← All posts

6 Step ISO 27001 Asset Inventory Playbook for Compliance Teams

An ISO 27001 asset inventory is a maintained, auditable register of information and associated assets, built to satisfy control A.5.9 of ISO/IEC 27001:2022. The single most important action is to assign a named owner to every asset and link each entry to your risk register. Get those two things right and most audit findings on assets simply disappear.


TL;DR:

  • Assign a dedicated owner to each asset and link it to the risk register, as auditors expect clear accountability and traceability.
  • Keep the inventory live and regularly updated by integrating it into onboarding, offboarding, procurement, and review workflows to prevent drift and stale data.
  • Limit classification to three levels—Confidential, Internal, and Public—and avoid excessive granularity to ensure practical and defendable tracking.
  • Use an automated or semi-automated platform that can generate audit-ready exports, incorporate multiple frameworks, and streamline evidence collection.
  • Address common audit findings quickly by fixing missing ownership, updating review dates, and establishing risk linkages within one week before certification.

Table of Contents

What does ISO 27001 actually require for asset inventory?

Three controls in ISO/IEC 27001:2022 govern how you handle assets, and auditors treat them as a package rather than three separate boxes to tick.

A.5.9, Inventory of information and other associated assets, requires you to identify assets connected to information and information processing, then maintain a register of them. The word "maintain" carries weight here. The 2022 revision expects the inventory to reflect the live environment, not a spreadsheet somebody filled in before last year's certification audit and never opened again.

A.5.10, Acceptable use of information and other associated assets, sits alongside asset ownership. Once an asset has a named owner, that owner is responsible for defining and communicating how it should be used, handled, and protected. This is where organisations often stumble. They assign an asset to "the IT department" rather than a person, which satisfies nobody. Auditors have seen this pattern often enough that it has become one of the most commonly cited nonconformities in the entire standard.

A.5.11, Return of assets, covers what happens when someone leaves, changes role, or a contract ends. Laptops, access cards, credentials, and any physical or logical asset issued to that person need a documented return process, and evidence that the process actually ran.

If you certified under ISO 27001:2013, the renumbering matters in practice, not just cosmetically. The old A.8 asset management clauses were split and folded into the broader A.5 organisational controls group. Scope has not shrunk. If anything, "associated assets" now reads more broadly, covering cloud services and logical assets that a 2013-era inventory might have skipped entirely.

Defining "in scope" for your own inventory means answering one blunt question: does this asset touch information within your ISMS boundary, either by storing it, processing it, or granting access to it? If yes, it belongs in the register. That includes:

  • Physical hardware (laptops, servers, network kit)
  • Software licences and applications
  • Cloud services and SaaS subscriptions
  • Information assets (databases, document repositories, key data sets)
  • Personnel roles carrying privileged access or asset ownership responsibilities

What fields and categories belong in an audit-ready register?

A register that satisfies an auditor needs specific fields, not a loose collection of spreadsheet columns invented department by department. Factorial's implementation guidance and practitioner consensus converge on a consistent minimum data model.

Five categories cover almost everything an SME needs to track: information (data sets, contracts, intellectual property), software (applications, licences, code repositories), hardware (physical devices, network infrastructure), services (cloud platforms, outsourced processing, SaaS tools), and personnel (roles carrying elevated access or ownership duties, rather than named employees as assets in themselves).

Five ISO asset inventory categories

Classification levels should be kept simple. Three tiers, Confidential, Internal, and Public, cover most organisations without creating a labelling system nobody remembers to apply. Each tier needs handling rules attached directly to it: who can access it, how it's stored, whether encryption is mandatory, and what happens on disposal.

On granularity, don't over-engineer this. You don't need to list every mailbox or shared file individually. Practical registers track individual high-risk devices while aggregating lower-risk logical assets, a single entry for "Microsoft 365 tenant" rather than one per licence, provided traceability holds up where risk actually concentrates. Auditors care about defensible logic, not exhaustive granularity for its own sake. A data classification framework that maps clearly to these categories makes the whole exercise faster to build and easier to defend.

How do you build an asset inventory from scratch?

Building a compliant inventory is a sequence, not a single weekend project. Rushing straight to a spreadsheet without governance is the single most common reason registers fall apart within six months.

  1. Define scope and governance (2 to 3 days). Confirm your ISMS boundary: which business units, locations, and systems are in scope. Assign a single accountable owner for the register itself, separate from the individual asset owners you'll name later.
  2. Run discovery (1 to 2 weeks). Pull from multiple sources simultaneously: HR records for personnel and role data, procurement and contract records for software and services, automated network discovery tools for hardware and endpoints, and structured interviews with department heads to catch shadow IT that automated tools miss.
  3. Document and classify (1 week). Populate the core fields for every discovered asset and apply classification levels. This is where the minimum field set pays off, consistent structure means faster classification decisions.
  4. Assign named owners (3 to 5 days). Every asset gets a person, not a department. Ownership confirmation should be a documented step, ideally with a signed or logged acknowledgement.
  5. Link to risk assessment (ongoing). Cross-reference each classified asset against your risk register so that high-value or high-exposure assets have a corresponding, documented risk treatment.
  6. Set review triggers. Define a standard review cadence (annually at minimum) plus event-driven triggers: new hires, leavers, mergers, new supplier contracts, or infrastructure changes.

A readiness gap analysis before you start discovery often surfaces shadow IT and orphaned licences that would otherwise slip through interviews entirely.

Pro Tip: Run discovery and HR data pulls in parallel, not sequentially. Waiting for one to finish before starting the other is the single biggest cause of multi-week delays in first-time inventory builds.

Organisations with high change rates, frequent new SaaS subscriptions, distributed teams, or a fast-growing headcount, should expect discovery to take longer than the estimate above and should plan for automated tooling sooner rather than later.

How do you build an asset inventory from scratch? — overview diagram

How do you keep the asset register accurate after launch?

A register built once and never touched again is the same as no register at all, as far as an auditor is concerned. Keeping it current means wiring inventory updates directly into the business processes that already create or retire assets.

  • Joiner/mover/leaver (JML) integration. New hires trigger asset issuance entries; role changes trigger ownership and access reviews; departures trigger the A.5.11 return-of-assets process, with confirmation logged against the register.
  • Procurement integration. New software, hardware, or service contracts should not go live without a corresponding register entry created at the point of purchase, not weeks later.
  • Risk assessment linkage. Every material change to an asset's classification or exposure should prompt a review of its linked risk entries, not a separate, disconnected risk exercise.
  • Access review cadence. Periodic access reviews should reference the register directly, confirming that who has access still matches who should have access.

Organisations that tie inventory updates to onboarding and offboarding workflows see markedly fewer drift-related findings than those relying on periodic manual reconciliation. The logic is straightforward: assets change when people and contracts change, so the update trigger should live at that same moment, not on a separate calendar.

Standard review cadence should sit at a minimum of annually, with exceptional reviews triggered by: a security incident involving the asset, a change in supplier or hosting arrangement, a merger or acquisition, or a material change in data volume or sensitivity.

What evidence do auditors actually expect to see?

Auditors don't want to hear that a register exists. They want to see it, cross-reference it, and confirm it's alive. The evidence auditors commonly request breaks down into a short, predictable list.

  • A full register export, timestamped, showing every required field populated.
  • Owner confirmation records, evidence that named owners acknowledged their assignment, not just an entry in a spreadsheet column.
  • Review logs, dated records showing the register was reviewed on schedule, with any changes noted.
  • Disposal certificates or decommissioning records for retired hardware, cross-referenced to the register entry they close out.
  • Risk register cross-references, showing that classified assets link to a corresponding risk treatment, not a orphaned classification with no downstream action.

Generic ownership and stale records account for the majority of asset-related nonconformities raised in ISO 27001 audits. Both are fixable within days once identified, which makes them frustrating findings to receive, since they usually reflect a process gap rather than a genuine security failure.

Cross-referencing is the detail most teams skip. An asset classified as "Confidential" with no linked risk entry looks incomplete to an auditor, even if the classification itself is correct. Build the linkage into your template from day one rather than retrofitting it before an audit.

When should you move off spreadsheets?

Spreadsheets work for small, stable environments. They stop working once change outpaces your ability to track it manually. Two practical triggers signal it's time: your asset count crosses roughly 150 to 200 tracked items, or your rate of change (new SaaS subscriptions, new hires, contract turnover) exceeds what one person can reconcile weekly without errors creeping in.

Whatever tooling you adopt, it needs to deliver on a short but non-negotiable list:

  • Automated or semi-automated discovery, so new assets don't rely on someone remembering to log them
  • HR system integration for joiner/mover/leaver triggers
  • A structured owner resolution workflow, not a free-text field
  • One-click audit export in a format an assessor can actually use
  • An immutable review log showing who changed what, and when

Pro Tip: Ask any vendor demonstrating asset management capability to show you a live audit export, not a marketing screenshot. If it takes more than two clicks to generate, it will slow you down on audit week.

If you're evaluating IT asset management approaches more broadly, the same discovery and integration principles apply whether or not compliance is the immediate driver.

What are the top audit findings and how do you fix them fast?

Three findings recur more than any others, and all three are fixable inside a working week if you catch them before certification day.

  1. Generic or missing owners. Fix within 24 to 48 hours by assigning a named individual to every asset and logging their acknowledgement.
  2. Stale review dates. Fix within 48 to 72 hours by running a full register review, updating every "last reviewed" field, and documenting who performed it.
  3. No linkage to risk. Fix within a week by cross-referencing each classified asset against an existing risk entry, creating one where none exists.

Watch for ongoing red flags between audits: assets with no recent review activity, new SaaS subscriptions appearing on expense reports but not in the register, and departing staff whose asset returns were never logged.

How does ShieldIQ support an audit-ready inventory?

Manually chasing owner confirmations and review dates across spreadsheets is exactly the kind of overhead that pulls SME compliance leads away from actual security work. An asset register module lets you assign named owners, tag classification levels, and generate an audit export directly from a platform, without a dedicated GRC team behind it.

Some platforms suit organisations juggling ISO 27001 alongside other frameworks, allowing asset entries to feed risk assessments and control mapping across NIS2, GDPR, and DORA requirements from the same record. That cross-framework linkage is where most spreadsheet-based registers fall down first.

This article's perspective section was prepared with input from Matthew Lemon, drawing on the control requirements and evidence patterns outlined above.

What actually keeps an asset register alive

Most inventory failures aren't technical. They're cultural. A register only stays accurate when someone's job depends on it staying accurate, and that means owner accountability has to be real, not decorative. If an "owner" field just holds a job title, you haven't assigned ownership at all.

The organisations that get this right build two habits nobody talks about enough. First, they tie asset review to something that already has a deadline, a quarterly access review, an HR offboarding checklist, a procurement sign-off, rather than inventing a standalone "asset review day" that gets deprioritised the moment something urgent lands. Second, they measure it: a simple internal metric like "percentage of assets reviewed in the last 90 days" surfaces drift long before an auditor does.

If you take one thing from this: stop treating the register as a compliance artefact and start treating it as an operational tool people actually consult. That shift alone prevents most of the findings covered above.

— Matthew Lemon

Get audit-ready faster with automated asset tracking

Building and maintaining an ISO 27001 asset register by hand costs most SME compliance leads weeks they don't have, especially once ownership confirmations, review logs, and risk linkages all need to stay in sync. An alternative to spreadsheet-based tracking is an asset register module that assigns named owners, applies classification levels, and generates an audit export in minutes rather than days of manual reconciliation.

ShieldIQ

Some platforms suit SMEs managing ISO 27001 alongside frameworks like DORA or the EU AI Act, allowing asset data to feed directly into risk assessments and control mapping without duplicate entry across separate tools. If your inventory currently lives across three spreadsheets and a shared drive, that is a common gap such platforms are built to close. Request a demo through ShieldIQ's platform overview to see how your existing asset data would map into an audit-ready register before your next assessment.

Where to go for templates and deeper guidance

Sources

Recommended