Compliance & Security Steps on Intake: Asking the Awkward Questions Up Front
The two request steps that pin down certifications, data treatment and handling constraints before the bid round opens.
A pickup request that never says what the disposal has to prove comes back with bids priced for a different job. Everyone discovers this after award, in a meeting, with a procurement officer who is no longer charmed. Two steps in the request wizard exist so those answers land before bidding opens: one for what the customer needs proven, one for how the goods have to be handled on the way out.
The compliance step
The customer states whether the devices are data-bearing, then picks the data treatment: logical erasure, physical destruction, or both. Required certifications come from a short fixed list — R2v3, e-Stewards, NAID AAA, ISO 14001, ISO 27001 and WEEELABEX — and each one narrows the pool of ITADs the request can reach. Alongside them sit the evidence asks: on-site destruction, witness destruction, video evidence, a per-asset report, an ESG report. The step closes with the disposition preference: reuse preferred, recycle only, or either.
Six certifications is not a shortage of ambition. It is precisely the set that mirrors the certification tags an ITAD keeps on its Sourcing coverage, which is what lets the matching gate work at all. A picker with ninety entries produces longer forms and the same six answers.
The security step
Different concern, separate step. Brand protection comes first: remove the asset tags, strip the branding, do not resell these machines in this region — the questions a company asks when its logo on a second-hand laptop is a bigger exposure than the laptop. Then transport security: GPS-tracked vehicles, sealed containers, a two-person crew, background-checked drivers. Then on-site access: after-hours pickup, weekend pickup, and a named security contact for the site, because the loading dock at 06:00 belongs to someone.
Note what is not here. The data-destruction choice lives in the compliance step, since it is a promise about the data rather than about the van.
Two lists, not a mapping
The picks do not each translate into one tidy code. The request carries two arrays: required certifications and required services. Certifications are gates — an ITAD whose coverage does not carry every required tag never sees the request in the first place. Services are what the request asks the winning bidder to actually perform, and they surface on the bidder’s side in the same words the customer chose. One request, two lists, no translation layer nobody asked for.
When nobody bids
A published request sitting at zero bids, with no award and no downstream handoff, can be relaxed: drop one required certification, or drop one required service. The platform suggests which constraint is standing in the way, the customer applies one at a time, and the request republishes so it surfaces near the top of the Sourcing inbox again — without exposing coverage counts or anything about who did not bid.
One constraint at a time is the point. It keeps the request honest about what it still requires, instead of quietly becoming a different request. And sometimes the honest conclusion is that WEEELABEX was aspirational.