How to Build a Secure Laptop Return Process
GroWrk Team
IT asset recovery is the process of getting company laptops back from departing employees, verified against your asset register, sanitized to a documented standard, and routed to redeployment or disposal. For a mid-size company recovering devices from remote employees who quit, it has to work with no physical access, no office to walk into, and — critically — no payroll leverage. That last constraint is where most return processes fail, because the enforcement mechanism companies reach for first is the one that creates legal liability. A working laptop retrieval process removes friction instead of applying pressure.
The short answer:
- Do not withhold the final paycheck. South Dakota is the only US state that permits holding a final check until company property is returned. Everywhere else, wages and property are separate matters.
- For exempt employees, the deduction is prohibited even with written consent. DOL opinion letter FLSA 2006-7 is explicit — and most remote employees issued laptops are exempt.
- Start before the last day. Once corporate email and chat are revoked, your only channel is a personal address you may never have validated.
- Lock, don’t pre-wipe. A device the employee resets destroys your audit trail and any evidence of data exfiltration.
- Delivery is not recovery. The case closes when the serial is verified against your register and a sanitization certificate is attached to it.
What is the best way to get laptops back from remote employees who quit?
Treat the return as a controlled IT workflow with a named owner and defined escalation, not an informal exchange of emails between HR, IT, and someone who no longer works for you.
A secure laptop return process does ten things:
- Starts automatically when a departure is approved, not when someone remembers to email IT.
- Identifies every asset assigned to that employee, by serial number.
- Revokes access and secures the device at the correct time for the departure type.
- Gives the employee prepaid packaging and instructions that take four minutes to follow.
- Tracks every physical handoff through a documented chain of custody.
- Escalates delayed returns against defined aging thresholds.
- Inspects and sanitizes the device after receipt.
- Reconciles the device against the asset register.
- Routes it to storage, redeployment, resale, recycling, or destruction.
- Preserves evidence that each of those actions occurred.
Recovering the physical laptop is only part of the job. The company also has to protect its data, keep an accurate inventory, document custody, and recover residual value.
The scale of the problem is well documented. Capterra’s offboarding research found that 71% of HR workers who managed a departure in the previous year had at least one employee fail to return company equipment, at an average of roughly $2,000 per case — and separately that hybrid and remote employees are meaningfully more likely to retain devices after leaving. In allwhere’s 2026 ITAM survey, respondents ranked equipment recovery and offboarding as the second-largest ITAM challenge, behind only asset tracking and inventory accuracy. Those two are the same problem viewed from opposite ends.
Where remote returns actually break
Design the process around these, because they are the recurring failures:
- IT doesn’t hear about the departure in time.
- Nobody knows exactly which assets the employee holds.
- Return instructions arrive after the employee has already gone.
- The employee has no suitable packaging.
- A shipping label is created and never used.
- The device enters transit without adequate tracking or insurance.
- Nobody follows up when the shipment stops moving.
- The receiving team can’t match the laptop to the employee.
- The device arrives but is never inspected or wiped.
- The asset stays assigned to the former employee in inventory.
- IT, HR, Security, and Legal each assume another team owns it.
A process that only works when everything goes as expected is not a process.
The payroll deduction trap: what one in five companies gets wrong
This is where most published advice on the topic is actively dangerous.
allwhere’s survey found that when employees refuse to return equipment, 21% of companies withhold payroll delivery. A further 33% remotely lock the device via MDM, 29% refer the matter to legal, and 15% write it off. Roughly one in five companies reaches first for the remedy most likely to convert a $1,200 asset problem into a wage claim.
The actual position in the US:
Withholding the entire final paycheck is almost never lawful. The FLSA requires payment of all earned wages by the next regular payday, and most state wage payment laws are stricter, with deadlines that apply regardless of whether property has been returned. South Dakota is the sole exception — under S.D. Codified Laws § 60-11-14 it permits withholding a final paycheck until company property is returned. California and Texas explicitly prohibit holding a final check past the legal deadline for any reason, including unreturned equipment.
For exempt employees, the deduction is prohibited even with written authorization. In opinion letter FLSA 2006-7, the Department of Labor states that an employer cannot dock an exempt employee’s salary to recover the cost of unreturned company property even where the employee has authorized it, because the salary-basis rule entitles exempt employees to their full guaranteed salary. This is the detail almost nobody states, and it is the one that matters: the remote knowledge workers you issue laptops to are usually exempt. The category where deduction is most clearly barred is the category holding your hardware.
For non-exempt employees, a deduction may be permissible — conditionally. Federally it must not reduce pay below minimum wage or cut into owed overtime. Most states additionally require prior written authorization, some require advance notice (North Carolina requires at least seven days), and some, including Delaware, prohibit it outright.
Even where lawful, improper execution invites wage-theft claims, penalties or double damages in some jurisdictions, and predictable damage to trust with the employees who stay and hear about it.
The operational conclusion: pay in full and on time, and pursue the device as a separate debt. Equipment is a debt, and debts are resolved through collection — demand letters, invoicing at replacement cost, small claims — not through payroll. That is the compliant path, not a workaround, and it means the retrieval process has to be good enough to work without leverage.
Note how much circulating guidance gets this wrong. Sample return policies routinely include a clause stating that failure to return “may result in deductions from the final paycheck,” and vendor articles suggest damage costs “will be deducted from their salary.” Applied to an exempt employee, that clause is unenforceable. Written into policy and acted on, it is a liability you created yourself.
Employment and wage-deduction law varies by state and by classification, and this is not legal advice — but the safe default is identical everywhere: separate the paycheck from the laptop, and keep your enforcement clause pointed at civil recovery, which is enforceable in every state.
Who owns the return process?
One team must be accountable for the outcome. HR may trigger it, Security may revoke access, Finance may track value, a provider may move the box — but a shared responsibility with no named owner is how devices disappear.
| Team | Primary responsibility |
|---|---|
| HR / People Ops | Confirm departure date and type, employee status, personal contact details, jurisdiction-specific requirements |
| IT Operations | Verify assigned assets, initiate retrieval, manage inventory, close the asset record |
| Security | Revoke access, classify risk, preserve evidence, approve any destructive action |
| Manager | Help establish contact, confirm whether additional equipment was issued |
| Finance | Record losses, recovered value, lease obligations, disposition proceeds |
| Legal | Review non-return cases, litigation holds, jurisdiction-specific enforcement |
| Retrieval provider | Package, collect, transport, inspect, sanitize, document |
Assign a single recovery owner per departure. That person or platform should know which device is due, which stage it’s in, how long it has been there, what happens next, who does it, and when it escalates.
Building the process, step by step
1. Start at onboarding, not at exit
The strongest return process begins before the laptop ships. When equipment is issued, record device type, make and model, serial number, asset tag, purchase or lease status, accessories, condition, replacement value, employee name and location, shipping address, and date assigned — with a signed acknowledgement that the equipment belongs to the company.
The equipment agreement should state which items must be returned, who pays shipping (you do), how packaging is provided, the return window, expected condition, how loss or damage is reported, who to contact for help, and what happens when equipment isn’t returned. Keep that last clause pointed at civil recovery rather than payroll.
2. Trigger the workflow from the exit approval
An HRIS event should create the retrieval case automatically through HRIS integration, carrying employee name, personal email and phone, current address, final working date, departure type, manager, region, expected assets, risk classification, and any legal instructions.
Planned resignations and immediate terminations should not follow the same sequence. For a planned resignation, communicate the return process before the final day. For a sensitive termination, Security may need to revoke access before the employee receives shipping instructions. Predefine the order for each departure type.
3. Reconcile the assigned assets
Before sending anything, confirm what you expect back. Check IT asset management records, MDM, HRIS, procurement, shipping history, support tickets, lease records, and the signed acknowledgement.
Never write “return your laptop and equipment.” Write:
MacBook Pro, serial ending 9X2Q · Dell 27-inch monitor · USB-C dock · power adapter · security key · company phone
The serial number is the point. A return is not complete because a laptop-shaped package arrived. If your records disagree with each other, resolve that before initiating the return.
4. Classify the security risk
Not every offboarding needs the same response.
Standard risk: voluntary departure, no known concern, device visible in MDM, normal access profile.
Elevated risk: involuntary termination, access to sensitive customer or financial data, privileged admin permissions, unusual download or transfer activity, legal hold, pending investigation, or a device that has stopped checking in to MDM.
The classification determines when credentials are revoked, whether sessions are terminated, whether the device is locked, whether remote wipe is permitted, whether forensic preservation applies, whether the return is expedited, and whether Legal must approve disposition.
5. Revoke access - and don’t rely on the laptop as your security control
You may wait days for the hardware. Access revocation shouldn’t wait for it. At the authorized termination time, address identity provider access, email, VPN, SSO sessions, cloud applications, admin accounts, API keys, password managers, source repositories, file sharing, local credentials, recovery keys, and MDM status.
Then record the encryption status and last MDM check-in. That record is your evidence if the device never comes back — a lost laptop with verified full-disk encryption and a successful remote wipe is a materially different incident from one whose state you can’t establish.
6. Lock, don’t wipe
Some guidance recommends remotely wiping before shipment. That is usually wrong. Immediate wiping can destroy forensic evidence, erase locally stored business information you still need, remove device visibility, and violate a legal hold.
The safer sequence: revoke account access, terminate sessions, confirm disk encryption, place the device in a managed lock or restricted state, preserve logs, and only then decide whether remote sanitization is warranted based on risk, connectivity, and incident-response requirements. Security approves any destructive action — not the departing employee, not logistics.
7. Confirm the address and contact details
Addresses change during employment. Verify the full address, unit number, postal code, country, personal email, personal phone, pickup restrictions, building access, and availability — via a confirmation link, not an old HR record. For involuntary departures, get the best personal contact details from HR before company access is disabled.
Treat residential addresses as sensitive personal information and limit access to the teams that need them.
8. Send a kit the employee can use in four minutes
Correctly sized protective box, cushioning or inserts, antistatic protection where appropriate, tamper-evident closure, prepaid label, packing instructions, the expected equipment list, the deadline, pickup scheduling, a support contact, tracking reference, and prohibited-items guidance. Ground shipping for lithium-ion compliance.
Instructions should be short, visual, and specific:
1. Place the laptop in the protective sleeve. 2. Put the sleeve in the insert. 3. Power adapter goes in the accessory section. 4. No personal property. 5. Seal with the supplied strip. 6. Photograph the sealed box. 7. Schedule pickup using the link.
Offer carrier pickup rather than requiring a trip to a depot. The person has already left; they have no reason to make the drive.
9. Set a real deadline and a communication cadence
“As soon as possible” is not a deadline. State the action and the date: confirm your address by Tuesday 4 August, hand the package to the carrier no later than Friday 7 August.
| Timing | Action |
|---|---|
| Day 0 | Return notice sent, address confirmation requested |
| Day 1 | Reminder if unacknowledged |
| Day 2 | Contact attempt via second approved channel |
| Day 3 | Escalate to former manager and HR |
| Day 5 | Confirm kit delivery and pickup status |
| Day 7 | Escalate unused label or missed pickup |
| Day 10 | HR or Legal reviews non-return case |
| Day 14 | Classify as seriously overdue, begin formal recovery |
Adjust for geography, carrier availability, and local employment requirements. The control that matters is that every aging threshold triggers a defined action. Never use an open-ended status like “waiting for employee” — use “address confirmation overdue” or “kit delivered, pickup not scheduled,” which name the owner and the next step.
10. Track status and aging, not just shipments
Every open retrieval needs a standardized status with an owner, start timestamp, target completion, next action, and escalation threshold.
| Status | Owner | Escalate when |
|---|---|---|
| Awaiting address confirmation | HR | No response after 2 business days |
| Kit delivered | IT Operations | No pickup scheduled after 3 business days |
| In transit | Logistics provider | No carrier movement after 2 business days |
| Delivery exception | Logistics provider | Unresolved after 1 business day |
| Inspection pending | Receiving team | Not completed within 2 business days |
| Sanitization pending | Security or ITAD partner | Not completed within agreed SLA |
That distinction — status and aging versus tracking numbers — is the difference between watching a shipment and controlling a recovery.
11. Predefine the exceptions
Employee unavailable. Wrong address. Kit lost. Label expired. Missed pickup. Package refused. No carrier movement. Damaged package. Device reported stolen. Wrong device returned. Missing charger. Customs hold.
Each needs a named owner and a defined response. For example, no carrier movement for 48 hours: confirm the first scan, contact the carrier, notify the recovery owner, record the carrier case number, review insurance, escalate if unresolved within one business day.
12. Verify on arrival, same day
Don’t close the case on carrier delivery confirmation. Check the tracking number, package seal, and damage. Photograph the outer packaging before opening if chain-of-custody or damage concerns warrant it. Unbox and verify manufacturer, model, serial, and asset tag against your records. Confirm accessories, condition, power-on state, encryption or firmware-lock status, MDM enrolment, and signs of tampering.
Record the inspection against the original asset, not just the shipment. If the wrong laptop or an incomplete set arrives, reopen the recovery workflow rather than marking it complete.
The step nearly every guide omits: if the employee was terminated, filed a complaint, or is otherwise in dispute with the company, flag the asset for litigation hold before anything else happens to it. Mark the record, move the device to locked storage, involve Legal before any wipe. Sanitizing a device that turns out to be evidence is a far larger problem than an unreturned laptop.
Chain of custody, sanitization, and disposition
What chain of custody actually means
A carrier tracking number tells you where a package may be. Chain of custody tells you which asset moved, who held it, when possession changed, where, in what condition, who accepted the next handoff, and what happened afterwards.
Record: case ID, employee, make and model, serial, asset tag, outbound kit tracking, kit delivery, employee acknowledgement, pickup confirmation, carrier acceptance, transit events, delivery confirmation, receiving location and recipient, package condition, device condition, sanitization status, final routing, photographs, and certificates.
Require signature confirmation or an equivalent documented handoff for higher-value devices. When custody passes to a third party, that provider should update the same asset record rather than producing a disconnected report.
Sanitize to NIST SP 800-88 Rev. 2
This is where a lot of policy documentation is now out of date. NIST withdrew SP 800-88 Rev. 1 on 26 September 2025 and superseded it entirely with Revision 2 — the first update since 2014. Policies, contracts, and RFP language still citing Rev. 1 or its Appendix A device tables now reference a withdrawn document, which is exactly the kind of gap an auditor flags.
What changed matters operationally:
- The three methods - Clear, Purge, Destroy - remain, but Rev. 2 shifts focus from hands-on technique selection to running a documented sanitization program, aligned with SP 800-53 and ISO/IEC 27040.
- Apart from cryptographic erase, Rev. 2 removed the technique and tool detail entirely and defers to IEEE 2883-2022, NSA specifications, or an organizationally approved standard.
- Multi-pass overwriting is not required. A single pass or the device’s dedicated sanitize command satisfies Clear. On SSDs, extra passes add nothing and consume drive endurance — so a vendor still selling you a three-pass DoD wipe is quoting retired guidance.
- Degaussing does nothing to SSDs and flash media, and overwrites alone don’t reach Purge on solid-state drives.
Record per device: make and model, serial, asset tag, media type, sanitization method and technique, tool and version, operator, date and time, verification result, exceptions, and final destination. Rev. 2 includes a sample certificate of sanitization with these fields.
A generic certificate saying “devices were securely wiped” is worthless. The certificate must be tied to the individual serial number, and sanitization without verification and a serialized record is not defensible.
Route the asset and close the record
Every recovered device gets a documented disposition: redeploy, repair and redeploy, store with a known location and last-audit date, resell with grade and recovered value recorded, or recycle and destroy with certificates retained.
Then reconcile. Update assigned employee, location, condition, completion date, sanitization status, availability, storage location, new assignment, resale value, certificate references, and accounting treatment. Remove the device from the former employee’s profile but preserve the assignment history.
A recovered laptop with no disposition decision has not been recovered — it has been relocated. Set a 30-day clock.
Measure outcomes, and decide whether to outsource
Most teams measure retrievals completed, which tells you almost nothing. Measure instead: recovery rate split by voluntary versus involuntary departure and by region; recovery within 7, 14, and 30 days; average time from retrieval trigger to verified receipt rather than to label creation; time to first employee contact; time in each status; open retrievals by age bracket; unrecovered asset value; damage-in-transit rate; serial-match accuracy on intake; sanitization evidence completion; and recovered value through redeployment, resale, and avoided replacement purchases.
For context on why this deserves real ownership: in allwhere’s survey, 37% of companies reported spending over 21 hours per week on ITAM tasks overall, with another 25% spending 11 to 20 hours. Recovery is a meaningful share of that, and it’s the part most amenable to automation.
In-house works when employees are concentrated in one country, volume is low, IT has logistics capacity, you have secure receiving and sanitization facilities, and asset records are reliable.
A provider becomes the better answer when employees are distributed, offboarding is continuous, IT is spending real time chasing people and carriers, devices are falling between HR, shipping, and inventory systems, or you need consistent chain-of-custody evidence across regions.
Two structural notes for a mid-size company. Recovery is worth outsourcing before deployment is — deployment is schedulable, while recovery is unpredictable, awkward, and requires chasing someone who no longer works for you. And watch the pricing model: per-seat platforms bill your headcount whether you offboard two people this quarter or twenty, so if turnover is lumpy, pay-as-you-go tracks the actual work.
When evaluating any provider, the question is whether it owns the recovery outcome or merely generates shipping labels.
Frequently asked questions
Can we withhold a final paycheck until the laptop comes back?
Almost certainly not. South Dakota is the only state permitting withholding a final paycheck until company property is returned. Elsewhere, federal and state wage laws require payment of earned wages by the applicable deadline regardless of unreturned property. Pay on time and pursue the device separately.
Can we deduct the laptop’s cost from the final paycheck?
It depends on classification and state. For exempt employees, DOL opinion letter FLSA 2006-7 says no — even with written authorization. For non-exempt employees a deduction may be permissible federally if it doesn’t reduce pay below minimum wage or cut into overtime, but many states require prior written consent, some require advance notice, and some prohibit it entirely.
How long should an employee have to return a company laptop?
Most policies use 7 to 14 days from the last working day. What matters more than the number is that the deadline appears in the signed equipment agreement, the kit arrives before the clock starts, and intermediate deadlines exist for address confirmation, pickup scheduling, and carrier acceptance.
Should the laptop be wiped before it’s returned?
No, not automatically. Revoke access, terminate sessions, confirm encryption, and lock the device. Security then decides whether remote wiping is appropriate. Don’t wipe when forensic evidence, a legal hold, locally stored business information, or device visibility must be preserved — and inspect before sanitizing.
Who pays for return shipping?
The company. Requiring a former employee to fund the return of your property depresses recovery rates, and prepaid kits are the single highest-leverage change most teams can make.
What happens if a remote employee never returns the laptop?
Follow the documented escalation: confirm they received instructions and packaging, attempt contact through approved channels, involve HR and the former manager, secure the device through MDM, and refer to Legal. Recovery runs through civil channels — demand letter, invoice at replacement cost, small claims. Assess whether it’s a reportable data incident, and record the write-off.
What’s the difference between laptop retrieval and IT asset disposition?
Retrieval gets the device back from the employee. Disposition decides what happens next — sanitization, redeployment, resale, recycling, or destruction. A complete IT asset recovery process connects both through the same asset and chain-of-custody record.
The process is the enforcement
The instinct when someone quits with your laptop is to find leverage. The law has largely removed the leverage that feels most obvious, and the companies with the best recovery rates aren’t the ones with the most aggressive policies - they’re the ones where returning the laptop takes the departing employee about four minutes.
So the work happens upstream. An agreement signed at onboarding that names serial numbers and points at civil recovery. A kit that arrives before the last day, prepaid and correctly sized. An MDM posture that can lock the device the moment access is revoked. Automated follow-up that doesn’t route through an email account you’ve disabled. Aging thresholds that trigger action instead of statuses that wait. And an intake process that verifies the serial, holds the device if there’s a dispute, sanitizes to NIST 800-88 Rev. 2, and files the certificate against that serial.
GroWrk runs that sequence on one asset record - HRIS-triggered retrieval, prepaid kits with employee communication handled for you, in-country warehousing across 150+ countries, verified sanitization with per-device certificates, and redeployment, resale, or certified recycling on the other side. Customers using the service see recovery rates of 95%, and higher over longer recovery windows.
A recovered device protects more than its replacement cost. It protects data you remain accountable for, preserves residual value, produces the evidence an audit will ask for, and ends the employment relationship in a way the departing employee will describe accurately to other people.
