1. Purpose
The Asset Return Checklist provides a structured process for recovering organizational assets when an employee, contractor, consultant, intern, supplier personnel, or other authorized user changes role or leaves the organization.
The objective is to ensure that:
- Organizational assets are identified
- Assigned assets are recovered
- Information stored on assets remains protected
- Devices are securely handled
- Security credentials and authentication devices are addressed
- Asset ownership is updated
- Missing assets are investigated
- Evidence of return is maintained
- Returned devices are securely processed before reuse or disposal
Core Principle
Identify → Notify → Inventory → Recover → Verify → Secure → Update → Record → Close
2. When to Use
Use this checklist when:
☐ Employee terminates employment
☐ Contractor engagement ends
☐ Consultant engagement ends
☐ Internship ends
☐ Employee changes role
☐ Employee transfers department
☐ Equipment is replaced
☐ Device is upgraded
☐ Temporary equipment is returned
☐ Security token is no longer required
☐ Remote employee leaves
☐ Supplier personnel access ends
☐ Asset is recalled
☐ Other: __________________________
3. Asset Return Information
| Field | Details |
|---|---|
| Asset Return ID | |
| Employee/Contractor Name | |
| Employee/Contractor ID | |
| Department | |
| Role | |
| Manager | |
| Return Trigger | |
| Effective Date | |
| Return Deadline | |
| Asset Custodian | |
| IT Owner | |
| Security Reviewer | |
| Completion Date |
4. Return Trigger
☐ Employee termination
☐ Resignation
☐ Role change
☐ Department transfer
☐ Contract completion
☐ Internship completion
☐ Device replacement
☐ Asset reassignment
☐ Security incident
☐ Lost/stolen asset recovery
☐ Supplier offboarding
☐ Other: __________________________
Trigger Details
5. Asset Inventory
Identify all assets assigned to the individual.
☐ Laptop
☐ Desktop
☐ Mobile phone
☐ Tablet
☐ Monitor
☐ Keyboard
☐ Mouse
☐ Docking station
☐ Headset
☐ Printer
☐ USB/removable media
☐ External hard drive
☐ Hardware security key
☐ MFA token
☐ Smart card
☐ Access card
☐ Physical keys
☐ Network equipment
☐ Development equipment
☐ Other: __________________________
6. Asset Register Verification
Compare the assets being returned with the organization’s asset register.
| Asset ID | Asset Type | Serial Number | Assigned To | Expected Return | Returned |
|---|---|---|---|---|---|
| ☐ | |||||
| ☐ | |||||
| ☐ |
☐ Asset register reviewed
☐ All assigned assets identified
☐ Missing assets identified
☐ Ownership confirmed
☐ Return responsibility confirmed
7. Asset Return Notification
Confirm that the individual has been informed.
☐ Return requirement communicated
☐ Return date communicated
☐ Return location communicated
☐ Shipping instructions provided where applicable
☐ Packaging instructions provided
☐ Security requirements communicated
☐ Missing/damaged asset process communicated
Notification Date
8. Return Method
☐ In-person return
☐ Courier
☐ Company collection
☐ Office drop-off
☐ Authorized third-party collection
☐ Supplier return
☐ Other: __________________________
Return Details
9. Laptop/Desktop Return
☐ Device received
☐ Asset ID verified
☐ Serial number verified
☐ Physical condition recorded
☐ Power adapter returned
☐ Docking station returned where applicable
☐ Accessories returned
☐ Device ownership confirmed
☐ Device assigned to correct employee
Device Information
| Field | Details |
|---|---|
| Device Type | |
| Manufacturer | |
| Model | |
| Asset ID | |
| Serial Number | |
| Return Date | |
| Condition | |
| Received By |
10. Mobile Device Return
☐ Mobile phone returned
☐ Asset ID verified
☐ IMEI/serial number recorded where appropriate
☐ Charger returned
☐ SIM/eSIM addressed
☐ Corporate account removed or transferred
☐ MDM status reviewed
☐ Corporate applications addressed
☐ Device lock status verified
☐ Device ownership confirmed
11. Tablet and Other Portable Devices
☐ Tablet returned
☐ E-reader returned where applicable
☐ Portable workstation returned
☐ Handheld device returned
☐ Corporate accessories returned
☐ Device identity verified
☐ Security status assessed
12. Security Devices
Identify security-related assets.
☐ Hardware security key
☐ MFA token
☐ Smart card
☐ OTP device
☐ Digital certificate device
☐ Security token
☐ Administrative device
☐ Other security equipment
Security Device Actions
☐ Returned
☐ Revoked
☐ Disabled
☐ Reassigned
☐ Securely destroyed
☐ Other: __________________________
13. Access Cards and Physical Keys
☐ Office access card returned
☐ Building badge returned
☐ Data-center badge returned
☐ Restricted-area card returned
☐ Physical keys returned
☐ Cabinet keys returned
☐ Server-room keys returned
☐ Parking access card returned
Physical Access Verification
☐ Physical access disabled
☐ Missing access card investigated
☐ Missing keys investigated
14. Removable Media
Identify organizational removable media.
☐ USB drives
☐ External hard drives
☐ Memory cards
☐ Backup media
☐ Encrypted media
☐ Other removable media
For each item:
☐ Returned
☐ Ownership verified
☐ Data protection requirements reviewed
☐ Encryption verified where applicable
☐ Data transfer requirements addressed
☐ Secure disposal required
15. Development Equipment
For engineering personnel:
☐ Development laptop returned
☐ Hardware development devices returned
☐ Test devices returned
☐ Development servers returned
☐ Hardware tokens returned
☐ Specialized equipment returned
☐ Source-code access revoked separately
☐ SSH keys/tokens addressed separately
Asset return does not replace access revocation.
16. Network and IT Equipment
Where applicable:
☐ Router
☐ Firewall appliance
☐ Network switch
☐ Access point
☐ Modem
☐ VPN device
☐ Network testing equipment
☐ Other IT equipment
Asset Details
| Asset | Asset ID | Returned | Condition | Verified |
|---|---|---|---|---|
| ☐ | ☐ | |||
| ☐ | ☐ |
17. Information Stored on Assets
Before reuse, disposal, or reassignment, determine whether the asset contains organizational information.
☐ Customer information
☐ Personal data
☐ Confidential information
☐ Restricted information
☐ Source code
☐ Credentials
☐ API keys
☐ Security information
☐ Business records
☐ Local backups
Information Assessment
Do not automatically erase a device if information may be required for a security investigation, legal requirement, regulatory obligation, or other approved retention requirement.
18. Device Security Assessment
After receiving a device:
☐ Device secured
☐ Device placed under organizational control
☐ Device encryption status checked
☐ Device management status checked
☐ Security software status checked
☐ Device condition recorded
☐ Suspicious activity considered
☐ Security incident suspected?
☐ Investigation required?
Security Concern
☐ No
☐ Yes — escalate to Information Security
19. Data Transfer
Where information must be retained:
☐ Business information identified
☐ Authorized owner identified
☐ Required files transferred
☐ Business records transferred
☐ Project files transferred
☐ Customer information transferred where appropriate
☐ Documentation transferred
☐ Ownership updated
Information should be transferred through approved methods.
20. Device Wipe and Reuse
Before reassignment:
☐ Data-retention requirements checked
☐ Investigation requirements checked
☐ Required information preserved
☐ Authorized wipe performed
☐ Device reset securely
☐ Storage securely erased where appropriate
☐ Corporate accounts removed
☐ Device management re-enrolled
☐ Security controls reconfigured
☐ Device ready for reassignment
Reuse Status
☐ Ready for reuse
☐ Requires repair
☐ Requires further security review
☐ Not suitable for reuse
21. Secure Disposal
If an asset will not be reused:
☐ Disposal authorized
☐ Data-retention requirements checked
☐ Investigation requirements checked
☐ Data securely erased where appropriate
☐ Storage media securely destroyed where required
☐ Disposal provider approved
☐ Disposal evidence obtained
☐ Asset register updated
Disposal Evidence
22. Lost or Missing Asset
If an asset cannot be returned:
☐ Missing asset identified
☐ Employee/contractor notified
☐ Manager notified
☐ IT notified
☐ Security notified where required
☐ Asset marked missing
☐ Remote-lock/wipe considered
☐ Credentials/access reviewed
☐ Security incident assessment performed
☐ Investigation initiated where appropriate
☐ Replacement process initiated
☐ Risk assessed
Missing Asset Details
23. Damaged Asset
If an asset is returned damaged:
☐ Damage documented
☐ Photographic evidence retained where appropriate
☐ Asset condition recorded
☐ Security implications assessed
☐ Data protection implications assessed
☐ Repair required
☐ Replacement required
☐ Management notified where appropriate
Damage Description
24. Remote Employee Asset Return
For remote employees:
☐ Return instructions provided
☐ Secure packaging provided where required
☐ Courier/collection arranged
☐ Tracking information recorded
☐ Asset received
☐ Serial number verified
☐ Device secured
☐ Data/security assessment completed
☐ Final receipt confirmed
Shipment Information
Courier: __________________________
Tracking Number: __________________
Dispatch Date: ____________________
Receipt Date: ______________________
25. Contractor and Supplier Personnel
For contractors and supplier personnel:
☐ Contract reviewed
☐ Assigned assets identified
☐ Supplier-owned assets distinguished
☐ Company-owned assets recovered
☐ Security devices recovered
☐ Physical access cards recovered
☐ Third-party access revoked separately
☐ Asset ownership updated
☐ Supplier notified of completion
26. Asset Ownership Transfer
If an asset is being reassigned:
☐ Previous custodian removed
☐ New custodian identified
☐ New custodian approved
☐ Asset condition recorded
☐ Security configuration verified
☐ Asset register updated
☐ New assignment acknowledged
New Custodian
Name: ______________________________
Employee ID: ________________________
Assignment Date: ____________________
27. Asset Condition
Classify returned assets.
☐ New/Excellent
☐ Good
☐ Fair
☐ Damaged
☐ Non-functional
☐ Security concern
☐ Requires disposal
Condition Notes
28. Asset Security During Storage
Returned assets awaiting processing should be protected.
☐ Secure storage location identified
☐ Physical access restricted
☐ Asset tagged
☐ Asset register updated
☐ Unauthorized access prevented
☐ Chain of custody maintained where required
29. Chain of Custody
Use chain-of-custody controls where the asset may contain sensitive information or evidence.
| Date/Time | Released By | Received By | Purpose | Location | Signature/Confirmation |
|---|---|---|---|---|---|
This is particularly important when an asset is associated with a security investigation.
30. Asset Return Verification
A responsible person should verify that the expected assets were returned.
☐ Asset inventory reconciled
☐ Serial numbers verified
☐ Missing assets identified
☐ Accessories reconciled
☐ Security devices reconciled
☐ Physical access items reconciled
☐ Device condition recorded
☐ Asset register updated
Verified By: __________________________
Verification Date: ____________________
31. Exceptions
Document any asset that could not be returned or any deviation from the process.
| Asset | Exception | Reason | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
Exceptions should be risk-assessed and approved according to the organization’s exception-management process.
32. Asset Return Evidence
Retain appropriate evidence such as:
☐ Asset register record
☐ Signed/confirmed return record
☐ Serial-number verification
☐ Courier receipt
☐ Tracking information
☐ Device condition record
☐ Disposal certificate
☐ Chain-of-custody record
☐ Missing-asset investigation
☐ Security assessment
☐ Asset reassignment record
Do not retain unnecessary passwords, private keys, API keys, or other credentials as evidence.
33. Asset Register Update
After completion:
☐ Previous custodian removed
☐ Asset status updated
☐ Asset location updated
☐ New custodian recorded
☐ Asset condition updated
☐ Disposal status recorded where applicable
☐ Missing status recorded where applicable
☐ Security status updated
☐ Asset lifecycle status updated
Asset Status
☐ In Storage
☐ Ready for Reuse
☐ Reassigned
☐ Under Repair
☐ Under Investigation
☐ Disposed
☐ Lost/Missing
☐ Other: __________________________
34. Asset Return Register
| Asset Return ID | Person | Asset ID | Return Date | Condition | Verified | Status |
|---|---|---|---|---|---|---|
| ☐ | ||||||
| ☐ |
35. Completion Criteria
The asset return should not be marked Complete until:
☐ All assigned assets have been identified
☐ Assets have been returned or an approved exception exists
☐ Asset identity has been verified
☐ Serial numbers have been reconciled
☐ Security devices have been recovered or revoked
☐ Physical access items have been returned
☐ Information protection requirements have been assessed
☐ Investigation requirements have been considered
☐ Device condition has been recorded
☐ Required data has been transferred
☐ Device has been securely processed before reuse/disposal
☐ Missing/damaged assets have been investigated
☐ Asset register has been updated
☐ Final verification has been completed
☐ Evidence has been retained
36. Final Approval
Employee/Contractor: ______________________________
Employee/Contractor ID: __________________________
Manager: _________________________________________
Asset Custodian: __________________________________
IT Representative: _________________________________
Security Reviewer: _________________________________
Return Date: ______________________________________
Completion Date: __________________________________
Status
☐ Complete
☐ Complete with Approved Exceptions
☐ Further Action Required
Comments
37. AWS SaaS Startup Example
A DevOps engineer leaves a SaaS startup.
The company has assigned:
- Laptop
- Hardware security key
- Mobile phone
- Company access card
- External monitor
- Development equipment
The laptop may contain:
- Source-code repositories
- AWS configuration
- Development files
- Customer-related information
- Security tools
Asset Return Process
1. HR/Manager → informs IT of the termination.
2. Asset Owner → identifies all assets assigned to the employee.
3. IT → receives the laptop, phone, security key, access card, and monitor.
4. Security → confirms access has been separately revoked.
5. Security/IT → checks whether the laptop is subject to investigation or evidence preservation.
6. IT → transfers required business information to the authorized owner.
7. IT → securely wipes and reconfigures the laptop after retention requirements are satisfied.
8. Asset Management → updates the asset register.
9. Reviewer → verifies that all assets are reconciled.
Audit Trail
Identify Assets → Notify → Recover → Verify → Protect Information → Secure Device → Update Register → Close
38. Startup-Friendly Asset Return Model
A startup can implement a simple process:
1. Check the Asset Register
Find everything assigned to the employee.
2. Recover
Collect:
- Laptop
- Phone
- Access card
- Security key
- USB drives
- Other company equipment
3. Verify
Check asset IDs and serial numbers.
4. Protect
Secure the device and assess information stored on it.
5. Transfer
Move required business information to the authorized owner.
6. Wipe or Preserve
Determine whether the device can be wiped, must be retained, or requires investigation.
7. Update
Update the asset register.
8. Close
Keep evidence of the return and final verification.
39. Common Mistakes
Avoid:
- Not maintaining an accurate asset register.
- Assuming the employee will return everything automatically.
- Forgetting chargers and accessories.
- Forgetting security keys and MFA devices.
- Forgetting access cards and physical keys.
- Forgetting removable media.
- Forgetting company-owned mobile phones.
- Failing to verify serial numbers.
- Wiping a laptop before checking investigation requirements.
- Transferring sensitive data through unapproved methods.
- Reassigning a device without securely processing it.
- Failing to investigate missing assets.
- Failing to revoke access when an asset is missing.
- Failing to update the asset register.
- Treating asset return as a replacement for access revocation.
- Failing to maintain disposal evidence.
40. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Asset Management Policy | Defines overall asset-management requirements |
| Asset Management Procedure | Defines asset lifecycle activities |
| Asset Register | Records organizational assets |
| Employee Offboarding Policy | Defines personnel offboarding requirements |
| Employee Termination Security Checklist | Coordinates termination security activities |
| Access Revocation Checklist | Removes associated access |
| Employee Role Change Checklist | Handles asset changes during role changes |
| Mobile Device Policy | Controls mobile devices |
| Endpoint Security Procedure | Defines endpoint-security requirements |
| Information Classification Policy | Protects information stored on assets |
| Secure Disposal Procedure | Controls asset/data disposal |
| Incident Response Procedure | Handles lost, stolen, or compromised assets |
| Evidence Preservation Procedure | Protects assets relevant to investigations |
| Supplier Offboarding Checklist | Handles supplier-owned/assigned assets |
| Corrective Action Tracker | Tracks unresolved asset findings |
41. ISO 27001 Connection
Asset return supports the organization’s management of information and associated assets, protection of information on devices, access revocation, secure disposal, personnel offboarding, and information-security risk management.
The Asset Return Checklist is not itself a universally mandatory ISO 27001 form. The organization should establish appropriate asset-return and asset-lifecycle controls based on:
- ISMS scope
- Risk assessment
- Asset types
- Information classification
- Personnel roles
- Device environment
- Legal and regulatory requirements
- Customer requirements
- Contractual requirements
- Business requirements
The organization should be able to demonstrate that assets remain under appropriate organizational control throughout their lifecycle.
42. Final Audit Checklist
☐ Asset return trigger documented
☐ Employee/contractor identified
☐ Asset register reviewed
☐ All assigned assets identified
☐ Laptop returned
☐ Mobile device returned
☐ Tablet/portable devices returned
☐ Security keys/tokens returned
☐ Access cards returned
☐ Physical keys returned
☐ Removable media returned
☐ Development equipment returned
☐ Network equipment returned where applicable
☐ Serial numbers verified
☐ Asset condition recorded
☐ Information stored on assets assessed
☐ Investigation requirements checked
☐ Business information transferred
☐ Device securely processed
☐ Data securely erased where authorized
☐ Disposal evidence obtained where applicable
☐ Missing assets investigated
☐ Damaged assets assessed
☐ Remote-return process documented
☐ Supplier/contractor assets addressed
☐ Asset ownership updated
☐ Asset register updated
☐ Exceptions documented
☐ Final verification completed
☐ Evidence retained
☐ Asset return closed
43. Final Audit Trail
For every significant asset return, the organization should be able to demonstrate:
What asset was assigned?
Who was responsible for the asset?
Why was the asset being returned?
When was it returned?
Was the asset identity and serial number verified?
Was the physical condition recorded?
Did the asset contain organizational information?
Was customer/personal/confidential information protected?
Were investigation requirements considered before wiping the device?
Were security keys and authentication devices recovered or revoked?
Were physical access cards and keys recovered?
Were missing or damaged assets investigated?
Was the device securely processed before reuse or disposal?
Was ownership updated?
Was the asset register updated?
Who verified the return?
Were exceptions documented and approved?
What evidence proves the asset was returned and secured?
Final Principle
Asset return is not complete when a device is physically handed back. It is complete when the asset is identified, recovered, secured, its information is appropriately protected, its ownership and status are updated, and completion is verified and recorded.
