Most of the R2v3 inquiries I see start the same way: a facility already has some paperwork, maybe a data destruction procedure, a downstream vendor list, an old EHS manual, and the owner wants to know how far it is from certifiable. That is a gap analysis question, and the honest answer depends on how each document compares to what the R2v3 Standard says, not on how thick the binder is.
This guide walks through how I would assess an existing document set against the R2v3 Core Requirements and the Appendices, in the order that tends to surface the expensive problems first. It is written for electronics recyclers, ITAD providers, refurbishers, and facilities still working out whether they are ready.
A note on numbering before we start. SERI publishes the R2v3 Standard and the numbering of requirements and provisions is specific to that document. I organize this checklist by topic and name the requirement areas, and I would ask you to map each item to the exact provision in your licensed copy of the Standard. Please don't rely on any summary, including this one, as a substitute for the Standard itself.
What is an R2v3 gap analysis?
An R2v3 gap analysis is a structured comparison between what your facility actually does and documents today and what the R2v3 Standard requires. It produces a list of findings, each tied to a requirement, with an owner, a fix, and a priority. It is not an audit and it does not result in a certificate. The audit is performed by a certification body that has been approved by SERI and accredited, and the gap analysis is how you decide whether you are ready to ask for one.
The most useful gap analyses test three things for every requirement: whether a documented procedure exists, whether people follow it, and whether records prove they did. Paperwork that passes the first test and fails the other two is the most common situation I see, and in my view it is the most dangerous one because it feels finished.
Step 1: Confirm your scope and the Appendices that apply to you
Scope drives everything else, so start here. The Standard expects you to define the facility, the activities performed, the equipment and materials handled, and which Appendices apply. The Appendices are not all mandatory for everyone. They apply based on what you do.
| Appendix | Topic | Applies when your facility... |
|---|---|---|
| A | Focus Materials | handles items such as CRTs, batteries, circuit boards, mercury-containing devices, or other defined focus materials |
| B | Downstream Recycling Chain | sends any equipment or material to another company (nearly everyone) |
| C | Test and Repair | tests, repairs, or refurbishes equipment for reuse |
| D | Data Sanitization | receives equipment that may hold data |
| E | Specialty Electronics Reuse | reuses specialty electronics such as certain medical or industrial devices |
| F | Materials Recovery | shreds, separates, or otherwise processes equipment to recover materials |
| G | Photovoltaic Modules | handles photovoltaic modules |
Gap check for scope:
- Is there a written scope statement that matches what the floor really does, including activities you do occasionally?
- Does every process in your process flow map to an Appendix, or to a deliberate decision that none applies?
- Are any sites, storage yards, or outside warehouses used by the business included or explicitly excluded with a reason?
- Does the scope on your marketing material match the scope in your documents?
Scope mismatches are where I find the first surprise. A facility that "doesn't really do repair" but has a bench with a technician swapping drives has a Test and Repair question to answer.
Step 2: Check legal compliance and the permit register
R2v3 requires you to identify and comply with applicable legal and other requirements, and to keep evidence. For a US facility that usually means a mix of federal, state, and local rules. Examples worth checking by name include:
- 40 CFR Part 273 for universal waste such as batteries and mercury-containing equipment, plus any stricter state universal waste rule.
- 40 CFR 261.39 for the conditional exclusion covering used cathode ray tubes, and the related export provisions in 40 CFR 261.41.
- OSHA general industry standards that show up on every recycling floor, including 29 CFR 1910.147 (lockout/tagout), 29 CFR 1910.1200 (hazard communication), and 29 CFR 1910.132 (personal protective equipment).
- Stormwater, air, and local fire code requirements that apply to your site.
Gap check for legal requirements:
- Do you have a register listing each obligation, the source, who owns it, and when it was last reviewed?
- Can you produce the current permits, registrations, and licenses, and are the expiration dates tracked?
- Is there a record of the last inspection by any agency and how findings were closed?
- Is there a procedure for how new or changed laws reach the person who needs to act?
ISO 14001:2015 clause 6.1.3 asks for the same thing (determine and have access to compliance obligations), and clause 9.1.2 asks you to evaluate compliance. If your EHS management system already satisfies those clauses, a lot of this step is a matter of pointing to existing records.
Step 3: Test the EHS management system
The Standard requires an environmental, health, and safety management system that covers the whole scope, and it expects that system to be certified against recognized standards (the ISO 14001 and ISO 45001 pair, or RIOS) and audited as part of the R2v3 process. Confirm the exact certification language in your copy of the Standard, since this is the point where facilities most often underestimate the work.
If you already hold ISO certificates, check that the certified scope covers every R2 activity and every R2 location. I have seen certificates that cover "electronic waste collection" while the facility also shreds and sells commodities. If you do not hold them, this is the longest part of the road, and it is worth reading about ISO 14001 consultant support and ISO 45001 consultant support early, because those systems take real operating time to produce records.
Gap check for the management system:
- Policy, objectives, and roles are documented and current.
- Aspects and impacts, and hazards and risks, have been assessed for every R2 process, including battery handling and shredding.
- Internal audits have been completed across the whole scope (ISO 14001:2015 clause 9.2 and ISO 45001:2018 clause 9.2), with findings closed.
- Management review has happened and the minutes show decisions, not just attendance (clause 9.3 in both standards).
- Corrective action records show cause analysis, not just the quick fix.
- Hazard controls follow the hierarchy of controls from ISO 45001:2018 clause 8.1.2, with PPE as the last resort rather than the first answer.
- Emergency plans (fire, battery thermal events, spills) have been drilled, and the drill records exist.
The question I ask at this stage is simple: if an auditor sampled any record from last year, would it tell a coherent story? A management system that exists only in the months before an audit rarely does.
Step 4: Review the downstream recycling chain
Appendix B is where most gap analyses of existing paperwork find the most missing material. R2v3 holds you responsible for knowing where your equipment and materials go after they leave your building, and for making sure the downstream vendors handle them appropriately. That includes the vendors your vendors use, up to the point the material is fully processed or disposed.
Gap check for downstream vendors:
- Is there a complete list of every downstream vendor by material stream, including brokers, haulers, smelters, and landfills?
- Does each vendor have a due diligence file: current certification or documented evaluation, permits, insurance, and the basis for approving them?
- Do you track the flow of material from receipt to final disposition, and can you show a mass balance for a sample period?
- Do contracts or purchase terms require vendors to meet R2 requirements, flow them down, and give you access for review?
- Are focus materials sent only to vendors who are allowed to receive them, and are exports handled in line with 40 CFR 261.41 and the importing country's rules?
- Is there a procedure for what happens when a vendor loses a certificate or fails a review?
A vendor list in a spreadsheet is a starting point. The Standard expects evidence behind each name. When I review these files, the usual gaps are expired documents, vendors who were approved by a phone call, and no record of the second-tier recipients.
Step 5: Examine focus materials and materials of concern
Appendix A covers focus materials, which are items that need special handling because of their hazard or because they have restricted flows. Your documents need to show that you identify them on receipt, segregate them, store them safely, and send them only to approved downstream recipients.
Gap check for focus materials:
- Is there a written list of the focus materials you actually receive, mapped to the Standard's definitions?
- Do receiving procedures include a way to detect them, for example an inspection step for batteries embedded in devices?
- Are storage areas controlled (containers, labeling, limits, fire protection) and inspected on a schedule?
- Do you have a process for removing batteries and other components before shredding, with training records for the people doing it?
- Are records kept of what focus material left, to whom, and when?
- Has the facility determined whether any focus material is subject to a particular prohibition or condition, such as limits on certain exports?
Step 6: Audit the data security and sanitization paperwork
If you accept anything that could hold data, Appendix D and the data security requirements are in play, and this is the section where a customer will look most closely at your certificate.
Gap check for data security:
- A written data security plan names the sanitization methods you use and the types of media they apply to.
- The methods trace to a recognized sanitization guideline. NIST SP 800-88 is the reference most programs use, so confirm which revision your procedures cite and that it matches current expectations in the Standard.
- Verification is documented: who verified, what tool or method, and what the result was.
- Physical security covers the whole path: receiving, storage, processing, and shipping, with access control and, where appropriate, video coverage.
- Staff who handle data-bearing devices are trained, screened according to your policy, and acknowledged confidentiality.
- Data-bearing devices that cannot be sanitized are routed to destruction, and the destruction records are retained.
- Customers get the documentation they were promised, such as certificates tied to serial numbers.
Procedure pages are not enough here. Pull ten recent jobs and trace one end to end: the intake log, the sanitization result, the verification record, the downstream transfer. The jobs that fall apart in this trace are the gaps.
Step 7: Review reuse, test, and repair controls
For facilities that reuse equipment, Appendix C (Test and Repair) and, where applicable, Appendix E (Specialty Electronics Reuse) set the rules for deciding what can be sold or donated as working and what must be treated as waste.
Gap check for reuse:
- Do you have a written functionality test procedure for each equipment category, with pass and fail criteria?
- Are test results recorded for each unit or lot, and are they retrievable?
- Is untested equipment handled as non-working unless it falls into an allowed category, and are those exceptions documented?
- Are repaired units, replacement parts, and refurbished items controlled so nothing slips back into the stream without being tested again?
- Do export shipments of equipment for reuse carry the supporting evidence the Standard expects?
- If you handle specialty electronics, have you defined the categories, applicable regulatory status, and additional controls?
This is the area where a pilot or startup facility often has the least paperwork, because testing starts informally. Writing the procedure after the habit exists is easier than the other way around, so I encourage doing it as early as you can.
Step 8: Check materials recovery, transportation, and monitoring
If you shred or otherwise process equipment (Appendix F), the paperwork should show how output fractions are sampled, characterized, and sent on. For photovoltaic modules (Appendix G), confirm that handling and downstream rules specific to modules are covered.
Transportation controls apply to anything you ship or receive. Look for carrier selection criteria, packaging and loading instructions, and shipping documents that carry what the regulations require for the hazard class involved.
Gap check:
- Do you have throughput records and a reconciliation between inputs and outputs?
- Are process monitoring and equipment maintenance records current?
- Are shipping papers and manifests retained for the period the Standard and the law require?
- Is there a defined way to deal with incidents, spills, and customer complaints, and do records show it is used?
How to score what you find
Once each item has been checked, I classify findings by how they would land in a real audit. This keeps the remediation plan from turning into an undifferentiated to-do list.
| Rating | What it means | Typical example |
|---|---|---|
| Conforming | Procedure, practice, and records all exist and agree | Current permit register reviewed each quarter |
| Partial | Procedure exists but practice or records are incomplete | Downstream vendor files with expired documents |
| Missing | No procedure or no evidence at all | No written functionality test criteria |
| Not applicable | Excluded by scope with a documented reason | No photovoltaic modules handled |
Then rank the Partial and Missing items. Things that take the longest to generate evidence, such as management system records and internal audits, go to the front of the plan even if the fix looks small. Documents you can write in a week can wait until the long-lead items are underway.
A realistic sequence for a facility starting from partial paperwork
- Lock the scope and the list of applicable Appendices.
- Decide how the EHS management system will be certified and begin collecting records.
- Build the downstream vendor register and start the due diligence files.
- Rewrite data security and reuse procedures around what you actually do, and run a trial trace on recent jobs.
- Run a full internal audit against the R2v3 Standard, close the findings, and hold a management review.
- Choose a certification body and schedule the audit once the records have enough history to be convincing.
How long this takes depends mostly on where your management system stands, so I would be wary of anyone who gives you a fixed timeline before reviewing your documents.
When to bring in outside help
An internal gap analysis works best when the person doing it is not the person who wrote the procedures. If your team is small, an outside reviewer brings the distance. Our team at Certify Consulting performs gap assessments that follow the structure above, and we also support facilities working through the broader ISO certification path that sits underneath R2v3. If your facility is also thinking about AI governance in its operations, there is a page on ISO 42001 for R2 and ITAD facilities.
I have come to think that the best gap analysis is the one that makes you a little uncomfortable. If everything comes back green on the first pass, the review probably was not deep enough.
Last updated: 2026-10-08
Frequently Asked Questions
What is an R2v3 gap analysis?
An R2v3 gap analysis compares your facility's current practices, procedures, and records against the R2v3 Standard's Core Requirements and the Appendices that apply to your scope. It produces a prioritized list of findings with owners and fixes. It is not a certification audit, which must be performed by a certification body approved by SERI.
Which R2v3 Appendices apply to my facility?
It depends on your activities. Appendix B (Downstream Recycling Chain) applies to nearly every facility, Appendix D (Data Sanitization) applies if you receive equipment that can hold data, Appendix C covers test and repair, Appendix F covers materials recovery, and Appendix A covers focus materials. Confirm applicability against your licensed copy of the Standard.
Do I need ISO 14001 and ISO 45001 before R2v3?
The Standard requires an environmental, health, and safety management system that is certified to recognized standards (ISO 14001 and ISO 45001, or RIOS) and covers your whole R2 scope. Check the exact language in the Standard for your facility, because this is usually the longest lead-time item.
What is the most common gap in existing R2 paperwork?
The downstream recycling chain is where I most often find gaps: vendor lists with no due diligence evidence behind them, expired documents, and no records of second-tier recipients. Data sanitization verification records are a close second.
Can a new or pilot facility do a gap analysis before it has operating history?
Yes. A gap analysis is useful before operations scale because it shows which procedures and records need to exist from day one. Records that take time to accumulate, such as internal audits and management reviews, should be started as early as possible.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.