Stackroom

How to Write an Asset Management Policy (With Structure and Examples)

What an asset management policy should cover, how long it should be, and the clauses that make the difference between a document people follow and one they file.

By Dia Fernandes, Compliance & Audit16 Sept 2026 5 min read
Colleagues collaborating over a laptop

An asset management policy defines what is tracked, who is responsible, and what must happen at each stage of an asset's life. Keep it to two pages: policies longer than that are filed rather than followed, and the detail belongs in procedures that can change without a governance cycle.

Asset management policies fail in one of two directions, and I've reviewed plenty of both.

Either it's three sentences that commit to nothing anyone could be held to, or it's fourteen pages that nobody has opened since the approval meeting. Neither changes what happens on a Tuesday.

A policy has one job: make it unambiguous who is responsible for what, and what has to happen at each stage. Everything else is procedure, and procedure belongs somewhere it can change without a governance cycle.

Structure

Section

What it settles

Length

Purpose and scope

Which assets this covers and which it does not

A short paragraph

Roles and responsibilities

Who owns the register, who approves, who custodies

A short table

Acquisition and registration

What must be recorded, and when

A list

Tagging and identification

What gets tagged and how it is identified

A list

Custody and movement

Issue, transfer and return rules

A list

Maintenance and inspection

What is scheduled and who owns it

A short paragraph

Verification and audit

Frequency and evidence

A short paragraph

Disposal

Authorisation and record-closing

A list

Review

When the policy itself is revisited

One line

The clauses that actually matter

Scope, including the threshold

State the value threshold for capitalisation and, separately, the threshold for operational tracking. Conflating them is the most common policy error, because it leaves low-value portable equipment untracked — which is precisely what goes missing.

A single named owner of the register

Not a committee and not a department. One role, named, accountable for the register's accuracy. Registers without a named owner drift by default, and every subsequent clause depends on somebody being answerable.

Custody rules with a signature requirement

State that assets above a defined value are issued to a named individual and that acceptance is recorded. Include what happens on internal transfer and on departure — departures are the single most concentrated source of loss, and the policy should be explicit that recovery is initiated by the leaver process.

Disposal authorisation

State who can authorise disposal, what evidence is required, and — the part usually omitted — that the register record must be closed with a disposal date and method. Unclosed disposals create phantom assets that inflate every count afterwards.

Verification frequency

Commit to a frequency and a coverage target. "Periodically" commits to nothing. "Every asset verified at least annually, achieved through rolling quarterly counts by department" is a policy somebody can be held to.

Roles, in the only form that works

Most policies write this as a paragraph of prose and it settles nothing. A table settles it.

Role

Accountable for

Typical holder

Register owner

Accuracy of the register as a whole

One named person, not a committee

Custodian

The specific items issued to them

Whoever holds the equipment

Approver

Authorising acquisition and disposal

Budget holder

Verifier

Carrying out counts

Independent of the custodian, where possible

Maintainer

Servicing and statutory inspection

Facilities, or a named contractor

The first row is the one that decides whether any of this happens. A register owned by "the operations team" is owned by nobody, and it will drift by default.

Thresholds, stated separately

Two numbers, and conflating them is the most common policy error I see.

  • Capitalisation threshold — the value above which an item goes on the fixed asset register. A finance decision.
  • Tracking threshold — the value above which an item is individually tracked, tagged and issued to a named holder. An operational decision, and usually much lower.

State both. A policy with one number leaves everything below it untracked, and everything below it's where equipment quietly goes.

The disposal clause people forget

Disposal clauses usually cover authorisation and data destruction and stop there. The missing sentence is that the register record must be closed with a disposal date and method.

Unclosed disposals are the largest single source of phantom assets. They make every subsequent count look worse than reality, they waste time being searched for, and after a few years they make the register untrustworthy in a way that's very hard to unpick.

A review clause that will actually fire

"Reviewed periodically" means never. Name a date, name the owner, and tie the review to something that already happens — the end of the financial year, or the annual verification — so it isn't a standalone task competing with real work.

What to leave out

  • Software names. Tools change; policies should outlive them.
  • Screen-by-screen procedure. That is a work instruction, and it will be wrong within a release.
  • Unenforceable liability clauses. Wage deductions for lost equipment are restricted in many jurisdictions; an unenforceable clause weakens the document.
  • Aspirations. "Best-in-class asset stewardship" is not a rule anyone can follow or breach.

A structure you can copy

If you want somewhere to start, this is the skeleton I would use. Each section is a short paragraph or a list — the whole thing should fit on two pages.

Section

One sentence that settles it

1. Purpose

Why the organisation maintains an asset register at all.

2. Scope

Which assets are covered, with the capitalisation and tracking thresholds stated separately.

3. Roles

The table from earlier — owner, custodian, approver, verifier, maintainer.

4. Acquisition

What must be recorded before an asset enters service, and who checks.

5. Identification

What gets tagged, with what, and that identifiers are meaningless and permanent.

6. Custody

Issue to named individuals, signature thresholds, transfers, and return on departure.

7. Maintenance

What is scheduled, who owns it, and that out-of-certification equipment cannot be issued.

8. Verification

Frequency, coverage target, independence, and what the output must contain.

9. Disposal

Who authorises, what evidence is kept, and that the record is closed.

10. Review

The date, the owner, and what triggers an earlier review.

Getting it approved without it being watered down

Policies get softened in review, usually by replacing anything measurable with something unfalsifiable. "Assets will be verified annually" becomes "assets will be verified periodically", and the policy stops meaning anything.

  • Bring the baseline. A measured accuracy figure makes the case for a specific commitment far better than an argument does.
  • Separate what is required from what is good practice, explicitly. Reviewers soften things because they cannot tell which is which.
  • Name the owner before the meeting, ideally with their agreement. An unowned policy invites the vaguest possible wording.
  • Accept a lower commitment rather than a vaguer one. Quarterly counts on high-value categories is a real policy; 'regular counts' is not.

Making it real

A policy takes effect through three things, none of which are the document.

  1. A named owner who is actually asked about register accuracy at intervals.
  2. A system that makes the policy the path of least resistance. If policy-compliant behaviour is slower than the alternative, the policy loses.
  3. A measurement. Register accuracy, verification coverage and overdue inspections, reported somewhere visible.

Without those, the policy is a document that exists so somebody can point at it. With them, it's the description of how the organisation already behaves — which is what a good policy actually is.

Key takeaways

  • Keep the policy to about two pages; detail belongs in procedures that can change without governance.
  • State the capitalisation threshold and the operational tracking threshold separately.
  • Name one role as owner of the register — committees do not own accuracy.
  • Require disposal records to be closed; unclosed disposals create phantom assets.
  • Commit to a verification frequency and coverage target rather than 'periodically'.

Frequently asked questions

What should an asset management policy include?

Purpose and scope, roles and responsibilities, acquisition and registration requirements, tagging, custody and movement rules, maintenance and inspection, verification and audit frequency, disposal authorisation, and a review date for the policy itself.

How long should an asset management policy be?

About two pages. Longer policies get filed rather than followed, and operational detail changes faster than a governance cycle — so it belongs in procedures or work instructions referenced by the policy instead.

Who should own the asset management policy?

One named role, accountable for register accuracy and answerable for it at defined intervals. Ownership by a committee or a department in the abstract is the most reliable predictor that nobody will maintain the register.

Should an asset policy name the software used?

No. Policies should outlive tools. Reference the register generically and keep system-specific instructions in a separate procedure that can be updated without reapproving the policy.

What is the difference between a policy and a procedure here?

The policy states what must be true and who is responsible. The procedure states how to do it in the current system. The first should change rarely; the second will change whenever the tooling does.

Do small businesses need an asset management policy?

A two-page one, yes, and mostly so that responsibility is unambiguous when the person who has been quietly handling it is away or leaves. The governance apparatus that suits a large organisation does not, and copying one is how small businesses end up with a policy nobody follows.

How often should an asset management policy be reviewed?

Annually, tied to something that already happens — the financial year end, or your annual verification — so it is not a standalone task competing with real work. Review earlier if the estate changes materially, or if a count reveals the policy is describing something you no longer do.

What is the difference between an asset policy and an asset register?

The policy states what must happen and who is responsible. The register is the record produced by following it. A policy with no register is an intention; a register with no policy tends to have no owner, which is why it drifts.