Service Robot Decommissioning and End-of-Life Fleet Management
At a glance: Procurement focuses entirely on getting robots onto the floor and almost never on getting them off it. Yet the exit is where a fleet either returns value or creates liability: batteries that must be transported as dangerous goods, storage that still holds footage and floor plans, and capital that could have been redeployed to a busier site. This guide sets out the decommissioning sequence, the data-wipe evidence to keep, the residual-value routes, and the contract terms to secure before you ever need them.
Why the Exit Plan Belongs in the Original Contract
The cheapest time to secure decommissioning terms is before signature, when the supplier still wants the order. Afterward, every one of those terms is a negotiation the operator is likely to lose. Four provisions in particular have to be agreed up front: the data-wipe obligation and the evidence format, the battery take-back or disposal responsibility, the availability of spare parts for a defined post-sale period, and the firm's right to transfer or resell the unit without voiding remaining support.
Framing the exit at purchase is not pessimism, it is the same discipline applied to any capital asset. A fleet financed with a lease has an explicit end date and a defined hand-back condition, so the exit is planned by construction; a fleet bought outright has no such forcing function and drifts out of service one degraded unit at a time. The financing structures that embed an exit date are compared in the lease versus buy analysis, and the residual assumptions behind them are set out in the depreciation and residual value guide.
The Decommissioning Sequence
Decommissioning a unit is a defined sequence of steps, and doing them out of order creates risk. Work through the stages below for each unit rather than pulling the fleet at once, so that a fault found on the first unit informs the rest.
| Stage | Action | Evidence to retain |
|---|---|---|
| 1, Freeze | Stop the unit from taking new tasks; confirm no active jobs reference it | Final task log; date of removal from service |
| 2, Data extraction | Export any operational data still needed for reporting or audit | Export manifest with date range and fields |
| 3, Data wipe | Factory-reset the unit and clear stored footage, maps and credentials | Wipe certificate or signed attestation with serial number |
| 4, Credential revocation | Revoke the unit's access to network, doors, lifts and management software | Revocation confirmation from each system |
| 5, Battery handling | Discharge to transport state, disconnect, pack to dangerous-goods rules | State-of-charge reading; packing record |
| 6, Physical removal | Remove the unit and its dock; restore the site | Removal note; dock and cabling disposal record |
| 7, Asset record | Close the asset in the register and the management software | Final asset status entry |
Stage 4 is the one most often skipped and the most consequential. A robot that has been physically removed but still holds network credentials or door permissions is an open door in an audit, and the management software will keep counting it against the fleet. Revoking access across every system it touched is the step that closes the loop, and it maps directly onto the access-control discipline used during operation in the fleet cybersecurity guide.
Data Wipe: The Evidence Compliance Will Ask For
A wiped robot and a robot you believe has been wiped look identical from the outside. What a compliance or data-protection reviewer wants is evidence, tied to the specific serial number, not an assurance. Keep three artefacts for every decommissioned unit.
- A wipe attestation: a signed statement, from the supplier or your own team, that the unit's storage was reset and that the classes of data it held were removed. Name the serial number explicitly.
- The data inventory: a short record of what the unit actually held, since a cleaning robot may carry floor plans and footage while a delivery robot may hold access logs and recipient data. The inventory determines how seriously the wipe must be treated.
- Retention decisions: if any exported data is kept, record where, how long, and under what authority. If it is deleted, record when. The absence of a decision is the finding an auditor writes up.
Where the fleet processed occupant footage or personal data at all, run the decommissioning past whoever owns data protection before physical removal, not after. The ownership and access questions that apply during operation, covered in the data ownership and interoperability guide, become exit questions the moment a unit leaves the estate.
Residual Value: The Routes Back to Money
A decommissioned unit is not automatically scrap. Choose the route that recovers the most value consistent with the data and battery obligations, and make the choice at fleet level, not unit by unit.
| Route | Recovers | Requires |
|---|---|---|
| Internal redeployment | Full unit value, no transaction cost | A site with compatible floors and docks, and transferable credentials |
| Resale to a secondary buyer | A fraction of original cost | Clean data wipe, battery health report, remaining parts availability |
| Trade-in against new units | Credit against purchase | A supplier offering it; strongest leverage before signing the next order |
| Part harvest | Value in spares for the retained fleet | Common platform across units; a place to store harvested parts |
| Scrap and recycle | Minimal; mainly liability closure | Battery disposal to local dangerous-goods rules |
Internal redeployment almost always beats resale because it recovers the whole unit rather than a discounted fraction, so survey the wider estate before listing anything for sale. Where it is not possible, resale depends on the buyer's confidence in battery health and parts supply, both of which are exactly the provisions you secured in the original contract. A unit whose platform is shared with the retained fleet is also worth more as a parts donor than as a sale; the planning logic for holding spares is the same as in the spares and consumables planning guide.
Batteries: The Hard Part of Any Exit
Lithium packs carry transport, storage and disposal obligations that outlive the robot, and they are the reason a decommissioned unit cannot simply be left in a corner. Discharge to the transport state of charge before packing, store away from occupied areas, and hand disposal to a route that can document it. Where the original contract includes battery take-back, use it: it shifts a genuine liability off the operator's books. The compliance framework behind battery transport is the same one described in the battery certification and transport guide.
Plan the whole exit backwards from the asset register. If each unit's purchase date, expected service life and residual assumption are recorded when it is bought, the fleet's exit becomes a schedule rather than a series of emergencies, and each unit retires on plan with its data, credentials and battery accounted for. The forward-looking version of the same discipline, deciding when a unit is no longer worth maintaining, is covered in the maintenance and TCO guide.
Frequently Asked Questions
How long before retirement should the exit be planned? Twelve months for a fleet, and at purchase for an individual unit. The contract terms have to exist before you need them, and the redeployment or resale route needs lead time to find.
Can I just factory-reset and sell? A reset is necessary but not sufficient. Without a wipe attestation and a record of the data held, a secondary buyer or auditor has no assurance, and the operator carries the residual risk.
Who owns the robot's data after decommissioning? Whoever the operating contract says owns it, which is why the ownership clause has to be written before deployment. Absent a clause, assume the operator holds the obligation and act accordingly.
Is part harvesting worth it? Only if the retained fleet shares the platform and you have somewhere dry to store the parts. Otherwise the effort of harvesting exceeds the value of the spares recovered.
