Asset Management Policy Template (Canada)

Updated on August 9, 2026

A Canadian asset management policy sets the rules for approving, recording, securing, maintaining, insuring, transferring and disposing of assets. It is the governance layer above the asset register and supports tax records, privacy safeguards, cyber hygiene, insurance and grant compliance.

This version is built around CRA six-year record retention, capital cost allowance evidence, OPC PIPEDA retention and destruction expectations, and Canadian Centre for Cyber Security sanitization guidance. It also separates owned assets from leased, financed, employee and client property.

0 of 10 blanks filled

Tap any highlighted blank in the document below and type straight into it.Free — no sign-up, no watermark

Canadian Asset Management Policy

Organization:
Effective date:
Policy owner:
Register owner:

1. Purpose and Scope

This policy governs the acquisition, recording, custody, maintenance, security, transfer and disposal of these assets:

2. Acquisition and Register Entry

Acquisition approvals:

Mandatory register fields:

3. Security and Maintenance

4. Disposal and Privacy

5. Review

The policy review cycle is . Exceptions must record approver, reason, expiry date and mitigation.

Policy owner

Date signed:

Scope and roles

The policy should cover equipment, vehicles, computers, phones, storage media, furniture, artwork, tools, software licences, domains, leased items, client property and grant-funded assets. It should name the policy owner, register owner, finance owner, IT owner, custodian, approver and disposal approver.

Without named roles, the register goes stale. Finance, IT and operations each hold part of the evidence; the policy decides who owns the master record and who resolves conflicts.

Acquisition and register standards

Assets should enter the register when acquired or first controlled. Mandatory fields include ID, description, supplier, invoice, cost, GST/HST, purchase date, funding source, ownership status, location, custodian, warranty, maintenance and insurance.

CRA records should show enough detail to support tax obligations and entitlements. For depreciable property, the policy requires CCA class, business use, additions, dispositions and proceeds fields, while leaving calculations to finance advisers.

Security, maintenance and insurance

Physical security, user allocation, remote-work use, calibration, servicing, inspection and insurance schedules should be set by asset category. High-value, mobile and data-bearing assets need more frequent verification.

The policy also requires reconciliation with insurance schedules, finance records and physical stocktakes. A missing laptop is both an asset issue and potentially a privacy or cyber incident.

Retention, privacy and sanitization

OPC guidance under PIPEDA says personal information should be retained only as long as needed and disposed of securely, including fully deleting personal information before disposing of computers, photocopiers and cellphones. That turns device disposal into a privacy control.

The Cyber Centre says sanitization is permanent removal of data and that deletion alone is not enough. The policy requires backup review, account unlinking, reset or secure erase, crypto erase or destruction as appropriate, plus documented evidence before a device leaves organizational control.

Review, exceptions and restricted assets

The policy sets stocktake frequency, missing-asset escalation, exception logs, disposal approvals and review dates. Exceptions need approver, reason, expiry date and mitigation.

Grant-funded, client-owned or restricted-use assets need their own field because disposal proceeds, return obligations and public reporting may be driven by a grant agreement or client contract rather than ordinary asset rules.

The policy should also say when a missing or stolen asset becomes an incident. A lost phone may require IT containment, privacy assessment, insurance notice, payroll deduction review, police report or funder notification. The register owner should not have to invent that escalation path after the asset is gone.

Finally, multi-province organizations should record where the asset is used and which local rules apply. Quebec, Alberta and British Columbia have private-sector privacy statutes alongside PIPEDA in many settings, and provincial sales tax or insurance treatment can make location more than an inventory field.

Policy clause guide

Purpose and scope
Defines tangible, digital, leased, client and data-bearing assets covered.
Roles
Names policy owner, register owner, custodians, approvers and disposal approver.
Acquisition controls
Requires approval, purchase evidence, tax treatment and register entry.
Register standards
Sets mandatory asset data for finance, tax, insurance and custody.
Security and maintenance
Sets physical, IT, inspection, calibration and insurance controls.
Privacy disposal
Requires secure deletion, anonymization, sanitization or destruction evidence.
Disposal
Controls sale, transfer, write-off, recycling and retained evidence.
Review and exceptions
Sets stocktakes, exception logs, missing-asset escalation and policy review.

Canadian policy checklist

  • Support CRA record keeping

    CRA says records must provide enough detail to determine tax obligations and entitlements and are generally kept for six years.

    CRA - keeping records
  • Preserve CCA evidence

    The policy should require facts needed for depreciable property and Class 14.1 intangible property treatment where relevant.

    CRA - buying an existing business
  • Limit retention and destroy securely

    OPC says organizations should keep personal information only as long as needed and dispose of it in a way that prevents a privacy breach.

    OPC - PIPEDA retention and disposal
  • Sanitize devices before release

    The Cyber Centre says deleting is not sanitization and identifies reset, overwrite, crypto erase, degaussing and destruction methods.

    Cyber Centre - device sanitization
  • Mark non-owned assets

    Leased, financed, client and employee assets need separate custody, insurance and return rules.

  • Reconcile insurance and stocktake

    Review location, custodian, condition and insured value on a defined cycle.

  • Track restricted assets

    Grant-funded or client-owned assets need restriction, approval and return fields.

  • Escalate lost data-bearing assets

    A missing laptop, phone, drive or printer may be an IT, privacy, insurance and records incident, not only an asset variance.

How to adopt the policy

  1. Name owners. Assign policy, register, finance, IT and disposal owners.
  2. Define categories. List equipment, IT, software, IP, leased, client and grant-funded assets.
  3. Set register fields. Require purchase, custody, ownership, tax, insurance and disposal evidence.
  4. Add disposal controls. Require approval and privacy or sanitization evidence for data-bearing assets.
  5. Review and audit. Set stocktake cycle, exception log and policy review date.

Frequently asked questions

What is an asset management policy?

It is the organization rulebook for approving, recording, securing, maintaining, insuring, transferring and disposing of assets.

How is it different from an asset register?

The register lists assets. The policy says who controls the process, what data is required and how checks happen.

Does it need privacy wording?

Yes where assets can contain personal information. PIPEDA guidance requires retention and disposal procedures and secure disposal.

Should leased assets be included?

Yes, but marked as leased or financed so ownership, insurance and disposal are handled correctly.

Does the policy calculate tax depreciation?

No. It preserves records for finance advisers to apply CRA rules and CCA treatment.

How often should assets be checked?

Set a cycle by risk. High-value, mobile or data-bearing assets usually need more frequent checks.

Who approves disposal?

The policy should name an approver and require sale, transfer, wipe, recycling or destruction evidence.

Related templates

Disclaimer

This Canadian template and guide are provided for general information only and are not legal, tax, employment, immigration, privacy, corporate-filing, insolvency, accounting, PPSA, Quebec civil-law or professional advice. Federal and provincial law, government forms, fees and filing practice can change; check the current official source and take advice before relying on the document.