Annex A Controls Explained
ISO 27001 Control 5.11 Return of Assets
Control 5.11 concerns the return of assets (laptops, equipment, and other information assets) upon the change or termination of the contract.
Last Updated: 16 May 2026
Alan Parker, ISO 27001 Consultant & Internal Auditor,
Helping UK SMEs hit ISO 27001 in 90 days.
B.Sc (Hons) Information Systems · CISMP · ITIL Expert · 30+ years in IT governance and security.
Read full bio →
ISO 27001 Control 5.11 Return of Assets: “Personnel and other interested parties as appropriate shall return all the organization’s assets in their possession upon change or termination of their employment, contract or agreement.”
https://www.iso.org/standard/27001
Key Takeaways
- Control 5.11 applies to not just leavers but internal movers. A staff member changing roles may need to hand back assets, too; this is the part most organisations miss.
- The asset return process should integrate with your existing Joiners/Leavers/Movers process, not run separately. The audit evidence is specific: asset register status changes, signed return checklists, and records of how gaps are handled when something isn’t returned.
- Remote workers complicate the return process. Build in remote wipe before courier collection, or accept the residual risk and document it.
- The control covers more than laptops; Authentication hardware, paper documents, and portable storage all count as returnable assets.
Table of Contents

The Purpose of Control 5.11 Return of Assets
5.11 is not a particularly complicated control, as ISO 27001 asks you to outline your procedure for returning computers and other devices when a person leaves the organisation or changes roles and no longer requires them.
As such, you should ensure you have the following;
- A clear policy on asset return (or at least be part of the Acceptable Use Policy).
- A documented procedure for the return of assets. Typically, this is part of the Leavers and Movers processes.
- Maintain asset records accurately so that the asset is tracked accurately upon its return.
For many businesses in the UK and around the world, the rise of hybrid working has complicated asset returns. According to the UK Government’s Cyber Security Breaches Survey 2025/2026, the majority of staff in UK SMEs now work from home at least some of the time, meaning a laptop returned by post is increasingly the norm rather than the exception.
Asset Return Process
The asset returns process may be separate, but I’d normally recommend that it’s an integral part of your Joiners/Leavers/Movers process. ISO 27001 doesn’t specify exactly how you should approach it, just that you have assets returned, and the best way to achieve that is through a clearly understood process.
In my experience, the process usually looks like this;
- Manager notifies HR of the leaver. This triggers the leaver process, and the HR system records the exit date and sends email notifications to various departments (Payroll, Facilities, IT, etc.). If it’s not exactly this process, the manager might inform IT directly via email/form. It varies across companies, but personally, I like the trigger point to be in one place rather than many.
- The Manager & employee agree on a date for asset return (typically the employee’s last day) and schedule the handover of the assets to the line manager, who in turn passes them to IT.
- The line manager and the employee sign a receipt form so everyone is confident that the assets have been returned.
- The asset is returned to IT, who ensure the asset database is updated to reflect the change, then trigger a data wipe/asset rebuild, and even a backup if deemed necessary.
Running alongside this process is normally the removal of access rights (also triggered by the leavers process) and the asset lifecycle process.
A genuinely hard case: the dismissed-for-cause leaver who refuses to return company assets. This isn’t an asset return process problem; it’s a legal one. The right answers usually involve final pay deductions (within the limits of the Employment Rights Act 1996), a formal demand letter, remote wipe of the device, and acceptance that the physical asset may be a write-off.
Auditors don’t expect you to recover every asset in every circumstance, as in the above, but they do expect to see that you tried, escalated appropriately, and documented the outcome.
Short Term Consultants / Third-Parties
A small point on the standard wording: the control says ‘Personnel and other interested parties as appropriate‘. The ‘as appropriate’ qualifier is doing some work; it tells you that the obligation extends beyond direct employees to contractors and third-party staff, but proportionately.
A two-day external consultant who never received a company asset isn’t subject to this control; a six-month contractor with a company laptop and a security pass is. Be deliberate about where you draw the line, and document it.
Asset Return Sheet
I’ve created an asset return sheet that allows you to sign off on an asset being returned by an employee or contractor.
The document is editable in Word and covers leavers, internal movers, and contractor exits, with sign-off fields for the employee, line manager, IT, and HR. Adapt the asset categories and branding to fit your business.
Assets to Be Returned
I’ve tried to impress upon you in other sections that assets aren’t just laptops and tablets, and that you should think wider than that. Information assets could include any of the following;
- User Endpoint Devices: Such as laptops, desktops, smartphones, and tablets.
- Portable Storage Devices: Including USB drives, external hard drives, and SD cards.
- Specialist Equipment: Industry-specific tools and hardware.
- Authentication Hardware: Keys, tokens, smartcards, and other access control devices.
- Physical Information: Paper files, printed documents, and archived materials (DR Plans, Contact Details, etc).
So any process you define should try to recognise the various types of assets that fall under the process.
What Auditors Will Look For
Control 5.11 is one of the easier controls to evidence during an audit, provided your offboarding process is documented and consistent. I would always suggest that the entire Joiners/Movers/Leavers process (asset issuance, return, access rights, etc.) be robustly documented, as it becomes a focal point in any audit.
An auditor will typically ask for:
- A documented asset return process, either as part of your Joiners/Leavers/Movers process or as a standalone procedure. A reference to the Acceptable Use Policy or HR policy is usually enough.
- An asset register that genuinely tracks current status. Auditors look for status fields like “Allocated”, “Returned”, “In Stock”, or “Disposed”. If every asset on the register reads “Allocated” regardless of whether the person still works for you, the register isn’t doing its job.
- Signed return checklists or equivalent receipts for recent leavers. The auditor will usually pick a small sample (three to five recent leavers) and trace the assets through.
- Records of what happened where assets weren’t returned. This is the gap-handling evidence: did you chase, did you wipe remotely, did you legally pursue, did you write off the asset? “We never followed up” is the answer that triggers a nonconformity.
- Evidence that role-change movers, not just leavers, are picked up by the process. This is the question many auditors specifically test because it’s commonly missed.
If you can produce these five pieces of evidence in five minutes when asked, you’re in a good position to pass control 5.11.
To give you a concrete sense of what good evidence looks like: I recently reviewed a client’s asset register before their Stage 2 audit. For each of their last twelve leavers, the register showed the asset status change date, the IT team member who actioned the change, the wipe certificate reference (where applicable), and a link to the signed return checklist in their HR system. That’s good audit-ready evidence. Compare that to ‘here are some laptops, we think these are returned’, which is what auditors often get.
Common Issues I Find During Internal Audits
When I perform internal audits, some of the key things I tend to discover include;
- The asset register is out of sync with the leavers. I’ll pick a person who has left in the past 3 to 6 months, then track them through the system, and see if their asset has been updated to reflect who (if anyone) it’s assigned to. Or, if I know things like swipe cards exist for the organisation, I might focus on those.
- No process for internal movers. The leaver process is usually documented and consistent, but the role-change process either doesn’t exist or doesn’t trigger an asset review. So, you can have a situation where a member of staff moves from the back-office team to a field-operations team (e.g., construction) and keeps the high-spec laptop (and access rights) they no longer need. Please note that the control in ISO 27001 actually says “change or termination of employment,” so it needs to cover the ‘change’ part, which is very commonly overlooked.
- Remote leavers and returns. With hybrid working, leavers often need to courier kit back to IT or their line manager. Without a clear process (and ideally a remote wipe before the device leaves their hands), it’s potentially open to issues. So, you might ensure the policy stipulates which courier, or that IT need to wipe the asset remotely first. In honesty, this isn’t something I’d pick up on in an audit, but I have seen in operational practice when working in IT teams.
- No follow-up on assets that weren’t returned. Someone left, didn’t return the laptop, you sent a few emails, and then the matter quietly died. The asset register still shows the laptop as allocated to them three years later. The right answer isn’t to chase forever; it’s to formally write off the asset, record the decision, and update the register.
I recently audited a medium-sized SaaS company with just under 250 staff and picked two leavers from the past six months. Both still showed their laptops as ‘Allocated’ on the asset register, despite both having been returned. The root cause was a manual process that wasn’t working. Yes, the laptops had been returned, but because the IT team hadn’t updated the register and just ‘eyeballed’ the cupboard shelf to check stock when they needed a replacement asset. It’s a gap a decent auditor will quickly find, and the fix is just a small amount of process discipline.
The NCSC’s guidance on managing the security of remote working covers the broader controls; for asset return specifically, the practical points to capture in your policy are which courier to use, who pays, and whether IT needs to wipe the device before it leaves the user’s hands.
How does ISO 27001 Control 5.11 link to other clauses and controls
As I’ve mentioned, 5.11 doesn’t operate in isolation; it depends on several other controls being in place to function properly.
- Annex A 5.9 – Inventory of information and associated assets: 5.11 only works if 5.9 is in place. You can’t return what isn’t tracked.
- Annex A 5.10 – Acceptable use of information and other associated assets: Should commit staff in advance to returning assets when employment ends. The obligation is set out under 5.10 and enforced under 5.11.
- Annex A 5.18 – Access rights: Running alongside asset return is access revocation. Both should be triggered by the same leaver/mover process.
- Annex A 5.19 – Information security in supplier relationships: Where contractors or suppliers hold organisational assets, the return obligation should be in their contract.
- Annex A 6.5 – Responsibilities after termination or change of employment: Covers the broader exit obligations, including post-employment confidentiality.
- Annex A 7.14 – Secure disposal or re-use of equipment: Once an asset is returned, this control governs what happens next.
- Annex A 8.1 – User endpoint devices: The device-level controls that should be in place during use, particularly encryption and remote wipe capability, which support secure return.
FAQs
What is the aim of Control 5.11 in ISO 27001?
The goal is to ensure that all assets provided to employees, contractors, or third parties (like laptops, ID badges, mobile devices, or data) are returned when they leave the organisation or change roles. This prevents unauthorised access or data loss.
What counts as an “asset” under this control?
Assets include both:
– Physical items: laptops, access cards, USB drives, phones
– Information assets: confidential documents, intellectual property, client data
– Also includes software licenses and user accounts that must be deactivated
When should the return of assets process be triggered?
Asset return should be part of:
– Offboarding procedures (employee exits)
– Role or department changes
– Contractor or supplier disengagements
It should be tracked and documented to ensure nothing is missed.
How do we ensure all assets are returned properly?
Implement a return checklist during offboarding that:
– Lists all assigned assets
– Requires formal sign-off when items are returned
– Includes steps to revoke access rights and recover data from devices
Why is this control important for security and compliance?
Failing to recover assets can lead to:
– Unauthorised access to systems or data
– Data breaches if devices are lost or misused
– Non-compliance with GDPR or contractual requirements
It also helps maintain the accuracy of asset inventory.
Conclusion
Control 5.11 is one of the simpler ISO 27001 controls, but one of the easiest to fail at audit, because the gap between “we have an offboarding process” and “we can prove every asset was returned” is wider than most organisations realise.
The fix isn’t complicated: integrate asset return into your existing Joiners/Leavers/Movers process, keep the asset register current, capture signed return receipts, and document what happened in the cases where assets weren’t recovered. Apply the same discipline to internal movers as to leavers.
If you’d like a ready-made Leaver/Mover Asset Return Checklist alongside the wider HR security templates, the Iseo Blue ISO 27001 Toolkit includes both. Or if you’d rather talk through how to integrate asset return into your offboarding process, the free 30-minute consultation is genuinely free and genuinely 30 minutes.
Author Background
This article was written by Alan Parker, an ISO 27001 consultant and founder of Iseo Blue Limited. He helps UK SMEs achieve certification in 90 days or less, often without a dedicated security team or a large budget.
With over 30 years in IT governance and information security, Alan works with software companies, IT service providers, managed service providers, and professional services firms across the UK, Europe, and internationally.
Qualifications: ITIL v3 Expert, ITIL v4 Bridge, PRINCE2 Practitioner. Named IT Project Expert of the Year (2024, UK). Alan writes in plain English for busy teams who need to get things done.
Connect on LinkedIn or Bluesky, or explore his free ISO 27001 tools and templates at iseoblue.com. B.Sc (Hons) Information Systems, CISMP certified.