A mid-size company came to us after failing an ISO 27001 audit. The reason wasn’t a sophisticated breach or a misconfigured firewall. It was 42 laptops.
Employees who’d left over the past 18 months never had their devices retrieved or wiped. Their accounts were still active. Their SaaS licenses were still billing. Nobody caught it because nobody had a single view of what existed, who owned it, and where it was.
Most IT teams manage assets the way they manage everything else when no real system exists: reactively. Spreadsheets for hardware. A separate tool for SaaS. IAM handled somewhere else entirely. It works until it doesn’t, and by the time it doesn’t, the damage is already done.
This guide isn’t another definition of ITAM. It’s a way to figure out exactly where your program sits on the maturity curve, what it’s actually costing you to stay there, and what moving up one level looks like in practice.
IT asset management is the discipline of tracking what IT assets a company owns, where they are, and whether they’re being used, across hardware, software, SaaS, and cloud resources. It combines inventory, financial, and risk data into one system instead of four disconnected ones.
A simple test: can your IT team say what you own, where it is, and whether it’s active, without opening a spreadsheet or making a call? If not, you have a partial record, not ITAM.
Most companies think they’re further along than they are, because “we have a system” and “we have a program that works” get used interchangeably. They’re not the same claim. Here’s a five-level model to place your program honestly.

No central record. Hardware gets tracked (if at all) in whatever spreadsheet the last person to care about it built. SaaS is discovered by accident, usually when a renewal invoice surprises finance. Nobody owns the category. This is where most companies under 50 employees sit, and it’s tolerable at that size purely because the blast radius of a mistake is small.
A record exists, but it’s updated in response to problems, not on a schedule. IT finds out a device wasn’t returned when they need to reissue one. SaaS waste gets discovered during a budget review, not a scheduled audit. The record is real but always behind the current state of the business.
Discovery is automated for at least one asset category (usually SaaS, since that’s the easiest to instrument). Hardware may still be manual. There’s a defined owner for each category, but the categories don’t talk to each other. IT doesn’t know that Finance just approved a new tool that duplicates one already in use.
All four asset categories are discovered automatically and tied to a single source of truth. HRIS events trigger asset actions without a human initiating them. Compliance evidence generates continuously rather than getting compiled before an audit. This is the level ISO 27001 and SOC 2 auditors actually expect to see, even if it’s not stated explicitly in the standard.
Everything in Level 3, plus the data actively informs decisions rather than just documenting them: refresh cycles are timed against actual device health data, license reclamation happens quarterly without anyone having to remember to run it, and finance uses live utilization data (not renewal-time guesses) to negotiate contracts.
Most organizations we talk to land at Level 1 or 2 and assume they’re closer to Level 3 because they have a tool. The gap between “we have a tool” and Level 3 is almost always the automation layer: whether asset actions happen because someone remembered, or because an HR event triggered them.
Treating these four as one undifferentiated “asset” bucket is the single most common reason ITAM programs stall. Each category fails through a different mechanism, so each needs a different control.

Physical devices: laptops, desktops, servers, monitors, phones, networking equipment. Hardware has a physical location, a serial number, an owner, a warranty, and a defined end-of-life.
The failure mechanism here is almost always retrieval, not tracking. Companies can usually tell you what hardware they bought. What they can’t tell you is where it physically is six months after an employee leaves, because retrieval requires a logistics process, not a database entry. A device that’s “in inventory” and a device that’s actually recoverable are two different claims, and most hardware ITAM programs conflate them. (We cover the full procure-to-retire process in our IT asset lifecycle management guide if you want the operational side of this.)
Operating systems, productivity suites, enterprise applications, individual licenses. The failure mechanism is entitlement drift: the license terms you agreed to and the way the software is actually being used quietly diverge over time. A named-user license gets shared across a team. A server license gets applied to a VM that scaled beyond its permitted core count. None of this looks like a compliance violation day-to-day. It looks like a compliance violation the day a vendor audit shows up, at which point it’s retroactive and expensive rather than a fixable configuration issue.
Subscriptions, SaaS platforms, cloud instances. This is the fastest-growing and hardest-to-track category, and the failure mechanism is procurement bypass: most SaaS gets bought with a credit card by someone outside IT, which means the tool exists in the business before it exists in any inventory. More than half of purchased SaaS licenses sit idle at any given time, and research puts unused SaaS license waste at an estimated $21 million a year for the average enterprise. That number isn’t a discovery problem so much as an ownership problem: someone bought the tool, stopped using it, and never told anyone it could be canceled.
SSL certificates, domain names, API keys, software keys. The failure mechanism is invisibility until failure: these assets don’t degrade gradually or get noticed sitting unused in a warehouse. They work perfectly until an expiry date passes, and then something breaks in production with no warning. An expired certificate takes down an environment. A rotated API key breaks a critical integration. The fix isn’t more monitoring of the asset itself, it’s assigning an explicit owner and expiry alert to every credential the same way you’d assign one to a laptop.
ITAM is the ledger: what you own, who holds it, whether it’s compliant. It’s a state of knowledge you can check at any moment. ITALM is the process that moves an asset through its stages, from procurement to retirement. You can have accurate ITAM records for a laptop that’s still sitting in a warehouse because nobody owns the process of getting it deployed.
This guide focuses on the governance layer: what to track, why it fails, and what a mature program looks like. For the five lifecycle stages themselves, and where each one typically breaks down, check out our dedicated IT Asset Lifecycle Management guide.
A program that only tracks inventory isn’t ITAM. It’s a list. Four components have to work together, and the order matters: skipping straight to compliance reporting without discovery in place just produces reports full of gaps.
You can’t govern what you can’t see. This means automated IT procurement across hardware, software, SaaS, and cloud, not a manual spreadsheet someone updates when they remember to. Shadow IT only surfaces through discovery, since employees don’t announce the tools they sign up for on a company card. The practical test of whether discovery is real or theoretical: pull a report of every active tool right now, with zero advance notice. If that report takes more than an hour to produce, discovery isn’t automated. It’s a project.
Every asset has a cost, a contract, and a device refresh cycle. Without this layer, renewals auto-fire on tools nobody uses, and IT has no data to negotiate volume pricing or push back on price increases at renewal time. The teams that do this well track renewal dates 60 to 90 days out, not at the point the invoice lands, because that window is the only one where you can actually negotiate or cancel instead of just paying.
License audits, data protection requirements, and certification standards (ISO 27001, SOC 2, GDPR) all require documented evidence: who has access to what, when it was granted, and how devices were wiped at end of life. This is the layer that turns “we think we’re compliant” into “here’s the audit trail.” The distinction that trips people up: compliance requires evidence of a process, not just the outcome. A device that was correctly wiped but has no logged record of the wipe is, from an auditor’s perspective, indistinguishable from a device that wasn’t wiped at all.
Access is an asset in its own right. An orphaned account from an employee who left eight months ago is exactly the kind of gap ITAM exists to close, and it’s a different failure mode than an unreturned laptop even though both stem from the same root cause: nobody owned the offboarding process end to end. Access governance is also the component most likely to be owned by a different team (security or IT ops) than hardware and SaaS, which is precisely why it tends to fall through the cracks between departmental handoffs rather than failing outright.
Industry stats about breach costs and audit fines are easy to skim past because they feel abstract. Here’s a calculation you can run with your own numbers instead.
The true cost of one unreturned device:
| Cost Component | How to Estimate It |
|---|---|
| Replacement hardware | Device cost, since the original is unrecoverable |
| SaaS licenses left active | Sum of per-seat cost × months until someone notices and revokes |
| IT time spent chasing it | Hours spent on emails/calls × loaded hourly rate |
| Data exposure risk | Not quantifiable per incident, but factor in your last breach cost or industry average if you’ve never had one |
| Audit finding remediation | If flagged during ISO 27001/SOC 2, add remediation and re-audit time |
Run this for even five known unreturned devices and the total is almost always higher than what a structured retrieval process would have cost to prevent it. That’s the argument for ITAM in a form a CFO will actually engage with, instead of a generic industry statistic.
A 60-second self-assessment. Answer yes or no:
Four “no”s puts you at Level 0 or 1 on the maturity model above. Two or fewer puts you at Level 2. All “yes” puts you at Level 3, which is genuinely rare.
Most ITAM tools solve one layer: hardware tracking, or SaaS management, or MDM. IT teams end up stitching together three or four separate tools to cover the full scope, and the gaps between those tools are exactly where compliance findings show up.
ZenAdmin starts from a different premise. Device operations, not software features, are the hard part of ITAM for a distributed team, and it’s the part most platforms can’t actually deliver on because it requires physical logistics, not just a dashboard.
ZenAdmin’s inventory dashboard tracks every device by model, serial number, OS, health, allocation history, and status, backed by real procurement and retrieval operations across 150+ countries. When Multiplier moved its device operations onto ZenAdmin, average lead times dropped to 5 working days with 90% of orders arriving on or before the promised date, while scaling device volume 4x without adding headcount. Retrieval, wiping, and ITAD run through the same workflow, triggered directly from HRIS offboarding events instead of an email to IT. ZenCare adds a 3-year global warranty covering unlimited accidental repairs, which most competing platforms don’t offer.
ZenAdmin discovers every app in use, including shadow IT, tracks real usage, and flags unused seats for reclamation. Employees request access through Slack or Teams; approvals and provisioning log automatically for audit purposes.
Joiner, mover, leaver events update access across every connected system the moment they’re recorded in HR, with SSO handled through ZenAdmin’s Scalekit partnership. Orphaned accounts, one of the most common audit findings, get eliminated by design rather than by policy reminder.
ZenAdmin integrates with Hexnode, Jamf, JumpCloud, Miradore, and Microsoft Intune, so device management, SaaS governance, and identity all live in one place. Support runs 24/7 with a 15-minute response SLA, and up to 90% of L1/L2 access-related tickets get resolved without a human touching them.
The difference isn’t more features than a point solution. It’s that physical device operations, the part every pure-software ITAM tool has to hand off to someone else, are native to the platform.
Explore ZenAdmin’s IT Asset Management module.
ITAM in 2026 isn’t a tracking exercise. It’s the operational foundation that determines whether your IT spend is under control, your security posture is defensible, and your compliance evidence is ready before the auditor asks for it.
Most programs don’t fail from lack of effort. They fail because “we have a tool” gets mistaken for Level 3 maturity, when the actual gap is automation: whether asset actions happen because someone remembered, or because the system triggered them.
ZenAdmin runs procurement, deployment, retrieval, and disposal alongside SaaS, identity, and helpdesk, so nothing falls through the cracks between vendors.
Asset inventory is a list. ITAM includes the list plus financial tracking, compliance evidence, and access governance tied to that list.
Discovery should run continuously, not as a periodic audit. Reserve scheduled reviews (quarterly is typical) for license reclamation and contract renegotiation, not for finding out what you own.
Yes. The core discipline is the same, but distributed teams add physical logistics (cross-border shipping, customs, local retrieval) that a domestic-only ITAM program never has to solve for.