A sales manager resigns on a Friday. By Monday her Okta account is disabled, her Slack is archived and her Google Drive has moved to her manager. Your Jamf console still shows her MacBook Pro, enrolled, encrypted and checking in from her apartment. Row 214 of the asset spreadsheet says “return label sent.” Nobody has touched row 214 in six weeks.

For a SOC 2 or ISO 27001 audit, laptop return evidence means four records per device: the serial number, the date it left the employee’s possession, a third-party receipt and a wipe certificate. Row 214 has none of them.
What evidence does a SOC 2 audit need for returned laptops?
Evidence, not a status column. SOC 2 criterion CC6.5 says you discontinue protections over a physical asset only after the ability to read or recover its data has been diminished. ISO 27001 control A.5.11, return of assets, asks the same question from the other side: did the asset come back when the person left?
In practice the request is simple. The auditor samples 14 terminations from Q3 and asks, for each one, for the serial number, the date the device left the employee’s possession, who received it and how the drive was sanitized. You open the spreadsheet and find dates you typed by hand, two rows marked “TBD” and a link to an email where an ex-employee says the box is “on the porch.” That is not a chain of custody. That is a finding.
Why can’t the spreadsheet produce it?
Because a spreadsheet records intent, not custody. Ivanti’s 2025 Digital Employee Experience report found that 34 percent of organizations still rely on spreadsheets to track IT assets, so this is the normal starting point, not a failure of your team.
The pattern is familiar. HR enters the termination. IT finds out later, sometimes only when the laptop stops checking in. Someone emails a label, adds a row and sets a reminder. The sheet now says a label was sent and a box was “probably shipped.” Every date in it was typed by someone on your team, which is exactly why an auditor will not accept it. We covered why spreadsheets break as exit volume grows in Why Your Offboarding Spreadsheet Breaks in 2026. The audit problem is narrower: even a perfectly maintained sheet is still your own testimony.
Doesn’t MDM already cover this?
No. MDM proves a device is enrolled. It does not prove where the device is, who has it or whether it will come back. A locked laptop in a former employee’s closet is still an unrecovered asset, with your data on the drive and your serial number on the depreciation schedule. Remote lock is a containment step. It does not close the record.
Access is not solved either. ShareGate’s 2026 survey of nearly 1,800 IT professionals found that 38 percent of organizations left former employees or guests with access they should have lost, and 35 percent hit an audit or compliance gap. None of this is new: in a 2009 Ponemon Institute study of 945 people who had left a job, 59 percent admitted keeping corporate data. Departing employees do not need malice to create exposure. They need a device nobody asked for back.
What does audit-ready laptop return evidence look like?
Four things, none of which require a six-figure platform.
First, a trigger tied to the HRIS, not to someone’s memory. The return starts when the termination is entered in BambooHR or Rippling, the same day the account is disabled. That gives the auditor a start date that matches the termination record.
Second, a return the employee cannot get wrong. A prepaid box with packing material and the label inside, shipped to their door, beats a label emailed to an inbox they no longer check. It also works fast: across our last 9K+ returns, the median employee ships the laptop back four days after the box arrives.
Third, timestamps you did not create. Carrier scans, receipt confirmation at intake and a recorded condition check give you a custody record that holds up because nobody on your team typed it.
Fourth, a documented end state. The drive is wiped to a named standard, the wipe is verified and a certificate is attached to the serial number. That is the line that lets you honestly say protections were discontinued after the data was gone.
The takeaway
The gap is not your tooling. HRIS and MDM each do their job. The gap is the handoff between them, where a departure becomes a physical box that has to travel back with proof attached. Run the auditor’s test before the auditor does: pull your last ten terminations and produce, for each one, the serial number, the date it left the employee, a third-party receipt and a wipe certificate. Every one you cannot produce is a finding waiting for a sample.
If you would rather not build this in-house, this is the work we do at LaptopReturn.
FAQ
What evidence does a SOC 2 audit need for returned laptops?
For each sampled termination: the device serial number, the date it left the employee’s possession, who received it, and how the drive was sanitized. SOC 2 CC6.5 and ISO 27001 control A.5.11 (return of assets) both point to dated records produced by a third party, not dates typed into a spreadsheet.
Does MDM prove a laptop was returned?
No. Jamf, Kandji or Intune prove a device is enrolled and can be locked. They do not prove who physically holds it or that it came back. Remote lock is a containment step, not recovery, and it does not close the asset record an auditor will sample.
How do you produce laptop return evidence without ITAM software?
Start the return from the HRIS termination, ship a prepaid box to the employee’s door, and keep the carrier scans, the receipt confirmation and the wipe certificate against each serial number. That gives you a dated, third-party record per device without buying an enterprise platform.