Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 6.5

Responsibilities After Termination or Change of Employment: A Practical Implementation Guide

Ensure security duties, access and knowledge transfer remain controlled when a working relationship changes or ends.

This control concerns defining, enforcing and communicating information security responsibilities that remain valid after termination or role change.

Practical interpretation: The final working day is not the only control point. Organizations must anticipate changes, remove obsolete access, transfer ownership and remind people of continuing obligations.

What should the control achieve?

  • Continuing duties are contractually clear.
  • Role changes trigger timely access adjustment.
  • Assets, information and responsibilities are handed over.
  • High-risk departures receive coordinated treatment.

Step-by-step implementation

1

Define continuing obligations

Identify confidentiality, intellectual property, privacy, non-disclosure and record duties.

2

Create mover and leaver triggers

Managers notify HR, IT, Facilities and asset owners promptly.

3

Plan access changes

Remove old rights before or when new responsibilities begin; disable leavers at the appropriate time.

4

Transfer knowledge and ownership

Reassign information, approvals, service accounts, keys and open actions.

5

Recover assets and information

Coordinate devices, badges, documents and organizational data.

6

Communicate and verify

Remind personnel of duties and retain closure evidence.

What this could look like in practice

A sales manager joins a competitor. HR coordinates a risk-based exit: access is disabled at the agreed time, customer files and approvals transfer to a deputy, devices are returned and continuing confidentiality obligations are confirmed in writing.

ActivityPractical implementationEvidence
Internal transferOld role rights are removed before new access.Mover ticket
Planned exitOwner and asset handover are scheduled.Exit checklist
High-risk exitSecurity, HR and Legal coordinate timing and monitoring.Risk plan
Post-exitContinuing duties and unresolved assets are followed up.Confirmation record

Implementation evidence

  • Mover/leaver procedure
  • Contractual continuing duties
  • Notifications
  • Access-removal logs
  • Handover records
  • Asset returns
  • Exit reminders
  • High-risk exit assessments

Useful metrics

  • Access removed within target
  • Mover rights adjusted on time
  • Incomplete handovers
  • Unreturned assets

Common mistakes

  • Treating internal transfers as low risk.
  • Waiting for payroll termination to disable access.
  • Forgetting shared secrets and approvals.
  • Not transferring ownership of records or services.
  • Using excessive surveillance without lawful basis.

Questions an auditor may ask

  • Which duties continue after exit?
  • Show a recent role transfer.
  • How are high-risk departures handled?
  • How is ownership transferred?
Implementation test: Sample a mover and leaver and reconcile access, assets, responsibilities, records and continuing obligations.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.