Most organisations meet their disposal obligation the week before an audit, when someone asks
where the old laptops went. ISO 27001 is usually the reason the question gets asked at all, because
one of its Annex A controls is specifically about equipment leaving your control.
What the control actually says
In the 2022 edition of ISO/IEC 27001, Annex A control 7.14 is titled
Secure disposal or re-use of equipment. It applies to any item of equipment
containing storage media, which in practice means most of the estate.
The control expects four things.
- Verification before the equipment leaves. Sensitive data and licensed software
must be removed or securely overwritten, and that removal must be verified rather than assumed. - Physical destruction of storage media where the media is not being re-used.
- Removal of identifying labels and markings, including asset tags that reveal
the organisation the device came from. - A documented procedure covering disposal and re-use across the organisation,
rather than a decision taken per device by whoever is clearing the cupboard.
What it does not do is name a method. There is no shred size in the control, no mandated
software, no approved supplier list. The requirement is that the action is proportionate to the
sensitivity of the data and that you can show it happened.
The word auditors care about is “verified”
Almost every organisation can describe a disposal process. Far fewer can produce evidence tied
to a specific device. That is the gap Annex A 7.14 is written to close, and it is where audits
tend to stall.
The practical test is simple. Pick a laptop off last year’s asset register, one that has since
been retired, and ask what happened to it. If the answer is a collection note covering forty items,
that is a process description. If the answer names the serial number, the method used and the date,
that is evidence.
Licensed software is the part everyone forgets
The control asks you to remove sensitive data and licensed software. The second half
gets overlooked because it is not a security risk in the usual sense, but a device leaving your
control with your licensed software still installed is a licensing exposure as well as an
information one. It is worth adding to the disposal checklist explicitly, because an auditor
reading the control will.
How this sits alongside the destruction standards
Annex A 7.14 tells you that disposal must be secure and verifiable. It does not tell you how.
The standards that answer that question are different documents, and a disposal contract usually
names one of them.
NIST SP 800-88 supplies the method vocabulary of Clear, Purge and Destroy. BS EN 15713:2023 is
the British and European code of practice governing how destruction is actually carried out, and it
is certifiable. Where government data is involved, HMG IA Standard No. 5 governs instead.
The three are compared here.
So the honest answer to “which standard do we need for ISO 27001” is that 27001 does not require
any of them by name. It requires that whatever you do is proportionate and evidenced, and naming a
recognised destruction standard is the simplest way to demonstrate that.
What to keep for the audit
- A certificate of destruction naming each device serial number, not each collection.
- The method applied to each device, so a Purge and a Destroy are distinguishable.
- Time-stamped chain of custody from your site to the point of destruction.
- Your own disposal procedure, showing the decision rule for when equipment is destroyed rather
than re-used. - WEEE evidence notes, which are a separate legal obligation but tend to be asked for in the same
conversation.
How Surplex UK Limited handles it
Every device is recorded against its serial number and issued a certificate of destruction, with
the method named. Hard drives and solid state drives are shredded mechanically to BS EN 15713:2023,
the Destroy method defined by NIST 800-88, and where value is recovered from hardware the data is
erased with Certus certified software to the same standard’s Purge method. Chain of custody is
time-stamped from collection, and the records sit in your portal rather than arriving by email when
you ask.
Collections run across England, Wales and Scotland, and there is no minimum quantity. Most
customers find their collection is free, because the value recovered from the hardware is set
against the cost of the work under an open-book value-offset model. Where the recovered value does
not cover it, a small logistics and processing fee is payable, quoted and agreed upfront.
Related reading: which disposal document you need for each asset type.
Frequently asked questions
No. Annex A control 7.14 requires that disposal or re-use is secure, proportionate to the sensitivity of the data, and verified. It names no shred size, no software and no approved supplier. Naming a recognised standard such as BS EN 15713:2023 or NIST 800-88 is simply the clearest way to demonstrate that the action was proportionate.
Evidence tied to a device rather than to a collection. In practice that means a certificate of destruction naming each serial number, the method applied to it, a time-stamped chain of custody, and your own documented disposal procedure. A collection note covering forty items describes a process; it does not evidence one.
It is the control titled “Secure disposal or re-use of equipment” in the 2022 edition of ISO/IEC 27001. It applies to any equipment containing storage media and requires that sensitive data and licensed software are removed or securely overwritten and verified before the equipment leaves your control, that media is physically destroyed where it is not being re-used, that identifying labels are removed, and that a documented procedure covers this.
The control asks for identifying labels and markings to be removed, and asset tags are the obvious case because they link a device back to your organisation. It is worth agreeing with your disposal supplier who removes them and at what point, so it is not discovered during an audit that neither side did.
Yes, and it is the half most often missed. Annex A 7.14 asks that sensitive data and licensed software are removed or overwritten. A device leaving your control with your licensed software still installed is a licensing exposure as well as an information one, so it belongs on the disposal checklist explicitly.
Focused Disposal & Data Security
Comprehensive IT Solutions

Get in Touch About Your IT Recycling Needs
We provide IT recycling services for organisations of all sizes across England, Wales and Scotland.
Whether you’re recycling a few old laptops, decommissioning a data centre, or need secure data destruction, our team will help you dispose of IT equipment compliantly and responsibly.
Prefer to speak with us directly?
Call: +44 (0)1684 252583
Email: info@surplex.co.uk
Monday-Friday, 9am-5pm




