ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 5.11 Return of assets

ISO 27001 Annex A 5.11 Return of assets

What is ISO 27001 Annex A 5.11 – Return of Assets?

ISO 27001 Annex A 5.11 focuses on ensuring that employees, contractors, and other relevant parties return organizational assets when their employment, contract, or access to the organization ends or changes.

The purpose is to make sure that organizational assets are recovered and that the organization does not lose control over:

  • Laptops
  • Mobile phones
  • Access cards
  • Security tokens
  • Storage devices
  • Documents
  • Company information
  • Keys
  • Equipment
  • Software or licensed resources
  • Other assets provided for business purposes

Simple explanation

A.5.11 means when someone leaves the organization, changes roles, or no longer needs an organizational asset, the organization should ensure that the relevant assets are returned and accounted for.

The control is not limited to employees.

It may also apply to:

  • Contractors
  • Consultants
  • Temporary workers
  • Interns
  • Vendors
  • Third-party personnel

Why is A.5.11 important?

When an employee or contractor leaves, the organization may lose control over assets if there is no proper return process.

For example, a departing employee may still have:

  • Company laptop
  • Mobile phone
  • Access card
  • USB drive
  • Company documents
  • Printed confidential information
  • Security token
  • Backup device

If these assets are not returned or appropriately handled, they may create security risks.

Potential risks include:

  • Unauthorized access
  • Information leakage
  • Loss of confidential information
  • Theft of company equipment
  • Exposure of customer data
  • Loss of intellectual property
  • Continued use of company resources

Simple principle

When access ends, control over organizational assets should also be recovered.


What does A.5.11 require?

The organization should establish a process to ensure that organizational assets are returned when:

  • Employment ends
  • A contract ends
  • A contractor leaves
  • An employee changes roles
  • An employee transfers departments
  • An asset is replaced
  • An asset is no longer required
  • Access or responsibility is transferred

The organization should also determine what happens when an asset cannot be returned.

For example:

  • Lost
  • Stolen
  • Damaged
  • Destroyed
  • Permanently retained under an approved arrangement

The organization should document the appropriate action.


What counts as an organizational asset?

Assets can include both physical and information assets.

Physical assets

Examples:

  • Laptops
  • Desktop computers
  • Mobile phones
  • Tablets
  • Monitors
  • Access cards
  • Security tokens
  • USB drives
  • External hard drives
  • Keys
  • Company vehicles
  • Office equipment

Information assets

Examples:

  • Printed documents
  • Customer records
  • Contracts
  • Business documents
  • Source code
  • Product information
  • Confidential reports
  • Project documentation

Digital assets

Depending on the organization’s environment:

  • Cloud credentials
  • Security certificates
  • API keys
  • Authentication tokens
  • Cryptographic keys
  • Software licenses
  • Digital repositories
  • Administrative accounts

The return or recovery process should be appropriate to the type of asset.


Activities required to implement A.5.11

1. Maintain an asset assignment record

The organization should know which assets have been assigned to which users.

For example:

EmployeeAssetAsset IDDate IssuedStatus
Employee ALaptopLAP-10201-Jan-2026Assigned
Employee AMobileMOB-04401-Jan-2026Assigned
Employee BLaptopLAP-10315-Feb-2026Assigned
Employee CSecurity TokenTOK-01910-Mar-2026Assigned

This makes the return process much easier.


2. Include asset return in the offboarding process

Asset return should be part of the employee or contractor offboarding checklist.

A simple process could be:

Termination / Contract End

↓

Identify Assigned Assets

↓

Notify Employee / Contractor

↓

Collect Assets

↓

Verify Condition

↓

Confirm Information Handling

↓

Disable Access

↓

Update Asset Register

↓

Complete Offboarding

This should be coordinated with HR, IT and relevant management.


3. Define responsibilities

Clearly assign responsibility for asset recovery.

For example:

ActivityResponsibility
Initiate offboardingHR / Management
Identify assigned assetsIT
Collect laptop/deviceIT
Collect access cardsFacilities
Recover documentsDepartment Owner
Disable accountsIT / Security
Update asset registerIT
Confirm completionHR / IT

For a small startup, one person may perform several roles.


4. Recover physical devices

When an employee leaves, the organization should recover applicable devices.

Examples:

  • Laptop
  • Mobile phone
  • Tablet
  • USB drive
  • Security token
  • Access card

The organization should record whether the asset was:

  • Returned
  • Lost
  • Stolen
  • Damaged
  • Reassigned
  • Disposed

5. Address information stored on returned devices

Returning a laptop is not necessarily the end of the process.

The organization should consider information stored on the device.

Depending on the organization’s requirements, IT may:

  • Back up required business information
  • Verify synchronization
  • Remove organizational accounts
  • Revoke access
  • Securely erase the device
  • Reimage the device
  • Reassign the device

The approach should depend on the organization’s asset-management and data-protection requirements.


6. Recover or revoke digital assets

Some assets cannot simply be physically returned.

For example:

  • API keys
  • Passwords
  • Access tokens
  • Certificates
  • Encryption keys
  • Shared secrets

Where appropriate, the organization should:

  • Revoke credentials
  • Rotate secrets
  • Disable accounts
  • Transfer ownership
  • Revoke tokens
  • Replace certificates
  • Recover administrative access

This is particularly important when an employee had privileged access.


7. Handle remote workers

Remote employees may have organizational assets at home.

The organization should define how assets are returned.

Options may include:

  • Courier collection
  • Company pickup
  • Office return
  • Approved shipping process

The organization should maintain evidence that the asset was received.


8. Handle contractors and third parties

The return process should also cover relevant external parties.

For example:

A contractor may have:

  • Company laptop
  • Customer documents
  • Access card
  • Security token
  • Project documentation

When the contract ends, the organization should confirm that relevant assets are returned and access is appropriately terminated.


9. Handle role changes

A.5.11 is not limited to people leaving the organization.

An employee may move from:

Engineering → Marketing

The employee may no longer require:

  • Production access
  • Development laptop
  • Security credentials
  • Administrative tokens
  • Engineering documentation

The organization should review assigned assets and recover or reassign those no longer required.


10. Deal with lost or stolen assets

Sometimes an asset cannot be returned.

For example:

Employee reports that company laptop was stolen.

The organization should have a process for:

  • Reporting the incident
  • Locking or wiping the device where possible
  • Revoking access
  • Investigating potential data exposure
  • Updating the asset register
  • Recording the incident

This may also trigger the organization’s incident-management process.


Startup Example

Consider a SaaS startup with 50 employees.

An employee resigns.

The employee has:

  • Company laptop
  • Mobile phone
  • Access card
  • Security token

The HR team initiates offboarding.

Step 1

HR informs IT of the last working day.

↓

Step 2

IT checks the asset register.

Laptop → Assigned

Mobile → Assigned

Security Token → Assigned

↓

Step 3

IT arranges collection.

↓

Step 4

Assets are physically received.

↓

Step 5

IT checks the laptop and secures organizational information.

↓

Step 6

Accounts and tokens are disabled or revoked as applicable.

↓

Step 7

Asset register is updated.

Laptop → Returned

Mobile → Returned

Token → Returned

↓

Step 8

HR/IT records completion of offboarding.

This provides evidence that organizational assets were recovered.


Example Asset Return Checklist

Asset / ActivityReturned / CompletedRemarks
LaptopYes/No
Mobile phoneYes/No
TabletYes/No
Access cardYes/No
Security tokenYes/No
USB / storage deviceYes/No
Physical documentsYes/No
Company keysYes/No
Business information recoveredYes/No
Accounts disabledYes/No
Access tokens revokedYes/No
API keys rotated where requiredYes/No/N/A
Asset register updatedYes/No
Offboarding completedYes/No

Example Asset Return Register

EmployeeAssetAsset IDExit DateReturn DateConditionStatus
Employee ALaptopLAP-10220-Sep-202620-Sep-2026GoodReturned
Employee AMobileMOB-04420-Sep-202620-Sep-2026GoodReturned
Employee AAccess CardAC-01820-Sep-202620-Sep-2026GoodReturned
Employee BLaptopLAP-10725-Sep-202626-Sep-2026GoodReturned

What if an asset cannot be returned?

The organization should have a defined process.

Lost

Report → Investigate → Disable/Revoke → Assess Risk → Update Register

Stolen

Report → Incident Process → Secure Accounts → Assess Data Exposure → Update Register

Damaged

Assess → Repair/Replace → Update Asset Status

Permanently retained

If an employee is formally authorized to retain an asset, the organization should document the approval and ownership arrangement.


A.5.11 Audit Evidence

An auditor may look for evidence such as:

Asset assignment

  • Asset register
  • Laptop allocation records
  • Device assignment records
  • Security token records

Offboarding

  • Employee offboarding checklist
  • Contractor offboarding checklist
  • HR/IT notifications
  • Exit clearance

Return evidence

  • Asset return forms
  • Courier records
  • IT acknowledgment
  • Asset register updates

Digital asset recovery

  • Account deactivation
  • Token revocation
  • Credential rotation
  • Ownership transfer

Exception handling

  • Lost asset reports
  • Theft reports
  • Incident records
  • Risk assessments

A.5.11 Audit Checklist

Audit QuestionEvidence
Does the organization maintain records of assigned assets?Asset Register
Is asset return included in offboarding?Offboarding Checklist
Are laptops and other devices recovered?Return Records
Are access cards and security tokens recovered?Return Records
Are contractors included?Contractor Offboarding
Are role changes considered?Access/Asset Review
Are digital credentials and tokens appropriately revoked?Access Records
Are lost or stolen assets handled through an appropriate process?Incident Records
Is the asset register updated after return?Updated Register
Is completion of asset return documented?Exit Clearance

Common Mistakes

1. Only recovering laptops

Organizations sometimes focus on physical devices and forget:

  • Access cards
  • Security tokens
  • USB drives
  • Documents
  • Credentials
  • API keys
  • Digital access

2. Relying entirely on HR

HR may know that an employee is leaving, but may not know which technical assets the employee has.

HR, IT, Security and relevant business owners should coordinate.


3. No asset assignment records

If the organization does not know who has which laptop or device, recovering assets becomes difficult.


4. Ignoring contractors

Contractors and consultants may have access to highly sensitive information and systems.

Their assets should be included where applicable.


5. Forgetting role changes

Asset return can also be relevant when someone changes responsibilities.

An employee should not retain assets or access simply because they had them in their previous role.


6. Treating digital assets like physical assets

You cannot physically “return” an API key or password.

These assets may need to be:

Revoked → Rotated → Reissued


Practical Startup Implementation Model

A startup can implement A.5.11 with a simple process:

Employee / Contractor Exit or Role Change

↓

Check Asset Register

↓

Identify Assigned Assets

↓

Collect / Recover Assets

↓

Secure Organizational Information

↓

Disable / Revoke Digital Access

↓

Update Asset Register

↓

Record Completion

↓

Close Offboarding


Policy vs. Process vs. Evidence

ElementExample
PolicyOrganizational assets assigned to employees, contractors and other users shall be returned when no longer required or when employment or contractual relationships end.
ProcessHR initiates offboarding, IT identifies assigned assets, assets are recovered, digital access is revoked and the asset register is updated.
EvidenceAsset register, offboarding checklist, asset return acknowledgment, access-revocation records and exception records.

The objective is not simply to collect company laptops.

The objective is to ensure that the organization maintains control of its physical, information and digital assets throughout the employee or contractor lifecycle.


Useful Resources

Recommended documents

  • Asset Return Checklist – [Insert Draft Document Link]
  • Employee Offboarding Checklist – [Insert Draft Document Link]
  • Contractor Offboarding Checklist – [Insert Draft Document Link]
  • Asset Register – [Insert Draft Document Link]
  • IT Asset Handover Form – [Insert Draft Document Link]
  • Access Revocation Checklist – [Insert Draft Document Link]
  • Lost/Stolen Asset Incident Form – [Insert Draft Document Link]

Related ISO 27001 controls

A.5.11 can work closely with:

  • A.5.9 – Inventory of information and other associated assets
  • A.5.10 – Acceptable use of information and other associated assets
  • A.5.12 – Classification of information
  • A.5.15 – Access control
  • A.5.16 – Identity management
  • A.5.17 – Authentication information
  • A.6.5 – Responsibilities after termination or change of employment
  • A.7.7 – Clear desk and clear screen
  • A.7.9 – Security of assets off-premises
  • A.8.1 – User endpoint devices

Final Takeaway

ISO 27001 Annex A 5.11 is about ensuring that organizational assets are returned or otherwise appropriately recovered when employees, contractors or other authorized users no longer need them.

A practical organization should be able to answer:

What assets were assigned to the person?
Were those assets returned?
What happened to organizational information stored on them?
Were digital credentials and tokens revoked where necessary?
Was the asset register updated?
Is there evidence that the process was completed?

For startups, the approach can remain simple:

Identify → Collect → Secure → Revoke → Update → Record

The goal is to ensure that when someone’s role or relationship with the organization ends, the organization’s assets and information do not leave with them.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *