ITAD RFP: 12 Essential Questions for the Best Vendor Selection

Learn how to write an effective ITAD RFP with the right questions to evaluate vendors, define scope, and secure the best asset disposition partner.

By Marcus Holt·Published Sep 2, 2026·25 min read
Hero image for ITAD RFP article

Introduction

IT asset disposition (ITAD) is the process of retiring IT equipment in a way that destroys data, recovers value, and ensures compliance with regulations. When the stakes are high — protected health information on decommissioned servers, financial records on storage arrays, or simply enough devices that a mistake becomes expensive — organizations turn to a formal request for proposal.

An ITAD RFP is more than a procurement formality. It is the document that forces vendors to commit to specifics before they touch your assets. It defines scope, sets expectations for data destruction methods, and establishes the documentation trail you will need if something goes wrong. Use an RFP when requirements are complex or high-stakes, especially in scenarios involving multiple stakeholders, compliance needs, or significant budget exposure.

The difference between a strong RFP and a weak one often appears months later, when an auditor asks for serialized proof of destruction or when a vendor turns out to be something other than what their marketing claimed. The questions you ask — and the answers you require — determine whether your ITAD engagement protects your organization or creates new risk.

This guide walks through the structure of an effective ITAD RFP, the terms that matter, and the essential questions that separate vendors who can execute from those who cannot. The goal is not to generate the longest RFP, but to write one that surfaces the information you need to make a decision you can defend.

Learn how to write an ITAD RFP and ask the right questions to choose the best vendor.

Understanding ITAD RFP

An ITAD RFP is a formal document organizations use to solicit proposals from IT asset disposition vendors. It structures the procurement process by defining the scope of work, technical requirements, and evaluation criteria in a standardized format. The RFP ensures that vendors respond to the same set of questions and requirements, making it possible to compare capabilities, pricing, and compliance posture on equal terms.

The document serves two purposes: it communicates what you need, and it reveals what the vendor can actually deliver. A well-constructed ITAD RFP forces vendors to disclose their processes, certifications, and subcontracting relationships before you sign anything. A weak one invites vague promises and leaves critical details to be discovered during an audit.

Core Components of an ITAD RFP

Every effective ITAD RFP includes several structural elements. The project scope defines the asset types, volumes, locations, and timeline. Technical requirements specify data destruction methods, chain-of-custody documentation, and environmental handling standards. Functional needs cover logistics, reporting, and remarketing if applicable. Evaluation criteria establish how you will score and compare vendor responses.

These sections work together to create a complete picture of the engagement. The scope sets boundaries; the requirements define quality; the evaluation criteria determine who wins. Missing any of these components opens the door to misaligned expectations and incomplete vendor accountability.

What the RFP Reveals About the Vendor

The way a vendor responds to your RFP tells you as much as the content of their response. Vendors who answer every question directly, provide certifications without being asked twice, and disclose subcontractor relationships upfront are signaling operational discipline. Vendors who dodge questions about data destruction methods, offer vague timelines, or submit boilerplate responses are signaling risk.

Pay attention to what is not answered. If you ask for a list of downstream processors and receive a paragraph about "trusted partners," that is a gap. If you request specific NIST 800-88 compliance documentation and receive a general security statement, that is a gap. The ITAD industry's verification standards exist precisely because these gaps are common, and the consequences are expensive.

Why RFP Discipline Matters

The RFP is your first filter. It separates vendors who can document their processes from those who cannot. It identifies which vendors understand your regulatory environment and which ones are guessing. It creates a paper trail that auditors and regulators will review if something goes wrong.

Without a structured RFP, you are negotiating in the dark. Vendors will emphasize their strengths and downplay their weaknesses, and you will have no systematic way to compare them. The RFP levels the field and puts you in control of the evaluation process.

Key Terms in ITAD RFP

Every ITAD RFP contains a vocabulary that shapes how vendors understand your requirements and how you evaluate their answers. Misaligned definitions lead to misaligned bids—one vendor prices shredding while another prices overwrite, and neither matches what you actually need. This section defines the core terms that appear in most ITAD RFPs and explains why each one matters when you compare proposals.

Certificate of Destruction vs. Certificate of Data Sanitization

A certificate of destruction confirms physical destruction—shredding, crushing, or degaussing—has rendered media unreadable. A certificate of data sanitization (or erasure) confirms logical methods like NIST 800-88 overwrite or cryptographic erasure have removed data while leaving hardware intact for reuse. Many RFPs use these terms interchangeably; vendors do not. When you ask for "certificates," specify which type you require and whether you need serialized documentation (one certificate per asset) or batch summaries.

Chain of Custody

Chain of custody is the documented trail of who handled each asset, when, and where, from pickup to final disposition. In an audit or breach investigation, this trail proves you maintained control over sensitive data throughout the ITAD process. Strong chain-of-custody documentation includes timestamps, signatures, serial numbers, and location logs at every handoff. Weak documentation uses batch manifests without asset-level detail, which leaves gaps regulators and auditors will question.

Downstream Subcontracting and Vendor Transparency

Many ITAD vendors subcontract portions of the process—logistics, shredding, or resale—to third parties. Downstream subcontracting means your data touches entities you never vetted. An effective RFP requires vendors to disclose all subcontractors by name, describe what each subcontractor does, and confirm whether those subcontractors hold the same certifications (R2, e-Stewards, NAID) as the prime vendor. The Morgan Stanley case demonstrated the cost of failing to verify subcontractor qualifications—$100 million in fines and settlements because the prime vendor handed drives to an unvetted moving company.

Data Destruction Method: Physical vs. Logical

Physical destruction (shredding, crushing, degaussing) permanently destroys hardware along with data. Logical destruction (overwrite, cryptographic erasure) removes data while preserving hardware for reuse or resale. Your RFP should specify which method is acceptable for each asset class. For example, end-of-life hard drives in a secure environment may require physical destruction, while laptops eligible for remarketing may only need logical sanitization. Vendors price these methods differently, so ambiguity here produces bids you cannot compare.

MethodHardware OutcomeCost ProfileUse Case
Physical destructionDestroyedLower (no refurb)High-security, end-of-life assets
Logical sanitizationReusableHigher (resale value)Remarketing, redeployment

Compliance Certifications and What They Cover

Vendors cite certifications like R2v3, e-Stewards, and NAID AAA to signal compliance rigor. Each certification covers different aspects of the ITAD process. R2v3 and e-Stewards focus on environmental responsibility, data security, and downstream accountability. NAID AAA certifies physical destruction facilities and practices. An RFP should ask which certifications the vendor holds, which facilities are covered, and whether subcontractors hold equivalent certifications. A vendor with R2v3 certification at headquarters but no certification at the facility handling your assets is effectively uncertified for your engagement.

Asset Inventory and Serialized Tracking

An asset inventory is the list of every device entering the ITAD process, typically including make, model, serial number, and data sensitivity classification. Serialized tracking means each asset is tracked individually throughout the process, not aggregated into batches. Serialized tracking enables true chain of custody and makes it possible to prove, asset by asset, that data was destroyed or sanitized. RFPs that do not require serialized tracking often receive bids that assume batch processing, which leaves gaps in auditability and accountability.

Service Level Agreements (SLAs) and Performance Metrics

An SLA defines measurable commitments—pickup timelines, turnaround for certificates, response time for chain-of-custody requests. RFPs that omit SLAs receive proposals with vague promises ("timely service," "industry-standard turnaround") that cannot be enforced. Effective SLAs include penalties for missed commitments and specify exactly what documentation the vendor must provide and when. For example: "Certificates of sanitization delivered within 10 business days of asset receipt, with serialized asset detail and NIST 800-88 method confirmation."

Essential Questions for ITAD RFP

The questions you ask in an ITAD RFP determine whether you get a vendor who can execute or one who sounds confident until the audit arrives. A well-structured RFP separates vendors who understand chain-of-custody from those who treat it as paperwork. The essential questions below address data destruction methods, compliance posture, logistics capabilities, and documentation standards.

Data Destruction and Security

Ask how the vendor destroys data on different media types. Generic answers about "secure erasure" are insufficient. You need specifics: which NIST 800-88 methods they use for hard drives, how they handle SSDs with wear-leveling, and whether they physically destroy media that cannot be sanitized. Request details on their process for network equipment, which often retains configuration data even after factory resets.

Inquire about their data protection measures during transportation and processing. How do they secure assets in transit? What access controls exist at their facilities? Who handles the actual destruction work, and what background checks or training do those workers complete? These operational details reveal whether security is engineered into the process or bolted on for compliance theater.

Compliance Certifications and Audit Trail

Request a complete list of current certifications with expiration dates and scope documents. R2v3, e-Stewards, and NIST 800-171 certifications carry different weights depending on your industry and data sensitivity. Ask for the actual certificate, not marketing claims. Verify that the certification covers the specific facility and services you will use.

The audit trail question matters more than most buyers realize. Ask what documentation the vendor provides for each asset: serial-level certificates of destruction, chain-of-custody logs, and compliance reports. Specify the format and timeline for delivery. Vendors who hesitate or offer vague promises about "standard reporting" often lack the systems to produce detailed records under pressure.

The documentation you receive after the job determines whether you survive the audit, not the promises made before the contract.
ITAD vendor evaluation framework

Logistics and Value Recovery

Understand the vendor's logistics capabilities in detail. Do they provide on-site services or require you to ship assets? What is their pickup timeline and minimum volume? How do they handle rush projects or facilities in remote locations? Logistics failures create security gaps, so clarity here prevents surprises.

For organizations seeking value recovery, ask about redeployment and resale processes. What percentage of assets typically qualify for reuse? How do they calculate residual value, and when do you receive payment? Request their approach to data sanitization for assets entering secondary markets. The balance between maximizing recovery and ensuring complete data destruction requires technical sophistication, not just competitive pricing.

Vendor Experience and Downstream Practices

Ask for examples of projects similar in scale and complexity to yours. Request references from clients in your industry, particularly those subject to the same regulatory requirements. Generic experience means little; you need evidence they understand your specific compliance landscape.

Inquire directly about downstream subcontracting. Who handles the work if the vendor cannot process certain assets in-house? How do they vet subcontractors, and what contractual protections extend to downstream partners? Undisclosed subcontracting is a common failure point, as seen in cases where prime vendors delegated work to unvetted moving companies without proper oversight.

Step 1

Document the full processing chain

Require vendors to disclose every entity that will touch your assets, from pickup to final disposition. Verify that certifications and insurance coverage extend through the entire chain, not just the prime contractor.

Sustainability and Environmental Responsibility

For organizations with environmental commitments, ask how the vendor supports circular economy principles. What percentage of materials are recycled versus landfilled? Do they provide reporting on environmental impact metrics? How do they handle hazardous materials and ensure compliance with e-waste regulations?

Sustainability questions also serve as a proxy for operational maturity. Vendors with robust environmental programs typically have better process controls, documentation systems, and regulatory awareness. A vendor who cannot articulate their recycling methodology likely lacks rigor in other operational areas.

Evaluating ITAD Vendors

Once RFP responses arrive, the real work begins: separating vendors who can execute from those who merely claim they can. The evaluation framework you apply to these responses determines whether you select a partner who protects your organization or one who becomes your next compliance incident.

Core Evaluation Criteria

Three pillars anchor every credible vendor assessment: return on investment, certification posture, and risk identification. Return on investment extends beyond asset recovery rates—it includes the cost of oversight, the burden of documentation review, and the internal hours spent managing exceptions. A vendor offering higher residual values but requiring constant supervision often costs more than one with lower payouts and clean execution.

Certification and minimum standards form the second pillar. Review not just which certifications a vendor holds, but how recently they were audited, whether they cover all facilities handling your assets, and what scope exclusions exist. A vendor with R2v3 certification at their primary facility but unaudited downstream partners introduces gaps your RFP was designed to close.

Questions That Reveal Capability

The vendor's answers to operational questions expose their actual practices. Ask about secure data destruction methods and listen for specifics: do they describe NIST 800-88 compliance for logical sanitization, or do they offer vague assurances about "industry-standard wiping"? Request details on value recovery processes—how assets are graded, where remarketing occurs, and what documentation trails each path. Inquire about redeployment capabilities if internal reuse is part of your strategy, and how they support sustainability goals with measurable outcomes rather than marketing claims.

Data protection measures deserve granular scrutiny. How are assets tracked from pickup through final disposition? What physical and logical controls prevent commingling with other clients' equipment? How is chain-of-custody maintained when subcontractors are involved, and what audit rights do you retain over those third parties?

The vendor who answers "it depends on your requirements" without defining the decision tree is telling you their process adapts to whatever the client will accept.
Vendor evaluation framework

Documentation and Logistics Standards

Logistics management questions reveal operational maturity. How does the vendor handle scheduling conflicts, equipment access restrictions, and multi-site coordination? What happens when an asset arrives damaged or when your inventory count doesn't match theirs at pickup? The answers should reference specific protocols, not general assurances.

Documentation provided after service completion is your audit defense. Require sample certificates of destruction, asset disposition reports, and chain-of-custody logs during the RFP evaluation phase. Compare the level of detail across vendors—serial-level tracking with timestamps and facility locations is the standard; batch-level summaries with generic destruction dates are not. If a vendor cannot produce representative samples during the RFP process, they cannot produce them under contract pressure either.

Common Mistakes in ITAD RFP

Most ITAD failures don't announce themselves in the RFP response—they surface months later when the audit trail breaks, the certificate doesn't match the work performed, or the vendor's subcontractor turns out to be a moving company with no destruction capability. The mistakes that matter aren't typos in the template; they're structural gaps that let unqualified vendors pass through and leave you holding the risk.

Treating the RFP as a Procurement Formality Instead of a Risk Document

Many organizations approach the ITAD RFP as a price-and-timeline exercise, copying a generic services template and adding "data destruction" to the scope. The result is a document that collects bids but doesn't surface the operational details that separate compliant disposition from expensive failure.

An effective ITAD RFP is a risk-transfer instrument. It must force vendors to disclose their chain of custody, destruction methods, subcontracting relationships, and audit readiness in enough detail that you can verify the claims before signing. If your RFP doesn't ask for serialized tracking, witnessed destruction options, and downstream facility certifications, you're selecting on price and hoping the rest works out.

Failing to Define Scope with Asset-Level Precision

Vague scope definitions—"dispose of retired IT equipment" or "sanitize all hard drives"—create two problems. First, they let vendors underbid by assuming the easiest interpretation of your requirements. Second, they leave you without contractual leverage when the vendor's actual process doesn't match your compliance obligations.

Define scope at the asset level: drive models and capacities, device types, quantities, ePHI or PII status, and whether you need individual serial tracking or batch processing. Specify the destruction method (shred, crush, degauss, overwrite) and the evidence standard (certificate of destruction, witnessed event, serialized reporting). If you're disposing of network equipment, call out configuration data separately—factory resets don't clear everything, and your RFP should acknowledge that.

Accepting Certifications Without Asking What They Cover

R2v3 and e-Stewards certifications confirm that a facility meets certain operational and environmental standards, but they don't guarantee that your specific engagement will be handled under those standards—or that the vendor's downstream partners hold the same credentials. Many RFPs ask "Are you R2 certified?" and move on; the better question is "Which of your facilities handling our assets hold R2v3, and will any portion of the work be subcontracted to non-certified partners?"

Certifications are necessary but not sufficient. Your RFP should require vendors to disclose the certification status of every facility and subcontractor that will touch your assets, and to commit contractually that all work stays within certified channels unless you explicitly approve an exception.

The certification proves the vendor can do the work correctly; the contract proves they will do your work correctly.
ITAD vendor evaluation framework

Skipping the Contract Language Review

The RFP is the filter; the contract is the enforceable record. Many organizations spend weeks refining the RFP and then sign the vendor's standard Master Service Agreement without modification, assuming the RFP commitments carry over. They don't—not unless the contract incorporates them by reference and includes specific performance standards, liability caps, audit rights, and breach notification timelines.

Your RFP should state that the selected vendor's response will be incorporated into the contract as an exhibit, and that any deviation from the stated process requires written approval. It should also require the vendor to provide a sample MSA and Standards of Work document as part of the proposal, so you can evaluate contract terms before selection, not after.

Evaluating Only on Cost

The lowest bid is often the riskiest. Vendors who underbid either plan to cut corners (subcontracting to cheaper, less-certified partners; skipping serialized tracking; batch-certifying without individual verification) or didn't understand the scope and will surprise you with change orders once the work begins.

Price matters, but it's a trailing indicator. Evaluate first on process transparency, certification depth, and contract enforceability; then compare cost among the vendors who meet the threshold. If one bid is significantly lower than the others and the vendor can't explain the operational difference, that's a signal to disqualify, not select.

Not Asking About Subcontracting and Downstream Relationships

Many ITAD vendors don't own destruction facilities—they coordinate logistics and subcontract the physical work. That's not inherently a problem, but it becomes one when the RFP doesn't require disclosure and the prime vendor's certification doesn't extend to the subcontractor. The result is a compliant-looking contract with a non-compliant execution path.

Your RFP must ask: Will any portion of the work be subcontracted? If so, to whom, under what certifications, and with what audit rights for the client? Require the vendor to provide a list of anticipated downstream partners and their credentials, and include a contractual provision that prohibits substitution without approval.

Ignoring the Audit Trail Requirement

Compliance doesn't end when the truck leaves your loading dock—it ends when you can prove, years later, that every serialized asset was destroyed according to policy. Many RFPs ask for a "certificate of destruction" without specifying what that certificate must contain: serial numbers, destruction method, facility location, date, witness signature, and a chain-of-custody log tying the certificate back to the pickup manifest.

If your RFP doesn't define the evidence standard in detail, you'll receive whatever the vendor normally provides—which may be a one-page PDF with no serial numbers and no way to tie it to your specific assets. Define the reporting format, the data fields, the retention period, and the delivery timeline in the RFP, and make it a scored evaluation criterion.

Who Should Choose What

Not every organization needs the same ITAD vendor. A healthcare system retiring 500 workstations faces different risks than a hyperscaler decommissioning a data center, and a financial institution replacing network gear has different audit requirements than a municipal government refreshing classroom laptops. The right vendor for one scenario may be poorly suited to another, and the RFP must reflect the specific operational context, compliance burden, and value recovery expectations of the buyer.

Match Vendor Capabilities to Your Risk Profile

Organizations handling regulated data—healthcare, financial services, legal—should prioritize vendors with demonstrated chain-of-custody documentation, third-party audits, and certifications that align with their compliance frameworks. A vendor claiming "we've never had a breach" is less credible than one showing serialized tracking, independent verification, and a documented incident response protocol. For these buyers, the cheapest bid is often the most expensive mistake.

Organizations with lower data sensitivity but high asset volumes—retailers, educational institutions, logistics operators—can emphasize operational efficiency and value recovery. Here, the vendor's ability to process large quantities quickly, provide transparent reporting, and return residual value becomes the differentiator. The RFP should focus on turnaround time, logistics coordination, and pricing models that reward scale.

Align Vendor Selection to Sustainability Goals

For organizations with published ESG commitments or circular economy targets, the ITAD vendor becomes a reporting partner, not just a service provider. The vendor must quantify reuse rates, material recovery, and avoided emissions in terms that align with the buyer's sustainability framework. A vendor that reports only tonnage diverted from landfill is less valuable than one that calculates the circularity delta in financial terms—how much value was retained in the economy versus destroyed.

Data center decommissioning projects, in particular, present sustainability opportunities that extend beyond asset removal. The vendor's ability to document and verify circular outcomes directly impacts the buyer's ability to report credible environmental performance.

The ITAD vendor that can quantify the circularity delta in dollars, rather than tonnage, is more likely to win the RFP and survive re-tendering.

Consider Operational Scale and Geographic Footprint

A single-site buyer can work with a regional vendor offering personalized service and flexible scheduling. A multi-site enterprise needs a vendor with national or global reach, standardized processes across locations, and centralized reporting. The RFP should specify site counts, asset distribution, and whether the vendor must coordinate logistics across jurisdictions with different regulatory requirements.

Vendors with limited geographic coverage often subcontract downstream partners, introducing chain-of-custody gaps and diluting accountability. The RFP must require disclosure of all subcontractors, their certifications, and the contractual language governing data security and liability transfer. If the vendor cannot name the subcontractor and produce their audit reports, the proposal is incomplete.

Evaluate Vendor Financial Stability and Longevity

An ITAD engagement is not a one-time transaction; it creates a long-term liability relationship. If the vendor exits the market, is acquired, or suffers a data breach, the buyer's compliance posture is affected. The RFP should request financial statements, insurance certificates, and evidence of business continuity planning. A vendor unwilling to provide this information is not a serious candidate.

Organizations with multi-year refresh cycles should also assess whether the vendor's business model is sustainable. A vendor offering below-market pricing may be using the contract as a loss leader to capture market share, raising questions about whether they can maintain service quality or even remain solvent through the contract term. The cheapest vendor is the one whose paper trail you trust enough to hand the auditor without hesitation.

Case Studies in ITAD RFP

Real-world failures and successes reveal which ITAD RFP questions actually matter under pressure. Two contrasting outcomes show what happens when organizations either skip the hard questions or build them into the selection process from the start.

The Morgan Stanley Breach: When the RFP Failed to Ask About Subcontracting

Morgan Stanley's ITAD engagement resulted in over $161 million in cumulative penalties after customer data from decommissioned equipment appeared on public auction sites. The root cause was not a technical failure — it was a procurement failure. The firm hired a vendor that subcontracted the work to a moving company with no data security capability, no chain-of-custody documentation, and no oversight.

The engagement unraveled because the initial vendor selection process treated ITAD as a logistics problem rather than a data-security problem. No questions about certifications, no requirement for serialized asset tracking, no audit rights over subcontractors. When regulators reconstructed the timeline, they found that the moving company had been reselling intact drives for months before anyone noticed.

Key lessons for your ITAD RFP:

  • Require disclosure of all subcontractors by name, location, and scope of work before contract signature.
  • Demand serialized chain-of-custody for every asset, not batch-level summaries.
  • Include audit rights that extend to any party physically handling your equipment.
  • Verify certifications independently — don't rely on vendor self-attestation.

For a detailed breakdown of how the subcontracting relationship was structured and why it evaded detection, see They Knew It Was a Moving Company.

The Counterfactual: What a Rigorous RFP Prevents

Organizations that build verification into the RFP process avoid the Morgan Stanley outcome not because their vendors are perfect, but because the contract gives them the tools to detect problems early. A well-structured ITAD RFP in a similar context would have:

  • Required the vendor to name every facility and subcontractor in the proposal, with updated disclosures every 90 days.
  • Specified that all data destruction occur on-site or at a certified facility under the buyer's audit rights.
  • Mandated serialized reporting with timestamps, GPS coordinates, and destruction method per asset.
  • Included termination language triggered by any undisclosed subcontracting or certification lapse.

These terms don't eliminate risk — they shift the burden of proof. When something goes wrong, the organization has documentation that shows it conducted reasonable due diligence. When nothing goes wrong, the vendor knows the contract is enforceable and behaves accordingly.

The cheapest vendor is the one whose paper trail you trust enough to hand the auditor without flinching.

The ITAD market is projected to grow from $19.3 billion in 2025 to $35.4 billion by 2034, driven largely by regulatory pressure and the increasing value of recovered materials. As the market expands, the gap between certified and uncertified providers widens — and the RFP is the only checkpoint where you can verify which side of that gap your vendor occupies.

Conclusion

A well-structured ITAD RFP is the difference between a vendor relationship that survives audit and one that becomes a compliance footnote. The questions you ask before signing determine what you can prove after the equipment leaves your loading dock. When requirements are complex or high-stakes — scenarios involving multiple stakeholders, compliance needs, or significant budget exposure — the RFP becomes the only tool that forces vendors to document their promises in writing before you're contractually bound.

The Morgan Stanley case remains the canonical reference for what happens when the RFP process fails: a moving company was hired to handle data-bearing assets, and the resulting $100M+ settlement followed predictably. That outcome was not a surprise to anyone who read the contract; it was baked into the vendor selection from the start. The ITAD RFP is where you prevent that scenario — by defining scope with serial-level precision, requiring chain-of-custody documentation that survives legal discovery, and asking the questions that separate certified processes from paper compliance.

Final Takeaways

IT asset disposition is the process of retiring IT equipment in a way that destroys data, recovers value, and ensures compliance with regulations. Your RFP must address all three pillars, not just the one your procurement team finds easiest to price. The essential questions outlined in this guide — around data destruction methods, downstream subcontracting, certificate-versus-practice gaps, and audit-ready documentation — are the minimum threshold for a defensible vendor selection. Anything less is a compliance risk dressed up as cost savings.

The vendors who answer these questions with specificity, supporting documentation, and no hedging language are the ones whose paper trail you can hand to an auditor without flinching. The ones who deflect, generalize, or promise to "work it out later" are the ones who will leave you holding the liability when something goes wrong. Your ITAD RFP is not a formality — it is the legal and operational foundation of every asset that leaves your control. Write it accordingly.