Four records carry the data-security half of the engagement, and each closes a gap the other three leave open.
The serialized asset inventory
Capture make, model, serial number, and condition for every unit before it leaves your control, then treat that file as the baseline every later document gets measured against. NIST SP 800-88 Rev. 2 ties this to record-keeping at both ends of the asset's life. Without a front-end record, it notes, sanitization records "will only show that specific ISM were sanitized and not whether the organization is effectively sanitizing all ISM that have been introduced into the operating environment" [1]. Build the inventory from your own asset management system rather than adopting the vendor's receiving count, which cannot detect anything lost between your rack and their truck.
Chain-of-custody records
Require a dated receipt at every custody transfer showing the type and quantity of material moved plus an acknowledgement of the service performed, which is what NAID AAA certification obliges a certified provider to hand over when custody passes from your staff to theirs [3]. The HIPAA Security Rule asks for the same thing through its accountability specification: a record of the movements of hardware and electronic media and any person responsible for them [10]. Two details are worth writing into the contract. If a subcontractor touches the load, you are entitled in writing to that subcontractor's name and the service it performs [3]. And if the provider routes material through a transfer processing station rather than straight to a destruction facility, NAID AAA specifications require it to reach a facility-based destruction operation within 15 business days, a defensible timeline to hold them to [3].
The certificate of data destruction or sanitization
Insist the certificate name individual serial numbers and state the method applied, because a certificate that names only a customer and a date proves nothing about any particular drive. NIST SP 800-88 Rev. 2 lists what the record should carry: manufacturer, model, serial number, any internal property number, media type, media source, the sanitization method chosen from clear, purge, or destroy, the specific technique used, the tool and its version, the verification method, and the name, title, date, location, and signature of the people performing verification and validation [1]. Its Appendix C sample form adds a destination block distinguishing internal reuse, external reuse, a recycling facility, and return to a manufacturer, plus a second signature for concurrence [1]. Blancco, whose erasure software is used widely across the ITAD market, publishes a comparable vendor-side list that adds the software version, the erasure start and end time, a pass or fail status, and a digital signature with a report identifier [12]. NAID AAA certification adds an entitlement buyers rarely invoke: a provider destroying hard drives records the serial numbers and returns that log to the customer on completion, and a customer who declines has to sign an opt-out agreement stating that recordation is a certification requirement [3].
The exception report
Require a named list of anything that did not go to plan, since this is the document most likely to be left out and the first one an investigation will ask for. Under NAID AAA specifications, a provider holding the overwriting endorsement must leave the customer documentation identifying any drives that failed the wiping process, with those drives' unique identifiers included regardless of any opt-out agreement in place. If a non-erased drive stays behind with the customer, that document also has to state that custody is being transferred back [3]. The same specifications require the verification software to differ from the wiping software, which is the control that makes a failure detectable at all [3]. Ask for it even when there is nothing to report, because a signed statement that zero drives failed is itself a record you can produce later.