Remote IT Asset Management & Hardware Lifecycle3 min readUpdated September 2026

Rippling vs Firstbase for Asset-Based Lending Teams

A specialty asset-based lender's device question is shaped less by where people work than by what's on the device when they're working. Underwriters handle detailed borrower financials. Field examiners carry hardware to a collateral site and bring findings back. Both groups create a genuine device security question that a general HR platform doesn't automatically solve.

Rippling and Firstbase both offer pieces of the answer, but the more useful starting point is figuring out which of your teams actually handles sensitive borrower data on a portable device.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Underwriters handle borrower financials, so device security isn't optional

An underwriter's laptop routinely holds detailed financial statements, tax returns, and collateral valuations for borrowers who expect that information handled carefully. Whether underwriters work remotely or from an office, the device itself needs encryption, access controls, and a documented offboarding process that doesn't depend on someone remembering to do it right.

This is true regardless of company size. A small underwriting team handling a handful of active files still carries the same category of sensitive data as a larger one, just at smaller scale.

Field examiners carry hardware to a collateral site, then come back

An examiner conducting a collateral audit, verifying inventory or receivables in person, typically carries a laptop or tablet to the site and returns with findings that feed directly into a lending decision. That laptop is genuinely mobile in a way an underwriter's usually isn't, making it a closer match for what Rippling or Firstbase is built to manage.

If examiners cover a wide territory or travel to sites for multi-day audits, Firstbase's shipping and retrieval logistics matter more than they would for a team that mostly works from a single office.

Say an examiner's laptop fails midway through a multi-day site visit. Getting a working replacement to them at the borrower's location, rather than waiting for them to return to an office first, is exactly the kind of logistics Firstbase is built around.

A departing loan officer's laptop can carry a client list you don't want to lose

A loan officer or relationship manager who leaves, especially for a competitor, has an obvious incentive to take borrower and prospect information with them. Revoke system access the same day the departure is known, before the physical device return, since the data risk exists the moment access isn't cut off, not once the laptop is physically back in your hands.

Don't treat this differently based on how the departure looks. A loan officer who seems to be leaving on good terms deserves the same same-day revocation as one who's clearly headed to a competitor, because the risk to your client list doesn't depend on how the conversation went.

Remote underwriting teams still need a retrieval plan

If your underwriting team works remotely by default, the devices they use are effectively always off-site, which changes the retrieval calculus. A remote underwriter's laptop needs to come back through a reliable shipping process when they leave, not an assumption that they'll mail it back eventually. Firstbase's prepaid return labels and tracking handle this more predictably than an informal request and a hope.

An informal request tends to work fine for a departure that ends well, and fails exactly when it matters most, when someone's leaving on bad terms and has little incentive to prioritize mailing back a laptop promptly.

What an auditor actually wants to see about your device controls

A regulatory or investor audit of your lending operation will typically ask about data security controls generally, and a documented device policy, covering issuance, encryption requirements, and offboarding, is part of a reasonable answer. Keep that documentation current and specific to your actual practice rather than a generic template, since an auditor asking follow-up questions will quickly notice the difference. For anything specific to your regulatory requirements, confirm with your compliance officer or counsel rather than assuming a general best practice covers it.

A documented device policy for an audit should cover these areas:

  • How devices are issued to underwriters and to field examiners, since the two groups carry hardware differently.
  • Encryption requirements for any laptop or tablet holding borrower financials, tax returns, or collateral valuations.
  • Same-day access revocation when a loan officer or relationship manager leaves, ahead of the physical device return.
  • A shipping and retrieval process for remote underwriters' laptops, rather than an assumption that devices come back on their own.

Sizing the tool to the size of your underwriting team

A small lending team with a handful of underwriters and one or two examiners can often manage this with a documented policy and a same-day revocation checklist, run through Process Street, without a dedicated platform yet. Once your examiner team is traveling regularly to collateral sites, or your underwriting staff has grown enough that manual offboarding is a genuine time cost, Rippling or Firstbase starts to earn its place, with the choice between them depending on how much of your team is remote versus office-based.

Revisit this as your loan volume grows. A lender that doubles its underwriting headcount without revisiting its device policy is usually the one that discovers, during an audit or a departure gone wrong, that the informal process never actually scaled.

Executive Capability Standard

What Good Looks Like

Good hardware handling at an asset-based lender means every device touching borrower financials has documented encryption and access controls, and every departure, regardless of how it looks, triggers the same same-day access revocation before the physical device is even discussed.

Building The Capability (5-Stage Skill Ladder)

1. Learn:List which roles handle sensitive borrower data on a portable device and whether your current policy actually covers them consistently.
2. Do Manually:Write a documented device security policy and a same-day access revocation checklist that applies to every departure equally.
3. Delegate:Assign one person, likely in compliance or operations, to own offboarding execution so it doesn't depend on individual managers remembering.
4. Automate:Use Rippling or Firstbase to trigger access revocation and device retrieval automatically off your HR system's termination date.
5. Buy:Once examiner travel or underwriting headcount makes manual tracking unreliable, standardize the fleet on one platform.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Do underwriters need a different device policy than field examiners?

The security baseline, encryption, access controls, documented offboarding, should be the same for both, since both handle sensitive borrower information. The physical logistics differ: examiners genuinely travel with hardware to collateral sites, which makes shipping and retrieval features more relevant for that group specifically.

How fast should we revoke a departing loan officer's system access?

The same day the departure is known, regardless of how the departure looks or where they're headed next. The risk to your borrower and prospect data exists the moment access isn't cut off, not once a physical laptop is returned. Treat every departure with the same standard rather than judging case by case.

What does an audit typically expect to see about our device security?

A documented policy covering device issuance, encryption requirements, and offboarding, specific to your actual practice rather than a generic template. For requirements tied to your specific regulatory framework, confirm with your compliance officer or counsel rather than assuming a general best practice fully covers it.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides