IT asset disposition for banking and financial services
ATMs, payment terminals, branch equipment and tapes that have cleared their retention period. We remove them under continuous custody, sanitize with a certificate per serial number, and hand you a file your audit can walk without gaps.
Business and institutional clients only — minimum 20 units per pickup.
- Certificate per serial number
- Reconciled to your inventory
- Retention periods respected
- On-site destruction when required
In banking the hard part is not the hardware — it is the proof
Almost any company can say it recycled its equipment. A financial institution has to demonstrate something harder: exactly what was done to every medium that touched customer information, by whom, when, and that at no point in the journey did that medium fall out of custody.
That difference changes everything. The technical work — erase, destroy, recycle — is the easy part. What gets examined is documentary: reconciliation against inventory, the per-serial-number certificate, unbroken chain of custody and the order in which things happened. A process that gets the technical side right and the documentary side wrong is worthless here.
The retention schedule comes first
This is the step most often skipped and the costliest to skip. Before a single device is touched, the asset list has to be reconciled against the retention periods your institution’s regulation imposes. Two symmetrical errors:
- Destroying too early. Leaves you without evidence when an authority request or a customer dispute arrives. It is irreversible and there is no way to explain it away.
- Holding too long. Every month a data-bearing medium exists without needing to, your risk surface grows. "Just in case" is not a retention policy.
We do not determine those periods — your compliance team does, based on your regulatory framework. What we do is execute once the decision is made, and record the exact date each medium ceased to exist, which is precisely the data point that closes the retention cycle.
What leaves a financial institution
ATMs
There is a computer inside: a drive running the operating system, transaction journals and the PIN module. A retired ATM is not a metal cabinet — it is a data-bearing device with components that need controlled handling.
Payment terminals and readers
POS units, magnetic-stripe and chip readers, pinpads and anything that processed cardholder data. Retiring these is not like retiring a peripheral: the payment-card framework expects secure disposal and evidence.
Branch equipment
Check scanners, cash counters and recyclers, statement printers, signature pads and teller workstations. All of it passed through customer information.
Back-office compute
Servers, workstations, executive laptops, storage arrays and the data center’s backup tapes.
Legacy backup media
Tapes and drives held for retention periods that have already expired. The stream carrying the most history and usually the least inventory.
Tokens, HSMs and security devices
Retired cryptographic modules, authentication tokens and biometric readers. They are hardware holding sensitive information and follow the same treatment as any other medium.
An ATM is not furniture
Worth pausing here, because this is where risk gets most underestimated. A retired ATM looks like a heavy metal cabinet, and inside it is a computer: a drive running the operating system, transaction journals, the PIN module and card readers. If that unit leaves your branch network as scrap metal, it left with data inside.
The same applies, at smaller scale, to payment terminals and any reader that processed cardholder data: their retirement is contemplated by the payment-card framework and expects secure disposal with evidence, not simply switching them off.
Our treatment is the same in all three cases: storage media are identified and extracted, sanitized or destroyed with a per-serial-number certificate, sensitive components receive controlled handling, and the remaining equipment enters material recovery with its disposal record.
Branch closures and consolidation
This is the sector’s signature project and the one that goes worst when improvised. A closure releases equipment from several locations at once, with dates tied to lease agreements, branch inventories that are almost never current, and staff whose attention is already elsewhere.
What separates an orderly closure from one with findings:
- An inventory per branch before anything moves. What was not counted on the way out cannot be reconciled on arrival.
- Defined routes and custody. Equipment from several sites travelling without seals or a signed record is the single most common leak point in the whole project.
- One consolidated file, not twelve loose ones. The audit reviews the whole; it helps if the whole existed from the start.
Multi-site collection logistics are covered on reverse logistics.
Continuous custody: where chains actually break
Chain of custody does not break at the destruction facility. It breaks in the gaps: the night the equipment spent in a van, the weekend it sat in an unlogged warehouse, the transfer nobody signed. A file with a 48-hour hole and no responsible party is a file with a finding, no matter how impeccable the erasure was.
So removal runs with a signed record, seals and identified personnel from the first movement, and for higher-risk lots there is the option of witnessed destruction at your site with your staff observing — the certificate records the witness. It is slower and more expensive, so it is normally reserved for the critical fraction.
Which frameworks apply, and whose responsibility it is
Worth stating plainly, because this sector attracts a lot of sales noise:
- You are the obligated party. The provisions applying to your institution, the payment-card framework and Mexico’s LFPDPPP bind you, and you keep answering even when a third party does the work. No vendor transfers that responsibility to itself, however many logos appear in the deck.
- NIST 800-88 is a method, not a seal. It defines the Clear, Purge and Destroy levels we declare on each certificate. It is not a certification scheme and nobody is "certified" under it.
- What we do contribute is evidence. Sanitization with method and level declared, per-serial-number certificate, chain of custody and documented final destination under NOM-161-SEMARNAT. That is what your control needs in order to be demonstrable.
The project’s environmental metrics are consolidated separately for your ESG reporting.
How it runs
- 01
Check against the retention schedule
Before anything is touched, we confirm with your compliance team which assets have cleared the retention period your regulation imposes. Destroying early is as serious a finding as not destroying at all.
- 02
Inventory and risk classification
We separate by data type and device: what carried cardholder data, what carried personal data and what is only hardware. The sanitization level follows that classification.
- 03
Removal under sealed custody
Collection with a signed record, seals and identified personnel. For high-risk lots the option is witnessed destruction by your staff or on your premises, so the medium never leaves unsanitized.
- 04
Sanitize or destroy
Verified erasure using NIST 800-88 methods for anything being reused; physical destruction for whatever your policy will not allow to leave intact. Every medium, by serial number.
- 05
Reconcile and certify
What was processed is reconciled against the opening inventory, and the certificate issues per serial number with method, level, date and responsible party. Discrepancies get explained at the time.
- 06
Documented disposal
Sanitized hardware is recycled under Mexican NOM-161-SEMARNAT, with a final-destination record that closes the environmental file too.
Residual value counts too
A reasonably recent fleet of laptops and workstations has a real secondary market, and that value is yours — value lowers the net cost of the project. The rule is non-negotiable and the order matters: verified certified destruction of the drive first; then you decide what to do with the machine. If your policy prohibits certain equipment from reaching the secondary market even after sanitization, it is flagged at inventory and goes straight to destruction. See asset valuation and buyback.
Start with the list, not the quote
The most useful thing you can send us is not a price request — it is the list of what is waiting for disposal and where each item stands against its retention period. From there we can tell you which sanitization level applies to each group, what is worth destroying on site, and exactly what evidence you will receive. Message us on WhatsApp or through the contact page.
Financial sector questions
Can we destroy equipment as soon as it is written off?
Not necessarily, and this is the most expensive scheduling mistake in the sector. Financial information carries retention periods set by the regulation applying to your institution: destroying before they elapse leaves you without evidence when a request arrives, and holding beyond what is needed expands your risk surface for no reason. So the first step is not technical — it is reconciling the asset list against your retention schedule with your compliance team. We execute once that decision is made.
What do you do with a retired ATM?
We treat it as a data-bearing device, not as furniture. Inside there is a drive running the operating system and transaction journals, plus the PIN module and card readers. We sanitize or destroy the storage media with a per-serial-number certificate, give controlled handling to the sensitive components, and the rest of the cabinet — metal, power supply, display — goes to material recovery with its disposal record.
We are closing branches. Can you handle the whole wave?
Yes, and it should be planned as a project rather than a series of loose pickups. A closure or consolidation releases equipment from several locations at once, with dates tied to lease agreements and branch inventories that are rarely current. We coordinate routes, removal order and per-branch reconciliation, so you end up with one consolidated file instead of twelve separate packets nobody can square.
Does using your service make us PCI DSS or CNBV compliant?
Let us be precise: the obligated party is your institution, not us. Those frameworks are yours, and you answer to the regulator or the card brands even when a third party does the work. What we do is produce the evidence those controls call for — sanitization with the method and level declared, a per-serial-number certificate, chain of custody and documented final destination — so your compliance team can demonstrate the control. We do not sell or claim certifications we do not hold.
Can destruction happen at our facility?
Yes, and for certain lots it is the right call. Where policy does not allow a data-bearing medium to leave your perimeter unsanitized, destruction happens on site with your staff witnessing, and the certificate records the witness. It is slower and more expensive than doing it at our plant, so it is normally reserved for the highest-risk fraction while the rest travels under sealed custody.
What does our internal audit receive?
Opening inventory reconciled against what was actually processed; a destruction or erasure certificate per serial number with method, level applied, date, responsible party and witness where there was one; continuous chain of custody from pickup onward; and the final-destination record for the hardware under NOM-161-SEMARNAT. A package an auditor can walk end to end without gaps.
What about equipment that still works — can it be resold?
Yes, and the value stays on your side. We destroy the storage medium — always, with a per-serial-number certificate — and the machine stays with you: redeploy it internally, donate it or sell it. That income is entirely yours; it never passes through us. If your policy prohibits certain equipment from leaving the institution even without a drive, it is flagged at inventory and goes whole to material recovery, which we can also buy from you.
We report to a parent company abroad. Will the evidence work for them?
Yes. We issue documentation in Spanish and English, because the same file usually has to answer to a local review and to a parent company or external auditor outside Mexico. The technical vocabulary — NIST 800-88 and its Clear, Purge and Destroy levels — is what a U.S. security team already reads, so only the language needs translating, not the substance.
Close the audit without findings
Continuous custody, a certificate per serial number, reconciliation against your inventory and a documented final destination. The whole file, from one provider.