Asset Management Policy Template (UK)

Updated on 9 August 2026

A UK asset management policy tells an organisation how assets are approved, recorded, tagged, maintained, secured, insured, transferred and disposed of. It is the governance layer above the asset register. For a limited company it supports accounting records; for a charity, school, studio or professional firm it also supports grant restrictions, insurance and data-protection controls.

The source policy is short and generic. It does not distinguish assets from information assets, leased items from owned items, ordinary disposal from data-bearing device sanitisation, or accounting records from tax evidence. This UK version builds the policy around accountable ownership, records, risk, secure disposal and review.

0 of 10 blanks filled

Tap any highlighted blank in the document below and type straight into it.Free — no sign-up, no watermark

UK Asset Management Policy

Organisation:
Effective date:
Policy owner:
Register owner:

1. Purpose and Scope

This policy governs the acquisition, recording, custody, maintenance, security, transfer and disposal of the following assets:

2. Acquisition and Register Entry

Acquisition approvals:

Mandatory register fields:

3. Security, Maintenance and Insurance

4. Disposal and Data Sanitisation

5. Review and Exceptions

The policy review cycle is . Exceptions must record the approver, reason, expiry date and mitigation.

Policy owner

Date signed:

Scope, ownership and roles

The policy should apply to tangible assets such as equipment, vehicles, IT devices, tools, artwork, furniture and stock-like project assets, and can also cover intangible assets such as software licences, domains and IP records. It should identify who owns the policy, who maintains the register, who approves purchases, who performs stocktakes and who can authorise disposal.

Without named roles, an asset register quickly becomes stale. The template separates policy owner, finance owner, IT owner, asset custodian, approver and disposal approver, so accountability follows the asset life cycle.

Acquisition and register standards

Assets should enter the register at acquisition or first use, not months later at year-end. The minimum record should include asset ID, description, supplier, invoice, acquisition date, cost, VAT, funding source, location, custodian, condition, warranty, maintenance requirement, insurance value and ownership status.

Leased, financed, client-owned and employee-owned assets must be marked separately. That prevents the organisation insuring, claiming allowances on, pledging or disposing of assets it does not own.

Security, maintenance and insurance

A policy should set physical security and access controls for high-value or mobile assets, and IT controls for devices that store or access data. Maintenance, calibration, inspection and PAT testing where relevant should have named cycles and evidence.

Insurance schedules are only useful if they match reality. The policy therefore requires register reconciliation with insurance values and location data, especially for vehicles, tools, computers, artworks and specialist equipment.

Data-bearing assets and sanitisation

Data-bearing devices need special handling at allocation, return and disposal. NCSC guidance on secure sanitisation covers electronic storage media broadly and explains that different risk levels need different sanitisation or destruction approaches. The ICO also warns that deleting files or quick formatting may not remove data before sale or disposal.

This policy requires encryption status, return checks, factory reset where appropriate, secure erase or destruction evidence, recycler or destruction certificate, and approval before a data-bearing asset leaves the organisation. That makes privacy and cyber risk part of the asset process rather than an IT afterthought.

Review, exceptions and audit

Policies fail when exceptions are invisible. This document requires exceptions to be logged with approver, reason, expiry date and mitigation. It also sets review frequency, stocktake cadence, missing-asset escalation and evidence retention.

The result is a policy that supports directors, trustees, auditors and managers. It does not attempt to calculate depreciation or capital allowances, but it does require the register to preserve the facts that finance advisers need.

Policy clause guide

Purpose and scope
Defines which tangible, digital and intangible assets are controlled.
Roles and accountability
Names the policy owner, register owner, custodian, approvers and disposal approver.
Acquisition controls
Requires approval, purchase evidence, funding-source notes and timely register entry.
Register standards
Sets mandatory fields for cost, serial number, location, custodian, ownership, insurance and tax notes.
Security and maintenance
Sets physical, IT, inspection, calibration and maintenance requirements by asset category.
Data sanitisation
Requires secure erasure, reset, destruction or certified disposal for devices that may contain data.
Disposal
Controls sale, transfer, write-off, recycling and evidence of authority.
Review and audit
Sets stocktake cycles, exception logs, missing-asset escalation and policy review.

UK policy checklist

Use these checks to make the policy operational rather than decorative.

  • Support company accounting records

    Company records should include details of assets owned, and accounting records should be sufficient to show the company position.

    GOV.UK - company and accounting records
  • Keep accounting-record duties separate from tax advice

    Companies House and GOV.UK guidance use different record periods in different contexts. The policy should preserve evidence and prompt professional tax/accounting review.

    Companies House - accounts guidance
  • Protect data-bearing devices

    NCSC secure-sanitisation guidance treats electronic storage media broadly and links disposal choices to risk.

    NCSC - secure sanitisation of storage media
  • Delete data before disposal

    ICO guidance tells users to delete data before selling or disposing of computers, laptops and devices, and simple deletion may not be enough.

    ICO - deleting data from devices
  • Preserve tax evidence for capital allowances

    The policy should require purchase, use and disposal evidence so advisers can apply the current HMRC capital allowances rules.

    HMRC - capital allowances collection
  • Control leased and client assets

    Assets not owned by the organisation should be marked and handled under their lease, finance, bailment or client-property terms.

  • Audit exceptions

    Exceptions should have an approver, reason, expiry date and mitigation, not a permanent undocumented workaround.

How to adopt the policy

  1. Name owners. Assign the policy owner, register owner, finance owner, IT owner and disposal approvers.
  2. Define asset categories. List tangible, IT, software, IP, leased and client assets covered by the policy.
  3. Set register fields. Require ID, cost, supplier, location, custodian, ownership, maintenance, insurance and disposal fields.
  4. Add disposal controls. Require approval, valuation, transfer evidence and data sanitisation where relevant.
  5. Review and audit. Set stocktake frequency, exception logging, missing-asset escalation and annual policy review.

Frequently asked questions

What is an asset management policy?

It is the organisation rulebook for approving, recording, securing, maintaining, insuring, transferring and disposing of assets.

How is it different from an asset register?

The register lists the assets. The policy says who owns the process, what fields are required, how checks happen and how exceptions are handled.

Does it need data-protection wording?

Yes where devices can store personal or confidential data. The policy should require secure sanitisation or destruction evidence before disposal.

Should leased assets be covered?

Yes, but they should be marked separately so the organisation does not treat them as owned or dispose of them without permission.

Can the policy set depreciation?

It can record the depreciation approach, but tax and accounting treatment should be confirmed by finance advisers under current rules.

How often should stocktakes happen?

Set a cadence based on value, mobility and risk. IT devices, vehicles and high-value portable equipment often need more frequent checks.

Who approves disposal?

The policy should name an approver and require evidence of sale, transfer, recycling, destruction and data sanitisation where relevant.

Related templates

Disclaimer

This UK template and guide are provided for general information only and are not legal, tax, employment, regulatory, filing, insolvency, data-protection, accounting, title or professional advice. Laws, fees, government forms and filing practice can change; check the current official source and take advice before relying on the document.