ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. IT Asset Handover Form

IT Asset Handover Form

IT Asset Handover Form

1. Purpose

The IT Asset Handover Form records the formal transfer of an organizational IT asset from one person or custodian to another.

It provides evidence of:

  • Who had custody of the asset
  • Who received the asset
  • What asset was transferred
  • Asset condition at handover
  • Information/security requirements
  • Accessories transferred
  • Required security configuration
  • Acceptance by the recipient
  • Updates to the Asset Inventory and Ownership Register

Key principle:

Identify → Verify → Transfer → Accept → Update → Evidence


2. When to Use This Form

Use this form when:

  • A new employee receives an IT asset
  • An employee changes department or role
  • An asset is transferred between employees
  • A contractor receives an organizational device
  • An employee leaves and the asset is assigned to another person
  • A laptop/device is reassigned
  • IT transfers equipment to another office/location
  • A device is temporarily issued to another user
  • A project team receives shared equipment
  • Custody of an asset changes

This form should be used together with the Asset Return Checklist when an asset is returned before being reassigned.


3. Handover Information

FieldDetails
Handover Form ID
Handover Date
Handover TypeIssue / Transfer / Reassignment / Temporary Handover
Department
Location
Business Unit
Previous Custodian
New Custodian
Asset Owner
IT Representative
Reason for Handover
Effective Date
Expected Return Date, if Temporary

4. Previous Custodian Details

FieldDetails
Name
Employee/Contractor ID
Department
Job Title
Email
Manager
Signature
Date

If the asset is being reassigned after an employee exit, the previous custodian may be recorded as Former Employee / Contractor, with the offboarding record referenced.


5. New Custodian Details

FieldDetails
Name
Employee/Contractor ID
Department
Job Title
Email
Manager
Location
Signature
Date

6. IT Asset Details

FieldDetails
Asset ID
Asset TypeLaptop / Desktop / Mobile / Tablet / Server / Network / Other
Asset Name
Manufacturer
Model
Serial Number
Service Tag
Hostname
Operating System
Purchase Date
Warranty Expiry
Current Location
Asset Owner
Technical Custodian
Information Classification
CriticalityLow / Medium / High / Critical
Asset StatusActive / Temporary / Spare / Other

7. Asset Condition

Assess the physical and operational condition at the time of handover.

ConditionSelect
New☐
Good☐
Used – Good Condition☐
Used – Minor Wear☐
Damaged☐
Requires Repair☐

Condition Details




If damage exists, attach photographs or an IT service record where appropriate.


8. Accessories and Additional Items

ItemProvidedConditionRemarks
Laptop Charger☐
Power Adapter☐
Docking Station☐
Monitor☐
Keyboard☐
Mouse☐
Headset☐
Carrying Bag☐
Security Cable☐
Mobile Charger☐
SIM Card☐
Security Key☐
Other☐

9. Security Configuration Verification

Before handing over an IT asset, IT should verify the applicable security controls.

Security RequirementVerifiedEvidence / Remarks
Supported operating system☐
Security patches applied☐
Endpoint protection installed☐
Firewall enabled☐
Disk encryption enabled☐
Screen lock configured☐
Strong authentication configured☐
MFA enabled where applicable☐
Corporate account configured☐
Unauthorized local accounts removed☐
Administrative privileges reviewed☐
Device enrolled in management platform☐
Secure configuration applied☐
Asset hostname recorded☐
Asset inventory updated☐

Not every control will apply to every type of asset.


10. User Account and Access

The recipient’s access should be provisioned separately through the organization’s approved access-management process.

AccessStatus
Corporate identity account☐
Email☐
SSO☐
VPN☐
Approved SaaS applications☐
File storage☐
Development systems☐
Cloud systems☐
Administrative access☐

Important: Asset handover does not automatically authorize system access. Access should be granted based on the organization’s Access Control Policy and approved business requirements.


11. Information and Data

Before transfer, IT should determine whether the asset contains organizational information.

Information Review

  • ☐ No organizational information stored
  • ☐ Corporate information retained as required
  • ☐ Previous user’s data transferred appropriately
  • ☐ Previous user’s personal information handled appropriately
  • ☐ Customer information reviewed
  • ☐ Confidential information protected
  • ☐ Restricted information protected
  • ☐ Unauthorized information removed
  • ☐ Device securely wiped/reconfigured where required

Data Transfer

If information is transferred:

InformationFromToApproved ByDate

12. Asset Reassignment After Employee Exit

If the asset belonged to a departing employee:

  1. ☐ Asset returned
  2. ☐ Asset condition checked
  3. ☐ Previous user’s data reviewed
  4. ☐ Device securely wiped/reconfigured where required
  5. ☐ Previous user account removed
  6. ☐ Previous user’s access revoked
  7. ☐ Device patched
  8. ☐ Security configuration verified
  9. ☐ New user account configured
  10. ☐ Asset assigned to new custodian
  11. ☐ Asset Inventory updated
  12. ☐ Handover form completed

Important: Do not simply give the previous employee’s configured laptop to another employee without completing the required security and data-handling steps.


13. Temporary Asset Handover

For temporary assignments:

FieldDetails
Reason for Temporary Assignment
Start Date
Expected Return Date
Temporary Custodian
Asset Owner
Approved By
Return Conditions

The temporary custodian must:

  • ☐ Protect the asset
  • ☐ Protect organizational information
  • ☐ Not share the device/account with unauthorized users
  • ☐ Report loss or theft immediately
  • ☐ Follow Acceptable Use and IT Usage requirements
  • ☐ Return the asset by the agreed date

14. Remote / Home Handover

If the asset is delivered remotely:

  • ☐ Recipient identity verified
  • ☐ Delivery address/process verified
  • ☐ Asset serial number recorded
  • ☐ Courier/delivery record retained
  • ☐ Packaging condition checked where applicable
  • ☐ Recipient confirmed receipt
  • ☐ Initial security configuration completed
  • ☐ Device enrollment verified
  • ☐ Security controls confirmed after first connection

15. Cloud and Security Assets

For specialized IT assets, additional information may be required.

Examples:

  • Cloud administration devices
  • Security monitoring devices
  • Network equipment
  • Authentication devices
  • Hardware security keys
  • VPN devices
  • Backup devices
  • Infrastructure administration equipment

Verify where applicable:

  • ☐ Ownership recorded
  • ☐ Custodian recorded
  • ☐ Administrative access controlled
  • ☐ Credentials not shared
  • ☐ MFA configured
  • ☐ Configuration backed up where required
  • ☐ Logging enabled where applicable
  • ☐ Security monitoring enabled
  • ☐ Related cloud/system access approved

16. Asset Ownership and Custody

The following distinctions should be maintained:

Asset Owner

The person responsible for the business/security requirements of the asset.

Technical Custodian

The person responsible for operating or maintaining the asset.

User / Custodian

The person who physically uses or holds the asset.

A user receiving a laptop does not necessarily become its business owner.


17. Asset Register Update

After the handover, update the Asset Inventory.

FieldPrevious ValueNew Value
Custodian
Department
Location
Asset Status
Owner
Classification
Criticality
Assigned Date
Review Date

Asset Inventory Updated By: __________________

Date: __________________


18. Recipient Acknowledgement

I confirm that:

  • I have received the asset identified in this form.
  • I have verified the asset and accessories listed above.
  • I will use the asset only for authorized business purposes.
  • I will protect organizational information stored or accessed through the asset.
  • I will not share the asset or associated credentials with unauthorized persons.
  • I will follow the organization’s security, acceptable-use, remote-working, and information-classification requirements.
  • I will report loss, theft, damage, suspected compromise, or security incidents promptly.
  • I will return the asset when requested or when my employment/engagement ends.

Recipient

Name: ______________________________

Signature: ___________________________

Date: _______________________________


19. Previous Custodian Acknowledgement

I confirm that the asset has been transferred to the new custodian and that any required business information or responsibilities have been appropriately handed over.

Name: ______________________________

Signature: ___________________________

Date: _______________________________


20. IT Verification

IT confirms that:

  • ☐ Asset identity verified
  • ☐ Serial number verified
  • ☐ Condition verified
  • ☐ Accessories verified
  • ☐ Security configuration verified
  • ☐ Previous user access removed where applicable
  • ☐ Device configured for new user where applicable
  • ☐ Asset Inventory updated
  • ☐ Ownership/custody updated
  • ☐ Relevant evidence retained

IT Representative: __________________________

Signature: __________________________________

Date: ______________________________________


21. Manager / Asset Owner Approval

I confirm that the asset assignment/transfer is authorized and that the new custodian has a legitimate business requirement for the asset.

Name: ______________________________

Role: _______________________________

Signature: ___________________________

Date: _______________________________


22. Exceptions

Any deviation from the standard handover process should be recorded.

Exception IDRequirementReasonRiskCompensating ControlOwnerDue DateStatus

23. Evidence to Retain

Depending on the asset and process, retain:

  • Completed IT Asset Handover Form
  • Asset Inventory record
  • Ownership Register update
  • Device configuration record
  • Device enrollment record
  • Asset photographs
  • Delivery/courier record
  • Data transfer record
  • Device wipe/reimage evidence
  • Access approval
  • Security configuration evidence
  • Previous custodian acknowledgement
  • New custodian acknowledgement
  • Manager approval
  • Exception record

24. Quick IT Handover Checklist

Before Handover

  • ☐ Asset identified
  • ☐ Asset ID/serial number verified
  • ☐ Owner identified
  • ☐ New custodian identified
  • ☐ Asset condition checked
  • ☐ Previous data reviewed
  • ☐ Device wiped/reconfigured where required
  • ☐ Security configuration completed
  • ☐ Required access approved

During Handover

  • ☐ Asset transferred
  • ☐ Accessories transferred
  • ☐ Recipient identity verified
  • ☐ Recipient acknowledges responsibility
  • ☐ Handover date recorded

After Handover

  • ☐ Asset Inventory updated
  • ☐ Ownership/custody updated
  • ☐ Access provisioning completed
  • ☐ Security controls verified
  • ☐ Evidence retained
  • ☐ Handover closed

25. Relationship With Other ISMS Documents

The IT Asset Handover Form should work together with:

  • Information & Asset Inventory
  • Asset Ownership Register
  • Asset Lifecycle Management Procedure
  • Asset Return Checklist
  • Employee Offboarding Checklist
  • Contractor Offboarding Checklist
  • Access Control Policy
  • Employee IT Usage Policy
  • Acceptable Use Policy
  • Information Classification Policy
  • Remote Working Policy
  • BYOD Policy
  • Data Inventory
  • Cloud Asset Inventory
  • Security Incident Management Procedure

The overall lifecycle is:

Acquire → Assign → Handover → Use → Maintain → Transfer → Review → Return/Retire


26. ISO 27001 Connection

The IT Asset Handover Form provides evidence supporting asset-management and information-security processes, including controls related to:

  • Inventory of information and associated assets
  • Ownership of assets
  • Acceptable use
  • Return of organizational assets
  • Information classification and handling
  • Access control
  • Secure configuration and endpoint protection
  • Asset lifecycle management

The exact applicable controls should be determined through the organization’s risk assessment and Statement of Applicability (SoA).


27. Final Audit Trail

An auditor should be able to select an asset and trace:

Asset Inventory
↓
Asset Owner
↓
Previous Custodian
↓
Handover Form
↓
Security Configuration
↓
New Custodian
↓
Access Authorization
↓
Updated Asset Register
↓
Evidence

Final Principle

Identify → Verify → Secure → Transfer → Accept → Update → Evidence → Review

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *