Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryObsolescence Procedure
Contents & downloads
- GOV-POL-001
- QHSE-MAN-001
Nomenclature
| Term | Definition |
|---|---|
| DISP | Defence Industry Security Program. |
| EoL | End of Life. |
| EOSL | End of Service Life (also called End of Support Life). The date after which the original manufacturer (OEM) will no longer provide support, maintenance, software updates, security patches or technical assistance for a product. |
| FTM | Finance and Technology Manager. |
| ICS | Industrial Control System(s). |
| OPEX | Operational Expenditure. |
| OT | Operational Technology. |
| Obsolescence | A condition where an asset no longer meets required performance, safety, security, supportability, regulatory or economic criteria due to EoL, vendor support termination, parts unavailability, incompatibility, or cost/risk imbalance. |
| System of Record | The Fixed Asset Register in Xero is Westlink’s authoritative register for fixed assets; supporting registers may exist for tax accounting, configuration, software licensing and information assets. |
Purpose
This procedure defines how Westlink Logistics identifies, assesses, and manages obsolescence across all asset classes. It protects safety, quality, security, compliance, service continuity, and cost efficiency. It sets minimum requirements for planning lifecycle transitions, mitigating risks from end-of-life (EoL) components, and ensuring compliant, secure, and sustainable disposal.
Scope and Asset Classes
This procedure applies to all Westlink assets, whether owned, leased, or under custodial control, including:
-
Information & Technology Assets: End-user devices, servers, network equipment, OT/ICS devices, storage, licensed software, operating systems, applications, and cloud services.
-
Plant, Equipment & Tooling: Lifting gear, project equipment, workshop tools, instruments, and test/measurement devices.
-
Fleet & Vessels: Vehicles, trailers, marine craft and related equipment.
-
Facilities & Infrastructure: Building systems, security systems, generators, UPS, environmental controls.
-
Data, Media & Records: Digital data, removable media, paper records, and archival holdings.
-
Commercial/Support Assets: Furniture, fixtures, and other durable goods.
-
Spares & Consumables: Obsolescence-susceptible parts that affect maintainability or safety.
-
Out of scope: Consumables fully expensed on purchase unless their obsolescence creates safety, regulatory, or service risk.
Key Principles
-
ISO 9001 Alignment: Integrates risk-based thinking, control of externally provided processes, and change management.
-
Lifecycle Management: Obsolescence risks are assessed at acquisition, during operation, and prior to decommissioning.
-
Trigger Events: Includes vendor end-of-life (EoL) notices, support termination, cyber risks, parts scarcity, regulatory changes, and performance issues.
-
Treatment Options: Range from life extension and migration to secure disposal, with a strong preference for recycling and data sanitisation per best practice standards.
-
Records & Evidence: All actions and decisions are documented in the Xero Fixed Asset Register, with supporting evidence retained per QMS requirements.
-
Roles & Responsibilities: Clearly assigned to the Policy Owner (Finance & Technology Manager), CEO, Finance, Procurement, IT, and QHSE.
-
Continuous Improvement: Performance is monitored through KPIs such as EoL coverage, timely assessment, secure disposal, and recycling rates.
Policy Statements
Governance & Compliance Alignment
Westlink must manage obsolescence within its Quality Management System. This management must align with ISO 9001:2015 principles of risk-based thinking, control of externally provided processes, control of nonconforming outputs, and change management.
For defence-related work and sensitive holdings, Westlink must maintain controls consistent with DISP (Entry Level). These controls include protective security, information & cyber security, and secure disposal of ICT assets and media.
Obsolescence controls must interact with Westlink’s internal procedures and standards.
Planning & Risk Management
Asset owners must identify obsolescence risks at acquisition, during operation, and prior to decommissioning using Westlink’s Risk Management Procedure and project planning processes. Treatments must consider safety, security, quality, environmental impact, continuity of service, total cost of ownership, and legal/contractual obligations.
Identification & Assessment of Obsolescence
Triggers include vendor EoL / EOSL notices, support termination, cyber exposure, parts scarcity, statutory changes, performance degradation, or interoperability conflicts. Each trigger must be recorded and assessed for likelihood/impact; non-conforming or unsafe assets must be controlled per Westlink’s Non-Conformance Procedure.
Treatment Planning
Treatments may include life-extension, redesign, spares strategy, migration / upgrade, containment, or retirement/disposal. Treatments that alter configuration, process, or service delivery are managed under Change Management and, where documents are affected, by the Document Control Procedure.
Records & Systems of Record
The Fixed Asset Register in Xero is the system of record for fixed assets. Each asset record must hold complete and timely master data (ID, location, owner, class). It must also record status (in service, obsolete, decommissioned) and key dates (acquisition, EoL / EOSL, decommission). Decisions (treatment, approval, disposal certificate references) must be recorded too.
Supporting evidence (vendor notices, risk assessments, approvals, wipe certificates, disposal dockets) must be retained per Document Management and QMS requirements.
Change, Communication & Training
Material obsolescence treatments that affect operations, interfaces, or controls require stakeholder communication, training, and controlled documentation updates under the Document Control Procedure.
Exceptions
Exceptions (e.g., life-extension for legacy OT devices) must be risk-assessed, justified, time-bound, and approved by the Policy Owner; high-risk cases are escalated to the CEO.
Compensating controls (segmentation, monitoring, spares strategy, restricted use) must be documented and reviewed at least every 6 months.
Roles and Responsibilities
| Role | Responsibility | When |
|---|---|---|
| Policy Owner (Finance & Technology Manager) | Owns this procedure; ensures integration with financial controls, cyber security, and asset lifecycle; maintains KPI reporting and review cadence. | Ongoing; per review cadence |
| CEO | Approves this procedure and any high-risk exceptions or major obsolescence programs. | At approval; on high-risk exception |
| Finance | Maintains asset records in Xero; monitors vendor notices; initiates assessments and treatment plans; ensures safe and secure handling through to disposal; validates financial treatment (impairment, write-off, gain/loss on disposal), approvals, and documentation per payables/approval processes. | Throughout asset lifecycle |
| Procurement & Supply Chain | Embeds obsolescence risk in sourcing, contracts, and supplier management; prefers vendors with lifecycle roadmaps and take-back programs; coordinates returns and certified recyclers. | At sourcing and disposal |
| IT & Cyber Security | Tracks software / firmware EoL and vulnerabilities; mandates data sanitisation and chain-of-custody for ICT / media disposal; maintains evidence (wipe and destruction certificates). | Throughout asset lifecycle |
| QHSE | Ensures safety, environmental and quality controls; escalates non-conformances; verifies compliant handling of hazardous components and e-waste. | At treatment and disposal |
Obsolescence Management Process
Triggering Events
-
Vendor EoL / EOSL announcement or support termination;
-
Security advisories indicating unpatchable vulnerabilities;
-
Regulatory change making an asset non-compliant;
-
Parts / consumables scarcity impacting maintainability;
-
Performance, cost, or reliability thresholds breached;
-
Interoperability conflicts (e.g., OS upgrade breaks application).
Assessment
-
Record: Log the event against the asset in Xero (system of record).
-
Assess Risk: Use Westlink’s Risk Management Procedure across safety, quality, security, environment, continuity, and cost.
-
Decide Path: Select preferred treatment; document rationale, compensating controls, and target dates.
-
Non-Conformance: If unsafe or non-compliant, control immediately under the Non-Conformance Procedure.
Treatment Options & Disposal Preferences (Best-practice Defaults)
Order of Preference:
-
Avoid (design-out) at acquisition by specifying supported roadmaps;
-
Redeploy / Re-use within Westlink where risk and compliance permit;
-
Return to Vendor / Lease-Return (including take-back programs);
-
Resale / Donation (subject to risk assessment and CEO approval for donations);
-
Recycle via certified e-waste recyclers (AS/NZS 5377 or R2) with Certificate of Recycling;
-
Secure Destruction (last resort or mandated by DISP / information security).
Data & Media Sanitisation: Apply NIST SP 800-88 Rev.1 methods (Clear / Purge / Destroy as appropriate). Require wipe / destruction certificates. Maintain chain-of-custody from decommission to final disposition. Apply dual-control for high-sensitivity items. Use physical destruction where purge is infeasible or data classification demands. Paper records: secure shredding.
Environmental & QHSE Controls: Handle hazardous components under Westlink’s Environmental Management Policy and applicable regulations; document manifests and recycler dockets.
Approval & Funding
Treatment plans requiring capital or OPEX beyond delegated limits must be approved per the Payables Approval Process and financial delegations; high-risk changes require CEO approval.
Execution & Verification
Execute the approved plan; update Xero status and attach evidence (vendor notices, approvals, certificates, dockets, sales/return documentation).
For ICT / media, IT must verify sanitisation / destruction evidence before closing the record.
Post-Implementation Review
Confirm risks reduced to acceptable levels; update procedures to incorporate lessons learned.
Update lifecycle plans and supplier criteria.
Close related non-conformance records and verify effectiveness through the QMS.
Measures, KPIs & Reporting
-
EoL Coverage: % of in-service assets with EoL / EOSL date and vendor recorded in Xero.
-
Timely Assessment: % of obsolescence triggers assessed within 30 days.
-
Treatment On-Time: % of approved treatments executed by target date.
-
Secure Disposal Assurance: % of ICT / media disposals with valid wipe / destruction certificates attached to the asset record.
-
Residual Risk: Count of approved exceptions with compensating controls, by risk level and age.
-
Recycling Rate: % of disposed assets recycled or returned vs. destroyed.
Appendix A — Asset Class Obsolescence Criteria
| Asset Class | Typical Triggers | Minimum Treatments |
|---|---|---|
| IT End-User Devices | OS EoL / EOSL; No security patches; Hardware incompatible with current baseline | Refresh / upgrade; NIST 800-88 wipe; AS/NZS 5377 recycling; Update Xero |
| Servers / Network / OT | Firmware / OS EOSL; Critical CVEs with no patches; Vendor support ended | Segmentation/compensating controls; Migrate workloads; Decommission; Physical destruction of storage media if purge not acceptable |
| Software & Licences | Vendor EoL / EOSL; Dependency incompatibility; Compliance mandates | Version upgrade/migration; Replace; Revoke licences; Update licensing records |
| Plant & Equipment | Parts scarcity; Safety standard changes; Maintenance costs exceed threshold | Spares strategy; Retrofit; Replacement; Decommission and recycle / hazard handling |
| Fleet / Vessels | Regulatory updates; Parts scarcity; Unsafe defects; High downtime | Repair / refurb; Replace / retire; Compliant sale; Update registration / insurance and Xero |
| Facilities / Infrastructure | Standard changes; Energy inefficiency; Reliability decline | Retrofit / replace; Safe removal; Recycle / dispose per environmental controls |
| Data / Records / Media | Retention expiry; Format obsolescence | Disposition per retention; Digitise / migrate; Secure destruction (paper / media) |
Appendix B — Obsolescence Management Workflow
The Obsolescence Management Workflow is depicted as a process diagram in the source document. The workflow steps are set out in narrative form in Section 6 (Obsolescence Management Process) and in checklist form at Appendix C (Obsolescence Management Checklist).
Appendix C — Obsolescence Management Checklist
Asset Details
-
Asset identified (type, location, owner, asset ID);
-
Asset recorded in Xero Fixed Asset Register.
Trigger Event
-
Vendor EoL/EOSL notice received;
-
Support/maintenance termination notice received;
-
Security advisory (unpatchable vulnerability) received;
-
Regulatory change identified;
-
Parts/consumables scarcity detected;
-
Performance, cost, or reliability threshold breached;
-
Interoperability conflict identified.
Assessment
-
Trigger event logged in Xero;
-
Risk assessment completed (using Risk Management Procedure);
-
Impact on safety, quality, security, environment, continuity, cost, and compliance evaluated;
-
Non-conformance identified and controlled (if applicable).
Treatment Planning
-
Treatment options considered: life extension; redesign; spares strategy; migration/upgrade; containment; retirement/disposal;
-
Preferred treatment selected and documented;
-
Change Management Procedure initiated (if configuration/process/service is affected);
-
Document Control Procedure initiated (if documentation is affected);
-
Approvals obtained (Policy Owner/CEO as required).
Execution
-
Treatment plan executed;
-
Asset status updated in Xero;
-
Evidence attached (vendor notices, approvals, certificates, dockets, sales/return docs);
-
Data/media sanitisation completed (NIST SP 800-88 methods);
-
Environmental and QHSE controls applied (hazardous components handled per policy).
Verification & Review
-
Post-implementation review completed;
-
Risks reduced to acceptable levels;
-
Lessons learned recorded (if applicable);
-
Lifecycle plans and supplier criteria updated;
-
Non-conformance records closed (if applicable);
-
Effectiveness verified through QMS.
Reporting & Continuous Improvement
-
KPIs updated (EoL coverage, timely assessment, treatment on-time, secure disposal, residual risk, recycling rate);
-
Feedback provided to Policy Owner (if process improvements are identified).
Compliance coverage — cited by 3 requirements across 1 framework
ISO 9001:2015(3)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO9001-2015-7.5.3.2-01 | 7.5.3.2 | Partial | Low | §Records & Systems of Record / Appendix ARetention and disposition of documented information; secure destruction of data, media and paper records (NIST SP 800-88). |
| ISO9001-2015-8.1-01 | 8.1 | Full | §Treatment Planning / Change & Non-ConformanceQMS process control over obsolescence-driven change and nonconforming-output handling. | |
| ISO9001-2015-8.4.1-01 | 8.4.1 | Full | §Key Principles / ProcurementControls externally provided processes in the obsolescence/disposal chain (lifecycle roadmaps, take-back, certified recyclers). |
Declared compliance references (3)
ISO9001-2015-7.5.3.2-01ISO9001-2015-8.1-01ISO9001-2015-8.4.1-01
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 2025-09-19 | QHSE-PRO-013 | Obsolescence Procedure | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | Procedure creation. Migrated as-is from WLK-GBL-QHSE-PRO-013 through the WMS generator; content and metadata preserved. Compliance wiring deferred (orphan). |