ISO27001:2022 –
A5.11 Return of Assets
ISO 27001 – A5.11 Return of Assets
At first glance, this might seem like a simple control, but there’s actually a lot to it. It’s also a great example of why ISO27001 controls shouldn’t be viewed in isolation.
Watch the video below for insights into what’s required for ISO 27001 – A5.11.
What does ISO 27001 – A5.11 require?
The standard states that:
“Personnel and other interested parties as appropriate shall return all the organisation’s assets in their possession upon change or termination of their employment, contract or agreement.” (A5.11 Return of Assets)
Why is this required?
When someone leaves your organisation or changes roles, they must return any items issued to them — such as mobile phones, keys, laptops, software, or any other assets.
This control is essential not only from a financial standpoint — recovering valuable equipment — but also to ensure that no sensitive company or client information is retained improperly, which could lead to data breaches or confidentiality issues.
It’s also applicable to third parties like service providers and contractors, not just internal staff.
What the auditor is looking for
A policy isn’t required, but you must be able to show that a process is followed consistently. Examples of acceptable evidence include:
- A HR-led exit checklist that includes asset return
- Contract clauses with vendors and contractors covering asset and data return
- Inventory of assets (linked to control A5.9)
The auditor will expect to see that your organisation understands the process and follows it consistently. Even if it’s not formally documented, a working, repeatable process will suffice.
Q & A
How do we deal with the use of personal devices?
While the focus is on company-owned assets, personal devices used for work may also store business data. During the exit process, ensure that any company data on these devices is securely deleted. If the person isn’t present, ask for written confirmation that company data has been erased. It’s also a good opportunity to remind them of their ongoing responsibilities around data protection and confidentiality.
Is it possible to get this wrong?
Yes — if you don’t have an asset register or any return process in place. However, the standard doesn’t require a formal policy or detailed flowchart. A simple, well-followed checklist is usually enough to comply.
Difficulty rating
We rate this a 1 out of 5. It doesn’t require technical skills. The main requirement is a repeatable, consistent process — typically a checklist — used when employees or contractors leave or change roles.
More questions?
Remember that ISO27001 controls are interconnected. This one ties closely with A5.9 (Asset Inventory). Check our FAQ for more insight, or contact us directly for support.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.
