Software asset management best practices, in the standards, describe a management system with policies, roles and a reconciliation between entitlements and deployments. In a small organisation the entitlements are a folder of invoices and the deployments are whatever people installed, and the practice that matters is the one that keeps the two in sight of each other. This page sets out five practices for the office or IT manager who pays the software bills for a company of five to two hundred people: a seat register, seats against named people, release on leavers, a record of what is installed against what is paid for, and an audit file kept as you go rather than assembled under pressure.
Keep a seat register, not a subscription list
A subscription list says the organisation pays for a mail suite. A seat register says it pays for sixty seats of it at a price each, and names the sixty people. The difference is the whole practice: the register can be counted against the headcount, the list cannot. The IT asset inventory worksheet on this site takes the seat count and the price per seat and returns the licence spend a year and a month, which is the number that makes the register worth keeping.
Count seats against named people and release them on the day they leave
A seat is bought per person and, in most small organisations, cancelled per nobody. The practice is to record every seat against the person using it on the same line as their laptop, and to release the seat as part of the leaver's return on the day it happens. The annual saving is usually the cost of the register several times over, and the record is what a vendor's licence audit asks for first: who used what, from when to when.
Reconcile what is installed against what is paid for
Software asset management has two counts: entitlements, which is what the invoices say, and deployments, which is what is actually installed and running. CIS Control 2 asks for an inventory of authorised software and the removal of what is not authorised. In a small organisation the practical version is a discovery pass that lists the installed software per device, reconciled against the seat register, with the gap in either direction recorded: paid for and not installed is waste, installed and not paid for is the audit risk.
Keep the audit file as you go
ISO/IEC 19770-1 describes a management system whose purpose is to be able to demonstrate control over software assets at any time. For a small organisation that reduces to a folder: the invoices and agreements, the seat register with its history, the reconciliation results with their dates, and the leaver releases. Kept as the rows are written, it is a file; assembled after the vendor's letter arrives, it is a fortnight.
Questions people ask about software asset management best practices
What is the difference between software asset management and IT asset management?
Software asset management is the licence half of IT asset management: the seats bought, the seats in use and the gap between them. In a small organisation they are one register with two views, and the person keeping it is the same.
How many seats should a small organisation expect to find unused?
There is no published figure this site will quote; the honest answer is to count. The seat register against the headcount, done once, is the measurement, and it is usually the first thing that pays for the register.
Do I need a software asset management tool?
You need a seat register with history and a way to list what is installed. Many small organisations run the first in their asset register and the second from the management agent or the discovery pass they already have.
What does a vendor licence audit ask for?
Proof of entitlement (the invoices and agreements), a record of deployments (what is installed where), and the reconciliation between them. The practices on this page are that record kept in advance.