ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Asset Return Checklist

Asset Return Checklist

1. Purpose

The purpose of this Asset Return Checklist is to ensure that organizational assets are identified, recovered, verified, and securely handled when an employee, contractor, consultant, or other authorized user:

  • Leaves the organization
  • Changes role
  • Changes employment status
  • No longer requires an asset
  • Completes a project
  • Returns from a long-term assignment
  • Ends third-party access

The checklist helps prevent:

  • Loss of organizational assets
  • Unauthorized access
  • Retention of confidential information
  • Unauthorized use of company equipment
  • Loss of customer information
  • Retention of credentials or access tokens
  • Incomplete offboarding

2. Scope

This checklist applies to assets issued, assigned, or made available to personnel, including:

Hardware

  • Laptops
  • Desktops
  • Mobile phones
  • Tablets
  • Monitors
  • Docking stations
  • Headsets
  • Security keys
  • USB devices
  • Network equipment
  • Other company-owned equipment

Information and Media

  • Documents
  • Printed records
  • USB drives
  • Backup media
  • Customer information
  • Company information
  • Confidential or Restricted information

Access-Related Assets

  • Access cards
  • Building keys
  • Security tokens
  • MFA devices
  • Digital certificates
  • Hardware authentication devices

Other Assets

  • Software licenses
  • Corporate SIM cards
  • Company credit/payment cards where applicable
  • Specialized equipment
  • Project-specific assets

3. Asset Return Process

The recommended process is:

Exit / Role Change Identified
↓
Identify Assigned Assets
↓
Prepare Return List
↓
Collect Assets
↓
Verify Condition
↓
Check Information/Data
↓
Revoke Digital Access
↓
Securely Erase / Reconfigure
↓
Update Asset Register
↓
Confirm Return
↓
Close Offboarding


4. Employee / User Information

FieldDetails
Employee/User Name
Employee ID
Department
Job Title
Manager
Employment Type
Last Working Date
Exit/Transfer Date
ReasonResignation / Termination / Transfer / Project End
Asset Coordinator
IT Representative
HR Representative
Checklist Date

5. Asset Return Register

Asset IDAsset TypeDescriptionSerial/IdentifierAssigned ToConditionReturned DateVerified ByStatus
AST-001LaptopDell LaptopXXXXXEmployeeGood☐ Returned
AST-002MobileCompany PhoneXXXXXEmployeeGood☐ Returned
AST-003Security KeyMFA KeyXXXXXEmployeeGood☐ Returned
AST-004Monitor24″ MonitorXXXXXEmployeeGood☐ Returned

6. Hardware Return Checklist

Laptop/Desktop

  • ☐ Device returned
  • ☐ Asset ID verified
  • ☐ Serial number verified
  • ☐ Physical condition checked
  • ☐ Charger returned
  • ☐ Docking station returned where applicable
  • ☐ Accessories returned
  • ☐ Device recorded in Asset Inventory
  • ☐ Device securely wiped/reconfigured before reassignment

Mobile Device

  • ☐ Device returned
  • ☐ SIM card returned where applicable
  • ☐ Charger/accessories returned
  • ☐ Device identifier verified
  • ☐ Corporate account removed
  • ☐ Device securely reset before reassignment

Other Equipment

  • ☐ Monitor
  • ☐ Keyboard
  • ☐ Mouse
  • ☐ Headset
  • ☐ Webcam
  • ☐ Security key
  • ☐ USB/removable media
  • ☐ Network equipment
  • ☐ Other equipment

7. Information and Data Check

Before an asset is reassigned, disposed of, or transferred, the organization should determine whether it contains organizational information.

Check for:

  • ☐ Customer information
  • ☐ Employee information
  • ☐ Confidential information
  • ☐ Restricted information
  • ☐ Source code
  • ☐ Security information
  • ☐ Local documents
  • ☐ Downloaded files
  • ☐ Browser-stored information
  • ☐ Cached credentials
  • ☐ Authentication tokens
  • ☐ Encryption keys
  • ☐ Certificates
  • ☐ Backup files

Important:

Do not simply delete files manually and assume the device is clean.

The organization should use an approved secure wiping, reimaging, reset, or other appropriate process based on the asset and information sensitivity.


8. Corporate Accounts and Access

Asset return should be coordinated with access termination.

Verify:

  • ☐ Corporate account disabled where applicable
  • ☐ SSO access removed
  • ☐ Email access removed
  • ☐ VPN access removed
  • ☐ SaaS access removed
  • ☐ Cloud access removed
  • ☐ Source-code repository access removed
  • ☐ Customer-system access removed
  • ☐ Privileged access removed
  • ☐ MFA sessions/tokens revoked where appropriate
  • ☐ API tokens revoked
  • ☐ SSH keys revoked
  • ☐ Certificates revoked where applicable
  • ☐ Active sessions terminated
  • ☐ Shared credentials changed where necessary

Access termination should be completed according to the organization’s offboarding and access-control procedures.


9. Cloud and AWS Access

For users with AWS or other cloud access:

  • ☐ AWS IAM access reviewed
  • ☐ SSO access removed
  • ☐ IAM roles reviewed
  • ☐ Privileged roles removed
  • ☐ Access keys disabled/revoked
  • ☐ Temporary credentials expired/revoked where applicable
  • ☐ SSH keys reviewed
  • ☐ Cloud console sessions terminated
  • ☐ CI/CD credentials reviewed
  • ☐ Secrets associated with the user reviewed
  • ☐ Cloud access logs retained as required

Important

Returning a laptop does not automatically remove cloud access.

Both physical assets and digital access must be addressed.


10. Source Code and Development Assets

For developers or technical personnel:

  • ☐ GitHub/GitLab/Bitbucket access removed
  • ☐ Repository permissions reviewed
  • ☐ SSH keys revoked
  • ☐ Personal access tokens revoked
  • ☐ Cloud credentials revoked
  • ☐ CI/CD access removed
  • ☐ Deployment permissions removed
  • ☐ Secrets associated with the user reviewed
  • ☐ Local source-code copies addressed
  • ☐ Customer/production data removed according to procedure

11. Physical Access

Recover:

  • ☐ Employee ID card
  • ☐ Building access card
  • ☐ Office keys
  • ☐ Server-room access
  • ☐ Security tokens
  • ☐ Visitor/access credentials
  • ☐ Parking access where applicable
  • ☐ Other physical access devices

Verify:

  • ☐ Physical access disabled
  • ☐ Access card deactivated
  • ☐ Keys returned
  • ☐ Restricted-area access removed

12. Information Classification Check

Before an asset is reassigned or disposed of, determine whether it contains:

ClassificationAction
PublicNormal handling as appropriate
InternalSecure organizational handling
ConfidentialSecure transfer/wipe/storage
RestrictedStrictly controlled handling and secure disposal

The higher the classification, the stronger the required protection should be.


13. BYOD and Personal Devices

If the employee used a personal device under the organization’s BYOD Policy:

  • ☐ Corporate account access removed
  • ☐ Corporate applications removed where required
  • ☐ Corporate work profile removed
  • ☐ Corporate certificates/tokens revoked
  • ☐ Corporate data removed where technically supported
  • ☐ Cloud sessions terminated
  • ☐ Corporate VPN access removed
  • ☐ Corporate credentials revoked
  • ☐ Organizational information confirmed as removed where required

The organization should avoid accessing unrelated personal information on the user’s device.


14. Remote Worker Asset Return

For remote employees, assets may need to be returned through:

  • Courier
  • Authorized logistics provider
  • Office return
  • Local collection
  • Other approved process

The organization should maintain evidence of:

  • Shipment
  • Delivery
  • Asset identification
  • Condition
  • Receipt
  • Verification

Example

Employee → Courier → IT Asset Receipt → Asset Verification → Secure Wipe → Asset Register Update


15. Asset Condition Assessment

Each returned physical asset should be checked for:

  • ☐ Physical damage
  • ☐ Missing accessories
  • ☐ Broken components
  • ☐ Signs of tampering
  • ☐ Missing labels
  • ☐ Functional condition
  • ☐ Storage/media condition
  • ☐ Battery condition where relevant

Condition should be recorded objectively.

Example:

Good: Normal operational condition.

Fair: Minor wear but usable.

Damaged: Physical damage requiring repair.

Unusable: Cannot reasonably be returned to service.


16. Lost or Missing Assets

If an assigned asset is not returned:

  1. Confirm the asset assignment.
  2. Contact the user.
  3. Determine whether the asset is lost, stolen, or otherwise unavailable.
  4. Report the matter to IT/Security.
  5. Revoke associated access where appropriate.
  6. Assess information exposure.
  7. Determine whether an information security incident occurred.
  8. Update the asset register.
  9. Document the investigation and resolution.

Example:

A company laptop is not returned because the employee reports that it was stolen during travel.

The organization should not treat this only as an inventory issue. It may also require a security incident assessment.


17. Lost Device Security Actions

For a lost or stolen device, consider:

  • Account lock
  • Session revocation
  • Password reset
  • MFA/session revocation
  • Remote lock
  • Remote wipe
  • Certificate revocation
  • VPN access removal
  • Cloud access review
  • Data exposure assessment
  • Incident investigation

The specific actions depend on device capabilities and organizational risk.


18. Asset Transfer

If an asset is being transferred to another employee:

  • ☐ Existing owner removed
  • ☐ New owner identified
  • ☐ Asset condition recorded
  • ☐ Information securely removed
  • ☐ Device reimaged/reset where required
  • ☐ New user assigned
  • ☐ New asset acknowledgement completed
  • ☐ Asset Register updated
  • ☐ Access configured separately for new user

Lifecycle

Return → Verify → Secure → Reassign → Record


19. Asset Disposal

If an asset is being retired:

  • ☐ Asset identified for disposal
  • ☐ Information classification assessed
  • ☐ Data securely erased/destroyed
  • ☐ Storage media handled appropriately
  • ☐ Disposal method recorded
  • ☐ Disposal vendor verified where applicable
  • ☐ Certificate of destruction obtained where applicable
  • ☐ Asset status changed to Retired/Disposed
  • ☐ Asset Register updated

For sensitive information, normal file deletion may not be sufficient.


20. Software and Licenses

Where applicable:

  • ☐ Software licenses recovered/reassigned
  • ☐ User licenses removed
  • ☐ SaaS seats reassigned
  • ☐ Administrator privileges removed
  • ☐ Developer tools access removed
  • ☐ Security tools access removed
  • ☐ Subscription ownership transferred where required

21. Third-Party Personnel

For contractors, consultants, suppliers, and temporary personnel:

  • ☐ Company assets returned
  • ☐ Customer assets returned where applicable
  • ☐ Supplier-issued access removed
  • ☐ VPN access removed
  • ☐ SaaS access removed
  • ☐ Cloud access removed
  • ☐ Source-code access removed
  • ☐ Confidential information returned/deleted as required
  • ☐ Contractual return/destruction requirements verified
  • ☐ Completion confirmed by responsible owner

Third-party offboarding should also consider contractual requirements.


22. Employee Acknowledgement

The employee/user should confirm:

I confirm that I have returned the organizational assets assigned to me, except those specifically identified in this checklist. I understand that organizational information and access credentials must not be retained or used after my authorization ends.

Employee/User

Name: __________________________

Signature: _______________________

Date: ____________________________


23. IT Verification

IT confirms that:

  • ☐ Physical assets have been received.
  • ☐ Asset identifiers have been verified.
  • ☐ Device condition has been recorded.
  • ☐ Corporate access has been removed.
  • ☐ Required credentials/tokens have been revoked.
  • ☐ Corporate information has been securely handled.
  • ☐ Device has been wiped/reimaged where required.
  • ☐ Asset records have been updated.

IT Representative:

Name: __________________________

Signature: _______________________

Date: ____________________________


24. Security Verification

Security confirms, where applicable:

  • ☐ Privileged access removed
  • ☐ Cloud access reviewed
  • ☐ MFA sessions/tokens revoked
  • ☐ API keys/access keys reviewed
  • ☐ SSH keys reviewed
  • ☐ Security systems access removed
  • ☐ Incident assessment completed where required
  • ☐ Sensitive information exposure assessed
  • ☐ Required evidence retained

Security Representative:

Name: __________________________

Signature: _______________________

Date: ____________________________


25. HR / Management Verification

HR or the responsible manager confirms:

  • ☐ Exit/transfer date confirmed
  • ☐ Asset list reviewed
  • ☐ Required assets returned
  • ☐ Missing assets escalated
  • ☐ Access termination coordinated
  • ☐ Final checklist completed

Representative:

Name: __________________________

Signature: _______________________

Date: ____________________________


26. Final Asset Return Status

ItemStatus
All physical assets returned☐
Missing assets investigated☐
Organizational information secured☐
Corporate accounts disabled☐
Privileged access removed☐
Cloud access removed☐
Source-code access removed☐
Physical access removed☐
BYOD access removed where applicable☐
Devices wiped/reimaged where required☐
Asset Register updated☐
Security incident assessment completed if required☐
Exceptions documented☐
Offboarding completed☐

27. Asset Return Record

FieldDetails
Asset Return ID
User
Exit/Transfer Date
Assets Assigned
Assets Returned
Missing Assets
Asset Condition
Data/Wipe Status
Access Revocation Status
Security Review
Exceptions
Final StatusCompleted / Pending / Escalated
Verified By
Verification Date

28. Common Mistakes

Mistake 1: Only Collecting the Laptop

A user may also have:

  • Mobile device
  • Security key
  • Access card
  • USB device
  • Company SIM
  • Physical documents

All assigned assets should be checked.

Mistake 2: Returning the Device but Leaving Access Active

Asset return and access termination are separate activities.

Mistake 3: Forgetting Cloud Access

AWS, Azure, SaaS, Git repositories, VPN, and other digital access must be reviewed.

Mistake 4: Ignoring Local Data

A returned laptop may contain customer information, source code, credentials, or other sensitive information.

Mistake 5: No Evidence

The organization should retain evidence showing what was returned, when, by whom, and how it was processed.

Mistake 6: Treating Lost Devices as Only an HR Issue

A lost device may represent a security incident and should be assessed accordingly.


29. Startup-Friendly Process

A small organization can use a simple centralized checklist.

HR

Exit Identified

↓

Manager

Confirm Assigned Assets

↓

IT

Collect Assets + Disable Access

↓

Security

Review Sensitive/Privileged Access

↓

IT

Secure/Wipe Device

↓

Asset Owner

Update Asset Register

↓

HR

Close Offboarding

The process can be managed through an existing HR, ticketing, or IT service-management system rather than creating a separate complex platform.


30. Audit Evidence

Useful ISO 27001 evidence may include:

  • Completed Asset Return Checklists
  • Asset Inventory
  • Asset Ownership Register
  • Device return receipts
  • Courier/delivery records
  • Asset condition records
  • Secure wipe/reimaging records
  • Disposal certificates
  • Access revocation records
  • IAM/SSO records
  • Cloud access removal records
  • SaaS offboarding records
  • VPN termination records
  • Security incident records
  • Employee acknowledgements
  • HR offboarding records
  • Exception approvals

Auditors may sample terminated employees and compare:

HR Exit Record → Asset Register → Return Evidence → Access Revocation → Device Wipe → Closure


31. Relationship with Other ISMS Documents

The Asset Return Checklist connects with:

  • Asset Management Procedure
  • Asset Ownership Register
  • Information & Asset Inventory
  • Asset Lifecycle Management Procedure
  • Access Control Policy
  • Employee IT Usage Policy
  • Remote Working Policy
  • BYOD Policy
  • Information Classification Policy
  • Data Inventory
  • Security Incident Management Procedure
  • Incident Response Plan
  • HR Onboarding/Offboarding Procedure
  • Supplier Security Management

The overall relationship is:

Exit/Transfer → Identify Assets → Return → Verify → Revoke Access → Secure Data → Update Inventory → Close


32. ISO 27001 Connection

Asset return supports the organization’s information security and asset-management processes, particularly controls addressing:

  • Asset inventory
  • Acceptable use
  • Return of organizational assets
  • Access rights
  • Information classification
  • Secure disposal
  • Offboarding
  • Remote working and endpoint security

The organization should determine the exact applicable controls through its risk assessment and Statement of Applicability.

The checklist itself is not sufficient evidence. The organization should be able to demonstrate that the process is actually followed through completed records, asset-register updates, access revocation, secure wiping, and disposal evidence.


33. Final Principle

The asset-return lifecycle should be:

Identify → Collect → Verify → Secure → Revoke → Wipe/Transfer/Dispose → Update → Evidence → Close

The key principle is:

When a person no longer needs an organizational asset or access, the organization must recover the asset, protect the information, remove the access, and retain evidence of completion.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *