Why financial-services ITAD needs more than equipment collection
Banks, insurers, investment firms, fintechs, accountancy organisations and other financial-services businesses can hold high-value personal, commercial and security-sensitive information across laptops, servers, storage arrays, backup media and network appliances. Retiring those assets is therefore a security and operational process as well as a logistics task.
The objective is not simply to remove old hardware. A controlled ITAD programme should establish what each asset is, whether production still depends on it, what data or credentials it may contain, the sanitisation or destruction outcome required, who has custody of it, and what evidence will demonstrate final disposition.
Do not assume physical destruction is always legally required
There is no single rule saying every storage device used by a UK financial-services firm must be physically destroyed. The appropriate treatment depends on the information, media, organisational policy, assurance requirement, intended reuse and applicable regulatory or contractual obligations.
NIST SP 800-88 Rev. 2 frames sanitisation around the sensitivity of information and an organisation-wide media sanitisation programme. NCSC guidance likewise distinguishes sanitisation that enables reuse from destructive approaches. A risk-based policy should decide when secure reuse is acceptable and when destruction is required.
Map the regulatory and governance context before disposal
Financial-services firms may operate under FCA requirements and expectations concerning operational resilience, systems and controls, outsourcing and third-party risk. The exact obligations depend on the firm's permissions, activities and arrangements, so an ITAD supplier should not present itself as the organisation's regulator or legal adviser.
FCA guidance states that firms remain responsible and accountable for regulatory responsibilities applicable to outsourcing and third-party service arrangements. That makes supplier oversight, data security and evidence important considerations when disposal activities are entrusted to a third party.
Operational resilience begins before the asset leaves service
FCA operational-resilience material emphasises understanding and mapping the people, processes, technology, facilities, information and third-party dependencies needed to deliver important business services. In an ITAD context, this supports a disciplined approach to identifying dependencies before infrastructure is withdrawn.
A server, firewall, switch or storage array should not become an 'ITAD asset' until its operational role has been safely migrated or retired. Decommissioning engineering and asset disposition should therefore be coordinated rather than treated as unrelated workstreams.
Build an authoritative asset inventory
Create or validate a serial-level inventory before collection. Useful fields can include manufacturer, model, serial number, asset tag, hostname, rack/location, storage-media type, ownership, data classification, disposition route and exception status.
Compare physical discovery with the CMDB, asset register and project scope. Missing and unexpected equipment should be resolved before custody transfers wherever practical.
Laptops, desktops and end-user devices
End-user equipment can contain customer information, employee records, downloaded reports, cached data, browser sessions, local databases, credentials and encryption material. Determine whether the device will be redeployed, resold, returned, recycled or destroyed before selecting the sanitisation process.
Where devices are encrypted, understand the encryption and key-management design rather than assuming that the presence of encryption alone proves sanitisation.
Servers and virtualisation infrastructure
Physical servers can contain local boot disks, RAID sets, flash modules, cache devices and out-of-band management configuration even where primary application data lived on shared storage. Virtualisation hosts also participate in clusters, management systems, shared datastores and backup platforms.
Migrate workloads and validate replacement capacity before hardware removal. Then identify every data-bearing component that requires sanitisation, quarantine or destruction.
SAN, NAS and enterprise storage
Storage systems require particular care because snapshots, replicas, caches, spare drives and failed members can retain data outside the obvious active volume. Map hosts, LUNs, file shares, replication, snapshots, zoning, multipathing and backup relationships before retirement.
Do not release failed drives merely because the array reports them as unusable. A failed device can still contain recoverable information and should remain within the approved media-handling process.
Network and security appliances also contain sensitive information
NCSC notes that routers, switches and many other electronic devices contain electronic storage media. Network devices may also retain configuration, topology, credentials, certificates and security policy.
NCSC's network-device disposal guidance recommends revoking certificates associated with a device before disposal, changing or revoking other credentials as appropriate, following secure media-sanitisation guidance for relevant devices, and using factory reset or device wiping as a general precaution.
Backups, tapes and removable media
Backup media can be among the highest-risk assets because it may contain historical copies of systems long after production data has changed. Identify tapes, removable drives, USB media, SD cards, optical media and appliance-specific removable storage.
Retention obligations should be resolved before destruction. Media that must be retained should remain under controlled custody; media approved for disposal should follow the organisation's sanitisation or destruction standard.
Data classification drives the sanitisation outcome
Classify the information and understand the harm that could result from unauthorised recovery. Consider personal data, payment-related information, commercially sensitive records, authentication material, security configuration and intellectual property.
The chosen process should reduce the likelihood of recovery to the assurance level required by the organisation. High-value data does not automatically imply one universal physical-destruction method; the decision should follow documented policy and risk.
NIST SP 800-88 Rev. 2
NIST published SP 800-88 Rev. 2 in September 2025, superseding Rev. 1. The revision shifts the emphasis toward establishing an enterprise media-sanitisation programme and selecting applicable controls based on information sensitivity.
NIST also strengthened the emphasis on sanitisation validation and vendor trust. Apart from cryptographic erase guidance, Rev. 2 points organisations toward current relevant standards such as IEEE 2883, NSA specifications or an organisationally approved standard rather than acting as a device-by-device wiping-command catalogue.
Clear, Purge and Destroy decisions
An ITAD policy should define the required sanitisation outcome for each media class and disposition route. Clear, Purge and Destroy are not marketing labels; they describe different sanitisation approaches and assurance outcomes in the NIST framework.
The organisation should document which outcome is acceptable for internal reuse, external reuse/resale and final disposal, together with validation and exception requirements.
Secure erasure can preserve asset value
Where policy permits external reuse, validated sanitisation can allow suitable laptops, servers and storage devices to retain residual value. This can improve financial recovery and reduce avoidable electronic waste.
The commercial benefit should never override the required security outcome. Assets should not enter resale channels until sanitisation has succeeded and the asset has been released from any quarantine or exception state.
Physical destruction
Physical destruction can be appropriate for failed media, unsupported devices, higher-risk information or policies that prohibit reuse. The destruction specification should match the organisation's threat model and approved standard.
NCSC's public storage-media guidance is designed around the protections proportionate for OFFICIAL data and notes that separate guidance applies to HMG SECRET or above. Its public guidance describes destruction to particles of 6 mm or less in specified higher-risk circumstances and recommends verifying the resulting particle size. That figure should not be presented as a universal requirement for every financial-services organisation.
HDD, SSD and NVMe need technology-aware processes
Magnetic disks and flash storage have different characteristics. SSDs and NVMe devices use controller-managed flash, wear levelling and over-provisioning, while HDDs rely on magnetic storage.
A generic overwrite or degaussing claim should not be applied indiscriminately. Use an approved standard, supported device capabilities and validation appropriate to the media.
Cryptographic erase and key management
Cryptographic erase can be appropriate for correctly implemented encrypted media where the relevant cryptographic keys can be sanitised with sufficient assurance. NIST Rev. 2 expands its cryptographic-erase guidance and discusses key sanitisation and externally managed keys.
Document where keys reside, whether copies exist elsewhere and how the sanitisation operation is validated. Deleting one local key is not enough if another usable key can still decrypt the target data.
Failed media and sanitisation exceptions
Define what happens when a drive cannot be detected, a sanitisation command fails, a serial number is unreadable or a device contains unexpected storage. Failed processing should create an exception, not an assumed pass.
Quarantine affected assets, preserve custody and route them to an approved alternative process such as physical destruction where policy requires it.
Chain of custody
Chain of custody should start when an asset leaves operational control. Record asset identifiers, releasing and receiving parties, time/date, location and subsequent transfers. Containers or consignment references can provide additional traceability for larger collections.
NCSC's decommissioning guidance recognises that sensitive or valuable assets may need detailed chain-of-custody tracking when transferred between people or teams.
Onsite processing and destruction
Some organisations choose onsite erasure or destruction to reduce the period during which unsanitised media is outside direct control. Onsite processing can also allow customer representatives to witness selected activities.
Onsite service does not remove the need for inventory, reconciliation, equipment controls, operator competence, validation and evidence. The security outcome matters more than the location alone.
Secure staging before collection
Equipment awaiting collection remains part of the risk boundary. Use access-controlled staging, separate processed from unprocessed assets and avoid leaving data-bearing equipment in corridors, loading bays or other uncontrolled areas.
NCSC advises that assets holding potentially sensitive data should not be stored in insecure environments while awaiting later decommissioning stages.
Secure transport
Transport should preserve accountability. Controls may include documented handover, appropriate packaging, vehicle/security arrangements matched to risk, consignment records and controlled transfer at the processing site.
The purpose is to maintain continuity of custody, not merely to show that a collection occurred.
Supplier due diligence
Assess whether the ITAD provider's controls match the sensitivity and scale of the engagement. Relevant evidence may include information-security certifications, data-sanitisation capability, insurance, staff controls, environmental permissions, downstream arrangements, incident procedures and sample reporting.
FCA material on outsourcing and third-party providers emphasises managing third-party risk and protecting data handled by providers. The depth of supplier assurance should be proportionate to the firm's own obligations and risk assessment.
Third-party responsibility cannot simply be outsourced away
Using a specialist supplier can provide expertise and operational capacity, but it does not automatically transfer the customer's governance responsibilities. Define responsibilities contractually, including custody, sanitisation standards, subcontracting, breach/incident escalation, evidence, retention and destruction of processing records.
Know which activities are performed directly and which are passed further downstream.
Certificates of sanitisation and destruction
Certificates should identify what was done and be traceable to the relevant assets or media. A generic statement that a consignment was 'securely destroyed' provides less assurance than evidence linked to serial numbers and the actual process.
NCSC's decommissioning guidance recommends retaining evidence when an external party performs sensitive decommissioning tasks and notes that certificates are a typical form of such evidence.
Audit-ready evidence pack
A financial-services ITAD evidence pack can include approved scope, change references, source inventory, collection manifest, chain-of-custody records, sanitisation results, destruction records, exception log, recovered-value statement and final disposition evidence.
The test is practical: can an authorised reviewer select one asset and determine where it came from, who handled it, what happened to its data and what its final disposition was?
Asset reconciliation
Reconcile the source inventory against collected and processed assets. Investigate missing serials, duplicate records, unexpected assets and components separated from parent equipment.
Do not close discrepancies simply to make totals match. Record the explanation and approval for legitimate exceptions.
Asset recovery and resale
Enterprise servers, network equipment, memory, processors, SSDs and optics may retain value. A transparent recovery process should grade assets consistently and link recovered value or resale outcome back to the relevant inventory.
Data security and contractual restrictions come first. No asset should be released for resale merely because it has commercial value.
Environmental disposition and recycling
Assets that cannot be reused should enter an appropriate downstream recycling route. Maintain sufficient evidence to explain where residual equipment went and how it was treated.
Environmental compliance depends on the organisation's role and the actual waste transaction, so avoid reducing WEEE responsibilities to a single generic statement. Applicable carrier, processor, producer or waste obligations should be established for the project.
Incident handling
Define the response if an asset is lost, custody is broken, a sanitisation result is uncertain or unexpected data is discovered. Escalation should be prompt enough for the customer to assess security, contractual, data-protection and regulatory implications.
Do not conceal operational exceptions inside routine completion reporting.
Records retention
Agree how long manifests, sanitisation records, certificates, exception evidence and commercial reports will be retained. Retention should support audit and contractual needs without keeping unnecessary sensitive information indefinitely.
Protect ITAD records themselves because asset inventories can reveal infrastructure details and security-relevant information.
Post-decommission system updates
After successful retirement, update the CMDB, asset register, monitoring, configuration management, IPAM/DNS, licensing and support records as appropriate. Revoke credentials and certificates that no longer have a legitimate purpose.
NCSC recommends updating asset inventories following decommissioning and continuing monitoring for unexpected impacts.
A practical financial-services ITAD workflow
A controlled workflow is: approve scope and governance; discover and reconcile assets; map technical dependencies; classify data and intended disposition; migrate services; validate replacements; withdraw equipment under change control; sanitise or quarantine media; reconcile serials; establish custody; securely stage and transport assets; process reuse, recovery, destruction or recycling; resolve exceptions; issue evidence; update authoritative records; and obtain formal closure.
Pre-collection checklist
Confirm business and technical owners; approved asset scope; serial inventory; data classification; retention decisions; dependency migration; change approval; sanitisation standard; failed-media process; chain-of-custody method; secure staging; transport controls; supplier/subcontractor responsibilities; evidence format; exception escalation and final acceptance criteria.
Questions to ask an ITAD supplier
Ask how assets are tracked from collection to disposition; which sanitisation standards are supported; how results are validated; how failed media is handled; whether processing is onsite or offsite; how subcontractors/downstream processors are controlled; what certificates and serial-level reports are supplied; how incidents are escalated; how recovered value is calculated; and how long records are retained.
Common mistakes
Common mistakes include assuming encryption alone resolves disposal risk; sending failed disks through normal resale channels; treating a collection receipt as a complete audit trail; destroying reusable equipment without a documented risk decision; failing to revoke network-device certificates; leaving equipment unsecured before collection; accepting non-serialised destruction evidence; overlooking backup media; failing to assess downstream providers; and closing projects with unresolved reconciliation exceptions.
How Compritech approaches financial-services ITAD
Compritech combines infrastructure engineering with IT asset disposition. The approach is designed to connect technical decommissioning, secure sanitisation or destruction, asset tracking, chain of custody, evidence and responsible final disposition.
For complex environments, this can include server/storage retirement, Cisco and Juniper network decommissioning, firewall retirement, onsite engineering, data sanitisation, physical destruction, serial-level reconciliation and asset recovery.
Final takeaway
For financial-services organisations, secure IT disposal is strongest when the audit trail begins before hardware leaves service. Technical dependencies, data sensitivity, media handling, third-party controls, custody, sanitisation validation and final disposition all need to form one controlled process.
The goal is not to claim that every device must be destroyed. It is to make a documented, risk-based decision for every asset and retain enough evidence to demonstrate that the approved outcome actually occurred.
Related Compritech guides
- IT Asset Disposition (ITAD) for Data Centres: A Complete UK Guide
- Secure Data Erasure vs Physical Destruction
- HDD, SSD and NVMe Destruction: Which Method Should You Use?
- How to Securely Decommission Servers and Storage Systems
- How to Decommission Firewalls Securely
- Why an Auditable Chain of Custody Matters in IT Disposal
Primary guidance used
- NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization
- NCSC — Decommissioning assets
- NCSC — Secure sanitisation and disposal of storage media
- NCSC — Acquiring, managing and disposing of network devices
- FCA — Outsourcing and operational resilience
- FCA — Operational resilience
Planning secure IT asset disposal for a financial-services environment?
Compritech provides engineer-led ITAD, infrastructure decommissioning, onsite support, secure data sanitisation and destruction, serial-level asset reconciliation and responsible final disposition across the UK.
Discuss your projectIT asset disposal servicesSecure data destruction servicesOnsite data destruction