Home / Insights

What Evidence Should an ITAD Provider Supply?

UK guide to ITAD evidence businesses should expect: asset records, chain of custody, sanitisation results, destruction certificates and exception reporting.

Why ITAD evidence matters

A secure IT asset disposition project should produce more than an invoice and a certificate stating that equipment was processed. Organisations need enough evidence to demonstrate what assets left their control, who handled them, what happened to data-bearing media, how exceptions were resolved and where equipment ultimately went.

The appropriate evidence depends on the project, information sensitivity, contractual requirements and organisational policy. The objective is traceability: an authorised reviewer should be able to select an in-scope asset and understand its journey from operational service to final disposition.

Evidence should begin before collection

The audit trail should start with the authorised project scope and source inventory. Waiting until equipment reaches the ITAD facility creates an avoidable gap between operational ownership and supplier processing.

Before collection, establish the expected asset population, relevant locations, owners, intended disposition and any special handling requirements. Record unresolved inventory discrepancies as exceptions rather than adjusting records simply to make totals match.

1. Approved scope and project instructions

Retain the approved scope defining which sites, rooms, racks, asset categories or consignments are included. It should also identify the expected service: collection, decommissioning, sanitisation, destruction, reuse, asset recovery, recycling or a combination.

Where different asset groups require different sanitisation or disposition outcomes, those instructions should be explicit.

2. Source asset inventory

The source inventory provides the baseline for reconciliation. Useful fields can include manufacturer, model, serial number, asset tag, hostname where appropriate, location, media type, operational owner and intended disposition.

Not every field is required for every project. Collect enough information to support accountability without unnecessarily placing sensitive operational information into disposal records.

3. Collection manifest

A collection manifest records what physically transferred into the ITAD process. It should be reconcilable against the source inventory and identify the collection or consignment.

For bulk projects, the manifest can distinguish individual serialised assets from containers or lower-value peripherals handled by quantity where that approach has been approved.

4. Chain-of-custody records

Chain-of-custody evidence records responsibility as equipment moves between people, locations and processing stages. Relevant information can include releasing and receiving parties, date/time, location, consignment identifiers and asset or container references.

NCSC's decommissioning guidance recognises that sensitive or valuable assets may require detailed chain-of-custody tracking when transferred between people or teams.

5. Secure transport and handover evidence

Where transport is part of the service, retain sufficient evidence to connect the customer handover to receipt at the processing location. Depending on risk, this may include collection references, driver or receiving details, vehicle or consignment information, seal references and receipt confirmation.

The purpose is continuity of accountability rather than collecting transport data for its own sake.

6. Sanitisation processing records

For data-bearing media, evidence should identify the asset or media and the sanitisation outcome. Useful fields can include serial number, media identifier, sanitisation method, approved technique or standard reference, processing result, completion status, processing reference and date/time.

A statement that equipment was 'NIST wiped' is less useful than a record showing what was processed, which outcome was required and whether the operation completed successfully.

7. Verification and validation evidence

NIST SP 800-88 Rev. 2 gives sanitisation verification and validation important roles. Verification determines the outcome of the sanitisation technique, while validation considers whether the result is acceptable.

An ITAD provider's reporting should therefore distinguish successful processing from failed or uncertain processing. A job that started but returned errors should not appear as a successful sanitisation result.

8. Failed-media and exception records

Failed drives, unreadable serial numbers, missing assets, unexpected storage devices and incomplete sanitisation results should create visible exceptions. The exception record should identify the issue, status and final resolution.

A mature evidence pack does not hide failures. It demonstrates that exceptions were controlled and resolved through the customer's approved process.

9. Destruction records

Where media is physically destroyed, the evidence should connect the destruction event to the relevant media or asset population. Depending on requirements, this can include serial-linked destruction records, batch references, processing date and destruction method.

If particle-size or another destruction specification is contractually required, the evidence should address that requirement rather than relying solely on a generic destruction statement.

10. Certificate of destruction

A certificate of destruction can provide formal confirmation that an agreed destruction service was completed. Its value depends on what it certifies and whether it can be reconciled to the underlying asset or media records.

A certificate should not be treated as a substitute for inventory and reconciliation. A beautifully formatted certificate cannot prove that a particular drive was destroyed if the provider cannot connect that drive to the processing record.

11. Certificate or record of sanitisation

Where media is sanitised for reuse, customers may require a sanitisation certificate or equivalent processing report. It should identify the relevant media and provide enough information to understand the sanitisation outcome.

The terminology should match what was actually performed. Avoid ambiguous claims such as 'military-grade wipe' or '100% unrecoverable' where the provider cannot define the applicable technical standard and assurance basis.

12. Serial-level reconciliation report

Reconciliation compares the authorised source inventory with collected and processed assets. It should identify matched assets and clearly expose missing, duplicate, unexpected or substituted records.

For high-assurance projects, the ability to reconcile individual serial numbers from source to final outcome is one of the most useful forms of ITAD evidence.

13. Final disposition report

The customer should be able to understand what happened after sanitisation. Final disposition categories may include internal return, external reuse, resale, component recovery, recycling or destruction.

This report helps separate data-security outcomes from commercial and environmental outcomes. Sanitisation and recycling are not the same control.

14. Asset recovery and resale statement

Where equipment has residual value, the provider should supply a transparent record of the assets accepted for resale or recovery and the commercial treatment agreed with the customer.

Depending on the commercial model, evidence can include grading, sale value, revenue share, project credit or other agreed recovery information. The customer should be able to reconcile commercially recovered assets to the project inventory.

15. Recycling and downstream evidence

Equipment unsuitable for reuse should enter an appropriate downstream recycling route. Evidence requirements depend on the project and applicable environmental responsibilities, but the customer should have sufficient information to understand the final route.

A recycling certificate alone does not demonstrate that data-bearing media was securely sanitised or destroyed; those controls require their own evidence.

16. Subcontractor and downstream visibility

Customers should understand which material activities are performed by the contracted ITAD provider and which are passed to logistics companies, specialist destruction facilities, remarketing partners or downstream recyclers.

Where subcontracting is permitted, evidence and contractual controls should preserve accountability through the downstream process.

17. Photographic or witnessed evidence

Some projects request photographs, video or customer witnessing of destruction. These can supplement the evidence pack where appropriate but should not replace serial-level processing and reconciliation.

Photographs can also introduce information-security or privacy concerns, so their use should be agreed and controlled rather than treated as automatically beneficial.

18. Change and decommissioning records

Infrastructure projects may require technical evidence before ITAD begins. Change references, shutdown approvals, dependency checks, migration confirmation and decommissioning records can establish that equipment was legitimately withdrawn from service.

This is particularly useful for servers, storage arrays, switches, routers and firewalls where disposal is only one stage of a wider technical change.

19. Credential and certificate revocation evidence

Network and security appliances can retain credentials, certificates and configuration. NCSC guidance recommends revoking certificates associated with network devices before disposal and changing or revoking other credentials as appropriate.

For higher-assurance projects, the project closure record can confirm that relevant credential and certificate actions were completed, even where the detailed security information remains in the customer's internal change record rather than the supplier's report.

20. Project exception register

Maintain one consolidated register for discrepancies and non-standard outcomes. Examples include missing serials, damaged labels, inaccessible drives, failed sanitisation, unexpected equipment, broken seals or changes to the authorised disposition.

Each exception should have an owner, status, resolution and approval where required.

21. Project completion or closure report

A final closure report brings the evidence together. It can summarise scope, assets received, sanitised media, destroyed media, reused/resold assets, recycled assets, exceptions and outstanding actions.

The closure report should reconcile to the underlying detailed records rather than introducing a new set of unexplained totals.

What NCSC says about external decommissioning evidence

NCSC's decommissioning guidance advises organisations to confirm and retain evidence that sensitive decommissioning tasks have been completed when an external party performs them. It notes that evidence will typically be in the form of a certificate.

That certificate is strongest when supported by the inventory, custody, processing and reconciliation records described throughout this guide.

What NIST Rev. 2 adds to the evidence discussion

NIST SP 800-88 Rev. 2 places greater emphasis on verification and validation of media sanitisation. This strengthens the case for reporting actual processing outcomes rather than simply stating that a sanitisation policy exists.

The provider's evidence should allow successful sanitisation to be distinguished from rejected, failed or escalated results.

Evidence for Clear, Purge and Destroy

If the customer's sanitisation policy uses NIST terminology, the evidence should record the applicable method and the approved technique or standard used to achieve it.

Do not label every logical sanitisation process 'Purge' or every physical action 'Destroy' without confirming that the process meets the applicable sanitisation requirements.

How much evidence is enough?

Evidence should be proportionate. A small collection of low-risk peripherals does not necessarily require the same reporting package as a data-centre exit containing thousands of serialised, data-bearing assets.

The organisation should define evidence requirements before procurement or project commencement so that the provider can design the workflow around them.

Avoid evidence that creates unnecessary risk

Reports can themselves become sensitive because they may reveal hostnames, infrastructure models, serial numbers, locations, network roles or security information. Apply access controls and data minimisation to ITAD records.

Do not include passwords, encryption keys, patient/customer data or detailed security configuration simply to make the disposal report appear comprehensive.

Evidence retention

Agree how long the provider and customer will retain manifests, sanitisation records, certificates, exception reports and commercial records. Retention should support audit, contractual and legal requirements without preserving unnecessary sensitive information indefinitely.

The agreement should also address secure deletion of provider-held records when their retention period ends.

What should appear on a certificate of destruction?

Depending on the engagement, useful certificate fields can include customer/project reference, provider identity, processing date, service performed, relevant asset or media references, applicable destruction specification where agreed and authorised sign-off.

Where the asset list is too large for the certificate itself, the certificate can reference a controlled serial-level schedule or processing report.

What should appear on a sanitisation report?

Useful fields can include media serial number, parent asset identifier, media type, sanitisation method, approved technique/standard, tool or process reference, result, verification/validation status, date and exception outcome.

Exact fields should be agreed to meet the customer's assurance needs rather than copied from a generic template.

Red flags when reviewing ITAD evidence

Warning signs include certificates with no asset references; reports where every asset is marked successful despite known failed drives; unexplained differences between collected and processed totals; generic 'NIST compliant' claims with no method; missing exception records; no visibility of downstream processing; and commercial recovery statements that cannot be reconciled to the inventory.

A practical evidence pack

A strong project pack can contain the approved scope, source inventory, collection manifest, custody records, sanitisation report, destruction schedule/certificate, exception register, reconciliation report, asset recovery statement, downstream disposition evidence and final closure summary.

Not every project needs every document, but the pack should collectively answer four questions: what was transferred, who controlled it, what happened to its data, and what was its final disposition?

Questions to ask an ITAD provider before appointment

Ask for a sample report before awarding the work. Confirm whether reporting is serial-level, how sanitisation failures appear, how chain of custody is recorded, what destruction evidence is produced, whether subcontractors are visible, how discrepancies are resolved, what resale reporting is supplied and how long records are retained.

A provider's sample evidence often reveals more about operational maturity than marketing statements about secure disposal.

How Compritech structures ITAD evidence

Compritech's engineer-led approach is designed around traceability from technical decommissioning through asset disposition. Depending on project scope, evidence can connect source inventories, serial-level asset records, chain of custody, sanitisation or destruction outcomes, exception handling, asset recovery and final disposition.

For infrastructure projects, this can be integrated with server/storage retirement, Cisco and Juniper decommissioning, onsite engineering and controlled project closure.

Final takeaway

The most useful ITAD evidence is not the document with the most logos or pages. It is evidence that allows the organisation to prove what happened to the assets and data entrusted to the process.

Define evidence requirements before collection, preserve chain of custody, record sanitisation outcomes and failures honestly, reconcile serial numbers, document final disposition and close exceptions. A certificate should complete that evidence trail—not replace it.

Related Compritech guides

Primary guidance

Need an auditable ITAD evidence pack?

Compritech provides engineer-led ITAD, infrastructure decommissioning, secure sanitisation and destruction, chain of custody, serial-level reconciliation and evidence-led project closure across the UK.

Discuss your projectSecure data destruction and evidenceOnsite data destruction