For most of the last two decades, it asset disposition lived at the bottom of the IT org chart, somewhere between facilities and procurement. Someone booked a truck, equipment left the building, and a spreadsheet got updated. That arrangement has quietly stopped working — not because the logistics got harder, but because the questions being asked about them changed.
The question shifted
The old question was straightforward: is our data safe? A vendor said yes, and that was generally the end of the conversation.
The question now is can we demonstrate that our entire technology lifecycle is secure, responsible, and defensible? That’s a different kind of question. It can’t be answered with an assurance. It has to be answered with records.
That shift is what moved asset disposition out of operations and into governance. A board committee asking about ESG performance and an auditor asking about chain of custody are, functionally, asking the same thing — show me the evidence.
Five things an IT asset disposition program has to produce in 2026
Compliance leaders designing programs right now are building around a consistent set of outputs:
- Provable data protection — erasure and destruction documented to a named standard, not described in general terms
- Regulatory alignment — privacy, environmental, and records-retention requirements handled by one process rather than three
- Measurable ESG outcomes — numbers that survive contact with a sustainability report
- Maximum value recovery — reuse pursued before recycling, with the recovery quantified
- End-to-end accountability — unbroken chain of custody from collection through final disposition
Read that list again and notice what it has in common. Every item is a reporting requirement. None of them is a transport requirement.
Why reuse-first is the commercially better answer too
There’s a habit of treating reuse as the sustainability option and resale as the financial one. In practice they point the same direction.
A three-year-old business laptop retains real market value. Shredding it converts a working asset into a few dollars of aluminium and copper. Refurbishing it either recovers resale value or generates a donation with a documented community outcome — and either result reports better than scrap tonnage.
Reuse also produces the ESG story that actually holds up. “We diverted X tonnes from landfill” is a weak claim; diversion is table stakes. “We extended the service life of X devices and placed them with named community organisations” is specific, verifiable, and hard to accuse of greenwashing.
The reuse-first model that Canadian non-profit processors have built their programs around works precisely because it serves both columns at once.
What to ask a prospective partner
Vendor selection is where programs succeed or fail, and the useful questions are narrower than most RFPs make them.
Ask what documentation comes as standard versus on request. Ask whether serial numbers are captured at intake or reconstructed later — the answer tells you how much the chain of custody is really worth. Ask what happens to a device that fails refurbishment testing, and get the downstream processor named.
Ask about subcontracting. A single-hop chain you can audit beats a multi-hop chain with impressive certifications at the front end.
Then ask for a sample report pack. If a vendor can’t show you what your evidence file will look like, they haven’t built for this use case.
The failure that costs the most
The expensive failure in this space is almost never a truck arriving late. It’s discovering, mid-audit, that the records don’t reconstruct.
Equipment left the building. Something was signed. But the intake inventory doesn’t reconcile against the destruction certificate, three serial numbers appear on neither, and nobody can say where two drives went. Nothing was necessarily stolen — the process simply didn’t generate proof.
That’s a governance failure with a governance cost: regulatory exposure, disclosure obligations, and a control weakness that follows you into the next audit cycle.
Where this leaves IT leaders
Treat it asset disposition as an evidence-production function and the design decisions get easier. Instrument the process to generate serial-level records by default. Pick partners on documentation quality rather than pickup speed. Report reuse and community placement, not just diversion tonnage.
Do that and disposition stops being the loose end at the bottom of the refresh project. It becomes one of the few places where security posture, audit readiness, and sustainability reporting all improve from the same piece of work — which is a rare enough combination to be worth the attention.
