
Retire customer-data hardware with controls that survive the walkthrough.
For banks, insurers, broker-dealers, and FinTech operators retiring hardware that touched customer financial data. Every storage-bearing device is sanitized to NIST SP 800-88 Rev. 1 with PCI-acceptable Purge or Destroy methods per media type, and the serial-level audit trail is issued with the Settlement Report — ready for your auditor’s control-effectiveness binder.
What financial-services teams need from ITAD.
Not marketing requirements — the ones your compliance office actually reviews when retired hardware leaves the building.
Customer financial data is everywhere
Trading workstations, retired ATMs and branch hardware, work-from-home laptops, and even imaging hardware can carry account numbers, SSNs, and transaction histories. Every one needs a verified wipe, not a blanket attestation.
SOX requires documented controls — including disposal
Internal-control attestations now routinely include the disposition of IT assets. “We threw it out” doesn’t satisfy a SOX 404 walkthrough. A per-serial disposal record does.
PCI media-destruction obligations
PCI DSS §9.8.2 requires media containing cardholder data to be destroyed so it cannot be reconstructed — and demands proof. The method has to match the media, and the record has to satisfy your QSA.
A vendor your compliance file can defend
Vendor review asks who touches your media, under which certifications, audited by whom. The answers have to be third-party-verifiable — not self-declared.
What we run against each need.
Every line below is a verified, third-party-audited capability — no promises that aren’t written at a station on the Dallas floor.
NIST SP 800-88 Rev. 1, aligned to PCI
STN 04 · WIPE LOGPCI-acceptable Purge or Destroy methods per media type, with the Certificate of Destruction your QSA expects. Method, result, date, and technician recorded per drive. The wipe gate is a hard stop — no device advances without a completed, verified log.
Spec →SOX-friendly settlement reports, one line per serial
STN 05 · FINAL CERTSerial-level audit trail issued with the Settlement Report — drops directly into your auditor’s control-effectiveness binder. Our record on the process it documents: zero data incidents, ever.
Crosswalk →100% serialized chain of custody, five stages
BOL → FINAL CERTSealed, manifested transport on your schedule — custody transfers at your dock, on paper. Every pallet is reconciled against your manifest within 48 hours. Documentation suitable for FFIEC, state-DFS, or federal-banking examiner review on request.
Walk it →R2v3 — Responsible Recycling · #274644
SERI R2v3 StandardScope: IT Asset Disposition & Refurbishment, certified by Amtivo (ANAB-accredited) · SERI, independently audited annually, valid through March 2029 — verifiable on the SERI directory. Backed by ISO 9001, ISO 14001, and ISO 45001 management-system registrations.
Certs →What this does — and doesn’t — claim. No vendor can make a financial institution GLBA-, SOX-, or PCI-compliant, and we won’t claim to. VIG supports your compliance program: third-party-verified process controls, per-serial records, and the disposal documentation your internal controls require. Your program stays yours; ours documents its disposal controls.
The paper trail, before you commit.
Five stages. One record per serial. Zero gaps. Each station below writes a named document — the same language our auditors see.
What lands in your file
Certificate records and controlled QC documents are viewable in the client portal. Nothing here is a download — originals are available for inspection on request.
Other industries we serve.

Ready to retire your fleet?
Send us your asset list and get a free valuation within one business day — no minimums, no commitment. Free pickup for 50+ unit lots in Texas. Serialized Certificate of Destruction included with every job.