IronbayAsset Recovery

Choose the partner.
Check the evidence.

A useful vendor review goes beyond a badge and a price per device. Ask for evidence that covers your equipment, your data policy, and the people who will actually handle the work.

1. Start with the actual scope

Give each vendor the same brief so the proposals are comparable: equipment categories, quantities, locations, target dates, data-handling requirements, and expected reports. Separate a one-time refresh from an ongoing collection program.

  • Who performs collection, transport, processing, and resale? Identify subcontractors and downstream facilities.
  • Which locations will handle your assets, and what happens if work is redirected?
  • What equipment or conditions are excluded from the quote?
  • Who owns scheduling, exceptions, and final reconciliation?

Ask for a written scope and an escalation contact. A verbal promise is difficult to reconcile at the end of a project.

2. Verify credentials and their scope

If a vendor claims a certification, ask for the current certificate, legal entity, facility address, scope, and expiration date. Check those details with the issuing organization. A logo alone does not tell you which site or activities are covered.

  • Does the certificate name the entity that will contract with you?
  • Does its scope cover the services you need at the processing location?
  • Are any relevant downstream partners outside that scope?
  • Can your procurement team review current insurance and the relevant policies?

For R2 certification, use the SERI facility directory. For NAID AAA, consult i-SIGMA. These are verification resources, not a statement that Ironbay holds either certification.

3. Agree on data handling and exceptions

Your security team should approve the method for each media category before collection. Ask how the vendor determines that a technique is suitable and how results are verified and validated. NIST SP 800-88 Rev. 2 provides guidance for establishing a media sanitization program.

  • How are media and asset serials captured and linked?
  • How are failed, unreadable, or inaccessible devices handled?
  • What records demonstrate the sanitization outcome?
  • When is physical destruction required by your policy?
  • Can you review a representative report before signing?

Do not assume an operating-system reset, a deleted partition, or an unspecified “wipe” meets your policy. Ask for the actual technique and its applicability to the device.

4. Follow the custody and downstream path

Map each handover from the collection site to the final disposition. The useful question is not just whether assets are tracked, but how your team can reconcile the evidence.

  • Which inventory is signed at collection, and how are discrepancies recorded?
  • How is access to equipment restricted in transit and storage?
  • How are mixed loads separated and customer assets identified?
  • Where do reusable equipment, destroyed media, batteries, and residual materials go?
  • What evidence supports any environmental claim?

Request an example of an exception record. Lost labels, quantity differences, failed sanitization, and locked devices need a documented resolution path.

5. Make pricing and closeout explicit

A high resale estimate can hide an expensive process. Compare the same assumptions across vendors and separate projected value from a guaranteed offer.

  • List collection, packing, labor, sanitization, destruction, recycling, and reporting charges.
  • Confirm who pays for non-resalable or locked equipment.
  • Define revenue share, testing deductions, settlement timing, and ownership transfer.
  • Agree on reporting deadlines and how exceptions affect closeout.
  • Review one sample asset report and one sample settlement statement.

Close the review with a written decision: approved scope, required evidence, open questions, and the person responsible for each item.

Keep it with your project

A checklist your team can use.

Download a plain-text copy to edit in your project notes, or print this page from your browser.

Reference: NIST SP 800-88 Rev. 2. Confirm the appropriate controls with your security and procurement teams.

Related: Business laptop retirement checklist · Data center decommissioning checklist