ISO 27001A.5 — Return of assets
A.5.11
Return of assets
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Ensure assets are returned when employment, contract, or agreement ends, or when assets are otherwise no longer needed.
Points of focus
- Return checklist for hardware and tokens
- Linked to leaver HR process
- Cloud/SaaS access revoked with asset return
- Lost-asset handling defined
Implementation notes
Integrate asset return into the same JML workflow as A.5.16/A.6.5. For remote staff, use prepaid ship labels and remote wipe via MDM before reuse. Track hardware security keys as assets. Confirm SaaS OAuth and personal-device wipe policies when BYOD is allowed. Document exceptions when equipment is purchased by the employee.
Audit tip: Sample three recent leavers: IdP disable time, laptop return/wipe, and residual SaaS grants.
Evidence auditors typically request:
- Leaver checklist with asset return fields
- IT tickets closing laptop recovery
- YubiKey / badge inventory updates
- Lost device wipe records
Common gaps
- Remote leavers keep company Macs for weeks
- Hardware recovered but SaaS OAuth grants remain
- No tracking of security keys
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.11 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.11)
Frequently Asked Questions
Document the transfer, wipe or re-image requirements, and remove MDM/company accounts before ownership changes.
Yes for endpoints, tokens, and any office badges; access revocation alone does not retire physical assets.
Focus on access revocation, data deletion attestations, and return of any company-issued tokens.