Skip to content

Resources

Every provider claims chain of custody. Few can show you where theirs breaks.

The phrase appears on every ITAD website in the industry. What distinguishes providers is not whether they use it, but whether they can describe the specific points at which custody is most likely to fail — and what stops it failing there.

The premise

A chain with a gap is not a chain

Chain of custody means an unbroken, documented record of who held each asset, when, and what was done to it. Every word in that sentence is load-bearing, and the one that gets skipped is unbroken.

A record with a gap in it is not a chain of custody. It is two records with an unexplained space between them — and in an audit, that space is the only thing anyone will want to discuss.

Which means the interesting question about any provider is not whether they maintain custody. It is where they think custody is most likely to break, and what they do about it there.

Failure modes

Five places custody actually breaks

Note that four of the five happen before equipment reaches a processing facility. The floor is rarely the problem.

  1. 01

    The collection point

    Someone puts equipment on a pallet without a manifest, or with a manifest written from memory. Everything downstream inherits that error, and it is invisible until reconciliation.

  2. 02

    The storeroom

    Assets sit for months between decommission and collection. Units go missing in ways nobody notices because no record said they were there.

  3. 03

    The handoff between vendors

    Procurement, support and disposal sit with different providers. Each holds a partial record; nobody holds a continuous one.

  4. 04

    The subcontractor

    The company you contracted with is not the company processing the equipment. Custody transferred to a party you never assessed.

  5. 05

    The batch certificate

    A certificate covering a shipment rather than a device. It looks like evidence right up until an auditor asks about one specific serial number.

What an unbroken chain produces

Six artifacts, per asset

Custody is not a promise; it is a set of records. If a provider maintains it, these exist for every individual device — not for the shipment.

  1. 01 Chain-of-custody receiptIssued at intake, after the manifest is reconciled against what physically arrived.
  2. 02 Stage recordsOne per processing stage, each naming who verified it.
  3. 03 Sanitization certificatePer device — serial, method, operator, station, timestamp, result, validation hash.
  4. 04 Condition and grading recordWhat state the asset was in, and what that made it worth.
  5. 05 Disposition authorizationReuse, resale or certified recycling, recorded per asset.
  6. 06 Outbound manifestWith carrier confirmation, and downstream manifest where material is recycled.
Palletized inventory held under controlled conditions in the WesternTechSystems warehouse

How we handle it

Gates, not intentions

Our processing workflow is gated and sequential. No device advances to the next stage until the criteria for the current stage are verified and documented, and each gate produces the artifact above. Manual overrides are not permitted.

The gate that matters most is downstream of sanitization. A device without a passing wipe record is blocked in software at label creation and again at fulfilment — so it cannot ship, cannot enter finished goods, and cannot be invoiced. That is a mechanism rather than a policy, which is the distinction worth testing in any provider.

Assets under legal hold are segregated on arrival into restricted-access storage and cannot be wiped or transferred until a written release is received and logged from your authorized representative.

See the full process

FAQ

Questions auditors and security teams ask

What does chain of custody actually mean in ITAD?
An unbroken, documented record of who held each asset, when, and what was done to it — from the moment it leaves your control to its final disposition. The operative word is unbroken. A record with a gap is not a chain; it is two records with an unexplained space between them, and that space is what an auditor will ask about.
Where does it usually break?
Almost never during processing, which is where people expect. It breaks at the edges — at collection, where the manifest is created; in storerooms, where assets accumulate before anyone counts them; and at handoffs between vendors, where two partial records meet and neither is complete. The strongest processing floor in the world cannot repair a manifest that was wrong on arrival.
How is it evidenced in an audit?
By tracing a single serial number end to end and getting a complete answer. That means a chain-of-custody receipt at intake, a record of each stage the asset passed through, a sanitization certificate specific to that device, a condition and grading record, a disposition authorization, and an outbound manifest with carrier confirmation. If any link is missing for that one asset, the chain has failed regardless of how good the aggregate reporting looks.
What happens if an asset goes missing?
The honest answer is that reconciliation is what surfaces it, and the value of the process is that it surfaces it quickly rather than at audit. Our opening inventory is reconciled against your declared manifest at intake, so a discrepancy between what you sent and what arrived is visible at the start of the engagement — while it is still a logistics question with a chance of being resolved, rather than a disclosure question months later.
When does liability transfer?
This is a contractual question and you should establish the answer in writing before equipment moves, not after. It is one of the more important questions to ask a prospective provider, and a provider who is vague about it is telling you something. Ask where in the process custody formally transfers, what documentation marks that transfer, and what happens in the window between collection and intake.
How is custody maintained across multiple collection sites?
Each site is treated as its own inbound event with its own declared manifest, reconciled independently. That is the difference between a real multi-site process and a nominal one: if fifty branches send equipment and the totals are only reconciled in aggregate, a shortfall at one site is invisible because it is absorbed into the portfolio. Reconciling per site is more work and it is the only version that means anything.
What is the difference between per-device and per-batch certification?
A per-batch certificate asserts that a shipment was processed. A per-device certificate asserts what happened to one asset, identified by serial number, with the method, operator, workstation, timestamp and result recorded. Only the second one answers an auditor's actual question. Batch-only certification is widely treated as a red flag in vendor assessments for exactly this reason.

Test us on this.

Ask us to trace a serial number, or schedule a records review. Compliance officers and third-party auditors can arrange a facility walkthrough on 48 hours' notice.