ISO/IEC 27001:2022 Annex A · Control 6.5
Responsibilities After Termination or Change of Employment: A Practical Implementation Guide
Ensure security duties, access and knowledge transfer remain controlled when a working relationship changes or ends.
This control concerns defining, enforcing and communicating information security responsibilities that remain valid after termination or role change.
What should the control achieve?
- Continuing duties are contractually clear.
- Role changes trigger timely access adjustment.
- Assets, information and responsibilities are handed over.
- High-risk departures receive coordinated treatment.
Step-by-step implementation
Define continuing obligations
Identify confidentiality, intellectual property, privacy, non-disclosure and record duties.
Create mover and leaver triggers
Managers notify HR, IT, Facilities and asset owners promptly.
Plan access changes
Remove old rights before or when new responsibilities begin; disable leavers at the appropriate time.
Transfer knowledge and ownership
Reassign information, approvals, service accounts, keys and open actions.
Recover assets and information
Coordinate devices, badges, documents and organizational data.
Communicate and verify
Remind personnel of duties and retain closure evidence.
What this could look like in practice
A sales manager joins a competitor. HR coordinates a risk-based exit: access is disabled at the agreed time, customer files and approvals transfer to a deputy, devices are returned and continuing confidentiality obligations are confirmed in writing.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Internal transfer | Old role rights are removed before new access. | Mover ticket |
| Planned exit | Owner and asset handover are scheduled. | Exit checklist |
| High-risk exit | Security, HR and Legal coordinate timing and monitoring. | Risk plan |
| Post-exit | Continuing duties and unresolved assets are followed up. | Confirmation record |
Implementation evidence
- Mover/leaver procedure
- Contractual continuing duties
- Notifications
- Access-removal logs
- Handover records
- Asset returns
- Exit reminders
- High-risk exit assessments
Useful metrics
- Access removed within target
- Mover rights adjusted on time
- Incomplete handovers
- Unreturned assets
Common mistakes
- Treating internal transfers as low risk.
- Waiting for payroll termination to disable access.
- Forgetting shared secrets and approvals.
- Not transferring ownership of records or services.
- Using excessive surveillance without lawful basis.
Questions an auditor may ask
- Which duties continue after exit?
- Show a recent role transfer.
- How are high-risk departures handled?
- How is ownership transferred?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.