ISO 27001 Annex A 5.11 Return of assets requires personnel and external parties to return all organisational assets upon changing roles or ending employment. Documented handover rules prevent data leaks, track hardware, and protect confidential business property.
Table of contents
Key Takeaways
- Recover all organisational assets: Collect company laptops, portable drives, identity badges, keys, and documents when contracts or roles end.
- Store rules centrally: Keep offboarding policies, handover forms, and asset logs in a central document repository to prove accountability.
- Define clear exit procedures: Establish formal offboarding checklists that require management sign-off before a worker departs.
- Include contractors and third parties: Ensure external vendors, consultants, and temporary workers return all issued items upon contract completion.
- Delete personal device data: Wipe company files and revoke corporate access profiles from personal devices used for business tasks.
- Transfer operational knowledge: Hand over critical documents, system access credentials, and project files to remaining staff before departure.
- Track asset inventories: Reconcile returned hardware against the central asset inventory to identify missing equipment quickly.
- Revoke physical and digital access: Cancel system accounts, security keys, and building access passes alongside the physical asset return.

How to Implement ISO 27001 Annex A 5.11
- Draft an asset return policy: Write clear guidelines for returning equipment upon role change or termination and store them centrally.
- Build a leaver asset checklist: Create a standard form listing all hardware, software licences, tokens, and physical access cards issued to staff.
- Enforce return agreements in contracts: Include binding terms in employment and supplier agreements stating all property must be returned upon exit.
- Manage remote worker returns: Provide secure courier collections or prepaid tracked return boxes for home-based and remote staff.
- Sanitise returned hardware: Wipe and re-image returned computers fully before reissuing them to new workers.
- Wipe company data on personal devices: Ensure departing workers delete corporate emails, cached documents, and backups from personal equipment.
- Collect specialised physical items: Recover physical keys, parking passes, office badges, and sensitive printed papers during final exit meetings.
- Update central inventory registers: Mark returned equipment as in stock, reassigned, or retired in the asset management database.
- Coordinate with human resources: Link final payroll clearance or contract sign-off to the completion of the asset return checklist.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.11
- Review return of asset policies: Inspect written procedures to verify clear rules govern asset recovery during employment termination and internal transfers.
- Sample departed employee records: Check recent leaver files to confirm signed asset handover forms match originally assigned inventory items.
- Verify return timing: Compare employment termination dates with asset check-in timestamps to ensure items were returned on time.
- Audit contractor exit files: Sample closed supplier contracts to verify external workers returned all security tokens, badges, and company equipment.
- Inspect personal device wipe logs: Check records to confirm staff removed corporate applications and data from personal phones and laptops.
- Reconcile inventory updates: Cross-check returned asset forms against the central hardware inventory to ensure asset statuses were updated.
- Check unreturned asset incident logs: Review incident reports to confirm teams logged security investigations for lost or unreturned devices.
- Inspect physical storage for returns: Verify that returned laptops and media stay locked in secure rooms or safes prior to sanitisation.
Audit Evidence Checklist
- Asset return policy: Maintain a documented return of assets policy with a complete version history in your central repository.
- Signed offboarding checklists: Provide completed and signed asset handover forms for staff and contractors who left during the period.
- Asset tracking register: Supply an up-to-date inventory showing updated custody statuses for all returned and reassigned equipment.
- Courier delivery receipts: Maintain tracking receipts and signed delivery proofs for assets returned by remote employees.
- Device sanitisation logs: Supply technical wipe records proving returned storage media was cleared before reassignment or disposal.
- Employment contract templates: Provide standard contract templates showing clauses requiring the return of company property upon exit.
- Missing asset incident tickets: Provide security incident logs and management escalation records for unrecovered assets.
What to Teach Employees
- Return all company property: Teach staff that all laptops, phones, badges, keys, and paperwork remain company property and must be returned.
- Hand over files before leaving: Instruct departing workers to transfer project files, access links, and technical notes to team leads.
- Delete company files from home devices: Remind staff to delete saved work files, emails, and corporate backups from personal computers upon exit.
- Use secure return shipping: Instruct remote workers to use provided tracked shipping packaging when posting equipment back to the office.
- Do not keep access passes: Warn employees that retaining building passes, parking fobs, or physical keys after leaving is strictly prohibited.
- Report missing gear immediately: Ensure workers know to inform management fast if issued equipment is lost, broken, or stolen before exit.
Common Implementation Challenges
- Unreturned remote equipment: Remote workers fail to post laptops back after leaving. Use prepaid tracked courier pick-ups to make returns easy.
- Incomplete asset logs: Handed-over peripherals and spare tokens go unrecorded. Maintain a complete inventory log for every worker from day one.
- Overlooking paper and notes: Staff return computers but keep sensitive printed customer files. Include paper documents in the return checklist.
- Residual data on personal devices: Workers retain corporate files on personal phones. Enforce automated corporate profile removal during offboarding.
- Neglecting internal movers: Staff change departments and keep specialised hardware from old roles. Require asset reviews during role changes.
- Informal contractor offboarding: Temporary staff leave without returning badges or keys. Route all contractor exits through formal checklists.
How to Measure Effectiveness (KPIs)
- Asset return rate: Track the percentage of issued hardware and access tokens successfully recovered from departing workers.
- On-time return compliance: Measure the proportion of assets returned on or before the official employee termination date.
- Unreturned asset incident rate: Track the total number of missing or unrecovered devices reported to the security team each year.
- Inventory reconciliation accuracy: Measure the percentage of returned assets correctly updated in the central asset register within two days.
- Contractor asset return rate: Track the percentage of third-party contractors who complete full asset handovers upon contract end.
