Green IT Hub
Professional Devices Lesson 5 of 5

Professional · Lesson 5 · ~7 min

Reporting & Compliance.

A 4 R policy without measurement is a poster. The leap from 'we recycle our hardware' to a defensible CSRD disclosure is mostly about asset-tagging discipline and a handful of well-chosen metrics.

This lesson covers what to measure, how the EU regulatory pipeline (CSRD, Right to Repair, Critical Raw Materials Act) maps to the IT lifecycle, and a 5-level lifecycle maturity model to position your organisation.

Close-up of a computer circuit board

What to measure

Few metrics, well chosen

The temptation when starting a sustainability programme is to measure everything. The reality is that 5–6 well-chosen metrics, reviewed quarterly, capture whether the 4 R policy is actually working. More than that and the dashboard becomes noise; fewer and the trends are invisible.

Three principles for choosing:

Auditable — each metric must derive from primary records (asset register, ITAD certificates, procurement contracts), not estimates.

Trend-sensitive — a metric that moves slowly is useless. Average device age at retirement is good (it shifts year-over-year). 'Total devices owned' is useless (it stays flat).

Action-linked — each metric should correspond to a lever someone can pull. If no one in the organisation can move it, why measure it?

Lifecycle KPIs worth tracking

A small set of metrics that captures whether your 4 R policy is actually working. Pick four to six and stick with them.
Suggested KPIs by lifecycle phase
Metric What it tells you Target direction
Average device age at retirement (years) Whether the cycle is genuinely extending ↑ over time, towards 6+ years
Refurbished-purchase share (% of procurement) Whether refurbished-first is real or aspirational ↑ over time, towards 50 %+ for office laptops
Repair completion rate (% of failures repaired vs replaced) Whether the repair operation actually works ↑ over time, towards 75 %+ for laptops
Mean time to repair (MTTR) (days from failure to user back working) Whether the in-house process is fast enough to defend the policy ↓ over time, towards < 2 days
Donation share of decommissioned devices (%) Whether the cascade to non-profits is operating ↑ over time, target depends on fleet composition
NIST 800-88 sanitisation coverage (% of decommissioned devices with certificates) Audit defensibility on data destruction 100 %
Material recovery by mass (kg by material category) Scope 3 disclosure quality ↑ as ITAD reports improve
Scope 3 IT hardware emissions (tonnes CO₂e) CSRD disclosure line ↓ over time, with refresh-cycle extension

Pick 4–6 to start, not all 8. A common-starter set: average age at retirement, refurbished-purchase share, NIST sanitisation coverage, donation share. Add MTTR and material-recovery once the basics are stable.

Knowledge check Your CFO asks for the IT hardware Scope 3 disclosure for the CSRD report. What is the most useful combination of KPIs to provide?

A 5-level lifecycle maturity model

Honest self-assessment

Most organisations sit between levels 2 and 3 and don't know it. Move up one level per year and you are doing well. Where does yours sit?

Level 1 — Replacement. No documented policy. Devices replaced on a fixed cycle (typically 3 years) regardless of condition. End-of-life: 'we recycle' (usually means no certificate trail).

Level 2 — Awareness. A documented refresh cycle exists. End-of-life routed through a single ITAD vendor, possibly without certifications. Some battery replacements, no systematic in-house repair.

Level 3 — Documented 4 R policy. Written 4 R policy, certified ITAD partner with sanitisation reports, KPIs reviewed quarterly, internal cascade tier defined (engineering → office). The threshold for 'doing it'.

Level 4 — Measured & reported. Monthly KPI tracking, CSRD-aligned material-recovery reporting, in-house repair function with parts stock, MTTR targets, refresh-cycle extension formalised. CSRD disclosures are primary-source-backed.

Level 5 — Circular by default. Refurbished-first procurement (>50 % of office devices), integrated donation pipeline with documented carbon offset, ITAD partner KPIs in their contract, internal carbon price applied in TCO. The maturity level that EU regulatory direction is heading toward.
Knowledge check Your organisation has a documented 4 R policy, certified ITAD partner with sanitisation reports, KPIs reviewed quarterly, and a battery-refresh programme. Which lifecycle maturity level does it sit at?

You've completed the Professional Devices path

Where to go from here

Five lessons of operational substance: procurement contracts as the biggest lever, fleet lifecycle and the 6-year case, repair and refurbishment at scale, decommissioning with audit trails, reporting that survives a CSRD audit.

The natural next step is the Green IT Ambassador — Professional Devices certificate assessment: 13 questions (5 from the shared Foundations pool, 8 from the Professional-specific pool), 75 % to pass, ~20 minutes. The certificate is downloadable as a PDF with a verification code — useful for LinkedIn, internal training records, sustainability programme documentation.

If you also make decisions for your own household, the Private Devices path covers that ground — the principles are the same but the levers and resources are different (consumer refurbishers, Repair Cafés, individual decision rules). The Private and Professional paths complement each other rather than overlap.

Watch — related video