Guides → Law & compliance

ISO 27001 and secure disposal: the controls an auditor will ask about

· 4 min read

Equipment disposal is one of the places ISO 27001 audits most reliably find a gap, and it's rarely because the organisation does nothing. More often the process works, but nobody can produce the evidence to show it did.

The controls that apply

ISO/IEC 27001:2022 reorganised Annex A into 93 controls in four themes. Organisations certified to the 2013 edition had until October 2025 to move across, so the numbering below is what auditors now work to. Disposal touches several controls rather than one.

ControlWhat it asks for
5.9An inventory of information and associated assets, with owners
5.11Return of assets when people leave or change role
5.19–5.22Security in supplier relationships, agreements and monitoring
7.10Management of storage media through its whole life, including disposal
7.14Secure disposal or re-use of equipment containing storage media
8.10Deleting information when it's no longer required

7.14: Secure disposal or re-use of equipment

This is the headline control. It expects you to verify that equipment containing storage media has had any sensitive data and licensed software removed or securely overwritten before disposal or re-use. The key word is verify. A policy stating that drives are wiped isn't evidence that a given drive was.

What satisfies an auditor: a documented procedure that names the methods by media type, and records that tie individual devices to the method applied, such as certificates listing serial numbers or erasure reports per drive. Auditors will usually sample a few assets marked as disposed in your register and ask you to show what happened to each one.

7.10: Storage media

This control covers removable and internal media across their whole life: how they're labelled, stored, moved and finally disposed of. For disposal, the evidence is the chain of custody. Who had the media, how it was secured in transit, and when it was destroyed. A certificate that shows both the collection date and the destruction date covers this neatly. See what a certificate should contain.

Network cabling behind a patch panel in a comms room
Exhibit 01Comms room clearances often hold the media auditors ask aboutPhoto: dmitrybarsky, CC BY 2.0

8.10: Information deletion

Information deletion covers the data rather than the device. It's broader than disposal and includes retention schedules and deleting information from live systems. For end-of-life equipment, the evidence overlaps with 7.14. The point auditors care about is that the method was appropriate to the media, which is why an SSD listed as "degaussed" is an obvious finding. Degaussing does nothing to flash memory (see why).

5.9 and 5.11: The register and the return

You can't show that every asset was disposed of properly if you can't show which assets you had. The asset register is the foundation for everything else, and 5.11 covers the most common leak: devices that never come back from people who have left. Both have their own guides, on building the register and getting devices back.

5.19 to 5.22: Your disposal supplier

If a third party destroys your media, the supplier controls apply. Expect to show:

  • That you assessed the supplier before using them, including registrations checked on the public registers.
  • A written agreement covering security requirements. Under UK GDPR this is also where your Article 28 processor terms sit.
  • That you monitor the service, for example by reconciling certificates against what was collected and reviewing the supplier periodically.

The evidence pack auditors like to see

  1. Disposal and media handling procedure, naming methods by media type
  2. Asset register with disposed items marked and referenced to certificates
  3. Certificates of destruction listing serial, method and dates
  4. Waste transfer notes, and consignment notes for any hazardous items
  5. Supplier due diligence record and signed agreement
  6. Evidence of reconciliation: certificate serials checked against collection lists

Where audits usually find problems

  • Certificates with quantities instead of serial numbers, which can't be tied to the register.
  • Disposed assets still showing as live in the register months later.
  • Loose drives taken out of servers or failed laptops that were never recorded anywhere.
  • No record of supplier checks, beyond the fact that the supplier was used.
  • A procedure that says "wipe" for everything, with no distinction between hard drives, SSDs and tapes.

Audit coming up? Our certificates list every serial with the method and both dates, ready to file straight into your evidence pack.

Request a sample certificate

→ Next step

Ready to clear the cupboard?

Most collections are free. Tell us roughly what you have and where it is, and we'll come back with a date.