SMB1001 · Control 24 · Gold

Secure document destruction: what the standard actually requires

Gold-tier SMB1001 asks you to destroy paper securely. That does not automatically mean a contract with a destruction company, but sometimes it should.

· 5 min read

By the Gold tier, SMB1001 has moved past technology and into how your business physically handles information. Control 24 asks you to use secure methods of physical document destruction.

What counts as secure

The practical test is whether the output can be reassembled or read. A strip-cut shredder, the kind that produces long ribbons, does not really pass that test for anything sensitive. A cross-cut or micro-cut shredder does.

Tearing paper in half and putting it in the recycling does not count, and neither does a locked bin that is eventually emptied into general waste. What matters is the whole path from desk to destruction, not just the bin.

The simple way to comply

A cross-cut shredder, a written procedure saying what must be shredded rather than binned, and a log recording when destruction happened and who did it. For a small office with a filing cabinet and occasional printouts, this is the sensible answer.

The written procedure is the part most businesses skip, and it is the part that makes the control real. It should say plainly which categories of document must be destroyed (client records, financial documents, anything with personal information) so staff are not asked to make a judgement call at the bin.

When to use a destruction service

A destruction provider collects locked consoles on a schedule, destroys the contents under controlled conditions and issues a Certificate of Destruction. Several operate across Perth. Look for NAID AAA accreditation, which is the industry standard for secure destruction and is what gives the certificate its weight.

That certificate is the real difference. It is third-party evidence with a date on it, which is a stronger artefact than your own log if you are ever asked to demonstrate what happened to a particular file. Worth it when you handle client records under professional obligations, when you have volume rather than occasional pages, or when a contract requires certified destruction.

Be careful what you claim. Certificates of Destruction come from accredited destruction providers. An IT company shredding your paper and writing you a letter is not the same thing, and should not be described as if it were. If a supplier offers you “certificates”, ask who issues them and against what accreditation.

The part people forget

Archive boxes. Most businesses have a corner, a storeroom or a garage holding years of paper nobody has looked at. Under the standard that material is still in scope, and under privacy law you should not be keeping personal information longer than you need it.

A one-off bulk destruction of genuinely expired records is often the single most useful thing a business does when working toward Gold. It reduces what you have to protect, which is always cheaper than protecting it.

What an assessor will ask for

Your written procedure, evidence that destruction actually happens (a log, or certificates if you use a service) and a sensible answer about the archive. If you use a provider, keep the certificates somewhere you can find them rather than in a drawer.

Written by Steven Usher, Director of Owls Nest Solutions. Nothing here is legal advice, and none of it is a pitch. If the cheap option fits, take the cheap option.

Keep reading

More on the same standard