Multi-million dollar ITAD fine for bank

05 January 2021
3 minute read
Best practice

Multi-million dollar ITAD fine for bank

05 January 2021
3 minute read
multi-million dollar ITAD fine

Image by dokumol from Pixabay

International bank Morgan Stanley have been hit with a $60 million fine from the US Treasury Dept. for “engaging in unsafe or unsound practices relating to information security and noncompliance”; this was brought about by failures in their ITAD (IT Asset Disposition) policies and procedures.
The “Office of the Comptroller of the Currency” (OCC) – which, as part of the Treasury Dept. regulates and supervises all national banks, and federally licensed branches of foreign banks, in the United States of America – issued a “consent order” that gave more details on the issues. They found that, in 2016, Morgan Stanley fell short in several areas and failed to:

  • Exercise proper oversight of the decommissioning of two datacentres
  • Effectively assess/address risks associated with the decommissioning of its hardware
  • Adequately assess the risk of using third party vendors, including subcontractors
  • Maintain an appropriate inventory of customer data stored on the devices
  • Exercise adequate due diligence in selecting the third-party vendor
  • Adequately monitor the vendor’s performance

They then experienced “similar vendor management control deficiencies” in 2019, prompting further action. It seems that data was left on devices post-decommissioning and that they were also unable to account for some of the server hardware after it had been retired. As well as the OCC fine, Morgan Stanley now face a range of class-action lawsuits that have been brought by customers.

We have highlighted several times this year that, with the rise of remote working driven by COVID-19, Hardware Asset Management (HAM) and IT Asset Disposition (ITAD) are more critical than ever before. This case helps highlight some of the elements that must be considered when implementing these areas within the business and shows that simply passing it off to a third-party isn’t the end of it. If engaging with an ITAD provider, you must ensure that you have procedures in place to:

  1. Select the right partner and assess the risks
    • Check their credentials and certifications, as well as their lifecycle management processes
  2. Continually monitor that they’re doing what they should be
    • Regular checks, a set of benchmark criteria, a process for remediation

While this multi-million dollar ITAD fine is perhaps an above average penalty, it does highlight the possible risks – financial and reputational – that can accompany less than stellar ITAD management. Consider this as you work with your business to identify priorities for 2021.

Further Reading

ITAD firms weigh in on bank’s $60M data mismanagement fine
OCC Consent order
What you need to know about ITAD
ITAD maturity assessment

About Rich Gibbons

Rich has been in the world of IT and software licensing since 2003, having been a software sales manager for a VAR, a Microsoft licensing endorsed trainer, and now an ITAM analyst looking at software licensing and cloud.

A Northerner renowned for his shirts, Rich is a big Hip-Hop head, and loves travel, football in general (specifically MUFC), baseball, Marvel, and reading as many books as possible. Finding ways to combine all of these with ITAM & software licensing is always fun!

Connect with Rich on Twitter or LinkedIn.

Can’t find what you’re looking for?

  • news post 1 ITAM News & Analysis

    Will 'Sustainable IT' be Caught in the Crossfire?

    In the days immediately following his inauguration, President Trump and his team declared war on Diversity, Equity, and Inclusion (DEI) programs at the federal level. The impact has been felt far and wide. Many government contractors ...
    Read More
  • news post 1 AI

    Are we ready for outcome-based pricing?

    When I first joined the ITAM industry (which feels like a million years ago), the predominant licensing metric in the market was per device. So, if you have three devices, you need three licenses. Then, with ...
    Read More
  • news post 1 AI

    AI and ML: The Game Changers in ITAM for 2025

    IT Asset Management (ITAM) is experiencing a groundbreaking evolution, heavily influenced by the adoption of Artificial Intelligence (AI) and Machine Learning (ML). These cutting-edge technologies will revolutionise conventional ITAM methods while bringing both exciting possibilities and ...
    Read More
  • news post 1 Best practice

    Data Management Best Practices

    Effective data management is crucial for successful IT asset management. Leveraging a structured approach like the PDCA (Plan-Do-Check-Act) cycle can help structure your efforts. This approach should be easy to integrate into the existing processes and/or ...
    Read More