Every ITAD provider sells chain of custody as breach prevention. Your auditor cares about it for an entirely different reason.
Ask an IT director why chain of custody matters and you'll get an answer about data. Drives leaving the building, breach exposure, regulatory penalties. All true, all well covered by every vendor in this industry.
Ask a controller the same question and you get a different answer, or more often, a blank look followed by a question of their own: what do you mean the server's still on the register?
That gap is where the money is. Not the dramatic breach scenario, which is rare. The quiet, chronic one: equipment that physically left the building years ago and never left the books.
The Asset That Won't Die
The accounting term is a ghost asset — a fixed asset carried on the register that no longer physically exists or is no longer usable. The most common cause is exactly the one this industry creates: equipment scrapped, sold, or donated, but never removed from the record. By some estimates that single category accounts for roughly 40 percent of all ghost assets.
The consequences are unglamorous and compounding. Property, plant and equipment is overstated. Depreciation keeps running on hardware that hasn't existed for three years. In many jurisdictions you're paying property tax on it. You may well be insuring it.
None of that is dramatic enough to trigger a crisis. It's dramatic enough to trigger an audit finding, and it accumulates silently until someone finally walks the floor.
Three Truths That Have to Line Up
Derecognition — the accounting event where an asset comes off the books — isn't really a journal entry. It's a moment where three separate versions of reality have to agree.
Physical Truth. The asset is actually gone. Not staged in a hallway. Not in a closet awaiting pickup. Gone, or verifiably destroyed.
Documentary Truth. There is evidence of that, tied to the specific asset, produced by someone accountable for producing it.
Ledger Truth. The register and the general ledger reflect it, depreciation has stopped, and the disposal is posted in the right period.
In most organizations these three fall out of sync at exactly one point: the handoff to the disposition vendor. IT knows the equipment left. Finance doesn't know when, or which units, or what happened next. The paperwork that would connect them is either a single invoice or a certificate listing batch totals instead of serial numbers.
That's the whole problem in one sentence. A certificate that says "42 drives destroyed" cannot be reconciled against a register that lists 42 individual asset tags.
What the Auditor Is Actually Testing
Fixed asset audit procedures are not mysterious, and knowing them makes it much easier to see what your disposition process needs to produce.
Auditors verify in two directions. They trace items from the register to the floor, to confirm that what you say you own actually exists. Then they trace items on the floor back to the register, to confirm that everything that exists is recorded. Ghost assets are what the first direction is designed to catch.
They test disposals specifically — sampling retirements and asking for the supporting evidence. Authorization to dispose. Proof of what happened to the asset. Confirmation that the derecognition posted correctly and that depreciation stopped.
And they look at segregation of duties. Whether the same person authorized the disposal, executed it, and verified it. A disposition process where one manager decides what goes, calls the vendor, and signs off on the result is a control design problem regardless of how honest that manager is.
For public companies, systems that supported financial reporting draw particular attention, since disposal controls fall within the scope of what external auditors evaluate under Section 404. The specifics of how your auditor treats a documentation gap will depend on materiality and on their judgment — that's a conversation to have with them, not with a vendor. But the general shape is consistent: undocumented disposals are a control question, not just a housekeeping one.
Where It Actually Breaks
In practice, chain of custody rarely fails through anything sophisticated. It fails through ordinary operational gaps.
Unlogged Collections. Equipment leaves without a formal handoff record, so there is no defensible start to the trail.
Batch-Level Certificates. Documentation that reports totals rather than serial numbers, which cannot be reconciled to an asset register at any level of detail.
The Invoice as the Only Artifact. A line item saying "IT equipment disposal, $1,400" is a payment record. It is not evidence of what happened to any particular asset.
The Staging Limbo. Equipment pulled from production, stacked in a storage room, and left there. It isn't in service, it hasn't been disposed of, and nobody has decided which it is. It sits on the register at a depreciated value while quietly losing most of its recoverable value.
Untracked Downstream Flow. Your vendor's subcontractor is still your exposure. If you can't name where assets go after the first handoff, you can't stand behind the disposition.
What Good Looks Like
Finance can hand this list to IT and to any disposition vendor, and the answers are diagnostic on their own.
Serialized Records End to End. Every asset tracked by serial number from pickup through final outcome — resold, redeployed, recycled, or destroyed. If a device can't be traced individually, the trail has a gap.
Certificates That Name Assets, Not Quantities. Serial-level certificates of destruction or data sanitization, issued per device, delivered on a defined timeline rather than eventually.
A Settlement Report That Reconciles to the Register. The disposition report and the fixed asset subledger should be comparable line by line, in the same period. If reconciling them requires a spreadsheet exercise and three emails, the process isn't working.
Documented Authorization, Separate From Execution. Someone approves disposal. Someone else carries it out. Someone else confirms it. Written down before the first pallet moves.
Retention That Matches Your Longest Obligation. Chain of custody records and destruction certificates kept for the longest retention period that applies to you across every framework you operate under — commonly six to seven years, though you should confirm the specific requirement with your own advisors rather than assume.
A Named Downstream Chain. Who processes what, where, and under which certifications.
The Part That's Changed This Year
There's a new reason for finance to care, and it isn't about risk.
Retired hardware is currently worth more than most organizations' records suggest. The memory market repriced sharply through the first half of 2026, and equipment sitting in staging is carrying value that nobody has measured. If those assets were fully depreciated or written off, proceeds on disposal land as gain. If they were disposed of informally and never recorded, that value left the building without ever appearing anywhere in the financial statements.
Chain of custody is what makes recovered value visible and attributable. Without it, disposition is a cost line. With it, it's a recovery your controller can actually book.
The Uncomfortable Question
Pull your fixed asset register. Filter for IT equipment older than four years that hasn't been marked as disposed. Then ask someone to physically find ten of those assets.
Most organizations cannot complete that exercise. The ones that can usually discovered why the hard way — during an audit, in a quarter when they had other things to do.
Vibrant Technologies has provided secure, documented IT asset disposition since 1998, and is R2v3 certified. Serialized chain of custody, asset-level certificates, and settlement reporting your finance team can reconcile. Request a valuation
This article describes general audit and accounting practice and is not accounting, tax, or legal advice. Confirm requirements specific to your organization with your auditors and advisors.
Sources
- AccountingTools — Definition of ghost assets and the causes of unrecorded disposals. Article
- CPCON — Ghost asset categories and prevalence, including the share attributable to disposals that were never recorded; floor-to-sheet and sheet-to-floor verification methodology. Ghost asset detection · How to audit fixed assets
- CPCON — Fixed asset reconciliation procedure and the requirement that reconciliation be performed independently of asset custody. Reconciliation guide
- AssetCues — Derecognition as the alignment of physical, documentary and ledger records; disposal evidence packs and the retention of sanitization certificates alongside them. Fixed asset disposal accounting