
An asset management policy defines what is tracked, who is responsible, and what must happen at each stage of an asset's life. Keep it to two pages: policies longer than that are filed rather than followed, and the detail belongs in procedures that can change without a governance cycle.
Asset management policies fail in one of two directions, and I've reviewed plenty of both.
Either it's three sentences that commit to nothing anyone could be held to, or it's fourteen pages that nobody has opened since the approval meeting. Neither changes what happens on a Tuesday.
A policy has one job: make it unambiguous who is responsible for what, and what has to happen at each stage. Everything else is procedure, and procedure belongs somewhere it can change without a governance cycle.
Structure
|
Section |
What it settles |
Length |
|---|---|---|
|
Purpose and scope |
Which assets this covers and which it does not |
A short paragraph |
|
Roles and responsibilities |
Who owns the register, who approves, who custodies |
A short table |
|
Acquisition and registration |
What must be recorded, and when |
A list |
|
Tagging and identification |
What gets tagged and how it is identified |
A list |
|
Custody and movement |
Issue, transfer and return rules |
A list |
|
Maintenance and inspection |
What is scheduled and who owns it |
A short paragraph |
|
Verification and audit |
Frequency and evidence |
A short paragraph |
|
Disposal |
Authorisation and record-closing |
A list |
|
Review |
When the policy itself is revisited |
One line |
The clauses that actually matter
Scope, including the threshold
State the value threshold for capitalisation and, separately, the threshold for operational tracking. Conflating them is the most common policy error, because it leaves low-value portable equipment untracked — which is precisely what goes missing.
A single named owner of the register
Not a committee and not a department. One role, named, accountable for the register's accuracy. Registers without a named owner drift by default, and every subsequent clause depends on somebody being answerable.
Custody rules with a signature requirement
State that assets above a defined value are issued to a named individual and that acceptance is recorded. Include what happens on internal transfer and on departure — departures are the single most concentrated source of loss, and the policy should be explicit that recovery is initiated by the leaver process.
Disposal authorisation
State who can authorise disposal, what evidence is required, and — the part usually omitted — that the register record must be closed with a disposal date and method. Unclosed disposals create phantom assets that inflate every count afterwards.
Verification frequency
Commit to a frequency and a coverage target. "Periodically" commits to nothing. "Every asset verified at least annually, achieved through rolling quarterly counts by department" is a policy somebody can be held to.
Roles, in the only form that works
Most policies write this as a paragraph of prose and it settles nothing. A table settles it.
|
Role |
Accountable for |
Typical holder |
|---|---|---|
|
Register owner |
Accuracy of the register as a whole |
One named person, not a committee |
|
Custodian |
The specific items issued to them |
Whoever holds the equipment |
|
Approver |
Authorising acquisition and disposal |
Budget holder |
|
Verifier |
Carrying out counts |
Independent of the custodian, where possible |
|
Maintainer |
Servicing and statutory inspection |
Facilities, or a named contractor |
The first row is the one that decides whether any of this happens. A register owned by "the operations team" is owned by nobody, and it will drift by default.
Thresholds, stated separately
Two numbers, and conflating them is the most common policy error I see.
- Capitalisation threshold — the value above which an item goes on the fixed asset register. A finance decision.
- Tracking threshold — the value above which an item is individually tracked, tagged and issued to a named holder. An operational decision, and usually much lower.
State both. A policy with one number leaves everything below it untracked, and everything below it's where equipment quietly goes.
The disposal clause people forget
Disposal clauses usually cover authorisation and data destruction and stop there. The missing sentence is that the register record must be closed with a disposal date and method.
Unclosed disposals are the largest single source of phantom assets. They make every subsequent count look worse than reality, they waste time being searched for, and after a few years they make the register untrustworthy in a way that's very hard to unpick.
A review clause that will actually fire
"Reviewed periodically" means never. Name a date, name the owner, and tie the review to something that already happens — the end of the financial year, or the annual verification — so it isn't a standalone task competing with real work.
What to leave out
- Software names. Tools change; policies should outlive them.
- Screen-by-screen procedure. That is a work instruction, and it will be wrong within a release.
- Unenforceable liability clauses. Wage deductions for lost equipment are restricted in many jurisdictions; an unenforceable clause weakens the document.
- Aspirations. "Best-in-class asset stewardship" is not a rule anyone can follow or breach.
A structure you can copy
If you want somewhere to start, this is the skeleton I would use. Each section is a short paragraph or a list — the whole thing should fit on two pages.
|
Section |
One sentence that settles it |
|---|---|
|
1. Purpose |
Why the organisation maintains an asset register at all. |
|
2. Scope |
Which assets are covered, with the capitalisation and tracking thresholds stated separately. |
|
3. Roles |
The table from earlier — owner, custodian, approver, verifier, maintainer. |
|
4. Acquisition |
What must be recorded before an asset enters service, and who checks. |
|
5. Identification |
What gets tagged, with what, and that identifiers are meaningless and permanent. |
|
6. Custody |
Issue to named individuals, signature thresholds, transfers, and return on departure. |
|
7. Maintenance |
What is scheduled, who owns it, and that out-of-certification equipment cannot be issued. |
|
8. Verification |
Frequency, coverage target, independence, and what the output must contain. |
|
9. Disposal |
Who authorises, what evidence is kept, and that the record is closed. |
|
10. Review |
The date, the owner, and what triggers an earlier review. |
Getting it approved without it being watered down
Policies get softened in review, usually by replacing anything measurable with something unfalsifiable. "Assets will be verified annually" becomes "assets will be verified periodically", and the policy stops meaning anything.
- Bring the baseline. A measured accuracy figure makes the case for a specific commitment far better than an argument does.
- Separate what is required from what is good practice, explicitly. Reviewers soften things because they cannot tell which is which.
- Name the owner before the meeting, ideally with their agreement. An unowned policy invites the vaguest possible wording.
- Accept a lower commitment rather than a vaguer one. Quarterly counts on high-value categories is a real policy; 'regular counts' is not.
Making it real
A policy takes effect through three things, none of which are the document.
- A named owner who is actually asked about register accuracy at intervals.
- A system that makes the policy the path of least resistance. If policy-compliant behaviour is slower than the alternative, the policy loses.
- A measurement. Register accuracy, verification coverage and overdue inspections, reported somewhere visible.
Without those, the policy is a document that exists so somebody can point at it. With them, it's the description of how the organisation already behaves — which is what a good policy actually is.
Key takeaways
- Keep the policy to about two pages; detail belongs in procedures that can change without governance.
- State the capitalisation threshold and the operational tracking threshold separately.
- Name one role as owner of the register — committees do not own accuracy.
- Require disposal records to be closed; unclosed disposals create phantom assets.
- Commit to a verification frequency and coverage target rather than 'periodically'.
Frequently asked questions
What should an asset management policy include?
Purpose and scope, roles and responsibilities, acquisition and registration requirements, tagging, custody and movement rules, maintenance and inspection, verification and audit frequency, disposal authorisation, and a review date for the policy itself.
How long should an asset management policy be?
About two pages. Longer policies get filed rather than followed, and operational detail changes faster than a governance cycle — so it belongs in procedures or work instructions referenced by the policy instead.
Who should own the asset management policy?
One named role, accountable for register accuracy and answerable for it at defined intervals. Ownership by a committee or a department in the abstract is the most reliable predictor that nobody will maintain the register.
Should an asset policy name the software used?
No. Policies should outlive tools. Reference the register generically and keep system-specific instructions in a separate procedure that can be updated without reapproving the policy.
What is the difference between a policy and a procedure here?
The policy states what must be true and who is responsible. The procedure states how to do it in the current system. The first should change rarely; the second will change whenever the tooling does.
Do small businesses need an asset management policy?
A two-page one, yes, and mostly so that responsibility is unambiguous when the person who has been quietly handling it is away or leaves. The governance apparatus that suits a large organisation does not, and copying one is how small businesses end up with a policy nobody follows.
How often should an asset management policy be reviewed?
Annually, tied to something that already happens — the financial year end, or your annual verification — so it is not a standalone task competing with real work. Review earlier if the estate changes materially, or if a count reveals the policy is describing something you no longer do.
What is the difference between an asset policy and an asset register?
The policy states what must happen and who is responsible. The register is the record produced by following it. A policy with no register is an intention; a register with no policy tends to have no owner, which is why it drifts.