ISO 27001 Control A.6.5: Responsibilities After Termination or Change of Employment

· 5 min read · Lyudmil Arkov

Control A.6.5 addresses one of the most common sources of real-world breaches: the access and obligations that outlive the job. When someone leaves or changes role, their accounts, devices, keys, and duty of confidentiality do not automatically sort themselves out. A.6.5 requires you to define, communicate, and enforce the information security responsibilities that remain valid after termination or a change of employment. Get it right and departures are clean; get it wrong and you accumulate orphaned accounts, unreturned laptops, and confidentiality obligations nobody remembers. This is the fifth control in our walk through Annex A.

What the control requires

Annex A control 6.5 of ISO 27001:2022 states that information security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced and communicated to relevant personnel and other interested parties.

Three obligations:

  • Defined - you have identified which duties survive an exit or role change (typically confidentiality, return of assets, and non-use of information)
  • Communicated - the departing or changing person is reminded of those continuing duties
  • Enforced - the practical steps (revoking access, recovering assets) actually happen

Note the control covers change of employment, not just leaving. Someone moving from engineering to sales should lose the access their old role required - “access creep” from accumulated roles is a classic audit finding. A.6.5 is a preventive control. Annex A states it; ISO 27002 gives the guidance, and your Statement of Applicability records how you apply it.

How to implement termination and change responsibilities

Build an offboarding checklist and actually run it

The heart of this control is a repeatable offboarding (and role-change) checklist triggered the moment HR knows someone is leaving or moving. Typical steps:

  • Revoke system and application access on the effective date (ideally automated via your identity processes)
  • Disable or transfer email and accounts; reassign ownership of data and resources
  • Recover physical and logical assets: laptops, phones, tokens, access cards, keys
  • Remove the person from privileged groups, shared credentials, and access lists
  • Remind them, in writing, of continuing confidentiality obligations

Do not forget the leavers who never had a laptop from you

Contractors, temporary staff, and third parties also change and depart. The control says “other interested parties,” so your process must handle non-employees whose access should end - often coordinated through the supplier, not HR.

Time revocation to the risk

For an amicable, planned departure, revoking access at end of the last day is usually fine. For a high-risk exit - dismissal, a disgruntled leaver, or someone with privileged access - access should be cut immediately, sometimes before the person is informed, coordinated between HR, IT, and management. Define these scenarios in advance so nobody is improvising under pressure.

Reconfirm duties on a change of role, not just an exit

When someone changes role, run the access half of the process: remove what the old role needed and grant what the new one requires, rather than simply adding. A short periodic access review catches creep that slips through. This ties directly to the access-rights controls in the technological theme.

Keep evidence the process ran

Auditors want proof, per leaver, that offboarding happened: a completed checklist, the date access was revoked, confirmation assets were returned, and the acknowledgement of continuing obligations. A leaver log or tickets in your HR/IT system provide this cleanly.

A.6.1 and A.6.2 connection. Screening and terms and conditions open the employment lifecycle; A.6.5 closes it. The confidentiality duties defined at hiring are the ones enforced at exit.

A.6.6 connection. The confidentiality or non-disclosure agreement (A.6.6) is what makes post-employment confidentiality legally binding; A.6.5 is the reminder and enforcement of it.

A.5.11 connection. Return of assets (A.5.11) is the control that recovers laptops, tokens, and media - a core offboarding step.

A.5.16 and A.5.18 connection. Identity management and access rights are the mechanisms that actually revoke and adjust access on exit or role change.

Clause 7.3 connection. Awareness keeps continuing obligations understood, so a reminder at exit lands on prepared ground.

What auditors check

A defined offboarding process. Auditors expect a documented process covering access revocation, asset return, and continuing obligations - not an informal “IT usually handles it.”

Evidence it runs, per leaver. They sample recent leavers and check that access was actually revoked on time and assets recovered, with dated records.

Role changes handled. Auditors look at movers, not just leavers, checking that access from a previous role was removed rather than simply accumulating.

Continuing obligations communicated. They look for evidence the person was reminded of confidentiality duties that survive the exit.

Timeliness on high-risk exits. Auditors check that access for dismissed or high-risk leavers was cut promptly, not days later.

Common mistakes to avoid

Orphaned accounts. The signature failure of this control: a former employee’s account still active weeks or months after they left. Auditors specifically hunt for these.

Handling leavers but not movers. Adding access on promotion while never removing the old role’s access produces access creep and over-privileged staff.

Slow revocation on risky exits. Waiting until the next access review to disable a dismissed employee’s account is a serious gap.

Forgetting contractors. Non-employees whose engagement ends are often missed because they are outside the HR leaver process.

No return of assets. Laptops, phones, and access cards that are never recovered leave data and access in the wild.

No evidence. Even a clean offboarding fails the audit if there is no record it happened. Log it.

How 27kay can help

We help organizations build offboarding and role-change processes that actually close the loop - so access ends when employment does and confidentiality obligations survive it. As part of ISO 27001 implementation, we design the checklist, wire it to your identity and asset-return controls, define the high-risk exit playbook, and set up the evidence auditors ask for. For the full picture, see our ISO 27001 knowledge hub.

Worried you have orphaned accounts or leavers who kept their laptops? Get in touch - we will review your joiner-mover-leaver process and help you close the gaps.