The email that arrives eight months later
A bank decommissions a floor. Four hundred and something laptops, a rack of servers, monitors, docking stations. A vendor picks them up on a Tuesday, the yard weighs the truck in as mixed e-scrap, and everyone moves on.
Eight months later the bank's internal audit team sends one line: "Please confirm the disposition of asset tag BK-LT-08814."
If the answer is "it was in that 6.4 tonne load", the vendor has just failed. Not because the metal went anywhere wrong, but because nobody can say what happened to one specific machine that may or may not have had a customer database on it. That is the whole of ITAD chain of custody in a single exchange, and it is why the enterprise end of e-waste behaves nothing like the rest of the yard.
Why the client is buying data security, not recycling
When a scrap buyer looks at a pallet of laptops, they see aluminium, copper, gold-bearing boards and a plastics problem. When the client's risk committee looks at the same pallet, they see a hundred storage devices that were inside their perimeter last week and are now in a truck belonging to somebody they have never met.
The asymmetry matters. The recycling value of that pallet might be modest. The cost of one drive surfacing on a resale market with readable customer records is a regulatory event, a disclosure obligation, and a headline. India's data protection regime, GDPR in the UK and EU, and sector rules in banking, health and defence all put the obligation on the data controller, which is the client, not the recycler. They cannot outsource the liability. So they outsource the work and audit it instead.
Meanwhile the material side has its own paperwork. In India, e-waste sits under the Extended Producer Responsibility framework, where producers must account for collection and channelisation to authorised recyclers, and where the recycling certificate is the instrument that discharges the obligation. A recycler who is casual about identity and traceability creates problems on both sides at once: a security gap for the client and a weak audit trail for the EPR filing.
Treat this as the working rule: for enterprise IT, the recycling is the easy half of the job.
What an audit actually asks for
Strip away the questionnaire formatting and almost every ITAD audit reduces to five questions.
What arrived. Not "4.2 tonnes of e-scrap". A count and an identity. How many units, of what type, and which ones. The client already has an asset register; they want yours to agree with it.
When. Timestamps at each transfer, not dates. "Collected 14 March" is weaker than "sealed 09:42, departed 10:05, arrived 14:38, unloaded and counted 15:20". Gaps in time are where auditors look for gaps in control.
From where. Which site, which floor, which contact handed it over, under which work order or purchase order.
What happened to it. Per unit where it matters: wiped and resold, physically destroyed, harvested for parts, or sent downstream to a smelter or authorised processor. If it left your facility again, who took it and under what document.
Who handled it. Named people, not roles. The driver, the receiving operator, the technician who ran the sanitisation, the supervisor who signed off destruction. An auditor testing your controls will pick three units at random and ask you to name every person who touched them.
The uncomfortable part is that these are not five separate records. They are one record with five views, and most yards store them in five different places: the gate register, the weighbridge printout, a WhatsApp photo, a technician's spreadsheet, and a certificate template in Word. The audit fails at the joins.
Serial level or weight level, and when to switch
The common mistake is arguing about which one is correct. Both are correct, for different parts of the same job. The real skill is knowing where the handover point sits.
Serial level applies while an item can still hold data or still has identity value to the client. Weight level applies once the item has been irreversibly reduced to material.
| Stage | Track by | Because |
|---|---|---|
| Collection at client site | Serial / asset tag | Must reconcile against the client's own register |
| Transport | Sealed container ID plus unit count | Custody is over a sealed set, not loose pieces |
| Receipt at facility | Serial, unit by unit | This is where discrepancies must surface |
| Data sanitisation or destruction | Serial, method, operator | The evidence the certificate rests on |
| Post-destruction fractions | Weight by category and grade | Identity is gone; only mass and material remain |
| Onward sale to smelter | Weight, with lot linkage back | Material accounting and EPR reporting |
One practical note: not every unit deserves the same depth. A reasonable policy tiers it. Anything with non-volatile storage gets a serial and a sanitisation record. Monitors, keyboards, cabling and docks can be counted and weighed by category. Write the tiering down and apply it consistently, because an auditor will accept a documented policy far more readily than case-by-case judgement.
The reconciliation nobody wants to do
Consider a yard that collects a declared 412 units from a client site. The receiving count at the facility comes to 409.
Three missing units is the entire audit. It does not matter that the weight was within tolerance. Somebody has to close those three: suppose two were scanned at the client site but pulled back by IT before the truck sealed, and one was double-counted because its asset label had peeled and been re-tagged. Both explanations are ordinary. Both are fine. What is not fine is discovering the gap eight months later when the client asks.
So build the reconciliation into receipt, not into reporting. Declared count against received count, at the point of unload, with an exception raised and resolved while the driver is still standing there. Discrepancies found in an hour are administration. The same discrepancies found in a quarter are an incident.
Certificates of destruction are an output, not a document
Most certificates of destruction in circulation are typed. Somebody opens a template, fills in a client name, a date and a tonnage, applies a signature image and emails a PDF. It looks official and proves nothing, which experienced auditors know.
A certificate is only worth what sits behind it. The defensible version is generated from records that already existed: the collection manifest, the transport leg, the receipt reconciliation, the per-unit sanitisation or destruction log with method and operator, and the onward disposition of the resulting material. The certificate becomes a rendering of that chain, with the serial list attached as an appendix, not a claim made about it afterwards.
The test is simple. Take any certificate you have issued and try to reconstruct it from your underlying data without the certificate itself. If you cannot, you did not certify anything. You typed.
The same logic applies to the method statement. Recognised media sanitisation guidance, such as the NIST guidelines widely referenced in this field, distinguishes clearing, purging and destruction, and expects the outcome to be verified. Recording "wiped" is not a method. Recording the method, the tool, the verification result and the operator is.
The three gaps that fail audits
The transport leg. Custody is usually strong at the client site and strong inside the facility, and vague in between. GPS breadcrumbs, a sealed container ID, and a proof of delivery captured by the driver rather than typed by the office close it.
Subcontractors. The moment a downstream processor is involved, the client's audit follows the material into them. If your subcontractor cannot produce the same five answers, their weakness becomes your finding.
Photographs with no anchor. A photo of a destroyed drive is worthless unless it is tied to a serial, a timestamp and an operator. A photo attached to a specific ticket at the moment of capture is evidence. A photo in a phone gallery is not.
Why this is commercial, not just compliance
Here is the part operators underrate. Enterprise procurement teams do not choose ITAD vendors on price per kilo. They choose on the ability to survive an audit, because the person signing the contract is personally exposed if the vendor cannot.
That produces an unusual market. A vendor who can hand over a complete, queryable custody record in a day competes against vendors who take three weeks and produce a spreadsheet. The first one wins multi-year contracts at better rates, gets invited to renewals without a fresh tender, and gets referred sideways to other divisions. Traceability is not overhead in this segment. It is the product.
The corollary is that the discipline scales upward. A yard that runs serialised custody for enterprise IT tends to end up with cleaner records everywhere, because the habit of capturing at the point of work rather than reconstructing later is contagious.
Where a system carries the weight
None of this needs specialist ITAD software to begin with. It needs the ordinary yard record to be granular enough, and joined up enough, to answer the five questions.
In Scraplytics that means the intake ticket carries the client, the site, the operator and photos captured at the scale rather than added later; inventory is held by category and grade so post-destruction fractions stay accounted for by weight; dispatch and the driver app cover the transport leg with GPS and proof of delivery; documents attach to the record they belong to instead of a shared drive; the supplier portal lets a corporate client see their own history without emailing for it; and the API lets their asset management system reconcile against yours directly. Multi-location keeps the chain intact when collection, processing and destruction happen at different sites.
The software is not what convinces an auditor. The record is. The software just makes it expensive to have a bad one.
If you cannot answer the asset-tag question in an afternoon, you do not have a chain of custody. You have a filing habit.
Frequently asked questions
What is chain of custody in ITAD and why do enterprise clients care?
Chain of custody is the documented, unbroken record of who held an IT asset at every point from pickup to final destruction or resale. Enterprise clients care because they remain the data controller even after handing hardware over. If a drive resurfaces with readable data, the originating company carries the disclosure and reputational exposure. Auditors test the record for gaps in time, custody transfer signatures, and matching counts between pickup and processing.
Do I need serial number tracking or is weight tracking enough?
Serial number tracking is required for any asset that could have stored data, while weight tracking is appropriate for downstream commodity streams. Weight alone cannot prove a specific drive was destroyed, because it only proves an aggregate mass moved. Most enterprise contracts expect serialised records for drives, laptops, servers and network gear, then weight-based reporting once material is shredded into mixed commodity fractions.
What does a certificate of destruction actually need to contain?
A defensible certificate of destruction identifies each asset by serial number, states the destruction method used, gives the date and physical location of destruction, and names the responsible operator or witness. It should reference the originating pickup or work order so it can be traced back. Generic certificates that list only a total weight or unit count are commonly rejected during audits because they cannot be tied to specific assets.
What do enterprise auditors usually check first during an ITAD audit?
Auditors typically start by picking a handful of serial numbers from the client's own asset register and asking the vendor to produce the full trail for each one. They look for the pickup receipt, transport record, receiving scan, disposition decision, and the destruction or resale evidence. Unexplained gaps, back-dated entries, or counts that change between stages are the most common findings.
How long should ITAD chain of custody records be retained?
Retention periods are set by the client contract and by whichever data protection and environmental rules apply in the operating jurisdiction, so there is no single universal figure. In practice many enterprise ITAD contracts require records to be held for several years and to be retrievable on request during that window. Confirm the required period contractually before disposal begins, and store records so they survive vendor system changes.
Sources and further reading
- NIST Special Publication 800-88, Guidelines for Media Sanitization - National Institute of Standards and Technology
- R2 Responsible Recycling Standard - SERI (Sustainable Electronics Recycling International)
- e-Stewards Standard for Responsible Recycling and Reuse of Electronic Equipment - Basel Action Network
- E-Waste (Management) Rules - Ministry of Environment, Forest and Climate Change (India)
This article is general operational guidance, not legal or compliance advice. Always confirm current obligations against the source rules and your own advisers.
