🔒 Free Onsite Hard Drive Shredding · Witnessed Destruction · Greater Phoenix AreaSee Mobile Shredding
Vendor Due Diligence · 2026 Edition

ITAD Vendor Due Diligence Checklist: 25 Questions to Ask Before Hiring

Choosing the wrong ITAD vendor can result in data breaches, compliance failures, and environmental violations. This checklist covers the 25 most important questions to ask any ITAD vendor before signing a contract — and what the right answers look like.

Questions 1–8

Certification & Compliance

  • Q1.Are you R2 certified?

    Right AnswerYes, R2v3 — verify at sustainableelectronics.org
  • Q2.Are you NAID AAA certified?

    Right AnswerYes — verify at isigma.org
  • Q3.Do you hold ISO 27001 certification?

    Right AnswerYes
  • Q4.Are you HIPAA compliant with BAA available?

    Right AnswerYes, Business Associate Agreement available
  • Q5.Can I verify your certifications directly with the certifying bodies?

    Right AnswerYes, always
  • Q6.When were your certifications last audited?

    Right AnswerWithin the last 12 months
  • Q7.Do you have a compliance documentation package I can review?

    Right AnswerYes, available upon request
  • Q8.What compliance frameworks do your Certificates of Destruction satisfy?

    Right AnswerHIPAA, SOX, GLBA, PCI-DSS, CMMC, FERPA
Questions 9–14

Data Destruction Methods

  • Q9.What data destruction methods do you use for HDDs?

    Right AnswerNIST 800-88 Purge (degaussing or overwrite) plus physical shredding option
  • Q10.What data destruction methods do you use for SSDs?

    Right AnswerCryptographic erase, block erase, or physical shredding
  • Q11.Do you provide individual Certificates of Destruction for every device?

    Right AnswerYes, with serial numbers
  • Q12.Can I witness the destruction of my hard drives?

    Right AnswerYes — onsite or at our facility
  • Q13.Do you use NSA EPL-listed degaussers?

    Right AnswerYes
  • Q14.How do you handle RAID arrays?

    Right AnswerIndividual destruction of every drive in the array
Questions 15–19

Chain of Custody & Security

  • Q15.How do you track assets from pickup to destruction?

    Right AnswerBarcode tracking with GPS transport logs and 24/7 client portal access
  • Q16.Do your personnel undergo background checks?

    Right AnswerYes — required by NAID AAA certification
  • Q17.What insurance do you carry?

    Right AnswerGeneral liability, professional liability, cyber liability, and cargo
  • Q18.Do you use tamper-evident seals during transport?

    Right AnswerYes, with numbered seals recorded in the manifest
  • Q19.Can I access my chain-of-custody documentation 24/7?

    Right AnswerYes — through secure client portal
Questions 20–23

Environmental & Downstream

  • Q20.Do you have a zero-landfill policy?

    Right AnswerYes — guaranteed and audited annually
  • Q21.Can I see your downstream vendor list?

    Right AnswerYes — R2v3 requires this transparency
  • Q22.How do you audit your downstream vendors?

    Right AnswerAnnual audits required by R2v3 certification
  • Q23.Do you comply with the Basel Convention?

    Right AnswerYes — no illegal export of e-waste
Questions 24–25

Service & Logistics

  • Q24.What is your pickup response time?

    Right Answer24 hours for Phoenix metro area
  • Q25.Do you assign a dedicated project manager?

    Right AnswerYes — for all enterprise engagements
Our Score: 25 / 25

How Phoenix ITAD Answers These 25 Questions

Phoenix ITAD answers “yes” to every question on this checklist. We hold R2v3, NAID AAA, and ISO 27001 certifications, carry all four types of insurance, and provide complete chain-of-custody documentation for every engagement. Request our vendor qualification package to receive our full answers to all 25 questions.

Walk Away Signals

10 Red Flags That Should End the Conversation

If a vendor exhibits any of these warning signs during your evaluation, treat it as disqualifying. The risk of a downstream data breach, EPA violation, or failed HIPAA / SOX audit far outweighs any short-term cost savings.

  • 1

    Won't let you verify certifications directly with R2 (sustainableelectronics.org) or NAID (isigma.org).

  • 2

    Refuses to sign a Business Associate Agreement (BAA) for HIPAA-covered data.

  • 3

    Issues a single bulk Certificate of Destruction instead of serial-number-level documentation.

  • 4

    Can't or won't produce a downstream vendor list — R2v3 explicitly requires this transparency.

  • 5

    No tamper-evident seals, GPS-tracked transport, or background-checked personnel.

  • 6

    Quotes that seem too cheap — legitimate certified destruction has real cost; deep-discount vendors often illegally export e-waste.

  • 7

    Pressures you to skip witnessed destruction or onsite shredding when your policy requires it.

  • 8

    Carries only general liability — no cyber liability or professional liability coverage.

  • 9

    Can't provide a sample chain-of-custody report or client portal walkthrough before contract.

  • 10

    Last certification audit was more than 12 months ago, or 'pending renewal' for an extended period.

Common Questions

How to Choose a Secure ITAD Vendor

How to choose a secure ITAD vendor

Verify R2v3 and NAID AAA certifications directly with the certifying bodies, require a signed BAA when ePHI is in scope, insist on serial-number-level Certificates of Destruction, review the vendor's downstream recycler list, and confirm they carry cyber liability — not just general liability — insurance. The 25-question checklist above walks through the full due diligence process.

How do ITAD vendors track asset chain of custody

A compliant ITAD vendor tracks every device by serial number from pickup to destruction using barcoded manifests, numbered tamper-evident seals, GPS-tracked transport, background-checked personnel, and a 24/7 client portal with signed pickup and receiving manifests plus a per-device Certificate of Destruction that ties back to the original manifest ID.