Introduction
Fixed asset control procedures are the documented, owner-assigned steps that support the control of fixed assets and keep every asset event acquisition, tagging, transfer, verification, reconciliation, and disposal authorized, recorded, and evidenced. This guide maps the full procedure set, the policy clauses behind it, and the audit tests that prove it operates, with a free template of the whole thing.
For teams that need these procedures executed by trained specialists rather than built from scratch, a fixed asset management service covers tagging, verification, reconciliation, and disposal end to end.
This guide gives you the full set, and the template at the end turns it into a document you can adopt. It is written for the finance controller, fixed asset manager or internal auditor who has been asked to produce a policy and has nothing to start from.
In this guide, you will learn:
- What fixed asset control procedures must achieve, including existence, completeness, accuracy, authorization, custody, and safeguarding across the asset lifecycle.
- How to implement seven core controls covering acquisition, tagging, transfers, physical verification, reconciliation, useful-life reviews, and disposal.
- Why fixed asset policies, evidence requirements, audit testing, and approval controls support compliance with SOX and CARO 2020 requirements.
- How to build and roll out a practical control framework using defined owners, evidence, audit tests, control matrices, jurisdiction requirements, and periodic reviews.
Control Objectives: What Control of Fixed Assets Must Achieve
Procedures without objectives become paperwork. The control of fixed assets exists to satisfy five testable objectives; auditors will recognize them as the assertions behind every fixed asset question:
- Existence: Every asset on the register is physically there; no ghost assets.
- Completeness: Every asset that is physically there is on the register; no unrecorded assets.
- Accuracy and valuation: Costs, useful lives, depreciation, and locations are right.
- Authorization: Every addition, transfer, write-off, and disposal was approved by the right role before the record changed.
- Custody and safeguarding: A named person is accountable for each asset, and movement leaves a trail.
Every procedure below exists to serve at least one of these. If a step in your current process serves none of them, it is friction, not control.
Fixed Asset Control Procedures: Acquisition to Disposal
Seven procedures cover the life cycle of fixed assets across four phases — acquisition and capitalization, depreciation, maintenance and tracking, and disposal. Each names its objective, owner, evidence, and frequency in the same structure; the template turns into your document.
Approval routing is the backbone: route by value, asset class, and transaction risk, so high-risk events get scrutiny and routine events keep moving.
Control ID | Procedure | Control objective | Owner | Minimum evidence | Frequency |
|---|---|---|---|---|---|
| CP-01 | Acquisition & capitalization review | Valid, complete, correctly valued additions | Finance (review) / requester (initiate) | Approved capex request, invoice/receipt, capitalization checklist | Event-based |
| CP-02 | Identification & tagging | One unit, one identity, linked to the record | Fixed asset manager | Tag issue log from a controlled registry; serial capture | Event-based |
| CP-03 | Custody & transfer | Authorized movement; custody never ambiguous | Sending + receiving owners/approver by threshold | Transfer request, both confirmations, old/new values | Event-based |
| CP-04 | Physical verification | Existence and condition, periodically proven | Asset-control owner + site owners | Count results with scan/photo evidence, exception log | Risk-based cycle |
| CP-05 | Reconciliation (register to GL, floor to register) | Records agree; differences explained and resolved | Finance | Reconciliation file, reconciling items, reviewer sign-off | Monthly / cycle-end |
| CP-06 | Useful-life & impairment-trigger review | Values stay realistic | Finance, fed by operations notifications | Review report, estimate-change approvals | Periodic |
| CP-07 | Disposal & derecognition | Authorized exits, promptly removed from books | Asset owner + finance + approver by threshold | Disposal pack: request, approvals, sale/scrap/data-wipe proof, posting confirmation | Event-based |
Physical Verification Controls
Verification is the procedure most programs run informally and the first one auditors probe. Run it as scheduled projects, not reminders: cycles created by plan, tasks auto-created by location and custodian, progress monitored, closure enforced. Exceptions get owners, reason codes, and approval-gated resolution; never silent register edits.
Every verification event should leave asset-wise proof scans, photos, location stamps, reviewer sign-offs in one repository, so ‘show me the evidence for this control‘ is a filter, not a project. That repository is what turns a clean count into an audit-ready control.
The Fixed Asset Management Policy Behind the Procedures
Procedures need authority; the fixed asset management policy is where they get it. The policy is the rulebook (what must happen and who decides); procedures are the playbook (how it happens); the control matrix is the test model. Your policy needs twelve clauses; the map below names each and what it must define.
Policy clause | What it must define |
|---|---|
| Purpose & scope | Covered entities, locations, asset classes, users; whether leased and low-value attractive assets are in scope |
| Definitions & asset classes | What counts as a fixed asset here; the approved class list |
| Roles & authority | Who requests, approves, records, verifies, reviews – by value threshold and transaction type |
| Capitalization thresholds | Threshold by class or entity; treatment of bundles, components, project costs |
| Asset master data | Mandatory fields for every record; who may change them and how changes are evidenced |
| Acquisition & capitalization | Approval prerequisites; readiness confirmation before capitalization |
| Identification & tagging | Controlled registry, uniqueness, tag exceptions and their approval |
| Custody & transfer | Custodian duties; approval before the register changes; both-side confirmation |
| Verification & reconciliation | Risk-based cadence; exception investigation and closure before sign-off |
| Disposal & write-off | Approval, evidence (incl. data-wipe where relevant), accounting follow-through |
| Low-value attractive assets | Tracking rule for portable, theft-prone or data-bearing items below threshold |
| Evidence retention & review | What is kept, where, for how long; annual policy review and training |
Procedures for Stock and Fixed Asset Control
Stock and fixed assets meet at the receiving dock and diverge from there, and programs that blur them lose both. The procedures for stock and fixed asset control differ on purpose: stock is counted for quantity and valuation of things meant to leave; fixed assets are verified for existence, custody, and condition of things meant to stay.
- Separate the registers: Inventory systems count SKUs; the asset register controls identities. One item, one regime.
- Decide at receipt: A receiving procedure that routes capital items to asset onboarding and stock to inventory prevents the classic drift of assets living in the stock system.
- Bridge the middle: Tools, spares and low-value attractive items need an explicit rule either controlled-stock treatment or the low-value asset register not case-by-case habit.
- Do not mix the counts: A stock take is not a fixed asset verification; the evidence, sampling and resolution rules differ. Schedule and staff them separately.
Audit Tests: How Each Procedure Gets Tested
Design controls with their tests in mind and audits stop being archaeology. The short version, procedure by procedure:
Procedure | Typical design test | Typical operating test |
|---|---|---|
| CP-01 Acquisition | Policy defines thresholds, approvers, checklist | Sample additions to approvals and source documents; search for unrecorded assets |
| CP-02 Tagging | Registry control and uniqueness rules exist | Trace tags to records on a floor sample; test duplicate rejection |
| CP-03 Transfer | Approval routing matches the authority matrix | Sample moves to both-side confirmations; test for post-hoc updates |
| CP-04 Verification | Risk-based cadence documented; exception workflow defined | Reperform a count sample; review exception aging and closure evidence |
| CP-05 Reconciliation | Tie-out procedure and reviewer named | Reperform the reconciliation; test resolution of reconciling items |
| CP-06 Useful-life review | Trigger events and review cadence defined | Review estimate changes and their support; test fully-depreciated-in-use assets |
| CP-07 Disposal | Approval gates and evidence list defined | Sample disposals to packs; test for retired-in-place assets |
The Free Template, Section by Section
The download is a complete, editable Word document in five parts.
- A – Policy: All twelve clauses as editable text with [bracketed fill-ins] and customization notes per clause.
- B – Control procedures: CP-01 to CP-07 written out objective, steps, owner, evidence, frequency ready to adapt.
- C – Control matrix: The register your internal audit team fills in IDs, activities, owners, frequency, evidence, test approach.
- D – Audit-test appendix: The design and operating tests above, mapped to each procedure.
- E – Jurisdiction addenda: Separate SOX and CARO 2020 sections, each labelled with the condition under which it applies, so you can keep the one that fits your entity and delete the rest.
SOX & CARO 2020: The Dual Compliance Frame
Two regimes put fixed asset controls under formal scrutiny, and the same procedure set answers both. For US filers, SOX section 404 requires management’s assessment of internal control over financial reporting, and PCAOB AS 2201 governs how auditors test it. CP-01 through CP-07 are exactly the testable, evidenced controls that assessment needs.
For companies under India’s Companies Act, CARO 2020 requires the auditor to report on whether proper records of property, plant and equipment are maintained, whether physical verification happens at reasonable intervals, and how material discrepancies were dealt with. CP-02, CP-04 and CP-05 are the operating answer. The template carries a toggle block per regime; keep what applies and have counsel confirm.
Neither regime is satisfied by software or a document alone: management operates the controls, keeps the evidence and owns the assessment. This guide and the template are drafting aids, not legal or audit advice.
Rolling It Out: Eight Steps
- Define the scope by specifying the entities, countries, asset classes, and teams covered, and decide whether leased and low-value attractive assets are included.
- Set capitalization and class rules; confirm thresholds and componentization treatment.
- Assign procedure owners one name per CP row, not a department.
- Set approval thresholds for additions, transfers, write-offs, disposals, and estimate changes.
- Specify evidence by event, from the minimum-evidence column. Vague “retain support” rules fail audits
- Map clauses to controls using the control matrix of the template.
- Review with finance, internal audit, IT, and operations for field practicality.
- Publish, train, monitor exceptions, and review annually.
Common Mistakes
Mistake | Better approach |
|---|---|
| Copying a generic policy without local thresholds, titles, and systems | Customize every [bracketed] field; the template’s notes flag each decision |
| Treating the capitalization threshold as the only control trigger | Add the low-value attractive asset rule: portable and data-bearing items disappear first |
| Writing ‘retain documentation’ without naming the evidence | Specify evidence by asset event, as the CP table does |
| Register updates without approval history | Approval before the record changes, on every high-risk event |
| Publishing without training or review cadence | Role-based training at issue; annual review with a named owner |
Key Takeaways
- Control of fixed assets means five testable objectives; existence, completeness, accuracy, authorization, and custody, and every procedure serves one.
- Seven procedures, CP-01 to CP-07, cover acquisition to disposal with named owners, evidence and frequency.
- The policy authorizes the procedures; twelve clauses cover it, and the free template carries their full editable text.
- SOX and CARO 2020 test the same procedure set from two directions; the template’s addenda toggle between them.
- Design every control with its audit test in mind, and year-end becomes confirmation instead of archaeology.
Conclusion
Controls that live in habit die in turnover; controls that live in a policy, a procedure set and an evidence repository survive audits, acquisitions and ERP migrations. Download the template, adapt the brackets, route the jurisdiction blocks through review, and give every CP row a name.
And when the procedures call for verification, tagging programs, physical verification cycles, and reconciliation projects, that is delivered work, not just documentation.
Controls & Policy FAQ
Q1. Is a fixed asset policy the same as a control matrix?
Ans: No. The policy defines the rules scope, thresholds, authority, evidence requirements. A control matrix maps risks to control activities, owners, frequency, evidence and test approach, and is what internal audit uses for testing. Use the policy as the rulebook and the matrix as the operating and testing model; the template carries both.
Q2. Who should approve fixed asset disposals?
Ans: Route disposal approval by asset value, risk and class: typically the asset owner initiates, finance confirms the accounting follow-through, and senior management approves above defined thresholds. The approval must precede the register change, and the disposal pack request, approvals, sale or scrap evidence, data-wipe proof where relevant is the control’s evidence.
Q3. Do we need a fixed asset policy if we already use software?
Ans: Yes. Software enforces workflows and retains evidence, but the policy defines the rules the workflows should enforce thresholds, authority, evidence, cadence. Without it, the system automates whatever assumptions each team configured. Write the policy first, then configure the software to match; the audit question is always the rule, then the enforcement.
Q4. What are procedures for stock and fixed asset control?
Ans: They are deliberately different regimes that meet at receiving: stock procedures count quantities and valuation for items meant to leave; fixed asset procedures verify existence, custody and condition for items meant to stay. Separate the registers, route items at receipt, give bridging items like tools an explicit rule, and never substitute a stock take for asset verification.