Company context
The company manages the secure movement, custody, retrieval and destruction of information-bearing materials for institutional customers. Its operations combine scheduled collection, sealed transport, controlled facilities, identity and access management, evidence generation, material segregation and downstream recycling. The business is expanding through regional density, additional services and selective acquisitions.
Trust is the core asset. A service can appear complete in billing systems while a container was never collected, custody was interrupted, destruction evidence was unreliable or recovered material left the controlled chain. The company must also balance confidentiality with environmental objectives: material recovery is valuable only after information has been irreversibly destroyed and downstream processors are appropriately governed. The Board seeks an Independent Director capable of protecting that hierarchy.
The Board mandate
The Director will provide independent oversight of chain-of-custody integrity, destruction assurance, customer-data protection, workforce screening, route controls, evidence systems, recycling counterparties, acquisition integration and leverage. The mandate includes examining whether growth creates operational shortcuts or excessive dependence on manual attestations.
The successful candidate will help management turn customer trust into a scalable control architecture. Procedures must work at remote collection points, during route changes, across temporary staff and after acquisitions—not only inside flagship facilities. The Director will also challenge commercial practices that promise unrealistic retrieval or destruction timelines, underprice risk or accept ambiguous ownership of customer materials.
Strategic and governance responsibilities
-
Establish end-to-end custody evidence. Define custody events from customer handover through transport, facility receipt, storage, processing, destruction and downstream transfer. Exceptions, broken seals and missing scans must trigger timely investigation.
-
Assure irreversible destruction. Review approved methods, equipment settings, maintenance, residue size, segregation, operator access, video or sensor evidence, sample verification and certificate issuance. Certificates should arise from completed evidence, not scheduled work.
-
Protect customer metadata. Govern service addresses, collection patterns, box indexes, retrieval requests, employee identities, legal holds and destruction authorisations. Metadata itself may reveal sensitive commercial or personal information.
-
Strengthen authorisation controls. Ensure only valid customer representatives can request retrieval, transfer or destruction. High-risk or bulk actions should use enhanced verification, separation of duties and immutable logs.
-
Govern transport security. Review route planning, vehicle access, seal control, tracking, unscheduled stops, subcontracting, incident escalation and reconciliation of every container loaded and unloaded.
-
Control facility access. Examine zoning, visitor management, surveillance coverage, blind spots, key and credential control, tailgating prevention, emergency access and retention of evidence. Privileged access should be regularly recertified.
-
Oversee workforce integrity. Review background screening, role rotation, conflicts, confidentiality, temporary labour, contractor supervision, incentive design and whistle-blower protection. Productivity targets must not encourage bypassing custody steps.
-
Make contract obligations explicit. Examine liability, service levels, destruction standard, legal holds, incident notification, subcontracting, audit rights, evidence retention, ownership of recovered material and termination transfer.
-
Govern downstream recovery. Require diligence on processors, transport, residue custody, environmental compliance, mass balance and prohibition of unauthorised resale. Recycling claims must follow verified destruction and traceable transfer.
-
Improve customer-level economics. Capture collection frequency, route density, storage occupancy, retrieval effort, destruction volume, evidence burden, equipment use, insurance and receivables. Recurring invoices do not automatically mean attractive recurring cash.
-
Prepare for compound incidents. Test response to lost containers, unauthorised retrieval, destruction-system failure, insider misconduct, facility intrusion, ransomware, fire, flood and failure of a downstream processor. Notification choices must be governed, not improvised.
-
Create acquisition discipline. Assess target custody practices, undocumented inventory, customer authorisations, workforce screening, environmental liabilities, leases, litigation, evidence quality and owner dependence before valuation.
-
Govern integration. Require early physical verification, access reset, policy migration, customer communication, route-control adoption, evidence-system conversion and closure of unsafe sites. Synergy timing must not outrun control migration.
-
Balance leverage and resilience. Stress-test debt service against customer loss, a material breach, delayed integration, facility shutdown, insurance gaps and required remediation. Maintain liquidity for incident containment and customer restitution.
Decisions expected at Board level
The Director will contribute to acquisitions, new facilities, destruction equipment, digital-custody platforms, subcontracting models, major institutional contracts, recycling partnerships, insurance limits, debt facilities and strategic exit readiness.
Every acquisition paper should distinguish reported earnings from earnings after required security, environmental, technology and workforce upgrades. Every major customer contract should identify custody boundaries, authorisation logic, evidence standard, incident obligations, liability allocation and the resources needed to meet service levels under disruption.
Audit, security and sustainability agenda
The Board dashboard should include containers collected and reconciled; custody exceptions; retrieval and destruction authorisation exceptions; certificate corrections; facility access anomalies; route deviations; background-screening gaps; customer complaints; security incidents; volume mass balance; downstream processor exceptions; contract contribution; receivable ageing; acquisition controls migrated; insurance matters; and covenant headroom.
Internal assurance should use surprise counts, route shadowing, seal reconciliation, controlled retrieval tests, destruction-evidence sampling, access-log review and downstream mass-balance verification. Serious custody or destruction concerns must have a direct path to the Independent Director even when management has not yet confirmed customer impact.
Candidate profile
Candidates should have at least 22 years of leadership experience in information security, records management, secure logistics, regulated operations, facilities services, waste and recycling, audit, risk, finance or private equity portfolio governance. Experience with chain-of-custody operations, distributed workforces, sensitive customer information, acquisitions or evidence-based compliance is desirable.
Suitable candidates may be former CEOs, COOs, CFOs, CISOs, risk leaders, quality executives, operating partners or Audit Committee Chairs. The candidate must be able to challenge both physical and digital controls and should be willing to visit collection, storage, destruction and downstream processing operations, including without extensive advance preparation.
Eligibility, independence and conflicts
Active inclusion in the IICA Independent Directors Databank is mandatory. The appointee must remain independent of the financial sponsor, founders, management and significant counterparties. Relationships with major customers, competitors, transport providers, facility owners, security vendors, recycling processors, insurers, lenders, investors or acquisition targets must be disclosed.
The role may not be used to sell cyber, audit, security, logistics, real-estate or transaction services. Because Board materials may describe sensitive customer operations, the appointee must observe enhanced confidentiality and secure-document handling.
First 100-day priorities
- Trace sample containers from customer authorisation through custody, destruction evidence and material recovery.
- Visit a storage facility, destruction operation and downstream processing counterparty.
- Review custody exceptions, certificate corrections, access anomalies and prior security incidents.
- Examine the largest customer contracts and the economics of route, storage and retrieval commitments.
- Assess recent acquisitions for unremediated security, environmental and inventory risks.
- Agree non-negotiable Board escalation triggers for loss of custody, invalid destruction or insider misconduct.
First-year outcomes
Success will mean independently testable custody, reliable destruction evidence, controlled customer authorisations, verified downstream recovery, acquisitions integrated to a common security baseline and a value-creation plan that does not depend on understated risk investment. The company should be more scalable precisely because accountability is explicit at every handoff.