🏦 Financial Services🔒 Bank-Grade Disposal

How Do Banks Securely Dispose of Old IT?

For a bank, insurer or super fund, disposing of old IT is not a facilities task. It is an information-security control. Every retired laptop, server, teller workstation and payment terminal held customer financial data, and finance is one of the most breached sectors in the country. This guide walks through how regulated financial institutions retire IT securely, and prove they did it to standard.

Certified to ISO 27001:2022 CPS 234-Ready Evidence

The Quick Answer

How do banks dispose of old IT?

Through a certified disposal process that classifies each device by the sensitivity of the data it held, destroys that data to a recognised standard, tracks every asset under a documented chain of custody, and issues a certificate of destruction for each one, all delivered by a provider whose own information security has been assessed. Banks cannot treat disposal as simply removing old hardware. They are bound by APRA CPS 234, the Privacy Act 1988 and, for payment devices, PCI DSS, and they hold customer financial data that is a prime target. So a financial institution retires IT the same way it protects data in use: to a standard, under custody, and with evidence. That is what financial services IT disposal is built to deliver.

The phrase worth keeping in mind is "bank-grade disposal". It does not mean the truck is different; it means the evidence is. A general disposal might destroy the data perfectly well, but a regulated financial institution has to be able to demonstrate, for any specific device, that the data was destroyed to a recognised standard by a party whose capability was assessed. This guide covers what banks retire, the regulations that govern it, the process they follow, and why the disposal provider itself is part of the compliance picture.

What a Financial Institution Retires

The fleet is broad, and almost all of it touched customer or member financial data.

EquipmentWhy it holds sensitive data
Servers, storage & core systemsThe highest-risk items; hold the central store of customer accounts, transactions and records, destroyed and certified drive by drive
Staff laptops & workstationsAccess customer records, applications and correspondence; local caches and files remain until wiped
Branch & teller equipmentTeller workstations and branch peripherals used for customer transactions and identity documents
Payment terminals & card devicesCardholder-data media in scope under PCI DSS; must be destroyed and documented when retired
Photocopiers & multifunction devicesInternal drives store an image of everything scanned, including applications, statements and identity documents
Mobile devices & networkingPhones and tablets with app access; switches and firewalls retaining configuration and credentials

As with any sector, the risk is not confined to the obvious computers. The payment terminal swapped out at a branch, the photocopier returned at lease end, the firewall retired during a network upgrade, each can carry sensitive financial or identity data, and each needs the same certified treatment. A bank-grade disposal covers every data-bearing device, because a single overlooked one is the gap a regulator or an attacker finds.

When Financial Institutions Retire IT

Disposal is not a once-a-year event. It is the predictable tail of the changes a bank runs constantly, which is why a standing, certified process matters.

1

Technology refreshes

Rolling replacement of laptops, workstations and servers is the most common trigger, and usually the one with the most recoverable value if the data is handled properly.

2

Branch closures and consolidations

A closing or merging branch produces teller equipment, peripherals and payment devices to clear, often to a deadline, all of it holding customer and transaction data.

3

Data-centre moves and cloud migration

Migrating to the cloud or consolidating data centres strands on-premise servers and storage that still hold live customer records until they are properly retired.

4

Mergers and acquisitions

Consolidating two institutions duplicates systems and equipment, and the retired estate carries the sensitive data of both, needing certified destruction across the board.

5

Remote and hybrid staff offboarding

Returned laptops from departed or relocated staff accumulate steadily, each an access point to customer systems that should be wiped and certified, not reissued unchecked.

The Rules That Govern Bank IT Disposal

Three frameworks converge on the same point: retired data-bearing equipment must be destroyed to standard and evidenced.

CPS 234
APRA information security. Requires controls across the information-asset life-cycle, disposal included, and assessment of any third party handling your assets.
APRA-regulated entities
Privacy Act
APP 11. Personal information must be destroyed or de-identified once no longer needed, with reasonable steps to protect it.
All entities
PCI DSS
Cardholder data. Payment-card media must be rendered unrecoverable when retired, with the destruction documented.
Card-handling entities

These three do not conflict; they reinforce each other. APRA's CPS 234 makes information security a life-cycle obligation and holds you accountable for third parties handling your assets. The Australian Privacy Principles, overseen by the OAIC, require personal information to be destroyed once it is no longer needed. And PCI DSS treats a retired payment terminal's media as in scope until it is destroyed. From 1 July 2025, APRA's CPS 230 adds an operational-risk lens over the service providers a bank relies on, disposal included. Read together, they describe a single expectation: certified destruction, documented, by an assessed provider. Our guide to CPS 234 and data destruction covers the APRA angle in depth.

The Process a Bank-Grade Disposal Follows

Six steps that turn a pile of retired equipment into a defensible, documented disposal.

1

Classify by sensitivity

Each device is identified by the data it held, so the destruction method matches the sensitivity, exactly as CPS 234 expects controls to be commensurate with the asset.

2

Collect under chain of custody

Every asset is logged at collection and tracked from the site to the point of destruction, so no device holding customer data is ever unaccounted for.

3

Destroy to a recognised standard

Certified wiping to NIST 800-88 for reusable equipment, physical shredding for drives that cannot be verified, and a method matched to flash for solid-state media.

4

Certify every device

A certificate of destruction is issued for each asset, recording what was destroyed and how, reconcilable to the bank's asset register.

5

Recover value where it exists

Once data is destroyed and certified, working equipment is refurbished and its value recovered through buyback, offsetting the cost of a refresh.

6

Report for the record

The bank receives a full report: the asset list, destruction method per device, value recovered and recycling outcome, ready for an internal or APRA information-security review.

Why Your Disposal Provider Is Part of the Compliance Picture

This is the point most organisations miss. Handing devices to a contractor does not transfer the obligation. CPS 234 extends it to that contractor.

CPS 234 requires a regulated entity to classify its information assets including those managed by third parties, and to assess the information security capability of any party managing its assets. A disposal company that collects a bank's retired equipment is, by definition, a third party managing its information assets at their most vulnerable moment, in transit and at destruction. So the standard's logic is direct: the bank remains accountable, and it is expected to have assessed the provider it hands the data to. That assessment should rest on evidence, not assurances: recognised certifications, a documented chain of custody, and a destruction record for every asset.

This reframes how a financial institution should choose a disposal partner. A provider whose own information security is certified to ISO 27001:2022 gives the bank a defensible basis for that assessment, because the certification is independent evidence of the controls the standard expects it to check for. The moment of greatest exposure is not the destruction itself, which a competent provider performs to standard, but the handover and transit, the window between a device leaving the bank's control and its data being destroyed. A provider who accounts for every asset from the moment of collection closes that window; one who cannot leaves it open with customer data inside it.

The three-question assessment

Before a single device leaves a branch or data centre, the assessment comes down to three things: is the provider's information security independently certified, can they prove an unbroken chain of custody, and do they issue a certificate of destruction for every asset. ITC's process is built around exactly these three, so the assessment is straightforward to document.

Bank-Grade vs General Disposal

The difference is the evidence that comes back, and whether it would survive an APRA information-security review.

Bank-grade disposal

  • Every device classified by the sensitivity of the data it held
  • Destruction to a recognised standard such as NIST 800-88
  • Unbroken chain of custody from collection to destruction
  • A certificate for every device, reconcilable to the asset register
  • Provider certified to ISO 27001:2022, giving assessable evidence

General disposal

  • A single method applied to everything, or an unverified reset
  • Devices handed over with no logged tracking
  • A verbal assurance, or nothing, in place of a certificate
  • An unassessed provider, so the third-party gap sits with you
  • No way to show a specific device was cleared if APRA asks

Read down the right-hand column and the theme is the absence of evidence. A general disposal might destroy the data perfectly well, but if it leaves no record, a bank cannot demonstrate that it did, and under a prudential standard the ability to demonstrate a control is much of the point. Bank-grade disposal turns each retirement into a defensible artefact: a specific asset, a specific method, a specific certificate, traceable to the day the device left the branch or data centre. That is what makes an information-security review a matter of retrieving records rather than reconstructing what probably happened.

Why Finance Is a Prime Target

Financial services sits near the top of the national breach statistics, and the penalties for mishandling personal information are among the largest in the world. Figures from named sources.

2nd
Finance was the second highest-reporting sector for notifiable data breaches, at 14% of all breaches, behind only health
Source: OAIC, Jan to Jun 2025
532
Notifiable data breaches reported to the OAIC in the first half of 2025, with breaches remaining at a high level
Source: OAIC, Jan to Jun 2025
$50M+
Maximum penalty for a serious or repeated privacy breach under the Privacy Act 1988
Source: OAIC

The OAIC reported that finance was the second most affected sector for notifiable data breaches in the first half of 2025, at 14% of all breaches, behind only health. A retired device that leaves a bank without its data destroyed holds exactly the customer financial and identity information those statistics are about, and it is easy to lose track of during a branch closure, a refresh or a data-centre move. Against a maximum privacy penalty of $50M or more, and the reputational cost to an institution that trades on trust, certified destruction is not the expensive option, it is the prudent one, and CPS 234 makes it an expectation.

How Banks Dispose of Old IT: FAQ

The questions financial-services risk and technology teams ask most about secure disposal.

The evidence, not the equipment. A bank must be able to demonstrate, for any specific device, that the data was destroyed to a recognised standard by a provider whose capability it assessed. That means classification by sensitivity, a documented chain of custody, a certificate for every device, and a certified provider, so the disposal stands up to an APRA information-security review rather than relying on an assurance.

Yes, in effect. CPS 234 requires information security controls commensurate with the stage of an information asset's life-cycle, and defines that life-cycle as running through to decommissioning and disposal. So the duty to protect the data extends to the point you dispose of the device, which means destroying it to standard and documenting it. It also requires you to assess the capability of any third party handling your assets, your disposal provider included.

Payment terminals and card devices hold cardholder-data media that is in scope under PCI DSS, which requires that media to be rendered unrecoverable when retired, with the destruction documented. In practice they are handled like any other data-bearing device in a bank-grade disposal: destroyed to standard, with a certificate, under chain of custody.

Yes. CPS 234 requires you to classify information assets including those managed by third parties and to assess the security capability of any party managing your assets. Handing devices to a disposal contractor extends the obligation to that contractor rather than transferring it. Recognised certifications, a documented chain of custody and per-device certificates are the evidence that assessment relies on.

Yes, once the data is destroyed and certified. Working servers, laptops and networking gear can be securely wiped to standard and refurbished, with their value recovered through buyback to offset the cost of a refresh, while the rest is recycled responsibly. The sequence is essential: the data is destroyed and documented first, then the clean hardware carries its value forward.

A certificate of destruction for every device, plus a report covering the asset list, the destruction method for each item, the value recovered and the recycling outcome, all reconcilable to your asset register. Together with your assessment of the provider's certification, this is the evidence trail an APRA information-security review is looking for.

Reviewing your IT disposal against CPS 234? Contact our team or call 1300 048 226.

Retire Bank IT to a Standard You Can Prove

See how ITC delivers certified, documented data destruction for banks, insurers and super funds, with the classification, chain of custody and per-device certificates that turn a disposal into evidence for CPS 234.

Evidence for your auditor

Disposal that stands up to a compliance review

Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.

Talk to a compliance specialist View certifications

Book Your Free Collection

Request a callback