ISO 27001 Responsibilities After Termination or Change of Employment Explained – Control 6.5

ISO 27001 Responsibilities After Termination or Change of Employment Explained – Control 6.5

The risk does not end when someone leaves your business. In many cases, it increases dramatically. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations run smooth technical onboarding processes, only to completely fumble off boarding, leaving active credentials assigned to departed contractors, allowing ex-employees to walk away with client databases on personal devices, or ignoring internal role transfers that result in massive permission creep. Transitions expose organizational gaps quickly, and Annex A 6.5 exists to protect your information when people leave or change roles.

ISO 27001:2022 includes Annex A 6.5 to ensure your business defines, communicates, and enforces continuing information security responsibilities after employment or contractual relationships end or change. This control updates former 2013 requirements (7.3.1) and aligns post-employment obligations directly with access control revocation (Annex A 8.2), physical asset return (Annex A 7.9), and legal confidentiality terms (Annex A 6.6).

Quick Summary: What ISO 27001 Annex A 6.5 Requires

At a practical level, Annex A 6.5 is about protecting information beyond the active lifecycle of an employment or supplier contract. It does not mean treating departing staff like criminals; it expects clear, enforceable, and structured transition governance. Here is what you need to do in plain English:

  • Define Ongoing Security Obligations: Explicitly document which responsibilities (e.g., confidentiality, IP ownership, non-solicitation) remain binding after departure.
  • Embed Obligations in Contracts: Ensure employment contracts and supplier agreements explicitly state that confidentiality requirements survive termination (Annex A 6.6).
  • Conduct Formal Exit Briefings: Re-state post-employment duties during offboarding interviews and obtain written confirmation of compliance.
  • Revoke & Adjust Access Immediately: Synchronize HR offboarding tickets with IT to revoke logical access and retrieve physical credentials (Annex A 8.2) on or before the last working day.
  • Manage Internal Role Transfers: Re-evaluate access permissions when staff move between departments to eliminate “permission creep” (Annex A 8.3).
  • Recover Corporate Assets & Media: Collect all corporate laptops, mobile devices, physical keys, and storage media before final departure sign-off (Annex A 7.14).

Why Offboarding and Role Changes Present Critical Hazards

Departing employees, contractors, or transferred staff hold deep knowledge of your internal systems, business processes, and customer records. When departure responsibilities are left implicit or unmanaged, your organisation faces extreme exposure to data theft, operational disruption, and lost intellectual property.

Ignoring responsibilities after termination or change exposes your business to severe hazards:

  • Post-Departure Data Exfiltration: Ex-employees downloading client lists, price sheets, or proprietary source code to take to a direct competitor or new venture.
  • “Orphaned” Active Credentials: Former contractors or employees logging into SaaS portals, cloud environments, or VPNs weeks after leaving because access revocation was missed.
  • Permission Creep via Internal Role Changes: Staff accumulating administrative rights as they move through different internal roles over time, creating severe segregation-of-duties conflicts.
  • Unreturned Corporate Hardware: Unencrypted laptops or mobile devices remaining in the physical custody of ex-staff, exposing stored corporate data to physical loss (Annex A 8.1).

My 8 Step Plan to Implement Annex A 6.5 Fast

You do not need a complex legal team to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready post-termination and role-change framework.

1. Embed Post-Employment Terms into Base Contracts

Ensure legal contracts explicitly cover continuing security obligations long before an offboarding scenario occurs:

  • Include explicit “Survives Termination” clauses inside standard employment contracts and contractor agreements (Annex A 6.6).
  • Define ongoing duties regarding intellectual property (IP) assignment, trade secret protection, and client data confidentiality.
  • Incorporate non-solicitation and restrictive covenants where permitted by local employment legislation.

2. Formalize the Employee Offboarding Workflow

Eliminate ad-hoc departures by establishing a standardized, cross-departmental offboarding checklist:

  • Trigger automated notifications across HR, IT, Facilities, and direct managers immediately upon receipt of a resignation or termination notice.
  • Define specific SLAs for access revocation (e.g., revoking cloud access instantly upon formal departure or high-risk dismissal).
  • Assign explicit ownership for recovering company hardware, physical keys, and access badges.

3. Conduct Structured Exit Briefings

Reinforce continuing security obligations during the final days of employment:

  • Conduct a formal exit interview reminding the departing individual of their ongoing legal confidentiality commitments.
  • Provide a written summary detailing surviving post-employment obligations and obtain a signed sign-off copy for the employee file.
  • Remind departing staff that erasing or taking company data, intellectual property, or code constitutes a illegal breach.

4. Automate Immediate Access Revocation

Contractual commitments are meaningless if logical access pathways remain open. Block access fast (Annex A 8.2):

  • Disable Single Sign-On (SSO) accounts, email routing, and cloud tenant access on or before the employee’s official final working hour.
  • Terminate active remote VPN/ZTNA sessions and invalidate OAuth tokens across all managed endpoints (Annex A 6.7).
  • Forward or archive email inboxes and update shared resource distribution lists to maintain operational continuity.

5. Recover All Corporate Assets and Storage Media

Ensure physical corporate assets are returned before the final exit sign-off is completed:

  • Collect all company-issued hardware: laptops, smartphones, tablets, USB drives, and physical security tokens (Annex A 7.10).
  • Retrieve physical keys, building access cards, and parking passes (Annex A 7.2).
  • Execute remote wipe commands via MDM/MAM for any personal BYOD devices that accessed corporate containers (Annex A 8.1).

6. Govern Internal Role Changes (Prevent Permission Creep)

Treat internal role transfers with the same security discipline as external offboarding:

  • Require HR to notify IT whenever an employee changes departments, roles, or operational responsibilities.
  • Conduct a formal access rights review (Annex A 8.3) to strip legacy access rights that are no longer required for the new role.
  • Ensure knowledge transfer takes place cleanly without the employee retaining administrative override rights on former systems.

7. Enforce Contractor and Third-Party Exit Discipline

Third-party contractor and vendor exits are frequently overlooked, creating significant supply-chain risks:

  • Maintain explicit expiration dates on all contractor accounts, requiring mandatory renewal approvals.
  • Incorporate contractual exit clauses forcing third-party vendors to certify the deletion or secure return of hosted corporate data (Annex A 7.14).
  • Revoke vendor remote access tunnels and API keys immediately upon project completion (Annex A 8.30).

8. Audit Exit Records and Access Log Integrity

Demonstrate compliance to your auditor through verifiable audit trails and periodic reviews:

  • Maintain a central register of all completed exit checklists, signed exit statements, and asset recovery logs.
  • Perform quarterly spot-check audits comparing HR departure lists against active Active Directory / Identity Provider accounts.
  • Feed any discovered offboarding gaps (e.g., delayed account disabling) into your security incident management workflow (Annex A 6.8).

Common Implementation Pitfalls and How to Fix Them

When preparing clients for ISO 27001 audits, I frequently spot the same post-termination mistakes. Here are the main traps and how to solve them:

  • Problem: IT Revoking System Access Days or Weeks After an Employee Departs
    Ninja Solution: Automate Identity Provider (IdP) deprovisioning directly from the HR management tool upon status change.
  • Problem: Employees Moving from Finance to Sales Retaining Full Access to Financial Databases
    Ninja Solution: Enforce a mandatory “Zero-Based Access Review” during internal transfers—revoke all existing rights before provisioning new ones.
  • Problem: Contractors Leaving with Unmonitored API Keys and Direct Database Passwords
    Ninja Solution: Require unique, named credentials for contractors and rotate shared environment secrets immediately upon contract termination.
  • Problem: Relying on Verbal Agreements that “Data Has Been Deleted” from Personal Devices
    Ninja Solution: Deploy MAM containerisation to scrub corporate data remotely or require a signed Affidavit of Destruction.

The ISO 27001 Ninja Bottom Line

ISO 27001 Annex A 6.5 is about protecting your business during one of the highest-risk points in the people lifecycle. People move on, but your information assets, customer databases, and intellectual property must remain fully protected by design.

By embedding surviving confidentiality terms in base contracts, executing structured offboarding checklists, conducting exit briefings, automating immediate logical access revocation, recovering physical assets, scrubbing BYOD containers, and managing internal role transfers cleanly, you eliminate post-employment exposure pathways, safeguard your intellectual property, and satisfy your ISO 27001 auditor with complete confidence.