Policy Register

Offboarding and termination procedure

The steps when someone leaves or changes role: access removed, assets returned, obligations that continue, and the record that it was done.

How the register reads it

Also calledleavers procedure, exit checklist
FamilyPeople
Document typeProcedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the hr security policy (joiners, movers, leavers); when neither is listed, the gap is counted once, under the parent.
Expected ownerThe head of HR.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, hr security policy (joiners, movers, leavers), is).
TemplateOffboarding policy.

Which standards require it, and what each expects it to contain

3 requiring clauses, 1 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 6.5 Responsibilities after termination or change of employment

Define and enforce security responsibilities that remain valid after an exit or role change.

What the ISO 27002 guidance expects the document to say: Requires the security duties and responsibilities that survive the end of employment, or a move to a different role, to be defined, communicated to the people concerned and enforced.

Evidence an auditor accepts: Documented responsibilities that remain in force after employment ends or after a change of role, such as confidentiality and non disclosure; evidence these were communicated to the individual at the point of departure or change, with acknowledgement; the leaver and mover procedure showing the security steps and their completion within a defined timeframe
Common gap: Delayed revocation of privileged accounts
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.11 Return of assets

Recover all organizational assets on exit or role change.

What the ISO 27002 guidance expects the document to say: Requires personnel and other relevant interested parties to return all organisational assets in their possession when employment, a contract or an agreement changes or ends.

Evidence an auditor accepts: The leaver and role change procedure showing asset return as a mandatory step; the checklist or ticket used per departure, listing assets issued to that person from the inventory; signed confirmation of return, and records for assets not returned including the escalation taken
Common gap: Missing signatures on return forms
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.18 Access rights

Provision, review, modify and remove access rights in line with the access control policy.

What the ISO 27002 guidance expects the document to say: Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.

Evidence an auditor accepts: Provisioning records showing the authorisation behind each access grant, tied to the access control rules; modification records where access changed after a role change, showing removal of the previous entitlements; removal records on termination, with the date of removal against the date of departure
Common gap: Reviews lack documented corrective actions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

HR security policy (joiners, movers, leavers) · Remote working policy