What is ISO 27001 Annex A 5.11 – Return of Assets?
ISO 27001 Annex A 5.11 focuses on ensuring that employees, contractors, and other relevant parties return organizational assets when their employment, contract, or access to the organization ends or changes.
The purpose is to make sure that organizational assets are recovered and that the organization does not lose control over:
- Laptops
- Mobile phones
- Access cards
- Security tokens
- Storage devices
- Documents
- Company information
- Keys
- Equipment
- Software or licensed resources
- Other assets provided for business purposes
Simple explanation
A.5.11 means when someone leaves the organization, changes roles, or no longer needs an organizational asset, the organization should ensure that the relevant assets are returned and accounted for.
The control is not limited to employees.
It may also apply to:
- Contractors
- Consultants
- Temporary workers
- Interns
- Vendors
- Third-party personnel
Why is A.5.11 important?
When an employee or contractor leaves, the organization may lose control over assets if there is no proper return process.
For example, a departing employee may still have:
- Company laptop
- Mobile phone
- Access card
- USB drive
- Company documents
- Printed confidential information
- Security token
- Backup device
If these assets are not returned or appropriately handled, they may create security risks.
Potential risks include:
- Unauthorized access
- Information leakage
- Loss of confidential information
- Theft of company equipment
- Exposure of customer data
- Loss of intellectual property
- Continued use of company resources
Simple principle
When access ends, control over organizational assets should also be recovered.
What does A.5.11 require?
The organization should establish a process to ensure that organizational assets are returned when:
- Employment ends
- A contract ends
- A contractor leaves
- An employee changes roles
- An employee transfers departments
- An asset is replaced
- An asset is no longer required
- Access or responsibility is transferred
The organization should also determine what happens when an asset cannot be returned.
For example:
- Lost
- Stolen
- Damaged
- Destroyed
- Permanently retained under an approved arrangement
The organization should document the appropriate action.
What counts as an organizational asset?
Assets can include both physical and information assets.
Physical assets
Examples:
- Laptops
- Desktop computers
- Mobile phones
- Tablets
- Monitors
- Access cards
- Security tokens
- USB drives
- External hard drives
- Keys
- Company vehicles
- Office equipment
Information assets
Examples:
- Printed documents
- Customer records
- Contracts
- Business documents
- Source code
- Product information
- Confidential reports
- Project documentation
Digital assets
Depending on the organization’s environment:
- Cloud credentials
- Security certificates
- API keys
- Authentication tokens
- Cryptographic keys
- Software licenses
- Digital repositories
- Administrative accounts
The return or recovery process should be appropriate to the type of asset.
Activities required to implement A.5.11
1. Maintain an asset assignment record
The organization should know which assets have been assigned to which users.
For example:
| Employee | Asset | Asset ID | Date Issued | Status |
|---|---|---|---|---|
| Employee A | Laptop | LAP-102 | 01-Jan-2026 | Assigned |
| Employee A | Mobile | MOB-044 | 01-Jan-2026 | Assigned |
| Employee B | Laptop | LAP-103 | 15-Feb-2026 | Assigned |
| Employee C | Security Token | TOK-019 | 10-Mar-2026 | Assigned |
This makes the return process much easier.
2. Include asset return in the offboarding process
Asset return should be part of the employee or contractor offboarding checklist.
A simple process could be:
Termination / Contract End
↓
Identify Assigned Assets
↓
Notify Employee / Contractor
↓
Collect Assets
↓
Verify Condition
↓
Confirm Information Handling
↓
Disable Access
↓
Update Asset Register
↓
Complete Offboarding
This should be coordinated with HR, IT and relevant management.
3. Define responsibilities
Clearly assign responsibility for asset recovery.
For example:
| Activity | Responsibility |
|---|---|
| Initiate offboarding | HR / Management |
| Identify assigned assets | IT |
| Collect laptop/device | IT |
| Collect access cards | Facilities |
| Recover documents | Department Owner |
| Disable accounts | IT / Security |
| Update asset register | IT |
| Confirm completion | HR / IT |
For a small startup, one person may perform several roles.
4. Recover physical devices
When an employee leaves, the organization should recover applicable devices.
Examples:
- Laptop
- Mobile phone
- Tablet
- USB drive
- Security token
- Access card
The organization should record whether the asset was:
- Returned
- Lost
- Stolen
- Damaged
- Reassigned
- Disposed
5. Address information stored on returned devices
Returning a laptop is not necessarily the end of the process.
The organization should consider information stored on the device.
Depending on the organization’s requirements, IT may:
- Back up required business information
- Verify synchronization
- Remove organizational accounts
- Revoke access
- Securely erase the device
- Reimage the device
- Reassign the device
The approach should depend on the organization’s asset-management and data-protection requirements.
6. Recover or revoke digital assets
Some assets cannot simply be physically returned.
For example:
- API keys
- Passwords
- Access tokens
- Certificates
- Encryption keys
- Shared secrets
Where appropriate, the organization should:
- Revoke credentials
- Rotate secrets
- Disable accounts
- Transfer ownership
- Revoke tokens
- Replace certificates
- Recover administrative access
This is particularly important when an employee had privileged access.
7. Handle remote workers
Remote employees may have organizational assets at home.
The organization should define how assets are returned.
Options may include:
- Courier collection
- Company pickup
- Office return
- Approved shipping process
The organization should maintain evidence that the asset was received.
8. Handle contractors and third parties
The return process should also cover relevant external parties.
For example:
A contractor may have:
- Company laptop
- Customer documents
- Access card
- Security token
- Project documentation
When the contract ends, the organization should confirm that relevant assets are returned and access is appropriately terminated.
9. Handle role changes
A.5.11 is not limited to people leaving the organization.
An employee may move from:
Engineering → Marketing
The employee may no longer require:
- Production access
- Development laptop
- Security credentials
- Administrative tokens
- Engineering documentation
The organization should review assigned assets and recover or reassign those no longer required.
10. Deal with lost or stolen assets
Sometimes an asset cannot be returned.
For example:
Employee reports that company laptop was stolen.
The organization should have a process for:
- Reporting the incident
- Locking or wiping the device where possible
- Revoking access
- Investigating potential data exposure
- Updating the asset register
- Recording the incident
This may also trigger the organization’s incident-management process.
Startup Example
Consider a SaaS startup with 50 employees.
An employee resigns.
The employee has:
- Company laptop
- Mobile phone
- Access card
- Security token
The HR team initiates offboarding.
Step 1
HR informs IT of the last working day.
↓
Step 2
IT checks the asset register.
Laptop → Assigned
Mobile → Assigned
Security Token → Assigned
↓
Step 3
IT arranges collection.
↓
Step 4
Assets are physically received.
↓
Step 5
IT checks the laptop and secures organizational information.
↓
Step 6
Accounts and tokens are disabled or revoked as applicable.
↓
Step 7
Asset register is updated.
Laptop → Returned
Mobile → Returned
Token → Returned
↓
Step 8
HR/IT records completion of offboarding.
This provides evidence that organizational assets were recovered.
Example Asset Return Checklist
| Asset / Activity | Returned / Completed | Remarks |
|---|---|---|
| Laptop | Yes/No | |
| Mobile phone | Yes/No | |
| Tablet | Yes/No | |
| Access card | Yes/No | |
| Security token | Yes/No | |
| USB / storage device | Yes/No | |
| Physical documents | Yes/No | |
| Company keys | Yes/No | |
| Business information recovered | Yes/No | |
| Accounts disabled | Yes/No | |
| Access tokens revoked | Yes/No | |
| API keys rotated where required | Yes/No/N/A | |
| Asset register updated | Yes/No | |
| Offboarding completed | Yes/No |
Example Asset Return Register
| Employee | Asset | Asset ID | Exit Date | Return Date | Condition | Status |
|---|---|---|---|---|---|---|
| Employee A | Laptop | LAP-102 | 20-Sep-2026 | 20-Sep-2026 | Good | Returned |
| Employee A | Mobile | MOB-044 | 20-Sep-2026 | 20-Sep-2026 | Good | Returned |
| Employee A | Access Card | AC-018 | 20-Sep-2026 | 20-Sep-2026 | Good | Returned |
| Employee B | Laptop | LAP-107 | 25-Sep-2026 | 26-Sep-2026 | Good | Returned |
What if an asset cannot be returned?
The organization should have a defined process.
Lost
Report → Investigate → Disable/Revoke → Assess Risk → Update Register
Stolen
Report → Incident Process → Secure Accounts → Assess Data Exposure → Update Register
Damaged
Assess → Repair/Replace → Update Asset Status
Permanently retained
If an employee is formally authorized to retain an asset, the organization should document the approval and ownership arrangement.
A.5.11 Audit Evidence
An auditor may look for evidence such as:
Asset assignment
- Asset register
- Laptop allocation records
- Device assignment records
- Security token records
Offboarding
- Employee offboarding checklist
- Contractor offboarding checklist
- HR/IT notifications
- Exit clearance
Return evidence
- Asset return forms
- Courier records
- IT acknowledgment
- Asset register updates
Digital asset recovery
- Account deactivation
- Token revocation
- Credential rotation
- Ownership transfer
Exception handling
- Lost asset reports
- Theft reports
- Incident records
- Risk assessments
A.5.11 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Does the organization maintain records of assigned assets? | Asset Register |
| Is asset return included in offboarding? | Offboarding Checklist |
| Are laptops and other devices recovered? | Return Records |
| Are access cards and security tokens recovered? | Return Records |
| Are contractors included? | Contractor Offboarding |
| Are role changes considered? | Access/Asset Review |
| Are digital credentials and tokens appropriately revoked? | Access Records |
| Are lost or stolen assets handled through an appropriate process? | Incident Records |
| Is the asset register updated after return? | Updated Register |
| Is completion of asset return documented? | Exit Clearance |
Common Mistakes
1. Only recovering laptops
Organizations sometimes focus on physical devices and forget:
- Access cards
- Security tokens
- USB drives
- Documents
- Credentials
- API keys
- Digital access
2. Relying entirely on HR
HR may know that an employee is leaving, but may not know which technical assets the employee has.
HR, IT, Security and relevant business owners should coordinate.
3. No asset assignment records
If the organization does not know who has which laptop or device, recovering assets becomes difficult.
4. Ignoring contractors
Contractors and consultants may have access to highly sensitive information and systems.
Their assets should be included where applicable.
5. Forgetting role changes
Asset return can also be relevant when someone changes responsibilities.
An employee should not retain assets or access simply because they had them in their previous role.
6. Treating digital assets like physical assets
You cannot physically “return” an API key or password.
These assets may need to be:
Revoked → Rotated → Reissued
Practical Startup Implementation Model
A startup can implement A.5.11 with a simple process:
Employee / Contractor Exit or Role Change
↓
Check Asset Register
↓
Identify Assigned Assets
↓
Collect / Recover Assets
↓
Secure Organizational Information
↓
Disable / Revoke Digital Access
↓
Update Asset Register
↓
Record Completion
↓
Close Offboarding
Policy vs. Process vs. Evidence
| Element | Example |
|---|---|
| Policy | Organizational assets assigned to employees, contractors and other users shall be returned when no longer required or when employment or contractual relationships end. |
| Process | HR initiates offboarding, IT identifies assigned assets, assets are recovered, digital access is revoked and the asset register is updated. |
| Evidence | Asset register, offboarding checklist, asset return acknowledgment, access-revocation records and exception records. |
The objective is not simply to collect company laptops.
The objective is to ensure that the organization maintains control of its physical, information and digital assets throughout the employee or contractor lifecycle.
Useful Resources
Recommended documents
- Asset Return Checklist – [Insert Draft Document Link]
- Employee Offboarding Checklist – [Insert Draft Document Link]
- Contractor Offboarding Checklist – [Insert Draft Document Link]
- Asset Register – [Insert Draft Document Link]
- IT Asset Handover Form – [Insert Draft Document Link]
- Access Revocation Checklist – [Insert Draft Document Link]
- Lost/Stolen Asset Incident Form – [Insert Draft Document Link]
Related ISO 27001 controls
A.5.11 can work closely with:
- A.5.9 – Inventory of information and other associated assets
- A.5.10 – Acceptable use of information and other associated assets
- A.5.12 – Classification of information
- A.5.15 – Access control
- A.5.16 – Identity management
- A.5.17 – Authentication information
- A.6.5 – Responsibilities after termination or change of employment
- A.7.7 – Clear desk and clear screen
- A.7.9 – Security of assets off-premises
- A.8.1 – User endpoint devices
Final Takeaway
ISO 27001 Annex A 5.11 is about ensuring that organizational assets are returned or otherwise appropriately recovered when employees, contractors or other authorized users no longer need them.
A practical organization should be able to answer:
What assets were assigned to the person?
Were those assets returned?
What happened to organizational information stored on them?
Were digital credentials and tokens revoked where necessary?
Was the asset register updated?
Is there evidence that the process was completed?
For startups, the approach can remain simple:
Identify → Collect → Secure → Revoke → Update → Record
The goal is to ensure that when someone’s role or relationship with the organization ends, the organization’s assets and information do not leave with them.
