Catch Advisors
Vendor Guidance

IT Asset Disposal Renewal: Trace One Device Before You Sign

Your IT asset disposal provider gives you a certificate that says a batch of equipment was destroyed.

That sounds reassuring. It does not prove that one specific laptop made it from your loading dock to the right sanitization process and final destination.

Before you renew the provider, trace one real device through the entire workflow. Use the serial number or asset tag. Match the pickup record, custody events, sanitization result, exceptions, certificate, and final disposition.

If the records connect, you have evidence. If they do not, you have found the gap while you still have contract leverage.

A destruction certificate is one record, not the whole control

IT asset disposition, often called ITAD, sits at the end of the asset life cycle. The device may be retired, but the data, ownership record, lease obligation, environmental handling, and security risk are not retired until someone proves what happened.

That is why a provider-level statement such as “we follow NIST” is too broad. Current NIST SP 800-88 Rev. 2 guidance separates the work into several decisions. The organization selects an appropriate sanitization method. The sanitization result is verified. Errors and anomalies are assessed during validation. The organization then decides whether the result is acceptable or needs another method.

NIST also says the value of a sanitization certificate depends on how the organization tracks storage media across its life cycle. Records should connect when the media enters the environment, leaves the place where it was last used, and reaches its destination after sanitization. A certificate can show that listed devices were sanitized. It cannot prove that every device your company released was included.

This is the renewal decision: can the provider and your team connect the asset population to device-level evidence without filling the gaps with assumptions?

Pick an awkward device for the test

Do not let the provider choose the cleanest record in the batch.

Pick a device that makes the workflow work a little harder. Good candidates include:

  • A laptop from a remote employee
  • A server with several storage devices
  • A leased device that must be returned
  • A damaged phone that cannot boot
  • Equipment with a missing or unreadable asset tag
  • A device removed from a restricted location
  • An asset that produced an exception during processing

The point is not to trap the provider. The point is to test the service you are paying for under realistic conditions.

Start with a device that appears in your IT asset inventory. Record the manufacturer, model, serial number, internal asset tag, assigned user or system, site, data sensitivity, retirement approval, and expected treatment.

If your own record is incomplete, call that out. Vendor evidence cannot repair a broken internal handoff. You need both sides of the workflow.

Trace the device through six records

1. Retirement approval

Confirm who approved the asset for retirement and why. Check whether legal hold, records retention, lease, warranty, insurance, or reuse requirements applied before release.

The disposal provider should not decide what company records can be destroyed. NIST assigns retention advice to the records management function and makes the information owner responsible for understanding the sensitivity of the information. Your titles may differ, but those decisions still need owners.

Ask for the approved asset list that was sent to the provider. The selected serial number should appear once, with the intended service and location.

2. Pickup and transfer

Match the device to the pickup manifest, date, time, site, quantity, container or pallet identifier, and the people or parties involved in the transfer.

Then ask how custody is recorded after pickup. Does the provider scan each asset at the site, at its facility, or only after equipment is unpacked? What happens between those events? Which carrier, subcontractor, or transfer location touches the equipment?

A batch count is useful, but it is not enough. If your manifest says 83 devices and the provider received 82, the workflow needs a named exception and an owner. It does not need a corrected total that quietly makes both systems match.

3. Receiving and reconciliation

Find the provider’s receiving record for the selected device. Compare the serial number and asset tag with your source inventory and pickup manifest.

Check the full batch reconciliation too:

Reconciliation pointEvidence to inspect
Released by your companyApproved asset list and pickup manifest
CollectedDriver or courier record, seal or container ID, date, and site
Received by providerDevice-level scan and facility receipt
Accepted for processingService assignment and condition record
CompletedSanitization or destruction result
ExceptionMissing, duplicate, damaged, unreadable, or misrouted item record
Final dispositionReuse, resale, recycling, return, or destruction record

Every difference needs a disposition. “The totals were close” is not a control.

4. Sanitization result

Identify the storage media inside the device and the method applied to it. A laptop record may not be enough if the device contains more than one drive or a replaced drive was handled separately.

NIST defines three sanitization methods: clear, purge, and destroy. The right method depends on the media, information sensitivity, intended reuse, available technology, policy, and accepted residual risk. Do not put a universal method into the contract and assume it fits every device.

Require the provider to record the actual technique and tool. Current NIST guidance says a completed certificate should include manufacturer, model, serial number, media or property number when applicable, media type, source, sanitization method, technique, tool and version, verification method, and information about the people performing verification and validation.

That is much stronger than a PDF that lists a batch number, a service date, and the word “destroyed.”

5. Verification, validation, and exceptions

These words are easy to blur together. Keep them separate.

Verification checks whether the selected technique completed successfully. For a software-based process, that can include completion status, errors, anomalies, and media health. For destruction, it includes inspecting the remnants and identifying the equipment used.

Validation is the decision that follows. Someone considers the verification result, the sensitivity of the data, any errors, and the residual risk. The result is accepted, rejected and repeated, or moved to a more secure method.

For the selected device, ask:

  • Did the tool report success?
  • Were there unreadable areas, tool errors, damaged media, or identification problems?
  • Who reviewed the result?
  • What rule determined acceptance?
  • If the first attempt failed, what happened next?
  • Does the certificate reflect the final accepted result rather than the first attempt?

A provider that reports only successful devices is not giving you a complete operating record. You need to see how failures are controlled.

6. Final disposition

Sanitization and disposition are related, but they are not the same event.

A sanitized device may be reused, resold, donated, returned to a lessor, recycled, or destroyed. Your contract should define which paths are allowed by asset type and who can approve an exception.

Match the selected device to its final record. If it was resold, confirm when ownership transferred and what record connects the asset to that path. If it was recycled or destroyed, identify the downstream facility or approved processor when another party handled the material.

Then reconcile financial treatment. Was there a resale credit, processing charge, freight fee, exception fee, storage charge, or lease penalty? Match the device or batch evidence to the invoice and credit report.

Security evidence and financial evidence should tell the same story.

Check the provider’s downstream boundary

Many buyers evaluate the company that signs the agreement and stop there.

Ask which work the provider performs itself and which work moves to a carrier, subcontractor, recycler, resale channel, or downstream processing facility. For each handoff, identify:

  • The service performed
  • The location
  • The custody record
  • The required security and handling standard
  • The evidence returned to your company
  • The party responsible for an incident or missing asset
  • The provider’s right and duty to audit the downstream party
  • The notice and approval process for changing downstream parties

A certification can help your due diligence, but it should not replace the device trace. Check the certification scope, named facilities, expiration, exclusions, and whether the entities touching your equipment are covered.

Put the evidence requirement into the renewal

A successful one-device trace is a useful test, not permission to ignore the contract.

The renewal should define:

  • How assets are identified at pickup and receipt
  • When custody transfers
  • Required reconciliation timing
  • Approved sanitization methods by media and risk class
  • Verification and validation evidence
  • Exception categories, escalation timing, and owners
  • Certificate fields and delivery deadline
  • Approved final disposition paths
  • Downstream-provider controls
  • Incident notice and investigation support
  • Insurance and liability treatment
  • Record retention and your access to records after termination
  • Pricing for pickup, processing, exceptions, storage, freight, resale, and reporting
  • Your audit rights and the provider’s response time

Run this work before the notice deadline using an IT contract renewal calendar. If the trace exposes missing records, you need time to correct the workflow, negotiate the terms, or compare providers.

Make one of four renewal decisions

Renew as proposed when your inventory, custody records, sanitization evidence, exceptions, final disposition, and billing connect cleanly, and the contract matches the service being delivered.

Renew with corrections when the provider performs well but the agreement, certificate fields, reconciliation timeline, exception process, downstream controls, or pricing needs to be tightened.

Use a short bridge when the current provider is not ready for a long commitment but an immediate transition would create more custody and security risk. Define the exact records and process changes the bridge must produce.

Compare alternatives when devices cannot be reconciled, failed sanitization is hidden, downstream handling is unclear, records arrive too late to investigate, or the provider will not commit to device-level evidence.

Do not renew because the boxes disappeared and a certificate arrived. Trace one device. Make the records connect. Then decide whether the provider has earned another term.

If your IT asset disposition agreement is approaching renewal, request a Contract and Spend Risk Review. Bring the agreement, proposal, invoices, asset inventory, pickup manifests, certificates, exception history, and a sample device record. Catch Advisors will help you identify what is proven, what is missing, and what needs to change before you sign.