IT assets are essential to the continuity, security and financial performance of your organization. Without systematic IT asset management, software licenses, hardware, cloud services and other technology assets can introduce financial, operational and information security risks.
ISO/IEC 19770-1 certification provides independent confirmation that your organization has implemented an effective IT asset management system. It enables you to demonstrate that IT assets are managed systematically throughout their life cycle.
Would you like to discuss whether ISO 19770-1 certification is relevant to your organization? Schedule an introductory meeting to discuss the scope and certification process.
What is ISO 19770-1?
ISO 19770-1 is the international management system standard for IT asset management, also known as ITAM. The standard specifies requirements for establishing, implementing, maintaining and continually improving an IT asset management system. ISO 19770-1 can be applied to different types of IT assets and by organizations of all types and sizes. Using a process oriented and risk based approach, the standard addresses IT assets throughout their life cycle. It also considers their relationship with other organizational processes, including financial management and information security.
The current version of the standard is ISO/IEC 19770-1:2017. This version was reviewed and confirmed in 2024 and therefore remains current.
Why is ISO 19770-1 important?
IT has become a critical component of almost every organization. As a result, effective IT asset management is receiving increasing attention from senior management and boards. Inadequate management of IT assets can lead to unnecessary expenditure, contractual issues, security vulnerabilities and operational disruption. Software licenses may remain unused or be deployed incorrectly, while hardware and other IT assets may no longer receive the required security updates. An IT asset management system provides a structured basis for controlling these risks. It creates greater insight into which IT assets are used, who is responsible for them and how they are managed throughout their life cycle.
What are the benefits of ISO 19770-1 certification?
ISO 19770-1 certification enables your organization to:
- demonstrate that IT assets are managed systematically
- gain greater insight into IT assets and their life cycles
- manage financial, operational and information security risks
- provide management with independent evidence of effective IT asset management
- increase the visibility of IT asset management at board level
- integrate IT asset management with other management systems
Certification does not assess individual IT assets in isolation. It assesses whether the management system used to control these assets meets the requirements of ISO 19770-1 and operates effectively.
Who can apply for ISO 19770-1 certification?
Organizations of all types and sizes can start an ISO 19770-1 certification process. To achieve certification, the organization must have an IT asset management system in place and be able to demonstrate that it meets the applicable requirements. An important first step is defining the scope of the management system. Organizations often use many different types of IT assets across multiple departments, locations or legal entities. The scope must therefore clearly specify which activities, assets and organizational units are covered by the certification.
The ISO 19770-1 certification process
The certification process consists of several stages.
Introductory meeting
During an introductory meeting, one of our account managers explains the ISO 19770-1 certification process. We discuss the intended scope, your organization and the structure of the audit. The meeting also provides insight into how ISO 19770-1 relates to other management system standards and what you can expect from the independent assessment.
Optional gap analysis
Before starting the certification audit, Brand Compliance can perform a gap analysis. This assessment provides independent insight into the differences between your current IT asset management system and the requirements of ISO 19770-1. The assessment also considers the proposed certification scope. You receive a report containing the requirements that have not yet been demonstrably fulfilled. The gap analysis does not include implementation advice and is separate from the certification decision.
Stage 1 audit
Stage 1 is the first stage of the initial certification audit. During this stage, the auditor assesses whether the design and documented elements of the IT asset management system meet the requirements of ISO 19770-1 and whether the organization is ready for Stage 2.
Stage 2 audit
Stage 2 is a more extensive assessment of the implementation and effectiveness of the management system. The auditor conducts interviews, reviews documented information and assesses whether established processes and procedures are followed in practice.
Certification decision
After the audit has been completed and any identified nonconformities have been addressed, the audit report is submitted to Brand Compliance’s independent Certification Committee. The Certification Committee reviews the audit findings and decides whether the ISO 19770-1 certificate can be issued. This ensures that the certification decision is made independently of the audit team. The process used by Brand Compliance follows the stages described by the ITAM Forum for its ISO 19770-1 certification scheme.
How long is ISO 19770-1 certification valid?
An ISO 19770-1 certificate is valid for three years. Surveillance audits are conducted during the certification cycle to assess whether the management system continues to meet the requirements and operates effectively. Before the certificate expires, a recertification audit is conducted. During this audit, the management system is assessed again as part of a new three-year certification cycle.
Combining ISO 19770-1 with other management systems
ISO 19770-1 follows the structure used for ISO management system standards. This facilitates integration with standards such as ISO 27001 and ISO 9001. If your organization already has an established management system, its processes may provide a basis for incorporating IT asset management. This may include existing processes for risk management, internal audits, management reviews, continual improvement and the control of documented information. The specific IT asset management requirements of ISO 19770-1 must still be demonstrably implemented and assessed.
Brand Compliance and the ITAM Forum
The ITAM Forum is the owner of the ISO/IEC 19770-1 certification scheme. It established a Committee of Experts consisting of almost 100 professionals from 20 countries and more than 30 industries to develop the scheme and determine how certification is assessed. The committee also works with NEN, the Royal Netherlands Standardization Institute.
Brand Compliance is the main auditor for the ITAM Forum’s ISO/IEC 19770-1 certification scheme. We conduct certification audits in accordance with the applicable scheme requirements. Following a successful audit, Brand Compliance’s independent Certification Committee reviews the audit report and decides whether the certificate can be issued.
Request ISO 19770-1 certification
Would you like independent confirmation that your IT asset management system meets the requirements of ISO 19770-1?
Schedule an introductory meeting with Brand Compliance to discuss your organization, the intended certification scope and the next steps in the certification process.
More information
