You already know the offboarding checklist: final paycheck, benefits paperwork, exit interview, access revoked in the directory. What you may not have a clean answer for is where the laptop actually is right now, today, for every employee who left in the last six months.
Is it an IT problem or an HR problem? If we have to ask that, then you know the answer. It sits right between the two, which is usually why it falls through.
The data security problem is worse than “a missing laptop”
Start with the basic exposure. A laptop or phone that walks out the door with a departing employee is still logged into your systems. Depending on the role, that means customer records, financial data, source code, internal chat history, and saved credentials that may still have live access even after you have disabled the account in your directory. Disabling SSO does not always kill a cached session, a local copy of a file, or a mobile app token that has not checked in for renewal yet.
Now stack the AI layer on top of that.
Most employees today are using some combination of ChatGPT, Copilot, Gemini, or an AI browser extension connected to their work accounts, and many of these tools retain conversation history, uploaded files, and connected-app permissions tied to that device and that login. An employee who pasted a client contract into an AI assistant, or connected it to their email or drive for “help drafting,” has effectively created a second copy of your data living outside your systems entirely, one that your offboarding checklist was never built to catch. The device is the access point, but the AI tool is where the data now also lives, cached, summarized, or logged in a place your IT team does not control and may not even know exists.
This is the part that should keep operational IT and HR compliance teams up at night. It used to be enough to wipe the device and revoke the account. Now you have to ask what that device was connected to, what it fed into, and whether any of that is still retrievable by someone who no longer works for you. A missing laptop is one incident. A missing laptop that had six months of AI tool access to your customer data is a much bigger conversation with legal.
Most of the time none of this is malicious. People forget devices exist, forget what they connected, and move on. But intent does not matter to an auditor or a regulator, and it will not matter to a customer whose data ends up somewhere it should not be. What matters is whether you can show, in writing, that access was revoked, the device was recovered, and the data trail was closed.
If your company carries SOC 2, ISO 27001, or HIPAA obligations, an unretrieved device is not a hypothetical risk. It is a documented finding waiting to happen. Auditors ask for evidence of a closed offboarding loop: access revoked, device returned, data wiped, chain of custody logged. “We think it’s fine” is not evidence. A missing laptop with no retrieval record is a gap you will have to explain, and increasingly, so is an unaccounted-for AI connection.
The financial problem
Set security aside for a moment and look at the balance sheet. A laptop that never gets recovered is not a soft loss. It is an asset still sitting on your books, still depreciating on paper, that IT now has to replace for the next hire at full price.
Multiply that across a year of turnover and the number adds up fast. A mid-size company with routine attrition can lose tens of thousands of dollars annually in hardware that was already paid for and simply never came back. That is money spent twice: once for the original device, once for its replacement.
Retrieval also affects the value you get back. A laptop returned within a week of separation, in working condition, with original accessories, resells or redeploys at a very different price than one that turns up eight months later with a cracked screen and no charger, if it turns up at all.
Why this keeps happening
You know why. Offboarding is owned by HR on paper, but device retrieval is an IT and logistics job, and when resignations happen fast or messy, nobody has time to think about the laptop until three months later when someone asks where it went. Remote and hybrid teams make this harder still. There is no manager walking past a desk to notice the hardware is still sitting there.
More urgency will not fix this. A process will. What actually works is a retrieval workflow that triggers automatically the moment offboarding starts in your HR system, with prepaid shipping, tracked chain of custody, and a hard deadline for return, so recovering the device is not a task someone has to remember to do on top of everything else.
How ComputerCare helps
This is exactly the gap our ITAM and device lifecycle services are built to close. We handle the retrieval logistics, provide prepaid return shipping and tracking, confirm devices arrive and get wiped to spec, and give you the documented audit trail your compliance team can hand to an auditor without a scramble. Whether it is one departing employee or a full reduction in force, we make sure the hardware comes back and the data trail closes with it.
If you are the one who ends up fielding the “did we ever get that laptop back” question, we would like to make sure you have a good answer every time. Reach out to the ComputerCare team to talk through what a retrieval workflow could look like for your organization.