What ISO 27001 Annex A 7.14 Requires for IT Disposal

What ISO 27001 Annex A 7.14 Requires for IT Disposal

ISO 14001 · ICO Registered · Environment Agency Licensed Carrier · JOSCAR Registered · FSQS Registered

8 September 2026

Most organisations meet their disposal obligation the week before an audit, when someone asks
where the old laptops went. ISO 27001 is usually the reason the question gets asked at all, because
one of its Annex A controls is specifically about equipment leaving your control.

What the control actually says

In the 2022 edition of ISO/IEC 27001, Annex A control 7.14 is titled
Secure disposal or re-use of equipment. It applies to any item of equipment
containing storage media, which in practice means most of the estate.

The control expects four things.

  • Verification before the equipment leaves. Sensitive data and licensed software
    must be removed or securely overwritten, and that removal must be verified rather than assumed.
  • Physical destruction of storage media where the media is not being re-used.
  • Removal of identifying labels and markings, including asset tags that reveal
    the organisation the device came from.
  • A documented procedure covering disposal and re-use across the organisation,
    rather than a decision taken per device by whoever is clearing the cupboard.

What it does not do is name a method. There is no shred size in the control, no mandated
software, no approved supplier list. The requirement is that the action is proportionate to the
sensitivity of the data and that you can show it happened.

The word auditors care about is “verified”

Almost every organisation can describe a disposal process. Far fewer can produce evidence tied
to a specific device. That is the gap Annex A 7.14 is written to close, and it is where audits
tend to stall.

The practical test is simple. Pick a laptop off last year’s asset register, one that has since
been retired, and ask what happened to it. If the answer is a collection note covering forty items,
that is a process description. If the answer names the serial number, the method used and the date,
that is evidence.

Licensed software is the part everyone forgets

The control asks you to remove sensitive data and licensed software. The second half
gets overlooked because it is not a security risk in the usual sense, but a device leaving your
control with your licensed software still installed is a licensing exposure as well as an
information one. It is worth adding to the disposal checklist explicitly, because an auditor
reading the control will.

How this sits alongside the destruction standards

Annex A 7.14 tells you that disposal must be secure and verifiable. It does not tell you how.
The standards that answer that question are different documents, and a disposal contract usually
names one of them.

NIST SP 800-88 supplies the method vocabulary of Clear, Purge and Destroy. BS EN 15713:2023 is
the British and European code of practice governing how destruction is actually carried out, and it
is certifiable. Where government data is involved, HMG IA Standard No. 5 governs instead.
The three are compared here.

So the honest answer to “which standard do we need for ISO 27001” is that 27001 does not require
any of them by name. It requires that whatever you do is proportionate and evidenced, and naming a
recognised destruction standard is the simplest way to demonstrate that.

What to keep for the audit

  • A certificate of destruction naming each device serial number, not each collection.
  • The method applied to each device, so a Purge and a Destroy are distinguishable.
  • Time-stamped chain of custody from your site to the point of destruction.
  • Your own disposal procedure, showing the decision rule for when equipment is destroyed rather
    than re-used.
  • WEEE evidence notes, which are a separate legal obligation but tend to be asked for in the same
    conversation.

How Surplex UK Limited handles it

Every device is recorded against its serial number and issued a certificate of destruction, with
the method named. Hard drives and solid state drives are shredded mechanically to BS EN 15713:2023,
the Destroy method defined by NIST 800-88, and where value is recovered from hardware the data is
erased with Certus certified software to the same standard’s Purge method. Chain of custody is
time-stamped from collection, and the records sit in your portal rather than arriving by email when
you ask.

Collections run across England, Wales and Scotland, and there is no minimum quantity. Most
customers find their collection is free, because the value recovered from the hardware is set
against the cost of the work under an open-book value-offset model. Where the recovered value does
not cover it, a small logistics and processing fee is payable, quoted and agreed upfront.

Related reading: which disposal document you need for each asset type.

Frequently asked questions

Does ISO 27001 require a specific data destruction standard?2026-09-08T08:45:52+01:00

No. Annex A control 7.14 requires that disposal or re-use is secure, proportionate to the sensitivity of the data, and verified. It names no shred size, no software and no approved supplier. Naming a recognised standard such as BS EN 15713:2023 or NIST 800-88 is simply the clearest way to demonstrate that the action was proportionate.

What evidence does an ISO 27001 auditor ask for on disposal?2026-09-08T08:45:53+01:00

Evidence tied to a device rather than to a collection. In practice that means a certificate of destruction naming each serial number, the method applied to it, a time-stamped chain of custody, and your own documented disposal procedure. A collection note covering forty items describes a process; it does not evidence one.

What is ISO 27001 Annex A 7.14?2026-09-08T08:45:53+01:00

It is the control titled “Secure disposal or re-use of equipment” in the 2022 edition of ISO/IEC 27001. It applies to any equipment containing storage media and requires that sensitive data and licensed software are removed or securely overwritten and verified before the equipment leaves your control, that media is physically destroyed where it is not being re-used, that identifying labels are removed, and that a documented procedure covers this.

Do we need to remove asset tags before disposal?2026-09-08T08:45:54+01:00

The control asks for identifying labels and markings to be removed, and asset tags are the obvious case because they link a device back to your organisation. It is worth agreeing with your disposal supplier who removes them and at what point, so it is not discovered during an audit that neither side did.

Does the control cover licensed software as well as data?2026-09-08T08:45:54+01:00

Yes, and it is the half most often missed. Annex A 7.14 asks that sensitive data and licensed software are removed or overwritten. A device leaving your control with your licensed software still installed is a licensing exposure as well as an information one, so it belongs on the disposal checklist explicitly.

Focused Disposal & Data Security

IT and Technology Recycling

Zero-to-landfill WEEE recycling for all your end-of-life IT and electronics. Environment Agency licensed, with WEEE evidence notes and Scope 3 carbon data for every collection.

Data Destruction & Sanitisation

Certified Certus erasure and on-site hard drive shredding, destroyed to NIST 800-88 standards – with a certificate of destruction for every device and a BS EN 1143-1 rated strong room behind it.

Battery & UPS Disposal

Safe, compliant disposal of batteries and UPS systems, including lithium-ion, handled by ADR-licensed teams. Collect it alongside your IT in a single visit.

Comprehensive IT Solutions

Secure Business IT Asset Disposal

Certified, end-to-end retirement of your IT hardware with a vetted chain of custody from the moment it leaves site – full compliance documentation, and value recovered from redundant hardware.

Managed ITAD & Asset Value Recovery

A governed disposal programme for larger estates: maximise the value recovered, automate compliance, and report your Scope 3 impact – with portal integrations for ServiceNow, Microsoft Endpoint Manager and Jira.

IT Asset Management Software

See and control your whole estate in real time — live valuations, compliance that files itself, and one-click disposal. Free to our clients.

The Surplex Portal showing tracked IT assets and their current value

Get in Touch About Your IT Recycling Needs

We provide IT recycling services for organisations of all sizes across England, Wales and Scotland.

Whether you’re recycling a few old laptops, decommissioning a data centre, or need secure data destruction, our team will help you dispose of IT equipment compliantly and responsibly.

Prefer to speak with us directly?

Call: +44 (0)1684 252583
Email:
info@surplex.co.uk
Monday-Friday, 9am-5pm

Go to Top