Home / Insights

How to Maintain Chain of Custody During an Office Closure

UK office-closure ITAD guide covering asset discovery, secure staging, handover, transport, chain of custody, sanitisation evidence and reconciliation.

Why office closures create unusual IT asset risk

An office closure compresses normal IT lifecycle work into a short, disruptive period. Staff may be leaving, furniture and equipment may be moving simultaneously, contractors may have access to the site, network services may be shutting down and the lease may impose a hard exit date.

That environment makes chain of custody particularly important. Laptops, desktops, servers, switches, firewalls, printers, removable media and storage devices can contain business or personal information even when they are obsolete, disconnected or faulty.

What chain of custody means in ITAD

Chain of custody is the documented transfer of responsibility for assets as they move between people, locations and processing stages. For an office closure, it should connect the asset in the closing office to its authorised final outcome.

NCSC guidance says transferred assets should have appropriate tracking and that sensitive or valuable assets may require more stringent, detailed chain-of-custody tracking. It also says assets holding potentially sensitive data should be stored securely while awaiting the next stage of decommissioning.

Start before the removal team arrives

The strongest chain of custody starts with planning, not at the loading bay. Establish the closure scope, responsible stakeholders, rooms and floors involved, lease-exit date, technical dependencies, data-bearing asset classes, reuse requirements, destruction policy and evidence requirements.

Agree who can authorise assets to leave the premises and who can approve exceptions.

Create a source-of-truth inventory

Build or validate an inventory before equipment is dispersed. Useful fields include manufacturer, model, serial number, asset tag, hostname where appropriate, room/floor, user or owner where appropriate, media type and intended disposition.

NCSC recommends validating asset records and understanding an asset's purpose and, where appropriate, the data it processes, stores or transmits. Shadow or unrecorded assets should be treated as exceptions rather than silently added to disposal totals.

Survey every office area

Walk the site systematically: comms rooms, server rooms, desks, meeting rooms, reception, print areas, storage cupboards, secure cabinets, build rooms and satellite spaces. Office closures often reveal forgotten equipment that has not appeared in the live asset register for years.

Record unexpected devices and do not allow unidentified data-bearing equipment to disappear into a general clearance stream.

Separate ITAD from general office clearance

Do not mix data-bearing IT equipment indiscriminately with furniture, scrap metal or general waste. Establish a controlled IT asset stream with defined ownership.

General clearance contractors may be excellent at removing furniture but should not automatically be given custody of devices containing corporate or personal data unless that role has been authorised and appropriately controlled.

Identify non-obvious data-bearing equipment

Storage is not limited to laptops and servers. Printers, multifunction devices, network appliances, phones, tablets, removable drives, USB media, CCTV equipment and specialist office systems may contain persistent storage.

The ICO notes that personal data can be stored on many devices with permanent memory, including printers and removable media. Faulty equipment should not be assumed safe simply because it no longer powers on.

Resolve retention before disposal

An office closure does not override retention obligations. Determine whether business records, legal holds, backups or other information must be retained before sanitisation or destruction begins.

Where data must be preserved, migrate or archive it through the authorised process before irreversible action.

Map technical dependencies

Before removing infrastructure, identify dependencies on servers, storage, internet circuits, telephony, access control, CCTV, printers, wireless, VPNs and network equipment. Confirm replacement services are working where the business is relocating or consolidating.

NCSC advises coordinating decommissioning and ensuring replacement assets are operating as expected before irreversible actions.

Define disposition before collection

Assign an intended route to each asset group: transfer to the new office, internal redeployment, return to lessor/vendor, secure sanitisation and resale, recycling or destruction.

This prevents valuable or required equipment being accidentally destroyed and prevents data-bearing equipment being released for resale before sanitisation.

Create a secure staging area

Designate a controlled room or caged area for IT assets awaiting collection. Restrict access, keep processed and unprocessed assets separated, and maintain an inventory of what enters and leaves.

ICO audit guidance recommends secure storage for hardware awaiting destruction, limited access and logs of devices awaiting destruction and their location.

Control access to the staging area

Limit access to named personnel and approved contractors. For higher-risk projects, maintain an access log and use physical controls appropriate to the site.

This is particularly important during dilapidation and clearance works, when many unfamiliar contractors may legitimately have access to the wider building.

Use asset labels carefully

Preserve serial numbers and asset tags long enough to support reconciliation. If ownership markings must be removed before resale, do so only after the identifier has been captured and the asset remains traceable through the processing record.

Do not remove labels simply to make equipment look ready for resale while it is still awaiting sanitisation or reconciliation.

Record the release event

At handover, record the project or consignment reference, releasing party, receiving party, date/time, site, asset/container references and any exceptions. Both sides should be able to identify what responsibility changed hands.

Where assets are containerised, record the relationship between serialised assets and the container or seal reference where required.

Use manifests that can be reconciled

The collection manifest should connect to the source inventory. For serialised equipment, individual serial numbers provide the strongest traceability. Lower-risk peripherals may sometimes be managed by quantity if that has been agreed in advance.

Do not rely solely on statements such as '12 pallets of IT equipment' where the project requires asset-level accountability.

Control loading

Loading is a custody transition point. Keep IT equipment within the controlled stream, prevent unauthorised additions or removals and record material discrepancies before the vehicle departs.

If the project uses numbered containers, cages or seals, record those references on the handover documentation.

Transport should preserve accountability

Transport controls should be proportionate to the value and sensitivity of the assets. The customer should be able to connect the collection event to receipt at the processing location.

Avoid unnecessary stops, uncontrolled storage or undocumented transfer between vehicles where the project's security requirements prohibit them.

Confirm receipt at the processing site

The ITAD provider should confirm receipt against the consignment and identify discrepancies. A broken seal, missing container, unexpected asset or damaged package should become an exception rather than being ignored.

The receipt record closes the transport leg of the custody trail and begins the processing leg.

Keep unprocessed assets controlled

Equipment that has arrived at a processing facility but has not yet been sanitised still contains potentially recoverable information. Secure storage and controlled access should continue until the required data treatment has been completed.

Sanitisation must remain linked to the asset

For data-bearing assets, processing records should remain linked to serial numbers or another approved identifier. Record the sanitisation method, relevant standard or technique, processing result and exception status as required by the project.

A generic certificate covering an entire office closure is weaker than evidence that can be reconciled to the actual assets transferred.

Handle failed media as exceptions

A drive that fails to initialise or a device that will not boot can still contain recoverable information. The ICO explicitly warns that faulty devices may still contain accessible data.

Quarantine failed media and route it through the approved exception process, which may require another sanitisation technique or physical destruction.

Physical destruction

Where destruction is required, preserve custody until destruction is complete. Link destruction records to the relevant media or asset population and retain the evidence required by the customer.

The ICO recommends keeping destruction logs and obtaining certificates when third parties securely destroy hardware.

Reuse and resale

Assets intended for resale should not be released merely because they have been removed from the old office. Complete the required sanitisation, validation and reconciliation first.

Only after the security gate has been passed should grading, resale value and commercial recovery determine the next stage.

Return-to-lessor and vendor-return equipment

Leased equipment can create competing deadlines: the lessor expects timely return while the organisation still needs to protect its information. Confirm contractual responsibilities for sanitisation and evidence before release.

Maintain custody records through the authorised handover rather than assuming ownership by a leasing company eliminates data-protection risk.

Network devices during office closure

Switches, routers, firewalls and VPN appliances may retain configuration, credentials, certificates and other sensitive information. NCSC recommends revoking certificates associated with network devices before disposal, changing or revoking other credentials as appropriate and applying suitable sanitisation controls.

Technical decommissioning should therefore be coordinated with physical asset removal.

Printers and multifunction devices

Office closures frequently include printers and multifunction devices that may contain internal storage. Do not automatically route them with ordinary office equipment.

Confirm the device's storage characteristics and the authorised sanitisation or return process before it leaves controlled custody.

Remote workers and equipment not at the closing office

The closure inventory may include laptops, monitors, phones and peripherals held by remote workers. Create a separate return workflow with tracked shipping or controlled collection where appropriate.

Reconcile remote assets to the same project register so that the office appears closed only when both onsite and offsite asset exceptions are resolved.

Staff departures

Leavers can create a high volume of device returns during restructuring or closure. Coordinate identity/access revocation with physical asset return and inventory reconciliation.

Do not allow returned laptops to accumulate at reception or open desks without being logged into the controlled staging process.

Third-party and personally owned equipment

Identify equipment that belongs to employees, landlords, managed-service providers, telecoms suppliers, leasing companies or other third parties. Ownership should be established before removal.

Do not sanitise or destroy an asset merely because it was physically located in the closing office.

Exception management

Maintain an exception register covering missing serials, duplicate assets, unreadable labels, failed media, unexpected devices, ownership disputes, broken seals, unplanned collections and processing failures.

Each exception should have an owner, status, resolution and approval where required.

Reconcile source, collection and processing records

At project close, compare the original authorised inventory with what was collected and what was ultimately processed. Investigate differences rather than forcing the numbers to match.

The objective is to account for every in-scope data-bearing or serial-controlled asset.

Evidence pack for an office closure

A practical evidence pack can include approved scope, source inventory, room/floor survey, collection manifest, chain-of-custody records, transport/receipt confirmation, sanitisation results, destruction records, exception register, asset recovery statement, final disposition report and project closure summary.

ICO guidance recommends evidence of management approval, secure disposal records, destruction logs and third-party certificates where appropriate.

Keep the evidence itself secure

Asset reports can expose serial numbers, hostnames, equipment models, office locations and infrastructure information. Apply access controls and retention rules to the evidence pack.

Do not put passwords, encryption keys or unnecessary personal data into disposal documentation.

Office closure chain-of-custody checklist

Before removal: approve scope, validate inventory, survey all areas, identify data-bearing equipment, resolve retention, map dependencies, define disposition and create secure staging.

At handover: reconcile assets, record releasing/receiving parties, document containers/seals where used, record discrepancies and preserve controlled loading.

After collection: confirm receipt, secure unprocessed equipment, sanitise or destroy as authorised, quarantine failures, reconcile serials, document reuse/recycling, close exceptions and issue the final evidence pack.

Common office-closure mistakes

Common mistakes include allowing general clearance teams to remove IT assets; leaving equipment in corridors or loading bays; failing to inventory printers and network devices; removing serial labels too early; treating faulty drives as empty; sending leased equipment back without confirming sanitisation; issuing one generic destruction certificate without reconciliation; and declaring the site cleared while remote-worker assets remain outstanding.

How Compritech supports office closures

Compritech combines onsite engineering with IT asset disposition. Depending on project scope, this can include discovery, infrastructure decommissioning, serial-level asset capture, secure staging, collection, chain of custody, sanitisation, physical destruction, asset recovery, recycling and final reconciliation.

This engineer-led model is particularly useful where the office closure includes live network, server or storage infrastructure that must be safely retired before equipment can enter the ITAD workflow.

Final takeaway

During an office closure, chain of custody is the control that connects a device in the old workplace to an authorised final outcome. It should survive the disruption of staff departures, contractors, transport and tight exit deadlines.

Inventory first, stage securely, document every custody transfer, keep processing linked to asset identity, expose exceptions and reconcile everything before closure. The office may be empty before the project is finished; the ITAD project is finished only when the assets and evidence are accounted for.

Related Compritech guides

Primary guidance

Planning an office closure or relocation?

Compritech provides engineer-led office and infrastructure decommissioning, ITAD, secure data sanitisation and destruction, chain of custody, asset recovery and serial-level reconciliation across the UK.

Discuss your projectOnsite data destruction