One ITAD Policy, Three Countries: The Certificate an Auditor Will Actually Accept
For the regional IT asset owner or facilities lead retiring three or four years of devices across Singapore, Taiwan and Vietnam in one programme — usually triggered by an audit or a lease event. What an erasure or destruction certificate actually has to show before an auditor will accept it, where chain of custody breaks between three countries, what genuinely differs by jurisdiction versus what should never be assumed, and how to write one group ITAD policy that survives three different sets of local logistics.
An auditor does not accept a certificate because it exists. It has to tie a named sanitisation method to a specific serial number, on a date, by an identified party, with an unbroken custody record from the desk it came off to the moment it stopped being readable — and that is a harder thing to produce consistently across three jurisdictions than inside one office.
A Regional Refresh, Three Countries, One Compliance Question
A group facilities or IT asset lead at a consumer-electronics or technology company is usually the one who ends up owning this problem, and it usually starts the same way: a three- or four-year-old device fleet is coming up for refresh across Singapore, Taiwan and Vietnam, and each site has been disposing of retired hardware the way it always has. The Singapore office uses a local recycler who wipes drives before collection. The Taiwan site has a facilities vendor who takes old laptops away with the rest of the office waste. Vietnam's IT contractor keeps a box of "dead" drives in a cupboard because nobody signed off on what to do with them. None of this is dishonest — it is what happens when disposal is handled locally, ad hoc, by whoever is nearest to the problem, in a company that has never had one written policy for it.
Then an audit, a lease event, or a new group compliance mandate asks the obvious question: can you prove what happened to the data on every device your company has retired in the last three years? At that point, three local practices are not three acceptable variations on the same control — they are three different answers to the same question, none of which is fully documented, and none of which line up with the other two. This is not a story about any one office doing something wrong. It is a story about a policy that was never written down travelling across three countries as three different informal habits instead.
The fix is not "pick the strictest local practice and apply it everywhere" — Vietnam's shipping lead times are not Singapore's, and Taiwan's local recycling market is not Singapore's. The fix is a single group ITAD policy with one certificate standard and one chain-of-custody format, executed through local logistics that are allowed to differ. That distinction — one standard, locally executed — is the spine of everything below.
What Does "Erased" Actually Have to Mean?
"We wiped it" is not a record; it is a claim. Three separate things get collapsed into that one sentence, and an auditor will pull them apart:
- A method — the specific sanitisation technique applied to that device, by name (a Blancco software wipe to NIST 800-88, a degauss pass, a physical drill or shred), not a generic "erased" or "reset."
- A verification — evidence that the method actually completed successfully on that specific unit, not just that it was scheduled to run. A software wipe that stalls or errors partway through a drive is a failed job, not a completed one, and the record has to show which outcome happened.
- A certificate — the document that ties the method and its verification to one serial number, one date, and one accountable party, in a form someone outside the process can check later without having been in the room.
NIST Special Publication 800-88 (currently at Revision 2, which superseded Revision 1 in late 2025) is the reference standard most auditors expect to see named, and it is useful precisely because it forces this separation. It defines sanitisation in three categories rather than one: Clear, which protects against ordinary data-recovery tools through the device's own interface; Purge, which is built to resist recovery even with specialist laboratory techniques while the media can still be reused; and Destroy, which makes the media itself no longer able to store or retrieve data at all. Which category is appropriate depends on the sensitivity of what was on the drive, not on which method happens to be fastest or cheapest that week — a distinction worth having your policy state explicitly rather than leaving to whoever is doing the collection that day.
How Do You Read an Erasure Certificate Like an Auditor?
Most disposal certificates look reassuring at a glance and fall apart under five specific questions. Before signing off on a batch, or accepting one from a vendor for a Taiwan or Vietnam site you cannot inspect in person, check that the document actually answers all of them for every device, not just for the batch as a whole:
- Serial-level identity. Does the certificate list the serial number or asset tag of each individual device, or only a device count and a date? A certificate that says "44 laptops processed" proves nothing about any one of them.
- Method and standard. Is the sanitisation technique named specifically — Blancco software erasure to a stated NIST 800-88 category, degaussing, physical drill, or third-party shredding — rather than a generic word like "wiped" or "destroyed"?
- Verification result. Does the record show the outcome of that specific device's process, not just that the process was initiated? A tamper-proof erasure report generated per device, with a timestamp, is what this looks like in practice.
- Date and operator. Is there a date the work was performed and an identified party — a named engineer or a specific vendor entity — accountable for it? A certificate with no operator named is a claim with no one to ask.
- What a failed-drive record looks like. This is the one most policies never specify, and it is the one that separates a real process from a paper one. A drive that will not complete a software wipe — because it is physically damaged, because a sector is unreadable — is not a gap in the paperwork. It should generate its own record: the device is flagged, routed to physical destruction instead of erasure, and the final certificate should show that substitution rather than quietly omitting the device from the batch.
A certificate that answers all five of these, per device, is auditable. A summary letter that says a batch was "securely processed" is not — however professional it looks.
Where Does Chain of Custody Actually Break?
Chain of custody is the part of an ITAD programme that sounds procedural and turns out to be where almost everything that goes wrong, goes wrong — and it breaks at handover points, not during the disposal work itself.
The first handover is collection: the moment a device leaves the desk, cupboard, or server rack it was retired from and enters someone else's custody. If this step is not logged — device tagged, photographed, and checked against an asset register before it is moved — then everything that follows is a record of what happened to an unverified pile of hardware, not to your fleet specifically.
The second handover is transit to wherever sanitisation actually happens, particularly when that is not the same building the device was collected from. A sealed, tagged transport with a documented custody log closes this gap; an unsealed box in the back of whichever van happened to be available does not, and it is the single easiest point for a device to go missing without anyone noticing for months.
The third handover is the transition from "sanitised" to "disposed of" — the point where a wiped or destroyed device leaves the processing site for recycling, resale, or a return shipment. A device can be perfectly erased and still represent a gap in the record if nobody can say what physically happened to it afterward: which recycler took it, on what date, under what agreement.
Across a single-country office this is a three-step internal handoff. Across Singapore, Taiwan and Vietnam it becomes three separate custody chains that have to use the same documentation standard to be auditable as one programme — which is a process design decision, not something that happens by default because each local team is competent on its own.
What Differs by Jurisdiction — and What You Should Not Assume
This is the part of a multi-country ITAD programme where it is tempting to state a rule for each country and move on, and it is exactly where that temptation should be resisted. This article does not state Singapore, Taiwan or Vietnam-specific legal requirements as fact — data protection, e-waste and cross-border movement rules are the kind of thing that changes, that varies by device and material class, and that genuinely needs to come from current local counsel or your ITAD provider's compliance team for the specific country, not from a blog post.
What is safe to say in general terms, and useful to have your policy account for explicitly, is the shape of what tends to differ:
- Cross-border movement of used electronics and e-waste is restricted to different degrees under international conventions and domestic customs and environmental rules almost everywhere — meaning "just ship the retired drives to whichever country has the capability" is rarely a decision you can make without checking first, and the answer is not the same for Singapore, Taiwan and Vietnam.
- What can be recycled locally depends on each market's certified e-waste infrastructure, which is not uniform across the region — a method that is routine in one location may need to route through a different local partner, or a shipment, somewhere else.
- Who may witness or notarise destruction — some clients' own compliance requirements call for a witnessed destruction event, and whether that is practical, and who is an acceptable witness, is a local operational question.
- How long records must be retained, and in what form, is set partly by your own group policy and partly by local regulatory expectations that should be confirmed per country rather than assumed to match.
The right posture for a group policy is to fix what a certificate and a custody record must contain everywhere — the standard described in the two sections above — and to leave the *how* of collection, local recycling routing, and witnessing local and confirmed per country before each programme run, not once at the start and never revisited.
Erasure or Physical Destruction: How Do You Choose?
For most retired laptops and desktops with intact, working drives, software erasure is the default: it is faster, it can be run wherever the fleet actually is, and — when the device still has resale or reuse value — it is what makes residual-value recovery possible at all, offsetting programme cost instead of adding to it. Physical destruction is the exception you reach for deliberately, not the default you fall back to because it feels more certain.
Erasure vs Degaussing vs Physical Shredding
- Software erasure (Blancco or equivalent, to NIST 800-88) — overwrites or cryptographically erases every accessible sector, produces a tamper-proof per-device report with serial number, method and timestamp, and needs nothing more exotic than a licence, a boot tool and an isolated lab network. Best fit: working HDDs and SSDs that will be resold, reused or recycled, where reuse value matters and the drive can complete the process cleanly.
- Degaussing — exposes a magnetic drive to a powerful field that permanently destroys the drive's magnetic domains; irreversible and verifiable, but it is equipment-dependent and, on Brocent's own infrastructure, the certified degausser is based in Beijing and has to be shipped to wherever the work is happening. Best fit: bulk HDD-only destruction where the shipping lead time is acceptable and the drives have no resale value.
- Physical destruction — drill or industrial shredding — a drill applied on-site renders a platter unrecoverable in minutes and needs only an engineer and the tool; certified third-party industrial shredding reduces media to fine particles and is what some government or financial-sector requirements specifically call for. Best fit: damaged or unreadable drives that failed erasure, devices with no resale value, or media where the client's own policy requires physical destruction regardless of erasure outcome.
The practical implication for a Singapore–Taiwan–Vietnam programme is that erasure is the method that travels most easily between all three sites, because it depends on a licence and a laptop rather than on shipping specialised equipment or locating a certified local shredding partner in each market — which is exactly why it should be positioned as the default, with physical methods reserved for the drives that actually need them.
Writing One ITAD Policy That Survives Three Countries
A policy that tries to specify every local detail centrally will be wrong about at least one country within a year, and a policy that leaves everything to local discretion will produce exactly the three-different-answers problem this article opened with. The workable middle is to be explicit about what is fixed group-wide and what is deliberately left to local execution:
- Fixed everywhere: the sanitisation standard required per data-sensitivity class (which category — Clear, Purge or Destroy — applies to which device type), the certificate format and the fields it must contain, the chain-of-custody documentation standard at each of the three handover points, and the retention period for records.
- Local by design: which certified local recycler or shredding partner is used, how collection is scheduled and transported, whether a device ships to a regional hub for a specific destruction method, and how local witnessing or notarisation requirements (once confirmed with local advice) are satisfied.
Writing this distinction into the policy document itself — not leaving it implicit — is what lets three country teams each do their own logistics without three different definitions of "done" emerging quietly over time. It is also what makes it possible to run the programme under one coordinated engagement rather than three unrelated local vendor relationships that happen to report into the same group.
The Reporting Pack That Actually Closes an Audit Finding
An audit finding about retired hardware is not closed by an email saying the devices were disposed of. It is closed by a reporting pack an auditor can work through without asking a follow-up question for every line: a comprehensive disposal report listing every asset by serial number and asset tag, the destruction method applied to each, the date, and the individual certificate reference for each device — plus the chain-of-custody record covering collection, transit and final disposition for the same assets, organised so that a Singapore, Taiwan and Vietnam batch can each be reviewed on the same template.
This is also the point where the earlier failed-drive question matters most in practice: if three drives out of two hundred failed a software wipe and were routed to physical destruction instead, the reporting pack needs to show that substitution explicitly, not quietly fold those three devices into the same "processed" total as the other 197. An auditor who finds one unexplained gap in an otherwise clean pack will usually go back and re-check the rest of it; a pack that documents its own exceptions is the one that gets signed off in a single pass.
Where This Belongs: Asset Lifecycle Inside the Managed Plan
Most of what makes a multi-country disposal programme hard — not knowing what devices exist where, discovering a retirement wave only when someone opens a storeroom, three sites keeping three different informal records — is a symptom of asset lifecycle tracking that only starts at the point a device is already being retired. When hardware inventory, warranty status and refresh scheduling live inside an ongoing managed IT plan rather than being reconstructed from scratch at each disposal event, a regional refresh stops being a forensic exercise and becomes a scheduled one: the fleet due for retirement across all three countries is already known, in one list, months before collection needs to start.
That is also usually the same conversation as office relocation and consolidation work — hardware refresh, site consolidation and lease-end disposal events tend to cluster together in practice — and, for the part of this that some group compliance teams do want folded into a wider control set, it connects to managed security services covering the identity and access side of decommissioning rather than the hardware side. A Singapore manufacturer's version of this exact problem — two hundred drives sitting in a store room because nobody could prove the data was gone — and a Singapore data-centre lease-exit decommission run under the same evidence-first discipline are both single-site versions of the same underlying problem this article treats as a three-country one; the certificate and custody standard is the same, only the number of local logistics chains changes.
Brocent's own IT asset disposal service runs on this model — NIST 800-88 sanitisation, chain-of-custody collection, and per-device destruction certificates as the fixed standard, with local collection and destruction logistics coordinated per site. For a programme spanning Singapore, Taiwan and Vietnam, the starting point is a scoping conversation, not a quote sight-unseen: get in touch to talk through fleet size, site count and current local practice, or see indicative pricing for how a managed disposal engagement is typically structured.
Frequently Asked Questions
Is a wipe the same as a secure erase?
No, and the distinction matters for what a certificate can actually claim. A basic factory reset or quick format only clears the file system's pointers to data — the underlying data is often still recoverable with commonly available tools. A secure erase to a named standard, such as a NIST 800-88 Purge-level wipe performed with software like Blancco, overwrites or cryptographically erases the actual storage sectors and is built to resist recovery even with advanced techniques. A certificate should specify which of these happened, not just say "wiped."
What standard should we require?
NIST 800-88 (currently Revision 2) is the reference point most auditors and cyber-insurance policies expect to see named, applied at the Clear, Purge or Destroy level appropriate to the data sensitivity of the device. Which level applies to which device class is exactly the kind of decision that belongs in your written group policy rather than being decided ad hoc per batch.
Do we need physical destruction, or is erasure enough?
For working drives with no unusual sensitivity that you intend to resell, reuse or recycle, a verified software erasure to an appropriate NIST 800-88 level is normally sufficient and preserves residual value. Physical destruction — drilling, degaussing or certified shredding — is the right call for drives that are damaged, unreadable, hold your highest-sensitivity data, or where your own compliance policy specifically requires it regardless of erasure outcome.
What happens if a drive fails erasure?
It should not be quietly excluded from the batch or reported as processed. A failed drive needs its own record: flagged as a failed erasure, routed to physical destruction instead, and the final certificate and reporting pack should show that substitution explicitly, with its own serial number, method and date — the same as every other device, just on the destruction path rather than the erasure path.
Can devices cross borders for disposal?
Sometimes, but this is exactly the kind of question that needs a current, country-specific answer rather than a general one — cross-border movement of used electronics and e-waste is restricted to varying degrees almost everywhere, and the rules differ by device type and by country. Confirm this per country, for the specific programme, before planning a shipment between Singapore, Taiwan and Vietnam.
Who issues the certificate?
The party that actually performed and verified the sanitisation or destruction — a named engineer or the specific vendor entity accountable for that device's processing — not a coordinating office that did not touch the hardware. For a multi-country programme run under one policy but executed by local teams or partners, each local execution point should still be named on the certificate for the devices it actually processed.
How long should we keep the records?
Long enough to cover your own group retention policy and any regulatory retention period that applies in each country where the devices were located — which is another item to confirm locally rather than assume matches your headquarters' default. In practice, most organisations retain ITAD certificates and chain-of-custody records for several years to cover audit cycles and potential disputes; treat the exact figure as a policy decision to set deliberately, not a default to inherit by accident.
Can one contract cover all three countries?
Yes — that is the point of designing one group standard with locally executed logistics rather than three separate local vendor relationships. A single coordinated engagement can apply the same certificate and chain-of-custody standard across Singapore, Taiwan and Vietnam sites while collection scheduling, local recycling partners and any market-specific requirements are handled per site under that one framework.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.