Skip to content
compliancebase
ISO 27001A.5 — Return of assets

A.5.11

Return of assets

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Ensure assets are returned when employment, contract, or agreement ends, or when assets are otherwise no longer needed.

Points of focus

  • Return checklist for hardware and tokens
  • Linked to leaver HR process
  • Cloud/SaaS access revoked with asset return
  • Lost-asset handling defined

Implementation notes

Integrate asset return into the same JML workflow as A.5.16/A.6.5. For remote staff, use prepaid ship labels and remote wipe via MDM before reuse. Track hardware security keys as assets. Confirm SaaS OAuth and personal-device wipe policies when BYOD is allowed. Document exceptions when equipment is purchased by the employee.

Audit tip: Sample three recent leavers: IdP disable time, laptop return/wipe, and residual SaaS grants.

Evidence auditors typically request:

  • Leaver checklist with asset return fields
  • IT tickets closing laptop recovery
  • YubiKey / badge inventory updates
  • Lost device wipe records

Common gaps

  • Remote leavers keep company Macs for weeks
  • Hardware recovered but SaaS OAuth grants remain
  • No tracking of security keys

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.11This control

Primary sources

Frequently Asked Questions

Document the transfer, wipe or re-image requirements, and remove MDM/company accounts before ownership changes.

Yes for endpoints, tokens, and any office badges; access revocation alone does not retire physical assets.

Focus on access revocation, data deletion attestations, and return of any company-issued tokens.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above