LICENSEWARE

Software asset management

This article is about software asset management as a discipline. For the wider practice that also covers hardware and cloud assets, see IT asset management. For the international standard family, see ISO/IEC 19770.

On This Page

Software asset management (SAM) is the organizational discipline of managing software, and the rights to use it, across the whole of its life cycle: requesting and procuring licenses and subscriptions, recording where software is deployed and how it is used, reconciling that usage against what the organization is entitled to, and optimizing, reharvesting or retiring what is no longer needed. The vocabulary part of the international standard family, ISO/IEC 19770-5, introduces SAM alongside IT asset management (ITAM) and describes the foundation principles on which SAM is based.[1]

SAM sits between several functions. It draws on procurement records for what was bought, on technical inventory for what is installed or consumed, and on the text of each software license for what counts as a licensable unit. Its central output is a reconciliation of the three, commonly called an effective license position. The first international standard for the discipline, ISO/IEC 19770-1:2006, framed its purpose as enabling an organization to show that it performs SAM well enough to satisfy corporate governance requirements and to support IT service management, and listed the management of business risk and cost control among the expected benefits.[3] The current edition of that standard generalizes the scope from software to all IT assets.[2]

History

License compliance origins

The practice grew out of copyright enforcement and license compliance. In the United Kingdom the Federation Against Software Theft (FAST) was set up in 1984 as a not-for-profit body to defend the intellectual property of software publishers.[5] The Business Software Alliance (BSA), the trade association of the enterprise software industry, describes part of its role as raising awareness of the risks of unlicensed software use and the benefits of software asset management, and driving license compliance.[6] Publisher associations of this kind, together with the audit clauses in publishers’ own contracts, made license compliance a governance concern for organizations that bought software in volume.

By the early 2000s public audit bodies were examining how government departments managed licenses. The Australian National Audit Office reported in December 2001 on five Commonwealth agencies, with the objective of giving assurance that the risks of illegal software were being managed and that compliance with license conditions was being monitored.[7] The UK National Audit Office reported in May 2003 that departments spent £610 million a year on software, including £100 million on more than one million licenses, and recommended that departments keep reliable records and check regularly that no unlicensed software was in use.[8]

Vendor guidance from the same period shows the basic method that later standards formalized. A 2005 Microsoft implementation guide set out a six-step checklist: inventory installed software, locate existing licenses, match the two, decide whether more licenses are needed, store licensing documents centrally, and put an ongoing program in place. Its worked example compared installations with licenses owned per product to show whether an organization was over- or under-licensed.[9]

Service management and standardization

SAM was also shaped by IT service management. ITIL, the IT service management framework, was part of the UK government’s Best Management Practice portfolio, developed within the Civil Service and managed by the Cabinet Office until a 2013 joint venture took over its commercial exploitation.[10] The first edition of ISO/IEC 19770-1, published in May 2006, was explicitly intended to align closely to, and support, the service management standard ISO/IEC 20000.[3]

The second edition (June 2012) reorganized the standard around an integrated set of SAM processes divided into tiers, so that organizations could implement, assess and be recognized incrementally. It stated that it applied to executable and non-executable software and to all technological environments, including virtualized applications and software as a service.[4] The third edition (December 2017) replaced the SAM process model with requirements for an “IT asset management system”, extending the scope to all types of IT assets; it is a discipline-specific extension of the asset management standard ISO 55001:2014.[2] The history of the standard family is covered in detail in ISO/IEC 19770.

Public-sector mandates

In the United States, a 2014 Government Accountability Office (GAO) review of 24 major agencies found that only two had comprehensive license management policies and none fully tracked and maintained a license inventory or analyzed license data.[11] The MEGABYTE Act of 2016 then required agency Chief Information Officers to adopt software licensing policies with central oversight, a comprehensive inventory covering at least 80 percent of software license spending, regular tracking, analysis of usage data, training, and consideration of the whole license life cycle.[12] The Office of Management and Budget’s memorandum M-16-12 of June 2016 required each covered agency to appoint a software manager and to maintain a continual inventory of licenses purchased, deployed and in use, including spending on software-as-a-service subscriptions.[13]

Scope and definitions

The 2012 edition of ISO/IEC 19770-1 defined the scope of SAM broadly: all software and “related assets”, meaning other assets whose characteristics are needed to use or manage software. It named application programs, operating systems and utilities as executable software, and fonts, graphics, recordings, templates, dictionaries, documents and data as non-executable software.[4] The JTC 1/SC 7 committee describes ITAM as all the infrastructure and processes needed for the effective management, control and protection of IT assets through every stage of the life cycle, and SAM is generally treated as the part of that discipline concerned with software.[14]

Several terms recur in the field:

Term Meaning in SAM practice 
Entitlement A right to use software acquired under a license or subscription. ISO/IEC 19770-3 treats software entitlements as the subset of license terms concerned with usage rights.[21] 
Proof of entitlement Records that demonstrate an entitlement, such as contracts, orders and invoices. IBM, for example, lists Proofs of Entitlement (PoEs) among the transaction documents that form part of its agreement.[16] 
Inventory A record of software deployed or consumed, from discovery tools, cloud and SaaS administration consoles, or manual collection. 
License metric The unit in which a license is counted, such as processors, cores, named users or devices. See software licensing models. 
Effective license position (ELP) A reconciliation of entitlements against measured demand for each product and metric, showing surplus or shortfall. 

Practice

Life cycle

SAM practice is usually described as a sequence of life-cycle stages. The MEGABYTE Act lists requisition, reception, deployment, maintenance, retirement and disposal as phases a licensing policy must consider.[12] OMB M-16-12 lists the capabilities that tooling should automate: hardware and software discovery, inventory tracking, software inventory normalization, reconciliation of contracts, purchases and product use rights, license optimization, and data sharing.[13] Combining these gives a working sequence:

  1. Request and approve. A user or project asks for software; the request is checked against an approved catalog and existing entitlements. M-16-12 asks agencies to review discovered software against their approved list and either add it or replace it with an approved alternative.[13]
  2. Procure. Licenses, subscriptions and support are bought under the appropriate contract, and the entitlement records are captured at the point of purchase.
  3. Deploy. Software is installed, provisioned or assigned. Some licenses restrict how often an assignment may change; Microsoft’s Universal License Terms, for instance, allow a license to be reassigned to another device or user but not within 90 days of its last reassignment.[25]
  4. Discover. Tools and administrative reports collect what is actually installed or consumed. Software identification tags defined in ISO/IEC 19770-2 are one mechanism for making installed software identifiable to discovery tools.[20]
  5. Normalize. Raw discovery records are mapped to a consistent publisher, product, version and edition so they can be compared with purchase records.
  6. Reconcile. Normalized demand is compared with entitlements under the relevant license metrics to produce the effective license position.
  7. Optimize. Unused or underused entitlements are reharvested, redeployed or not renewed, and license models are changed where another metric fits usage better.
  8. Retire. Software is uninstalled, subscriptions are cancelled, and records are updated so that retired assets no longer generate demand.

Effective license position

An effective license position is calculated per product and per license metric. For each line it sets the quantity of entitlements owned against the quantity required by the license rules, taking into account minimums, multipliers and use rights such as downgrade or virtualization rights. The arithmetic is simple in principle; the difficulty lies in applying each publisher’s definitions. Under Oracle’s License Definitions and Rules, for example, a Named User Plus is an individual authorized to use the programs whether or not they are actively using them, and Oracle Database Enterprise Edition carries a minimum of 25 Named Users Plus per Processor, so a position must be computed against both the actual user population and the processor-based floor.[28] Vendor-specific rules of this kind are documented in articles such as Oracle Database licensing and SQL Server licensing.

Metrics based on measured capacity add a further dependency on tooling. IBM’s Passport Advantage Agreement allows eligible products to be licensed on sub-capacity (virtualization capacity) terms only if the customer produces the required usage reports, generated by IBM’s License Metric Tool or manually where an exemption applies, at least quarterly and retains them for two years; failure to do so results in charging at full physical capacity.[16]

Roles

The organization of SAM varies, but public-sector mandates give an indication of the roles involved. OMB M-16-12 required a single software manager reporting to the agency CIO and working with the chief acquisition and chief financial officers to centralize license management and adopt best practice.[13] The MEGABYTE Act likewise required “clear roles, responsibilities, and central oversight authority”.[12] In practice SAM draws on procurement and contract management staff, IT operations teams who run discovery and deployment tooling, finance for budgeting and chargeback, and legal counsel for contract interpretation.

SaaS and cloud

The move to subscriptions and cloud services changes what SAM measures. For software as a service there is often nothing installed to discover, and demand is taken from user assignments or consumption reports in the provider’s administration console. OMB M-16-12 explicitly brought SaaS spending into the required inventory.[13] For infrastructure clouds, existing licenses may sometimes be brought to a provider’s platform under the publisher’s bring-your-own-license rules, which differ by publisher and cloud (see Cloud BYOL). A 2024 GAO report described “restrictive” licensing practices that impeded agencies’ cloud use, including higher charges for running software on a competitor’s cloud, requirements to repurchase licenses already owned, and conversion fees.[18] The FinOps Foundation’s framework treats licensing and SaaS as a FinOps capability and notes the need to coordinate with ITAM teams on how purchased licenses are used, and on BYOL rights and vendor-specific metering tools.[19]

Vendor audits

Most enterprise license agreements give the publisher a right to verify compliance. IBM’s Passport Advantage Agreement, for example, obliges the customer to keep records and tool outputs sufficient to verify its use, allows IBM or an independent auditor to verify compliance on reasonable notice, and requires the customer to pay for any excess use together with up to two years of subscription and support for it.[16] Publishers may also offer advisory reviews that are distinct from contractual audits; Microsoft states that its partner-delivered SAM engagements are not audits (compliance verification).[17] A maintained effective license position is the main means by which an organization prepares for a verification request.

Standards and frameworks

The principal standard is the ISO/IEC 19770 family, developed by ISO/IEC JTC 1/SC 7. Part 1 specifies requirements for an IT asset management system and can be used by internal and external parties to assess an organization’s capability.[2] The SC 7 committee describes three implementation tiers for the 2017 edition (Trustworthy Data, Life Cycle Integration and Optimization) and 15 ITAM process areas, and notes that the standard is designed to integrate with ISO/IEC 27001 and ISO/IEC 20000-1.[14] Other parts define data formats that support automation: software identification tags (Part 2), an entitlement schema (Part 3) whose stated benefits include easier demonstration of proof of ownership and license compliance management, and resource utilization measurement (Part 4).[20][21][22]

Security frameworks also require software inventories. The NIST Cybersecurity Framework 2.0 includes, under its Asset Management category, the outcome that inventories of software, services and systems managed by the organization are maintained, and that assets are managed throughout their life cycles.[23]

Relationship to other disciplines

  • IT asset management. Since the 2017 edition of ISO/IEC 19770-1, the international standard treats SAM as part of a wider IT asset management system covering all IT asset types.[2]
  • IT service management. SAM was first standardized as a support to service management, aligned with ISO/IEC 20000.[3] ISO/IEC 20000-1:2018 specifies requirements for a service management system covering the planning, design, transition, delivery and improvement of services.[26]
  • FinOps. The FinOps Foundation defines FinOps as an operational framework and cultural practice for maximizing the business value of technology through collaboration between engineering, finance and business teams, and has extended its scope from public cloud to SaaS, licensing and data centers.[27] The overlap with SAM is greatest for cloud BYOL and SaaS subscriptions.[19]
  • Procurement and contract management. Entitlement data originates in purchasing. OMB M-16-12 tied software license management to category management and government-wide purchasing agreements.[13]
  • Information security. Software inventory supports vulnerability and configuration management, as reflected in the NIST framework’s asset management outcomes.[23]

Criticism and challenges

Audit findings describe persistent difficulties in achieving the basic reconciliation. GAO reported in 2024 that it was unclear which products under agencies’ most widely used licenses were in fact most used, because agency data were inconsistent and incomplete and several products could be bundled under one license; none of the nine agencies it examined in detail had fully determined whether their five most widely used licenses were over- or under-purchased.[15] A 2025 GAO report found that the Department of Veterans Affairs was not tracking the appropriate number of licenses for software in use and did not regularly compare inventories with purchase records.[24]

Other recurring challenges include:

  • Metric complexity. Each publisher defines its own units, minimums and virtualization rules, and definitions change between contract versions, so the same deployment can require different quantities under different agreements (see software licensing models).
  • Measurement dependency. Some metrics can be counted only with publisher-specified tools or reports, as with IBM sub-capacity licensing.[16]
  • Cloud and SaaS. Restrictive terms on running licensed software in third-party clouds can limit options and raise costs.[18]
  • Incomplete entitlement records. Purchases made outside central procurement, and proof of entitlement held by resellers or individual departments, leave gaps on the supply side of the reconciliation. The UK National Audit Office recommended reliable record keeping as early as 2003.[8]

Out of scope

This article describes the discipline in general terms. It does not state the license rules of any particular product; those are covered, with vendor citations, in the vendor articles such as Oracle Database licensing, SQL Server licensing and IBM Passport Advantage. Hardware asset management and configuration management are covered only as they relate to software, in IT asset management. Nothing in this article is legal advice.

References

  1. ISO/IEC 19770-5:2015 Information technology: IT asset management, Part 5: Overview and vocabularyISO catalogue page. Edition 2, 2015-08.Effective 2015-08-01. Retrieved 2026-09-26.
  2. ISO/IEC 19770-1:2017 Information technology: IT asset management, Part 1: IT asset management systems, RequirementsISO catalogue page. Edition 3, 2017-12; confirmed 2024; Amd 1:2024.Effective 2017-12-01. Retrieved 2026-09-26.
  3. ISO/IEC 19770-1:2006 Information technology: Software asset management, Part 1: ProcessesISO catalogue page. Edition 1, 2006-05; withdrawn.Effective 2006-05-01. Retrieved 2026-09-26.
  4. ISO/IEC 19770-1:2012 Information technology: Software asset management, Part 1: Processes and tiered assessment of conformanceISO catalogue page. Edition 2, 2012-06; withdrawn.Effective 2012-06-01. Retrieved 2026-09-26.
  5. About FAST (Federation Against Software Theft)Organization's own description; founding year only.Retrieved 2026-09-26.
  6. About BSA (Business Software Alliance)Trade association's own description.Retrieved 2026-09-26.
  7. Agency Management of Software Licensing, Auditor-General Report No. 27 of 2001–02Australian National Audit Office; published 2001-12-17.Effective 2001-12-17. Retrieved 2026-09-26.
  8. Purchasing and Managing Software Licences (HC 579, 2002–03)UK National Audit Office; published 2003-05-01.Effective 2003-05-01. Retrieved 2026-09-26.
  9. Software Asset Management (SAM) Implementation GuideMicrosoft Canada; copyright 2005. Historical vendor guidance.Retrieved 2026-09-26.
  10. New deal will market government professional qualificationsUK Cabinet Office press release, 2013-04-26 (ITIL and the Best Management Practice portfolio).Effective 2013-04-26. Retrieved 2026-09-26.
  11. Federal Software Licenses: Better Management Needed to Achieve Significant Savings Government-Wide (GAO-14-413)US Government Accountability Office; published 2014-05-22.Effective 2014-05-22. Retrieved 2026-09-26.
  12. MEGABYTE Act of 2016 (Public Law 114-210)Approved 2016-07-29.Effective 2016-07-29. Retrieved 2026-09-26.
  13. OMB M-16-12, Category Management Policy 16-1: Improving the Acquisition and Management of Common Information Technology: Software LicensingUS Office of Management and Budget memorandum, 2016-06-02.Effective 2016-06-02. Retrieved 2026-09-26.
  14. ISO/IEC 19770-1:2017 (JTC 1/SC 7 flagship standards page)ISO/IEC JTC 1/SC 7 committee site.Retrieved 2026-09-26.
  15. Federal Software Licenses: Agencies Need to Take Action to Achieve Additional Savings (GAO-24-105717)US GAO; published 2024-01-29.Effective 2024-01-29. Retrieved 2026-09-26.
  16. International Passport Advantage Agreement (Z125-5831-10)IBM; form dated 11/2017. Section 1.12 Compliance Verification; 1.13 Sub-Capacity terms.Retrieved 2026-09-26.
  17. Microsoft SAM Program Frequently Asked QuestionsMicrosoft; undated PDF.Retrieved 2026-09-26.
  18. Cloud Computing: Selected Agencies Need to Implement Updated Guidance for Managing Restrictive Licenses (GAO-25-107114)US GAO; published 2024-11-13.Effective 2024-11-13. Retrieved 2026-09-26.
  19. Licensing & SaaS (FinOps Framework capability)FinOps Foundation framework page.Retrieved 2026-09-26.
  20. ISO/IEC 19770-2:2015 Information technology: IT asset management, Part 2: Software identification tagISO catalogue page. Edition 2, 2015-10.Effective 2015-10-01. Retrieved 2026-09-26.
  21. ISO/IEC 19770-3:2016 Information technology: IT asset management, Part 3: Entitlement schemaISO catalogue page. Edition 1, 2016-04.Effective 2016-04-01. Retrieved 2026-09-26.
  22. ISO/IEC 19770-4:2017 Information technology: IT asset management, Part 4: Resource utilization measurementISO catalogue page. Edition 1, 2017-09.Effective 2017-09-01. Retrieved 2026-09-26.
  23. The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29)Published 2024-02-26. Asset Management category ID.AM.Effective 2024-02-26. Retrieved 2026-09-26.
  24. Veterans Affairs: Actions Needed to Address Software License Challenges (GAO-25-108475)US GAO; published 2025-05-19.Effective 2025-05-19. Retrieved 2026-09-26.
  25. Microsoft Product Terms, Universal License Terms for all Software (EA/EAS)Live publication. License reassignment rule.Retrieved 2026-09-26.
  26. ISO/IEC 20000-1:2018 Information technology: Service management, Part 1: Service management system requirementsISO catalogue page. Edition 3, 2018-09.Effective 2018-09-01. Retrieved 2026-09-26.
  27. What is FinOps?FinOps Foundation definition, updated March 2026.Retrieved 2026-09-26.
  28. Oracle License Definitions and Rules BookletEffective 2024-06-15. Named User Plus and Processor definitions; user minimums table.Effective 2024-06-15. Retrieved 2026-09-26.

See also

Esc