Asset lifecycle costs inform investment planning. The ITAM system is fully aligned with corporate governance and risk frameworks.
  • Strategic cost reporting
  • Board-level visibility
  • Full risk integration
  • Continuous improvement
Quarterly Review

Gap Analysis: Common
19770 Failure Points

The following analysis identifies the most common ISO/IEC 19770 compliance gaps encountered in regulated organisations, and documents precisely how UNUS London's infrastructure addresses each one.

Cl. 8.2.3 — Asset Register
Resolved by UNUS
Incomplete or Absent Asset Register
The majority of regulated organisations lack a structured, evidenceable IT asset register. Spreadsheets are not auditable and cannot satisfy Clause 8.2.3 requirements for documented information. Regulators and licence publishers routinely reject informal records.
UNUS Resolution A production PostgreSQL asset register is deployed with enforced schema, mandatory field validation, and immutable audit logging. Every asset record includes: UUID, category, make/model, serial number, assigned user, location, procurement date, and current lifecycle status. Retrievable in under 30 seconds during live audit.
Cl. 8.2.3 — Software Reconciliation
Configuration Required
No Licence Reconciliation Process
Organisations routinely hold more software installations than licensed entitlements, or maintain paid entitlements for software no longer deployed. Both conditions create audit exposure. Manual reconciliation is error-prone and non-repeatable per ITIL standards.
UNUS Resolution The entitlement ledger schema provides automated licence position calculation. Deficit and surplus views update in real time. Weekly reconciliation reports are auto-generated and delivered to the IT Asset Manager. The process is repeatable, documented, and timestamped — satisfying the ITIL Definition of Done.
Cl. 7.5 — Documented Information
Resolved by UNUS
No Immutable Audit Trail
Clause 7.5 requires documented information that demonstrates conformance. File-based records, email threads, and mutable spreadsheets fail this requirement under external audit. Organisations cannot evidence the state of assets at a specific historical point in time.
UNUS Resolution Database-layer triggers create an append-only audit log for every asset record mutation. The log captures: changed field, old value, new value, changed_by (user ID), and changed_at (timestamp with timezone). Historical asset state can be reconstructed for any point in time. This is structurally immutable — application-layer changes cannot suppress it.
Cl. 9.2 — Internal Audit
Resolved by UNUS
Internal Audit Not Evidenced
Clause 9.2 requires that internal ITAM audits be conducted at planned intervals and that results be documented. Most organisations conduct ad hoc checks only and cannot evidence a systematic audit programme to external auditors or regulators.
UNUS Resolution Scheduled n8n workflows execute ITAM audit queries weekly. Each execution generates a timestamped audit record in the itam_audit_log table, capturing findings, exception count, and resolution status. Audit history is fully retrievable, providing the systematic programme evidence required by Clause 9.2.

ITAM Evidence
Retrieval in Under 30 Seconds

When a licence auditor or regulator requests evidence of software asset compliance, the UNUS London system produces structured, timestamped records in seconds — not hours. The following illustrates a live audit query session.

unus@itam-db:~$ psql -d unus_itam -c "SELECT * FROM vw_licence_compliance_position;"
-- ISO/IEC 19770-1 Cl.8.2.3 | Licence Position View | Generated: 2026-03-09 09:14:22 UTC
software_title | publisher | entitled_qty | deployed_qty | position | status
-----------------------+--------------------+--------------+--------------+-----------+----------
Microsoft 365 E3 | Microsoft Corp | 250 | 247 | +3 | SURPLUS
Adobe Acrobat Pro DC | Adobe Systems | 45 | 45 | 0 | COMPLIANT
AutoCAD 2025 | Autodesk Inc | 12 | 14 | -2 | DEFICIT ⚠
Slack Pro | Salesforce Inc | 300 | 298 | +2 | SURPLUS
Zoom Workplace Pro | Zoom Video Comm. | 150 | 150 | 0 | COMPLIANT
-- 1 DEFICIT detected. Risk record auto-created. Notifying IT Asset Manager.
unus@itam-db:~$ SELECT * FROM itam_audit_log WHERE asset_id = 'a3f8...' ORDER BY changed_at DESC LIMIT 5;
-- Immutable audit trail — Cl. 7.5 Documented Information
event_id | asset_id | field | old_value | new_value | changed_by | changed_at
-----------+---------+-------------+------------+------------+--------------+---------------------
e-00847 | a3f8... | status | active | retired | jsmith@firm | 2026-03-07 14:22:09
e-00791 | a3f8... | assigned_to | p.jones | k.adams | admin@firm | 2026-01-14 09:05:37
e-00653 | a3f8... | location | Floor 2 W | Floor 3 E | p.jones@firm | 2025-11-03 11:47:22
-- Elapsed: 0.018s | 3 rows | Audit trail confirmed. Evidence pack ready for export.
unus@itam-db:~$ _

ISO 19770 Compliance
Assessment

The UNUS London ITAM system achieves a composite readiness score of 91/100 against ISO/IEC 19770-1:2017. Scores are calculated across five assessment dimensions using weighted clause coverage.

0
Overall Readiness Score
StandardISO/IEC 19770-1:2017
Maturity TierTier 3 — Operational
Certification Ready✓ Yes — Tiers 1–3
Asset Register Completeness
97%
Licence Reconciliation Accuracy
93%
Audit Trail Integrity
99%
Internal Audit Programme
88%
Risk Management Coverage
82%
RUM Data Collection
87%
Documented Information (Cl.7.5)
95%

From Zero to
19770-Compliant in 14 Days

UNUS London delivers a production-ready ITAM system aligned to ISO/IEC 19770-1:2017 Tiers 1–3 within a 14-day structured deployment programme. All deliverables are transferred with full code ownership.

D1–2
Phase 1 — Context & Scoping
ITAM Scope Definition & Asset Classification
Discovery session to document the ITAM boundary, asset categories in scope (hardware, software, cloud, SaaS), and existing data sources. Asset classification taxonomy agreed and encoded as database ENUM values. Satisfies Clause 4.3 Scope Documentation.
Scope Document Asset Classification Schema Database ENUM Config
D3–5
Phase 2 — Asset Register Build
PostgreSQL Asset Register Deployment
Production database schema deployed on Supabase. Asset register table created with all required fields, UUID primary keys, and referential integrity constraints. Audit trigger functions deployed. Initial data migration from existing sources executed and validated. Satisfies Clause 8.2.3.
Asset Register Schema Audit Trigger Functions Data Migration Report
D6–8
Phase 3 — Licence & Entitlement Engine
Entitlement Ledger & SWID Integration
Entitlement schema deployed. All current software licences catalogued with metrics, quantities, and expiry dates. SWID ingestion webhook configured. Initial licence position calculated and deficit/surplus report generated. Satisfies Parts 2 and 3 of the standard.
Entitlement Schema SWID Webhook Licence Position Report
D9–11
Phase 4 — Automation & RUM
n8n Workflow Deployment & Usage Measurement
n8n automation workflows deployed: weekly audit report generation, licence deficit alerts, contract expiry notifications, and RUM data ingestion. Satisfies Clause 9.1 monitoring and measurement requirements and Part 4 resource utilisation measurement.
Audit Report Workflow Alert Workflows RUM Ingestion Config
D12–14
Phase 5 — Handover & Documentation
Evidence Pack, Training & Code Transfer
Full code ownership transferred. ITAM policy document produced. Internal audit procedure documented. Staff training session delivered. Initial evidence pack generated demonstrating compliance across Tiers 1–3. System is in production operation on Day 14.
ITAM Policy Document Internal Audit Procedure Full Code Ownership Evidence Pack

Software Asset Management,
Continuously Evidenced.

ISO 19770-1:2017 requires software asset management processes that produce verifiable evidence of compliance — not an annual license audit and a static inventory. UNUS Govern's Asset Monitor is built for this: it continuously tracks your software inventory, license entitlements, configuration items, and compliance state against the 19770-1 SAM processes. When the next external audit or internal review lands, the evidence layer is already current — because the system never stopped watching.

  • Continuous software inventory tracking (live)
  • License entitlement vs deployment reconciliation
  • Configuration Item (CI) state monitoring
  • Annual SAM review evidence pack (auto-generated)

Part of UNUS Govern's continuous evidence layer.
Available as a monthly subscription. Cancel anytime.

Ready to build an
ISO 19770-compliant ITAM system?

A 60-minute discovery call establishes your current ITAM maturity tier, identifies your critical licence compliance gaps, and scopes exactly what will be built and transferred to you. No sales pitch — a structured technical assessment.