FINANCIAL SERVICES · COMPLIANCE BRIEF

ITAD Compliance for Banks and Credit Unions: Retiring Equipment the Way an Examiner Expects

Every bank and credit union already has a written information security program, because the regulators require one. Fewer have thought about the moment that program has to prove itself on the loading dock — when a branch consolidates, a core system converts, a fleet of teller PCs and ATMs is replaced, and a truck arrives to take the old equipment away. The disposal duty is written into the same guidelines that govern the rest of the program, the vendor that takes the equipment is a service provider the examiner expects you to have vetted, and a device that leaves with data on it can start a notification clock measured in hours. This brief is the examiner-ready version of that moment: where the duty lives, what to have in the file, and which devices to worry about.

By Charles Nygard Published 9 min read ↓ PDF one-pager

STRAIGHT ANSWER

Banks and credit unions must dispose of customer and member information properly under the same guidelines that govern their information security programs — the Interagency Guidelines for banks and NCUA Part 748 Appendix A for credit unions, both incorporating the FACTA disposal standard. An ITAD vendor is a service provider subject to due diligence, contract terms, and monitoring. The examiner-ready file is an inventory, NIST 800-88 destruction, serialized certificates, and chain of custody.

01 / THE DUTYWhere the disposal obligation actually lives

Financial institutions are unusual among regulated industries in one respect: the duty to dispose of data properly is not a separate rule they have to go find. It is written into the same document that requires the information security program in the first place.

For banks, that document is the Interagency Guidelines Establishing Information Security Standards, issued by the OCC, the Federal Reserve, and the FDIC under the Gramm-Leach-Bliley Act and codified as appendices to each agency's regulations (for national banks, 12 CFR Part 30, Appendix B). The Guidelines require a written program with administrative, technical, and physical safeguards, and among the measures the program must include is one to properly dispose of customer information and consumer information — language added when the agencies implemented the FACTA disposal requirement in 2004. For federally insured credit unions, the parallel document is NCUA's Guidelines for Safeguarding Member Information at 12 CFR Part 748, Appendix A, whose objectives include ensuring the proper disposal of member information and consumer information. (NCUA proposed in December 2025 to move Appendix A out of the Code of Federal Regulations and republish it as a Letter to Credit Unions without substantive change; the obligation does not move, only the format — confirm the current status with your examiner.)

Neither document tells you how to sanitize a hard drive. That is by design: the Guidelines are outcome-based, and the outcome is that the information is not recoverable once the institution no longer controls the media. The technical benchmark examiners and auditors recognize for that outcome is NIST SP 800-88 Rev. 2, whose Clear, Purge, and Destroy categories map onto every device class a branch contains. The GLBA & FFIEC Field Guide walks the statute-level detail; this brief stays at the program level.

The disposal duty is not an add-on. It is a required element of the information security program the regulators already examine — which means a weak ITAD process is an information-security-program finding, not a facilities footnote.

02 / THE VENDOR FILEYour ITAD provider is a service provider, and the examiner knows it

The second place the duty shows up is in the sections on service providers. Both the Interagency Guidelines and NCUA Part 748 require an institution to exercise appropriate due diligence in selecting service providers, to require them by contract to implement appropriate measures to meet the Guidelines' objectives, and, where the institution's risk assessment indicates, to monitor them — reviewing audits, summaries of test results, or equivalent evaluations. A company that drives away with a pallet of teller PCs and a decommissioned core server is performing a service that involves customer information. It is inside that framework whether or not anyone in procurement labeled it a technology vendor.

For banks, the 2023 Interagency Guidance on Third-Party Relationships: Risk Management from the OCC, Federal Reserve, and FDIC organizes the same expectation into a life cycle — planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination — and asks that oversight be proportionate to the risk of the relationship. A disposition vendor handling data-bearing assets is a higher-risk relationship than its invoice size suggests, because the failure mode is a breach rather than a late delivery. NCUA's supervisory expectations for third-party relationships point the same way for credit unions.

Translated into a file an examiner can open, that means:

  • Due diligence, dated before the first pickup. Certifications verified in the issuing body's directory rather than from a logo — NAID AAA for the destruction operation, R2v3 with Appendix B for sanitization and downstream — plus insurance certificates, financial standing, and references. The NAID AAA and R2v3 field guides explain how to read each certificate.
  • A contract that says the right things. Sanitization or destruction to a named standard; serialized certificates per device; chain-of-custody documentation; notification obligations if anything goes missing; subcontractor disclosure; and the institution's audit or inspection rights.
  • Monitoring that actually happens. Certificate reconciliation against the asset list after every event; an annual review of the vendor's certifications and insurance; and a line in the annual board report, which both sets of Guidelines require to address service-provider arrangements.

The Vendor Due Diligence Scorecard turns this list into a scored evaluation you can drop into the vendor file.

03 / THE INVENTORYThe devices that hold account data — and the ones people forget

Most institutions have a clear picture of their servers and workstations. The disposition risk concentrates in the devices that are not thought of as computers.

  • ATMs and interactive teller machines. Modern units are PCs in armored cabinets: a hard drive or solid-state drive holding the operating system, transaction journals, and frequently card data and captured images. When a fleet is replaced or a branch closes, the drives must be sanitized or destroyed and certified like any server drive — and the removal often has to happen on site, before the cabinet is moved.
  • Check scanners and branch capture stations. Image-capture workstations store check images; many scanners buffer them. Both belong on the asset list.
  • Multifunction printers and copiers. Internal drives retain scanned and printed documents — loan files, statements, ID copies. Lease returns are the classic leak: the device goes back to the lessor with the drive intact. The Crunch episode on this is thirty seconds well spent.
  • Phones and mobile devices. Desk phones cache contacts and call logs; smartphones and tablets hold email, messaging, and authentication apps. Wipe-and-verify or destroy; do not rely on a factory reset alone for devices with soldered storage — see the SSD, SED & NVMe guide for why.
  • Card readers, signature pads, and payment terminals. May retain transaction or configuration data; treat as data-bearing until proven otherwise.
  • Network and security equipment. Firewalls, switches, and routers hold configurations, VPN keys, and credentials; DVRs and surveillance systems hold footage of the branch floor. Both classes need a documented wipe or destruction.
  • Backup media. Tapes and removable drives from the pre-cloud era still turn up in branch closets. Degaussing or destruction with a serialized record is the answer; a tape in a box is a finding.

The practical control is an inventory that tags every asset as data-bearing or not before the disposition event, so the sanitization path is decided in advance rather than discovered on the dock.

04 / THE CLOCKHow a lost device becomes a notification question

Two federal rules put a stopwatch on a disposition failure. The banking agencies' Computer-Security Incident Notification Rule, in effect since 2022, requires a bank to notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred. NCUA's cyber incident reporting rule, in effect since September 1, 2023, requires a federally insured credit union to report a reportable cyber incident within 72 hours of reasonably believing one has occurred. Layered on top are the state breach-notification statutes, several of which in this region require notice to the state attorney general or state police on their own timelines — the Mid-Atlantic law recap collects them.

Whether a particular unaccounted-for device meets the definition of an incident under those rules is a question for counsel, and this brief does not answer it. What it can say is that the analysis is triggered by a device with unsanitized customer or member data whose whereabouts cannot be proven — and that a device with a serialized certificate of destruction, matched to the inventory, never enters the analysis. Documented destruction is the difference between an audit artifact and an incident report.

Under the 36- and 72-hour rules, the question is not "was the data misused?" but "can we prove where the device and its data are?" A serialized certificate is the proof.

05 / THE PROGRAMThe examiner-ready ITAD program on one page

None of this requires a new department. It requires that the existing information security program extend to the last step of the asset lifecycle, with the same discipline it applies to the first. The one-pager attached to this brief compresses it; the components are:

  1. Policy. A disposition section in the information security program that names the standard (NIST SP 800-88 Rev. 2), assigns ownership, and covers every data-bearing device class above — not only servers and PCs.
  2. Inventory. Every asset tagged data-bearing or not, with a sanitization path decided in advance. Reconcile the list at pickup and again against the certificates.
  3. Vendor file. Due diligence dated before the first event, contract terms covering standard, certificates, custody, notification, and subcontractors, and monitoring evidence. Use the scorecard.
  4. Execution. On-site destruction where the risk or the policy calls for it (ATM drives, core servers), facility destruction under sealed transport otherwise, and sanitization for reuse only where the vendor's R2v3 Appendix B process and your policy allow it.
  5. Records. Serialized certificates per device naming method and standard, chain-of-custody documentation from handoff to final disposition, and retention on the institution's records schedule.
  6. Reporting. The annual board report both Guidelines require should reflect the service-provider arrangement, the year's disposition events, and any exceptions.

Branch consolidations, core conversions, and hardware refreshes are the moments this program earns its keep, because they generate hundreds of data-bearing devices in a compressed window. The Enterprise Refresh Playbook covers the logistics of a wave; the office-closure checklist covers the branch that is closing for good; and the financial-services overview shows how CyberCrunch runs the process end to end for institutions in the region.

06 / FAQBank and credit union ITAD FAQ

Does GLBA require banks to destroy data on retired computers?

In practice, yes. The Gramm-Leach-Bliley Act's safeguards provisions are implemented for banks through the Interagency Guidelines Establishing Information Security Standards, which require an information security program that includes appropriate measures to properly dispose of customer information and consumer information, and for federally insured credit unions through NCUA's Guidelines for Safeguarding Member Information at 12 CFR Part 748, Appendix A, which carry the same disposal objective. Neither names a technique; NIST SP 800-88 Rev. 2 is the accepted benchmark for what rendering data unrecoverable means.

Is an ITAD vendor a 'service provider' or 'third party' for examination purposes?

Yes. A vendor that takes custody of equipment containing customer or member information is performing a service involving that information, which places it inside the service-provider oversight expectations of the Interagency Guidelines and NCUA Part 748, and inside the life-cycle framework of the June 2023 Interagency Guidance on Third-Party Relationships: Risk Management for banks. Expect an examiner to ask for the due diligence performed before selection, the contract terms requiring safeguards, and evidence of ongoing monitoring.

Can a lost or unsanitized device trigger the 36-hour or 72-hour incident notification rules?

It can. The banking agencies' computer-security incident notification rule requires a bank to notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred, and NCUA's rule requires a federally insured credit union to report a reportable cyber incident within 72 hours of reasonably believing one occurred. Whether a specific lost device meets those definitions is a fact question for counsel, but a device with unsanitized member or customer data that cannot be accounted for is exactly the kind of event that has to be analyzed under them, and under the applicable state breach-notification laws.

Which bank and credit union devices hold customer or member data besides servers and PCs?

More than most inventories admit. ATMs and interactive teller machines contain hard drives or solid-state storage holding transaction logs, card data, and often images; check scanners and branch capture workstations hold check images; multifunction printers and copiers store scanned documents on internal drives; desk phones and mobile devices hold contacts, messages, and authentication tokens; card readers, signature pads, and POS-style devices may retain data; and network gear holds configurations and credentials. Each class needs a documented sanitization or destruction path.

What records should a bank or credit union keep from an ITAD event?

An asset-level inventory reconciled at pickup and at destruction, serialized certificates of sanitization or destruction naming the method and standard, chain-of-custody documentation from handoff to final disposition, the vendor's current certifications and insurance in the vendor file, and the annual board report entry that reflects service-provider arrangements and any incidents. Retention should follow the institution's records schedule; treating the ITAD file like any other examination artifact is the practical rule.

EXAMINER-READY, BY DESIGN

Retire the branch, the ATMs, and the core — with the file already built

CyberCrunch is NAID AAA certified continuously since 2012, R2v3 certified with Appendix B, and RIOS certified, and we work with banks and credit unions across the Mid-Atlantic and all 50 states. On-site or facility destruction to NIST SP 800-88 Rev. 2, serialized certificates per device, documented chain of custody, and a vendor packet your examiner can open.

This brief is informational only and reflects publicly available sources as of September 2026 — the Interagency Guidelines Establishing Information Security Standards, NCUA's Guidelines for Safeguarding Member Information (12 CFR Part 748, Appendix A) and its December 2025 proposal to relocate them, the 2023 Interagency Guidance on Third-Party Relationships, the banking agencies' computer-security incident notification rule, NCUA's cyber incident reporting rule, and NIST SP 800-88 Rev. 2 — described at the program level, not reproduced. It is not legal, regulatory, or examination advice, does not create an attorney-client relationship, and does not determine whether any specific event is a reportable incident. Requirements change and examiner expectations vary; confirm current obligations with qualified counsel and your primary regulator before acting. CyberCrunch credential statements reflect certificates held at the time of publication.