Why Annual Audits of Data Destruction Matter
Even well-designed data destruction processes drift over time. Staff changes, new device types enter the environment, providers change their practices, and small shortcuts accumulate into significant gaps. An annual audit of your data destruction process catches this drift before it becomes a compliance failure or, worse, a data breach.
Most compliance frameworks either require or expect periodic auditing of information security controls, including disposal. ISO 27001 mandates internal audits. APRA CPS 234 requires assurance from the internal audit function. PCI DSS expects regular review of security controls. Even where auditing isn’t explicitly required, it’s the primary mechanism for demonstrating ongoing due diligence.
Scope of the Audit
A comprehensive data destruction audit should cover four areas: policy, process, records, and providers.
Policy review: Is the data destruction policy current? Does it reflect the organisation’s current device landscape, data classifications, and regulatory obligations? Has it been reviewed and approved within the past 12 months? Does it cover all device types in use, including any new categories introduced during the period?
Process assessment: Are the documented procedures being followed in practice? Is there consistency in how destruction is performed across different teams, locations, and device types? Are the destruction methods still appropriate for the media types being processed?
Records examination: Are records complete, accurate, and properly maintained? Can you trace a random sample of disposed assets from the asset register through to the destruction certificate? Are there any gaps or discrepancies?
Provider evaluation: Are third-party disposal providers still meeting the standards required under your contract? Are their certifications current? Have there been any changes in their operations that affect their capability?
- Policy: Currency, completeness, approval status
- Process: Adherence, consistency, appropriateness
- Records: Completeness, accuracy, reconciliation
- Providers: Certification status, contractual compliance, performance
Policy Audit Checklist
Review the data destruction policy against these criteria:
Is the policy dated and showing a review within the past 12 months? Does it cover all device types currently in the organisation’s environment (including any new categories like IoT devices, smart screens, or wearables)? Does the policy reference current standards (NIST 800-88 Rev. 2, ISO 27001:2022)? Does it align with current regulatory requirements (including any changes to the Privacy Act, state legislation, or sector-specific regulations)? Are roles and responsibilities still accurate (have the named responsible parties changed roles or left the organisation)? Does the policy address data classification and the corresponding destruction methods? Is the legal hold interaction documented? Has the policy been approved by an appropriate authority (CISO, senior management, or Board)?
Process Audit: Testing Adherence
The most revealing part of the audit is comparing documented procedures against actual practice. Methods for testing include:
Observation: Watch the destruction process in action, either at your own facility or at the provider’s site. Does it match the documented procedure? Are all steps being followed? Is verification being performed?
Staff interviews: Talk to the people who actually perform or manage the destruction process. Do they know the policy? Can they describe the procedure? Are they aware of their responsibilities? Have they received training in the past 12 months?
Sample testing: Select a random sample of devices from the disposal queue or recently disposed assets. Trace them through the process. For software-wiped devices, check the wiping logs. For physically destroyed devices, verify that the destruction certificate corresponds to the correct assets.
Scenario testing: Present hypothetical scenarios to the team. “What happens if a device subject to a legal hold enters the destruction queue?” “What if a collection manifest doesn’t match the received items?” “What if a device can’t be wiped because it’s physically damaged?” Their responses indicate whether the process covers edge cases.
Records Audit: Reconciliation and Completeness
Records auditing is where most findings emerge. The core exercise is reconciliation: matching records across different stages to identify gaps and discrepancies.
Asset register reconciliation: Compare the list of devices shown as “disposed” or “decommissioned” in your asset register against your destruction certificates. Every disposed device should have a corresponding destruction record. Devices that are missing from the register or unaccounted for represent potential security gaps.
Manifest-to-certificate matching: For each disposal batch, compare the collection manifest (what was sent to the provider) against the destruction certificate (what the provider says they destroyed). The item counts and serial numbers should match exactly. Discrepancies require investigation.
Timeliness check: How long does it take from decommission to destruction? Excessive delays increase the risk window. If devices are sitting in staging areas for months before processing, the chain of custody controls during that period need to be robust.
Completeness check: For each record, verify that all required fields are populated: serial number, device type, destruction method, verification result, date, responsible person, and certificate reference. Incomplete records reduce the evidentiary value of the documentation.
Provider Audit
If you use third-party disposal providers, annual assessment of their continued suitability is essential.
Certification verification: Confirm that all certifications claimed by the provider (ADISA, ISO 27001, AS/NZS 5377, ISO 14001) are current. Certifications expire and are sometimes not renewed. Ask for copies of current certificates.
Insurance verification: Confirm that the provider’s insurance (public liability, professional indemnity, cyber liability) is current and adequate for the value of the data they handle.
Facility visit: If you haven’t visited the provider’s facility recently, schedule a visit as part of the audit. Look for changes in operations, security controls, staffing, and equipment. A provider that was excellent two years ago may have changed significantly.
Performance review: Assess the provider’s performance over the past year. Have certificates been delivered on time? Have there been any discrepancies in manifests? Have any incidents occurred? Has communication been responsive and professional?
Contractual compliance: Review whether the provider is meeting all contractual requirements, including destruction methods, documentation standards, turnaround times, and security controls.
Reporting Findings
Audit findings should be documented in a structured report that’s distributed to the appropriate stakeholders.
The report should include an executive summary of overall compliance status, detailed findings categorised by severity (critical, major, minor, observation), specific evidence supporting each finding, recommended remediation actions with suggested timelines, and a comparison against previous audit findings to demonstrate whether prior issues have been resolved.
Critical findings, such as devices unaccounted for, missing destruction certificates for sensitive data, or provider certifications that have lapsed, should be escalated immediately rather than waiting for the full report.
For organisations subject to APRA CPS 234, audit findings should be included in the internal audit report to the Board Audit Committee. For ISO 27001-certified organisations, findings feed into the management review process and the corrective action system.
Remediation Tracking
An audit is only valuable if findings are acted on. Each finding should be assigned to a responsible party with a target remediation date. Progress should be tracked and reported until all findings are resolved.
- Month 1: Plan the audit scope, schedule provider visits and staff interviews
- Month 2: Conduct fieldwork: policy review, process observation, records sampling
- Month 2-3: Provider assessment and facility visits
- Month 3: Draft findings report and distribute for management response
- Month 3-4: Finalise report with remediation plans and timelines
- Ongoing: Track remediation progress quarterly until all findings are resolved
Annual destruction audits are an investment in compliance confidence. They catch problems early, demonstrate governance discipline to regulators and auditors, and drive continuous improvement in a process where the consequences of failure can be severe.
For more on building the foundation these audits assess, see our guide to building an IT asset disposal policy and our complete guide to data destruction.
EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.
