Identification
Unique CoD number, preparer name, and organization details so each destruction event can be traced unambiguously.
A completed CoD reduces legal and privacy risk by documenting proper disposal, supporting audits, and showing compliance with federal rules like HIPAA and IRS recordkeeping where applicable.
Teams that commonly prepare or sign CoDs include records managers, IT asset disposition vendors, compliance officers, and business owners responsible for data lifecycle controls.
The final signed CoD should be retained according to your retention schedule and made available for internal or external review when required.
| Field | Configuration |
|---|---|
| Routing Order | Set signer sequence: preparer → approver → certifier |
| Authentication | Email + SMS code or organization SSO for higher assurance |
| Audit Trail | Enable IP, timestamp, and action logging |
| Archive Location | Save PDF/A copy to secure records repository |
Ensure the signing platform supports secure file formats, an auditable completion certificate, and integration with your records system.
Choose settings that produce a tamper-evident signed file with metadata export and searchable archive entries to meet audit and legal requirements.
Unique CoD number, preparer name, and organization details so each destruction event can be traced unambiguously.
Detailed descriptions, serial numbers, and quantities for all destroyed items to avoid disputes in later audits or legal reviews.
Specify the destruction method used (shredding, degauss, wipe) and any standards followed, such as NIST SP 800-88 for media sanitization.
Signed approval from the records owner or compliance officer showing permission to destroy items and confirming no legal holds exist.
Signature block for the person certifying destruction with date and role, optionally authenticated or notarized if required by policy.
Instructions on how long the CoD itself must be kept, including references to internal policy or external regulatory requirements.
Record actual destruction date in MM/DD/YYYY format; this starts retention for the CoD record.
Note when the records owner approved destruction to show proper permission was obtained.
Notify stakeholders within the timeframe set by internal policy or state privacy law where applicable.
Retention of the CoD typically begins on the destruction date unless law provides otherwise.
Make the CoD available for internal or external audit within the period required by governing policy.
Optica standardized destruction records across subsidiaries to reduce disputes.
A property manager began issuing CoDs after tenant file disposal.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |