MI Solutions
Insights/Operating model and governance
Operating model and governance

Writing a Software Asset Management Policy (With Template Outline)

What a software asset management policy should cover, with a section-by-section template outline and sample wording you can adapt.

By the MI Solutions SAM team10 min read2 exhibits

A SAM policy sets the rules for how software is requested, bought, used, renewed and retired. It gives everyone the same expectations and gives the SAM function the authority to act, for example to reclaim an unused license. The best policies are short, specific and enforced.

Template outline

Exhibit 1
A SAM policy in eight sectionsTemplate outline11–2Purpose andscopeWhat and who itcovers23RolesOwners andresponsibilities34–5Request andpurchaseCatalog, approval,contracts46Use and reclaimAssignment,inactivity,leavers57–8Renew, retire,complyDeadlines,records,exceptions

Sample wording is given in italics. Replace the values in brackets with your own.

1. Purpose

"This policy ensures the organization uses software legally, securely and cost-effectively, and can demonstrate compliance at any time."
Sample wording

2. Scope

All software and SaaS used for company business, on any device, paid or free, including AI tools.

3. Roles and responsibilities

Executive sponsor, SAM lead, vendor owners, procurement, finance, IT operations and employees. See software ownership RACI.

4. Requesting software

"Software must be requested through [channel]. Requests are checked against the approved catalog before any purchase."

5. Purchasing and contracts

Approval tiers, contract review requirements, and the requirement to record every contract in the SAM system on signature. See SaaS approval workflows.

6. Assignment and reclamation

"Licenses are assigned to named individuals. Licenses unused for [90] days will be reclaimed after notice of [14] days." See inactive user thresholds.

7. Renewals and retirement

"Every agreement above [threshold] must have a named owner and a recorded decision before its notice deadline."

8. Compliance and records

Proof of entitlement, audit coordination, exceptions process and policy review cycle.

Numbers make a policy enforceable

A policy that says "licenses should be reclaimed when not needed" cannot be applied consistently. One that says "after 90 days, with 14 days' notice" can. Every rule that triggers an action should carry a number.

Numbers to decide before you publish

01Inactivity threshold

Days without use before a license is reclaimed, per product type.

02Notice period to users

Days between notification and reclamation.

03Approval tiers

Cost and data-risk thresholds for each tier.

04Renewal threshold

Contract value above which the full renewal playbook applies.

05Review deadline

Days before the notice deadline by which a decision is recorded.

06Record deadline

Days after signature by which a contract is in the SAM system.

Which sections do the most work

In practice, a few sections of the policy are used far more than the others: the ones that trigger an action.

Exhibit 2
Three sections drive most of the day-to-day decisionsShare of policy-based decisions in a year by section, illustrative 900-person company0%10%20%30%40%6. Assignment and reclamation38%4–5. Request and purchase27%7. Renewals and retirement21%8. Compliance and records9%1–3. Purpose, scope, roles5%Illustrative. Sections with numbers attached are the ones people act on; give them the most care.

Making it stick

How MI One helps

Frequently asked questions

Should free software be covered?

Yes, especially if it holds company data.

How long should the policy be?

Short enough to read in ten minutes. Put detailed procedures in separate guides.

Who should approve exceptions?

The SAM lead for routine exceptions, the executive sponsor for significant ones, and every exception recorded.

See where your software budget goes

Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.