A5.11: Return of Assets
4 min read
ISO 27001 A.5.11: Return of Assets- ensures that organizations have a structured process for reclaiming assets and revoking access rights when employees or third parties exit or change roles. This helps in preventing security risks, data leaks, and compliance violations.
When an employee, contractor, or third party leaves an organization or changes roles, they may have access to company-owned assets such as laptops, mobile phones, access cards, USB drives, and sensitive documents. If these assets are not properly returned, it could lead to data breaches, loss of sensitive information, or unauthorized access to company systems.
Implementation Guide #
Step 1: Maintain an Updated Asset Inventory
- Create and update an Asset Register that tracks all company-owned hardware, software, and sensitive data.
- Assign each asset to an individual owner for accountability.
Step 2: Define a Clear Return Process
- Implement a formal exit procedure that includes asset return as a mandatory step.
- Ensure all employees and contractors acknowledge their asset responsibilities in their onboarding agreements.
- Set a deadline (e.g., on the last working day) for returning assets.
Step 3: Revoke Access to Systems and Data
- Disable user accounts, VPN access, email accounts, and cloud services.
- Remove the individual’s security badges, keycards, and physical access rights.
- If applicable, remotely wipe corporate data from personal or BYOD devices.
Step 4: Conduct Verification & Audit
- Ensure all returned assets are accounted for and in working condition.
- If an asset is missing, assess the risk and take necessary actions (e.g., report as lost/stolen).
- Conduct periodic audits to confirm compliance with asset return policies.
Templates #
- Asset Return Form (To document the return of each asset).
- Exit Checklist (Ensuring all assets and access rights are revoked).
- Acknowledgment Agreement (Signed at onboarding, stating return obligations).
Example #
A software developer resigns and forgets to return their company laptop, which contains sensitive source code. If this laptop is later found being used for unauthorized freelance work, the company could face data exposure and legal issues.
After implementing A.5.11:
- The IT department ensures all departing employees complete a return checklist before processing final payroll.
- All access credentials are revoked immediately upon resignation notice.
- A remote tracking and data wipe solution is installed on company laptops.
How to Comply #
To comply with ISO 27001 A.5.11, organizations should:
- Have a documented asset return policy in place.
- Track and maintain an inventory of assigned assets.
- Ensure HR and IT teams coordinate during employee offboarding.
- Revoke physical and digital access immediately upon departure.
How to Pass an Audit #
Key Documents to Prepare:
- Asset Register showing issued and returned assets.
- Employee Exit Checklist proving returned items and access revocation.
- Evidence of periodic asset audits to ensure compliance.
What the Auditor Will Check:
- Is there a structured return process for all employees and third parties?
- Are records maintained for all assigned and returned assets?
- Is there proof of access revocation after an employee leaves?
Top 3 Mistakes People Make #
- No Formal Asset Tracking – Many organizations fail to track which employees have which assets, leading to losses.
- Delayed Revocation of Access – If access to emails, systems, and cloud storage isn’t revoked immediately, ex-employees could misuse sensitive information.
- Failure to Account for Digital Assets – Many focus on physical assets but forget about login credentials, software licenses, or sensitive data stored in cloud services.
ISO 27001 Return of Assets FAQ #
Q1: What if an employee claims they lost an asset?
The organization should have a policy for reporting lost assets and define whether the employee is financially responsible for replacement.
Q2: Should personal devices (BYOD) also be included in the return process?
Yes, if company data was stored on a personal device, the organization should have a data-wiping policy to remove sensitive information before the employee leaves.
Q3: How can organizations ensure assets are returned on time?
Tie asset return to final payroll processing—employees must return all items before receiving their last paycheck.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.5.11 Return of Assets | Preventive, Risk-Based, Operational |
| Purpose | Ensure assets are returned to prevent security risks |
| Applicability | Employee offboarding, third-party contracts |
| ISO 27001 Domains | Asset Management, Access Control, HR Security |
A poorly managed asset return process can lead to security breaches, data loss, and compliance issues. By implementing A.5.11 effectively, organizations can minimize risks and ensure business continuity.