How Are Assets Tracked During On-Site Destruction?
Assets are tracked during on-site destruction by recording each data-bearing device before it enters the destruction process, maintaining control over its movement, confirming that it has been processed and reconciling the final records against the original asset list.
The level of tracking can vary. Some organisations require every hard drive, SSD or tape to be recorded by serial number. Others may use controlled batch tracking, where a defined quantity of media is sealed, counted and processed under a single reference.
For businesses handling sensitive, confidential or regulated information, asset-level tracking usually provides the clearest evidence. It allows the organisation to show that a specific device was authorised, presented, destroyed and included in the final certificate or destruction report.
This is particularly important during on-site data destruction because the process often takes place in a busy operational environment. Data centres, IT departments, healthcare organisations, financial institutions and public-sector bodies may present hundreds or thousands of storage devices during a single project.
Without a controlled tracking system, drives can be omitted, duplicated, misidentified or mixed with equipment that has not yet been approved for destruction.
Effective tracking therefore combines asset records, physical security, chain-of-custody controls, operator checks and final reconciliation.
Why is asset tracking important during on-site destruction?
The purpose of asset tracking is to connect each physical device to reliable evidence showing what happened to it.
A destruction machine can process a hard drive in seconds, but that does not automatically prove which drive entered the machine. The organisation needs a record that links the device’s identifier to the destruction event.
Tracking helps answer important questions such as:
- Was this device authorised for destruction?
- Did the correct asset reach the processing area?
- Which destruction method was used?
- Was the device processed successfully?
- Did any assets remain outstanding?
- Does the certificate accurately reflect the completed work?
These questions matter because data security failures often occur through handling errors rather than failures of the destruction machinery itself.
For example, a drive may remain in a secure cupboard after the project because it was not included on the asset list. Another device may be collected but rejected because it does not fit the machine. A serial number may be scanned incorrectly, leaving uncertainty over whether the correct asset was processed.
A strong tracking process identifies these issues before the project is closed.
What information should be recorded before destruction begins?
Tracking normally starts before the destruction provider arrives on site.
The organisation should identify the data-bearing assets due for disposal and prepare an authorised destruction list. This creates a reference against which the provider can check the devices presented on the day.
The record may include:
- Manufacturer
- Model
- Serial number
- Internal asset tag
- Device type
- Storage capacity
- Source system or server
- Department or site location
- Data classification
- Reason for disposal
- Authorising manager
- Planned destruction method
Not every organisation will require all these details. The correct level of information depends on the size of the project, the organisation’s asset-management practices and the sensitivity of the data.
Why serial numbers are commonly used
A manufacturer’s serial number provides a unique identifier for a specific device.
This can make it easier to distinguish between similar hard drives or SSDs. In a data centre, for example, hundreds of drives may have the same manufacturer, model and storage capacity. Their serial numbers are often the only practical way to identify them individually.
Where possible, serial numbers should be scanned rather than typed manually. Scanning reduces the risk of transcription errors and can speed up high-volume projects.
However, labels may be scratched, damaged, missing or difficult to access. The process should therefore include an agreed way to handle exceptions.
Internal asset tags
Many organisations attach their own asset numbers to IT equipment.
These can be useful because they connect the destruction record to the organisation’s finance, procurement or configuration-management systems.
The internal asset tag may remain attached to the computer or server rather than the individual storage device. If drives are removed before destruction, the organisation should ensure that the correct relationship between the host equipment and the media is recorded.
For example, a server asset number may be linked to several individual hard drive serial numbers.
Device type and storage technology
Recording the media type is essential because not all devices can be destroyed using the same method.
The asset list should distinguish between:
- Magnetic hard disk drives
- Solid-state drives
- M.2 storage modules
- Backup tapes
- USB flash drives
- Memory cards
- Optical media
- Embedded storage devices
- Circuit boards containing memory
A magnetic hard drive may be suitable for degaussing or shredding. An SSD cannot be reliably erased through degaussing and requires a physical process that targets its flash memory components.
Identifying the media type before processing prevents assets from being assigned to unsuitable equipment.
How are assets transferred into the destruction process?
Once the assets have been identified, they should move through a controlled handover process.
The organisation should nominate an authorised representative to release the media. The destruction provider should nominate a responsible operator to accept it.
The handover record may include:
- Date and time
- Destruction location
- Names of the responsible parties
- Number of containers
- Container or seal references
- Total quantity of assets
- Asset schedule reference
- Any known discrepancies
- Signatures or digital confirmation
This creates the beginning of the destruction chain of custody.
Secure containers and staging areas
Hard drives and other media awaiting destruction should remain in secure containers or controlled storage.
During a large project, it may be safer to release assets in smaller groups rather than moving the entire batch into the processing area at once.
A typical workflow may involve:
- A sealed container is moved from secure storage to the processing area.
- The container reference is checked.
- Devices are removed one at a time.
- Each identifier is scanned or recorded.
- The device is processed.
- The destruction status is updated.
- Destroyed material is placed into a separate secure container.
This approach helps prevent intact and destroyed assets from becoming mixed.
The staging area should also be access-controlled. Only authorised representatives, operators and approved witnesses should be able to enter.
How are serial numbers linked to the destruction event?
The exact method depends on the provider’s tracking system.
In a basic process, an operator may scan the serial number and manually mark the device as destroyed after it passes through the machine.
More advanced systems may record a sequence of events, including the time of scanning, operator identity, equipment used and cycle completion.
A typical asset-level workflow may be:
- The serial number is scanned.
- The system checks it against the authorised asset list.
- The device type and required method are confirmed.
- The operator loads the asset into the equipment.
- The destruction cycle is completed.
- The operator verifies the physical result.
- The asset status changes from awaiting destruction to destroyed.
- The record is added to the final report.
Where equipment produces digital cycle records, the system may also link the processing time or machine reference to the asset.
This creates stronger evidence than a simple spreadsheet showing a list of serial numbers and a general statement that the batch was destroyed.
Can several assets be processed at once?
Some shredders or other destruction systems may accept multiple smaller items during one cycle.
This can increase throughput, but the provider must still maintain an accurate connection between the assets presented and the output.
For individually tracked devices, each identifier should be recorded before the assets enter the loading area. The system should then confirm that the complete group has been processed before the next group begins.
The operator should avoid creating batches so large that it becomes difficult to verify whether every item entered the machine.
What is chain of custody during on-site destruction?
The chain of custody is the documented history of who controlled the assets and where they were located before final destruction.
On-site destruction can shorten the chain because intact media does not need to travel to an external processing facility.
A typical on-site chain may include:
- The device is removed from service.
- It is placed in secure internal storage.
- Disposal is authorised.
- It is released to the destruction provider.
- Its identifier is recorded.
- It enters the approved destruction equipment.
- The completed process is verified.
- The remaining fragments are securely contained.
- The destruction record is issued.
Although the chain is shorter than it might be for off-site processing, every transfer still needs to be controlled.
The fact that the equipment is located at the client’s premises does not prevent a drive from being misplaced between the storage room and the processing area.
Who remains responsible for the assets?
The point at which responsibility transfers should be agreed clearly.
Some organisations retain formal custody until each device enters the machine. Others transfer custody to the provider when sealed containers are handed over within the site.
The contract or service agreement should define this.
The organisation should also know what happens to the destroyed fragments. Although the original media is no longer functional, any remaining memory components may still require secure containment or further shredding before recycling.
How are different media types controlled during the process?
Mixed-media projects require clear separation.
Hard drives, SSDs, tapes and small flash devices may all look like data-bearing IT assets, but they require different processes.
The destruction team may use separate containers, work queues or labels for each category.
For example:
- Magnetic hard drives may be assigned to a degausser or hard drive shredder.
- SSDs may be assigned to a specialist crusher or solid-state shredder.
- Backup tapes may be degaussed using equipment suitable for their magnetic properties.
- USB drives and memory cards may require equipment capable of producing smaller fragments.
- Unusual devices may be set aside for assessment.
The tracking record should show which method was used for each item.
A certificate that lists an SSD as degaussed would indicate a serious process error because SSD data is stored in flash memory rather than magnetically.
Accurate classification helps prevent this type of mistake.
What happens when an asset cannot be identified?
Unidentified assets should be treated as exceptions, not quietly included in the batch.
A serial number may be missing because:
- The label has been damaged
- The label was removed during disassembly
- The device has no visible identifier
- The identifier is obscured by a caddy or enclosure
- The barcode cannot be scanned
- The asset was not included on the original list
The provider and client should agree how these assets will be handled.
Possible approaches include:
- Recording the manufacturer, model and other visible details
- Photographing the device where permitted
- Assigning a temporary project reference
- Obtaining written approval before destruction
- Recording the asset as an unidentified item within a controlled batch
- Withholding the asset until ownership and authorisation are confirmed
An unidentified drive should not be destroyed automatically if there is uncertainty over whether it has been authorised.
At the same time, it should not be left unsecured while the issue is investigated.
How are damaged or unreadable serial numbers handled?
Damaged drives are common in destruction projects.
A failed hard drive may have been removed from a damaged server, storage array or laptop. Its label may be scratched, heat-damaged or contaminated.
The process should preserve as much evidence as possible.
Where the full serial number cannot be read, the operator may record:
- A partial serial number
- Manufacturer and model
- Capacity
- Internal asset reference
- Source equipment
- Physical description
- Exception code
- Client approval reference
The final report should make clear that the asset could not be identified through the normal method.
It should not invent or guess a serial number simply to complete the schedule.
What happens if an asset is on the list but cannot be found?
This is one of the most important reasons for reconciliation.
An organisation may present 499 of the 500 drives listed for destruction. The missing drive must be investigated before the project is closed.
Possible explanations include:
- The drive remains installed in equipment
- It is stored in another location
- It was previously destroyed
- The asset list contains a duplicate
- The serial number was recorded incorrectly
- The device was transferred to another site
- It was presented under a different identifier
The final certificate should cover only assets that were actually processed.
The missing device should remain open within the organisation’s asset-management or incident process until its location and status are confirmed.
Marking it as destroyed without evidence would undermine the entire audit trail.
What if an asset is presented but is not on the authorised list?
The same principle applies in reverse.
A device may be found within a container but not appear on the approved schedule.
The operator should not assume that it can be destroyed.
The device may:
- Still be in active use
- Contain records subject to retention requirements
- Belong to another department
- Be part of a legal hold
- Have been included accidentally
- Require data migration before disposal
- Need a different destruction method
The provider should set it aside securely and seek authorisation from the nominated client representative.
If approval is given, the asset should be added to the project record with a clear explanation.
How is destruction verified?
Tracking proves which assets entered the process. Verification helps confirm that the intended destruction result was achieved.
Verification may include several controls.
Machine-cycle confirmation
Some degaussers and destruction machines record whether the operating cycle completed successfully.
This can support the audit trail, particularly when the cycle record is linked to the asset scan.
However, a completed cycle does not automatically prove that the physical outcome was sufficient. The equipment must still be suitable for the media.
Visual inspection
An operator may inspect the processed device or fragments.
For hard drives, this may involve checking that the casing and internal platters have been shredded or severely deformed.
For SSDs, the inspection should focus on whether the circuit board and flash memory packages have been sufficiently damaged.
A bent casing alone should not be accepted as proof of secure SSD destruction.
Witnessed destruction
Client representatives may observe the process.
This can be particularly valuable for organisations that require direct oversight or internal sign-off.
The witness may confirm that:
- The approved assets were presented
- Serial numbers were checked
- The correct machinery was used
- Devices entered the equipment
- No intact media remained in the processing area
Witnessing should support the written records rather than replace them.
How are records reconciled at the end?
Reconciliation compares the planned destruction list with the actual processing results.
The provider should confirm:
- How many assets were authorised
- How many were presented
- How many were destroyed
- How many were rejected or withheld
- How many could not be identified
- Whether any assets remain outstanding
- Whether additional assets were authorised during the project
A simple example might be:
- 1,000 drives authorised
- 998 presented
- 995 destroyed successfully
- Two rejected because they required different equipment
- One withheld because the serial number could not be matched
- Two not presented and still under investigation
The final documentation should reflect this result accurately.
It should not state that all 1,000 drives were destroyed merely because that was the original planned quantity.
Why reconciliation should happen promptly
Discrepancies are easier to resolve while the project is still active.
The relevant staff, containers, records and equipment are available, making it more likely that a missing device or data-entry error can be identified.
Waiting several weeks before checking the final asset list can make investigation much harder.
What evidence should the organisation receive?
The documentation should reflect the agreed level of tracking.
It may include:
- Certificate of destruction
- Individual asset or serial-number schedule
- Chain-of-custody record
- Collection or handover record
- Destruction date and location
- Processing method
- Exception report
- Witness confirmation
- Cycle or machine records
- Material handling or recycling records
The certificate should identify the project clearly and connect to any separate asset schedules.
For example, the certificate may state that the assets listed in an attached serial-number report were destroyed at the client’s premises using a specified method.
What should a strong certificate show?
A useful certificate may include:
- Client organisation
- Destruction provider
- Unique project reference
- Processing location
- Date of destruction
- Type of media
- Quantity processed
- Destruction method
- Asset schedule reference
- Authorised signatory
- Confirmation of completed destruction
It should be issued after the process and reconciliation are complete.
A document issued at the moment of collection may confirm receipt, but it cannot reliably confirm destruction that has not yet occurred.
Is batch tracking ever sufficient?
Yes, depending on the organisation’s requirements and the risk associated with the media.
Batch tracking may be appropriate when individual identifiers are unavailable or when large numbers of small, similar devices are processed under controlled conditions.
A secure batch process should include:
- A verified count or weight.
- A unique batch reference.
- A sealed container.
- Controlled handover.
- Confirmed processing of the entire batch.
- A record of the destruction method.
- Reconciliation of the container and final output.
Batch tracking is more reliable when the container remains sealed until it reaches the destruction area and the full contents are processed without interruption.
However, it does not provide the same level of evidence as individual serial-number tracking.
Organisations handling high-risk data should consider whether asset-level records are more appropriate.
How can organisations prepare for reliable tracking?
Good preparation can significantly improve the speed and accuracy of an on-site destruction project.
Before the visit, the organisation should:
- Create an authorised asset list
- Confirm which identifiers will be recorded
- Separate hard drives, SSDs, tapes and other media
- Remove devices from caddies where agreed
- Check whether serial numbers are visible
- Place assets in secure labelled containers
- Nominate an authorised handover representative
- Identify any legal holds or exceptions
- Confirm witness requirements
- Agree how unidentified assets will be treated
- Confirm the required certificate format
This preparation prevents delays caused by inaccessible labels, mixed media or unclear authority.
The provider should also explain its own tracking system before work begins. The organisation should understand whether records are scanned, typed manually, recorded by batch or linked to machine cycles.
Frequently Asked Questions
Does every hard drive need to be tracked by serial number?
Not always. The required level of tracking depends on the organisation’s policies, data sensitivity and audit requirements. Serial-number tracking generally provides stronger evidence than a simple batch count.
Can asset tags be used instead of serial numbers?
Yes, provided the internal asset tag uniquely identifies the device and remains connected to the organisation’s asset register. In some projects, both serial numbers and asset tags are recorded.
What happens if a barcode will not scan?
The identifier can be entered manually or recorded through an approved exception process. The final report should show that the asset required manual verification.
Can destroyed fragments be linked back to individual drives?
Once several devices have been shredded together, individual fragments may no longer be distinguishable. This is why asset identification and recording must take place before destruction.
Who should witness on-site destruction?
The witness may be an authorised representative from IT, information security, compliance, facilities management, data protection or internal audit.
Should rejected assets appear on the certificate?
They should not be marked as destroyed. They may appear on an exception report showing why they were rejected and what further action is required.
Can mobile phones and USB devices be included in the same tracking system?
Yes. The tracking system can cover different media categories, but the record should identify the device type and the correct destruction method used.
How soon should the final asset report be checked?
The organisation should review it as soon as possible after destruction. Prompt reconciliation makes missing devices and recording errors easier to investigate.
Asset tracking during on-site destruction creates the connection between the original data-bearing device and the final evidence of its destruction.
A reliable process starts with an authorised asset list and secure storage. Each device is then identified, transferred into a controlled processing area, assigned to the correct destruction method and marked as completed only after verification.
The final records should identify any missing, additional, rejected or unidentified assets. They should not hide discrepancies simply to make the totals match.
For organisations handling sensitive information, individual serial-number tracking often provides the strongest audit trail. Controlled batch tracking may also be suitable where it reflects the organisation’s risk assessment and documented procedures.
Varese Secure provides on-site data destruction for organisations requiring secure handling, clear asset traceability and certified processing. To discuss asset-level tracking, witnessed destruction or the documentation required for your project, contact the team.
Contact Varese Secure Ltd
Phone: 01489 854 131
Email: sales@varese-secure.co.uk
Find out more: https://varese-secure.co.uk/
-
Can a Certificate of Destruction Prove Data Has Been Permanently Destroyed?
19 August 2026A certificate of data destruction provides important evidence that a storage device or batch of media was processed using a stated destruction method. However, the certificate does not independently prove that data has been permanently…
Read More about Can a Certificate of Destruction Prove Data Has Been Permanently Destroyed? -
What Does GDPR Compliant Data Disposal Mean for Businesses?
12 August 2026GDPR compliant data disposal means removing personal data securely when a business no longer has a valid reason to retain it. The disposal method should prevent unauthorised access before, during and after the process, while…
Read More about What Does GDPR Compliant Data Disposal Mean for Businesses? -
Are SSD Crushers Suitable for Data Centres and IT Departments?
5 August 2026SSD crushers can be suitable for data centres and IT departments, provided the equipment is designed specifically for solid-state media and produces a level of physical destruction appropriate to the sensitivity of the data. They…
Read More about Are SSD Crushers Suitable for Data Centres and IT Departments?