Key Takeaways for Bank ITAD Compliance
- Bank IT equipment recycling compliance in 2026 requires serialized, cross-referenced documentation mapped to GLBA, PCI-DSS, SOX and state e-waste rules.
- Each framework sets specific documentation, retention periods and oversight expectations from its governing authority.
- GLBA requires physical destruction when data cannot be rendered irretrievable, and SOX auditors reject batch-only destruction certificates.
- Twenty-three states plus the District of Columbia maintain landfill or disposal bans on electronic devices, so banks must map each state’s ban status and covered devices.
- Full Circle Electronics delivers the documentation package described in this playbook; contact us to schedule a compliance review and receive a tailored audit packet for the next OCC, FDIC or NCUA examination cycle.
GLBA Disposal Rule Documentation Package
The FTC Safeguards Rule at 16 CFR Part 314 requires financial institutions to maintain a written disposal policy covering electronic customer nonpublic personal information. The 2021 amendments to the FTC Safeguards Rule (effective June 2023) added explicit third-party service-provider oversight requirements, so an ITAD vendor’s serialized Certificate of Destruction now serves as evidence of institutional oversight.
To demonstrate that oversight during an examination, banks must assemble a complete documentation package for each retirement event. That package must include:
- Written disposal policy referencing covered device types such as servers, workstations, ATM hard drives, backup tapes and removable media
- Vendor due-diligence file containing the signed service agreement, current certifications and annual review records
- Per-device inventory reconciliation tying the asset management system to the pickup manifest and to the Certificate of Destruction with no unresolved discrepancies
- Serialized Certificate of Destruction listing serial number, destruction method, date and authorized signature for each device
- Unbroken chain-of-custody manifest with timestamped, named handler signatures at every transfer point
- Erasure verification logs for any software-sanitized devices, referencing the NIST 800-88 level applied
Reformatting or degaussing alone is insufficient under GLBA. Physical destruction is required when data cannot otherwise be rendered irretrievable. GLBA’s Safeguards Rule requires financial institutions to maintain data retention policies that include timely disposal of unnecessary customer information, with no mandated retention period for disposal records.

PCI-DSS Hardware Scope for ATMs and POS Terminals
GLBA governs customer information disposal broadly, and banks must also address payment card data specifically. PCI-DSS v4.0.1, released in June 2024, sets requirements for devices that process, transmit or store cardholder data. For banks, that scope includes ATMs, POS terminals and data center assets.
Requirement 9.4.7 mandates destruction of electronic media containing cardholder data when no longer needed. Two destruction paths are permitted:
- Physical destruction through shredding, pulverization or disintegration
- Logical sanitization through cryptographic erasure or multi-pass overwriting executed to NIST SP 800-88 Rev. 2 Clear, Purge or Destroy states
NIST SP 800-88 Rev. 2 was issued in September 2025. QSA audit logs must document the method applied for each device.
Requirement 9.5.1 governs the full lifecycle of Point of Interaction devices. For PTS-certified terminals reaching end-of-life, cryptographic zeroization of all loaded keys is required before the device leaves merchant control. The decommissioning record must capture:
- Current POI device inventory entry with PTS approval number
- Tamper-inspection log completed at removal
- Cryptographic zeroization confirmation signed by a qualified payment technician
- Tamper-evident chain-of-custody record from removal through final disposition
SOX Control Evidence for Data-Center Assets
SOX Section 404 requires testing of IT general controls over any system that supports a material financial reporting process. When data-center hardware is retired, the decommissioning event becomes an IT general control point. Effective Dec. 15, 2026, PCAOB QC 1000 and amended AS 2201 apply to these controls.

A SOX-defensible disposition package must include:
- Serialized Certificate of Destruction per device with required fields described in the Certificate of Destruction Retention Schedule section
- Asset-level disposition report showing outcome by device such as reuse, remarketing, recycling or destruction
- Chain-of-custody records from intake through final disposition with timestamps and named handler signatures
- CMDB or asset inventory reconciliation confirming disposed assets are no longer carried as active
Batch certificates listing quantities rather than serial numbers do not satisfy SOX auditor inquiries about specific decommissioned assets. Many organizations receive audit findings because asset inventories fail to reconcile with destruction records. All SOX-relevant disposition records must be retained for 7 years under Section 802.
R2v3 and e-Stewards Contract Language for Downstream Vendors
R2v3 Core Requirement 3 requires a certified facility to identify, assess and document every downstream vendor that handles R2 materials and to track those materials to final disposition, not only to the next vendor. e-Stewards imposes equivalent downstream accountability.
Financial institutions should require the following language in ITAD vendor contracts:
- Vendor shall use only R2v3-certified or e-Stewards-certified downstream processors for post-destruction recyclables and shall name each downstream processor in writing.
- Vendor shall notify the institution of any change in downstream processor within five business days of the change.
- Vendor shall maintain a current approved vendor list with certification status, expiration dates and periodic performance review records, available to the institution on request.
- Vendor shall provide material tracking documentation from intake through confirmed end market or final disposition for every R2 material category handled.
- Vendor shall conduct periodic downstream vendor performance reviews per R2v3 Core Requirement 3.3 and make review records available during institution audits.
Full Circle Electronics holds both R2v3 and e-Stewards certifications and maintains device-level serialized tracking for all data-bearing assets through final disposition.

State E-Waste Landfill Bans by Branch Location
Twenty-three states plus the District of Columbia maintain landfill or disposal bans on electronic devices as of March 2026. Because e-waste regulation is state-based, no two states maintain identical prohibited-item lists. A bank retiring IT assets across multiple branch locations must map each state’s ban status and covered-device definitions before transfer, storage or disposal.
Commonly banned devices across these jurisdictions include:
- Desktop computers, laptops and tablets
- Monitors and CRT displays
- Printers, scanners and fax machines
- Cell phones and smartphones
- Electronic keyboards and mice
Penalty ranges vary significantly by state. California imposes civil penalties of up to $5,000 per offense by superior court (or $2,500 administratively) under the California Electronic Waste Recycling Act for failure to pay the required recycling fee. No specific e-waste violation fines are listed for Illinois. Pennsylvania’s related consumer protection statute imposes up to $1,000 for first violations and $3,000 for subsequent offenses. New Hampshire enacted a rechargeable lithium-ion battery landfill ban effective July 1, 2025.
The NJDEP and CalRecycle both updated program guidance in 2026. Banks with branch networks in New Jersey and California face the most prescriptive covered-device definitions and enforcement postures among eastern and western states respectively.
Compliant recycling of a covered device does not by itself satisfy data disposal obligations. End-of-life electronics containing storage media require both compliant recycling and certified data destruction to address all applicable obligations.

Certificate of Destruction Retention Schedule
A Certificate of Destruction is an audit requirement for every retired data-bearing device. Without it, a claim that an asset was recycled is unverifiable and fails to provide an audit trail.
Each certificate must contain the following fields to satisfy GLBA, PCI-DSS and SOX examiner requests:
- Customer name and address
- Asset serial number with one row per device
- Destruction method and NIST SP 800-88 level applied
- Date, time and location of destruction
- Technician and witness names with signatures
- Chain-of-custody reference number
- Regulatory reference such as GLBA §314.4, PCI-DSS v4.0.1 Req. 9.4.7 or SOX Section 802
- Recycling stream reference such as R2v3 or e-Stewards
- Unique Certificate of Destruction serial number
- Vendor NAID AAA seal
The minimum retention period is 6 years under SEC Rule 17a-4, while SOX Section 802 requires the 7-year period noted earlier. When a litigation hold applies, the hold period supersedes the default.
Vendor Audit-Rights Clause Template
Bank vendor management programs under OCC Bulletin 2013-29 and FDIC FIL-44-2008 require contracts with critical service providers to include audit rights. The following sample language is suitable for ITAD vendor agreements:
“Institution reserves the right, upon reasonable notice, to audit Vendor’s chain-of-custody records, downstream vendor agreements, certification status, and destruction logs for any assets processed under this Agreement. Vendor shall make all relevant documentation available within five business days of a written audit request. Vendor shall permit Institution or its designated third-party auditor to conduct on-site inspections of processing facilities no more than once per calendar year, or at any time following a confirmed or suspected security incident.”
Downstream Vendor Liability Matrix
The following controls define the minimum liability standards financial institutions should require of ITAD vendors and their downstream processors.
Certification requires R2v3 or e-Stewards for all downstream processors and NAID AAA for data destruction. Evidence includes current certificates with expiration dates on file, updated at each renewal. Notification obligations require notice within five business days of any lapse or change.
Insurance requires general liability coverage and cyber-incident liability coverage. Evidence includes a certificate of insurance at contract award, updated annually. Notification obligations require notice within five business days of any coverage reduction or cancellation.
Chain-of-custody documentation requires a timestamped, signed manifest at every custody transfer and serialized asset tracking from intake to final disposition. Evidence includes a custody log available on demand and retained for the 7-year period noted earlier. Notification obligations require immediate notice upon any unresolved custody gap.
Incident response requires a written incident response plan and prompt notification after determining that a notification incident has occurred. Evidence includes an incident response plan on file and a post-incident report within 72 hours of resolution. Notification obligations require immediate verbal notification followed by a written report within 24 hours of incident determination.
Printable Audit Packet Checklist
Attach this checklist to the ITAD vendor contract and present it as the examiner document request response.
- Written Disposal Policy – Current version, signed by CISO or compliance officer; retain 7 years
- Vendor Due-Diligence File – Signed service agreement, current R2v3 or e-Stewards or NAID AAA certificates, annual review memo; retain 7 years
- Per-Device Inventory Reconciliation – Asset management export matched to pickup manifest and to Certificate of Destruction; retain 7 years
- Serialized Certificate of Destruction – One certificate per device with all required fields; retain 7 years
- Chain-of-Custody Manifest – Timestamped and signed at every transfer point; retain 7 years
- Erasure Verification Log – NIST 800-88 level, method and technician per software-sanitized device; retain 7 years
- POI Device Decommissioning Record – PTS approval number, tamper-inspection log, cryptographic zeroization confirmation; retain per QSA cycle
- CMDB Reconciliation Report – Confirms disposed assets removed from active inventory; retain 7 years
- Downstream Vendor Approved List – Current certifications and expiration dates for all downstream processors; updated at each renewal
- State E-Waste Disposal Manifest – State-approved processor confirmation per branch location; retain per applicable state schedule
- Vendor Insurance Certificates – General liability and cyber-incident coverage; updated annually
- Incident Response Plan – Written plan with vendor notification obligations; current version on file
Next Steps with Full Circle Electronics
Full Circle Electronics delivers the documentation package described in this playbook. With R2v3, e-Stewards, NAID AAA, ISO 9001, ISO 14001 and ISO 45001 certifications, a U.S., Mexico and Colombia processing footprint and a secure real-time client portal for certificate access, Full Circle Electronics supports examiner-ready ITAD programs at financial institutions of all sizes. Contact us to begin a compliance review and receive a tailored audit packet for the next OCC, FDIC or NCUA examination cycle.
Frequently Asked Questions
Batch vs. Serialized Certificates of Destruction
A batch certificate lists a quantity of devices destroyed in a single job. A serialized certificate assigns a unique record to each device and ties the specific serial number to the destruction method, date, technician and chain-of-custody reference. OCC, FDIC and NCUA examiners, as well as SOX auditors, expect serialized certificates. Batch certificates consistently produce audit findings because they cannot answer the examiner’s core question about a specific device. Full Circle Electronics issues serialized Certificates of Destruction for every device processed, accessible on demand through the client portal.
Meeting GLBA and PCI-DSS with One ITAD Engagement
GLBA and PCI-DSS share a documentation core that includes a serialized Certificate of Destruction, chain-of-custody manifest, per-device inventory reconciliation and vendor due-diligence file. PCI-DSS adds POI-specific controls such as cryptographic zeroization records and PTS device inventory entries. A single ITAD engagement with a vendor that holds NAID AAA certification and supports PCI-DSS workflows can produce one documentation package that satisfies both frameworks. The Certificate of Destruction should reference both GLBA §314.4 and PCI-DSS v4.0.1 Req. 9.4.7 so that a QSA and a bank examiner can each locate relevant evidence without separate records.
State E-Waste Landfill Ban Triggers and Documentation
The trigger for a state e-waste landfill ban is the physical location of the branch or facility where the device was in service. If that state appears on the 23-state-plus-DC landfill ban map and the device type is on the state’s covered-device list, the bank must route the asset to a state-approved recycler rather than municipal waste. Documentation should include the recycler’s manifest, confirmation that the processor is approved under the applicable state program and a covered-device disposal log keyed to branch location. Banks with branch networks in New Jersey and California face the most prescriptive requirements and should confirm processor approval status with NJDEP and CalRecycle directly before each retirement event.
ITAD Documentation Retention Periods
When GLBA, SOX Section 802 and state disposal laws all apply to the same retirement event, the institution must retain documentation for the longest applicable period. In practice, the 7-year default noted earlier satisfies GLBA, SOX Section 802 and SEC Rule 17a-4 simultaneously. If a litigation hold is in place, the hold period supersedes the 7-year default and documentation must be preserved until the hold is lifted. Institutions should build the 7-year minimum into vendor contracts so that the ITAD provider’s retention obligations mirror the institution’s schedule.
Required ITAD Vendor Certifications for Examiners
Examiners and QSAs look for a combination of data security and environmental certifications that together cover the full disposition chain. At minimum, the vendor should hold NAID AAA for data destruction, R2v3 or e-Stewards for downstream environmental accountability and ISO 9001 for quality management. NAID AAA requires 100 percent background-checked employees and unannounced audits, which makes it the primary credential examiners reference for data destruction. R2v3 and e-Stewards both require material tracking to final disposition and periodic downstream vendor reviews, which directly satisfy the third-party oversight expectations of the GLBA Safeguards Rule. Full Circle Electronics holds these certifications and makes current certificates available through the client portal at any time.