Table of contents
ISO/IEC 27001:2022 Annex A 6.5
ISO 27001 Annex A 6.5 Responsibilities after termination or change of employment defines security duties when workers change roles or leave the company. Documented rules protect company data and revoke access rights smoothly.
Key Takeaways
- Define ongoing security duties: Establish clear, legally binding security obligations that remain active after staff depart or change roles.
- Store rules centrally: Keep offboarding policies, handover forms, and exit checklists in a central document repository.
- Revoke system access on time: Remove user accounts, cloud logins, and digital permissions promptly on the final working day.
- Recover all company assets: Collect laptops, mobile phones, security keys, and building passes before workers leave.
- Adjust role-change permissions: Update access rights immediately when staff move to new internal departments to prevent privilege creep.
- Remind workers of lasting duties: Issue formal written reminders covering continuous non-disclosure terms during exit interviews.
- Maintain exit audit trails: Keep signed handover logs and system offboarding records to prove compliance during audits.
- Protect company knowledge: Complete formal knowledge transfers and handover meetings to keep operations running without disruption.
How to Implement ISO 27001 Annex A 6.5
- Draft offboarding policies: Write a clear termination and role change policy and store it in your central document repository.
- Create standard exit checklists: Build simple offboarding task lists covering asset recovery, account revocation, and physical pass returns.
- Enforce role transition reviews: Review and reset user permissions whenever an employee transfers to a different internal position.
- Schedule formal exit interviews: Conduct offboarding meetings to review ongoing confidentiality duties and answer final questions.
- Notify internal teams promptly: Ensure human resources, management, and technical teams coordinate exit dates in advance.
- Retrieve all company hardware: Verify that departing staff return all assigned laptops, portable drives, and mobile devices.
- Cancel physical site access: Deactivate electronic door badges, collect physical keys, and cancel parking passes immediately.
- Issue written duty reminders: Provide departing employees with a written summary of their ongoing confidentiality obligations.
- Transfer critical account ownership: Move admin rights, shared documents, and service ownership to active staff before the final day.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 6.5
- Review offboarding policies: Check documented rules to confirm clear guidance exists for resignations, dismissals, and internal transfers.
- Audit recent exit records: Sample past employee departures to verify signed exit checklists and timely account closures.
- Check role transfer accounts: Inspect user accounts for staff who recently changed roles to ensure old, unnecessary permissions were removed.
- Verify account closure timings: Compare formal employment end dates against identity system deactivation logs to ensure zero delays.
- Inspect hardware return logs: Check asset registers to confirm all laptops, phones, and tokens were recovered upon exit.
- Audit physical access revocations: Review badge access records to ensure building entry rights ended on the employee’s last day.
- Check post-employment duty records: Verify that departing staff signed acknowledgement forms confirming ongoing non-disclosure terms.
- Inspect emergency revocation steps: Review records of any hostile or sudden terminations to ensure instant access cut-offs occurred.
- Verify shared password resets: Check that teams reset group passwords, shared logins, or service keys known to the departing worker.
Audit Evidence Checklist
- Termination and transfer policy: Maintain a documented offboarding policy with a complete version history in your central document repository.
- Completed exit checklists: Supply signed and dated offboarding checklists for all staff who left the company during the audit period.
- Account deactivation logs: Provide system timestamps showing the prompt revocation of user accounts, cloud tools, and email access.
- Asset return receipts: Produce sign-off forms proving full recovery of laptops, phones, hardware tokens, and keycards.
- Signed confidentiality acknowledgements: Keep signed records confirming staff understood their lasting post-employment duties.
- Internal transfer review tickets: Maintain change request tickets showing user access adjustments following role transfers.
- Physical access badge logs: Supply building security records showing the timely deactivation of door fobs and access passes.
What to Teach Employees
- Understand lasting duties: Teach workers that confidentiality rules and data safety obligations continue after they leave the business.
- Return all work equipment: Instruct staff to return all company-owned hardware, cables, tokens, and storage devices on their last day.
- Never copy company data: Warn departing workers that downloading, forwarding, or saving company files to personal accounts is strictly banned.
- Hand over work projects: Remind staff to transfer active files, admin access, and client information to designated colleagues.
- Follow role change steps: Teach workers to request removal of old access rights when transferring to a new internal team.
- Report unrevoked access: Encourage former or transferring workers to report any leftover accounts or tools they can still access by mistake.
- Protect intellectual property: Educate staff on the legal consequences of using proprietary code, plans, or customer lists in future jobs.
Common Implementation Challenges
- Delayed notification of exits: Managers fail to inform technical teams about staff departures in advance. Automate alerts from human resources workflows.
- Orphaned cloud accounts: Departing staff retain active logins to secondary cloud services. Use single sign-on systems to cut all access in one place.
- Privilege accumulation on transfer: Staff keep old system rights after moving to new teams. Enforce a clean-slate permission review on every role change.
- Unreturned remote hardware: Off-site employees delay shipping laptops back after leaving. Use prepaid courier boxes and track return deliveries closely.
- Unmonitored data forwarding: Workers email client lists to personal inboxes before resigning. Implement data loss prevention rules to block bulk transfers.
- Shared account vulnerability: Departing staff know shared team passwords. Enforce immediate password rotations on any shared tools after team exits.
- Incomplete exit documentation: Teams rush departures and skip signing exit checklists. Make final payroll processing dependent on completed offboarding forms.
How to Measure Effectiveness (KPIs)
- Account revocation speed: Measure the average time taken to revoke all system and cloud logins after employment terminates.
- On-time offboarding rate: Track the percentage of departing staff whose accounts were fully deactivated on or before their final day.
- Asset recovery success rate: Measure the percentage of company-issued hardware retrieved within target offboarding timeframes.
- Exit checklist completion rate: Track the proportion of staff departures supported by fully completed, signed exit records.
- Internal transfer review rate: Measure the percentage of internal job transfers that receive a documented access review within one week.
- Orphaned account discovery count: Track the number of active accounts belonging to departed workers discovered during monthly reviews.
- Post-exit security incident count: Monitor the total number of data breaches or access attempts linked to former staff each year.
