What happens to a laptop after someone hands it back?
Ask that question in most IT departments and you'll get a confident answer for the first 48 hours: it gets wiped, it gets logged, it goes to storage. Ask what happens to it in month four, and the confidence usually drops. By month eight, a lot of teams genuinely don't know. The device is gone from the desk, but it isn't gone from the risk column.
That gap between "the device left the building" and "we can prove exactly what happened to it and when" is where most IT asset disposition problems live. Not in dramatic failures. In small, quiet gaps that accumulate until an audit, a breach investigation, or a compliance review forces someone to go looking.
We work with IT leaders across manufacturing, healthcare, education, and financial services, and the same seven root causes show up again and again, regardless of industry or company size. None of them are exotic. That's exactly what makes them dangerous: they're easy to assume someone else is handling.
Ask most organizations who owns the chain of custody record for a retired device, and you'll get a different answer depending on who you ask. IT will point to facilities. Facilities will point to the vendor. The vendor will point to whatever paperwork got signed at pickup, if any did.
This isn't usually negligence. It's what happens when a process crosses three or four departments and nobody was assigned the record as their job. Ownership diffuses, and when ownership diffuses, documentation becomes optional the moment things get busy.
The fix isn't a memo asking everyone to try harder. It's naming one role, one system, or one partner as the record of truth for every device from the moment it's flagged for retirement through final disposition. If the chain of custody doesn't have a single owner, it doesn't really have an owner at all.
Most disposition failures happen at a handoff, not in the middle of a process. IT flags a batch of devices for retirement. Facilities schedules the pickup. Someone from either team is supposed to reconcile the device list against what actually left the building.
In practice, that reconciliation step is the first thing that gets skipped when either team is short-staffed or moving fast. A spreadsheet gets updated late, or not at all. A device that was supposed to go in batch three quietly ends up in a supply closet, still holding data, still on the books as "in use" even though nobody's used it in six months.
Every manual handoff is a place where the paper trail can silently break. The organizations with the cleanest disposition records are usually the ones who've reduced the number of handoffs, not the ones who've written the most detailed instructions for handling them.
Procurement gets a budget line, a vendor evaluation, and an approval chain. Disposal, for a lot of organizations, gets a phone call.
That asymmetry makes sense on the surface. Buying equipment feels strategic. Getting rid of it feels administrative. But disposal is the stage where data risk, environmental liability, and audit exposure all concentrate at once, which makes it arguably the highest-stakes step in the entire asset lifecycle, not the least.
Treating disposal as a documented process means the same discipline applied to procurement gets applied on the way out: a defined workflow, a named vendor with verifiable certifications, and a record that gets reviewed, not just filed. If your disposal process would be hard to describe to an auditor in under a minute, it's probably not documented enough.
Standard offboarding logistics assume an employee is sitting in an office with an IT desk down the hall. That assumption has been wrong for a growing share of the workforce for several years now, and a lot of disposition processes haven't caught up.
A remote employee's laptop doesn't get returned in the same predictable way an on-site device does. It gets mailed back late, or not at all. It sits in a closet for a year after someone leaves the company. It gets recovered eventually, if it gets recovered, through a mix of reminder emails and goodwill rather than a defined process.
This is also where a meaningful amount of leakage happens. Devices that never come back represent both a direct financial loss and an open data security question that most organizations can't actually answer if pressed. A disposition process that only works for on-site employees isn't a complete process anymore, it's a partial one with a growing blind spot.
Retiring a device on paper and processing it in reality are two different events, and the gap between them is where a lot of organizations lose track of equipment entirely.
An asset gets marked retired in the inventory system the day it's pulled from service. But "retired" and "picked up, wiped, and disposed of" can be months apart, and without a reconciliation step, nobody notices if that second event never actually happens. The spreadsheet says the device is gone. The device is sitting in a bin somewhere, still holding whatever was on the drive when it was pulled.
Reconciliation doesn't need to be complicated. It needs to exist. A monthly or quarterly check that every device marked retired has a corresponding disposition record, matched by asset tag, catches this gap before it becomes six months or two years old.
A lot of disposition vendors are transactional by design: they pick up equipment, and the relationship effectively ends at the loading dock. What happens after that is described in general terms in a service agreement, not documented on a per-device basis in a report you actually receive.
That works fine until someone asks a specific question. What happened to the 40 laptops from the Denver office closure? Were they remarketed, recycled, or destroyed? Where's the certificate of data destruction for that batch specifically, not for the vendor's process in general?
If your vendor can't produce device-level reporting on demand, without a special request or a delay, that's a sign the reporting infrastructure doesn't exist the way it needs to. The vendors worth keeping are the ones whose reporting is available before you have to ask for it, not after.
Most organizations have a written IT asset disposition policy. Fewer organizations have a policy that actually describes what happens in practice.
This gap usually opens up gradually. The policy was accurate when it was written. Then a new vendor came on. Then a hybrid work policy changed how devices got collected. Then someone left and the person who inherited their responsibilities did things slightly differently, because nobody handed off detailed instructions, just the general idea.
A year or two later, the written policy and the actual process have quietly diverged, and nobody's checked because nothing's gone wrong yet. The organizations that catch this before an audit does are the ones who periodically test their policy against reality, not just review it on paper.
Individually, each of these causes looks manageable. A missed handoff here, a slow vendor report there. The real risk shows up when several of them stack: no single owner, plus a manual handoff, plus a vendor that reports slowly, is a scenario where a device can go missing for months with nobody positioned to notice, question, or catch it.
That's the pattern that turns a routine audit into a finding, or a curious question from legal into a much longer investigation. None of these seven causes require a bad actor. They require an ordinary amount of organizational complexity and the absence of a process built to hold up under it.
The organizations that don't run into these problems generally share a few things in common. A single, named owner of the chain of custody record, regardless of which department or vendor is executing each step. Reporting that's generated automatically as part of the disposition process, not compiled after the fact when someone asks. A defined path for remote and hybrid employees that doesn't rely on reminder emails. And a vendor relationship built around certifications that get audited independently, R2v3, NAID AAA, ISO 14001, rather than claims made in a sales conversation.
None of this requires a bigger team. It requires a process where the documentation is a byproduct of doing the work correctly, not a separate task someone has to remember to do.
What is IT asset disposition chain of custody?
Chain of custody in IT asset disposition is the documented record of a device's location, handling, and status from the point it's retired through final disposal, recycling, or resale. A complete chain of custody record can answer where a device was, who had access to it, and what happened to its data at every stage.
How often should disposition records be reconciled against retired asset inventory?
Most organizations benefit from a monthly or quarterly reconciliation, matching every device marked "retired" in inventory against a corresponding disposition record. Waiting longer than a quarter makes gaps significantly harder to trace back to their source.
What certifications should an IT asset disposition vendor hold?
R2v3 and NAID AAA are the two most relevant certifications for data security and environmental compliance in device disposition, with ISO 14001, ISO 9001, and ISO 45001 indicating broader environmental, quality, and safety management standards. All of these should be independently audited, not self-reported.
Why do remote employee devices create more disposition risk?
Remote devices fall outside the standard on-site pickup logistics most disposition processes are built around, which means they're more likely to be returned late, returned never, or sit unaccounted for after an employee departs, creating both financial loss and unresolved data security exposure.
Where would your own disposition process hold up if someone asked for the chain of custody on a device from eight months ago?