In October 2020, the US Office of the Comptroller of the Currency fined Morgan Stanley $60 million over failures to oversee the 2016 decommissioning of two US wealth-management data centres, including vendor due diligence, performance monitoring and hardware-data inventory. The case concerned failures associated with decommissioning hardware containing customer data, including inadequate vendor oversight and inventory controls. It's a US penalty, not a UK one, but the lesson travels: disposal risk sits with the client that signed the contract, not just the vendor that missed a drive. UK IT leaders buying ITAD services face the same exposure, dressed in unfamiliar language — ADISA, R2v3, Blancco verified erasure — that ranges from a genuinely recognised UK GDPR certification to a badge that proves almost nothing. This piece decodes which is which, and what to demand in the contract before you sign.
View the data behind this chart
| Recognition Status | What It Assesses | Verification Evidence | |
|---|---|---|---|
| ADISA ICT Asset Recovery 8.0 | ICO-recognised, UK GDPR Art.42 | Whole-business sanitisation | UKAS-accredited ongoing audit |
| ADISA ITAD Essentials | Not government-recognised | Core ITAD process risk | Annual renewal audit |
| R2v3 recycling standard | Downstream recycling framework | Recycling/reuse compliance | Strongest with erasure proof |
| Blancco Verified Erasure | Vendor-issued technical proof | Per-device data sanitisation | Signed tamper-proof report |
The $60 Million Warning Behind Every ITAD Contract
The OCC's enforcement against Morgan Stanley underscores that enterprise exposure rarely stems from isolated disk-wiping errors alone, but rather from systemic breakdowns in third-party vendor due diligence, inventory controls, and ongoing supervision.
This is a US regulatory case, not a UK enforcement action, and the figure should never be read as a UK fine. But the underlying failure — inadequate vendor due diligence and ongoing monitoring around hardware disposal — is exactly what UK GDPR's accountability principle puts on the controller, regardless of which country's regulator eventually asks the questions. If you want to understand ITAD better before you evaluate suppliers, that's the right first step.

Why a Badge on a Website Proves Almost Nothing
Most ITAD marketing pages carry a wall of logos: security badges, environmental marks, generic "certified" seals. Some of these are independently assessed against a published standard with ongoing audits. Others are self-declared, meaning the company simply says it meets a bar nobody else checked.
For a UK buyer, the practical distinction is whether a certification is recognised by a relevant government authority for data protection purposes, or whether it's a private assurance scheme that's useful context but not a legal shield. Treating the two as interchangeable is how procurement teams end up with paperwork that looks reassuring and proves nothing if a regulator ever asks.
Buyers will also encounter badges like ISO 27001, which certifies an organisation's overall information-security management framework rather than verifying physical sanitisation, and NAID AAA, a predominantly US-centric scheme with limited recognition from UK regulatory bodies.
The Legal Floor: Waste Carrier Registration and Environmental Permits
Before evaluating voluntary data-security standards, UK organisations must verify the regulatory baseline: any ITAD vendor collecting and handling redundant electrical equipment must be registered as a waste carrier with the Environment Agency (or Natural Resources Wales / SEPA in Scotland) and comply with UK WEEE regulations.
Holding appropriate environmental permits or registered waste exemptions is the mandatory legal floor to operate lawfully. Voluntary industry accreditations like ADISA, R2v3, and Blancco-verified erasure serve as an assurance layer built on top of this statutory foundation, not as a replacement for it.
ADISA ICT Asset Recovery Standard 8.0: The One That's Actually Recognised
ADISA’s ICT Asset Recovery Standard 8.0 is an ICO-recognised UK GDPR certification scheme, and ADISA Certification Ltd is listed by the ICO as a UKAS-accredited certification body. Verify that the provider, relevant sites and stated scope are actually certified.
ADISA describes the 8.0 assessment as ongoing and formal, with assessment across parts of the business; buyers should still verify the certificate’s scope, sites and current status. Certification scope should be checked for the relevant sites, processes, asset types and subcontractors, rather than treated as organisation-wide proof without qualification.
ADISA ITAD Essentials: Useful, But Don't Mistake It for the Same Thing
ADISA also runs ITAD Essentials, which it describes as a formal independent professional evaluation focused on key risks in the core ITAD process, covering different use cases across the business. It is renewed annually.
ITAD Essentials is a separate annual assurance evaluation focused on core ITAD-process risks; ADISA says it is not recognised by a relevant government authority, unlike the ICT Asset Recovery Standard 8.0 scheme. That is not a criticism of the standard — it is a genuinely useful assurance layer — but buyers should ask which one their provider actually holds, and check ADISA's public certified-company search directory, which lists named companies, current status and UK addresses, before assuming any badge on a proposal is current.
R2v3 and Verified Erasure: Recycling Compliance Isn't a Data Destruction Certificate
R2v3 is primarily a downstream electronics-recycling standard; do not rely on it alone as proof that specific devices were securely erased—require per-device, independently verifiable erasure evidence. Its value to a buyer worried about data security is strongest when paired with explicit, verified-erasure reporting rather than treated as a standalone data-destruction credential in its own right.
This is where tools like Blancco's Drive Verifier come in: Blancco says it produces a signed, tamper-proof report for each verification and that it meets R2v3 standard requirements, giving proof of compliance with industry and regulatory requirements for verified data erasure. A separate Blancco document aimed at mobile resellers and recyclers says its solutions exceed R2's requirements by verifying and certifying each individual erasure. The takeaway: ask for the per-device signed report, not just a site-level recycling certificate that says nothing about what happened to any specific drive. This is the same evidence base covered by broader secure data destruction standards guidance.
View the data behind this chart
| Layer | Detail |
|---|---|
| Generic security or recycling badge | Self-declared, no independent audit trail |
| R2v3 recycling certificate | Proves responsible recycling, not data destruction |
| ADISA ITAD Essentials | Annual assurance review, not government-recognised |
| ADISA ICT Asset Recovery Standard 8.0 | ICO-recognised UK GDPR certification, UKAS-accredited |
| Blancco-style verified erasure report | Signed, tamper-proof, per-device proof of sanitisation |
Key Provider Selection Criteria Beyond Badges
A comprehensive vendor evaluation goes beyond decoding logos. Buyers should assess core operational capabilities to ensure the provider fits their technical and commercial profile:
- •On-site vs off-site erasure: Determine whether high-risk drives must be sanitized on your premises before removal, or if secure GPS-tracked transit to the vendor's facility is sufficient.
- •Data centre decommissioning capability: Verify specialized expertise in structured rack de-installation, enterprise storage arrays, and network hardware extraction.
- •Geographic coverage and fleet control: Confirm whether the vendor uses direct, security-vetted personnel and liveried vehicles nationwide, avoiding subcontracted general couriers.
- •Sector specialisation: Assess proven experience handling data types and compliance nuances specific to finance, healthcare, legal, or public sector environments.
- •Residual value and buyback models: Review transparent commercial terms around asset remarketing, revenue sharing, and fair pricing for reusable hardware.
Chain-of-Custody Proof Points to Put in the Contract
The practical UK test isn't whether a supplier can wave a certificate — it's whether they can produce auditable chain-of-custody, serial-level asset tracking, and certificate-backed sanitisation evidence that you can verify end to end, on demand, not just at contract signature.
- •Serial-level asset tracking from collection through to final disposition, not batch-level totals
- •Named certification scope in the contract — specifically which standard (8.0, ITAD Essentials, or neither) applies to your assets, and verifying relevant sites, processes, asset types and subcontractors rather than assuming unqualified coverage
- •Independent, per-device verified-erasure reports (see verification checklist below), avoiding generic destruction letters
- •Contractual requirement to maintain and verify active certifier directory listings (see checklist below)
A Practical Verification Checklist Before You Sign
Certificates are only worth what you actually verify. Before signing, work through this list rather than accepting a proposal document at face value.
- •Search ADISA's public certified-company directory yourself for the supplier's live status, UK address, and precise scope rather than trusting a website badge
- •Ask explicitly which standard they hold: ICT Asset Recovery Standard 8.0 or ITAD Essentials, and get the answer in writing with scope
- •Request a sample signed, tamper-proof erasure report (Blancco Drive Verifier or equivalent) for a device similar to yours before assets leave site
- •Confirm the annual renewal date and cadence for ITAD Essentials, verifying current standing so expired credentials are not accepted
- •Ask how they vet and monitor their own downstream subcontractors — the exact area the OCC found Morgan Stanley had failed on
- •Get the certification scope and reporting obligations written into the contract itself, not left as a marketing reference
What This Means for UK Procurement Decisions
For regulated or high-risk data, consider requiring ADISA 8.0 or an equivalent framework, while separately verifying scope, subcontractors, chain of custody and per-device sanitisation evidence; certification does not remove the controller’s accountability.
The $60 million figure is what happens when a large, regulated institution's vendor oversight around hardware disposal breaks down. UK GDPR puts the same accountability on the controller, at whatever scale. Whether you're planning to manage server end-of-life or clearing out laptops, the certificate check isn't paperwork — it's liability management. Make certification, chain-of-custody and erasure verification explicit procurement and contract requirements rather than relying on a collection-note sign-off. The recovered assets also feed into the circular IT and ESG benefits of ITAD, but only once the data-security question is settled.
Sources
Every figure in this article traces to the sources below.
- •American Banker — OCC's $60 million fine against Morgan Stanley over disposal and decommissioning failures
- •ADISA Certification — ICT Asset Recovery Standard 8.0 (ICO-recognised UK GDPR scheme)
- •ADISA Certification — Assurance levels (8.0 vs ITAD Essentials)
- •ADISA Certification — Public certified-company search directory
- •Blancco — Drive Verifier signed, tamper-proof erasure reports and R2v3 alignment
- •Blancco — R2 compliance guidance for mobile resellers and recyclers
