1. Purpose
The purpose of this Asset Return Checklist is to ensure that organizational assets are identified, recovered, verified, and securely handled when an employee, contractor, consultant, or other authorized user:
- Leaves the organization
- Changes role
- Changes employment status
- No longer requires an asset
- Completes a project
- Returns from a long-term assignment
- Ends third-party access
The checklist helps prevent:
- Loss of organizational assets
- Unauthorized access
- Retention of confidential information
- Unauthorized use of company equipment
- Loss of customer information
- Retention of credentials or access tokens
- Incomplete offboarding
2. Scope
This checklist applies to assets issued, assigned, or made available to personnel, including:
Hardware
- Laptops
- Desktops
- Mobile phones
- Tablets
- Monitors
- Docking stations
- Headsets
- Security keys
- USB devices
- Network equipment
- Other company-owned equipment
Information and Media
- Documents
- Printed records
- USB drives
- Backup media
- Customer information
- Company information
- Confidential or Restricted information
Access-Related Assets
- Access cards
- Building keys
- Security tokens
- MFA devices
- Digital certificates
- Hardware authentication devices
Other Assets
- Software licenses
- Corporate SIM cards
- Company credit/payment cards where applicable
- Specialized equipment
- Project-specific assets
3. Asset Return Process
The recommended process is:
Exit / Role Change Identified
↓
Identify Assigned Assets
↓
Prepare Return List
↓
Collect Assets
↓
Verify Condition
↓
Check Information/Data
↓
Revoke Digital Access
↓
Securely Erase / Reconfigure
↓
Update Asset Register
↓
Confirm Return
↓
Close Offboarding
4. Employee / User Information
| Field | Details |
|---|---|
| Employee/User Name | |
| Employee ID | |
| Department | |
| Job Title | |
| Manager | |
| Employment Type | |
| Last Working Date | |
| Exit/Transfer Date | |
| Reason | Resignation / Termination / Transfer / Project End |
| Asset Coordinator | |
| IT Representative | |
| HR Representative | |
| Checklist Date |
5. Asset Return Register
| Asset ID | Asset Type | Description | Serial/Identifier | Assigned To | Condition | Returned Date | Verified By | Status |
|---|---|---|---|---|---|---|---|---|
| AST-001 | Laptop | Dell Laptop | XXXXX | Employee | Good | ☐ Returned | ||
| AST-002 | Mobile | Company Phone | XXXXX | Employee | Good | ☐ Returned | ||
| AST-003 | Security Key | MFA Key | XXXXX | Employee | Good | ☐ Returned | ||
| AST-004 | Monitor | 24″ Monitor | XXXXX | Employee | Good | ☐ Returned |
6. Hardware Return Checklist
Laptop/Desktop
- ☐ Device returned
- ☐ Asset ID verified
- ☐ Serial number verified
- ☐ Physical condition checked
- ☐ Charger returned
- ☐ Docking station returned where applicable
- ☐ Accessories returned
- ☐ Device recorded in Asset Inventory
- ☐ Device securely wiped/reconfigured before reassignment
Mobile Device
- ☐ Device returned
- ☐ SIM card returned where applicable
- ☐ Charger/accessories returned
- ☐ Device identifier verified
- ☐ Corporate account removed
- ☐ Device securely reset before reassignment
Other Equipment
- ☐ Monitor
- ☐ Keyboard
- ☐ Mouse
- ☐ Headset
- ☐ Webcam
- ☐ Security key
- ☐ USB/removable media
- ☐ Network equipment
- ☐ Other equipment
7. Information and Data Check
Before an asset is reassigned, disposed of, or transferred, the organization should determine whether it contains organizational information.
Check for:
- ☐ Customer information
- ☐ Employee information
- ☐ Confidential information
- ☐ Restricted information
- ☐ Source code
- ☐ Security information
- ☐ Local documents
- ☐ Downloaded files
- ☐ Browser-stored information
- ☐ Cached credentials
- ☐ Authentication tokens
- ☐ Encryption keys
- ☐ Certificates
- ☐ Backup files
Important:
Do not simply delete files manually and assume the device is clean.
The organization should use an approved secure wiping, reimaging, reset, or other appropriate process based on the asset and information sensitivity.
8. Corporate Accounts and Access
Asset return should be coordinated with access termination.
Verify:
- ☐ Corporate account disabled where applicable
- ☐ SSO access removed
- ☐ Email access removed
- ☐ VPN access removed
- ☐ SaaS access removed
- ☐ Cloud access removed
- ☐ Source-code repository access removed
- ☐ Customer-system access removed
- ☐ Privileged access removed
- ☐ MFA sessions/tokens revoked where appropriate
- ☐ API tokens revoked
- ☐ SSH keys revoked
- ☐ Certificates revoked where applicable
- ☐ Active sessions terminated
- ☐ Shared credentials changed where necessary
Access termination should be completed according to the organization’s offboarding and access-control procedures.
9. Cloud and AWS Access
For users with AWS or other cloud access:
- ☐ AWS IAM access reviewed
- ☐ SSO access removed
- ☐ IAM roles reviewed
- ☐ Privileged roles removed
- ☐ Access keys disabled/revoked
- ☐ Temporary credentials expired/revoked where applicable
- ☐ SSH keys reviewed
- ☐ Cloud console sessions terminated
- ☐ CI/CD credentials reviewed
- ☐ Secrets associated with the user reviewed
- ☐ Cloud access logs retained as required
Important
Returning a laptop does not automatically remove cloud access.
Both physical assets and digital access must be addressed.
10. Source Code and Development Assets
For developers or technical personnel:
- ☐ GitHub/GitLab/Bitbucket access removed
- ☐ Repository permissions reviewed
- ☐ SSH keys revoked
- ☐ Personal access tokens revoked
- ☐ Cloud credentials revoked
- ☐ CI/CD access removed
- ☐ Deployment permissions removed
- ☐ Secrets associated with the user reviewed
- ☐ Local source-code copies addressed
- ☐ Customer/production data removed according to procedure
11. Physical Access
Recover:
- ☐ Employee ID card
- ☐ Building access card
- ☐ Office keys
- ☐ Server-room access
- ☐ Security tokens
- ☐ Visitor/access credentials
- ☐ Parking access where applicable
- ☐ Other physical access devices
Verify:
- ☐ Physical access disabled
- ☐ Access card deactivated
- ☐ Keys returned
- ☐ Restricted-area access removed
12. Information Classification Check
Before an asset is reassigned or disposed of, determine whether it contains:
| Classification | Action |
|---|---|
| Public | Normal handling as appropriate |
| Internal | Secure organizational handling |
| Confidential | Secure transfer/wipe/storage |
| Restricted | Strictly controlled handling and secure disposal |
The higher the classification, the stronger the required protection should be.
13. BYOD and Personal Devices
If the employee used a personal device under the organization’s BYOD Policy:
- ☐ Corporate account access removed
- ☐ Corporate applications removed where required
- ☐ Corporate work profile removed
- ☐ Corporate certificates/tokens revoked
- ☐ Corporate data removed where technically supported
- ☐ Cloud sessions terminated
- ☐ Corporate VPN access removed
- ☐ Corporate credentials revoked
- ☐ Organizational information confirmed as removed where required
The organization should avoid accessing unrelated personal information on the user’s device.
14. Remote Worker Asset Return
For remote employees, assets may need to be returned through:
- Courier
- Authorized logistics provider
- Office return
- Local collection
- Other approved process
The organization should maintain evidence of:
- Shipment
- Delivery
- Asset identification
- Condition
- Receipt
- Verification
Example
Employee → Courier → IT Asset Receipt → Asset Verification → Secure Wipe → Asset Register Update
15. Asset Condition Assessment
Each returned physical asset should be checked for:
- ☐ Physical damage
- ☐ Missing accessories
- ☐ Broken components
- ☐ Signs of tampering
- ☐ Missing labels
- ☐ Functional condition
- ☐ Storage/media condition
- ☐ Battery condition where relevant
Condition should be recorded objectively.
Example:
Good: Normal operational condition.
Fair: Minor wear but usable.
Damaged: Physical damage requiring repair.
Unusable: Cannot reasonably be returned to service.
16. Lost or Missing Assets
If an assigned asset is not returned:
- Confirm the asset assignment.
- Contact the user.
- Determine whether the asset is lost, stolen, or otherwise unavailable.
- Report the matter to IT/Security.
- Revoke associated access where appropriate.
- Assess information exposure.
- Determine whether an information security incident occurred.
- Update the asset register.
- Document the investigation and resolution.
Example:
A company laptop is not returned because the employee reports that it was stolen during travel.
The organization should not treat this only as an inventory issue. It may also require a security incident assessment.
17. Lost Device Security Actions
For a lost or stolen device, consider:
- Account lock
- Session revocation
- Password reset
- MFA/session revocation
- Remote lock
- Remote wipe
- Certificate revocation
- VPN access removal
- Cloud access review
- Data exposure assessment
- Incident investigation
The specific actions depend on device capabilities and organizational risk.
18. Asset Transfer
If an asset is being transferred to another employee:
- ☐ Existing owner removed
- ☐ New owner identified
- ☐ Asset condition recorded
- ☐ Information securely removed
- ☐ Device reimaged/reset where required
- ☐ New user assigned
- ☐ New asset acknowledgement completed
- ☐ Asset Register updated
- ☐ Access configured separately for new user
Lifecycle
Return → Verify → Secure → Reassign → Record
19. Asset Disposal
If an asset is being retired:
- ☐ Asset identified for disposal
- ☐ Information classification assessed
- ☐ Data securely erased/destroyed
- ☐ Storage media handled appropriately
- ☐ Disposal method recorded
- ☐ Disposal vendor verified where applicable
- ☐ Certificate of destruction obtained where applicable
- ☐ Asset status changed to Retired/Disposed
- ☐ Asset Register updated
For sensitive information, normal file deletion may not be sufficient.
20. Software and Licenses
Where applicable:
- ☐ Software licenses recovered/reassigned
- ☐ User licenses removed
- ☐ SaaS seats reassigned
- ☐ Administrator privileges removed
- ☐ Developer tools access removed
- ☐ Security tools access removed
- ☐ Subscription ownership transferred where required
21. Third-Party Personnel
For contractors, consultants, suppliers, and temporary personnel:
- ☐ Company assets returned
- ☐ Customer assets returned where applicable
- ☐ Supplier-issued access removed
- ☐ VPN access removed
- ☐ SaaS access removed
- ☐ Cloud access removed
- ☐ Source-code access removed
- ☐ Confidential information returned/deleted as required
- ☐ Contractual return/destruction requirements verified
- ☐ Completion confirmed by responsible owner
Third-party offboarding should also consider contractual requirements.
22. Employee Acknowledgement
The employee/user should confirm:
I confirm that I have returned the organizational assets assigned to me, except those specifically identified in this checklist. I understand that organizational information and access credentials must not be retained or used after my authorization ends.
Employee/User
Name: __________________________
Signature: _______________________
Date: ____________________________
23. IT Verification
IT confirms that:
- ☐ Physical assets have been received.
- ☐ Asset identifiers have been verified.
- ☐ Device condition has been recorded.
- ☐ Corporate access has been removed.
- ☐ Required credentials/tokens have been revoked.
- ☐ Corporate information has been securely handled.
- ☐ Device has been wiped/reimaged where required.
- ☐ Asset records have been updated.
IT Representative:
Name: __________________________
Signature: _______________________
Date: ____________________________
24. Security Verification
Security confirms, where applicable:
- ☐ Privileged access removed
- ☐ Cloud access reviewed
- ☐ MFA sessions/tokens revoked
- ☐ API keys/access keys reviewed
- ☐ SSH keys reviewed
- ☐ Security systems access removed
- ☐ Incident assessment completed where required
- ☐ Sensitive information exposure assessed
- ☐ Required evidence retained
Security Representative:
Name: __________________________
Signature: _______________________
Date: ____________________________
25. HR / Management Verification
HR or the responsible manager confirms:
- ☐ Exit/transfer date confirmed
- ☐ Asset list reviewed
- ☐ Required assets returned
- ☐ Missing assets escalated
- ☐ Access termination coordinated
- ☐ Final checklist completed
Representative:
Name: __________________________
Signature: _______________________
Date: ____________________________
26. Final Asset Return Status
| Item | Status |
|---|---|
| All physical assets returned | ☐ |
| Missing assets investigated | ☐ |
| Organizational information secured | ☐ |
| Corporate accounts disabled | ☐ |
| Privileged access removed | ☐ |
| Cloud access removed | ☐ |
| Source-code access removed | ☐ |
| Physical access removed | ☐ |
| BYOD access removed where applicable | ☐ |
| Devices wiped/reimaged where required | ☐ |
| Asset Register updated | ☐ |
| Security incident assessment completed if required | ☐ |
| Exceptions documented | ☐ |
| Offboarding completed | ☐ |
27. Asset Return Record
| Field | Details |
|---|---|
| Asset Return ID | |
| User | |
| Exit/Transfer Date | |
| Assets Assigned | |
| Assets Returned | |
| Missing Assets | |
| Asset Condition | |
| Data/Wipe Status | |
| Access Revocation Status | |
| Security Review | |
| Exceptions | |
| Final Status | Completed / Pending / Escalated |
| Verified By | |
| Verification Date |
28. Common Mistakes
Mistake 1: Only Collecting the Laptop
A user may also have:
- Mobile device
- Security key
- Access card
- USB device
- Company SIM
- Physical documents
All assigned assets should be checked.
Mistake 2: Returning the Device but Leaving Access Active
Asset return and access termination are separate activities.
Mistake 3: Forgetting Cloud Access
AWS, Azure, SaaS, Git repositories, VPN, and other digital access must be reviewed.
Mistake 4: Ignoring Local Data
A returned laptop may contain customer information, source code, credentials, or other sensitive information.
Mistake 5: No Evidence
The organization should retain evidence showing what was returned, when, by whom, and how it was processed.
Mistake 6: Treating Lost Devices as Only an HR Issue
A lost device may represent a security incident and should be assessed accordingly.
29. Startup-Friendly Process
A small organization can use a simple centralized checklist.
HR
Exit Identified
↓
Manager
Confirm Assigned Assets
↓
IT
Collect Assets + Disable Access
↓
Security
Review Sensitive/Privileged Access
↓
IT
Secure/Wipe Device
↓
Asset Owner
Update Asset Register
↓
HR
Close Offboarding
The process can be managed through an existing HR, ticketing, or IT service-management system rather than creating a separate complex platform.
30. Audit Evidence
Useful ISO 27001 evidence may include:
- Completed Asset Return Checklists
- Asset Inventory
- Asset Ownership Register
- Device return receipts
- Courier/delivery records
- Asset condition records
- Secure wipe/reimaging records
- Disposal certificates
- Access revocation records
- IAM/SSO records
- Cloud access removal records
- SaaS offboarding records
- VPN termination records
- Security incident records
- Employee acknowledgements
- HR offboarding records
- Exception approvals
Auditors may sample terminated employees and compare:
HR Exit Record → Asset Register → Return Evidence → Access Revocation → Device Wipe → Closure
31. Relationship with Other ISMS Documents
The Asset Return Checklist connects with:
- Asset Management Procedure
- Asset Ownership Register
- Information & Asset Inventory
- Asset Lifecycle Management Procedure
- Access Control Policy
- Employee IT Usage Policy
- Remote Working Policy
- BYOD Policy
- Information Classification Policy
- Data Inventory
- Security Incident Management Procedure
- Incident Response Plan
- HR Onboarding/Offboarding Procedure
- Supplier Security Management
The overall relationship is:
Exit/Transfer → Identify Assets → Return → Verify → Revoke Access → Secure Data → Update Inventory → Close
32. ISO 27001 Connection
Asset return supports the organization’s information security and asset-management processes, particularly controls addressing:
- Asset inventory
- Acceptable use
- Return of organizational assets
- Access rights
- Information classification
- Secure disposal
- Offboarding
- Remote working and endpoint security
The organization should determine the exact applicable controls through its risk assessment and Statement of Applicability.
The checklist itself is not sufficient evidence. The organization should be able to demonstrate that the process is actually followed through completed records, asset-register updates, access revocation, secure wiping, and disposal evidence.
33. Final Principle
The asset-return lifecycle should be:
Identify → Collect → Verify → Secure → Revoke → Wipe/Transfer/Dispose → Update → Evidence → Close
The key principle is:
When a person no longer needs an organizational asset or access, the organization must recover the asset, protect the information, remove the access, and retain evidence of completion.
