ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Contractor IP Review Checklist

Contractor IP Review Checklist

1. Purpose

The Contractor IP Review Checklist provides a structured process for reviewing intellectual-property ownership, confidentiality, permitted use, access, licensing, and return/deletion requirements when engaging contractors, consultants, freelancers, development partners, or other external personnel.

The checklist helps the organization:

  • Establish ownership of contractor-created IP
  • Identify contractor pre-existing IP
  • Protect organizational IP
  • Protect customer-owned IP
  • Identify third-party and open-source components
  • Confirm contractual IP assignment
  • Control access to source code and confidential information
  • Identify licensing restrictions
  • Prevent unauthorized reuse or disclosure
  • Support contractor onboarding
  • Support contractor offboarding
  • Maintain audit evidence

Core Principle

Identify → Contract → Establish Ownership → Protect → Control Access → Review Deliverables → Revoke → Return/Delete → Evidence


2. When to Use

Use this checklist when engaging contractors who may:

  • Develop software
  • Write source code
  • Design systems
  • Create documentation
  • Develop infrastructure
  • Access source repositories
  • Access cloud environments
  • Handle customer information
  • Create product designs
  • Develop algorithms
  • Perform research
  • Create marketing or creative content
  • Access trade secrets
  • Use organizational IP
  • Work with third-party or open-source software
  • Use AI tools to create deliverables

The review should be proportionate to the contractor’s role and access.


3. Contractor Information

FieldDetails
Review ID
Contractor Name
Contractor/Company
Role
Department/Project
Business Owner
Contractor Manager
Start Date
Expected End Date
Contract/SOW
Review Date
Reviewer
Risk Level
Review Status

Review Status

☐ Approved
☐ Approved with Conditions
☐ Further Information Required
☐ Remediation Required
☐ Not Approved


4. Contractor Type

☐ Individual Contractor
☐ Freelancer
☐ Consultant
☐ Development Contractor
☐ Design Contractor
☐ Security Contractor
☐ Cloud/Infrastructure Contractor
☐ Marketing Contractor
☐ Professional Services Firm
☐ Outsourced Service Provider
☐ Other: __________________


5. Contractor IP Exposure

Identify what the contractor may create or access.

IP Created

☐ Source code
☐ Scripts
☐ Infrastructure-as-Code
☐ Architecture
☐ Algorithms
☐ Technical documentation
☐ Product documentation
☐ Designs
☐ Graphics
☐ Videos
☐ Training material
☐ Research
☐ Business processes
☐ Reports
☐ Other proprietary material

IP Accessed

☐ Source code
☐ Customer information
☐ Product information
☐ Architecture
☐ Credentials/secrets
☐ Trade secrets
☐ Business information
☐ Security information
☐ Customer IP
☐ Personal data


6. Business Need

Confirm why the contractor is being engaged.

☐ Business requirement documented
☐ Scope defined
☐ Deliverables identified
☐ Duration defined
☐ Contractor role defined
☐ Access requirement defined
☐ IP creation requirement identified
☐ Customer impact assessed

Business Justification


7. Contract Review

Before work begins, verify that the contract or SOW addresses applicable IP requirements.

☐ Contractor identity confirmed
☐ Scope of services defined
☐ Deliverables defined
☐ IP ownership addressed
☐ IP assignment addressed where required
☐ Confidentiality addressed
☐ Pre-existing IP addressed
☐ Third-party IP addressed
☐ Open-source use addressed
☐ Customer IP addressed
☐ Information-security requirements addressed
☐ Access requirements addressed
☐ Return/deletion requirements addressed
☐ Offboarding requirements addressed

Contract Reference

Contract/SOW: __________________________

Effective Date: _________________________


8. IP Ownership

Determine who will own the IP created during the engagement.

DeliverableCreated ByIntended OwnerContract ReferenceOwnership Confirmed

Ownership Status

☐ Organization-owned
☐ Customer-owned
☐ Contractor-owned
☐ Licensed to organization
☐ Joint ownership
☐ Other: __________________

Ownership should be determined by the applicable contract and law rather than assumed.


9. IP Assignment

Where assignment is required:

☐ Assignment obligation included in contract
☐ Assignment covers applicable deliverables
☐ Assignment covers applicable rights
☐ Assignment documentation completed
☐ Contractor acknowledgment obtained
☐ Required supporting documentation retained

Evidence

Where ownership arrangements are legally sensitive, obtain appropriate legal review.


10. Contractor Pre-Existing IP

Identify IP the contractor owned or controlled before the engagement.

IPDescriptionContractor OwnerIntended UseOrganization RightsEvidence

Review

☐ Pre-existing IP declared
☐ Ownership verified where necessary
☐ Intended use documented
☐ License/right to use documented
☐ Restrictions understood
☐ Customer impact assessed

Do not assume that contractor pre-existing IP becomes organization-owned merely because it is incorporated into a deliverable.


11. Background IP

Identify reusable contractor frameworks, libraries, templates, tools, or methodologies.

Background IPOwnerUsed InOrganization RightsRestrictions

Determine whether the organization receives:

  • Ownership
  • License
  • Right to modify
  • Right to distribute
  • Right to continue using after termination

12. Third-Party IP

Determine whether contractor deliverables contain third-party material.

☐ No third-party IP
☐ Third-party software
☐ Third-party libraries
☐ Third-party images
☐ Third-party documentation
☐ Third-party datasets
☐ Third-party models
☐ Third-party APIs
☐ Other: __________________

Third-Party IP Register

ComponentProviderLicensePurposeRestrictionsReview

13. Open-Source Software

If the contractor develops software:

☐ Open-source use disclosed
☐ Component inventory provided where appropriate
☐ License identified
☐ Exact versions identified
☐ License obligations reviewed
☐ Copyleft implications assessed
☐ Attribution requirements identified
☐ Source-code obligations assessed
☐ SBOM provided where required
☐ Security vulnerabilities assessed
☐ Approval obtained

Open-Source Evidence

Contractors should not introduce open-source components into production deliverables without following the organization’s applicable software and license-management process.


14. Customer-Owned IP

If the contractor accesses or creates customer-owned material:

☐ Customer ownership identified
☐ Customer contract reviewed
☐ Permitted use defined
☐ Access restricted
☐ Confidentiality requirements identified
☐ Customer restrictions communicated
☐ Return/deletion requirement defined
☐ Offboarding requirement defined

Customer IP

CustomerIPContractor AccessPermitted UseContract Reference

15. Confidentiality

Verify that confidentiality requirements apply.

☐ NDA executed where required
☐ Confidentiality clause included in contract
☐ Trade secrets covered
☐ Source code covered
☐ Customer information covered
☐ Security information covered
☐ Information-disclosure restrictions defined
☐ Post-termination confidentiality addressed


16. IP Classification

Assign appropriate classification to important contractor-accessed or contractor-created IP.

☐ Public
☐ Internal
☐ Confidential
☐ Restricted

Classification

Information/IP: ______________________

Classification: _______________________

Reason: ______________________________


17. Access to IP

Identify exactly what access the contractor requires.

System/RepositoryInformation/IPAccessEnvironmentBusiness NeedExpiry
Development
Production

Apply least privilege.

Avoid providing broad access such as “full access” unless it is specifically required and appropriately controlled.


18. Source Code Access

If the contractor requires source-code access:

☐ Named account
☐ MFA
☐ Repository access restricted
☐ Branch protection
☐ Code review
☐ Access logging
☐ Production branch restrictions
☐ Secret scanning
☐ Access expiry
☐ Periodic access review

Repository

Repository: ___________________________

Access Level: __________________________

Expiry: _______________________________


19. Cloud Access

If the contractor requires cloud access:

☐ Named identity
☐ MFA
☐ Least privilege
☐ Role-based access
☐ Temporary access where practical
☐ Production access justified
☐ Privileged access separately approved
☐ Logging enabled
☐ Access expiry defined
☐ Credentials/tokens controlled

Cloud Environment

☐ Development
☐ Testing
☐ Staging
☐ Production


20. Secrets and Credentials

Contractors must not receive unnecessary permanent credentials.

☐ Credentials requirement identified
☐ Secrets stored in approved system
☐ No secrets in source code
☐ Temporary credentials used where practical
☐ MFA enabled
☐ Access logged
☐ Rotation defined
☐ Revocation process defined

Never record actual passwords, API keys, tokens, private keys, or other secrets in this checklist.


21. Remote Access

Where remote access is provided:

☐ Approved device
☐ MFA
☐ Secure connection
☐ Endpoint protection
☐ Access restrictions
☐ Session controls
☐ Logging
☐ Access expiry


22. Contractor Work Location

Record relevant working arrangements.

☐ Organization premises
☐ Contractor premises
☐ Remote
☐ Customer premises
☐ Multiple locations

Where location affects legal, privacy, contractual, or security requirements, assess the impact.


23. Contractor Devices

Determine whether organizational or contractor-owned devices are used.

☐ Organization-managed device
☐ Contractor-managed device
☐ BYOD
☐ Customer device

Where contractor-owned devices are permitted:

☐ Security requirements defined
☐ Supported operating system
☐ Encryption
☐ Endpoint protection
☐ Patch management
☐ Screen lock
☐ Secure storage
☐ Data transfer restrictions


24. Information Sharing

Record information that will be shared with the contractor.

InformationClassificationPurposeTransfer MethodRetentionApproved By

Use approved transfer mechanisms.


25. AI Tool Usage

Determine whether the contractor will use AI tools.

☐ AI tools not permitted
☐ AI tools permitted with restrictions
☐ Approved AI tools identified
☐ Customer information restrictions defined
☐ Confidential information restrictions defined
☐ Source-code restrictions defined
☐ AI-generated code review required
☐ Licensing implications assessed
☐ Data retention/training terms reviewed where relevant

Approved AI Tool

Tool: _________________________________

Permitted Use: _________________________

Restrictions: __________________________


26. Deliverable Review

Before accepting a contractor deliverable:

☐ Deliverable matches SOW
☐ Ownership confirmed
☐ Third-party IP identified
☐ Open-source components identified
☐ License obligations reviewed
☐ Security requirements satisfied
☐ Secrets removed
☐ Customer information handled appropriately
☐ Code/documentation reviewed
☐ Required testing completed
☐ Evidence retained


27. Software Deliverables

For software created by contractors:

☐ Source code delivered
☐ Build instructions delivered where required
☐ Dependency information delivered
☐ SBOM provided where required
☐ License information provided
☐ Documentation delivered
☐ Security testing completed
☐ Code review completed
☐ Repository ownership transferred where required
☐ Deployment information delivered


28. Documentation Deliverables

For documentation or creative material:

☐ Final deliverable received
☐ Editable source files received where required
☐ Ownership confirmed
☐ Third-party material identified
☐ License restrictions reviewed
☐ Customer restrictions reviewed
☐ Storage location established
☐ Access controlled


29. IP Quality and Integrity

Before accepting important deliverables:

☐ Correct version confirmed
☐ Source verified
☐ No unauthorized third-party material
☐ No unexplained code/components
☐ No embedded credentials
☐ No malicious or suspicious components identified
☐ Required security testing completed
☐ Required documentation completed


30. IP Risk Assessment

Assess contractor-related IP risks.

RiskLikelihoodImpactRatingTreatment
IP ownership uncertainty
Unauthorized disclosure
Source-code theft
Third-party IP infringement
Open-source license conflict
Customer IP exposure
Excessive access
Contractor offboarding failure
AI/IP risk

31. Subcontractors

Determine whether the contractor uses additional personnel.

☐ No subcontractors
☐ Subcontractors used
☐ Subcontractor approval required
☐ IP obligations flow down
☐ Confidentiality requirements flow down
☐ Security requirements flow down
☐ Customer requirements flow down
☐ Subcontractor access reviewed

Subcontractor Information

SubcontractorRoleIP AccessApprovedContractual Controls

32. Monitoring During Engagement

Periodically review:

☐ Contractor access
☐ Repository access
☐ Cloud access
☐ Customer IP access
☐ Deliverables
☐ Open-source usage
☐ Third-party IP
☐ Contract compliance
☐ Security requirements
☐ IP ownership records
☐ Subcontractors


33. IP Change Review

Reassess when:

☐ Scope changes
☐ New IP created
☐ New customer information introduced
☐ Production access requested
☐ Privileged access requested
☐ New repository required
☐ New open-source component introduced
☐ New AI tool introduced
☐ Subcontractor introduced
☐ Contract amended
☐ Customer requirements change

Change Process

Change → Assess IP Impact → Assess Security/Risk → Update Contract/Controls → Approve → Record


34. Contractor Offboarding

Before the engagement ends:

☐ Contractor access identified
☐ Repository access reviewed
☐ Cloud access reviewed
☐ SaaS access reviewed
☐ VPN access removed
☐ Accounts disabled
☐ Tokens revoked
☐ Credentials rotated where necessary
☐ Customer access removed
☐ Organizational equipment returned
☐ Source code returned/transferred
☐ Documentation transferred
☐ IP assignment confirmed
☐ Confidential information returned/deleted where required
☐ Subcontractor access removed


35. IP Return and Deletion

Confirm the treatment of information and IP after termination.

Asset/IPOwnerReturn RequiredDelete RequiredActionVerification

Verification

☐ Returned
☐ Deleted
☐ Access revoked
☐ Deletion confirmed where required
☐ Evidence retained


36. Post-Termination Rights

Review whether the contractor retains any rights after termination.

☐ No continuing rights
☐ Limited license retained
☐ Background IP retained
☐ Confidentiality continues
☐ Customer restrictions continue
☐ IP assignment remains effective
☐ Other contractual rights

Notes


37. Contractor IP Incident

If an IP-related incident occurs:

☐ Incident reported
☐ Access contained
☐ Evidence preserved
☐ Affected IP identified
☐ Customer impact assessed
☐ Contractual obligations assessed
☐ Legal/compliance review completed where necessary
☐ Corrective action initiated
☐ Contractor access reviewed
☐ Root cause identified

Examples:

  • Source-code disclosure
  • Unauthorized copying
  • Customer IP exposure
  • Lost device
  • Unauthorized repository access
  • License violation
  • Trade-secret disclosure

38. Corrective Actions

Action IDFindingRiskActionOwnerDue DateStatus

39. Approval

Contractor IP Review Result

☐ Approved
☐ Approved with Conditions
☐ Further Information Required
☐ Remediation Required
☐ Not Approved

Conditions:

Business Owner: ______________________

Security Reviewer: ____________________

Legal/Compliance Reviewer: ____________

Approver: _____________________________

Date: _________________________________


40. Evidence Checklist

Retain appropriate evidence such as:

☐ Contractor agreement
☐ Statement of Work
☐ NDA
☐ IP assignment
☐ Pre-existing IP declaration
☐ Third-party IP declaration
☐ Open-source review
☐ Access approval
☐ Repository access record
☐ Cloud access approval
☐ Deliverable acceptance
☐ SBOM where applicable
☐ Security testing evidence
☐ Periodic review
☐ Offboarding record
☐ IP return/deletion evidence
☐ Corrective actions

Do not retain unnecessary credentials or secret values as evidence.


41. AWS SaaS Startup Example

A SaaS startup engages an external developer to build a new module for its AWS-hosted application.

Contractor Scope

Role: Backend Developer
Access: Development AWS account and source repository
Deliverable: New API module
Customer Data: Not required for development
Production Access: Not required

IP Review

Ownership: Contract states that applicable deliverables are assigned to the organization.

Pre-existing IP: Contractor declares an existing utility library that may be incorporated.

Open Source: Contractor must disclose open-source dependencies and applicable licenses.

Access: Named repository account with MFA and development-only permissions.

Secrets: Contractor receives no permanent production credentials.

Customer IP: Customer production data is excluded from development.

AI: Contractor may use only approved AI tools and must not submit confidential/customer information.

Before Acceptance

MAE-style evidence should include:

Contract → IP Assignment → Pre-existing IP Declaration → Access Approval → Development → OSS Review → Security Testing → Deliverable Review → Ownership Confirmation → Access Revocation


42. Startup-Friendly Model

For a startup, focus the review on five areas.

1. Who Owns the Work?

Confirm:

  • Contract
  • IP assignment
  • Pre-existing IP
  • Customer IP
  • Third-party IP

2. What Can the Contractor Access?

Confirm:

  • Source code
  • Cloud
  • Customer data
  • Confidential information
  • Production
  • Privileged systems

3. What Goes Into the Deliverable?

Confirm:

  • Open-source software
  • Third-party libraries
  • Contractor background IP
  • AI-generated material
  • Customer material

4. What Happens When the Contractor Leaves?

Confirm:

  • Access revoked
  • Code transferred
  • IP assignment confirmed
  • Information returned/deleted
  • Credentials rotated
  • Subcontractors removed

5. Can We Prove It?

Maintain:

  • Contract
  • IP assignment
  • Review
  • Approval
  • Access records
  • Deliverable acceptance
  • Offboarding evidence

43. Common Mistakes

Avoid:

  • Assuming contractors automatically transfer IP ownership.
  • Not documenting pre-existing contractor IP.
  • Allowing contractors to use personal repositories.
  • Giving contractors permanent production access.
  • Ignoring subcontractors.
  • Allowing unrestricted open-source usage.
  • Ignoring third-party images, libraries, datasets, or documentation.
  • Allowing confidential/customer information into unapproved AI tools.
  • Failing to review contractor deliverables.
  • Failing to revoke access immediately after engagement.
  • Forgetting API keys and tokens during offboarding.
  • Failing to document IP assignment.
  • Assuming an NDA alone establishes IP ownership.
  • Failing to retain evidence of the ownership decision.

44. Relationship With Other ISMS Documents

DocumentRelationship
Intellectual Property Protection PolicyDefines IP protection requirements
Intellectual Property RegisterRecords important IP
Employee IP Review ChecklistApplies similar controls to employees
Contractor Onboarding ChecklistEstablishes contractor access and requirements
Contractor Offboarding ChecklistRemoves access and recovers information
Supplier Security AssessmentAssesses contractor/supplier security
Open-Source Software RegisterRecords OSS used in deliverables
Open-Source License Review ChecklistReviews OSS licensing
Software License RegisterRecords software licensing
Access Control PolicyControls contractor access
Information Classification PolicyClassifies IP and information
Secure Development PolicyControls software development
Customer Contract Security ReviewIdentifies customer IP commitments
Incident ManagementHandles contractor-related IP incidents
Risk RegisterTracks significant IP risks

45. ISO/IEC 27001 Connection

Contractor IP review supports the organization’s risk-based management of:

  • Intellectual property
  • Information assets
  • Access control
  • Supplier relationships
  • Secure development
  • Information transfer
  • Confidentiality
  • Technology supply-chain security
  • Information deletion
  • Offboarding
  • Legal and contractual requirements

The Contractor IP Review Checklist is not itself a universally mandatory ISO/IEC 27001 document.

The organization should determine the appropriate level of contractor review based on:

  • Risk
  • Contractor role
  • Information accessed
  • IP created
  • System access
  • Customer requirements
  • Contractual obligations
  • Legal requirements

Relevant controls should be addressed through the organization’s risk assessment and applicable Statement of Applicability.


46. Final Contractor IP Audit Trail

For every significant contractor engagement, the organization should be able to demonstrate:

Why was the contractor engaged?
What IP will they create or access?
Who owns the resulting IP?
What pre-existing IP does the contractor bring?
What third-party or open-source IP is used?
What customer IP is involved?
What information and systems can the contractor access?
What contractual protections apply?
Who approved the access?
Were deliverables reviewed?
Was ownership confirmed?
What happens when the contractor leaves?
Was access revoked?
Was IP returned or deleted where required?
What evidence proves the process was completed?


47. Final Principle

Contract → Establish Ownership → Declare Pre-Existing IP → Control Access → Review Third-Party/OSS Use → Protect Customer IP → Review Deliverables → Confirm Ownership → Revoke Access → Return/Delete → Preserve Evidence

Contractor IP management should not be treated as only a legal-contract exercise. It connects contractual ownership, source-code security, customer information, open-source licensing, access management, deliverable acceptance, and offboarding into one defensible process.