What's inside
A complete, audit-defensible vendor selection checklist for IT Asset Disposition. Designed for procurement teams, CISOs, DPOs, and IT directors who need to evaluate ITAD vendors against the right criteria, in the right order, with the right evidence retained at each stage.
29 pages of structured procurement content covering:
Three-phase methodology: RFP screening, weighted scoring, due diligence
Phase 1: 30+ mandatory and desirable criteria across certifications, insurance, operational capability, and personnel security
Phase 2: six-dimension weighted scoring system with 100 total weight points (Security and Compliance 30, Operational Capability 20, Environmental and ESG 15, Commercial Terms 15, Track Record 12, Cultural Fit 8)
Phase 3: site visit, reference checks, and document review with checklists for each
Glossary of 10 procurement and ITAD-specific terms
Six common procurement pitfalls with documented prevention steps
Appendix A: side-by-side scorecard for comparing three shortlisted vendors
Appendix B: reference check questionnaire (15 questions across service, compliance, incident, continuation, and open categories)
Appendix C: site visit checklist covering physical security, operational security, and process observation
Appendix D: mandatory contract clauses including UK GDPR Article 28 processor terms, certification maintenance covenants, data breach notification timelines, and risk allocation provisions
Why this template
Most free vendor selection checklists are flat lists of criteria. They miss the methodology that real procurement governance demands: a structured three-phase funnel with documented evidence at each stage. They also miss the certification rankings that matter for UK organisations specifically.
The ADISA Standard 8.0 angle. ADISA Standard 8.0 is approved by the UK Information Commissioner's Office as a UK GDPR certification scheme. For UK organisations processing personal data, ADISA is the most directly relevant ITAD-specific certification. Most generic vendor selection templates list ADISA as one option among many; this template positions it as mandatory for UK personal data scenarios and explains why.
This template is built to survive procurement governance scrutiny. Every criterion is flagged as mandatory or desirable. Every dimension carries an adjustable weight. Every phase produces an evidence pack. The decision is defensible to internal audit, the board, the ICO, and any future investigation.
Who it's for
Heads of procurement, sourcing managers, category managers, CISOs, DPOs, IT directors, and internal audit functions running ITAD vendor selection processes.
Pairs with
ITAD Policy Template (NS-TPL-001) which mandates the use of authorised vendors. Certificate of Data Destruction Template (NS-TPL-002) which sets the certificate format requirement. Data Retention and Destruction Policy (NS-TPL-003) which defines evidence retention. IT Asset Inventory Tracker (NS-TPL-004) which feeds capacity assessments. Chain of Custody Form (NS-TPL-005) which the vendor must align to.
Format: Microsoft Word (.docx) | 29 pages | Last updated: May 2026