An IT refresh sounds routine until you look at what’s leaving the building: retired servers that once touched core banking systems. Loan officer laptops with years of underwriting files still sitting in the browser cache. Branch workstations, ATM controllers, and backup tapes nobody’s opened in a decade. Every one of those assets carries nonpublic personal information, and every one of them is a liability the moment it rolls out the loading dock without a plan.

For banks and credit unions, that plan is regulated, audited, and increasingly expensive to get wrong. Financial services ranked among the costliest industries for data breaches in IBM’s 2025 Cost of a Data Breach Report, and a large share of exposure incidents trace back to retired hardware that never got properly sanitized. Once that hardware leaves the building, destroying the data on it is the bank’s last chance to make sure it’s gone.

The Gramm-Leach-Bliley Act (GLBA) set the foundation. Passed in 1999, it requires financial institutions to protect customers’ personal information and disclose how that information gets shared. It’s built on three parts:

  1. the Financial Privacy Rule, which governs how institutions disclose their information-sharing practices;
  2. the Safeguards Rule, which requires an written security program; and
  3. the Pretexting Provisions, which ban obtaining someone’s financial information under false pretenses.

The Safeguards Rule is the piece that later disposal requirements trace back to.

Regulators translated that into operational standards through the Interagency Guidelines Establishing Information Security Standards, jointly issued by the Federal Reserve, the Office of the Comptroller of the Currency (OCC), which regulates national banks, and the Federal Deposit Insurance Corporation (FDIC), which regulates state-chartered banks outside the Federal Reserve System. Those guidelines make disposal an explicit, ongoing obligation: an institution’s responsibility to safeguard customer information continues through the disposal process.

Credit unions fall under a parallel structure through the National Credit Union Administration (NCUA), the federal agency that regulates and insures credit unions. NCUA’s 12 CFR Part 748 requires federally insured credit unions to build proper disposal into their information security programs.

That requirement traces back to the Fair and Accurate Credit Transactions Act (FACT Act) of 2003, which directed regulators to write specific rules for disposing of consumer information pulled from credit reports, largely to cut down on identity theft. For credit unions, 12 CFR § 717.83 points to concrete methods, including destroying or erasing electronic media containing consumer information so it can’t practicably be read or reconstructed.

The Federal Financial Institutions Examination Council (FFIEC) ties all of this together across examiners. It’s an interagency body representing the Federal Reserve, the FDIC, the NCUA, the OCC, and the Consumer Financial Protection Bureau (CFPB), and it sets shared examination standards so an institution’s disposal practices get evaluated consistently no matter which agency happens to be doing the exam. Institutions that also process card payment data have the Payment Card Industry Data Security Standard (PCI DSS) running alongside all of it, with its own audit requirements around how systems handling payment information get retired.

What “Compliant” Means on the Ground: NIST 800-88

Regulators don’t typically prescribe a specific sanitization method, which leaves institutions looking for a defensible benchmark. Special Publication 800-88, issued by the National Institute of Standards and Technology (NIST), has become that benchmark, in banking and well beyond it.

The guidelines break sanitization into three tiers:

  1. Clear, which overwrites user-addressable storage so casual recovery tools can’t pull anything back;
  2. Purge, which applies stronger techniques like cryptographic erase or degaussing so even lab-grade recovery fails; and
  3. Destroy, which physically renders the media unusable through shredding, disintegration, or pulverization.

Which tier applies depends on where the asset is headed next. A laptop being redeployed inside the same institution might only need Clear. A decommissioned drive from a core banking server, one that’s leaving the building for good, might fall under Purge or Destroy. 

Where IT Refreshes Create Exposure

Most institutions know they’re supposed to destroy data on retired hardware. Where things break down is custody: the handoff points where nobody is explicitly responsible for an asset between the moment it’s pulled from service and the moment it’s actually destroyed.

A branch closes and workstations get boxed up by facilities before IT ever logs them. A server refresh leaves a pallet of decommissioned hard drives sitting in a storage closet for months because destruction got scheduled but never followed up on. A leasing company takes back end-of-term equipment, and once it’s off the truck, the institution has no record of what happened to it or when.

None of these require a data leak to become a problem. If you can’t show what happened to a piece of hardware, that missing record is the violation, whether or not anything was ever exposed.

What a Compliant Process Looks Like

A defensible IT refresh follows a chain that regulators, examiners, and auditors can all trace from pickup to certificate.

  • Inventory before anything moves. Every asset gets logged, serialized, and tracked before it leaves its original location, not after.
  • Secure chain of custody in transit. Assets should move under locked, tracked transport from pickup straight through to destruction. Hardware that isn’t tracked in transit is the easiest thing to lose.
  • Documented sanitization matched to the asset. Clear, Purge, or Destroy, selected deliberately and applied by trained technicians.
  • Witness options for institutions that want them. Some compliance teams want eyes on the process, whether that’s a staff member watching on-site shredding or reviewing footage after the fact.
  • A Certificate of Destruction for every asset. This is the document an examiner will actually ask to see, and the certificate needs to name the asset, the method, the date, and who performed the work.
  • Vendor due diligence, on both sides. The FFIEC requires institutions to vet their vendors with the same scrutiny they’d apply to an internal department. That means checking a vendor’s financial stability, security controls, certifications, and track record before signing anything.

Choosing a Partner That Can Stand Behind the Work

Look for an ITAD vendor with certification from the National Association for Information Destruction (NAID), specifically its AAA tier, since it involves scheduled and unannounced audits of the actual destruction process, as well as certification from the International Organization for Standardization (ISO), specifically ISO 9001 for quality management, ISO 14001 for environmental management, and ISO 45001 for occupational safety, and confirm the vendor undergoes its own PCI DSS audits if payment systems are anywhere in the mix.

That’s the standard TAMS holds itself to for every IT refresh we perform for banks, credit unions, and the vendors that support them. Our destruction processes align with NIST 800-88’s Clear and Purge methods, we offer both in-house and on-site shredding with witness options, and every job closes out with a Certificate of Destruction and real-time visibility through our client portal. 

If your next IT refresh is coming up, let’s talk about what compliant, well-documented banking ITAD services look like for your institution. Request a quote and we’ll walk you through it.

Ready to Protect Your Data?

Ready to safeguard your assets and the environment? Request a quote today and discover how TAMS can elevate your IT lifecycle management.

Request a Quote
TAMS Logo