Skip to content

Resources

Ten questions that separate ITAD providers

Written to be useful even if you do not choose us. Every question below has a falsifiable answer — which is the only kind worth asking when every provider's website says the same things.

Why this exists

Capability claims are cheap. Evidence requests are not.

Read four ITAD websites and you will find the same vocabulary on all of them: secure, certified, compliant, chain of custody, sustainable. The words are free. What differs is whether the controls behind them are mechanisms or intentions, and you cannot tell from the marketing.

So ask questions where a weak answer is visibly weak.

We have put our own answers into the pages on this site rather than reserving them for a sales call. If a provider will not answer these in writing before you contract, that is itself a finding.

The framework

Ask these, in writing

01

Certification scope — not the badge

“Which of your facilities hold which certifications, and what activities does each certificate's scope actually cover?”

A certificate names a scope. R2v3, for example, is issued with appendices covering specific activities — downstream recycling chain, data sanitization, test and repair — and a provider certified for logical sanitization is not thereby certified for physical destruction. Ask for the certificate, then read the scope line. Providers rarely lie about certification; they routinely let buyers assume a scope broader than the one they hold.

02

Where processing physically happens

“Where will our equipment be processed, and is any part of the work subcontracted?”

A provider who brokers your assets to a third party cannot show you the room they were processed in, and the party you assessed is not the party holding your data. Ask for the address. Ask whether you can visit it.

03

Evidence granularity

“Is a sanitization certificate issued per device or per batch?”

Per-batch certification looks like evidence until an auditor asks about one serial number. A per-device certificate should name the device serial, the method applied, the operator, the workstation, a timestamp, the result and a validation reference. Ask to see a sample.

04

Right to audit

“Can we or our third-party auditors inspect the facility and review records, and on what notice?”

Providers who have built for auditability say yes with a timeframe. Providers who have not become abstract. This question is unusually good at separating the two.

05

Verification versus validation

“Do you verify that the sanitization operation completed, or validate that the data was effectively sanitized?”

NIST SP 800-88 Revision 2 separates these deliberately. Verification asks whether the operation ran; validation asks whether it worked for that medium. A technique can execute perfectly and still be wrong for the storage type — an interface-level overwrite on flash being the classic case. A provider who only verifies is answering a narrower question than the standard poses.

06

What happens on failure

“What happens to a device that fails sanitization, and can it re-enter the flow?”

This exposes whether controls are mechanisms or intentions. Ask specifically whether a device lacking a passing result can still be shipped or invoiced. If the honest answer is that a supervisor could push it through, the control is advisory.

07

Downstream accountability

“Who processes residual material, do you audit them, and can we see the manifest trail?”

Liability for improper downstream handling does not disappear when the truck leaves. Certification schemes require downstream vendor management for exactly this reason, so ask how it is exercised rather than whether it exists.

08

Value recovery transparency

“How is residual value calculated, and how is it evidenced back to us?”

The weakest area in the industry. Very few providers publish anything about this. A credible answer ties proceeds back to individual assets — configuration at intake, grade at test, realised price at sale — rather than presenting a lump sum you cannot audit.

09

Insurance and liability transfer

“What insurance is carried and at what limits, and at exactly what point does liability transfer?”

Establish this in writing before equipment moves. The window between collection and intake is the least-governed part of most engagements and the one buyers most often forget to ask about.

10

Compliance framing

“Does engaging you make us compliant with HIPAA, GLBA or PCI-DSS?”

The correct answer is no. Those obligations rest with your organization and cannot be transferred to a vendor — NIST 800-88 itself assigns sanitization responsibility to roles inside the owning organization. A provider marketing itself as offering "HIPAA-compliant ITAD" has either misunderstood where the duty sits or is comfortable letting you misunderstand it. Either is informative.

FAQ

Questions about choosing a provider

What certifications should an ITAD provider hold?
R2v3 or e-Stewards is the baseline for responsible recycling and reuse, and most enterprise buyers treat one of them as a threshold requirement. Beyond that it depends on what you need: RIOS for operating-standard assurance, ISO 27001 where information security management is scrutinised. What matters more than the list is the scope on each certificate and which facilities it covers — a provider certified for logical data sanitization is not thereby certified for physical destruction, and that distinction is on the certificate if you read it.
Is more certification always better?
No. A long badge row can conceal a narrow scope, and some certifications are alternatives rather than additions — a facility normally holds R2 or e-Stewards, not both. Read scopes rather than counting logos.
How do I compare providers who all say the same things?
Ask questions with falsifiable answers. "Do you maintain chain of custody" gets a yes from everyone. "Where does chain of custody most often break, and what stops it breaking there" separates providers who have thought about the problem from providers who have a paragraph about it. The same trick works throughout: ask for the mechanism, not the commitment.
What are the clearest warning signs?
Batch-only certificates. Vagueness about which facility will process your equipment. Reluctance to be audited. No named compliance owner. Claiming to make you compliant with a regulation. And an unwillingness to say what happens to assets that fail — every real process has failures, and a provider who cannot describe theirs has either not looked or is not telling you.
Should price be a factor?
Yes, but understand what you are pricing. The cheapest disposal quote frequently reflects thinner documentation, a broader use of subcontractors, or value recovery that is not passed back — all of which are real costs, just deferred and harder to see. Compare the evidence package and the recovery model alongside the price, not after it.
How should we structure an ITAD RFP?
Around evidence rather than capability claims. Ask for a sample certificate, a sample closeout package, the certificate scopes for the specific facility that will process your assets, the downstream chain, the audit provisions, and the value-recovery methodology. Capability sections invite marketing answers; evidence requests do not.

This framework is provided for general information and is not legal, compliance or procurement advice. Certification requirements, regulatory obligations and contractual terms vary by organization and jurisdiction.

Put these questions to us.

Send your vendor questionnaire or your RFP. We would rather answer the hard ones during scoping than discover a blocker after contracting.