Most companies treat a device that doesn't come back as a lost asset — a line-item write-off, an IT annoyance. That framing is exactly the problem. The unrecovered laptop isn't primarily a cost. It's a live, unmanaged endpoint with your data on it, and an undocumented gap in the audit trail you'll have to answer for. Offboarding is a security function wearing an HR costume.
An unrecovered laptop is not primarily an asset-recovery problem — it is a compliance and security exposure. The device still exists, the data is still on it, and from an audit standpoint a device you can't account for is worse than one you've written off the cost of: it is an undocumented endpoint in your fleet and a hole in the chain of custody SOC 2, ISO 27001, GDPR, and HIPAA all expect you to close. The fix is to stop measuring offboarding as an HR status change and start measuring device retrieval and IT asset recovery as a security control — with a documented, defensible close for every departure.
In distributed companies, a meaningful share of devices never cleanly come back at offboarding. People leave, move, go unresponsive; the device is in another country; no one owns the retrieval. The asset gets quietly written off and everyone moves on.
But “written off” is an accounting decision, not a security one.
“Written off” is an accounting decision, not a security one. The device still exists. The data is still on it. And from a compliance standpoint, a device you can't account for is worse than one you've lost track of the cost of — it's a gap you have to disclose, or worse, one you don't even know to disclose.
The signal: device return is being measured (if at all) as an asset-recovery rate. It should be measured as a security and compliance control.
Walk the standard offboarding and watch where it stops.
HR marks the employee terminated. IT disables their accounts and SSO. Maybe a remote wipe command gets sent. The ticket closes. On paper, offboarding is “done.”
Here's what's still true the next morning:
Every one of those is a compliance problem, not a logistics one.
Security frameworks treat every device with company data as an endpoint you're responsible for. An unrecovered laptop is an endpoint you no longer manage but still own the liability for. It's the definition of shadow risk. MDM and device management can enforce policy on devices that stay online and enrolled — but the exposure lives in the ones that don't.
SOC 2, ISO 27001, and data-protection regimes like GDPR and HIPAA expect documented device disposition — proof that data was destroyed to a recognized standard. “We think it's gone” is not a control. An undocumented device is a hole in the audit trail.
Simply deleting files or reformatting a drive leaves recoverable data. Defensible destruction means wiping to a recognized standard (e.g., NIST 800-88) with a certificate — or physically destroying the drive with documentation. Most manual offboarding does neither.
The person is gone from your systems, but the exposure isn't. If that device surfaces in a breach, a lost-and-found, or a resale months later, it's still your data and your disclosure obligation.
The root cause is structural: offboarding is owned by no one end to end. HR owns the person, IT owns the accounts, and the physical device — the part that actually holds the data — falls between them. So it doesn't get done.
Treat every offboarding as a security event with a documented close, not an HR status change.
A complete offboarding has four physical steps after the account is disabled:
And measure it. Track a device disposition rate: of everyone who left this quarter, for what percentage do you have a recovered-and-certified-destroyed (or documented-destroyed) device? If you can't produce that number, that's the finding — and it's the same number a serious security review will ask you for.
The reframe to bring to your security and compliance teams: offboarding isn't complete when access is revoked. It's complete when the data-bearing device is recovered, destroyed to standard, and documented.
This is one of the clearest places to see the difference between managing a device and managing its lifecycle. Your MDM is the policy layer — it can lock and wipe a device if it's online and enrolled. But it can't put hands on the laptop that's gone dark in another country. That's an execution problem, and execution is the layer underneath.
GroWrk runs that layer: recovery through real local logistics in 150+ countries, certified wipe with a data-destruction certificate, chain of custody, and return to inventory for redeployment through global IT asset management. The offboarding doesn't close when HR clicks terminate — it closes when the device is back, wiped to standard, and documented, with the record to prove it.
MDM is the policy layer. GroWrk is the execution layer. Compliance lives in whether the execution actually happened — and whether you can prove it.
Same departing employee in another country.
Without lifecycle control: Account disabled. Remote wipe sent — device offline, never lands. Three follow-up emails to the ex-employee go unanswered. The laptop is written off. Six months later, no one can say where it is or whether the data was destroyed. At the next SOC 2 audit, it's a documented exception.
With lifecycle control: Offboarding triggers a recovery in-country. The device comes back, is wiped to standard, and a certificate of destruction plus chain-of-custody record is filed automatically. The device goes to inventory and is redeployed to the next hire. The audit asks for disposition proof; it already exists.
Same event. One is a compliance exception and a security risk. The other is a closed loop with a paper trail.
If your offboarding ends at “access revoked,” it isn't finished — it's paused at the riskiest point. The device that didn't come back is a security and compliance exposure sitting on someone's kitchen table, and it stays your problem until it's recovered, destroyed, and documented.
So here's the question worth taking to your next security review: what's our device disposition rate — and can we prove it? If the room goes quiet, that's the work.
If you want to see what a complete, audit-ready offboarding looks like across the countries your people are actually in, we would like to show you.