Home / Financial / GLBA & SOX Compliance for IT Disposal

Healthcare · Compliance supplement

GLBA & SOX Compliance for IT Disposal

Supplement to Financial Updated May 4, 2026 ~11 min read

In 2016, Morgan Stanley hired a moving and storage company — one with no data destruction expertise and no industry certifications — to decommission two wealth management data centers. Over the next five years, thousands of devices containing unencrypted customer data were sold to unauthorized third parties and eventually surfaced on public internet auction sites. A subsequent hardware refresh in 2019 revealed 42 servers that were entirely missing from inventory.

The cumulative cost: over $161.5 million in penalties across the Office of the Comptroller of the Currency ($60 million), the Securities and Exchange Commission ($35 million), and state attorney general and class-action settlements. The OCC cited “unsafe or unsound practices.” The SEC called the systemic security lapses “astonishing.”

This was not a cyberattack. It was a vendor oversight failure in IT asset disposition (ITAD). And the regulatory framework that governs your institution’s obligations in this area leaves no room for the argument that you delegated the responsibility to someone else.

The Regulatory Architecture Governing Financial IT Disposal

Financial services IT disposition operates under a multi-layered compliance framework that is more complex, more punitive, and more actively enforced than in any sector other than healthcare. Understanding these layers — and how they interact — is essential to building a defensible disposal program.

The Gramm-Leach-Bliley Act and the Safeguards Rule

The Gramm-Leach-Bliley Act (GLBA) serves as the foundational federal statute governing the protection of consumer financial privacy. Under the Safeguards Rule (16 CFR Part 314), financial institutions are legally mandated to develop, implement, and maintain a comprehensive written information security program that addresses the entire lifecycle of consumer information — from collection through disposal.

In the context of hardware disposition, the Safeguards Rule explicitly requires institutions to implement formal policies for the secure disposal of customer information in any format. The standard demands that digital media be destroyed such that data cannot be practically read or reconstructed. Compliance generally requires adherence to NIST SP 800-88 Rev. 2 (September 2025), using verified Clear, Purge, or Destroy methodologies appropriate to the media type and data sensitivity.

The Safeguards Rule does not expire at the loading dock. Your institution remains legally responsible for the protection of customer data regardless of which vendor physically handles the hardware. Violations resulting from improper disposal trigger severe civil penalties, regulatory consent orders, and class-action exposure.

Sarbanes-Oxley Act, Section 404

SOX Section 404 requires corporate management and external auditors to report on the adequacy of the company’s internal controls over financial reporting. In the context of IT asset disposition, this creates a specific obligation: your institution must demonstrate that unauthorized access to financial records via discarded hardware is a physical and logical impossibility.

Compliance requires that disposition processes be meticulously logged, serialized, and integrated into your institution’s IT asset management system. Every retired device containing financial records must be tracked from decommission through verified destruction, producing an audit trail that proves financial records were preserved according to retention schedules and destroyed securely only after those schedules expired.

The Certificate of Destruction is the central SOX compliance artifact for hardware disposition. It must be serialized to the individual device level, reference the sanitization method and standard met, and be retained for a minimum of seven years. (For detailed guidance on what a defensible certificate contains, see: What Is a Certificate of Destruction and Why It Matters.)

PCI-DSS Requirement 9.8

Financial institutions that process, store, or transmit credit card data must comply with the Payment Card Industry Data Security Standard. Requirement 9.8 specifically governs the destruction of media containing cardholder data, mandating that electronic media be rendered absolutely unrecoverable via secure wiping per industry-accepted standards or through physical destruction.

For certain highly sensitive components within a segmented Cardholder Data Environment (CDE), software wiping alone is deemed insufficient by PCI auditors. Physical destruction — industrial shredding to specified particle sizes — may be required. Your ITAD vendor must understand your PCI scope and apply the appropriate destruction method to devices that operated within the CDE versus those that operated outside it.

SEC Rule 17a-4 and FINRA Requirements

For registered broker-dealers, SEC Rule 17a-4 and FINRA recordkeeping rules impose a unique operational constraint. Rule 17a-4(f) requires that certain records be preserved for up to six years in formats that maintain a complete, time-stamped audit trail of all modifications.

This creates a tension that your ITAD program must manage explicitly: the mandate to preserve records for the required retention period versus the security imperative to destroy retired media. During hardware refreshes, data must be immutably migrated to compliant storage before the physical media is sanitized. Rule 17a-4(i) further requires a written undertaking from third-party recordkeepers — meaning your ITAD vendor’s involvement does not relieve your firm of its ultimate regulatory responsibilities.

Not sure where your organization stands? Take the free ITAD Readiness Assessment →

What FFIEC Examiners Expect to See

The Federal Financial Institutions Examination Council (FFIEC) sets the examination standards used by the OCC, FDIC, Federal Reserve, and state banking departments when evaluating your institution’s information security practices. ITAD is a specific area of examination focus, and examiners arrive with a clear set of expectations.

Written Disposal Policy

Your institution must maintain a formal, board-approved policy for the secure disposition of consumer information and all data-bearing IT assets. This policy must specify sanitization standards by media type, define the chain-of-custody process from decommission through verified destruction, assign clear organizational responsibility for each phase, and establish documentation retention requirements. A policy that exists in draft form, that hasn’t been updated since your last examination, or that doesn’t address modern media types (SSDs, flash storage, mobile devices) will draw findings.

Vendor Due Diligence and Third-Party Risk Management

After Morgan Stanley, examiner scrutiny of ITAD vendor oversight has intensified. The OCC’s guidance on third-party risk management for community banks explicitly requires financial institutions to conduct rigorous due diligence on any vendor that handles customer data — including ITAD providers. Examiners expect to see documented vendor selection criteria, evidence that you verified the vendor’s certifications (R2v3, NAID AAA, ISO 27001) before engagement and at renewal, an executed contract with specific data protection, indemnification, and breach notification provisions, and evidence of ongoing monitoring (periodic audits, certificate renewal verification, performance reviews).

The Morgan Stanley case is now part of the examination lexicon. Examiners use it as a reference point for what “inadequate vendor oversight” looks like — and they measure your program against it.

Serialized Destruction Documentation

Examiners will ask for Certificates of Destruction linked to specific devices from your asset inventory. They will cross-reference the devices listed on your certificates against your IT asset management records. If devices appear in your decommission records but not on any certificate, that gap becomes a finding. If your vendor provides batch-level receipts rather than serialized certificates, examiners will note the documentation as insufficient for audit purposes.

Incident Response for Disposition Failures

Your incident response plan should address the specific scenario of a disposition failure — a missing device, a failed sanitization, or a vendor chain-of-custody breach. Examiners expect to see this scenario documented, including escalation procedures, notification obligations, and remediation steps. The Morgan Stanley case demonstrated that the absence of a disposition-specific incident response process allowed a five-year gap between the initial failure and its discovery.

Not sure where your organization stands? Take the free ITAD Readiness Assessment →

The Data You May Not Realize Your Hardware Contains

Financial services organizations generate and store data across a wider range of devices than most IT teams recognize. An effective disposition program accounts for all of them.

Check scanners and imaging systems cache high-resolution images of deposited checks — including account numbers, routing numbers, signatures, and payee information. When a branch closes or upgrades its scanning hardware, those cached images remain on the device’s internal storage unless specifically sanitized.

ATMs and self-service terminals contain transaction logs, account access records, and in some cases, cached customer authentication data. ATM decommissioning requires coordination between physical security, IT, and the ATM vendor, and the data sanitization process must account for proprietary operating systems that may not respond to standard erasure tools.

Trading floor infrastructure includes Bloomberg terminals, multi-monitor workstations, and specialized networking equipment that may contain cached market data, unexecuted order information, and proprietary trading algorithms. The disposition of trading floor hardware requires both data sanitization and, in many cases, compliance with firm-specific information barriers.

Executive mobile devices — smartphones and tablets used by C-suite executives and portfolio managers — contain offline emails, strategic deal structures, and authentication tokens. These devices routinely leave the corporate perimeter during active use. Their disposition requires specialized micro-shredding to destroy the dense NAND flash memory chips that standard industrial shredders may not fully obliterate. NSA-recommended standards call for pulverization to two-millimeter particle size for this media type.

Backup and archival media — tape libraries, offline backup drives, and disaster recovery replication targets — contain complete copies of core banking systems, transaction databases, and customer records. These media types are frequently managed by infrastructure teams and overlooked in disposition planning.

The Morgan Stanley Precedent and What It Means for Your Institution

The Morgan Stanley case is not merely a cautionary tale — it has fundamentally changed how regulators evaluate financial services ITAD programs. The key lessons:

Vendor selection is a governance function. Morgan Stanley hired a standard moving company for a data destruction engagement. The vendor had no ITAD certifications, no data destruction expertise, and no secure chain-of-custody process. The institution’s failure was not in the vendor’s incompetence — it was in the selection process that allowed an unqualified vendor to handle data-bearing assets.

Vendor oversight cannot be passive. Over a five-year period, devices were sold and resurfaced publicly. The gap between the initial failure and detection demonstrated that the institution had no ongoing monitoring, no inventory reconciliation process, and no mechanism to verify that its vendor was actually destroying the hardware.

Regulatory penalties compound. The OCC’s $60 million penalty was the opening action, not the final cost. The SEC added $35 million. State attorneys general pursued concurrent enforcement. Class-action settlements added further liability. The cumulative $161.5 million in penalties exceeded the cost of the most comprehensive ITAD program by orders of magnitude.

The precedent is now embedded in examination standards. Examiners reference the Morgan Stanley case when evaluating other institutions’ programs. “Would your ITAD process have prevented the Morgan Stanley outcome?” is the implicit question behind every examination finding related to hardware disposition.

Not sure where your organization stands? Take the free ITAD Readiness Assessment →

Building a Defensible Financial Services ITAD Program

The compliance requirements are demanding, but the program architecture is straightforward:

Formal, board-approved policy. Specifies sanitization standards by media type (aligned with NIST 800-88 Rev. 2 and IEEE 2883:2022), defines chain-of-custody requirements, assigns organizational responsibility, and establishes documentation retention (seven years for SOX, six years for SEC Rule 17a-4, aligned with your longest applicable requirement).

Certified, vetted vendors. Minimum certification stack: R2v3 (or e-Stewards) + NAID AAA + ISO 27001. Documented vendor due diligence at selection and annual renewal. Executed contracts with indemnification, cyber liability insurance requirements, breach notification provisions, and liquidated damages clauses for chain-of-custody failures.

Serialized documentation. Device-level Certificates of Destruction or Sanitization, cross-referenced to your IT asset management system. No batch-level receipts. No exceptions.

Retention schedule integration. Before any device is sanitized, verify that all data subject to SEC, FINRA, SOX, or GLBA retention requirements has been migrated to compliant storage. Document the migration verification as part of the disposition record.

Ongoing monitoring. Periodic vendor audits, certificate renewal verification, and inventory reconciliation. The gap between decommission records and destruction certificates should be zero. Any discrepancy triggers your disposition incident response process.

Where You Stand Matters

The financial services regulatory environment treats IT asset disposition as a governance obligation — not an operational convenience. GLBA, SOX, PCI-DSS, and SEC/FINRA rules create overlapping requirements that demand documented, verifiable, auditable proof that every retired device was sanitized to a defensible standard with an unbroken chain of custody.

The cost of a comprehensive ITAD program is measured in thousands. The cost of the Morgan Stanley outcome is measured in hundreds of millions. The distance between the two is a set of documented processes, a qualified vendor, and the organizational discipline to treat hardware disposition with the same rigor your institution applies to every other aspect of information governance.


Ready to assess your institution’s ITAD readiness? SureDispose’s free assessment evaluates your current practices across regulatory exposure, compliance gaps, data sanitization standards, vendor documentation, and chain of custody — and connects you with certified providers experienced in financial services requirements. Take the Assessment →

SureDispose is an independent advisory platform. We connect organizations with vetted ITAD service providers but do not perform disposition services directly. Providers compensate us for qualified introductions.

The step before the vendor

How SureDispose works

Three steps to go from uncertainty to a clear, documented action plan.

1

Assess your compliance exposure

Answer a few questions about your industry, data types, and current practices. Get a clear picture of where you stand.

2

Understand your regulatory requirements

See exactly which regulations apply to your organization and what they require for IT asset disposition.

3

Get matched with certified providers

Connect with vetted, certified ITAD providers who meet your specific industry requirements. No obligation.

Ready to assess your ITAD readiness?

Free. Independent. Takes about 5 minutes. No obligation.

Request Your Assessment