Procurement teams play a critical role in IT asset disposition, even though ITAD is not always recognised as a procurement function. Selecting the right ITAD vendor, negotiating favourable terms, and integrating disposal planning into the procurement lifecycle can significantly improve financial outcomes and reduce organisational risk.
This guide walks procurement professionals through the key considerations for selecting and managing an ITAD vendor.
Why Procurement Should Own the ITAD Vendor Relationship
ITAD vendor selection is fundamentally a procurement activity. It involves evaluating suppliers, negotiating contracts, managing performance, and optimising value. Yet in many organisations, the ITAD relationship is managed by IT or facilities without procurement involvement, which often results in suboptimal commercial terms and missed opportunities.
Procurement teams bring structured evaluation methodologies, negotiation expertise, and supplier management discipline that can materially improve ITAD outcomes. They also bring the perspective of total lifecycle cost, which is essential for making good decisions about equipment acquisition, use, and disposal.
Defining Your Requirements
Before evaluating vendors, you need to clearly define what your organisation needs from an ITAD provider. Key requirements to document include the types and volumes of equipment you dispose of annually, your data destruction requirements and the standards they must meet, geographic coverage needed (single site, multi-site, national), the level of reporting and documentation you require, any industry-specific compliance requirements, your expectations around value recovery, and logistical requirements such as on-site collection versus drop-off.
Be specific about data destruction requirements in particular. Specify the standard (such as NIST 800-88), the verification method, the documentation format, and any requirements for witnessed destruction. Vague requirements lead to inconsistent service and potential compliance gaps.
Vendor Evaluation Criteria
A structured evaluation framework helps you compare ITAD vendors objectively. The key criteria fall into several categories.
Certifications and credentials are your first filter. Look for providers that hold relevant industry certifications. R2 (Responsible Recycling) and e-Stewards are the two primary ITAD certifications. ISO 14001 (environmental management), ISO 9001 (quality management), and ISO 27001 (information security) provide additional assurance. AS/NZS 5377 compliance is particularly relevant for Australian operations.
Data destruction capabilities must match your requirements. Evaluate the provider’s destruction methods, verification processes, documentation quality, and chain of custody procedures. Ask for sample certificates of destruction and assess whether they meet your organisation’s needs. Determine whether the provider can offer both software-based sanitisation and physical destruction.
Financial stability matters because you are entrusting sensitive equipment to this vendor. Request financial statements or credit reports. A provider that goes out of business while holding your equipment creates a significant security and financial risk. Larger, established providers generally present lower counterparty risk.
Remarketing capability directly affects your value recovery. Assess the provider’s access to secondary markets, their refurbishment capabilities, their track record of value recovery for equipment similar to yours, and whether they operate their own remarketing channel or use third parties.
Commercial Models
ITAD vendors offer several commercial models, and understanding the differences is essential for negotiating the best arrangement.
Fee-for-service is the simplest model. You pay a per-unit or per-collection fee, and the vendor retains any resale proceeds. This model is predictable but typically delivers the lowest net financial outcome because you are not sharing in value recovery.
Revenue share models split the proceeds from equipment resale between you and the vendor. Typical splits range from 50/50 to 80/20 in the client’s favour, depending on equipment volumes, values, and the vendor’s processing costs. This model aligns incentives because both parties benefit from maximising resale values.
Guaranteed buy-back models provide a fixed price per unit regardless of resale outcome. The vendor assumes the market risk. This model offers budget certainty but may deliver lower returns than revenue share in a strong market.
Hybrid models combine elements of the above. For example, you might pay a fee for data destruction and receive a revenue share on remarketing proceeds. The right model depends on your priorities: certainty versus upside, simplicity versus optimisation.
Contract Negotiation
Key contract terms to negotiate include pricing and commercial model (as above), service level agreements covering collection response times, processing turnaround, and reporting timelines, data destruction standards and documentation requirements, liability and indemnification provisions particularly around data breaches, insurance requirements for the vendor, minimum and maximum volume commitments, contract term and termination provisions, and audit rights allowing you to inspect the vendor’s facilities and processes.
Pay particular attention to the liability provisions. If a data breach occurs because the vendor failed to properly destroy data, the contract should clearly allocate liability to the vendor and require them to carry adequate insurance. Your legal team should review these provisions carefully.
Due Diligence Process
Before finalising your vendor selection, conduct thorough due diligence. This should include a facility visit to see the vendor’s processing operations firsthand, reference checks with existing clients of similar size and industry, review of the vendor’s security practices and incident history, verification of all claimed certifications and accreditations, and assessment of the vendor’s business continuity and disaster recovery plans.
The facility visit is particularly important. Seeing how the vendor handles equipment, manages data destruction, and maintains security gives you insights that cannot be gained from documentation alone. Look for well-organised facilities, clear separation between pre-destruction and post-destruction areas, security cameras, access controls, and evidence of systematic processes.
Ongoing Vendor Management
Selecting the right vendor is only the beginning. Effective ongoing management ensures consistent performance and continuous improvement. Establish regular review meetings, typically quarterly, to review performance against SLAs, discuss any issues or incidents, review financial performance and value recovery trends, and plan for upcoming disposition activities.
Conduct an annual strategic review that evaluates the overall vendor relationship, benchmarks performance against market alternatives, and identifies opportunities for improvement. This review should inform whether to extend, renegotiate, or tender the contract.
EWV handles IT asset disposition (ITAD) end-to-end for Victorian businesses — from collection and data destruction through to certified recycling or refurbishment for resale. Get in touch for a tailored ITAD quote.
