Skip to content
arrow_back
search
Annex A 6.5 verified ISO/IEC 27001:2022

Responsibilities after employment termination or role change

Ensure security responsibilities are clear when employment ends or roles change.

record_voice_over

Plain language

When someone leaves your organisation or changes roles, their responsibilities related to keeping information safe need to be clear. Think of it like making sure someone locks the door behind them after they leave. If we don't do this, sensitive information could get into the wrong hands, leading to data breaches or misuse.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

People controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Information security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced and communicated to relevant personnel and other interested parties.
verified ISO/IEC 27001:2022 Annex A 6.5
priority_high

Why it matters

If post-employment/role-change duties aren’t defined and enforced, staff may misuse retained access or disclose information, causing breaches and legal/reputational harm.

settings

Operational notes

At termination/role change, promptly revoke/adjust access, recover assets, update role responsibilities, and remind personnel of ongoing confidentiality and security obligations.

Mapping detail

Mapping

Direction

Controls