ISO 27001 Annex A 6.5 Responsibilities after termination or change of employment defines security duties when workers change roles or leave the company. Documented rules protect company data and revoke access rights smoothly.
Table of contents
Key Takeaways
- Define ongoing security duties: Establish clear, legally binding security obligations that remain active after staff depart or change roles.
- Store rules centrally: Keep offboarding policies, handover forms, and exit checklists in a central document repository.
- Revoke system access on time: Remove user accounts, cloud logins, and digital permissions promptly on the final working day.
- Recover all company assets: Collect laptops, mobile phones, security keys, and building passes before workers leave.
- Adjust role-change permissions: Update access rights immediately when staff move to new internal departments to prevent privilege creep.
- Remind workers of lasting duties: Issue formal written reminders covering continuous non-disclosure terms during exit interviews.
- Maintain exit audit trails: Keep signed handover logs and system offboarding records to prove compliance during audits.
- Protect company knowledge: Complete formal knowledge transfers and handover meetings to keep operations running without disruption.
How to Implement ISO 27001 Annex A 6.5
- Draft offboarding policies: Write a clear termination and role change policy and store it in your central document repository.
- Create standard exit checklists: Build simple offboarding task lists covering asset recovery, account revocation, and physical pass returns.
- Enforce role transition reviews: Review and reset user permissions whenever an employee transfers to a different internal position.
- Schedule formal exit interviews: Conduct offboarding meetings to review ongoing confidentiality duties and answer final questions.
- Notify internal teams promptly: Ensure human resources, management, and technical teams coordinate exit dates in advance.
- Retrieve all company hardware: Verify that departing staff return all assigned laptops, portable drives, and mobile devices.
- Cancel physical site access: Deactivate electronic door badges, collect physical keys, and cancel parking passes immediately.
- Issue written duty reminders: Provide departing employees with a written summary of their ongoing confidentiality obligations.
- Transfer critical account ownership: Move admin rights, shared documents, and service ownership to active staff before the final day.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 6.5
- Review offboarding policies: Check documented rules to confirm clear guidance exists for resignations, dismissals, and internal transfers.
- Audit recent exit records: Sample past employee departures to verify signed exit checklists and timely account closures.
- Check role transfer accounts: Inspect user accounts for staff who recently changed roles to ensure old, unnecessary permissions were removed.
- Verify account closure timings: Compare formal employment end dates against identity system deactivation logs to ensure zero delays.
- Inspect hardware return logs: Check asset registers to confirm all laptops, phones, and tokens were recovered upon exit.
- Audit physical access revocations: Review badge access records to ensure building entry rights ended on the employee’s last day.
- Check post-employment duty records: Verify that departing staff signed acknowledgement forms confirming ongoing non-disclosure terms.
- Inspect emergency revocation steps: Review records of any hostile or sudden terminations to ensure instant access cut-offs occurred.
- Verify shared password resets: Check that teams reset group passwords, shared logins, or service keys known to the departing worker.
Audit Evidence Checklist
- Termination and transfer policy: Maintain a documented offboarding policy with a complete version history in your central document repository.
- Completed exit checklists: Supply signed and dated offboarding checklists for all staff who left the company during the audit period.
- Account deactivation logs: Provide system timestamps showing the prompt revocation of user accounts, cloud tools, and email access.
- Asset return receipts: Produce sign-off forms proving full recovery of laptops, phones, hardware tokens, and keycards.
- Signed confidentiality acknowledgements: Keep signed records confirming staff understood their lasting post-employment duties.
- Internal transfer review tickets: Maintain change request tickets showing user access adjustments following role transfers.
- Physical access badge logs: Supply building security records showing the timely deactivation of door fobs and access passes.
What to Teach Employees
- Understand lasting duties: Teach workers that confidentiality rules and data safety obligations continue after they leave the business.
- Return all work equipment: Instruct staff to return all company-owned hardware, cables, tokens, and storage devices on their last day.
- Never copy company data: Warn departing workers that downloading, forwarding, or saving company files to personal accounts is strictly banned.
- Hand over work projects: Remind staff to transfer active files, admin access, and client information to designated colleagues.
- Follow role change steps: Teach workers to request removal of old access rights when transferring to a new internal team.
- Report unrevoked access: Encourage former or transferring workers to report any leftover accounts or tools they can still access by mistake.
- Protect intellectual property: Educate staff on the legal consequences of using proprietary code, plans, or customer lists in future jobs.
Common Implementation Challenges
- Delayed notification of exits: Managers fail to inform technical teams about staff departures in advance. Automate alerts from human resources workflows.
- Orphaned cloud accounts: Departing staff retain active logins to secondary cloud services. Use single sign-on systems to cut all access in one place.
- Privilege accumulation on transfer: Staff keep old system rights after moving to new teams. Enforce a clean-slate permission review on every role change.
- Unreturned remote hardware: Off-site employees delay shipping laptops back after leaving. Use prepaid courier boxes and track return deliveries closely.
- Unmonitored data forwarding: Workers email client lists to personal inboxes before resigning. Implement data loss prevention rules to block bulk transfers.
- Shared account vulnerability: Departing staff know shared team passwords. Enforce immediate password rotations on any shared tools after team exits.
- Incomplete exit documentation: Teams rush departures and skip signing exit checklists. Make final payroll processing dependent on completed offboarding forms.
How to Measure Effectiveness (KPIs)
- Account revocation speed: Measure the average time taken to revoke all system and cloud logins after employment terminates.
- On-time offboarding rate: Track the percentage of departing staff whose accounts were fully deactivated on or before their final day.
- Asset recovery success rate: Measure the percentage of company-issued hardware retrieved within target offboarding timeframes.
- Exit checklist completion rate: Track the proportion of staff departures supported by fully completed, signed exit records.
- Internal transfer review rate: Measure the percentage of internal job transfers that receive a documented access review within one week.
- Orphaned account discovery count: Track the number of active accounts belonging to departed workers discovered during monthly reviews.
- Post-exit security incident count: Monitor the total number of data breaches or access attempts linked to former staff each year.

