Ask three people in a growing IT company where a particular laptop is and you will often get three answers: the spreadsheet says one thing, the IT engineer remembers another, and the laptop is actually with someone who left last month. The register did not fail on the day of the audit. It failed quietly, every time an asset moved without being recorded.
What an auditor checks
- Can you find a named asset — by tag or serial — and say who holds it today?
- Is there an acknowledgement from the person who received it?
- What happened to the assets of the last three leavers?
- How is a disposed device wiped, and where is the record of that wipe?
- Which assets hold customer or personal data, and are they protected accordingly?
Custody is the whole game
A register is only as good as the moment of handover. Issue and return have to be events in the system, with the person acknowledging them — not an email to IT. Once custody is a record, the exit checklist writes itself: everything still showing against a leaver is the recovery list.
Request, approve, issue — in that order
Assets given out informally never make it back into the register. Put the request through the reporting line to the issuing department, gate the issue on stock, and let anything not in stock become a procurement indent. The audit trail is then a by-product of how people already work.
Rate the asset, not just the item
Two identical laptops are not equally critical: one holds source code and customer data, the other runs reception. Give each item type a default rating for Confidentiality, Integrity, Availability and the Expectations riding on it, and let an individual asset override it. Controls — encryption, backup, spare stock — then follow the rating instead of the price.
The three habits that keep it true
- Nothing leaves the store without an issue record and an acknowledgement.
- Physical verification of the high-rated assets every quarter, recorded as evidence.
- Disposal with a wipe certificate attached to the asset, not to an email thread.