The ISO/IEC 19770 family establishes internationally recognised requirements for IT Asset Management. UNUS London deploys database-first ITAM infrastructure that satisfies all five parts of the standard — from software identification to resource utilisation measurement.
ISO/IEC 19770 is a multi-part standard. Each part governs a distinct dimension of IT Asset Management. Together they form an integrated governance framework that regulators, auditors, and licence publishers recognise globally.
The table below maps key ISO/IEC 19770-1:2017 clauses to their mandatory requirements, prescriptive language, and UNUS London's fulfilment status. Conformance language follows ISO/IEC Directives, Part 2.
| Clause Ref. | Requirement (shall) | ITAM Domain | UNUS Status |
|---|---|---|---|
| Cl. 4.1 | The organisation shall determine external and internal issues relevant to its purpose and that affect its ability to achieve the intended outcome of its ITAM system. | Context | Fully Met |
| Cl. 4.3 | The organisation shall determine the boundaries and applicability of the ITAM system and shall document the scope. | Scope Definition | Fully Met |
| Cl. 5.1 | Top management shall demonstrate leadership and commitment with respect to the ITAM system by ensuring that the ITAM policy and objectives are established. | Leadership | Fully Met |
| Cl. 6.1.2 | The organisation shall plan how to address identified ITAM risks and opportunities, and shall maintain documented information as evidence of planning results. | Risk Planning | Fully Met |
| Cl. 6.2 | The organisation shall establish ITAM objectives at relevant functions, levels, and processes. Objectives shall be measurable, monitored, and updated as appropriate. | Objectives | Fully Met |
| Cl. 7.5 | The organisation shall maintain documented information required by the ITAM standard, including the IT asset register and associated lifecycle records. | Documented Information | Fully Met |
| Cl. 8.1 | The organisation shall plan, implement, control, and review ITAM processes needed to meet requirements, and shall retain documented information to demonstrate conformance. | Operational Control | Fully Met |
| Cl. 8.2.3 | The organisation shall maintain the IT asset register and shall ensure it reflects the current state of IT assets under management with sufficient detail for each tier of maturity targeted. | Asset Register | Fully Met |
| Cl. 8.3 | The organisation shall identify and manage risks associated with IT assets, including unauthorised software, licence non-compliance, and end-of-life hardware. | Risk Management | Partial — Config Req. |
| Cl. 9.1 | The organisation shall determine what needs to be monitored and measured, the methods for analysis and evaluation, and when results shall be analysed and reported. | Performance Evaluation | Fully Met |
| Cl. 9.2 | The organisation shall conduct internal ITAM audits at planned intervals to determine whether the ITAM system conforms to the requirements of this standard. | Internal Audit | Fully Met |
| Cl. 10.1 | The organisation shall continually improve the suitability, adequacy, and effectiveness of the ITAM system. | Continual Improvement | Advisory Review |
Each component of the UNUS London compliance infrastructure maps directly to one or more parts of the 19770 standard. The following cards detail exact system capabilities and the clauses they address.
A production PostgreSQL schema provides the formal IT asset register required under Clause 8.2.3. Every hardware and software asset is stored with complete lifecycle attributes, unique asset IDs, responsible owner, procurement date, and disposal records.
active | retired | disposal | lost | stolenThe software asset module ingests and stores SWID tag data via structured n8n workflows, creating a reconcilable record of all installed software titles against the asset register entries. This enables automated licence compliance checking.
A dedicated entitlements schema records all software licence rights, matching purchased quantities against installed deployments. The system surfaces licence deficits, surpluses, and constraint violations in real time.
entitlement_qty - deployed_qty with alert
triggersThe RUM module captures last-used timestamps, usage duration, and attributed user data per software installation. This evidences actual consumption against purchased entitlements and supports licence reclamation decisions.
Scheduled n8n workflows execute internal ITAM audit queries at configured intervals, generating compliance evidence packs that satisfy Clause 9.2 internal audit requirements. Every execution is logged with timestamp and outcome.
A structured risk register captures ITAM-specific risks including unlicensed software, end-of-life assets, data-bearing assets without encryption, and missing maintenance contracts. Risk ratings follow a probability × impact matrix aligned to ISO 31000.
ISO/IEC 19770-1:2017 introduced a four-tier maturity architecture. Organisations progress through tiers sequentially. Certification is achievable at any tier. UNUS London deployments satisfy Tiers 1–3 at go-live, with Tier 4 supported through quarterly architecture reviews.
The following analysis identifies the most common ISO/IEC 19770 compliance gaps encountered in regulated organisations, and documents precisely how UNUS London's infrastructure addresses each one.
itam_audit_log table, capturing findings, exception
count, and resolution status. Audit history is fully retrievable, providing the systematic
programme evidence required by Clause 9.2.
When a licence auditor or regulator requests evidence of software asset compliance, the UNUS London system produces structured, timestamped records in seconds — not hours. The following illustrates a live audit query session.
The UNUS London ITAM system achieves a composite readiness score of 91/100 against ISO/IEC 19770-1:2017. Scores are calculated across five assessment dimensions using weighted clause coverage.
UNUS London delivers a production-ready ITAM system aligned to ISO/IEC 19770-1:2017 Tiers 1–3 within a 14-day structured deployment programme. All deliverables are transferred with full code ownership.
ISO 19770-1:2017 requires software asset management processes that produce verifiable evidence of compliance — not an annual license audit and a static inventory. UNUS Govern's Asset Monitor is built for this: it continuously tracks your software inventory, license entitlements, configuration items, and compliance state against the 19770-1 SAM processes. When the next external audit or internal review lands, the evidence layer is already current — because the system never stopped watching.
Part of UNUS Govern's continuous evidence layer.
Available as a monthly subscription. Cancel anytime.
A 60-minute discovery call establishes your current ITAM maturity tier, identifies your critical licence compliance gaps, and scopes exactly what will be built and transferred to you. No sales pitch — a structured technical assessment.