
Build a unified software asset register, reconcile deployment data against entitlement records on a risk-based cadence, run cross-functional governance with named owners, and operate continuous discovery. Those four actions are what ISO/IEC 27001 auditors actually look for when they review your software controls under Annex A. ISO/IEC 19770 defines the SAM standard that underpins this work, and tools like Ismscalculator can help you estimate the effort and benchmark your program against sector averages before you commit resources.
Start here this week:
- Export your top five software vendors by spend and kick off a reconciliation between deployment data and entitlement records.
- Assign an administrative owner, a financial owner, and a security owner to each asset in your register.
- Schedule your first cross-functional governance meeting with Procurement, Finance, Legal, and InfoSec.
- Run a free readiness check to baseline your current SAM maturity before your next audit cycle.
Table of Contents
- 1. What your software asset register must actually contain
- 2. How to run a reconciliation that holds up in an audit
- 3. How to build governance that actually sustains SAM
- 4. Which discovery tools and integrations give you accurate inventory
- 5. How to plan your SAM program and benchmark your progress
- 6. What auditors will actually ask for: the evidence checklist
- Key Takeaways
- Why SAM succeeds or fails under ISO 27001
- Ismscalculator helps you estimate and plan your SAM program
- Sources and further reading
1. What your software asset register must actually contain
A unified asset register is the single piece of evidence that satisfies both ISO auditors and vendor license reviewers. Every field you include should map to a specific Annex A control or audit obligation, not just fill a spreadsheet column.
Required fields for every software asset record:
- Asset identifier: unique ID that ties the record to change tickets and reconciliation reports
- Owner(s): administrative, financial, and security owners named individually
- Software stack and version: exact product name, edition, and version number
- Deployment environment: production, test, or disaster recovery
- Licence entitlement reference: PO number, contract ID, or subscription record
- ISO classification: sensitivity level and governance state (e.g., restricted, internal)
- Last-verified date: when the record was last confirmed against a live discovery signal
- Contract and renewal dates: so renewals never catch you off guard
- Supplier name and supplier-risk register reference
- SBOM link or component inventory for software with third-party dependencies
- Change history: every modification with timestamp and actor
| Field | Purpose | Example value | Annex A control |
|---|---|---|---|
| Asset identifier | Unique traceability | — | A.5.10 |
| Owner (security) | Accountability | Jane Smith, InfoSec | A.5.10 |
| Licence entitlement ref | Compliance evidence | — | A.5.10 |
| Supplier | Supplier-risk mapping | Vendor Corp | A.5.19 |
| SBOM link | Component transparency | — | A.5.21 |
| Last-verified date | Freshness signal | — | A.8.6 |
ISO/IEC 27001:2022 maps six Annex A controls to documentary obligations that intersect directly with software licensing: A.5.10, A.5.19, A.5.21, A.5.30, A.8.6, and A.8.32. Your register fields should answer each of those obligations without requiring the auditor to chase down separate documents.
One practical rule: discovery signal takes precedence over procurement records, which take precedence over identity-provider data. When sources conflict, flag the discrepancy and resolve it before the audit pack is finalized.
Pro Tip: Start with a scoped subsystem, say your top 20 applications by risk or spend, and build the register in the format your certifier expects to receive it. Expanding scope is far easier than reformatting 500 records two weeks before a Stage 2 audit.
2. How to run a reconciliation that holds up in an audit
Reconciliation between deployment discovery and entitlement records should follow a documented, repeatable workflow with a risk-tiered cadence: quarterly for high-risk or high-spend vendors, semiannual for standard vendors, and annual for low-risk vendors.
Step-by-step reconciliation workflow:
- Export a baseline snapshot from your discovery tool and your entitlement repository on the same date.
- Normalize software titles across both sources (vendor name variations, version strings, edition names).
- Match entitlements to deployments line by line; flag gaps in both directions (over-deployed and under-utilized).
- Create exception records for every gap: owner, reason, expiry date, and planned remediation.
- Remediate or document accepted risk with management sign-off.
- Publish a reconciliation report with owner signature and attach it to the audit pack.
| Vendor risk tier | Cadence | Required artifacts |
|---|---|---|
| High-risk / high-spend | Quarterly | Reconciliation report, exception register, remediation evidence |
| Standard | Semiannual | Reconciliation report, exception register |
| Low-risk / low-spend | Annual | Reconciliation report |
Audit evidence to attach to every reconciliation:
- Timestamped discovery snapshot and entitlement export
- Normalization rules document
- Named owner sign-off on the reconciliation report
- Change-history proof for any assets modified since the last cycle
- Supplier-risk register entries for vendors covered in the run
For supplier-related entitlement risks, keep contractual terms and audit-rights clauses in the same register row so reviewers can cross-reference them without requesting separate documents.
3. How to build governance that actually sustains SAM
SAM cannot live solely in IT. A cross-functional governance committee with Procurement, Finance, Legal, and InfoSec prevents shadow IT and unmanaged vendor audit exposure. Without it, ownership gaps appear the moment a vendor sends an audit notice.
Governance structure essentials:
- Named committee chair with authority to escalate to the CISO or CTO
- Quarterly governance meetings with a standing agenda: reconciliation results, exception status, upcoming renewals, and risk register updates
- RACI clarity: InfoSec approves exceptions, Finance signs reconciliation reports, Procurement owns renewals, Legal reviews contract terms
- Management review minutes that capture attendees, decisions, and action owners with due dates
Visible senior leadership sponsorship is often the decisive factor for successful ISO 27001 certification. Auditors look for evidence that top management is engaged, not just that a policy document exists. That means signed review minutes, budget approvals on record, and a named executive sponsor in your ISMS documentation.
Pro Tip: Convert every management review meeting into a reusable audit artifact. A one-page template with agenda, attendees, decisions, and action owners takes ten minutes to complete and satisfies Clause 9.3 evidence requirements without additional effort.

4. Which discovery tools and integrations give you accurate inventory
Accurate inventory requires multiple discovery signals working together. No single source covers the full estate, and ITAM tools often lack the information-security context an ISMS register requires. The ITAM database should feed the register, not replace it.
Discovery signals to combine:
- Identity provider (IdP) or SSO logs: map user seat allocations to entitlements
- Expense and payment records: surface SaaS subscriptions purchased outside IT
- SaaS admin APIs: pull active user counts and feature usage directly from vendors
- Endpoint agents: detect installed software on managed devices
- Cloud inventory APIs: enumerate cloud-hosted workloads and their software stacks
SAM capability checklist:
- Telemetry coverage across endpoints, cloud, and SaaS
- Title normalization and deduplication engine
- Entitlement repository with contract linkage
- Change history with actor and timestamp
- SBOM linkage for third-party component tracking (see software testing documentation practices for component evidence patterns)
- API integrations that export audit packs in your certifier’s preferred format
- Role-based access controls on the register itself
For SaaS-heavy environments, prioritize expense-feed and SSO integrations first. Those two sources typically surface the majority of unmanaged subscriptions that endpoint agents miss entirely.
Prioritize data coverage and exportability when selecting tools. A tool that covers 95% of your estate and exports clean CSV beats a feature-rich platform that covers 70% and requires manual formatting before every audit.
5. How to plan your SAM program and benchmark your progress
Plan in four phases: discover and baseline, reconcile and classify, remediate and govern, then automate and maintain. A mid-size enterprise should expect about six to nine months to build a complete unified register, with sequencing being the primary success factor: inventory completeness first, then accuracy, then classification and lifecycle wiring.
Planning checklist before you start:
- Define scope (which systems, locations, and asset types are in)
- Identify all data sources and integration points
- Assign owners for each asset dimension
- Set reconciliation cadence by vendor risk tier
- Define audit artifact formats and storage location
- Schedule management review dates for the next 12 months
| Phase | Focus | Key milestone |
|---|---|---|
| 1. Discover and baseline | Deploy discovery signals, export initial inventory | asset coverage confirmed |
| 2. Reconcile and classify | Run first reconciliation, assign ISO classifications | all assets with named owners |
| 3. Remediate and govern | Close exceptions, stand up governance committee | First reconciliation report signed |
| 4. Automate and maintain | Continuous discovery, automated alerts, audit-pack exports | Time-to-reclaim metric under a month |
Use the Ismscalculator readiness assessment to validate your effort estimate against sector averages and generate a phase plan you can take directly to leadership for budget approval. The role of asset inventory in ISMS effectiveness is well documented, and benchmarking against organizations at a similar maturity level saves weeks of internal debate about scope and resourcing.
6. What auditors will actually ask for: the evidence checklist
Auditors want repeatable evidence, not a perfect spreadsheet. The question they are really asking is: can you demonstrate that this control ran consistently, not just that it ran once before the audit.
Audit pack checklist:
- Unified register export with timestamps and version history
- Reconciliation reports with named owner sign-off for each cycle
- Entitlement contracts and purchase orders
- Deployment telemetry snapshots with timestamps matching reconciliation dates
- Change-management tickets that reference licence entitlements
- SBOMs or component lists for software with third-party dependencies
- Supplier-risk register entries tied to A.5.19 and A.5.21
- Management review minutes covering SAM agenda items
- Exception register with time-bound records (owner, reason, expiry, mitigation)
Structure exception records so they are auditable: every exception needs an owner, a stated reason, an expiry date, and a documented mitigation or accepted-risk decision. An open-ended exception with no expiry is a finding waiting to happen.
Pro Tip: Build an audit-ready export template that maps each artifact to the ISO clause or Annex A control it supports. When an auditor requests evidence for A.5.10, you pull one file, not six.
For ISO 27001 asset classification guidance that maps directly to these control references, the classification scheme you apply in the register should match what appears in your Statement of Applicability.
Key Takeaways
Effective ISO 27001 software asset management requires a unified register, a risk-tiered reconciliation cadence, cross-functional governance with named owners, and continuous discovery signals feeding a single source of truth.
| Point | Details |
|---|---|
| Build the register first | Capture all required fields per asset before optimizing accuracy or classification. |
| Tier your reconciliation cadence | Run quarterly for high-risk vendors, semiannual for standard, annual for low-risk. |
| Governance needs named owners | Assign administrative, financial, and security owners; hold quarterly committee reviews. |
| Plan an appropriate timeline to complete a unified register with proper sequencing, which may vary depending on the size and complexity of your organization. | |
| Ismscalculator accelerates planning | Use the readiness check and phase estimator to benchmark effort and build a leadership-ready plan. |
Why SAM succeeds or fails under ISO 27001
SAM succeeds when leadership treats it as risk management and backs it with visible sponsorship. It fails when it stays an IT-only checklist with no budget, no cross-functional ownership, and no connection to the risk register.
The most common failure pattern is not a technical one. It is an ownership gap: nobody in Finance knows the procurement records exist, nobody in Legal has reviewed the vendor audit-rights clauses, and InfoSec is reconciling manually against a stale spreadsheet. That gap surfaces during a vendor audit or a Stage 2 finding, not before.
Expect resistance from three directions: shadow IT that predates the program, fractured data sources that do not normalize cleanly, and organizational inertia around assigning financial accountability for software. None of those are unsolvable, but all three take longer than most teams budget for.
The practical fix is to convert every policy statement into an operational trigger. “Software must be registered before deployment” is a passive rule. “No procurement approval is issued without a register entry and an assigned owner” is a trigger. Onboarding, offboarding, procurement approval, and change tickets are the four natural control points where SAM either runs automatically or falls apart.
Ismscalculator helps you estimate and plan your SAM program
Before you can get leadership buy-in for a SAM program, you need a credible effort estimate and a phase plan that reflects your organization’s size, industry, and current maturity. That is exactly what Ismscalculator is built for.

Run the free 2-minute readiness check to get an instant baseline estimate and see how your current SAM maturity compares to sector averages. Save the estimate, adjust the inputs, and export a Gantt-style phase plan you can walk into a budget conversation. If your program needs external support, the vetted consultant finder connects you with implementers and lead auditors who specialize in ISO 27001 SAM programs. No guesswork, no generic templates.
Sources and further reading
Standards and primary references:
- ISO/IEC 27001:2022 (Information security management systems)
- ISO/IEC 19770 (Software asset management standard)
Practical guides used in this article:
- ISO 27001 and software licensing — Reveal Compliance (Annex A control mapping)
- Software asset management best practices — Zluri (register fields, reconciliation cadence, sequencing)
- SAM best practices that hold up in audits — Cloudaware (continuous discovery, audit pack readiness)
- ISO 27001 asset management guide — ComplyJet (risk-management framing)
- ISO 27001 certification tips — URM Consulting (leadership engagement)
- SAM guide and best practices — Asset Management Global (cross-functional governance)
Ismscalculator planning tools:
- Free 2-minute readiness check
- Full readiness assessment and effort estimator
- ISO 27001 certification checklist
- Find a vetted ISO 27001 consultant