In this guide you will learn how to implement ISO 27001 Annex A 5.11 Return of Assets and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.11 is an ISO 27001 control that requires that people with organisation assets should return them when they leave.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.11 Training Video
- ISO 27001 Annex A 5.11 Requirements and Guidance
- How to implement ISO 27001 Annex A 5.11
- Return of Assets Checklist
- ISO 27001 Templates
- How to comply
- How to audit ISO 27001 Annex A 5.11
- What the auditor will check
- Top 3 Mistakes People Make and How to Avoid Them
- ISO 27001 Annex A 5.11 FAQ
- ISO 27001 Related Controls and Further Reading
- ISO 27001 Controls and Attribute Values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.11 is to ensure you protect the organisations assets as part of the process of changing or terminating employment, contract or agreement.
The ISO 27001 standard defines ISO 27001 Annex A 5.11 as:
Personnel and other interested parties as appropriate should return all the organisation’s assets in their possession upon change or termination of their employment, contract or agreement.
ISO 27001:2022 Annex A 5.11 Return of Assets
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.11 Training Video
In this free training video you will learn How to implement ISO 27001 Return Of Assets (Annex A 5.11) and Pass Your Audit.
ISO 27001 Annex A 5.11 Requirements and Guidance
You are going to have to
- Have an Asset Management Policy that sets out what you do for asset management
- Put in place an asset management process that describes exactly what you do through the asset management lifecycle
- Keep an asset register up to date that shows who is allocated what asset – which we covered in ISO 27001 Annex A 5.9 Inventory Of Information And Other Associated Assets Beginner’s Guide
- Put in place rules for the acceptable use of assets – which we covered in ISO 27001 Annex A 5.10 Acceptable Use Of Information And Other Associated Assets Beginner’s Guide
- Have legal contracts for employees and third parties that include clauses about assets, what they can do with them and that they must return them on termination
- Have a HR Starter, Leaver, Mover process that covers assets
You will need a process for people to return assets to you when they leave or your contract ends with them.
It is simple and straight forward but there a couple of steps to put in place first.
Consider that the employee that leaves.
Do we know what they have? Do they know they need to return it? How do they return it and in what time frame?
Asset Management Policy Template
The asset management policy sets out your approach to asset management and return of assets.

Data Asset Register
The Data Asset Register records the data as well as the data owner. It will be updated when a person leaves or moves role.
Data Asset Register Template
The data asset register is where you record your data assets and data owners. It is a data inventory.

Physical Asset Register
You will implement a Physical Asset Register that will include virtual machines. It records who the asset owner is and can be used to ensure that all assets are returned. You can learn more in our Beginner’s Guide to the Physical Asset Register.
Physical Asset Register Template
The physical asset register is where you record your physical assets and who owns them. It is a physical inventory.

How to implement ISO 27001 Annex A 5.11
Implementing ISO 27001 Annex A 5.11 is a critical security safeguard to ensure that organisational property, both physical and digital, is recovered when an individual’s relationship with the business ends. As a Lead Auditor, I have seen many organisations fail here because they rely on memory rather than a structured process. By following these 10 steps, you will establish a watertight offboarding procedure that protects your intellectual property and reduces your attack surface. This process ensures that assets are returned, access is revoked, and the risk of post-employment data breaches is effectively mitigated.
1. Formalise the Return of Assets Policy
- Document clear requirements within your Information Security Policy that mandate the return of all hardware and software upon termination of employment or contract.
- Ensure the policy explicitly covers employees, contractors, and third-party consultants.
- Result: A legally enforceable mandate that sets clear expectations for all personnel from the outset of their engagement.
2. Integration with the Human Resources Exit Process
- Embed the asset return requirements into the standard HR exit interview and offboarding checklist.
- Coordinate timelines between HR, IT, and Department Heads to ensure assets are recovered before the final day of service.
- Result: A synchronised workflow that prevents personnel from leaving the premises while still in possession of critical assets.
3. Provision a Comprehensive Asset Register
- Maintain an accurate Asset Register that links specific serial numbers and logical assets to individual owners.
- Ensure the register includes “intangible” assets such as proprietary software licenses and encryption keys.
- Result: Full visibility of exactly what needs to be recovered from a specific individual during the offboarding phase.
4. Utilise Record of Equipment (ROE) Documentation
- Implement a Record of Equipment (ROE) log that requires a signature from the user upon receipt and return of physical items.
- Use these documents as the primary evidence for internal and external ISO 27001 audits.
- Result: An auditable paper trail that confirms the physical chain of custody for company hardware.
5. Revoke Logical Access via IAM Roles
- Immediately disable or delete accounts within your Identity and Access Management (IAM) system upon the exit date.
- Ensure that access to cloud repositories, SaaS applications, and internal databases is included in the revocation.
- Result: Immediate cessation of the user’s ability to access organisational data remotely or from personal devices.
6. De-provision Multi-Factor Authentication (MFA)
- Revoke MFA seeds and hardware tokens associated with the individual to prevent secondary bypass attempts.
- Ensure that company-owned mobile phones used for MFA are physically returned and factory reset.
- Result: Elimination of residual authentication pathways that could be exploited post-termination.
7. Secure the Handover of Critical Information
- Enforce a formal knowledge transfer process for administrative passwords, encryption keys, and master files.
- Verify that no “single point of failure” exists where only the departing individual has access to specific encrypted assets.
- Result: Continuous operational resilience and the prevention of data being locked out following a departure.
8. Implement Secure Data Sanitisation for Returned Assets
- Follow a formal decommissioning process that includes data wiping or physical destruction of storage media for returned hardware.
- Maintain certificates of destruction or sanitisation logs for all storage-bearing devices.
- Result: Prevention of data leakage when assets are repurposed for new employees or sent for recycling.
9. Manage the Return of Assets for Role Changes
- Apply the return of assets protocol when an employee moves to a new department with different security requirements.
- Recover assets and access rights that are no longer required for the new role to maintain the principle of least privilege.
- Result: Reduced internal risk by preventing “privilege creep” as staff move through the organisation.
10. Audit the Offboarding Process Regularly
- Conduct quarterly spot checks comparing HR leaver logs against the Asset Register and IAM revocation timestamps.
- Report any discrepancies to the management review meeting to ensure continuous process improvement.
- Result: Verification that the control is operating effectively and remains compliant with Annex A 5.11 requirements.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Return of Assets Checklist
| Asset Type | Action Required | Evidence | ISO 27001:2022 Control |
|---|---|---|---|
| Physical Hardware | Return Laptop, Phone, Keys, Access Badge. | Signed “Equipment Return Form”. | Annex A 5.11 / 7.2 |
| Digital Accounts | Disable Active Directory / Email / SaaS Accounts. | Ticket closed by IT. | Annex A 5.11 / 5.18 |
| BYOD (Personal) | Wipe Company Email/Teams from personal phone. | Signed “Data Deletion Declaration”. | Annex A 5.11 / 6.7 |
| Intellectual Property | Return paper files / notebooks. | Exit Interview Note. | Annex A 5.11 / 5.13 |
ISO 27001 Templates

How to comply
To comply with ISO 27001 Annex A 5.11 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to
- Put in place contracts with employees and third parties that covers the use and return of assets
- Implement your HR Starter, Leaver, Mover process that includes assets
- Allocate assets to individuals and maintain a record
- On termination of contract ensure the secure transport and return of the asset
- Implement a process to securely store returned assets before reuse or reallocation
- Consider the remote wiping, as appropriate, of assets and devices before transport when returning
- Where employees and third parties use their own devices ensures processes are in place and followed for the deletion of company data assets
- Consider the documentation and knowledge transfer from employees and third parties
- Put in place appropriate controls during the notice period to prevent copying of information and intellectual property
How to audit ISO 27001 Annex A 5.11
Auditing ISO 27001 Annex A 5.11 requires a meticulous examination of the offboarding lifecycle to ensure no physical or digital assets remain in the possession of former employees or contractors. As a Lead Auditor, I look for a watertight “Return of Assets” process where the Asset Register, HR records, and IT revocation logs align perfectly. Follow these 10 steps to verify that your organisation effectively prevents data leakage and asset loss during personnel transitions.
1. Review the Return of Assets Policy
- Examine the formal policy to ensure it clearly defines the responsibilities of employees, contractors, and management regarding asset return.
- Verify that the policy specifies timeframes for the return of equipment following termination or change of role.
- Result: Confirmation of a documented mandate that governs the recovery of organisational property.
2. Cross-Reference HR Leavers Logs with Asset Records
- Sample a list of recent leavers from HR records and trace them back to the Asset Register.
- Verify that every item originally assigned to the individual has been marked as returned or decommissioned.
- Result: Assurance that the inventory remains accurate and that “ghost assets” are not left with former staff.
3. Inspect the Record of Equipment (ROE) Logs
- Audit the ROE documents to check for physical signatures or digital timestamps confirming the receipt of returned hardware.
- Ensure serial numbers on returned items match the original issuance records.
- Result: Validated physical evidence of the transfer of custody for laptops, mobiles, and hardware tokens.
4. Audit IAM Role Revocation and Access Logs
- Review Identity and Access Management (IAM) logs to confirm that logical access was revoked immediately upon the user’s departure.
- Verify that “Single Sign-On” (SSO) and individual application accounts are disabled in alignment with the exit date.
- Result: Proof that the organisation has eliminated the risk of unauthorised remote access by former personnel.
5. Verify Multi-Factor Authentication (MFA) De-provisioning
- Check that MFA seeds, hardware keys, or mobile authenticator links associated with the leaver have been revoked.
- Confirm that company-owned MFA hardware has been physically recovered.
- Result: Technical certainty that the secondary layer of authentication cannot be bypassed or misused.
6. Inspect Secure Disposal and Data Sanitisation Records
- Examine certificates of data destruction for assets that were decommissioned rather than reassigned.
- Verify that the sanitisation process follows industry standards to prevent data recovery from returned hard drives.
- Result: Evidence that sensitive information has been permanently removed from the asset lifecycle.
7. Audit the Recovery of Intangible Information Assets
- Confirm that intellectual property, such as source code, internal documentation, and encryption keys, has been accounted for.
- Verify that access to proprietary cloud repositories (e.g., GitHub, AWS) was removed.
- Result: Protection of the organisation’s competitive advantage and sensitive digital IP.
8. Evaluate Management Oversight of the Exit Checklist
- Review completed exit checklists to ensure they have been signed off by the relevant department head or IT manager.
- Check for instances where assets were not returned and verify if the organisation followed its recovery or “loss” procedure.
- Result: Confirmation of management accountability for the final stages of the asset management process.
9. Test the Return of Assets for Third-Party Contractors
- Perform a deep-dive audit on the offboarding process for temporary contractors and external consultants.
- Verify that contractual clauses regarding the return of data and hardware were enforced upon contract completion.
- Result: Mitigation of the specific risks associated with external partners and supply chain access.
10. Verify Knowledge Transfer and Handover Integrity
- Examine evidence that critical administrative passwords or master keys held by the individual were changed or handed over.
- Confirm that the individual no longer possesses unique knowledge that creates a “single point of failure” for asset access.
- Result: Maintenance of operational resilience and security continuity post-departure.
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
What the auditor will check
The audit is going to check a number of areas. Lets go through them
1. There is a starter, leaver, mover process
The audit will check you have a starter, leaver, mover process documented and that you are following it. It will check that the return of assets is included in that process. It will then seek evidence that it has been followed at least once. They will randomly choose a sample of leavers and ask you to walk through what you did when you left. They are checking that you followed your written process and have evidence that the assets were returned.
2. There is an up to date asset register
The asset register will be checked to see that it meets the requirements of the standard and as a minimum that assets are allocated to owners. Where assets are returned, even if not reallocated, they will want to see that recorded in the asset register. They may then ask questions arounds the physical security of stored assets – such as are they locked away, who has access, what is the process for secure disposal / destruction.
3. Contracts are in place
They are going to look at your employee contracts and your third party contracts and see if the return of assets is mentioned and covered. There are other security clauses that are required, but where appropriate, they want to see that contracts cover the return of assets. This can include the deletion of data and information where personal or Bring Your Own Devices have been allowed and used. It would be sensible for them to sample any BYOD devices that belong to people that have left to ask you how you ensured data was deleted. Clearly they will not audit the actually device but the process you went through and the assurances that you got.
Top 3 Mistakes People Make and How to Avoid Them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.11 are
1. Your asset register is not up to date
Either not having an asset register, an asset register that does not record all devices or an asset register that is out of date is the number 1 mistake people make. Usually as it is admin step that can get lost in the course of running a business.
2. Assets were not destroyed securely
Not a direct response to the the return of assets but they do check secure destruction and that it followed process. It is a common for organisations to have a room full of old assets that they do not know what to do with so keep them for ever. It can be a nightmare in time as no one knows why we keep them, what is on them and if we need them which brings up legal, regulatory and contractual issues.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 5.11 FAQ
Yes, a documented policy or procedure for the return of assets is essential to satisfy the requirements of Annex A 5.11 and provide legal standing for equipment recovery.
It defines clear timelines for the return of equipment.
It outlines the specific roles and responsibilities of HR, IT, and management.
It establishes the legal right to recover costs for unreturned items where applicable.
It provides a repeatable framework for auditors to verify compliance.
The scope of Annex A 5.11 extends beyond physical hardware to include all types of information and organisational property.
Physical hardware: Laptops, mobile phones, tablets, and monitors.
Access credentials: ID badges, physical keys, and MFA tokens.
Information assets: Intellectual property, customer data, and printed documentation.
Digital assets: Backups, software licenses, and cloud-stored corporate files.
The responsibility for managing the return of assets is typically shared across HR, IT, and the departing individual’s line manager.
HR: Initiates the offboarding workflow and communicates final requirements to the leaver.
IT: Verifies the return and functional state of technical hardware and digital data.
Line Manager: Ensures physical hand-overs occur and access cards are recovered on the final day.
Individual: Contractually obligated to return all property in their possession.
Yes, digital information assets are a core focus of Annex A 5.11, requiring users to return or delete corporate data stored on personal or external devices.
Includes the removal of corporate email accounts from personal smartphones.
Requires the handover of any administrative passwords or encryption keys.
Mandates the return of physical storage media like USB drives or external hard disks.
Covers intellectual property created during the term of employment.
Failure to return assets should be treated as a security incident and managed through defined legal and contractual escalations.
Immediate remote wiping of mobile devices and laptops where technically possible.
Reporting unreturned items to insurance providers for replacement recovery.
Legal communication regarding the retention of intellectual property.
Withholding final settlement amounts where permitted by local employment laws.
ISO 27001 Related Controls and Further Reading
- A Practical Guide: How to Implement ISO 27001:2022 Annex A 5.11 – Return of Assets
- How to Audit ISO 27001 Annex A 5.11: A Practical Guide to Return of Assets
- The Ultimate 10-Point Audit Checklist for ISO 27001 Return of Assets (A.5.11)
- A Practical Guide for SMEs: Mastering ISO 27001 Annex A 5.11 – Return of Assets
- A Guide for AI Companies to ISO 27001 Annex A 5.11: Return of Assets
- A Tech Startup’s Practical Guide to ISO 27001 Annex A 5.11: Return of Assets
- ISO 27001 Return of Assets Beginner’s Guide
- ISO 27001 Asset Management Policy Beginner’s Guide
- ISO 27001 Physical Asset Register Beginner’s Guide
ISO 27001 Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Protect | Asset management | Protection |
| Integrity | ||||
| Availability |
