AI Makes ITAD Verification Inevitable

AI Makes ITAD Verification Inevitable

In 2023, Bob Johnson and I wrote an article for IAITAM with an intentionally provocative title: Two Clicks Away From Getting F*ck#d.

Our argument was simple.

Most organizations already possessed the information necessary to determine whether retired IT assets were actually accounted for. They knew what equipment they expected to dispose of. Their IT asset disposition (ITAD) provider reported what it received.

But those two inventories were not always independently reconciled.

That created an accountability gap.

Missing assets could go unnoticed. Discrepancies could remain unexplained. And when the same vendor responsible for receiving and processing equipment was also responsible for reconciling the inventory, the organization was effectively asking the vendor to grade its own work.

We argued that this could also create whistleblower exposure. Someone with access to the records could identify discrepancies that management had never investigated.

At the time, relatively few people seemed concerned.
Three years later, something fundamental has changed.
AI has eliminated one of the biggest practical barriers to ITAD verification.

Two Files and a Question

Consider a typical ITAD project.

There is an expected inventory: the equipment the organization believes should be disposed of.

Then there is an actual inventory: the equipment the ITAD provider says it received.

Historically, comparing those files could be tedious.
Serial numbers might be formatted differently. Asset tags might be missing. Records could contain duplicates. Descriptions might not match. Someone needed to understand spreadsheets, lookup formulas, databases or specialized reconciliation software.

That friction mattered.

When reconciliation was difficult, it was easy for organizations to rely on the processor’s receiving report as the record of what happened.

AI changes the equation.

Today, someone can provide an AI system with two files and ask a single question: Compare these inventories and show me everything expected that was not reported received.

What once required specialized skills can increasingly be done in seconds.

That creates a deceptively simple question:

If we can determine whether every expected asset was accounted for, why aren’t we doing it?

AI Doesn’t Create the Accountability Gap. It Makes It Visible.

The underlying problem isn’t new.

Organizations have maintained asset records for decades. ITAD providers have produced serialized inventories, settlement reports and certificates for decades.

In some organizations, expected and actual records may even reside in the same technology environment.

The data exists.

What has often been missing is the comparison.
AI lowers the technical barrier to making that comparison. And that means the ability to discover discrepancies is no longer limited to someone who knows how to build a reconciliation model.

An IT asset manager can ask.

An internal auditor can ask.

Cybersecurity can ask.

Legal can ask.

Risk management can ask.

An executive can ask.

An employee can ask.

And a potential whistleblower can ask.

AI doesn’t create whistleblower risk. It lowers the barrier to discovering and documenting the conditions that might cause someone to raise a concern.

That changes the risk calculation.

Morgan Stanley Already Demonstrated Why This Matters

We don’t have to speculate about what an inventory reconciliation can uncover.

In its 2022 enforcement action against Morgan Stanley Smith Barney, the SEC said a records reconciliation exercise revealed that 42 servers were missing, all potentially containing unencrypted customer information. The SEC ultimately imposed a $35 million penalty relating to broader failures to safeguard customer information and properly dispose of devices.

The important lesson for ITAD is how those missing servers were identified. They were discovered through reconciliation.

That exposes a fundamental weakness in traditional ITAD reporting:

A control that starts with the vendor’s inventory cannot identify an asset that never appears on the vendor’s inventory.

A processor can provide a perfectly accurate report of everything it received — that still doesn’t prove it received everything it was supposed to receive. Those are two different claims.

To test completeness, you need an independent record of what was expected. Then you compare expected against actual.

Documentation Was the Ceiling. That Ceiling Just Disappeared.

ITAD controls have evolved as risks and expectations have evolved.

Initially, organizations relied heavily on trust.
Then came certification. Standards helped buyers evaluate whether providers had appropriate facilities, processes and controls.

As the industry matured further, buyers demanded documentation: serialized inventories, certificates of destruction, chain-of-custody records and detailed reporting.

Each step improved accountability.

But certification, documentation and verification answer different questions.

Certification asks whether the provider has a system capable of performing the work correctly.

Documentation tells us what the provider says happened.

Verification asks whether this specific transaction can be proven complete.

That last question requires comparing two independent assertions: what was expected, and what was actually accounted for.

Until recently, performing that comparison at scale could be cumbersome. AI is rapidly removing that excuse.

The excuse that verification was impractical is ending.

Verification Should Protect IT Asset Managers

For IT asset managers, verification can initially sound like an audit of their work. It shouldn’t be — the purpose isn’t to find someone to blame, it’s to find exceptions while they can still be investigated.

The better questions are: How would you know if an asset disappeared before it appeared on your disposition provider’s inventory? And when expected and actual inventories don’t match, what happens next?

Who sees the exception?

Who investigates it?

What evidence is collected?

Who determines whether the explanation is sufficient?

And is the person making that determination independent of the people whose work is being verified?

A mature verification process protects ITAM because it creates a systematic way to identify and resolve exceptions before an auditor, executive, customer, regulator or employee discovers them independently.

Finding your own problem and investigating it is very different from having someone else find a problem you didn’t know existed.

Independent Verification Protects ITAD Providers Too

There’s another side to this that’s often overlooked: independent verification can protect the ITAD provider as much as the client.

Suppose a client expected 1,000 assets to be disposed of, and the ITAD provider received 998. What happened to the other two? Perhaps the processor lost them. But perhaps it never received them. They could still be sitting in an office, reassigned to someone else, lost by a carrier, removed before pickup, or the client’s expected inventory could simply be wrong. Without reconciliation, nobody asks.

Then imagine one of those two assets turns up in a security incident two years later. The ITAD provider is now explaining what happened to equipment it may never have received. This is an unnecessary risk created entirely by the absence of a check that should have happened at the time.

The client should establish what it expected to dispose of. The processor should report what it actually received. Neither should be responsible for independently verifying its own assertion. An independent party should reconcile the two. That puts the client and ITAD provider on the same side of the table: both want every discrepancy discovered quickly, investigated fairly and resolved with evidence.

Independent verification isn’t an accusation against good ITAD providers. It’s protection for them.

The Question Won’t Stop With Clients and ITAD Providers

The implications extend across the IT asset management ecosystem.

ITAM software platforms often already store an organization’s expected inventory and its downstream disposition results. Logistics providers increasingly sit between those two files and call that connection chain of custody. Once those systems connect expected and actual records, the obvious next question is whether they match.

Consultants, auditors, associations, and analysts face a related question: if expected and actual inventory can now be reconciled easily, what should happen when they don’t match. And what does “mature ITAD” mean if that question has no answer?

That isn’t primarily a technology question. It’s a governance question. And increasingly, not having an answer will itself become difficult to explain.

But Reconciliation Is Not Verification

There is an important catch.

AI makes it easy to compare two files. That does not mean AI makes a process defensible.

Suppose AI identifies a missing server. Now what?

Was the expected inventory correct?

Was the serial number transcribed incorrectly?

Was the asset removed from the project?

Was it shipped separately?

Did the processor receive it but fail to report it?

Is there a duplicate record?

Was a source file subsequently changed?

Was the asset stolen?

Who investigates? Who has access to the source records? Who determines whether the explanation is credible? And what evidence proves it?

These aren’t spreadsheet problems. They are control problems.

In fact, making discrepancies easier to discover without establishing a process for handling them could create an entirely new problem: now you know. Finding an exception and failing to investigate it is very different from never having identified it.

Comparing files without independence, a hold when identity cannot be confirmed, and a duty to investigate does not reduce exposure. It timestamps it.

That is why organizations should not confuse AI-powered reconciliation with independent verification.

AI Can Find the Discrepancy. Controls Make the Answer Defensible.

A defensible verification program requires more than an algorithm.

It requires independent expected and actual records, and segregation of duties between the people producing them. It requires controls that prevent answers from being revealed before the test, and a process for holding equipment when identities or quantities can’t be verified. It requires evidence, escalation, and documented investigation of every exception.

And critically, it requires independence.
Verification cannot be outsourced to the disposition vendor or delegated to the employee performing the work. No one should grade their own work.

Technology can automate the comparison. It cannot eliminate the need for governance.

The Question Has Changed

For years, organizations could reasonably argue that independently reconciling large serialized ITAD inventories was difficult, expensive or impractical.

That argument is disappearing.

AI will make comparing expected and actual inventories faster, cheaper and increasingly routine. That means the question facing organizations is changing.

It is no longer: Can we verify whether every expected asset was accounted for?

Increasingly, the question will be: Why didn’t we?
That is the real consequence of AI for IT asset disposition.

The organizations that recognize this early have an opportunity to build the controls before someone else asks the question.

The ITAD providers that recognize it early have an opportunity to differentiate themselves by welcoming independent accountability rather than resisting it.
And the technology providers, consultants, associations and analysts serving this market have an opportunity to help define what good verification should look like.
The transition is coming either way. That’s the opportunity Veridy was built for.

We’ve spent years developing the controls and processes required to independently reconcile expected and actual inventories, investigate exceptions, preserve evidence, and produce a complete explanation of what happened. Veridy is built on decades of ITAD experience, including scenarios most organizations haven’t had reason to think through yet.

AI didn’t create the need for that work. It made the need much harder to ignore.

AI makes ITAD verification inevitable.

Veridy makes it independent, systematic and defensible.

AI Makes ITAD Verification Inevitable

Share:

Send Us A Message