Most facilities preparing for an R2v3 audit ask the wrong first question. They ask "what documents does the auditor want to see," when the better question is "what is the auditor actually trying to verify by looking at that document." A downstream vendor file isn't there to exist. It's there to prove that a facility knew, before it shipped material out the door, whether the company receiving it would recycle it responsibly or dump it. Understanding that distinction is the difference between an audit that goes smoothly and one that generates a stack of corrective action requests.
R2v3 is the certification standard published by Sustainable Electronics Recycling International (SERI), and it is audited exclusively by certification bodies (CBs) accredited by the ANSI National Accreditation Board (ANAB) to certify against it. The standard replaced R2:2013, and every R2-certified facility was required to complete the transition to R2v3 by July 1, 2023 — there is no longer a version of R2 an auditor can certify against other than R2v3. Below is what those CBs are structurally required to check, organized the way an audit actually unfolds: documents first, then the floor, then the exit interview.
How an R2v3 Audit Is Structured
An R2v3 audit isn't a single activity. It's three activities layered on top of each other, and auditors move between them throughout the visit rather than doing them in strict sequence.
Document review comes first, usually before the auditor sets foot on-site. The CB requests the EHSMS manual, downstream vendor due diligence files, throughput tracking records, training records, insurance certificates, and — if the facility handles data-bearing devices — data sanitization logs. Gaps here get flagged before the auditor ever walks the floor.
Physical verification is the walkthrough: focus materials segregation, hazardous waste storage, facility security controls, PPE use, and whether what's written in the SOP matches what's happening at the workstation. Auditors are specifically trained to look for the gap between paper and practice, because that gap is where most real nonconformities live.
Personnel interviews round it out. The auditor asks front-line staff what they'd do if they found a leaking battery, or how they verify a hard drive is actually wiped before it leaves the sanitization station. A written procedure that no operator can describe in their own words is a competence gap under the standard, not just a training gap.
The Ten Core Requirements, and What Evidence Satisfies Each
R2v3 is built around ten Core Requirements (CR1–CR10) that apply to every certified facility, plus a set of process-specific appendices (Appendix A through Appendix G) that only apply if the facility actually performs that process. An auditor scopes the audit to the facility's actual "R2 Universe" — the full set of processes, materials, and byproducts the facility handles — before deciding which appendices are in play.
| Core Requirement | What It Covers | Typical Evidence an Auditor Reviews |
|---|---|---|
| CR1 – R2 Universe | Scope of all processes and materials handled on-site | Facility process map, list of equipment types processed |
| CR2 – EHSMS | Environmental, health & safety management system | EHS policy, risk assessments, internal audit records |
| CR3 – Legal and Other Requirements | Ongoing legal compliance tracking | Legal register, permits, RCRA hazardous waste determinations |
| CR4 – Tracking Throughput | Mass-balance tracking of materials in vs. out | Throughput logs, inventory reconciliation reports |
| CR5 – Sampling | Downstream due diligence sampling for higher-risk streams | Sampling plans, vendor site visit records |
| CR6 – Data Security | Data-bearing device handling and sanitization | Chain of custody logs, sanitization verification records |
| CR7 – Focus Materials and Components | Handling of mercury, lead, cadmium, CRTs, batteries | Focus materials inventory, segregation records |
| CR8 – Facility Security | Physical and data access controls | Camera coverage maps, access logs, visitor logs |
| CR9 – Insurance | Adequate liability coverage | Certificates of insurance |
| CR10 – Financial Assurance | Financial capacity to manage a facility closure | Financial assurance instrument documentation |
I've found the CR that trips up more facilities than any other isn't data security — it's CR4, tracking throughput. Facilities that can produce a clean mass balance for their primary commodity often can't reconcile the smaller focus-materials streams, and that gap is exactly what an auditor is trained to chase. For the clause-level detail behind each of these ten requirements, the R2v3 Core Requirements Explained Clause-by-Clause guide walks through the full text.
Appendices: Only What You Actually Do Gets Audited
This is the part of the standard people misunderstand most often. Nobody gets audited against all seven appendices. A facility that only shreds material for commodity recovery doesn't need to satisfy Appendix C (Test and Repair) requirements, because it isn't testing or repairing anything. The auditor's scoping conversation at the start of the engagement exists specifically to determine which appendices apply, and that scoping decision should match the facility's R2 certificate exactly — nothing more, nothing less.
The appendices generally cover: downstream recycling chain due diligence and material disposition, data sanitization, test and repair of used equipment, specialty electronics reuse and refurbishing, materials recovery processes like shredding and smelting, brokering activities, and a dedicated appendix for photovoltaic module and component recycling. A facility that brokers material to a downstream partner without ever taking physical possession still has to satisfy the brokering appendix — auditors treat "we never touched it" as irrelevant to due diligence obligations, because the R2 chain of custody doesn't care who has title, it cares who's accountable.
Focus Materials: Where the Chain of Custody Gets Tested
Focus materials — mercury-containing lamps and devices, lead, cadmium, CRT glass, batteries — get their own Core Requirement (CR7) because they carry the highest risk of environmental harm if mishandled. Auditors don't just check that these materials are identified. They trace them: pick a focus material, ask to see where it entered the facility, where it's stored, and where it left — then compare that trail against the throughput records from CR4. A facility that identifies focus materials correctly on paper but can't produce a matching physical trail has a documentation-practice gap, and that's one of the more common findings CBs cite.
Downstream due diligence is the other half of this. R2v3 requires facilities to qualify every downstream vendor that receives focus materials or components with a risk-based level of scrutiny — a higher-risk stream (say, CRT glass headed to a smelter) demands more documentation than a lower-risk one. Auditors will ask for the due diligence file on a vendor the facility actually used in the audit period, not just a sample vendor kept on file for show.
Data Security: What Auditors Actually Verify
Data destruction is the requirement most facilities over-prepare for on paper and under-prepare for in practice. CR6 requires a documented data security policy, but the auditor's real interest is whether the sanitization method actually matches the media type and the claimed outcome. NIST Special Publication 800-88 Revision 1, Guidelines for Media Sanitization (December 2014), is the technical reference auditors expect a facility's sanitization procedures to align with — its Clear, Purge, and Destroy categories are the vocabulary a CB uses to evaluate whether a wipe, degauss, or physical shred was appropriate for the device in question.
In practice, this means an auditor may ask to witness a sanitization event live, then pull the corresponding verification log and match the serial number, method, and timestamp against what they just watched. A log that says "wiped" without a verification pass recorded, or a batch of hard drives shredded without a pre-shred inventory reconciliation, is a gap auditors are specifically trained to catch — not an edge case they might miss.
Facility Security: The Walkthrough Checklist
CR8 covers both physical and data security controls, and it's the requirement most visibly tested during the walkthrough. Auditors look for camera coverage of processing and storage areas, controlled access to areas where data-bearing devices or focus materials are stored, visitor sign-in procedures, and whether access logs are actually reviewed rather than just collected. A facility with cameras that record but that nobody has checked in six months has a control that exists on paper but doesn't function as a control in practice — and that distinction matters to an auditor evaluating whether the EHSMS is a living system or a binder on a shelf.
Audit Types: Initial, Surveillance, and Recertification Compared
R2v3 certification runs on a three-year cycle. The audit a facility experiences depends on where it sits in that cycle.
| Audit Type | When It Happens | Scope | Typical On-Site Duration |
|---|---|---|---|
| Initial Certification | Before a facility is first certified | Full standard — all applicable CRs and appendices | Multiple days, scaled to facility size |
| Surveillance (Year 1 & 2) | Annually between certification and recertification | Sampling of CRs and appendices, plus prior corrective actions | Typically shorter than the initial audit |
| Recertification | Before the 3-year certificate expires | Full standard again — comparable in depth to the initial audit | Comparable to initial certification |
Surveillance audits aren't lighter versions of the same checklist repeated every year — CBs are required to sample different Core Requirements and appendices across the cycle so that, by the time recertification arrives, the full standard has been reviewed at least once beyond the initial audit. A facility that assumes surveillance audits are a formality because "we passed everything last year" is misreading what the auditor is required to do.
Common Nonconformities Auditors Cite
Across the facilities I've helped prepare, the same handful of gaps show up again and again, and none of them are exotic:
- Throughput records that don't reconcile. Inbound weight, outbound weight, and inventory on hand don't add up for at least one material stream.
- Downstream due diligence files that are current for the top vendor but stale for a secondary one. Auditors sample more than the obvious vendor.
- Training records that predate a process change. Staff were trained on the old SOP, not the revised one.
- Data sanitization logs missing a verification step. The wipe happened; nobody recorded confirming it worked.
- Facility security controls that exist but aren't monitored. Cameras that record into a void nobody watches.
None of these are hard to fix. They're hard to catch internally, because they require someone to look at the operation the way an outside auditor does — tracing a specific unit through the process rather than reviewing the SOP in the abstract.
How to Prepare Before the Auditor Arrives
The facilities that move through recertification cleanly aren't the ones with the thickest binders. They're the ones that ran an internal audit against the same logic a CB uses: pick a real transaction, trace it end to end, and see where the paper trail and the physical trail diverge. If you haven't done that exercise yet, our R2 Audit Preparation page walks through how to structure that internal review before the CB walks in the door.
FAQ
How long does an R2v3 audit take? It depends on facility size and complexity, but initial certification and recertification audits typically run multiple days on-site, while annual surveillance audits are shorter because they sample rather than review the full standard.
Do certification bodies audit every appendix at every facility? No. Auditors scope the audit to the appendices that match the facility's actual processes, determined during the CR1 "R2 Universe" scoping step. A facility that doesn't test or repair equipment isn't audited against the Test and Repair appendix.
What happens when an auditor finds a nonconformity? The facility is required to submit a corrective action addressing root cause, not just the symptom, within a timeframe set by the CB. Certification isn't withheld for every finding, but unresolved major nonconformities can delay or block certification.
How often is an R2-certified facility audited? On a three-year cycle: an initial or recertification audit covering the full standard, followed by two annual surveillance audits that sample different parts of the standard before the next recertification.
Is R2v3 the only version of R2 that gets audited now? Yes. R2:2013 was retired, and all facilities were required to transition to R2v3 by July 1, 2023. No CB can certify a facility against the 2013 version anymore.
Last updated: 2026-08-21
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.