IronbayAsset Recovery

Retire the fleet.
Close every loose end.

A laptop refresh is not finished when the replacement arrives. Use this sequence to prepare retired devices, preserve useful records, and avoid gaps between IT, security, and the collection team.

1. Build one retirement inventory

Start with your asset register or MDM export, then reconcile it to the equipment physically available. Keep expected and actual quantities separate. Include a status for missing, damaged, or still-assigned devices.

  • Asset tag and manufacturer serial number
  • Manufacturer, model, and device category
  • Storage type and capacity where known
  • Physical location and collection group
  • Condition, power adapters, and known faults
  • Account or management lock status
  • Approved data-handling instruction

Keep passwords, encryption keys, user files, and unnecessary employee information out of the collection manifest. Share only the information needed to identify and process the equipment.

2. Get the retention and data decision

Have the authorized internal owner confirm that required business records are preserved and that no retention requirement or hold prevents the retirement. A recycling pickup should not decide what your organization is allowed to delete.

Next, have security approve a sanitization or destruction path. Device condition, storage technology, information sensitivity, and reuse plans affect the decision. Record who approved it and how exceptions must be handled.

NIST SP 800-88 Rev. 2 addresses media sanitization programs. The correct technique and validation depend on the media and the organization’s requirements; this checklist is not a device-specific sanitization procedure.

3. Plan management and account releases

Activation locks, firmware passwords, and enterprise enrollment can prevent reuse even when a device appears clean. Identify them early so the retirement does not stall after collection.

  • Confirm ownership and who is authorized to release each device.
  • Record management enrollment and activation-lock status.
  • Coordinate the timing of account releases with your security team and processor.
  • Preserve the identifiers needed for your final reconciliation.
  • Track devices that cannot be released as exceptions.

Avoid removing management controls prematurely if you still need them to secure or identify equipment. Follow the manufacturer’s process and your organization’s approved handoff sequence.

4. Prepare a collection your building can support

Count the devices, identify the collection groups, and agree on packing responsibilities. Tell the collection team about stairs, loading docks, freight elevators, parking restrictions, and building access requirements.

  • Confirm the pickup window and the person authorized to sign.
  • Agree on the manifest and how quantity differences will be handled.
  • Identify loose drives and other media separately.
  • Flag damaged or swollen batteries before packing; request appropriate handling instructions.
  • Keep retired equipment in a controlled location until handover.

Document what actually leaves. Retain a copy of the signed handover record with your project file.

5. Reconcile before you close the refresh

Match the final asset report to the collection manifest and the original retirement inventory. Investigate missing serials, duplicates, unprocessed media, and changes to the planned disposition.

  • Record the method, date, and outcome for each data-bearing asset.
  • Resolve exceptions with a named owner and written outcome.
  • Review any resale settlement against the agreed terms.
  • Update the CMDB and finance records after the reconciliation.
  • Store the reports under your organization’s retention policy.

For the fields to look for, see the sample reporting page. For the full project scope, explore IT asset disposition.

Keep it with your project

A checklist your team can use.

Download a plain-text copy to edit in your project notes, or print this page from your browser.

Reference: NIST SP 800-88 Rev. 2. Confirm the appropriate controls with your security and procurement teams.

Related: ITAD vendor evaluation checklist · Data center decommissioning checklist