Ask a large organisation a plain question — what does our technology cost, and can we defend how it's governed? — and you'll be handed to four different people.
Software sits with Software Asset Management, on ISO/IEC 19770. Hardware sits with Hardware Asset Management, also on ISO/IEC 19770 — the two share IAITAM good practice. Cloud sits with FinOps, measured against the FinOps Foundation Framework. AI, the newest arrival, now answers to the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework.
Four mature disciplines. Four sets of tools. Four owners. Four spreadsheets. And one thing in common: when an auditor or the board asks a question, someone rebuilds the evidence by hand.
We think that's the wrong shape — and SofClo exists because of it.
The four are already one system
The walls between them are drawn on paper, not in reality. The generative-AI tool your risk team is classifying as high-risk under the AI Act is also a subscription your SAM team is paying for, running on cloud your FinOps team is trying to forecast, on hardware someone has to account for. One system, one contract, one vendor, one budget line — described four times, by four people who rarely compare notes.
Split that contract across four programmes and no one is left holding the whole thing. That isn't a tooling gap. It's a structural one.
Governance fails in the gaps, not on tooling
Each discipline has good tools. What they lack is a shared spine. A saving your FinOps team books and a commitment your SAM team signs can quietly contradict each other. An AI system can be waved through by a committee that never sees the licence or the cloud bill behind it. A control can be genuinely well-run and still go invisible the moment the question crosses a team boundary — which is exactly when the board and the regulator ask.
So the evidence gets rebuilt by hand, from four sources that were never designed to agree — slow, expensive, and fragile in the moment you most need it to hold.
“Most tools can tell you what your technology costs. Far fewer can tell you whether you can defend it.
What changes with one programme
One programme doesn't mean one team doing everything. It means the four disciplines plan, execute and continuously improve as one programme — each still measured against the framework that governs it, but with the seams between them closed. Every action is mapped to its framework, so a control and its evidence are the same object. Evidence is captured as you go, so you're never preparing for the audit — the trail already exists. And you can see maturity, not just cost: score each discipline, benchmark it, and show the board it moved.
Why we're writing this
That second question — can you defend it — is the one we care about, and it's what this blog is about: working notes on how SAM, HAM, FinOps and AI Governance actually behave once they share one programme. More notes shortly. The short version is on the front page.