Most large IT estates are losing money right now, and almost none of it shows up as a single decision anyone made. A license still renewing for someone who left the company eight months ago. A server nobody has gotten around to decommissioning because nobody's certain it's safe to. A cloud instance still billing for a project that wrapped up last quarter. None of it looks urgent by itself. Add it up across a few thousand assets, and the total stops being a rounding error and starts being a number someone eventually has to explain to finance.
Most conversations about fixing this start in the wrong place, with the word "ITAM" itself, treated like one tool an organization either has or doesn't. It isn't one tool. IT assets split into a small number of genuinely different categories, physical hardware, software and licensing, and cloud consumption, and each behaves differently enough that lumping them together is exactly how the small losses above go unnoticed for so long. Hardware ages, moves, and gets lost. Software gets over-licensed or under-licensed depending on who last counted. Cloud spend moves in real time, often provisioned by a developer with a credit card at 11 p.m. and forgotten by everyone including the developer.
"Do we need ITAM" is really three smaller questions: do we need better control over physical hardware, over software licensing and compliance, or over cloud spend. Most organizations need more than one. Very few need all three configured to the same depth on day one.
Three products carry most of the weight inside ServiceNow's answer to these three questions: Hardware Asset Management, Software Asset Management, and Cloud Cost Management. Each is licensed independently even though all three run on the same CMDB underneath. That's the natural order to work through them.
Hardware Asset Management: Where the physical lifecycle lives
Hardware Asset Management runs the lifecycle of laptops, desktops, servers, monitors, mobile devices, and network equipment, using the CMDB as its source of truth rather than a separate inventory spreadsheet. It covers the full run from procurement through deployment, support, and eventual disposal, and it handles the unglamorous mechanics that make that run possible: defining stockroom hierarchies, setting reorder thresholds so a low-stock model triggers a purchase automatically instead of a fulfiller noticing three weeks late, and giving field teams a mobile app to receive a shipment against a purchase order by scanning barcodes rather than typing serial numbers by hand one at a time.
That last piece matters more once hardware gets tied to HR. When a new hire's onboarding case fires, HAM can source a standard laptop and monitor from stock, trigger a purchase if nothing's available, and stage the configuration before day one, the same workflow whether IT is provisioning one person or four hundred. The mobile experience runs the other direction too: employees can see the assets assigned to them, request new ones, and open an incident against a broken device from their phone, instead of emailing a help desk alias and waiting.
The AI layer sits on top of that same lifecycle, aimed at the parts that used to take the most manual effort. It can build a purchase order directly from a vendor quote someone uploads instead of a person retyping line items, generate a written summary of an asset's condition and history on demand, and help a technician work through a repair with a generated troubleshooting plan, which matters more than it sounds like it should. A lot of repair downtime has less to do with the actual fix and more to do with the time it takes someone to work out what's wrong and whether the device is still under warranty.
HAM also owns the data center side of hardware, tracking racks, servers, and network equipment from a facilities view rather than a per-device view. Organizations running telecom infrastructure specifically extend this further with Telecommunications Network Inventory, which applies the same lifecycle discipline to network assets, circuits, and topology at a scale a general hardware workspace isn't built for; AT&T built part of its own network inventory approach on it. Customers running HAM report a 50% reduction in manual tasks, a 50% decrease in inventory audit time per facility, and a 42% reduction in hardware assets, largely from finally having accurate enough data to stop over-buying.
Software Asset Management: Where compliance and waste live
Software Asset Management is the discipline most directly tied to audit exposure, because it has to reconcile two different realities. One is technical: what's actually installed or subscribed to, discovered across laptops, servers, and SaaS integrations. The other is commercial: what the organization has actually purchased the right to use. The gap between those two is where both overspending and audit risk live, and closing it is most of what SAM does.
The data behind that reconciliation runs to more than 4.3 million publisher part numbers, with normalization rates as high as 98%, which matters because inconsistent product naming across discovery sources is one of the most common reasons a license position comes out wrong in the first place. On top of that data, the AI layer does three specific jobs well. It manages requests: identifying which entitlements a software request actually needs, recommending the next action to fulfill it, and automating the transfer of stock or license allocation once approved. It prepares for audits: summarizing a publisher or product's current compliance position with one click instead of someone rebuilding it from spreadsheets, and surfacing true-up costs before they arrive as a surprise. And it builds reclamation rules: flagging software that doesn't have one configured, analyzing usage patterns to recommend where one should exist, and freeing up licenses that would otherwise auto-renew out of habit.
The audit-specific tooling goes a layer deeper for regulated organizations. Asset Audit Response, sold alongside IT Asset Management for Financial Services as a supplement to SAM or HAM rather than a separate core product, gives asset managers a dedicated workspace for managing evidence requests, tracking remediation against due dates, and keeping a full history of past audits instead of reassembling one from scratch every time a regulator asks.
SAM also picks up two problems that used to sit outside traditional asset management entirely. SaaS sprawl gets tracked by connecting to identity providers like Okta or Microsoft Entra ID, so a subscription nobody's touched since a project ended actually surfaces instead of quietly renewing. And software rationalization, deciding what to keep, consolidate, or retire across a portfolio, runs alongside enterprise architecture and procurement rather than as a spreadsheet exercise disconnected from what IT is actually planning. SAM is FedRAMP certified on top of all this, which lets it flag restricted or unauthorized software and trigger remediation before the next audit cycle finds it.
Cloud Cost Management: FinOps, and now AI governance too
Cloud Cost Management, sold under that name today after previously known as Cloud Insights, is the FinOps side of ITAM, covering SaaS, IaaS, and PaaS consumption across providers in one place instead of three separate vendor consoles. A workspace tracks hybrid cloud spend across computing, storage, containers, and databases; an executive dashboard rolls software, hardware, and cloud costs into one view; and tag normalization keeps cost reporting consistent across accounts that were never set up to talk to each other. Migration planning and Bring Your Own License support sit in the same product, so a licensing decision gets made before a workload moves to the cloud rather than discovered as a surprise line item after it lands there, and change management ties cloud spend controls into the same approval process IT already runs for everything else.
The newest use case folded into this product is AI governance, and it's a genuine fit rather than a bolt-on. Every model, agent, and dataset an organization runs is functionally a cloud asset: something acquired, something consuming resources, something with a bill attached. Most of it doesn't arrive through procurement. It shows up through an API key someone signed up for or a business unit trialing a tool nobody in IT approved. Cloud Cost Management compares AI and machine learning spend across providers the same way it compares any other cloud cost, and connects into AI Control Tower for the governance side, aligning AI initiatives to business context, managing AI operations end to end, and keeping controls in place to manage risk and demonstrate compliance.
The regulatory backdrop makes this less theoretical by the month. The EU AI Act's obligations for most standalone high-risk AI systems now land December 2, 2027, and for AI embedded in already-regulated products like medical devices, August 2, 2028, both pushed back from the original 2026 timeline. A narrower requirement, watermarking AI-generated content, kept a shorter runway and now applies from December 2, 2026, while the broader duty to tell people they're interacting with AI still takes effect in August 2026 regardless. None of that phases out the underlying question, which AI systems are running and against what data, it just changes when someone has to answer it with evidence. That answer depends entirely on the CMDB and asset data the rest of ITAM has already built. An organization with clean hardware and software records is starting AI governance from a real foundation. One without it is starting from nothing, no matter how good the dashboard looks on day one.
For organizations further along in cloud adoption, Cloud Cost Management also connects into the broader Cloud Governance Suite, which layers compliance and security controls on top of the same spend data rather than treating cost, security, and governance as three separate cloud initiatives run by three different teams.
The CMDB underneath all of it
Hardware Asset Management, Software Asset Management, and Cloud Cost Management each produce their own records. What ties them together, and what makes ServiceNow's version of ITAM different from three disconnected point tools, is the Configuration Management Database sitting underneath all three.
The split is deliberate, not incidental. Asset records live in a repository that tracks financial and contractual detail: what something cost, what contract governs it, what it's depreciated to. The CMDB tracks configuration items and their relationships: what's operational, what business service it supports, what breaks if it goes offline. A laptop can exist as an asset record without a matching configuration item, or as a configuration item without a full asset record, depending on whether it needs financial tracking, operational tracking, or both. When a new asset gets added, a business rule engine creates the matching CI record in the CMDB automatically where one's needed, which is what eliminates the manual reconciliation between an asset list and an operational inventory that most organizations running separate tools for each still do by hand.
That connection is also where ITAM rollouts most often stall. One organization has procurement, HAM, the CMDB, and SAM all pointed at the same underlying records with clear rules for who owns which exception. Another has the same systems technically wired together but nobody accountable when a retired asset keeps showing up in discovery, or a software entitlement points to the wrong product. The feature list looks identical in both cases. The result doesn't, because it depends entirely on whether the data feeding it is trustworthy, and that's a governance problem, not a configuration setting.
Enterprise Asset Management: The same discipline, beyond IT
For organizations that need it, the same lifecycle logic extends past IT entirely through Enterprise Asset Management, a separately licensed product covering facilities equipment, operational technology, and anything else with a maintenance schedule and a total cost of ownership worth tracking. It runs the same kind of workflow HAM applies to a laptop, applied instead to an HVAC system or a piece of manufacturing equipment, with AI increasingly helping a technician work through a repair rather than just logging a ticket and waiting for someone to show up.
Most ITAM conversations never need to go here, and most organizations shouldn't force the fit. It earns its place specifically when IT and facilities have historically run on separate systems and nobody can put one number on what the organization actually owns across both.
Connecting ITAM to what you already run
None of this is meant to replace the tools already collecting asset data across an organization. It's meant to bring that data onto one platform, and the mechanism that does it is called a Service Graph Connector, ServiceNow's term for a certified integration that syncs data from a third-party source directly into the CMDB.
On the endpoint side, certified connectors exist for Tanium Asset, syncing hardware, software, and software usage data directly in, along with Microsoft Intune, SCCM, and Jamf for Apple device management. For SaaS and identity, SAM connects to Okta and Microsoft Entra ID to reconcile who's actually using which single sign-on applications. On the procurement and financial side, asset data can sync with SAP Ariba's buying and sourcing records and with ERP-side purchasing and financial data, accounts, business units, cost centers, so an asset record and a general ledger line don't have to be reconciled by hand. Physical tracking extends further still through RFID and barcode scanning for asset location, and through connectors built for healthcare device discovery in clinical environments where a device's location and status carry compliance weight of their own.
The point of all of it is the same: an organization's existing investment in Tanium, or Intune, or SAP, or a barcode scanner on a warehouse floor doesn't get thrown out to adopt ITAM. It gets pointed at one shared record instead of feeding five separate ones that quietly drift apart from each other over time.
Buying and scoping it properly
HAM, SAM, Cloud Cost Management, and EAM are each quoted separately based on asset volume and which capabilities an organization actually needs, and Asset Audit Response is licensed as an addition to SAM or HAM rather than bought on its own. That separation is worth planning around rather than working around after the fact. An organization evaluating this space is better served scoping the conversation by which specific problem is costing the most right now, software audit exposure, hardware waste, or cloud spend nobody can fully explain, rather than asking for "ITAM" as one line item and finding out later which pieces were and weren't included.
The rollouts that go well tend to start narrow: pick the highest-cost or highest-risk category first, get the CMDB data clean enough for that one area to actually work, and expand from there. That approach also surfaces CMDB gaps early, while they're still cheap to fix, rather than after three product areas are all depending on the same broken data.
It's worth being honest about ownership before any of this gets configured, too. Procurement usually owns purchase orders and supplier relationships. IT typically owns stockrooms, deployment, and disposal. Finance owns depreciation and capitalization rules. Security cares about what's discoverable and what isn't. None of that has to live in one team, but there does need to be one place where those groups agree on who fixes what when a record doesn't match reality, because that decision gets much harder to make once three departments have already built processes around three different versions of the truth.
If you're trying to work out which of these pieces your organization actually needs first, or whether what's already licensed is being used the way it should be, that's the kind of assessment SYSUSA works through with ServiceNow customers regularly.



