Why Documentation Is as Important as Destruction
You can have the most technically rigorous data destruction process in the world, but if you can’t prove it happened, it might as well not have. Documentation transforms data destruction from an unverifiable claim into demonstrable compliance. Regulators, auditors, customers, and courts all require evidence, not assurances.
This guide covers what to document, how to structure it, and how to maintain records that withstand scrutiny from any direction.
The Three Layers of Documentation
Effective data destruction documentation operates at three levels:
Policy level: Your organisation’s documented policy for data destruction, setting out the principles, responsibilities, and standards that govern the process. This is the “what we commit to doing.”
Procedure level: Detailed, step-by-step procedures that describe how destruction is performed in practice. This is the “how we actually do it.”
Record level: Evidence that destruction was performed for specific assets on specific dates using specific methods. This is the “proof we did it.”
All three layers are necessary. A policy without procedures is aspirational. Procedures without records are unverifiable. Records without a policy lack governance context. Together, they form a complete documentation framework.
Layer 1: The Data Destruction Policy
Your data destruction policy should be a concise, board-approved document that establishes the governance framework. It should include:
Scope: What the policy covers. All data-bearing devices, all data types, all disposal scenarios (decommission, donation, sale, recycling, warranty return).
Responsibilities: Who is responsible for what. Typically, IT manages the technical process, information security provides oversight, legal advises on retention requirements, and senior management or the Board provides governance approval.
Data classification alignment: How destruction methods map to your data classification scheme. Higher sensitivity levels should require more rigorous destruction methods.
Standards referenced: The technical standards your process follows, such as NIST 800-88, ASD ISM, or ADISA guidelines.
Third-party requirements: Standards and certifications required of external disposal providers, including due diligence and monitoring expectations.
Review cycle: How often the policy is reviewed and updated. Annual review is the minimum expectation under most frameworks.
- Purpose and scope
- Roles and responsibilities
- Data classification and corresponding destruction methods
- Standards and references
- Third-party provider requirements
- Legal hold and retention interaction
- Incident management for disposal failures
- Review and approval history
Layer 2: Operational Procedures
Procedures translate policy into actionable steps. They should be detailed enough that someone unfamiliar with the process could follow them correctly. Key procedures to document include:
Device decommissioning procedure: How devices are taken out of service, who authorises decommission, how the device is registered in the disposal pipeline, and how it’s physically secured pending destruction.
Data destruction procedure by device type: Specific steps for wiping laptops, desktops, servers, phones, tablets, printers, network equipment, and any other device types in your environment. Different device types may require different tools and methods.
Verification procedure: How destruction is verified. For software wiping, this typically involves a verification scan that attempts to read the wiped media. For physical destruction, visual inspection confirms the media is destroyed beyond recovery.
Third-party handover procedure: Steps for preparing equipment for collection by a disposal provider, including manifest preparation, sealing containers, and obtaining signed collection receipts.
Certificate review procedure: How certificates of destruction from providers are reviewed, reconciled against manifests, and filed.
Legal hold check procedure: Steps for verifying devices against the legal hold register before they enter the destruction queue.
Layer 3: Individual Destruction Records
Records are the evidence layer. For every destruction event, you should have records that include:
Asset identification: Serial number, asset tag, device type, make, and model for each device destroyed.
Data classification: The classification level of data held on the device, which determines the required destruction method.
Destruction method: The specific method used (software overwrite to NIST 800-88 Purge, physical shredding, degaussing, cryptographic erasure, etc.) and the specific tool or equipment used.
Verification results: Confirmation that the destruction was verified and the outcome of that verification. For software wiping, the verification log from the wiping tool. For physical destruction, confirmation of media destruction.
Date and time: When the destruction was performed.
Personnel: Who performed the destruction and who verified it. If a third party performed it, their name, organisation, and the reference number of their certificate of destruction.
Certificate of destruction: The formal certificate, whether generated internally or received from a provider, linked to the specific assets.
Record-Keeping Systems
How you maintain records matters as much as what you record. Records should be accurate, complete, retrievable, and tamper-resistant.
Spreadsheet-based systems work for small organisations with low disposal volumes. A well-structured spreadsheet tracking each asset through the disposal pipeline, with links to scanned certificates, provides adequate documentation. The risk is human error, version control issues, and limited scalability.
IT asset management (ITAM) platforms provide better control for larger organisations. Most ITAM tools track assets through their lifecycle, including the disposal phase. Integration with barcode or RFID scanning reduces data entry errors. Some platforms generate disposal documentation automatically.
ITAD provider portals offered by many disposal companies provide real-time tracking and documentation. Equipment is scanned at collection, scanned at receipt, and scanned through the destruction process. Certificates are generated automatically and accessible through the portal. This provides excellent documentation for the provider’s portion of the chain, though you still need internal records for the decommission-to-handover phase.
Regardless of the system, records should be backed up and retained for the required period (typically 7 years, sometimes longer for specific regulatory requirements). Store them in a format that will remain accessible for the full retention period.
Common Documentation Mistakes
These documentation failures are the ones auditors find most frequently:
Batch-only records: Recording “50 laptops destroyed on 15 March” without listing individual serial numbers. This doesn’t allow verification that specific devices were destroyed.
Missing destruction method: Records show that devices were “disposed of” but don’t specify whether data was wiped, shredded, or simply given away. “Disposed” and “data destroyed” are not synonyms.
No verification evidence: The destruction is recorded but there’s no evidence it was verified. This is like recording that a lock was installed without confirming it actually locks.
Gaps in the timeline: A device was decommissioned in January, collected in March, and destroyed in April, but there’s no record of where it was or how it was secured between January and March.
Mismatched records: The collection manifest lists 30 items, the destruction certificate lists 28. The two missing items are unaccounted for, creating an audit finding and potential security incident.
Unsigned documents: Certificates and manifests without signatures or authorised approvals lack evidentiary weight.
Making Documentation Sustainable
Documentation that’s too burdensome to maintain consistently will eventually be abandoned. The key to sustainable documentation is building it into the workflow rather than treating it as a separate administrative task.
Use templates and checklists to standardise records. Automate where possible through scanning and ITAM integration. Assign clear responsibility for each documentation step. Audit regularly to catch and correct drift before it becomes systemic. And periodically review the documentation requirements themselves to ensure they’re adding value without unnecessary overhead.
- Every asset individually identified by serial number
- Destruction method specified for each asset or batch
- Standard referenced (NIST 800-88 level, ASD ISM classification, etc.)
- Verification results recorded
- Dates, times, and responsible personnel documented
- Chain of custody complete from decommission to destruction
- Certificates of destruction obtained and filed
- Records stored securely for the required retention period
- Regular reconciliation against asset register
Good documentation doesn’t just protect you during audits. It drives process discipline, enables continuous improvement, and provides the evidence that makes all other compliance claims credible.
For more on the broader disposal framework, see our guide to building an IT asset disposal policy and our complete guide to data destruction.
EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.
