Asset reconciliation is the process of comparing discovery data, procurement records, and entitlement information to find mismatches. It shows where software is installed, where licences exist, and where usage no longer aligns with ownership. This is a core SAM control because it turns raw data into an accurate compliance and cost picture.
Expanded Definition
Asset reconciliation is the disciplined comparison of discovery outputs, procurement records, and entitlement data to identify mismatches between what exists, what was purchased, and what is actually in use. In software asset management, that comparison is what turns inventory data into a defensible compliance position and a credible cost baseline.
In NHI environments, the same logic applies to service accounts, API keys, certificates, and other secrets-backed assets: discovery may show one set of active identities, procurement may show another, and entitlement records may reveal broader or narrower usage than expected. Definitions vary across vendors on whether reconciliation is a reporting step or a control in its own right, but the operational purpose is consistent: expose drift before it becomes audit exposure or unnecessary spend. This discipline aligns closely with the control intent found in NIST SP 800-53 Rev 5 Security and Privacy Controls, where inventory and accountability are foundational. The most common misapplication is treating reconciliation as a quarterly spreadsheet exercise, which occurs when discovery, procurement, and entitlement sources are never normalized to the same asset identifiers.
Examples and Use Cases
Implementing asset reconciliation rigorously often introduces data-normalization and ownership-mapping overhead, requiring organisations to weigh compliance accuracy against the effort of cleansing inconsistent records.
- A software licensing team compares endpoint discovery with purchase orders to identify unlicensed installations that should be removed or licensed.
- A cloud operations team reconciles discovered service accounts against approved entitlements to find dormant identities that still retain access.
- An audit team checks certificate inventory against procurement and renewal records to locate assets that were deployed outside approved workflows.
- A security team uses the reconciliation output from the Ultimate Guide to NHIs to compare known NHIs with actual usage and confirm whether retired integrations still exist in production.
- An engineering manager reviews application usage against licence allocation to retire redundant subscriptions and recover spend.
For the governance side of the same problem set, the inventory and accountability expectations reflected in NIST SP 800-53 Rev 5 Security and Privacy Controls provide a useful benchmark for what “complete” should mean in practice.
Why It Matters in NHI Security
Asset reconciliation matters because NHI risk often hides in the gap between declared ownership and actual deployment. NHIMG reports that only 5.7% of organisations have full visibility into their service accounts, while 96% store secrets outside secrets managers in vulnerable locations such as code, config files, and CI/CD tools. Together, those conditions make reconciliation a prerequisite for meaningful control, not a bookkeeping exercise.
When reconciliation is weak, orphaned service accounts, duplicated API keys, and forgotten certificates continue to operate long after teams believe they have been retired. That creates blind spots for rotation, offboarding, incident response, and licence governance. The same principle is reinforced in the Ultimate Guide to NHIs, which shows how visibility gaps compound identity risk across the lifecycle, and in NIST SP 800-53 Rev 5 Security and Privacy Controls, where traceability and control monitoring are central expectations. Organisations typically encounter the cost and security impact of asset reconciliation only after an audit exception, an expired certificate outage, or a secrets-leak investigation, at which point reconciliation becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Asset reconciliation depends on knowing which NHIs exist and where they are used. |
| NIST CSF 2.0 | ID.AM-1 | Asset management requires an accurate inventory of physical and logical assets. |
| NIST SP 800-63 | Identity proofing and lifecycle assurance rely on accurate record matching, though not a direct control term. | |
| NIST Zero Trust (SP 800-207) | Zero Trust depends on accurate asset and identity visibility for access decisions. | |
| CSA MAESTRO | Agent and tool inventories must be reconciled to govern autonomous execution safely. |
Maintain an authoritative NHI inventory and reconcile it routinely against discovery and entitlement records.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org