ISO 27001 Annex A 5.16 Identity management controls how organisations manage digital identities for users and devices throughout their full lifecycle. Documented rules ensure every person has a unique, verified account, preventing unauthorized access to sensitive company data.
Table of contents
Key Takeaways
- Manage identity lifecycles: Create clear rules to create, verify, update, disable, and delete all user and device identities.
- Store rules centrally: Keep identity management policies, onboarding workflows, and approval records in a central document repository.
- Enforce unique identifiers: Assign a distinct, individual identity to every employee, contractor, and machine to maintain accountability.
- Verify identity before access: Authenticate real-world personal identities during onboarding before issuing digital credentials or accounts.
- Prohibit shared accounts: Ban generic or shared team logins so system activity links directly to named individuals.
- Update identities during transfers: Modify identity records and team associations immediately whenever staff change roles internally.
- Disable leavers promptly: Deactivate or delete user identities on or before the employee or contractor leaves the company.
- Maintain central identity registers: Track all active, suspended, and retired identities across all business platforms in an authoritative directory.
How to Implement ISO 27001 Annex A 5.16
- Draft an identity policy: Write clear guidelines for managing identities and store them in your central document repository.
- Establish an authoritative source: Connect identity lifecycle workflows directly to your primary human resources record system.
- Standardise onboarding verification: Check official government identification documents before provisioning new user accounts.
- Assign unique user identifiers: Ensure system usernames map directly to a single named person rather than shared groups.
- Automate account provisioning: Use structured role templates to create standard accounts automatically upon HR approval.
- Manage non-human identities: Create a dedicated register for service accounts, scheduled jobs, and machine identities with named owners.
- Handle contractor identities: Set mandatory expiration dates on temporary accounts to ensure contractor access closes automatically.
- Deactivate departed users: Run automated deprovisioning routines to lock accounts immediately when workers depart.
- Run periodic identity audits: Reconcile active system accounts against payroll lists every quarter to eliminate orphaned logins.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.16
- Review identity policies: Inspect written procedures to verify complete processes exist for identity verification, creation, and retirement.
- Sample new user records: Check recent starter files to verify identity verification proof exists before account creation dates.
- Verify account uniqueness: Audit active directory logs to confirm that all system accounts belong to individual, identifiable persons.
- Audit leaver deactivation speed: Compare termination dates against account lock timestamps to confirm prompt deprovisioning.
- Inspect contractor accounts: Check temporary worker files to confirm active accounts carry explicit end dates and business sponsors.
- Check service account ownership: Verify that non-human and automated identities have assigned internal owners and documented business reasons.
- Inspect internal mover logs: Confirm that teams updated identity profiles and group memberships when workers transferred departments.
- Review dormant account reports: Verify that administrators regularly discover and disable accounts with zero login activity over long periods.
Audit Evidence Checklist
- Identity management policy: Maintain a documented identity policy with complete version history in your central repository.
- Central identity directory: Supply authoritative directory exports listing active, suspended, and deleted user accounts.
- Onboarding identity verification files: Provide completed verification forms and HR sign-offs for sampled new starters.
- Offboarding deactivation logs: Supply timestamps proving prompt account deactivation for workers who left during the audit period.
- Service account register: Keep an active log of all system, application, and non-human identities with named business owners.
- Periodic reconciliation reports: Provide audit records showing quarterly comparisons between payroll files and active digital accounts.
- Temporary account approval forms: Provide records showing approved time limits and sponsor names for external contractor accounts.
What to Teach Employees
- Protect your personal identity: Teach workers that their company username is their personal digital signature and must never be shared.
- Never use colleague logins: Instruct staff never to borrow a coworker’s account or log in on behalf of another team member.
- Report unneeded accounts: Encourage workers to notify administrators if they discover duplicate, test, or legacy accounts assigned to them.
- Sponsor contractors properly: Teach project leads to register temporary contractors formally and request account closures when projects end.
- Report suspicious account activity: Ensure staff know to alert security teams immediately if they notice login alerts from unexpected locations.
- Understand identity verification: Educate new hires on why identity proofing is required during onboarding to protect company security.
Common Implementation Challenges
- Orphaned ex-employee accounts: Managers fail to alert IT when workers leave. Connect directory tools directly to payroll systems to automate deactivation.
- Proliferation of shared logins: Teams create generic accounts to avoid licence fees. Mandate unique individual identities for all systems.
- Unmonitored service accounts: Non-human accounts run without clear ownership. Require annual re-approval for all automated service identities.
- Untracked contractor accounts: Third-party logins remain active long after contracts expire. Set automatic expiry dates on all temporary accounts.
- Siloed application accounts: Individual departments create separate identities in unmanaged web tools. Consolidate systems under a central identity directory.
- Incomplete identity verification: Remote staff get provisioned without verifying legal identity. Require verified ID checks before issuing access.
How to Measure Effectiveness (KPIs)
- Leaver deprovisioning speed: Track the average time taken to disable user identities following official employee departure notifications.
- Orphaned account rate: Measure the percentage of active accounts discovered with no matching active employee or contractor on payroll.
- Unique identity coverage rate: Track the proportion of active accounts mapped to verified single individuals versus shared logins.
- Contractor expiry compliance: Measure the percentage of temporary contractor accounts that have active, enforced expiration dates.
- Service account ownership rate: Track the proportion of non-human and service identities with documented, active business owners.
- Identity management audit findings: Monitor the number of non-conformities raised against identity controls during internal audits.
Related ISO 27001 Controls
ISO 27001 Control A 5.16 connects to several other ISO 27001 requirements:
Annex A 5.16 connects directly to other organisational controls. It supports Clause 5.15 (Access Control) by providing verified identities. It feeds into Clause 5.18 (Access Rights) to ensure permissions match valid identities. Proper identity management also strengthens Clause 8.2 (Privileged Access Rights). Each control depends on the validity of the underlying identity.

