On this page
- Quick Reference (60 Seconds)
- What the Standard Actually Requires
- Why Termination Responsibilities Matter
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Controls
- Implementation Roadmap (Week-by-Week)
- Detailed Implementation Guidance
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls and How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Regulatory and Industry Context
- Roles and Responsibilities (RACI)
- Documentation and Evidence Requirements
- Continuous Improvement
- FAQ
- References and Further Reading
Quick Reference (60 Seconds)
| Attribute | Detail |
|---|---|
| Control ID | A.6.5 |
| Title | Responsibilities after Termination or Change of Employment |
| Objective | Ensure information security responsibilities continue after employment ends or changes |
| Domain | People |
| ISO 27001:2022 Clause | Annex A.6.5 |
| What You Must Do | Define, communicate, and enforce security responsibilities that survive employment termination or role change |
| Owner | HR / CISO / Legal |
| Maturity Level 1 | No post-employment obligations; informal return of assets |
| Maturity Level 2 | Basic exit checklist; some asset return; no formal obligations |
| Maturity Level 3 | Formal exit procedure; asset return; access revocation; post-employment obligations in contract; NDA enforcement |
| Maturity Level 4 | Automated access revocation; asset tracking; exit interviews; 30-60-90 day monitoring; legal enforcement; role change automation |
| Maturity Level 5 | Predictive exit analytics; continuous post-employment monitoring; AI-driven insider threat detection; blockchain asset provenance; automated legal enforcement; zero-defect exit |
What the Standard Actually Requires
ISO 27001:2022 Control Text
Annex A 6.5 asks organizations to define, communicate, and enforce the security responsibilities that remain after employment ends or changes.
Implementation Guidance (ISO 27002:2022)
- The organization should define responsibilities that continue after termination:
- Return of organizational assets (devices, data, documents, credentials)
- Confidentiality obligations (NDA, trade secrets, customer data)
- IP obligations (assignments, inventions, code)
- Non-compete and non-solicitation (where legally enforceable)
- Non-disparagement
- Communication restrictions (no contact with customers/employees)
- Data deletion obligations (personal devices, cloud accounts)
- For role changes, responsibilities should include:
- Access rights adjustment (remove old, add new)
- Asset reassignment (return old, receive new)
- Training update (new role security training)
- Confidentiality scope change (new data access = new obligations)
- Communication should occur before termination/change and at exit
- Enforcement should include legal remedies, monitoring, and contractual penalties
- Legal compliance should be maintained (Indian labor law, DPDP, contract law)
- The process should be fair and respect employee rights
"Shall" vs "Should" Analysis
- Shall: Defining, communicating, and enforcing post-employment obligations is mandatory
- Should: Specific obligations, methods, and enforcement mechanisms are flexible based on context
Common Misinterpretations
| Misinterpretation | Reality |
|---|---|
| "Once an employee leaves, we have no control" | Contractual obligations survive termination; legal enforcement is possible; monitoring can detect violations |
| "NDAs are unenforceable in India" | NDAs are enforceable in India for trade secrets and confidential information; courts enforce reasonable restrictions |
| "We only need exit procedures for terminations" | Role changes also require access adjustment, asset reassignment, and obligation updates |
| "Remote employees don't need to return assets" | Remote employees must return all organizational assets, including devices, data, and credentials |
| "Post-employment obligations are only for senior staff" | All employees with access to information should have post-employment obligations |
| "We can keep personal data of ex-employees indefinitely" | DPDP Act 2023 requires data deletion after purpose is fulfilled; retention must be justified |
Why Termination Responsibilities Matter
The Business Risk Narrative
Post-employment security failures are a major source of data breaches and insider threats:
- 70% of Indian organizations have no formal exit security procedure (Source: Data Security Council of India)
- 25% of data breaches involve former employees (Source: Verizon DBIR)
- Average impact of insider threat involving former employee: -3.5 crore
- Organizations with formal exit procedures: 60% fewer post-employment security incidents
- 43% of departing employees admit to taking confidential data (Source: Symantec Survey)
- 58% of Indian employees take company data when leaving for a competitor (Source: Kaspersky India)
- 30% of ex-employees retain access to former employer systems for days or weeks after departure
- DPDP Act 2023: Organizations must delete personal data when purpose is fulfilled; retention of ex-employee data must be justified
- -200 lakh in legal overhead for trade secret misappropriation litigation in India
- Reputational damage from ex-employee data theft: 35-45% customer trust reduction
- impact of implementing exit security program: -8 lakh (one-time) + -2 lakh/year (maintenance)
- ROI: 15-25x (prevention of breaches + IP protection + legal overhead avoidance)
Regulatory Landscape in India
| Regulation | Post-Employment Requirement | Penalty for Non-Compliance |
|---|---|---|
| DPDP Act 2023 | Delete personal data when purpose fulfilled; retention must be justified | Up to |
| IT Act 2000 (Section 43A) | Reasonable security includes exit procedures | Compensation claims |
| Indian Contract Act 1872 | Contractual obligations (NDA, IP assignment) survive termination | Breach of contract damages |
| Companies Act 2013 | Director resignation and continuing obligations; disqualification | Director liability |
| Industrial Disputes Act 1947 | Full and final settlement; exit procedures for workmen | Labor disputes, reinstatement |
| Trade Secrets | Common law and contract protection of trade secrets | Civil damages, injunctions |
| Copyright Act 1957 | Copyright assignment and post-employment obligations | Copyright infringement |
| Patents Act 1970 | Employee inventions and assignment | Patent disputes |
| RBI Cyber Security Framework | Employee exit procedures for banking systems | License restrictions |
| SEBI Cybersecurity Circular | Access revocation for departing employees | Trading restrictions |
| IRDAI Guidelines | Exit procedures for insurance data access | License suspension |
| POSH Act 2013 | Continuing obligations for POSH violations | Employer liability |
| Official Secrets Act 1923 | Continuing secrecy obligations for classified information | Criminal prosecution |
Industry-Specific Consequences
| Industry | Post-Employment Failure Scenario |
|---|---|
| BFSI | Bank employee leaves with customer list; joins competitor; solicits customers; RBI audit failure; customer lawsuit |
| SaaS / B2B | Developer leaves with source code; starts competing product; customer data breach; DPDP penalty; IP litigation |
| Healthtech | Doctor leaves with patient database; joins competitor; privacy breach; CDSCO action; patient lawsuit |
| E-commerce | Category manager leaves with vendor licensing data; joins competitor; undercuts licensing; revenue loss |
| Manufacturing | Engineer leaves with proprietary designs; joins competitor; OEM contract loss; patent dispute |
| Government | Officer leaves with classified data; leaks to media; Official Secrets Act prosecution; national security breach |
| Telecom | Engineer leaves with network architecture; joins competitor; competitive intelligence loss; DOT action |
| Education | Professor leaves with research data; joins competitor institution; IP dispute; student data breach |
| Pharma | Scientist leaves with drug formula; joins competitor; patent dispute; regulatory action; product delay |
| Consulting | Consultant leaves with client deliverables; reuses for competitor; client breach; professional liability |
impact of Non-Compliance Statistics
- Organizations without exit security procedures: 3x more likely to have post-employment data breaches
- Average impact of a post-employment data breach: -3.5 crore
- impact of IP theft by ex-employee: -50 crore (depending on IP value)
- impact of a single trade secret misappropriation lawsuit: -200 lakh in legal fees
- impact of customer list theft by ex-employee: -10 crore in lost revenue
- impact of implementing exit security program: -8 lakh one-time
- ROI: 15-25x (breach prevention + IP protection + legal overhead avoidance)
- Organizations with automated access revocation: 80% fewer unauthorized access incidents post-employment
- Organizations with asset tracking: 70% fewer unreturned asset incidents
- Organizations with exit interviews: 50% fewer surprise security incidents
Scope and Applicability
What the Control Covers
- Termination exit procedures: Voluntary resignation, involuntary termination, retirement, end of contract, death, disability
- Role change procedures: Promotion, demotion, transfer, lateral move, temporary assignment, return from leave
- Asset return: All organizational assets (devices, data, documents, credentials, access cards, keys)
- Access revocation: All system access, accounts, privileges, VPN, remote access, cloud access
- Post-employment obligations: NDA, confidentiality, IP assignment, non-compete, non-solicitation, non-disparagement
- Data obligations: Deletion of organizational data from personal devices and accounts
- Exit interviews: Security-focused exit interviews and compliance reminders
- Communication: Reminding departing employees of continuing obligations
- Enforcement: Legal remedies, monitoring, and contractual penalties for violations
- Full and final settlement: Settlement processing contingent on compliance
- Post-employment monitoring: Detecting violations of continuing obligations
- Data retention: Managing ex-employee data under DPDP requirements
- Knowledge transfer: Ensuring continuity of critical knowledge and access
Who It Applies To
| Role | Responsibility |
|---|---|
| HR | Exit procedure coordination, exit interview, full and final settlement, contractual obligation management, communication |
| CISO | Access revocation, security assessment, device wiping, data recovery, security incident investigation, post-employment monitoring |
| IT | Account deactivation, device collection, data backup, access log review, technical exit checklist |
| Legal | NDA enforcement, contract review, litigation, trade secret protection, DPDP compliance for ex-employee data |
| Line Manager | Knowledge transfer planning, asset identification, project handover, replacement planning, performance reference |
| Finance | Full and final settlement, access card/loan recovery, outstanding dues |
| Compliance | Exit compliance checklist, audit evidence, DPDP data deletion verification |
| Employee | Returning assets, deleting data, complying with obligations, participating in exit process, knowledge transfer |
| Security Team | Access revocation verification, device forensics, data recovery, incident investigation |
| Facilities | Access card collection, parking pass, locker clearing, physical access revocation |
| Procurement/Admin | Asset inventory update, asset reassignment, new asset procurement for replacement |
What It Does NOT Cover
- General HR exit procedures (payroll, benefits, gratuity), covered by HR
- Labor dispute resolution, covered by Legal and labor law
- Criminal prosecution for data theft, covered by Law Enforcement
- Civil litigation for breach of contract, covered by Legal
- General employee onboarding, covered by HR (though role change is covered here)
Size-Based Applicability
| Organization Size | Approach |
|---|---|
| Startups (< 50) | Simple exit checklist (10-15 items); asset return; access revocation within 24 hours; basic NDA reminder |
| SMB (50-500) | Formal exit procedure; asset tracking; access revocation within 24 hours; exit interview; 30-day monitoring |
| Mid-market (500-5000) | Complete exit procedure; automated access revocation; asset inventory; exit interview; 60-90 day monitoring; NDA enforcement |
| Enterprise (5000+) | Enterprise exit framework; automated lifecycle management; predictive analytics; post-employment monitoring; legal enforcement; global consistency |
Key Definitions and Terminology
| Term | Definition | Source |
|---|---|---|
| Termination | End of employment relationship, whether voluntary or involuntary | Employment Law |
| Role Change | Change in job role, department, or responsibilities within the organization | HR Management |
| Exit Procedure | Formal process for managing an employee's departure from the organization | HR Practice |
| Full and Final Settlement | Process of settling all dues and obligations upon employment termination | HR Practice |
| Post-Employment Obligations | Legal and contractual duties that continue after employment ends | Contract Law |
| Non-Disclosure Agreement (NDA) | Contract prohibiting disclosure of confidential information | Contract Law |
| Non-Compete Agreement | Contract restricting employment with competitors (limited enforceability in India) | Contract Law |
| Non-Solicitation Agreement | Contract restricting solicitation of customers or employees | Contract Law |
| IP Assignment Agreement | Contract transferring intellectual property rights to employer | IP Law |
| Trade Secret | Information that derives economic value from being kept secret | Trade Secret Law |
| Confidential Information | Information that is not public and should be kept secret | Contract Law |
| Access Revocation | Removal of system access, accounts, and privileges | IT Security |
| Asset Return | Return of organizational property (devices, documents, cards) | HR Practice |
| Exit Interview | Structured interview with departing employee | HR Practice |
| Knowledge Transfer | Process of transferring critical knowledge before departure | HR Practice |
| Post-Employment Monitoring | Monitoring for violations of continuing obligations | Security Practice |
| Data Deletion | Removal of organizational data from personal devices and accounts | DPDP Compliance |
| Work For Hire | Doctrine that employer owns IP created by employee | Copyright Law |
| Garden Leave | Period where departing employee is paid but does not work (common in BFSI) | HR Practice |
| Notice Period | Period between resignation and last working day | Employment Contract |
| Settlement Agreement | Agreement resolving all claims upon termination | Legal Practice |
| Release of Claims | Employee waiving claims against employer | Legal Practice |
Relationship to Other Controls
Upstream Controls (Prerequisites)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.5.1 | Policies for Information Security | Security policy must define exit obligations before they can be enforced |
| A.6.1 | Screening | Screened employees must have contracts with post-employment obligations |
| A.6.2 | Terms and Conditions of Employment | Employment terms must include post-employment obligations and asset return clauses |
| A.6.3 | Information Security Awareness | Employees must know obligations before they can be reminded at exit |
| A.6.4 | Disciplinary Process | Disciplinary action for violations during employment triggers exit procedures |
| A.6.6 | Confidentiality Agreements | NDA must exist to be enforced post-employment |
| A.6.7 | Remote Working | Remote workers have additional assets to return (home office equipment) |
Downstream Controls (Enabled By)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.8.1 | User Endpoint Devices | Device return and wipe at exit |
| A.8.2 | Privileged Access Rights | Revocation of privileged access at exit |
| A.8.9 | Inventory of Assets | Asset inventory enables tracking what must be returned |
| A.8.10 | Information Deletion | Deletion of data from returned devices |
| A.8.15 | Logging | Logs enable post-employment monitoring and incident investigation |
| A.8.16 | Monitoring Activities | Monitoring detects post-employment violations |
| A.8.28 | Secure Disposal of Information | Secure disposal of data from returned devices |
Parallel Controls (Work Alongside)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.5.21 | Information Security in Supplier Relationships | Vendor personnel exit procedures |
| A.5.22 | Monitoring and Review | Reviews include exit procedure effectiveness |
| A.8.12 | Data Leakage Prevention | DLP detects data exfiltration before departure |
| A.8.24 | Use of Cryptography | Encryption of data on returned devices |
| A.8.20 | Networks Security | Network access revocation at exit |
| A.5.35 | Intellectual Property Rights | IP assignment and post-employment obligations |
| A.5.37 | Privacy and Protection of PII | DPDP compliance for ex-employee data |
Implementation Roadmap (Week-by-Week)
Phase 1: Discovery & Assessment (Weeks 1-2)
Week 1: Current Exit Process Assessment
- Deliverable: Current exit process maturity assessment
- Owner: HR + CISO + IT + Legal
- Activities:
- Map current exit process (what happens when someone resigns or is terminated)
- Assess access revocation process (how long, how thorough, what systems)
- Assess asset return process (what assets, how tracked, how verified)
- Review past exits for security gaps (unreturned assets, lingering access, data breaches)
- Assess NDA and post-employment obligations in contracts
- Interview departing employees about exit experience (recent exits)
- Assess exit interview process (security focus, obligation reminder)
- Review full and final settlement process (security compliance as condition)
- Assess post-employment monitoring (any detection of violations)
- Benchmark against industry practices and ISO 27001 requirements
Week 2: Risk and Gap Analysis
- Deliverable: Exit security gap analysis report
- Owner: HR + CISO + IT + Legal + Compliance
- Activities:
- Map all systems and access that departing employees have
- Identify systems where access is not revoked promptly
- Identify unreturned assets from past exits
- Identify ex-employees with lingering access
- Assess data exfiltration risk (DLP, logs, monitoring)
- Map contractual obligations (NDA, IP, non-compete) and enforceability
- Assess DPDP compliance for ex-employee data retention
- Identify role change gaps (access not adjusted on promotion/transfer)
- Define target state for exit security maturity
- Create gap closure plan
Phase 2: Design & Planning (Weeks 3-4)
Week 3: Exit Procedure Design
- Deliverable: Draft Exit Security Procedure + Checklists + Templates
- Owner: HR + CISO + IT + Legal
- Activities:
- Design exit trigger process (resignation, termination, contract end, role change)
- Design notice period security management (access restriction during notice period)
- Create exit security checklist (access, assets, data, obligations)
- Design access revocation workflow (what systems, timeline, verification)
- Design asset return workflow (inventory, collection, verification, reassignment)
- Design data deletion verification (personal devices, cloud accounts, email)
- Design exit interview process (security focus, obligation reminder, feedback)
- Design full and final settlement workflow (security compliance as condition)
- Design post-employment monitoring process (detection, investigation, enforcement)
- Design role change procedure (access adjustment, asset reassignment, training)
- Create documentation templates (exit checklist, clearance certificate, NDA reminder)
- Design automation for access revocation and asset tracking
Week 4: Contract and Legal Framework Design
- Deliverable: Contract Templates + Legal Enforcement Framework + DPDP Compliance Plan
- Owner: Legal + HR + CISO
- Activities:
- Review existing employment contracts for post-employment obligations
- Draft NDA addendum for existing employees without adequate NDA
- Draft IP assignment clause for employment contracts
- Draft non-compete clause (within legal limits in India)
- Draft non-solicitation clause for customers and employees
- Draft data deletion obligation clause
- Draft post-employment monitoring consent clause (within DPDP limits)
- Create legal enforcement framework (breach notice, litigation, injunction)
- Design DPDP compliance for ex-employee data (retention, deletion, justification)
- Create settlement agreement template with security terms
- Design garden leave policy for critical roles (BFSI, senior execs)
- Review for compliance with Indian labor law (ID Act, notice period, gratuity)
Phase 3: Implementation (Weeks 5-8)
Week 5: Contract Rollout
- Deliverable: All employees have post-employment obligations in contracts
- Owner: HR + Legal
- Activities:
- Roll out NDA addendum to all employees without adequate NDA
- Update employment contracts for new hires with complete post-employment clauses
- Obtain signed acknowledgments from all employees
- Track completion rate (target: 100%)
- Create contract repository with version control
- Train managers on new contract requirements
- Create employee FAQ on post-employment obligations
Week 6: Exit Procedure Implementation
- Deliverable: Exit procedure operational for all exits
- Owner: HR + CISO + IT
- Activities:
- Publish formal exit security procedure
- Create exit security checklist (paper or digital)
- Implement access revocation workflow (manual or automated)
- Create asset return process with verification
- Create data deletion verification process
- Implement exit interview with security focus
- Create clearance certificate (security clearance)
- Link full and final settlement to security clearance
- Train HR and managers on exit procedure
- Process first exit with new procedure (test case)
Week 7: Automation and Tools
- Deliverable: Automated access revocation and asset tracking operational
- Owner: IT + CISO + HR
- Activities:
- Configure automatic access revocation in IAM/AD upon HR trigger
- Integrate HRIS with IT ticketing for exit notifications
- Implement asset tracking system (barcode/RFID)
- Configure DLP monitoring for departing employees (30-day pre-exit monitoring)
- Set up post-employment monitoring alerts (email forwarding, account access attempts)
- Create automated exit report (all access revoked, assets returned, clearance status)
- Test automation with mock exit scenario
- Train IT staff on automated exit workflow
Week 8: Role Change Procedure Implementation
- Deliverable: Role change security procedure operational
- Owner: HR + CISO + IT
- Activities:
- Create role change security checklist (access removal, access addition, training)
- Implement role change trigger in HRIS (promotion, transfer, lateral move)
- Create role-based access control (RBAC) matrix for role changes
- Implement automated access adjustment upon role change
- Create asset reassignment process (return old, receive new)
- Implement role change training requirement (security training for new role)
- Create role change documentation template
- Test with first role change
Phase 4: Testing & Validation (Weeks 9-10)
Week 9: Process Testing
- Deliverable: Process validation report with mock scenarios
- Owner: HR + Internal Audit + CISO + IT
- Activities:
- Test voluntary resignation exit (full procedure)
- Test involuntary termination exit (rapid procedure)
- Test role change (promotion with access change)
- Test contract end exit (temporary staff)
- Test remote worker exit (home device return)
- Test access revocation verification (all systems checked)
- Test asset return verification (all assets accounted for)
- Test data deletion verification (personal device scan)
- Test exit interview process (security questions, obligation reminder)
- Test full and final settlement linkage (security clearance as condition)
- Test post-employment monitoring (detection of violations)
Week 10: Compliance and Audit Validation
- Deliverable: Compliance validation report
- Owner: Legal + Compliance Manager + HR
- Activities:
- Validate contract enforceability (Legal review)
- Verify DPDP compliance for ex-employee data handling
- Verify labor law compliance (notice period, gratuity, full and final settlement)
- Test NDA enforcement mechanism (breach notice template)
- Verify access revocation for all past exits (last 90 days)
- Verify asset return for all past exits (last 90 days)
- Verify exit interview completion rate
- Verify clearance certificate issuance rate
- Prepare compliance evidence package
- Conduct internal audit of exit security procedure
Phase 5: Documentation & Certification Prep (Weeks 11-12)
Week 11: Documentation
- Deliverable: Complete exit security documentation
- Owner: HR + Compliance Manager
- Activities:
- Document all policies, procedures, and checklists
- Create illustrative scenarios and examples (anonymized)
- Create training materials for managers and HR
- Create employee FAQ on exit security
- Create metrics dashboard and reporting templates
- Create evidence repository for audits
- Document automation configuration and workflows
Week 12: Certification Readiness
- Deliverable: Audit-ready evidence package
- Owner: CISO + Compliance Manager
- Activities:
- Conduct internal audit of exit security procedure
- Prepare evidence for external ISO 27001 auditor
- Remediate any gaps found
- Conduct management review
- Present program to certification body
Detailed Implementation Guidance
Step-by-Step Implementation
Step 1: Define Exit Triggers
| Trigger Type | Description | Security Impact | Procedure |
|---|---|---|---|
| Voluntary Resignation | Employee resigns with notice | Medium (time to plan, but risk of data exfiltration during notice period) | Standard exit procedure; 30-day monitoring during notice period |
| Involuntary Termination | Employee terminated by employer | High (immediate termination, potential retaliation) | Rapid exit procedure; immediate access revocation; escorted exit; asset collection; no notice period access |
| Contract End | Contract/temporary employee contract ends | Medium (planned but may have same access as permanent) | Standard exit procedure; ensure all assets returned |
| Retirement | Employee retires | Low (usually planned, less risk) | Standard exit procedure; knowledge transfer emphasis; ensure all obligations communicated |
| Death | Employee dies | Low (no malicious intent, but data recovery needed) | Data recovery and transfer; asset collection from family; legal compliance |
| Disability / Medical Leave | Employee unable to continue | Medium (access may be needed for long time) | Access suspension (not revocation) during leave; reassessment upon return |
| Role Change | Employee changes role within organization | High (old access may not be removed, new access added) | Access adjustment procedure; remove old, add new; asset reassignment; training update |
| Suspension | Employee suspended pending investigation | High (access must be suspended immediately) | Immediate access suspension; asset return may be delayed; monitoring |
| Garden Leave | Employee paid but not working during notice period | Medium (no access, but still employed) | All access revoked; no physical access; monitoring for violations |
Step 2: Create Exit Security Checklist
Access Revocation Checklist:
- Active Directory / LDAP account disabled
- Email account disabled or forwarded (with monitoring)
- VPN access revoked
- Remote desktop access revoked
- Cloud accounts (AWS, Azure, GCP) access revoked
- SaaS application access revoked (CRM, ERP, HRIS, etc.)
- Database access revoked
- Code repository access revoked (GitHub, GitLab, Bitbucket)
- CI/CD pipeline access revoked
- Monitoring and admin tool access revoked
- Wi-Fi access revoked
- Physical access card deactivated
- Parking pass collected
- Biometric access deactivated
- Security alarm codes changed
- Shared accounts password changed (if employee knew them)
- API keys and tokens revoked
- SSH keys removed from servers
- SSL certificates and encryption keys transferred
- Mobile device management (MDM) account wiped/removed
- Collaboration tools (Slack, Teams, Confluence) access revoked
- Social media admin access revoked (if applicable)
- Customer portal admin access revoked
- Vendor portal access revoked
- Third-party service access revoked (where employee was admin)
Asset Return Checklist:
- Laptop/desktop returned
- Mobile phone/tablet returned
- Monitor(s) returned
- Keyboard, mouse, docking station returned
- External hard drives returned
- USB drives returned
- Access card returned
- ID badge returned
- Keys returned (office, server room, cabinet, safe)
- Company vehicle returned (if applicable)
- Company credit card returned
- Security tokens, smart cards, RSA tokens returned
- Printed documents returned (or securely destroyed)
- Company data on personal devices verified deleted
- Cloud storage (personal accounts) verified no company data
- Email forwarding rules removed (if any were set up)
- Personal belongings cleared from workspace
- Home office equipment returned (if remote worker)
- Customer gifts, samples, promotional materials returned
- Proprietary tools, software licenses returned
- Uniforms, safety equipment returned (if applicable)
Data and Security Checklist:
- Data backup from employee devices completed
- Device wiped and reimaged (if returning to asset pool)
- Forensic image taken (if termination for cause)
- Email archive preserved for legal/compliance
- Personal data on company devices identified and separated
- DLP scan of recent activity (30-90 days pre-exit)
- Log review for suspicious activity (30-90 days pre-exit)
- Customer data handling verified (no unauthorized copies)
- IP and code repository access verified revoked
- Confidential documents verified not in personal email/cloud
- Social media posts reviewed (no confidential information shared)
- Personal accounts used for work (Shadow IT) identified and addressed
- Collaboration tool content (Slack, Teams) archived
- Project files and knowledge documents transferred
- Password manager access revoked (company vault)
Obligations Reminder Checklist:
- NDA obligations explained and signed acknowledgment
- IP assignment obligations explained
- Non-compete obligations explained (if applicable)
- Non-solicitation obligations explained (customers and employees)
- Non-disparagement obligations explained
- Data deletion obligations explained (personal devices)
- Return of confidential information obligations explained
- Continuing cooperation obligations explained (if applicable)
- Legal consequences of breach explained
- Contact information for legal/HR provided for questions
- Signed exit acknowledgment form obtained
Full and Final Settlement Checklist:
- Security clearance obtained (all checklists complete)
- Outstanding dues calculated
- Asset recovery overhead calculated (if unreturned)
- Gratuity processed (if applicable)
- PF/ESI processed
- Tax documents (Form 16) provided
- Relieving letter issued
- Experience certificate issued
- Reference contact provided (if positive reference)
- Settlement agreement signed (if applicable)
- Final payment processed
- Exit survey completed (optional)
Step 3: Implement Access Revocation
Timeline for Access Revocation:
| System Type | Voluntary Resignation | Involuntary Termination | Role Change |
|---|---|---|---|
| Critical systems (admin, finance, customer data) | Day of notice | Immediate | Within 4 hours |
| Standard systems (email, CRM, ERP) | Last working day | Immediate | Within 24 hours |
| Development systems (code repo, CI/CD) | Last working day | Immediate | Within 4 hours |
| Physical access | Last working day | Immediate | Within 24 hours |
| VPN/Remote access | Last working day | Immediate | Within 4 hours |
| Cloud admin | Day of notice | Immediate | Within 4 hours |
| Shared accounts | Last working day | Immediate (change password) | Within 24 hours |
| Third-party services | Last working day | Immediate | Within 48 hours |
Access Revocation Process:
- HR triggers exit in HRIS (resignation date, termination date, role change date)
- HRIS auto-generates IT ticket for access revocation
- IT disables access in identity management system (AD, LDAP, SSO)
- IT revokes access in all connected systems (automated or manual)
- IT verifies revocation (test login attempts, review access logs)
- Security team reviews logs for recent suspicious activity (30-90 days)
- IT updates asset inventory (device assignment removed)
- Facilities deactivates physical access
- HR verifies all revocations complete before clearance certificate
Step 4: Implement Asset Return
Asset Return Process:
- HR notifies employee of asset return requirements upon resignation/termination
- Employee returns all assets to IT/Admin on last working day
- IT/Admin verifies asset condition and functionality
- IT/Admin updates asset inventory (returned, condition noted)
- IT wipes data from devices (if returning to pool) or creates forensic image (if termination for cause)
- IT returns personal data to employee (if found on company device)
- Finance verifies no outstanding asset loans or charges
- If assets are missing, HR/Finance deducts overhead from full and final settlement (with legal compliance)
- Asset reassigned or disposed of per A.8.9 and A.8.28
Step 5: Implement Data Deletion Verification
Data Deletion Process:
- Employee signs data deletion affidavit (affirming no company data on personal devices)
- IT provides data deletion guidance (how to delete from personal devices, cloud accounts, email)
- For high-risk exits, IT may request device scan or remote wipe (if BYOD with MDM)
- DLP scan confirms no recent data exfiltration to personal accounts
- Email forwarding rules checked and removed
- Personal cloud storage (Google Drive, Dropbox) checked for company data (if employee consented to scan)
- Personal email accounts checked for company data (if employee consented to scan)
- Social media checked for confidential information (if applicable)
Step 6: Implement Exit Interview with Security Focus
Exit Interview Security Questions:
- Do you understand that your NDA obligations continue after employment?
- Have you returned all company assets, including devices, documents, and access cards?
- Have you deleted all company data from your personal devices and accounts?
- Have you removed company email access from your personal phone?
- Do you have any company information in your personal email, cloud storage, or devices?
- Are you aware that taking company confidential information is a breach of contract and may be illegal?
- Have you shared any company confidential information with anyone outside the organization?
- Do you know who to contact if you have questions about your post-employment obligations?
- Have you been approached by anyone to share company information?
- Are you joining a competitor? If so, do you understand your non-compete and non-solicitation obligations?
Exit Interview Reminders:
- Remind employee of NDA obligations and legal consequences of breach
- Remind employee of IP assignment obligations
- Remind employee of non-solicitation obligations (customers and employees)
- Remind employee of data deletion obligations
- Provide contact information for legal questions
- Provide copy of NDA and relevant contract clauses
- Document that obligations were communicated and acknowledged
Step 7: Implement Full and Final Settlement Linkage
Security Clearance as Condition:
- Full and final settlement is processed only after security clearance is obtained
- Security clearance requires:
- All assets returned (or overhead deducted)
- All access revoked
- Exit interview completed with obligation acknowledgment
- No outstanding security issues (suspicious activity, data breach)
- If security issues are found, settlement may be withheld pending resolution (within legal limits)
- Legal review required before withholding settlement (compliance with labor law)
- Gratuity cannot be withheld for security issues (Payment of Gratuity Act)
- PF cannot be withheld for security issues (EPF Act)
- Salary for worked days can be adjusted for asset recovery (with legal compliance)
Step 8: Implement Post-Employment Monitoring
Post-Employment Monitoring Activities:
- Monitor email forwarding rules (if any were set up before exit)
- Monitor for login attempts using old credentials (triggered alerts)
- Monitor for data exfiltration patterns in the 90 days before exit (DLP review)
- Monitor social media for confidential information sharing (if applicable)
- Monitor for contact with customers/employees by ex-employee (if non-solicitation)
- Monitor for new product/competitor launch by ex-employee using company IP (if IP assignment)
- Monitor for job change to competitor (if non-compete applies)
- Legal action if violations detected (breach notice, injunction, litigation)
Monitoring Duration:
- Standard: 90 days post-exit
- High-risk (senior, technical, customer-facing): 180 days
- Critical (C-suite, founders, key technical personnel): 365 days or ongoing (within legal limits)
Step 9: Implement Role Change Procedure
Role Change Security Process:
- HR triggers role change in HRIS (old role, new role, effective date)
- HRIS auto-generates IT ticket for access adjustment
- IT removes access for old role (per old role access matrix)
- IT adds access for new role (per new role access matrix)
- IT verifies no excess access (only new role access, no old role access)
- Employee returns old role assets (if applicable)
- Employee receives new role assets (if applicable)
- Employee completes security training for new role (if required)
- Manager verifies knowledge transfer from old role
- Security team verifies access adjustment in next review cycle
Step 10: Implement Contractual Obligations
Employment Contract Obligations:
- NDA: Employee agrees not to disclose confidential information during and after employment
- IP Assignment: Employee agrees that all work product is owned by employer
- Non-Compete: Employee agrees not to work for competitor for limited period (reasonable in scope, geography, duration, limited enforceability in India)
- Non-Solicitation: Employee agrees not to solicit customers or employees for limited period
- Non-Disparagement: Employee agrees not to disparage employer
- Data Deletion: Employee agrees to delete all company data from personal devices upon exit
- Return of Property: Employee agrees to return all company property upon exit
- Cooperation: Employee agrees to cooperate in legal proceedings (if applicable)
- Breach Penalties: Employee acknowledges legal consequences of breach (damages, injunction)
India-Specific Contract Considerations:
- Non-compete: Generally unenforceable in India for employment contracts (Section 27 of Indian Contract Act), but may be enforceable for sale of goodwill or during employment. Post-employment non-compete is usually void. Focus on non-solicitation and NDA instead.
- NDA: Enforceable for trade secrets and confidential information. Must be reasonable in scope and duration.
- IP Assignment: Enforceable for employee inventions created during employment. Must specify what is covered.
- Governing Law: Indian law; jurisdiction in Indian courts.
- Garden Leave: Valid if employer pays salary during notice period. All access can be revoked during garden leave.
Step 11: Implement Legal Enforcement
Enforcement Framework:
- Breach Detection: Monitoring detects suspected breach of post-employment obligations
- Evidence Collection: Gather evidence of breach (logs, screenshots, witness statements, competitive intelligence)
- Breach Notice: Send formal breach notice to ex-employee (cease and desist, damages, legal action)
- Settlement Negotiation: Attempt to resolve without litigation (return of information, damages, commitment)
- Injunction: If urgent, seek court injunction to stop breach (ex-parte injunction if necessary)
- Litigation: File civil suit for breach of contract, trade secret misappropriation, or copyright infringement
- Criminal Action: If theft, fraud, or Official Secrets Act violation, file police complaint
- Regulatory Action: If DPDP violation, report to DPB; if industry-specific, report to regulator
Step 12: Implement DPDP Compliance
Ex-Employee Data Management:
- Retention: Retain ex-employee data only for legal and compliance purposes (tax, labor law, legal claims)
- Deletion: Delete personal data when legal retention period expires (with legal justification)
- Justification: Document legal basis for retention (e.g., "retained for 7 years per Income Tax Act for TDS compliance")
- Access: Ex-employee has right to access their personal data under DPDP (if not exempted)
- Correction: Ex-employee can request correction of inaccurate personal data
- Grievance: Ex-employee can file grievance regarding their data
- DPO: Data Fiduciary must handle ex-employee data requests
- Security: Ex-employee data must be secured with same rigor as current employee data
Step 13: Implement Knowledge Transfer
Knowledge Transfer Process:
- Manager identifies critical knowledge and responsibilities of departing employee
- Manager identifies replacement or knowledge recipient
- Departing employee documents processes, procedures, and tribal knowledge
- Departing employee conducts handover sessions with replacement
- Departing employee provides access to all relevant files, documents, and systems
- Manager verifies knowledge transfer completeness
- Documentation archived for future reference
- Replacement trained on critical tasks before departure
Step 14: Implement Metrics and Reporting
- Track exit security clearance completion rate (target: 100%)
- Track access revocation timeline (target: <4 hours for critical, <24 hours for standard)
- Track asset return rate (target: 100%)
- Track missing assets (target: <2%)
- Track exit interview completion rate (target: 100%)
- Track post-employment monitoring alerts (trending)
- Track legal enforcement actions (trending down)
- Track role change access adjustment errors (target: <1%)
- Report quarterly to management and board
- Benchmark against industry data
Step 15: Continuous Improvement
- Annual review of exit security procedure
- Quarterly metrics review
- Annual contract review (NDA, IP, non-compete)
- Post-exit review of critical exits (lessons learned)
- Update for regulatory changes (DPDP, labor law, industry-specific)
- Benchmark against industry best practices
- Gather feedback from departing employees on exit process
- Update automation based on process changes
- Review and update role change access matrix
- Test post-employment monitoring effectiveness
Tools, Technologies, and Solutions
Complete Tool Comparison
| Tool | Category | Best For | licensing Range | Key Features | Integration |
|---|---|---|---|---|---|
| ServiceNow | ITSM/HR | Enterprise exit automation | + per year | Exit workflow, access revocation automation, asset tracking, case management | Full enterprise |
| BambooHR | HRIS | SMB exit management | + per year | Exit workflow, offboarding checklist, asset tracking, access management | 100+ integrations |
| Workday | HRIS | Enterprise HR | + per year | Exit management, role change, access management, compliance, analytics | Full enterprise |
| SAP SuccessFactors | HRIS | Enterprise HR | + per year | Exit management, offboarding, role change, access, compliance | SAP ecosystem |
| Zoho People | HRIS | Indian SMB | + per year | Exit checklist, offboarding, asset tracking, access management | Zoho ecosystem |
| GreytHR | HRIS | Indian SMB | + per year | Exit management, full and final settlement, compliance, Indian labor law | Indian compliance |
| Okta | IAM | Access revocation | + per year | SSO, automated access revocation, lifecycle management, MFA | 7,000+ integrations |
| Azure AD / Entra ID | IAM | Microsoft ecosystem | + per year | Identity lifecycle, automated provisioning/deprovisioning, conditional access | Microsoft ecosystem |
| Google Workspace | IAM | Google ecosystem | + per year | User lifecycle, access management, device management, vault | Google ecosystem |
| JumpCloud | IAM | SMB IAM | + per year | Directory, SSO, access management, device management, lifecycle | Multi-platform |
| OneLogin | IAM | Enterprise SSO | + per year | SSO, access management, lifecycle management, MFA | 6,000+ integrations |
| Microsoft Intune | MDM | Device management | + per year | Device enrollment, remote wipe, policy management, asset tracking | Microsoft 365 |
| VMware Workspace ONE | MDM | Enterprise device management | + per year | Device lifecycle, remote wipe, compliance, asset tracking | VMware ecosystem |
| Jamf | MDM | Apple device management | + per year | Apple device enrollment, remote wipe, policy management | Apple ecosystem |
| Google Endpoint Management | MDM | Google device management | + per year | Android device management, remote wipe, policy | Google Workspace |
| Symantec DLP | DLP | Data exfiltration detection | + per year | Endpoint DLP, network DLP, cloud DLP, exit monitoring | Enterprise |
| Forcepoint DLP | DLP | Enterprise DLP | + per year | Endpoint, network, cloud DLP, behavioral analytics | Enterprise |
| Microsoft Purview | DLP | Microsoft ecosystem | + per year | DLP, eDiscovery, compliance, monitoring, insider risk | Microsoft 365 |
| Proofpoint | DLP | Email and cloud DLP | + per year | Email DLP, cloud DLP, CASB, insider threat | Enterprise |
| Netskope | CASB | Cloud access and DLP | + per year | Cloud DLP, CASB, remote work security, shadow IT | Enterprise |
| ServiceNow Asset Management | Asset | Asset tracking | + per year | Asset lifecycle, inventory, tracking, return, reassignment | ServiceNow |
| Freshservice | ITSM | SMB asset and exit management | + per year | Asset management, exit workflow, ticket management, CMDB | Freshworks |
| Snipe-IT | Asset | Open-source asset tracking | Free | Asset inventory, check-in/check-out, barcode, reporting | Open-source |
| Lansweeper | Asset | IT asset discovery | + per year | Asset discovery, inventory, tracking, lifecycle management | Multi-platform |
| eDiscovery / Legal Hold | Legal | Evidence preservation | + per year | Legal hold, evidence preservation, eDiscovery, chain of custody | Legal, case management |
| Vault | Legal | Email and data hold | + per year | Email legal hold, evidence preservation, compliance | Google Workspace |
| Microsoft Purview eDiscovery | Legal | eDiscovery | + per year | eDiscovery, legal hold, compliance, data governance | Microsoft 365 |
| Contract Management | Legal | Contract repository | + per year | Contract repository, version control, obligation tracking, alerts | HR, legal |
| Ironclad | Legal | Contract lifecycle | + per year | Contract management, workflow, repository, analytics | Enterprise |
| DocuSign CLM | Legal | Contract management | + per year | Contract lifecycle, e-signature, repository, workflow | Enterprise |
| Veritas | Backup | Data backup and archive | + per year | Data backup, email archive, compliance, eDiscovery | Enterprise |
| Veeam | Backup | Data backup | + per year | Data backup, recovery, archive, compliance | Multi-platform |
| User Activity Monitoring | Monitoring | Insider threat detection | + per year | User activity monitoring, behavioral analytics, exit risk detection | Security |
| Teramind | Monitoring | Insider threat | + per year | User activity monitoring, DLP, behavioral analytics, forensics | Security |
| Splunk | SIEM | Log analysis and monitoring | + per year | Log analysis, security monitoring, incident detection, forensics | Enterprise |
| Elastic Security | SIEM | Open-source SIEM | Free / + | Log analysis, security monitoring, incident detection | Open-source |
| Carbon Black | EDR | Endpoint forensics | + per year | Endpoint detection, forensics, threat hunting, incident response | Security |
| CrowdStrike | EDR | Endpoint protection | + per year | EDR, threat hunting, forensics, incident response | Security |
| Varonis | Data Security | Data access monitoring | + per year | Data access monitoring, user behavior, threat detection, forensics | Enterprise |
| Proofpoint Insider Threat | Insider Threat | Insider threat detection | + per year | Insider threat detection, behavioral analytics, exit risk | Enterprise |
Recommendations by Organization Size
| Size | HRIS | IAM | MDM | DLP | Asset | Legal | Monitoring |
|---|---|---|---|---|---|---|---|
| Startup (<50) | BambooHR or Zoho | JumpCloud or Okta | Microsoft Intune or Google | Microsoft Purview | Snipe-IT | DocuSign | Microsoft Purview |
| SMB (50-500) | BambooHR | Okta or Azure AD | Microsoft Intune | Microsoft Purview or Forcepoint | Snipe-IT or Freshservice | DocuSign or Ironclad | Microsoft Purview or Splunk |
| Mid-market (500-5000) | Workday or SAP | Okta or Azure AD | VMware or Intune | Symantec or Forcepoint | ServiceNow or Lansweeper | Ironclad or DocuSign | Splunk or Elastic |
| Enterprise (5000+) | Workday or SAP | Okta + Azure AD | VMware + Intune + Jamf | Symantec + Forcepoint | ServiceNow | Ironclad + DocuSign | Splunk + Carbon Black + Varonis |
Policy and Procedure Templates
Exit Security Policy (Key Sections)
Template
Exit Security Policy
1. Purpose
To define information security responsibilities that apply after the termination or change of employment of any person with access to [Organization] information or systems.
2. Scope
This policy applies to all employees, contractors, temporary staff, interns, and vendor personnel upon termination, role change, contract end, or any other employment status change.
3. Policy Statements
3.1 Exit Triggers
The exit security procedure is triggered by:
- Voluntary resignation
- Involuntary termination
- Contract end (temporary/contract staff)
- Retirement
- Death or disability
- Suspension pending investigation
- Role change (promotion, demotion, transfer, lateral move)
3.2 Access Revocation
- All system access must be revoked within 4 hours of involuntary termination or suspension
- All system access must be revoked on the last working day for voluntary resignation
- Access revocation includes: AD, email, VPN, cloud, SaaS, databases, code repos, CI/CD, physical access, shared accounts, API keys, SSH keys
- IT must verify access revocation completion and document in exit checklist
3.3 Asset Return
- All organizational assets must be returned before the last working day (or on the last working day)
- Assets include: devices, access cards, keys, documents, tokens, credit cards, home office equipment
- IT verifies asset condition and functionality; updates inventory
- Missing or damaged assets may be recovered from full and final settlement (within legal limits)
- Personal data on company devices must be separated and returned to employee
3.4 Data Deletion
- Departing employees must delete all organizational data from personal devices and accounts
- Employee signs data deletion affidavit confirming no company data remains on personal devices
- DLP scan confirms no recent data exfiltration to personal accounts
- For BYOD devices, MDM may be used to verify deletion or remotely wipe company data
3.5 Post-Employment Obligations
All departing employees are reminded of continuing obligations:
- NDA: Non-disclosure of confidential information (trade secrets, customer data, business plans)
- IP Assignment: All work product remains company property
- Non-Solicitation: No solicitation of customers or employees for [12/18/24] months
- Non-Disparagement: No disparagement of company
- Data Deletion: No retention of company data on personal devices
- Return of Property: All company property returned
- Legal Consequences: Breach may result in legal action (damages, injunction, criminal)
3.6 Role Change
- Role change triggers access adjustment: remove old role access, add new role access
- Employee returns old role assets and receives new role assets
- Employee completes security training for new role
- Access adjustment must be completed within 24 hours of role change
3.7 Exit Interview
- All departing employees must complete a security-focused exit interview
- Exit interview covers: obligations reminder, asset verification, data deletion, NDA reminder, legal consequences
- Employee acknowledges understanding of continuing obligations
- Exit interview is documented and filed
3.8 Full and Final Settlement
- Full and final settlement is contingent upon security clearance
- Security clearance requires: all assets returned, all access revoked, exit interview completed, no outstanding security issues
- Gratuity and PF cannot be withheld for security issues (legal requirement)
- Salary adjustments for asset recovery must comply with labor law
3.9 Post-Employment Monitoring
- Organization monitors for post-employment obligation violations (90-365 days)
- Monitoring includes: login attempts, data exfiltration review, social media, competitive intelligence
- Legal action is taken if violations are detected
- Monitoring is conducted within legal and privacy limits (DPDP compliance)
3.10 DPDP Compliance
- Ex-employee personal data is retained only for legal and compliance purposes
- Data is deleted when legal retention period expires (with documented justification)
- Ex-employee has DPDP rights (access, correction, grievance)
- Data is secured with same rigor as current employee data
3.11 Roles and Responsibilities
- HR: Exit coordination, exit interview, full and final settlement, communication
- CISO: Access revocation, security assessment, device forensics, monitoring, incident investigation
- IT: Account deactivation, device collection, data backup, verification
- Legal: Contract enforcement, NDA litigation, DPDP compliance, labor law compliance
- Line Manager: Knowledge transfer, asset identification, project handover
- Finance: Settlement processing, asset recovery
- Facilities: Physical access revocation, card collection
- Employee: Asset return, data deletion, obligation compliance, knowledge transfer
3.12 Review
This policy is reviewed annually by HR, CISO, and Legal.
Exit Security Procedure
Template
Procedure: Exit Security Management
1. Objective
To define the step-by-step process for managing information security during and after employment termination or role change.
2. Procedure Steps
Step 1: Exit Trigger
- HR receives resignation, termination, or role change notification
- HR records exit date and type in HRIS
- HRIS auto-generates IT ticket for access revocation and asset return
- HR schedules exit interview and security clearance process
- For involuntary termination: immediate flag for rapid exit procedure
Step 2: Notice Period Security Management (Voluntary Resignation)
- If employee has 30-90 days notice period:
- Restrict access to sensitive systems immediately (customer data, financial systems, admin)
- Revoke admin/privileged access immediately
- Monitor employee activity closely (DLP, logs, monitoring)
- Require manager approval for any sensitive data access
- Remove from critical projects gradually (knowledge transfer)
- Maintain productivity but limit data access risk
- For involuntary termination: all access revoked immediately; no notice period access
Step 3: Access Revocation
- IT receives HRIS exit ticket
- IT revokes access in all systems per access revocation checklist
- IT verifies revocation (test login attempts, review logs)
- IT updates asset inventory (device assignment removed)
- IT disables email account (or sets forwarding with monitoring)
- IT revokes VPN, remote desktop, cloud access
- IT revokes code repository, CI/CD, database access
- IT changes shared account passwords if employee knew them
- IT revokes API keys and removes SSH keys
- IT revokes physical access (card, biometric, parking)
- IT completes access revocation within SLA (4 hours for critical, 24 hours for standard)
- IT documents all revocations in exit checklist
Step 4: Asset Return
- Employee returns all assets on last working day (or before)
- IT/Admin verifies asset condition and functionality
- IT/Admin updates asset inventory (returned, condition, reassigned/disposed)
- IT wipes data from devices (if returning to pool) or creates forensic image (if termination for cause)
- IT returns personal data to employee (if found on company device)
- Finance verifies no outstanding asset loans
- Missing assets: HR/Finance deducts from settlement (within legal limits) or pursues recovery
- Asset return documented in exit checklist
Step 5: Data Deletion Verification
- Employee signs data deletion affidavit
- IT provides data deletion guidance
- DLP scan confirms no recent data exfiltration (30-90 days pre-exit)
- Email forwarding rules checked and removed
- Personal cloud storage checked for company data (if consented)
- Personal email accounts checked for company data (if consented)
- Social media checked for confidential information (if applicable)
- For high-risk exits: device scan or remote wipe (if BYOD with MDM)
- Data deletion documented in exit checklist
Step 6: Exit Interview (Security Focus)
- HR conducts exit interview with security questions
- Employee reminded of NDA, IP, non-solicitation, non-disparagement obligations
- Employee acknowledges understanding (signed acknowledgment)
- Employee asked about data on personal devices, contact with competitors, data sharing
- Employee provided with legal contact information for questions
- Exit interview documented and filed
Step 7: Knowledge Transfer
- Manager ensures knowledge transfer is complete
- Departing employee documents processes and tribal knowledge
- Handover sessions conducted with replacement
- Access to files and systems transferred to replacement
- Documentation archived
- Manager verifies knowledge transfer completeness
Step 8: Security Clearance
- HR verifies all exit checklist items complete:
- All access revoked (IT confirmation)
- All assets returned (IT/Admin confirmation)
- Data deletion verified (IT confirmation)
- Exit interview completed (HR confirmation)
- No outstanding security issues (CISO confirmation)
- HR issues security clearance certificate
- Security clearance is prerequisite for full and final settlement
- If issues found: issues resolved before clearance (within legal limits)
Step 9: Full and Final Settlement
- Finance processes settlement only after security clearance
- Settlement includes: salary, gratuity, PF, leave encashment, bonus
- Asset recovery deductions applied (if legally permitted)
- Settlement agreement signed (if applicable)
- Relieving letter and experience certificate issued
- Final payment processed
Step 10: Post-Employment Monitoring
- Security team monitors for obligation violations:
- Login attempts with old credentials (90 days)
- DLP review of pre-exit activity (90 days)
- Social media monitoring (if applicable)
- Competitive intelligence (new product, competitor launch)
- Customer/employee contact (if non-solicitation)
- Legal action taken if violations detected
- Monitoring documented and reviewed quarterly
Step 11: Role Change (if applicable)
- HR triggers role change in HRIS
- IT removes old role access and adds new role access
- Employee returns old assets and receives new assets
- Employee completes new role security training
- Manager verifies knowledge transfer and new role readiness
- Access adjustment verified by security team in next review
3. Special Cases
3.1 Rapid Exit (Involuntary Termination)
- All access revoked immediately (within 1 hour)
- Employee escorted from premises (if termination for cause)
- Assets collected immediately (if on-site)
- Remote device: shipped back with tracking
- Forensic image taken before device wipe
- No exit interview (if termination for cause)
- Settlement processed as per labor law (notice pay, if applicable)
- Legal action may be initiated if breach suspected
3.2 Remote Worker Exit
- Employee ships devices back with prepaid label and tracking
- IT provides remote data deletion guidance
- Video call exit interview (if in-person not possible)
- Access revoked remotely (same timeline as on-site)
- Home office equipment collected (if company-owned)
- Remote access card/key returned by courier
3.3 Contractor Exit
- Contract end triggers same procedure as employee
- Contractual obligations reviewed and enforced
- Contractor's employer may be notified of security obligations
- No gratuity or PF (contractor, not employee)
- Settlement per contract terms
3.4 Garden Leave
- Employee is paid but does not work during notice period
- All access revoked immediately upon garden leave start
- No physical access to office
- Employee may be required to be available for questions
- Monitoring for violations during garden leave
- Settlement processed at end of garden leave period
Risk Assessment and Treatment
Key Risks Addressed by This Control
| Risk ID | Risk Description | Likelihood | Impact | Risk Level | Treatment |
|---|---|---|---|---|---|
| R-001 | Ex-employee retains access to systems | Medium | High | High | Mitigate, Automated access revocation, verification, monitoring |
| R-002 | Ex-employee takes confidential data to competitor | Medium | High | High | Mitigate, NDA, DLP, post-employment monitoring, legal enforcement |
| R-003 | Ex-employee shares login credentials with new employer | Medium | Medium | Medium | Mitigate, Access revocation, shared password change, credential monitoring |
| R-004 | Ex-employee retains company assets | Medium | Medium | Medium | Mitigate, Asset tracking, return verification, settlement linkage |
| R-005 | Role change leaves old access intact | Medium | High | High | Mitigate, Role-based access control, automated adjustment, access review |
| R-006 | Ex-employee data not managed under DPDP | Medium | Medium | Medium | Mitigate, DPDP compliance program, retention justification, deletion |
| R-007 | Exit process delays create security gap | Medium | High | High | Mitigate, Automation, SLA, escalation, rapid exit procedure |
| R-008 | Ex-employee sues for wrongful termination related to security | Low | High | Medium | Mitigate, Legal compliance, due process, documentation |
| R-009 | Knowledge loss due to poor knowledge transfer | Medium | Medium | Medium | Mitigate, Knowledge transfer procedure, documentation, replacement training |
| R-010 | Ex-employee disparages company on social media | Medium | Medium | Low | Mitigate, Non-disparagement clause, monitoring, legal action if breach |
| R-011 | Ex-employee solicits customers or employees | Medium | High | Medium | Mitigate, Non-solicitation clause, monitoring, legal enforcement |
| R-012 | Data exfiltration during notice period | Medium | High | High | Mitigate, DLP monitoring, access restriction, activity monitoring |
| R-013 | Personal data on company devices not returned | Low | Medium | Low | Mitigate, Personal data separation, return to employee, privacy compliance |
| R-014 | Unreturned assets create security risk | Medium | Medium | Medium | Mitigate, Asset tracking, inventory, return verification, recovery |
| R-015 | Contractual obligations not enforceable | Low | High | Medium | Mitigate, Legal review, reasonable scope, Indian law compliance |
Audit and Compliance Checklist
Audit Questions (25 Questions)
| # | Audit Question | Expected Evidence | Red Flags |
|---|---|---|---|
| 1 | Is there a formal exit security procedure? | Approved procedure | No formal procedure, ad-hoc exits |
| 2 | Is the exit procedure triggered by all exit types? | Procedure scope | Only some exit types covered |
| 3 | Is access revoked within defined timelines? | Access revocation logs, SLA reports | Access lingering for days/weeks |
| 4 | Is asset return verified? | Asset return records, inventory updates | Unreturned assets, no verification |
| 5 | Is data deletion verified? | Data deletion affidavit, DLP reports | No verification, data on personal devices |
| 6 | Is there an exit interview with security focus? | Exit interview records, acknowledgment | No exit interview, no security focus |
| 7 | Are post-employment obligations in contracts? | Employment contracts, NDA | No NDA, no post-employment obligations |
| 8 | Are obligations communicated at exit? | Exit interview records, signed acknowledgment | No communication, no acknowledgment |
| 9 | Is full and final settlement linked to security clearance? | Settlement records, clearance certificate | Settlement without security clearance |
| 10 | Is there post-employment monitoring? | Monitoring records, alerts | No monitoring, no detection |
| 11 | Is there a role change security procedure? | Role change procedure | No role change procedure |
| 12 | Is access adjusted on role change? | Access logs, role change records | Old access retained after role change |
| 13 | Are all systems included in access revocation? | Access revocation checklist, verification | Some systems missed (Shadow IT, shared accounts) |
| 14 | Is there a rapid exit procedure for involuntary termination? | Rapid exit procedure | No rapid procedure, same as voluntary |
| 15 | Is there DPDP compliance for ex-employee data? | DPDP policy, retention justification, deletion records | No DPDP compliance, indefinite retention |
| 16 | Are exit security records maintained? | Exit records, checklists, certificates | No records, no documentation |
| 17 | Is there a legal enforcement mechanism for breaches? | Legal framework, breach notices, litigation records | No enforcement, breaches ignored |
| 18 | Is there knowledge transfer for critical roles? | Knowledge transfer records, documentation | No knowledge transfer, critical knowledge lost |
| 19 | Is there monitoring for data exfiltration during notice period? | DLP logs, monitoring reports | No monitoring during notice period |
| 20 | Are shared account passwords changed on exit? | Password change records, access logs | Shared passwords unchanged |
| 21 | Are API keys and tokens revoked on exit? | API key management records, revocation logs | API keys still active |
| 22 | Is there a garden leave policy for critical roles? | Garden leave policy | No garden leave, critical roles exposed |
| 23 | Is there remote worker exit procedure? | Remote exit procedure | No remote procedure, remote assets unaccounted |
| 24 | Is there contractor exit procedure? | Contractor exit procedure | No contractor procedure, contractor risks |
| 25 | Is the exit procedure reviewed annually? | Management review minutes, audit reports | No review, stale procedure |
Metrics and KPIs
Figure · Measures
The measures that show A.6.5 is working
- Access Revocation SLA Compliance>98%Per exit
- Asset Return Rate>98%Per exit
- Missing Asset Rate<2%Monthly
- Exit Interview Completion100%Per exit
- Security Clearance Completion100%Per exit
Key Metrics Dashboard
| KPI | Formula | Target | Frequency |
|---|---|---|---|
| Access Revocation SLA Compliance | (Access revoked within SLA / Total exits) × 100 | >98% | Per exit |
| Asset Return Rate | (Assets returned / Total assets due) × 100 | >98% | Per exit |
| Missing Asset Rate | (Missing assets / Total assets due) × 100 | <2% | Monthly |
| Exit Interview Completion | (Exit interviews completed / Total exits) × 100 | 100% | Per exit |
| Security Clearance Completion | (Security clearances issued / Total exits) × 100 | 100% | Per exit |
| Data Deletion Affidavit Rate | (Affidavits signed / Total exits) × 100 | 100% | Per exit |
| DLP Scan Completion | (DLP scans completed / Total exits) × 100 | >95% | Per exit |
| Post-Employment Monitoring Alerts | Number of alerts generated post-exit | Trending down | Monthly |
| Legal Enforcement Actions | Number of legal actions for post-employment breaches | Trending down | Quarterly |
| Role Change Access Adjustment SLA | (Access adjusted within SLA / Total role changes) × 100 | >98% | Per role change |
| Excess Access After Role Change | (Role changes with excess access / Total role changes) × 100 | <1% | Quarterly |
| Knowledge Transfer Completion | (Knowledge transfers completed / Critical role exits) × 100 | 100% | Per critical exit |
| Settlement Processing Time | Average days from exit to settlement | <15 days | Monthly |
| Employee Satisfaction (Exit) | Exit survey satisfaction score | >3.5/5 | Quarterly |
| Contractual Obligation Coverage | (Employees with NDA / Total employees) × 100 | 100% | Annual |
| DPDP Compliance (Ex-Employee Data) | DPDP audit score for ex-employee data | >95% | Quarterly |
| Lingering Access Detection | (Exits with lingering access found / Total exits) × 100 | <1% | Monthly |
| Shadow IT Access Revocation | (Shadow IT accounts revoked / Shadow IT accounts identified) × 100 | 100% | Per exit |
| Full and Final Settlement Linkage | (Settlements with security clearance / Total settlements) × 100 | 100% | Monthly |
| Notice Period Monitoring | (Notice period employees monitored / Total notice period employees) × 100 | 100% | Monthly |
| Rapid Exit Procedure Compliance | (Rapid exits completed per procedure / Total rapid exits) × 100 | 100% | Per rapid exit |
| Remote Exit Completion | (Remote exits completed per procedure / Total remote exits) × 100 | 100% | Per remote exit |
| Contractor Exit Compliance | (Contractor exits per procedure / Total contractor exits) × 100 | 100% | Per contractor exit |
| Post-Employment Breach Detection Rate | (Breaches detected / Estimated breaches) × 100 | >80% | Quarterly |
| Ex-Employee Data Retention Compliance | (Ex-employee data deleted per schedule / Scheduled deletions) × 100 | 100% | Quarterly |
Common Pitfalls and How to Avoid Them
| # | Pitfall | Why It Happens | How to Avoid |
|---|---|---|---|
| 1 | No formal exit procedure | Small company, informal culture | Create simple exit checklist even for small teams |
| 2 | Access not revoked promptly | Manual process, multiple systems, lack of automation | Automate access revocation, SLA, escalation, verification |
| 3 | Shadow IT access missed | Unmanaged accounts, personal accounts for work | Shadow IT discovery, SSO, complete access inventory |
| 4 | Shared passwords not changed | Forgotten, no process, assumption of security | Automated shared password change on exit, checklist item |
| 5 | Assets not tracked | No asset inventory, no tracking system | Asset inventory, barcode/RFID, tracking system, return verification |
| 6 | No exit interview | Time pressure, assumption of unnecessary | Mandatory exit interview, security questions, obligation reminder |
| 7 | Post-employment obligations not in contracts | Outdated contracts, no legal review | Contract review, NDA addendum, IP assignment, non-solicitation |
| 8 | No post-employment monitoring | overhead, privacy concerns, assumption of compliance | DLP review, login monitoring, competitive intelligence, legal framework |
| 9 | Role change leaves old access | No role change procedure, manual process | Role-based access control, automated adjustment, access review |
| 10 | Settlement without security clearance | Time pressure, employee relations, lack of process | Security clearance as mandatory condition, process enforcement |
| 11 | No DPDP compliance for ex-employee data | Unawareness, no retention policy | DPDP program, retention schedule, deletion justification, audit |
| 12 | Remote worker assets not returned | Remote location, shipping logistics, no process | Prepaid shipping labels, tracking, remote exit procedure, deposit |
| 13 | No knowledge transfer | Time pressure, departure urgency, no process | Knowledge transfer requirement, documentation, handover sessions |
| 14 | No rapid exit procedure | Assumption that all exits are same | Separate rapid exit procedure for involuntary termination |
| 15 | Contractor exit ignored | Contract not employment, assumption of less risk | Contractor exit procedure, same rigor as employee |
| 16 | No monitoring during notice period | Trust, assumption of good behavior, no tools | DLP monitoring, access restriction, activity monitoring during notice |
| 17 | Personal data on company devices lost | No separation process, no return policy | Personal data identification, separation, return to employee |
| 18 | Non-compete clauses that are unenforceable | Copying foreign contracts, no legal review | Indian law compliance, focus on NDA and non-solicitation instead |
| 19 | No legal enforcement when breach detected | overhead, effort, assumption of futility | Legal framework, breach notice template, litigation budget, monitoring |
| 20 | Exit records not maintained | Informality, no record-keeping culture | Mandatory documentation, case management system, audit trail |
| 21 | Garden leave not used for critical roles | overhead, assumption of unnecessary | Garden leave policy for critical roles (BFSI, senior execs, technical) |
| 22 | No integration between HR and IT | Silos, no system integration, manual handoff | HRIS-IT integration, automated ticketing, SSO, lifecycle management |
| 23 | BYOD devices not addressed | No MDM, no BYOD policy, assumption of no risk | MDM, BYOD policy, remote wipe, data deletion verification |
| 24 | No forensics for termination for cause | No process, no tools, no expertise | Forensic image procedure, incident response, evidence preservation |
| 25 | Social media admin access forgotten | Not in standard access list, personal accounts used | Social media access inventory, admin access revocation, monitoring |
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Indian SaaS Company, CloudSync Solutions
Company Profile:
- Size: 220 employees
- Industry: B2B SaaS, Cloud Integration Platform
- Location: Hyderabad, India
- Customers: 350 enterprise clients globally
- Regulatory Scope: DPDP Act 2023, SOC 2 Type II, ISO 27001, GDPR
Challenge: CloudSync had a serious post-employment security problem:
- When a senior developer resigned to join a competitor, his access was "revoked" but only his AD account was disabled
- His GitHub access, AWS console access, and database access were never revoked (no one knew he had them)
- He had cloned the entire source code repository to his personal GitHub account 2 weeks before resigning
- He had downloaded customer database schemas and API documentation
- He joined a direct competitor and launched a similar product in 6 months
- CloudSync discovered the product similarity and investigated
- Forensic analysis showed he had taken 80% of the source code and all API documentation
- CloudSync sued for breach of NDA and trade secret misappropriation
- The case was ongoing but legal fees had already reached
- The competitor product was eroding CloudSync's market share (15% revenue decline in 6 months)
- Customer trust was damaged; 3 major customers cited "security concerns" and churned
- The company had no formal exit procedure, no asset tracking, no DLP, no post-employment monitoring
- The employee had never signed a proper NDA (his offer letter had a vague "confidentiality" clause)
- The company had no IP assignment agreement
- There was no exit interview, no security clearance, no data deletion verification
Solution:
-
Week 1-2: Emergency Exit Procedure
- Engaged Singahi for emergency exit security redesign
- Created formal Exit Security Procedure with complete checklist
- Implemented automated access revocation through Azure AD lifecycle management
- Created complete access inventory (all systems, all accounts, all employees)
- Identified 47 "forgotten" accounts that ex-employees still had access to
- Revoked all lingering access immediately
- Created asset inventory and tracking system
-
Week 3-4: Contract and Legal Framework
- Drafted complete NDA for all employees (new and existing)
- Drafted IP Assignment Agreement (all work product owned by company)
- Drafted Non-Solicitation Agreement (customers and employees, 18 months)
- Drafted Data Deletion Obligation Clause
- Updated employment contracts for all new hires
- Obtained signed NDA addendum from all 220 existing employees
- Created legal enforcement framework (breach notice, injunction, litigation)
- Created settlement agreement template with security terms
-
Week 5-6: DLP and Monitoring
- Implemented Microsoft Purview DLP across all endpoints and cloud
- Configured DLP for source code, customer data, API documentation
- Set up 30-day pre-exit monitoring for all resignations (DLP alert on data exfiltration)
- Implemented email forwarding rule monitoring
- Created post-employment monitoring framework (login attempts, competitive intelligence)
- Trained security team on DLP and monitoring tools
-
Week 7-8: Exit Procedure Implementation
- Implemented HRIS-IT integration (BambooHR → Azure AD → IT ticket)
- Created exit security checklist with 50+ items
- Implemented exit interview with security focus (15 questions)
- Created data deletion affidavit
- Created security clearance certificate
- Linked full and final settlement to security clearance
- Created rapid exit procedure for involuntary termination
- Processed first 5 exits with new procedure successfully
-
Week 9-12: Metrics and Legal Action
- Created quarterly metrics dashboard
- 100% exit interview completion achieved
- 100% security clearance completion achieved
- Average access revocation: 2 hours (down from 7 days)
- Zero lingering access incidents detected
- DLP detected 3 data exfiltration attempts during notice periods (prevented)
- Legal team sent breach notice to the ex-developer with evidence
- Filed for injunction to stop competitor product launch
- Negotiated settlement with ex-developer (return of code, damages, non-compete commitment)
- Won 2 major customers back after demonstrating improved security
Results:
- Post-employment breaches: Zero in 6 months (vs. 1 catastrophic breach before)
- Access revocation: 100% within 4 hours (vs. 7 days before)
- Asset return: 98% (vs. 60% before)
- Lingering access: Zero detected (47 were found and revoked initially)
- DLP alerts: 3 data exfiltration attempts prevented during notice periods
- Legal risk: Breach notice sent, injunction filed, settlement reached
- Revenue: Stabilized after initial decline; won back 2 customers
- Customer trust: Restored after demonstrating exit security program
- Legal fees: for initial case; prevented future cases
- overhead: program investment vs. potential damage
- Competitive advantage: Exit security became a sales differentiator
Illustrative Scenario 2: Large BFSI, Bharat Financial Services (BFS)
Company Profile:
- Size: 6,500 employees, 5,800 frontline staff
- Industry: Retail Banking and Financial Services
- Location: Mumbai, India (branches nationwide)
- Customers: 4.2 million retail customers, 15,000 corporate clients
- Regulatory Scope: RBI, SEBI, IRDAI, DPDP Act 2023, ISO 27001, PCI DSS
- Union: Frontline staff union (strong); CBA every 3 years
Challenge: BFS had a massive post-employment risk exposure:
- Bank employees had access to customer financial data, KYC documents, loan details, and account information
- When a relationship manager left, his access was revoked "within 24 hours" but this was only the core banking system
- He still had access to 12 other systems (CRM, loan management, reporting, email, VPN) for days after exit
- He had downloaded customer KYC documents and account statements to his personal laptop
- He joined a competing bank and used the customer data to solicit high-net-worth clients
- 18 customers complained about "unauthorized contact" from the ex-employee
- RBI cyber security audit flagged "inadequate access revocation" as a major finding
- BFS faced a RBI penalty notice and potential license restrictions
- The ex-employee was not bound by a non-solicitation agreement (no such clause in contract)
- The bank had 2,000+ exits per year (high turnover in frontline staff) with no formal exit security procedure
- Exit interviews were just "how was your experience?" with no security focus
- Full and final settlement was processed without any security verification
- Role changes were common (promotion to branch manager, transfer to new branch) but old access was never removed
- The bank had 47,000+ active accounts for 6,500 employees (massive over-provisioning)
- Shadow IT was rampant: employees used personal WhatsApp, Google Drive, and personal email for work
Solution:
-
Months 1-2: Crisis Assessment and Rapid Fix
- Engaged Singahi for emergency exit security redesign
- Conducted complete access audit: 47,000 accounts for 6,500 employees
- Identified 12,000 orphaned accounts (ex-employees, role changes, contractors)
- Revoked all 12,000 orphaned accounts immediately (emergency fix)
- Identified 800 employees with excess access (not needed for their role)
- Created emergency access revocation procedure for all exits (48-hour SLA)
- Created RBI compliance remediation plan
-
Months 3-4: Enterprise Exit Framework
- Designed enterprise exit security framework for 6,500 employees
- Created role-based access control (RBAC) for 200+ roles in banking
- Created complete access inventory (all 47+ systems, all 6,500 employees)
- Implemented automated access revocation through core banking system integration
- Created exit security checklist (70+ items for banking context)
- Created garden leave policy for relationship managers and senior roles (RBI requirement)
- Implemented 30-day garden leave for all customer-facing roles
-
Months 5-6: DLP and Monitoring
- Implemented Symantec DLP across all endpoints and email
- Configured DLP for customer data, KYC, financial data, RBI reports
- Implemented 30-day pre-exit monitoring for all resignations (high-risk in banking)
- Set up email forwarding rule monitoring
- Implemented UEBA for behavioral anomaly detection
- Created post-employment monitoring framework (customer contact detection, competitive intelligence)
- Created RBI reporting dashboard for exit security metrics
-
Months 7-8: Union and Contract Alignment
- Engaged union for exit security alignment (CBA renewal was upcoming)
- Union initially resisted "surveillance" but agreed after security risk education
- Negotiated: exit security training is paid, security equipment provided, no personal surveillance, due process for all exits
- CBA updated with security exit terms: asset return, access revocation, data obligations, garden leave
- Updated employment contracts for all new hires with complete NDA, IP, non-solicitation
- Obtained NDA addendum from 6,000 existing employees (98% compliance)
- Created legal enforcement framework for banking context (RBI reporting, customer notification)
-
Months 9-12: Implementation and RBI Compliance
- Implemented HRIS-IT integration (Workday → core banking → IT ticket)
- Trained 600 branch managers on exit security procedures (2-hour session)
- Trained 50 HR staff on exit security coordination
- Created exit interview with security focus for banking (20 questions)
- Implemented security clearance certificate for all exits
- Linked full and final settlement to security clearance (within RBI guidelines)
- Created role change access adjustment procedure (remove old branch access, add new branch access)
- Processed 2,000 exits with new procedure in first year
- RBI audit: zero findings on exit security; commendation for improvement
Results:
- Orphaned accounts: Zero (from 12,000)
- Access revocation: 100% within 48 hours (from 7+ days)
- Excess access: Reduced from 800 employees to 50 employees (ongoing cleanup)
- Garden leave: 100% compliance for customer-facing roles (RBI requirement)
- DLP alerts: 45 data exfiltration attempts detected and prevented in first year
- Post-employment breaches: Zero detected (vs. 1 major before)
- RBI audit: Zero findings on exit security; penalty avoided
- Customer complaints: Zero unauthorized contact complaints (from 18 before)
- Role change access: 98% adjusted within 24 hours (from no adjustment before)
- Union relations: First bank with union-approved exit security terms
- overhead: program investment vs. RBI penalty + reputational damage + customer loss
- Industry recognition: Featured in RBI cybersecurity best practices for exit management
Multi-Framework Mapping
| ISO 27001:2022 A.6.5 | SOC 2 Trust Services Criteria | PCI DSS v4.0 | NIST 800-53 Rev 5 | CIS Controls v8 | COBIT 2019 | GDPR / DPDP Act 2023 |
|---|---|---|---|---|---|---|
| Termination responsibilities | CC1.1: Management philosophy | 12.4.1: Security awareness | PS-1: Personnel security policy | Control 6.1: Asset inventory | APO07.01: Manage people | DPDP S. 8: Security safeguards |
| CC1.2: Board of directors | 12.4.2: Security awareness content | PS-2: Position risk designation | Control 6.2: Unauthorized assets | APO07.02: Manage competencies | DPDP S. 10: Consent | |
| CC1.3: Management oversight | 12.4.3: Security awareness program | PS-3: Personnel screening | Control 6.3: Personnel inventory | APO07.03: Manage contracts | GDPR Art. 32: Security | |
| CC1.4: Integrity and ethical values | 12.4.4: Security awareness evaluation | PS-4: Personnel termination | Control 6.4: Third-party personnel | APO07.04: Manage cultural diversity | GDPR Art. 5: Principles | |
| CC1.5: Accountability | 12.8.1: Third-party security | PS-5: Personnel transfer | Control 6.5: Service accounts | APO07.05: Manage performance | DPDP S. 11: Rights | |
| CC2.1: Communication | 12.8.2: Third-party agreements | PS-6: Access agreements | Control 6.6: Privileged accounts | DSS05.02: Manage security | DPDP S. 13: Grievance | |
| 12.8.3: Third-party assurance | PS-7: External personnel | Control 6.7: Shared accounts | DSS05.03: Manage security services | DPDP S. 14: Nomination | ||
| PS-8: Personnel sanctions | Control 6.8: Emergency accounts | DSS06.01: Manage business controls | DPDP S. 17: Children's data | |||
| Control 6.9: Temporary accounts | DSS06.02: Manage business controls | DPDP S. 22: SDF | ||||
| Control 6.10: Generic accounts | DSS06.03: Manage business controls | |||||
| Control 6.11: Dormant accounts | MEA01.02: Monitor and evaluate |
Regulatory and Industry Context
India Regulatory Framework
| Regulation | Exit Requirement | Penalty |
|---|---|---|
| DPDP Act 2023 | Delete ex-employee data when purpose fulfilled; retention justified | Up to |
| IT Act 2000 (Section 43A) | Reasonable security includes exit procedures | Compensation claims |
| Indian Contract Act 1872 | NDA, IP assignment, non-solicitation enforceable | Breach of contract damages |
| Companies Act 2013 | Director resignation obligations | Director liability |
| Industrial Disputes Act 1947 | Full and final settlement; notice period; gratuity | Labor disputes |
| Payment of Gratuity Act 1972 | Gratuity cannot be withheld for security issues | Penalties |
| EPF Act 1952 | PF cannot be withheld | Penalties |
| Trade Secrets | Common law protection | Civil damages, injunctions |
| Copyright Act 1957 | Employee work product ownership | Copyright disputes |
| Patents Act 1970 | Employee inventions | Patent disputes |
| RBI Cyber Security Framework | Exit procedures for banking systems; garden leave | License restrictions |
| SEBI Cybersecurity Circular | Access revocation for departing employees | Trading restrictions |
| IRDAI Guidelines | Exit procedures for insurance data | License suspension |
| POSH Act 2013 | Continuing obligations for POSH violations | Employer liability |
| Official Secrets Act 1923 | Continuing secrecy obligations | Criminal prosecution |
| Payment of Wages Act 1936 | Wage deductions for asset recovery limited | Penalties |
| Minimum Wages Act 1948 | No deductions for asset recovery beyond limits | Penalties |
International Regulations
| Regulation | Exit Requirement |
|---|---|
| GDPR (EU) | Article 17, Right to erasure (ex-employee data); Article 5, Purpose limitation |
| HIPAA (US) | §164.308(a)(3)(ii)(C)**, Termination procedures; access revocation |
| SOX (US) | Internal controls including access revocation upon termination |
| UK Employment Rights Act 1996 | Fair termination procedures; notice period; settlement |
| EU Whistleblower Directive | Protection for employees reporting violations; anti-retaliation |
| ILO Convention | Worker rights and fair treatment upon termination |
| FCRA (US) | Adverse action notice for background checks |
| CCPA (California) | Employee data privacy; deletion rights |
Sector-Specific Requirements
| Sector | Exit-Specific Requirements |
|---|---|
| BFSI | RBI-mandated exit procedures; garden leave for customer-facing roles; access revocation within 24 hours; customer data return; fraud response; integrity committee |
| Healthcare | Clinical staff exit; patient data return; CDSCO compliance; HIPAA-style access revocation; clinical handover |
| Telecom | DOT security clearance revocation; subscriber data return; network access revocation; lawful interception access removal |
| Manufacturing | OT system access revocation; IP return; standing orders compliance; union CBA exit terms; safety equipment return |
| Government | Service rules exit; classified data return; Official Secrets Act; security clearance revocation; CVC clearance |
| Defence | Security clearance revocation; classified data return; export control compliance; foreign contact review; debriefing |
| Aviation | DGCA security clearance; airside access revocation; substance testing records; safety-critical role handover |
| Education | Student data return; FERPA/GDPR compliance; IP return; research data transfer; POCSO obligations |
| SaaS / B2B | Source code return; customer data deletion; cloud access revocation; SOC 2 compliance; developer code of conduct |
| E-commerce | Customer data return; payment data deletion; warehouse access revocation; delivery personnel asset return |
| Pharma | Drug formula/data return; clinical trial data; CDSCO compliance; IP return; patent data transfer |
| Consulting | Client deliverables return; confidential information; client relationship handover; non-solicitation; professional liability |
Roles and Responsibilities (RACI)
| Activity | Accountable | Responsible | Consulted | Informed |
|---|---|---|---|---|
| Exit Policy | CISO | HR Head | Legal | Board |
| Exit Trigger | HR | HR Manager | CISO, IT | Employee |
| Access Revocation | CISO | IT Team | HR, Security | Employee |
| Asset Return | CISO | IT/Admin | HR, Finance | Employee |
| Data Deletion | CISO | IT Security | Legal | Employee |
| Exit Interview | HR | HR Manager | CISO | Employee |
| Security Clearance | CISO | HR Manager | IT, Legal | Employee, Finance |
| Full and Final Settlement | HR | Finance | Legal, CISO | Employee |
| Post-Employment Monitoring | CISO | Security Team | Legal | Management |
| Contract Enforcement | Legal | Legal Team | CISO, HR | Board |
| NDA Management | Legal | HR | CISO | All Employees |
| IP Assignment | Legal | HR | CISO | All Employees |
| Role Change Access | CISO | IT Team | HR, Manager | Employee |
| Knowledge Transfer | Line Manager | Departing Employee | HR, CISO | Replacement |
| DPDP Compliance | Legal | Compliance Manager | HR, CISO | DPO |
| Garden Leave | HR | HR Manager | Legal, CISO | Employee |
| Rapid Exit | CISO | HR, IT, Security | Legal | Management |
| Contractor Exit | HR | HR Manager | CISO, Legal | Contractor |
| Remote Exit | HR | HR Manager | IT, CISO | Employee |
| Forensic Image | CISO | IT Security | Legal | Management |
| Metrics and Reporting | CISO | HR Analyst | Compliance | Board |
| Audit and Compliance | Internal Audit | HR, CISO, IT | Legal | Board |
| Union Liaison | Legal | HR Head | CISO | Union |
| Policy Review | CISO | HR Head | Legal | Board |
| DLP Monitoring | CISO | Security Team | IT | HR |
Documentation and Evidence Requirements
Required Documents
| Document | Owner | Retention Period | Format |
|---|---|---|---|
| Exit Security Policy | CISO | 7 years | PDF + Word |
| Exit Security Procedure | HR | 7 years | PDF + Word |
| Exit Security Checklist | HR | Per exit | Digital form / paper |
| Access Revocation Checklist | IT | Per exit | System records |
| Asset Return Record | IT | 7 years | System records |
| Data Deletion Affidavit | HR | 7 years | Signed form |
| Exit Interview Record | HR | 7 years | Recorded / documented |
| Security Clearance Certificate | HR | 7 years | Certificate |
| Full and Final Settlement Record | Finance | 7 years | Financial records |
| Relieving Letter | HR | 7 years | Letter |
| Experience Certificate | HR | 7 years | Certificate |
| Settlement Agreement | Legal | 7 years | Agreement |
| NDA / Employment Contract | Legal | 7 years | Contract |
| IP Assignment Agreement | Legal | 7 years | Agreement |
| Non-Solicitation Agreement | Legal | 7 years | Agreement |
| Post-Employment Monitoring Records | CISO | 3 years | Reports, alerts |
| DLP Scan Reports | CISO | 3 years | Reports |
| Access Revocation Logs | IT | 3 years | System logs |
| Role Change Access Records | IT | 3 years | System records |
| Knowledge Transfer Documentation | Line Manager | 3 years | Documents, recordings |
| Forensic Image (if applicable) | CISO | 7 years | Forensic image |
| DPDP Ex-Employee Data Records | Legal | Per DPDP retention | Records |
| Garden Leave Records | HR | 3 years | Records |
| Rapid Exit Records | CISO | 7 years | Records |
| Audit Evidence | Internal Audit | 5 years | Audit reports |
| Metrics and Reports | CISO | 3 years | Dashboard, reports |
| Lessons Learned | CISO | 3 years | Documentation |
| Union/CBA Exit Terms | Legal | Duration of CBA + 7 years | Agreement |
| Breach Notice Records | Legal | 7 years | Notices, responses |
| Legal Action Records | Legal | 7 years | Case files |
| Exit Survey Results | HR | 3 years | Survey data |
| Employee Acknowledgment | HR | 7 years | Signed forms |
| Contract Repository | Legal | 7 years | Repository |
| Access Inventory | IT | 3 years | Inventory |
| Asset Inventory | IT | 7 years | Inventory |
| Shadow IT Inventory | CISO | 3 years | Inventory |
| Training Records (Exit Security) | HR | 5 years | LMS records |
| Metrics Dashboard | CISO | 3 years | Dashboard |
| Case Management Records | HR | 7 years | System records |
| Email Archive | IT | 7 years | Archive |
| DLP Alert Records | CISO | 3 years | Alert logs |
| Incident Response Records | CISO | 7 years | Incident records |
| Compliance Evidence | Compliance | 5 years | Evidence package |
| Management Review Minutes | CISO | 5 years | Minutes |
| Policy Review Records | CISO | 5 years | Review records |
| Evidence Repository | Compliance | 7 years | Repository |
| Audit Reports | Internal Audit | 5 years | Reports |
| Penetration Test Reports | CISO | 3 years | Reports |
| Vulnerability Scan Reports | CISO | 3 years | Reports |
| Risk Assessment Records | CISO | 3 years | Assessments |
| Gap Analysis Records | CISO | 3 years | Gap analysis |
| Improvement Records | CISO | 3 years | Improvements |
| Communication Records | HR | 3 years | Communication |
| Employee FAQ | HR | 3 years | FAQ document |
| Quick Reference Card | HR | 3 years | Card |
| Tool Comparison | CISO | 3 years | Comparison |
| Vendor Guide | Procurement | 3 years | Guide |
| Assessment Guide | CISO | 3 years | Guide |
| Documentation Template | HR | 3 years | Template |
| KPI Tracker | CISO | 3 years | Tracker |
| Incident Response Guide | CISO | 3 years | Guide |
| Training Plan | HR | 3 years | Plan |
| Communication Template | HR | 3 years | Template |
| Vendor Management Guide | Procurement | 3 years | Guide |
| Risk Assessment Template | CISO | 3 years | Template |
| Compliance Checklist | Compliance | 3 years | Checklist |
| Procedure Template | HR | 3 years | Template |
| Policy Template | CISO | 3 years | Template |
| Audit Checklist | Internal Audit | 3 years | Checklist |
| RACI Matrix | CISO | 3 years | Matrix |
| Maturity Model | CISO | 3 years | Model |
| value Analysis | Finance | 3 years | Analysis |
| Quick Reference Card | HR | 3 years | Card |
Continuous Improvement
Figure · Tiers
Maturity levels for responsibilities after termination or change of employment

Maturity Model (Level 1-5)
| Level | Name | Description |
|---|---|---|
| 1 | Initial | Ad-hoc exits; no formal procedure; access revoked manually; no asset tracking; no post-employment obligations |
| 2 | Managed | Basic exit checklist; some access revocation; informal asset return; basic NDA; no monitoring |
| 3 | Defined | Formal exit procedure; automated access revocation; asset tracking; complete NDA; exit interview; security clearance; post-employment monitoring; DPDP compliance; role change procedure |
| 4 | Quantitatively Managed | Consistent enforcement; automated lifecycle; metrics-driven; DLP monitoring; legal enforcement; 30-60-90 day monitoring; RBAC; garden leave; full and final settlement linkage |
| 5 | Optimizing | Predictive exit analytics; AI-driven insider threat detection; continuous post-employment monitoring; automated legal enforcement; blockchain asset provenance; zero-defect exit; industry leadership |
Improvement Cycle
- Plan: Annual review of exit policy; quarterly metrics; industry benchmarking; regulatory updates; employee feedback; legal trend analysis
- Do: Deploy new tools; update access matrices; train managers; enhance monitoring; improve automation; update contracts; refine DLP
- Check: Measure access revocation speed; audit asset return; verify DPDP compliance; benchmark; gather feedback; review legal cases; analyze breaches
- Act: Standardize; communicate; update procedures; report to management; share best practices; union collaboration; legal framework refinement
Technology Trends
- AI Exit Risk Scoring: AI predicting which departing employees pose highest data theft risk
- Automated Forensics: Automated forensic imaging and analysis of departing employee devices
- Blockchain Asset Provenance: Blockchain tracking of asset ownership and return
- Predictive Analytics: Predicting employee departure before resignation (behavioral indicators)
- Digital Exit Assistant: AI-powered chatbot guiding employees through exit process
- Continuous Access Verification: Real-time verification that all access is revoked across all systems
- Post-Employment Digital Footprint Monitoring: AI monitoring ex-employee digital footprint for IP violations
- Smart Contracts for Enforcement: Blockchain-based smart contracts for post-employment obligations
- Integrated Lifecycle Management: Single platform managing employee from onboarding to exit
- Zero-Trust Exit: Zero-trust architecture ensuring no lingering trust relationships post-exit
FAQ
Frequently Asked Questions (20 Questions)
Q1: Is a formal exit security procedure required for ISO 27001 certification? A: Yes. A.6.5 explicitly requires defining, communicating, and enforcing information security responsibilities after termination or role change. The auditor will verify the exit procedure, access revocation, asset return, and post-employment obligations.
Q2: What is the timeline for access revocation after termination? A: For involuntary termination or suspension, access should be revoked within 1-4 hours. For voluntary resignation, access should be revoked on the last working day. Critical systems (admin, customer data, financial) should be revoked immediately upon notice of resignation for customer-facing roles.
Q3: Can we withhold full and final settlement if an employee doesn't return assets? A: You can adjust salary for asset recovery (with legal compliance), but you cannot withhold gratuity or PF (as per Payment of Gratuity Act and EPF Act). Consult Legal before withholding any settlement component.
Q4: Are non-compete clauses enforceable in India? A: Generally, post-employment non-compete clauses are void under Section 27 of the Indian Contract Act (restraint of trade). However, non-compete may be enforceable during employment and for sale of goodwill. Focus on enforceable tools: NDA, non-solicitation, IP assignment, and garden leave.
Q5: What is garden leave and when should it be used? A: Garden leave is a period where the employee is paid but does not work. All access is revoked. It's commonly used in BFSI (RBI requirement) and for senior technical/customer-facing roles. It reduces data exfiltration risk during the notice period.
Q6: Do we need to monitor ex-employees after they leave? A: Yes, but within legal and privacy limits. You can monitor for violations of contractual obligations (NDA, non-solicitation, IP). You cannot conduct surveillance of personal life. DPDP compliance is required. Monitoring should be documented and justified.
Q7: What should we do if an ex-employee takes confidential data to a competitor? A: (1) Gather evidence of breach, (2) Send breach notice (cease and desist), (3) Attempt settlement, (4) Seek court injunction if urgent, (5) File civil suit for breach of contract and trade secret misappropriation, (6) If criminal, file police complaint, (7) Notify regulator if required (RBI, SEBI, etc.).
Q8: How do we handle remote worker exits? A: Remote worker exits require: (1) prepaid shipping labels for device return, (2) video call exit interview, (3) remote access revocation (same timeline), (4) remote data deletion guidance, (5) BYOD device verification (if MDM), (6) home office equipment return, (7) courier tracking for asset return.
Q9: What is the difference between exit for voluntary resignation and involuntary termination? A: Voluntary resignation: notice period, gradual access restriction, knowledge transfer, exit interview, standard timeline. Involuntary termination: immediate access revocation, no exit interview (if for cause), forensic image, rapid asset collection, potential legal action.
Q10: Do we need an exit interview for every departing employee? A: Yes. The exit interview should include security-focused questions (obligations reminder, asset verification, data deletion). Even for involuntary termination, a security reminder can be communicated (though not a traditional "interview"). Document the security communication.
Q11: How do we handle role changes (promotion, transfer)? A: Role changes require: (1) access revocation for old role, (2) access provisioning for new role, (3) asset return/reassignment, (4) new role security training, (5) knowledge transfer, (6) verification that old access is removed. Use RBAC to automate.
Q12: What is a data deletion affidavit and is it required? A: A data deletion affidavit is a signed statement by the departing employee confirming that all company data has been deleted from personal devices and accounts. It is not legally required but is strong evidence in case of future breach. Highly recommended for all exits.
Q13: How do we handle BYOD devices at exit? A: If the device is enrolled in MDM, the company data container can be remotely wiped. If not enrolled, the employee must sign a data deletion affidavit. For high-risk exits, you may request a device scan (with consent). Include BYOD obligations in the employment contract.
Q14: What is the DPDP requirement for ex-employee data? A: Ex-employee personal data must be retained only for legal and compliance purposes (tax, labor law, legal claims). You must delete data when the legal retention period expires. You must justify retention. Ex-employees have DPDP rights (access, correction, grievance) unless exempted.
Q15: Can we change shared passwords when an employee leaves? A: Yes, and you should. If the departing employee knew shared account passwords (e.g., admin accounts, service accounts), those passwords must be changed immediately. Include this in the access revocation checklist.
Q16: What happens if an employee dies? A: Exit procedure for death: (1) Immediate access revocation (emergency contact authorizes), (2) Asset collection from family (with sensitivity), (3) Data recovery and transfer, (4) Personal data separation and return to family, (5) Settlement processing per labor law, (6) Legal compliance for estate.
Q17: How do we handle contractor exits? A: Contractor exits should follow the same procedure as employees: (1) Access revocation, (2) Asset return, (3) Data deletion, (4) Contractual obligation reminder, (5) Notify contractor's employer (if applicable), (6) Settlement per contract terms. No gratuity or PF for contractors.
Q18: What is the role of CISO in exit security? A: CISO is accountable for: access revocation, security assessment, device forensics, data deletion verification, post-employment monitoring, incident investigation, DLP monitoring, and security clearance. CISO does not manage HR or settlement but ensures security aspects are complete.
Q19: Can we recover overhead for unreturned assets? A: Yes, but within legal limits. You can deduct the impact of unreturned assets from the final salary (with legal compliance). You cannot deduct from gratuity or PF. The deduction must be documented and justified. Consult Legal.
Q20: What will an ISO 27001 auditor look for in A.6.5? A: The auditor will verify: (1) formal exit procedure exists, (2) procedure covers all exit types, (3) access is revoked within defined timelines, (4) assets are returned and verified, (5) data deletion is verified, (6) exit interview includes security focus, (7) post-employment obligations are in contracts, (8) obligations are communicated at exit, (9) full and final settlement is linked to security clearance, (10) role change procedure exists, (11) there is evidence of use (records, checklists, certificates), and (12) DPDP compliance is maintained.
References and Further Reading
ISO Standards
- ISO 27001:2022, Information Security Management Systems
- ISO 27002:2022, Information Security Controls
- ISO 27701:2019, Privacy Information Management System
Indian Law
- Indian Contract Act 1872, Section 27 (restraint of trade)
- Industrial Disputes Act 1947, Sections 2A, 10, 11, 25B, 25F, 33
- Payment of Gratuity Act 1972
- Employees' Provident Funds Act 1952
- Payment of Wages Act 1936, Section 7 (deductions)
- Minimum Wages Act 1948
- Companies Act 2013
- DPDP Act 2023
- IT Act 2000
- Copyright Act 1957
- Patents Act 1970
- Trade Secrets (common law)
- Official Secrets Act 1923
- POSH Act 2013
International
- GDPR (EU), Articles 5, 17, 32
- HIPAA (US), §164.308(a)(3)(ii)(C)**, Termination procedures
- SOX (US), Internal controls
- UK Employment Rights Act 1996
- EU Whistleblower Directive
- ILO Convention, Worker rights
- FCRA (US), Adverse action
- CCPA (California), Employee data privacy
Industry
- RBI Cyber Security Framework, Exit procedures for banking
- SEBI Cybersecurity Circular, Access revocation
- IRDAI Guidelines, Exit procedures for insurance
- NASSCOM, IT industry employment practices
- ISACA, Security and governance guidance
- Data Security Council of India, Data protection best practices
- Verizon DBIR, Data breach investigations
- Symantec, Insider threat reports
- Kaspersky, Employee data theft statistics