Asset Management Policy Template (UK)
Updated on 9 August 2026
A UK asset management policy tells an organisation how assets are approved, recorded, tagged, maintained, secured, insured, transferred and disposed of. It is the governance layer above the asset register. For a limited company it supports accounting records; for a charity, school, studio or professional firm it also supports grant restrictions, insurance and data-protection controls.
The source policy is short and generic. It does not distinguish assets from information assets, leased items from owned items, ordinary disposal from data-bearing device sanitisation, or accounting records from tax evidence. This UK version builds the policy around accountable ownership, records, risk, secure disposal and review.
Tap any highlighted blank in the document below and type straight into it.Free — no sign-up, no watermark
UK Asset Management Policy
- Organisation:
- Effective date:
- Policy owner:
- Register owner:
1. Purpose and Scope
This policy governs the acquisition, recording, custody, maintenance, security, transfer and disposal of the following assets:
2. Acquisition and Register Entry
Acquisition approvals:
Mandatory register fields:
3. Security, Maintenance and Insurance
4. Disposal and Data Sanitisation
5. Review and Exceptions
The policy review cycle is . Exceptions must record the approver, reason, expiry date and mitigation.
Policy owner
Date signed:
Scope, ownership and roles
The policy should apply to tangible assets such as equipment, vehicles, IT devices, tools, artwork, furniture and stock-like project assets, and can also cover intangible assets such as software licences, domains and IP records. It should identify who owns the policy, who maintains the register, who approves purchases, who performs stocktakes and who can authorise disposal.
Without named roles, an asset register quickly becomes stale. The template separates policy owner, finance owner, IT owner, asset custodian, approver and disposal approver, so accountability follows the asset life cycle.
Acquisition and register standards
Assets should enter the register at acquisition or first use, not months later at year-end. The minimum record should include asset ID, description, supplier, invoice, acquisition date, cost, VAT, funding source, location, custodian, condition, warranty, maintenance requirement, insurance value and ownership status.
Leased, financed, client-owned and employee-owned assets must be marked separately. That prevents the organisation insuring, claiming allowances on, pledging or disposing of assets it does not own.
Security, maintenance and insurance
A policy should set physical security and access controls for high-value or mobile assets, and IT controls for devices that store or access data. Maintenance, calibration, inspection and PAT testing where relevant should have named cycles and evidence.
Insurance schedules are only useful if they match reality. The policy therefore requires register reconciliation with insurance values and location data, especially for vehicles, tools, computers, artworks and specialist equipment.
Data-bearing assets and sanitisation
Data-bearing devices need special handling at allocation, return and disposal. NCSC guidance on secure sanitisation covers electronic storage media broadly and explains that different risk levels need different sanitisation or destruction approaches. The ICO also warns that deleting files or quick formatting may not remove data before sale or disposal.
This policy requires encryption status, return checks, factory reset where appropriate, secure erase or destruction evidence, recycler or destruction certificate, and approval before a data-bearing asset leaves the organisation. That makes privacy and cyber risk part of the asset process rather than an IT afterthought.
Review, exceptions and audit
Policies fail when exceptions are invisible. This document requires exceptions to be logged with approver, reason, expiry date and mitigation. It also sets review frequency, stocktake cadence, missing-asset escalation and evidence retention.
The result is a policy that supports directors, trustees, auditors and managers. It does not attempt to calculate depreciation or capital allowances, but it does require the register to preserve the facts that finance advisers need.
Policy clause guide
- Purpose and scope
- Defines which tangible, digital and intangible assets are controlled.
- Roles and accountability
- Names the policy owner, register owner, custodian, approvers and disposal approver.
- Acquisition controls
- Requires approval, purchase evidence, funding-source notes and timely register entry.
- Register standards
- Sets mandatory fields for cost, serial number, location, custodian, ownership, insurance and tax notes.
- Security and maintenance
- Sets physical, IT, inspection, calibration and maintenance requirements by asset category.
- Data sanitisation
- Requires secure erasure, reset, destruction or certified disposal for devices that may contain data.
- Disposal
- Controls sale, transfer, write-off, recycling and evidence of authority.
- Review and audit
- Sets stocktake cycles, exception logs, missing-asset escalation and policy review.
UK policy checklist
Use these checks to make the policy operational rather than decorative.
Support company accounting records
Company records should include details of assets owned, and accounting records should be sufficient to show the company position.
GOV.UK - company and accounting recordsKeep accounting-record duties separate from tax advice
Companies House and GOV.UK guidance use different record periods in different contexts. The policy should preserve evidence and prompt professional tax/accounting review.
Companies House - accounts guidanceProtect data-bearing devices
NCSC secure-sanitisation guidance treats electronic storage media broadly and links disposal choices to risk.
NCSC - secure sanitisation of storage mediaDelete data before disposal
ICO guidance tells users to delete data before selling or disposing of computers, laptops and devices, and simple deletion may not be enough.
ICO - deleting data from devicesPreserve tax evidence for capital allowances
The policy should require purchase, use and disposal evidence so advisers can apply the current HMRC capital allowances rules.
HMRC - capital allowances collectionControl leased and client assets
Assets not owned by the organisation should be marked and handled under their lease, finance, bailment or client-property terms.
Audit exceptions
Exceptions should have an approver, reason, expiry date and mitigation, not a permanent undocumented workaround.
How to adopt the policy
- Name owners. Assign the policy owner, register owner, finance owner, IT owner and disposal approvers.
- Define asset categories. List tangible, IT, software, IP, leased and client assets covered by the policy.
- Set register fields. Require ID, cost, supplier, location, custodian, ownership, maintenance, insurance and disposal fields.
- Add disposal controls. Require approval, valuation, transfer evidence and data sanitisation where relevant.
- Review and audit. Set stocktake frequency, exception logging, missing-asset escalation and annual policy review.
Frequently asked questions
What is an asset management policy?
It is the organisation rulebook for approving, recording, securing, maintaining, insuring, transferring and disposing of assets.
How is it different from an asset register?
The register lists the assets. The policy says who owns the process, what fields are required, how checks happen and how exceptions are handled.
Does it need data-protection wording?
Yes where devices can store personal or confidential data. The policy should require secure sanitisation or destruction evidence before disposal.
Should leased assets be covered?
Yes, but they should be marked separately so the organisation does not treat them as owned or dispose of them without permission.
Can the policy set depreciation?
It can record the depreciation approach, but tax and accounting treatment should be confirmed by finance advisers under current rules.
How often should stocktakes happen?
Set a cadence based on value, mobility and risk. IT devices, vehicles and high-value portable equipment often need more frequent checks.
Who approves disposal?
The policy should name an approver and require evidence of sale, transfer, recycling, destruction and data sanitisation where relevant.
Related templates
Disclaimer
This UK template and guide are provided for general information only and are not legal, tax, employment, regulatory, filing, insolvency, data-protection, accounting, title or professional advice. Laws, fees, government forms and filing practice can change; check the current official source and take advice before relying on the document.


