Skip to content
Singahi

Compliance · guide

ISO 27001 A.6.5: Responsibilities After Termination or Change of Employment

71 min read

Share
On this page

Quick Reference (60 Seconds)

AttributeDetail
Control IDA.6.5
TitleResponsibilities after Termination or Change of Employment
ObjectiveEnsure information security responsibilities continue after employment ends or changes
DomainPeople
ISO 27001:2022 ClauseAnnex A.6.5
What You Must DoDefine, communicate, and enforce security responsibilities that survive employment termination or role change
OwnerHR / CISO / Legal
Maturity Level 1No post-employment obligations; informal return of assets
Maturity Level 2Basic exit checklist; some asset return; no formal obligations
Maturity Level 3Formal exit procedure; asset return; access revocation; post-employment obligations in contract; NDA enforcement
Maturity Level 4Automated access revocation; asset tracking; exit interviews; 30-60-90 day monitoring; legal enforcement; role change automation
Maturity Level 5Automated joiner-mover-leaver workflow; same-day access removal; continuing duties clearly communicated; lessons from exits feed the process
ISO 27002 attributesControl type: Preventive · Properties: Confidentiality, Integrity, Availability · Concepts: Protect · Capabilities: Human resource security, Asset management · Domains: Governance and ecosystem

What the Control Asks For

Do you need this control?

A.6.5 is not mandatory in itself: under clause 6.1.3 you include it if your risk assessment calls for it, and record the decision in your Statement of Applicability. Almost every organisation with leavers or role changes includes it. It works with A.5.11 (return of assets) and A.5.18 (access rights), so many organisations implement all three through one joiner-mover-leaver process.

The Control in Brief

Annex A 6.5 asks organizations to define, enforce and communicate to the relevant personnel and other interested parties the information security responsibilities and duties that remain valid after termination or change of employment.

Implementation Guidance (ISO 27002:2022, paraphrased)

  • Define which security responsibilities remain valid after termination or change: confidentiality of information, intellectual property and other knowledge obtained, and duties in any other confidentiality agreement (A.6.6)
  • Put continuing duties in the person's terms and conditions of employment (A.6.2), contract or agreement; other agreements that run for a defined period after employment can also carry security duties
  • Manage a change of role as the termination of the current role plus the start of the new one
  • Identify and transfer the security roles and responsibilities held by the leaver or mover to someone else
  • Communicate the change, and any change to operating procedures, to personnel, other interested parties and relevant contacts (for example customers and suppliers)
  • Apply the same process to external personnel (contractors, supplier staff)

Returning assets (A.5.11) and removing or adjusting access (A.5.18) happen in the same exit process; this guide covers them alongside A.6.5.

"Shall" vs "Should" Analysis

  • Shall (once you have selected this control): post-employment obligations are defined, communicated and enforced
  • Should: Specific obligations, methods, and enforcement mechanisms are flexible based on context

Common Misinterpretations

MisinterpretationReality
"Once an employee leaves, we have no control"Contractual obligations survive termination; legal enforcement is possible; monitoring can detect violations
"NDAs are unenforceable in India"NDAs are enforceable in India for trade secrets and confidential information; courts enforce reasonable restrictions
"We only need exit procedures for terminations"Role changes also require access adjustment, asset reassignment, and obligation updates
"Remote employees don't need to return assets"Remote employees must return all organizational assets, including devices, data, and credentials
"Post-employment obligations are only for senior staff"All employees with access to information should have post-employment obligations
"We can keep personal data of ex-employees indefinitely"DPDP Act 2023 requires data deletion after purpose is fulfilled; retention must be justified

Why Termination Responsibilities Matter

The Business Risk Narrative

Post-employment security failures are a major source of data breaches and insider threats:

  • A 2013 Symantec and Ponemon Institute survey found that about half of employees who left or lost their jobs kept confidential corporate data
  • Accounts left active after exit, and shared passwords that are never changed, are a recurring audit finding
  • DPDP Act 2023: Organizations must delete personal data when purpose is fulfilled; retention of ex-employee data must be justified

Regulatory Landscape in India

RegulationPost-Employment RequirementPenalty for Non-Compliance
DPDP Act 2023Delete ex-employee personal data when the purpose is served and no law requires keeping it (s.8(7)); a leaver taking customer personal data is a personal data breach (s.8(6))Up to ₹50 crore (residual); ₹200 crore for failing to notify a breach; ₹250 crore if safeguards fail
IT Act 2000 (Section 43A)Reasonable security includes exit proceduresCompensation claims
Indian Contract Act 1872Contractual obligations (NDA, IP assignment) survive terminationBreach of contract damages
Companies Act 2013Director resignation and continuing obligations; disqualificationDirector liability
Code on Wages 2019 (s.17(2))Wages due within two working days of exitClaims, penalties
Industrial Relations Code 2020 (replaced the Industrial Disputes Act 1947)Exit procedures for workersLabor disputes, reinstatement
Confidential information (no trade-secret statute)Contract (NDA) and the equitable action for breach of confidenceCivil damages, injunctions
Copyright Act 1957Copyright assignment and post-employment obligationsCopyright infringement
Patents Act 1970Employee inventions and assignmentPatent disputes
RBI Cyber Security Framework (2016) / IT Governance MD (2023)Timely removal of access for leavers in regulated entitiesSupervisory action
SEBI CSCRF (2024)Access revocation for departing personnel at regulated entitiesSupervisory action
Official Secrets Act 1923Continuing secrecy obligations for classified informationCriminal prosecution

Industry-Specific Consequences

IndustryPost-Employment Failure Scenario
BFSIBank employee leaves with customer list; joins competitor; solicits customers; RBI audit failure; customer lawsuit
SaaS / B2BDeveloper leaves with source code; starts competing product; customer data breach; DPDP penalty; IP litigation
HealthtechDoctor leaves with patient database; privacy breach under the DPDP Act; patient complaints
E-commerceCategory manager leaves with vendor pricing data; joins competitor; undercuts pricing; revenue loss
ManufacturingEngineer leaves with proprietary designs; joins competitor; OEM contract loss; patent dispute
GovernmentOfficer leaves with classified data; leaks to media; Official Secrets Act prosecution; national security breach
TelecomEngineer leaves with network architecture; joins competitor; competitive intelligence loss; DOT action
EducationProfessor leaves with research data; joins competitor institution; IP dispute; student data breach
PharmaScientist leaves with drug formula; joins competitor; patent dispute; regulatory action; product delay
ConsultingConsultant leaves with client deliverables; reuses for competitor; client breach; professional liability

Scope and Applicability

What the Control Covers

  • Termination exit procedures: Voluntary resignation, involuntary termination, retirement, end of contract, death, disability
  • Role change procedures: Promotion, demotion, transfer, lateral move, temporary assignment, return from leave
  • Asset return: All organizational assets (devices, data, documents, credentials, access cards, keys)
  • Access revocation: All system access, accounts, privileges, VPN, remote access, cloud access
  • Post-employment obligations: NDA and confidentiality, IP assignment, reasonable non-solicitation (post-employment non-competes are void in India under s.27 of the Indian Contract Act)
  • Data obligations: Deletion of organizational data from personal devices and accounts
  • Exit interviews: Security-focused exit interviews and compliance reminders
  • Communication: Reminding departing employees of continuing obligations
  • Enforcement: Legal remedies when there is evidence of a breach of continuing obligations
  • Full and final settlement: wages due on exit are paid within two working days (Code on Wages s.17(2)); exit security steps are finished by the last working day, not used to hold back pay
  • After exit: Checking internal systems for use of old credentials and forwarding rules; acting on evidence of misuse
  • Data retention: Managing ex-employee data under DPDP requirements
  • Knowledge transfer: Ensuring continuity of critical knowledge and access

Who It Applies To

RoleResponsibility
HRExit procedure coordination, exit interview, full and final settlement, contractual obligation management, communication
CISOAccess revocation, security assessment, device wiping, data recovery, security incident investigation, post-employment monitoring
ITAccount deactivation, device collection, data backup, access log review, technical exit checklist
LegalNDA enforcement, contract review, litigation, trade secret protection, DPDP compliance for ex-employee data
Line ManagerKnowledge transfer planning, asset identification, project handover, replacement planning, performance reference
FinanceFull and final settlement, access card/loan recovery, outstanding dues
ComplianceExit compliance checklist, audit evidence, DPDP data deletion verification
EmployeeReturning assets, deleting data, complying with obligations, participating in exit process, knowledge transfer
Security TeamAccess revocation verification, device forensics, data recovery, incident investigation
FacilitiesAccess card collection, parking pass, locker clearing, physical access revocation
Procurement/AdminAsset inventory update, asset reassignment, new asset procurement for replacement

What It Does NOT Cover

  • General HR exit procedures (payroll, benefits, gratuity), covered by HR
  • Labor dispute resolution, covered by Legal and labor law
  • Criminal prosecution for data theft, covered by Law Enforcement
  • Civil litigation for breach of contract, covered by Legal
  • General employee onboarding, covered by HR (though role change is covered here)

Size-Based Applicability

Organization SizeApproach
Startups (< 50)Simple exit checklist (10-15 items); asset return; access revocation within 24 hours; basic NDA reminder
SMB (50-500)Formal exit procedure; asset tracking; access removed by the last working day; exit interview; 30-day check of internal logs
Mid-market (500-5000)Complete exit procedure; automated access revocation; asset inventory; exit interview; review of internal logs and DLP for the notice period
Enterprise (5000+)Enterprise exit framework; automated lifecycle management; legal enforcement on evidence; global consistency

Key Definitions and Terminology

TermDefinitionSource
TerminationEnd of employment relationship, whether voluntary or involuntaryEmployment Law
Role ChangeChange in job role, department, or responsibilities within the organizationHR Management
Exit ProcedureFormal process for managing an employee's departure from the organizationHR Practice
Full and Final SettlementProcess of settling all dues and obligations upon employment terminationHR Practice
Post-Employment ObligationsLegal and contractual duties that continue after employment endsContract Law
Non-Disclosure Agreement (NDA)Contract prohibiting disclosure of confidential informationContract Law
Non-Compete AgreementContract restricting employment with competitors (limited enforceability in India)Contract Law
Non-Solicitation AgreementContract restricting solicitation of customers or employeesContract Law
IP Assignment AgreementContract transferring intellectual property rights to employerIP Law
Trade SecretInformation that derives economic value from being kept secretTrade Secret Law
Confidential InformationInformation that is not public and should be kept secretContract Law
Access RevocationRemoval of system access, accounts, and privilegesIT Security
Asset ReturnReturn of organizational property (devices, documents, cards)HR Practice
Exit InterviewStructured interview with departing employeeHR Practice
Knowledge TransferProcess of transferring critical knowledge before departureHR Practice
Post-Employment MonitoringMonitoring for violations of continuing obligationsSecurity Practice
Data DeletionRemoval of organizational data from personal devices and accountsDPDP Compliance
Work For HireDoctrine that employer owns IP created by employeeCopyright Law
Garden LeavePeriod where departing employee is paid but does not work (common in BFSI)HR Practice
Notice PeriodPeriod between resignation and last working dayEmployment Contract
Settlement AgreementAgreement resolving all claims upon terminationLegal Practice
Release of ClaimsEmployee waiving claims against employerLegal Practice

Relationship to Other Controls

Upstream Controls (Prerequisites)

Control IDRelationshipWhy It Matters
A.5.1Policies for Information SecuritySecurity policy must define exit obligations before they can be enforced
A.6.1ScreeningScreened employees must have contracts with post-employment obligations
A.6.2Terms and Conditions of EmploymentEmployment terms must include post-employment obligations and asset return clauses
A.6.3Information Security AwarenessEmployees must know obligations before they can be reminded at exit
A.6.4Disciplinary ProcessDisciplinary action for violations during employment triggers exit procedures
A.6.6Confidentiality AgreementsNDA must exist to be enforced post-employment
A.6.7Remote WorkingRemote workers have additional assets to return (home office equipment)

Downstream Controls (Enabled By)

Control IDRelationshipWhy It Matters
A.8.1User Endpoint DevicesDevice return and wipe at exit
A.8.2Privileged Access RightsRevocation of privileged access at exit
A.5.9Inventory of AssetsAsset inventory enables tracking what must be returned
A.8.10Information DeletionDeletion of data from returned devices
A.8.15LoggingLogs enable post-employment monitoring and incident investigation
A.8.16Monitoring ActivitiesMonitoring detects post-employment violations
A.7.14Secure Disposal or Re-use of EquipmentReturned devices are sanitised before re-use or disposal
A.5.11Return of AssetsAssets are collected at exit or role change
A.5.18Access RightsAccess is removed or adjusted at exit or role change

Parallel Controls (Work Alongside)

Control IDRelationshipWhy It Matters
A.5.19Information Security in Supplier RelationshipsVendor personnel exit procedures
A.5.22Monitoring and ReviewReviews include exit procedure effectiveness
A.8.12Data Leakage PreventionDLP detects data exfiltration before departure
A.8.24Use of CryptographyEncryption of data on returned devices
A.8.20Networks SecurityNetwork access revocation at exit
A.5.32Intellectual Property RightsIP assignment and post-employment obligations
A.5.34Privacy and Protection of PIIDPDP compliance for ex-employee data

Implementation Roadmap (Week-by-Week)

Phase 1: Discovery & Assessment (Weeks 1-2)

Week 1: Current Exit Process Assessment

  • Deliverable: Current exit process maturity assessment
  • Owner: HR + CISO + IT + Legal
  • Activities:
    1. Map current exit process (what happens when someone resigns or is terminated)
    2. Assess access revocation process (how long, how thorough, what systems)
    3. Assess asset return process (what assets, how tracked, how verified)
    4. Review past exits for security gaps (unreturned assets, lingering access, data breaches)
    5. Assess NDA and post-employment obligations in contracts
    6. Interview departing employees about exit experience (recent exits)
    7. Assess exit interview process (security focus, obligation reminder)
    8. Review the exit timeline so security checks finish within the notice period (pay is due within two working days of exit)
    9. Assess post-employment monitoring (any detection of violations)
    10. Benchmark against industry practices and ISO 27001 requirements

Week 2: Risk and Gap Analysis

  • Deliverable: Exit security gap analysis report
  • Owner: HR + CISO + IT + Legal + Compliance
  • Activities:
    1. Map all systems and access that departing employees have
    2. Identify systems where access is not revoked promptly
    3. Identify unreturned assets from past exits
    4. Identify ex-employees with lingering access
    5. Assess data exfiltration risk (DLP, logs, monitoring)
    6. Map contractual obligations (NDA, IP, non-solicitation) and their enforceability
    7. Assess DPDP compliance for ex-employee data retention
    8. Identify role change gaps (access not adjusted on promotion/transfer)
    9. Define target state for exit security maturity
    10. Create gap closure plan

Phase 2: Design & Planning (Weeks 3-4)

Week 3: Exit Procedure Design

  • Deliverable: Draft Exit Security Procedure + Checklists + Templates
  • Owner: HR + CISO + IT + Legal
  • Activities:
    1. Design exit trigger process (resignation, termination, contract end, role change)
    2. Design notice period security management (access restriction during notice period)
    3. Create exit security checklist (access, assets, data, obligations)
    4. Design access revocation workflow (what systems, timeline, verification)
    5. Design asset return workflow (inventory, collection, verification, reassignment)
    6. Design data deletion verification (personal devices, cloud accounts, email)
    7. Design exit interview process (security focus, obligation reminder, feedback)
    8. Design the exit workflow so security checks finish by the last working day
    9. Design post-employment monitoring process (detection, investigation, enforcement)
    10. Design role change procedure (access adjustment, asset reassignment, training)
    11. Create documentation templates (exit checklist, clearance certificate, NDA reminder)
    12. Design automation for access revocation and asset tracking

Week 4: Contract and Legal Framework Design

  • Deliverable: Contract Templates + Legal Enforcement Framework + DPDP Compliance Plan
  • Owner: Legal + HR + CISO
  • Activities:
    1. Review existing employment contracts for post-employment obligations
    2. Draft NDA addendum for existing employees without adequate NDA
    3. Draft IP assignment clause for employment contracts
    4. Draft confidentiality and non-solicitation clauses (do not rely on post-employment non-competes, which are void under s.27)
    5. Draft non-solicitation clause for customers and employees
    6. Draft data deletion obligation clause
    7. Draft post-employment monitoring consent clause (within DPDP limits)
    8. Create legal enforcement framework (breach notice, litigation, injunction)
    9. Design DPDP compliance for ex-employee data (retention, deletion, justification)
    10. Create settlement agreement template with security terms
    11. Design garden leave policy for critical roles (BFSI, senior execs)
    12. Review for compliance with Indian labor law (Industrial Relations Code, notice period, Code on Wages s.17(2), gratuity under the Code on Social Security)

Phase 3: Implementation (Weeks 5-8)

Week 5: Contract Rollout

  • Deliverable: All employees have post-employment obligations in contracts
  • Owner: HR + Legal
  • Activities:
    1. Roll out NDA addendum to all employees without adequate NDA
    2. Update employment contracts for new hires with complete post-employment clauses
    3. Obtain signed acknowledgments from all employees
    4. Track completion rate (target: 100%)
    5. Create contract repository with version control
    6. Train managers on new contract requirements
    7. Create employee FAQ on post-employment obligations

Week 6: Exit Procedure Implementation

  • Deliverable: Exit procedure operational for all exits
  • Owner: HR + CISO + IT
  • Activities:
    1. Publish formal exit security procedure
    2. Create exit security checklist (paper or digital)
    3. Implement access revocation workflow (manual or automated)
    4. Create asset return process with verification
    5. Create data deletion verification process
    6. Implement exit interview with security focus
    7. Create an exit clearance record
    8. Schedule exit checks within the notice period (do not link them to payment of wages)
    9. Train HR and managers on exit procedure
    10. Process first exit with new procedure (test case)

Week 7: Automation and Tools

  • Deliverable: Automated access revocation and asset tracking operational
  • Owner: IT + CISO + HR
  • Activities:
    1. Configure automatic access revocation in IAM/AD upon HR trigger
    2. Integrate HRIS with IT ticketing for exit notifications
    3. Implement asset tracking system (barcode/RFID)
    4. Configure DLP monitoring for departing employees (30-day pre-exit monitoring)
    5. Set up post-employment monitoring alerts (email forwarding, account access attempts)
    6. Create automated exit report (all access revoked, assets returned, clearance status)
    7. Test automation with mock exit scenario
    8. Train IT staff on automated exit workflow

Week 8: Role Change Procedure Implementation

  • Deliverable: Role change security procedure operational
  • Owner: HR + CISO + IT
  • Activities:
    1. Create role change security checklist (access removal, access addition, training)
    2. Implement role change trigger in HRIS (promotion, transfer, lateral move)
    3. Create role-based access control (RBAC) matrix for role changes
    4. Implement automated access adjustment upon role change
    5. Create asset reassignment process (return old, receive new)
    6. Implement role change training requirement (security training for new role)
    7. Create role change documentation template
    8. Test with first role change

Phase 4: Testing & Validation (Weeks 9-10)

Week 9: Process Testing

  • Deliverable: Process validation report with mock scenarios
  • Owner: HR + Internal Audit + CISO + IT
  • Activities:
    1. Test voluntary resignation exit (full procedure)
    2. Test involuntary termination exit (rapid procedure)
    3. Test role change (promotion with access change)
    4. Test contract end exit (temporary staff)
    5. Test remote worker exit (home device return)
    6. Test access revocation verification (all systems checked)
    7. Test asset return verification (all assets accounted for)
    8. Test data deletion verification (personal device scan)
    9. Test exit interview process (security questions, obligation reminder)
    10. Test that exit checks complete by the last working day
    11. Test post-employment monitoring (detection of violations)

Week 10: Compliance and Audit Validation

  • Deliverable: Compliance validation report
  • Owner: Legal + Compliance Manager + HR
  • Activities:
    1. Validate contract enforceability (Legal review)
    2. Verify DPDP compliance for ex-employee data handling
    3. Verify labor law compliance (notice period, gratuity, full and final settlement)
    4. Test NDA enforcement mechanism (breach notice template)
    5. Verify access revocation for all past exits (last 90 days)
    6. Verify asset return for all past exits (last 90 days)
    7. Verify exit interview completion rate
    8. Verify clearance certificate issuance rate
    9. Prepare compliance evidence package
    10. Conduct internal audit of exit security procedure

Phase 5: Documentation & Certification Prep (Weeks 11-12)

Week 11: Documentation

  • Deliverable: Complete exit security documentation
  • Owner: HR + Compliance Manager
  • Activities:
    1. Document all policies, procedures, and checklists
    2. Create illustrative scenarios and examples (anonymized)
    3. Create training materials for managers and HR
    4. Create employee FAQ on exit security
    5. Create metrics dashboard and reporting templates
    6. Create evidence repository for audits
    7. Document automation configuration and workflows

Week 12: Certification Readiness

  • Deliverable: Audit-ready evidence package
  • Owner: CISO + Compliance Manager
  • Activities:
    1. Conduct internal audit of exit security procedure
    2. Prepare evidence for external ISO 27001 auditor
    3. Remediate any gaps found
    4. Conduct management review
    5. Present program to certification body

Detailed Implementation Guidance

Step-by-Step Implementation

Step 1: Define Exit Triggers

Trigger TypeDescriptionSecurity ImpactProcedure
Voluntary ResignationEmployee resigns with noticeMedium (time to plan, but risk of data exfiltration during notice period)Standard exit procedure; 30-day monitoring during notice period
Involuntary TerminationEmployee terminated by employerHigh (immediate termination, potential retaliation)Rapid exit procedure; immediate access revocation; escorted exit; asset collection; no notice period access
Contract EndContract/temporary employee contract endsMedium (planned but may have same access as permanent)Standard exit procedure; ensure all assets returned
RetirementEmployee retiresLow (usually planned, less risk)Standard exit procedure; knowledge transfer emphasis; ensure all obligations communicated
DeathEmployee diesLow (no malicious intent, but data recovery needed)Data recovery and transfer; asset collection from family; legal compliance
Disability / Medical LeaveEmployee unable to continueMedium (access may be needed for long time)Access suspension (not revocation) during leave; reassessment upon return
Role ChangeEmployee changes role within organizationHigh (old access may not be removed, new access added)Access adjustment procedure; remove old, add new; asset reassignment; training update
SuspensionEmployee suspended pending investigationHigh (access must be suspended immediately)Immediate access suspension; asset return may be delayed; monitoring
Garden LeaveEmployee paid but not working during notice periodMedium (no access, but still employed)All access revoked; no physical access; monitoring for violations

Step 2: Create Exit Security Checklist

Access Revocation Checklist:

  • Active Directory / LDAP account disabled
  • Email account disabled or forwarded (with monitoring)
  • VPN access revoked
  • Remote desktop access revoked
  • Cloud accounts (AWS, Azure, GCP) access revoked
  • SaaS application access revoked (CRM, ERP, HRIS, etc.)
  • Database access revoked
  • Code repository access revoked (GitHub, GitLab, Bitbucket)
  • CI/CD pipeline access revoked
  • Monitoring and admin tool access revoked
  • Wi-Fi access revoked
  • Physical access card deactivated
  • Parking pass collected
  • Biometric access deactivated
  • Security alarm codes changed
  • Shared accounts password changed (if employee knew them)
  • API keys and tokens revoked
  • SSH keys removed from servers
  • SSL certificates and encryption keys transferred
  • Mobile device management (MDM) account wiped/removed
  • Collaboration tools (Slack, Teams, Confluence) access revoked
  • Social media admin access revoked (if applicable)
  • Customer portal admin access revoked
  • Vendor portal access revoked
  • Third-party service access revoked (where employee was admin)

Asset Return Checklist:

  • Laptop/desktop returned
  • Mobile phone/tablet returned
  • Monitor(s) returned
  • Keyboard, mouse, docking station returned
  • External hard drives returned
  • USB drives returned
  • Access card returned
  • ID badge returned
  • Keys returned (office, server room, cabinet, safe)
  • Company vehicle returned (if applicable)
  • Company credit card returned
  • Security tokens, smart cards, RSA tokens returned
  • Printed documents returned (or securely destroyed)
  • Company data on personal devices verified deleted
  • Cloud storage (personal accounts) verified no company data
  • Email forwarding rules removed (if any were set up)
  • Personal belongings cleared from workspace
  • Home office equipment returned (if remote worker)
  • Customer gifts, samples, promotional materials returned
  • Proprietary tools, software licenses returned
  • Uniforms, safety equipment returned (if applicable)

Data and Security Checklist:

  • Data backup from employee devices completed
  • Device wiped and reimaged (if returning to asset pool)
  • Forensic image taken (if termination for cause)
  • Email archive preserved for legal/compliance
  • Personal data on company devices identified and separated
  • DLP scan of recent activity (30-90 days pre-exit)
  • Log review for suspicious activity (30-90 days pre-exit)
  • Customer data handling verified (no unauthorized copies)
  • IP and code repository access verified revoked
  • Confidential documents verified not in personal email/cloud
  • Social media posts reviewed (no confidential information shared)
  • Personal accounts used for work (Shadow IT) identified and addressed
  • Collaboration tool content (Slack, Teams) archived
  • Project files and knowledge documents transferred
  • Password manager access revoked (company vault)

Obligations Reminder Checklist:

  • NDA obligations explained and signed acknowledgment
  • IP assignment obligations explained
  • Confidentiality and non-solicitation obligations explained
  • Non-solicitation obligations explained (customers and employees)
  • Non-disparagement obligations explained
  • Data deletion obligations explained (personal devices)
  • Return of confidential information obligations explained
  • Continuing cooperation obligations explained (if applicable)
  • Legal consequences of breach explained
  • Contact information for legal/HR provided for questions
  • Signed exit acknowledgment form obtained

Full and Final Settlement Checklist:

  • Exit security checklist complete by the last working day
  • Outstanding dues calculated
  • Asset recovery costs calculated (if unreturned)
  • Gratuity processed (if applicable)
  • PF/ESI processed
  • Tax documents (Form 16) provided
  • Relieving letter issued
  • Experience certificate issued
  • Reference contact provided (if positive reference)
  • Settlement agreement signed (if applicable)
  • Final payment processed
  • Exit survey completed (optional)

Step 3: Implement Access Revocation

Timeline for Access Revocation:

System TypeVoluntary ResignationInvoluntary TerminationRole Change
Critical systems (admin, finance, customer data)Day of noticeImmediateWithin 4 hours
Standard systems (email, CRM, ERP)Last working dayImmediateWithin 24 hours
Development systems (code repo, CI/CD)Last working dayImmediateWithin 4 hours
Physical accessLast working dayImmediateWithin 24 hours
VPN/Remote accessLast working dayImmediateWithin 4 hours
Cloud adminDay of noticeImmediateWithin 4 hours
Shared accountsLast working dayImmediate (change password)Within 24 hours
Third-party servicesLast working dayImmediateWithin 48 hours

Access Revocation Process:

  1. HR triggers exit in HRIS (resignation date, termination date, role change date)
  2. HRIS auto-generates IT ticket for access revocation
  3. IT disables access in identity management system (AD, LDAP, SSO)
  4. IT revokes access in all connected systems (automated or manual)
  5. IT verifies revocation (test login attempts, review access logs)
  6. Security team reviews logs for recent suspicious activity (30-90 days)
  7. IT updates asset inventory (device assignment removed)
  8. Facilities deactivates physical access
  9. HR verifies all revocations complete before clearance certificate

Step 4: Implement Asset Return

Asset Return Process:

  1. HR notifies employee of asset return requirements upon resignation/termination
  2. Employee returns all assets to IT/Admin on last working day
  3. IT/Admin verifies asset condition and functionality
  4. IT/Admin updates asset inventory (returned, condition noted)
  5. IT wipes data from devices (if returning to pool) or creates forensic image (if termination for cause)
  6. IT returns personal data to employee (if found on company device)
  7. Finance verifies no outstanding asset loans or charges
  8. If assets are missing, HR/Finance pursues return or recovery; deductions from wages only where the Code on Wages s.18 permits, with Legal sign-off
  9. Asset reassigned or disposed of per A.5.9 and A.7.14

Step 5: Implement Data Deletion Verification

Data Deletion Process:

  1. Employee signs data deletion affidavit (affirming no company data on personal devices)
  2. IT provides data deletion guidance (how to delete from personal devices, cloud accounts, email)
  3. For high-risk exits, IT may request device scan or remote wipe (if BYOD with MDM)
  4. DLP scan confirms no recent data exfiltration to personal accounts
  5. Email forwarding rules checked and removed
  6. Personal cloud storage (Google Drive, Dropbox) checked for company data (if employee consented to scan)
  7. Leaver confirms in writing that company data has been deleted from personal devices and accounts (do not scan personal accounts)
  8. (No social media checks: act only on specific evidence, with legal advice)

Step 6: Implement Exit Interview with Security Focus

Exit Interview Security Questions:

  1. Do you understand that your NDA obligations continue after employment?
  2. Have you returned all company assets, including devices, documents, and access cards?
  3. Have you deleted all company data from your personal devices and accounts?
  4. Have you removed company email access from your personal phone?
  5. Do you have any company information in your personal email, cloud storage, or devices?
  6. Are you aware that taking company confidential information is a breach of contract and may be illegal?
  7. Have you shared any company confidential information with anyone outside the organization?
  8. Do you know who to contact if you have questions about your post-employment obligations?
  9. Have you been approached by anyone to share company information?
  10. Do you understand your continuing confidentiality and non-solicitation obligations, whoever your next employer is?

Exit Interview Reminders:

  • Remind employee of NDA obligations and legal consequences of breach
  • Remind employee of IP assignment obligations
  • Remind employee of non-solicitation obligations (customers and employees)
  • Remind employee of data deletion obligations
  • Provide contact information for legal questions
  • Provide copy of NDA and relevant contract clauses
  • Document that obligations were communicated and acknowledged

Step 7: Complete Exit Security Checks Without Holding Back Pay

Exit checks run during the notice period, not after it:

  • Plan the exit checklist so it is complete on or before the last working day:
    • All assets returned
    • All access revoked (on the last day at the latest; immediately for high-risk exits)
    • Exit interview completed with obligation acknowledgement
    • Any security concerns (suspicious activity, data exfiltration) escalated to the CISO and Legal
  • Wages due on exit must be paid within two working days of resignation, removal, dismissal or retrenchment (Code on Wages 2019, s.17(2)). Security checks are not a lawful reason to delay them.
  • Deductions for unreturned or damaged assets are allowed only where the asset was expressly entrusted to the employee and the loss is attributable to their neglect or default, within the limits of the Code on Wages s.18 (total deductions are capped). Get Legal sign-off first; otherwise recover the asset or its value separately.
  • Gratuity can be forfeited only on the narrow grounds in the Code on Social Security 2020, s.53(6) (for example, to the extent of damage caused by wilful omission or negligence). Provident fund cannot be withheld.
  • Serious security concerns are handled through the legal enforcement route (Step 11), not by holding back statutory dues.

Step 8: Implement Post-Employment Monitoring

After-Exit Checks (internal systems only):

  • Check for email forwarding rules set up before exit and remove them
  • Alert on login attempts using the leaver's old credentials
  • Review DLP and access logs for unusual data movement during the notice period
  • Act on specific evidence of misuse (for example a customer complaint or a found document) with legal advice

General surveillance of former employees (social media, job moves, contacts) is disproportionate under the DPDP Act and is not needed for A.6.5. Post-employment non-competes are void in India, so a move to a competitor is not itself a breach.

Duration: 30 to 90 days of internal log review is usually enough; keep the period proportionate and documented.

Step 9: Implement Role Change Procedure

Role Change Security Process:

  1. HR triggers role change in HRIS (old role, new role, effective date)
  2. HRIS auto-generates IT ticket for access adjustment
  3. IT removes access for old role (per old role access matrix)
  4. IT adds access for new role (per new role access matrix)
  5. IT verifies no excess access (only new role access, no old role access)
  6. Employee returns old role assets (if applicable)
  7. Employee receives new role assets (if applicable)
  8. Employee completes security training for new role (if required)
  9. Manager verifies knowledge transfer from old role
  10. Security team verifies access adjustment in next review cycle

Step 10: Implement Contractual Obligations

Employment Contract Obligations:

  • NDA: Employee agrees not to disclose confidential information during and after employment
  • IP Assignment: Employee agrees that all work product is owned by employer
  • Non-Compete: Employee agrees not to work for competitor for limited period (reasonable in scope, geography, duration, limited enforceability in India)
  • Non-Solicitation: Employee agrees not to solicit customers or employees for limited period
  • Non-Disparagement: Employee agrees not to disparage employer
  • Data Deletion: Employee agrees to delete all company data from personal devices upon exit
  • Return of Property: Employee agrees to return all company property upon exit
  • Cooperation: Employee agrees to cooperate in legal proceedings (if applicable)
  • Breach Penalties: Employee acknowledges legal consequences of breach (damages, injunction)

India-Specific Contract Considerations:

  • Non-compete: Generally unenforceable in India for employment contracts (Section 27 of Indian Contract Act), but may be enforceable for sale of goodwill or during employment. Post-employment non-compete is usually void. Focus on non-solicitation and NDA instead.
  • NDA: Enforceable for trade secrets and confidential information. Must be reasonable in scope and duration.
  • IP Assignment: Enforceable for employee inventions created during employment. Must specify what is covered.
  • Governing Law: Indian law; jurisdiction in Indian courts.
  • Garden Leave: Valid if employer pays salary during notice period. All access can be revoked during garden leave.

Step 11: Implement Legal Enforcement

Enforcement Framework:

  1. Breach Detection: Internal logs, a complaint or other specific evidence suggests a breach of continuing obligations
  2. Incident first: If personal or customer data has left with the person, treat it as a security incident (A.5.24–A.5.26): contain, assess, and decide notifications now (CERT-In within 6 hours for reportable incidents; DPDP Board and affected people without delay once the Rules' breach duties apply; sector regulators as required)
  3. Evidence Collection: Preserve evidence (A.5.28): logs, documents, witness statements
  4. Breach Notice: Send formal breach notice to ex-employee (cease and desist, damages, legal action)
  5. Settlement Negotiation: Attempt to resolve without litigation (return of information, damages, commitment)
  6. Injunction: If urgent, seek court injunction to stop breach (ex-parte injunction if necessary)
  7. Litigation: File civil suit for breach of contract, breach of confidence, or copyright infringement
  8. Criminal Action: If theft, criminal breach of trust or cheating (BNS), IT Act offences, or Official Secrets Act violation, file a police complaint

Step 12: Implement DPDP Compliance

Ex-Employee Data Management:

  • Retention: Retain ex-employee data only for legal and compliance purposes (tax, labor law, legal claims)
  • Deletion: Delete personal data when legal retention period expires (with legal justification)
  • Justification: Document the legal basis for retention (for example payroll records in the books of account for 8 years under Companies Act s.128(5), Labour Code registers as their rules prescribe, and limitation periods for possible claims)
  • Access: Ex-employees have DPDP rights to information, correction and erasure once the Act's duties apply (about May 2027)
  • Correction: Ex-employee can request correction of inaccurate personal data
  • Grievance: Ex-employee can file grievance regarding their data
  • Contact point: The Data Fiduciary's published contact person (s.8(9)) handles ex-employee requests; a DPO is required only for Significant Data Fiduciaries
  • Security: Ex-employee data must be secured with same rigor as current employee data

Step 13: Implement Knowledge Transfer

Knowledge Transfer Process:

  1. Manager identifies critical knowledge and responsibilities of departing employee
  2. Manager identifies replacement or knowledge recipient
  3. Departing employee documents processes, procedures, and tribal knowledge
  4. Departing employee conducts handover sessions with replacement
  5. Departing employee provides access to all relevant files, documents, and systems
  6. Manager verifies knowledge transfer completeness
  7. Documentation archived for future reference
  8. Replacement trained on critical tasks before departure

Step 14: Implement Metrics and Reporting

  • Track exit security clearance completion rate (target: 100%)
  • Track access revocation timeline (target: <4 hours for critical, <24 hours for standard)
  • Track asset return rate (target: 100%)
  • Track missing assets (target: <2%)
  • Track exit interview completion rate (target: 100%)
  • Track post-employment monitoring alerts (trending)
  • Track legal enforcement actions (trending down)
  • Track role change access adjustment errors (target: <1%)
  • Report quarterly to management and board
  • Benchmark against industry data

Step 15: Continuous Improvement

  • Annual review of exit security procedure
  • Quarterly metrics review
  • Annual contract review (NDA, IP, non-solicitation)
  • Post-exit review of critical exits (lessons learned)
  • Update for regulatory changes (DPDP, labor law, industry-specific)
  • Benchmark against industry best practices
  • Gather feedback from departing employees on exit process
  • Update automation based on process changes
  • Review and update role change access matrix
  • Test post-employment monitoring effectiveness

Tools, Technologies, and Solutions

Complete Tool Comparison

ToolCategoryBest ForPricing modelKey FeaturesIntegration
ServiceNowITSM/HREnterprise exit automationCommercialExit workflow, access revocation automation, asset tracking, case managementFull enterprise
BambooHRHRISSMB exit managementCommercialExit workflow, offboarding checklist, asset tracking, access management100+ integrations
WorkdayHRISEnterprise HRCommercialExit management, role change, access management, compliance, analyticsFull enterprise
SAP SuccessFactorsHRISEnterprise HRCommercialExit management, offboarding, role change, access, complianceSAP ecosystem
Zoho PeopleHRISIndian SMBCommercialExit checklist, offboarding, asset tracking, access managementZoho ecosystem
GreytHRHRISIndian SMBCommercialExit management, full and final settlement, compliance, Indian labor lawIndian compliance
OktaIAMAccess revocationCommercialSSO, automated access revocation, lifecycle management, MFA7,000+ integrations
Azure AD / Entra IDIAMMicrosoft ecosystemCommercialIdentity lifecycle, automated provisioning/deprovisioning, conditional accessMicrosoft ecosystem
Google WorkspaceIAMGoogle ecosystemCommercialUser lifecycle, access management, device management, vaultGoogle ecosystem
JumpCloudIAMSMB IAMCommercialDirectory, SSO, access management, device management, lifecycleMulti-platform
OneLoginIAMEnterprise SSOCommercialSSO, access management, lifecycle management, MFA6,000+ integrations
Microsoft IntuneMDMDevice managementCommercialDevice enrollment, remote wipe, policy management, asset trackingMicrosoft 365
Omnissa Workspace ONE (formerly VMware)MDMEnterprise device managementCommercialDevice lifecycle, remote wipe, compliance, asset trackingVMware ecosystem
JamfMDMApple device managementCommercialApple device enrollment, remote wipe, policy managementApple ecosystem
Google Endpoint ManagementMDMGoogle device managementCommercialAndroid device management, remote wipe, policyGoogle Workspace
Symantec DLPDLPData exfiltration detectionCommercialEndpoint DLP, network DLP, cloud DLP, exit monitoringEnterprise
Forcepoint DLPDLPEnterprise DLPCommercialEndpoint, network, cloud DLP, behavioral analyticsEnterprise
Microsoft PurviewDLPMicrosoft ecosystemCommercialDLP, eDiscovery, compliance, monitoring, insider riskMicrosoft 365
ProofpointDLPEmail and cloud DLPCommercialEmail DLP, cloud DLP, CASB, insider threatEnterprise
NetskopeCASBCloud access and DLPCommercialCloud DLP, CASB, remote work security, shadow ITEnterprise
ServiceNow Asset ManagementAssetAsset trackingCommercialAsset lifecycle, inventory, tracking, return, reassignmentServiceNow
FreshserviceITSMSMB asset and exit managementCommercialAsset management, exit workflow, ticket management, CMDBFreshworks
Snipe-ITAssetOpen-source asset trackingFreeAsset inventory, check-in/check-out, barcode, reportingOpen-source
LansweeperAssetIT asset discoveryCommercialAsset discovery, inventory, tracking, lifecycle managementMulti-platform
eDiscovery / Legal HoldLegalEvidence preservationCommercialLegal hold, evidence preservation, eDiscovery, chain of custodyLegal, case management
VaultLegalEmail and data holdCommercialEmail legal hold, evidence preservation, complianceGoogle Workspace
Microsoft Purview eDiscoveryLegaleDiscoveryCommercialeDiscovery, legal hold, compliance, data governanceMicrosoft 365
Contract ManagementLegalContract repositoryCommercialContract repository, version control, obligation tracking, alertsHR, legal
IroncladLegalContract lifecycleCommercialContract management, workflow, repository, analyticsEnterprise
DocuSign CLMLegalContract managementCommercialContract lifecycle, e-signature, repository, workflowEnterprise
VeritasBackupData backup and archiveCommercialData backup, email archive, compliance, eDiscoveryEnterprise
VeeamBackupData backupCommercialData backup, recovery, archive, complianceMulti-platform
User Activity MonitoringMonitoringInsider threat detectionCommercialUser activity monitoring, behavioral analytics, exit risk detectionSecurity
TeramindMonitoringInsider threatCommercialUser activity monitoring, DLP, behavioral analytics, forensicsSecurity
SplunkSIEMLog analysis and monitoringCommercialLog analysis, security monitoring, incident detection, forensicsEnterprise
Elastic SecuritySIEMOpen-source SIEMFree / +Log analysis, security monitoring, incident detectionOpen-source
Carbon BlackEDREndpoint forensicsCommercialEndpoint detection, forensics, threat hunting, incident responseSecurity
CrowdStrikeEDREndpoint protectionCommercialEDR, threat hunting, forensics, incident responseSecurity
VaronisData SecurityData access monitoringCommercialData access monitoring, user behavior, threat detection, forensicsEnterprise
Proofpoint Insider ThreatInsider ThreatInsider threat detectionCommercialInsider threat detection, behavioral analytics, exit riskEnterprise

Recommendations by Organization Size

SizeHRISIAMMDMDLPAssetLegalMonitoring
Startup (<50)BambooHR or ZohoJumpCloud or OktaMicrosoft Intune or GoogleMicrosoft PurviewSnipe-ITDocuSignMicrosoft Purview
SMB (50-500)BambooHROkta or Azure ADMicrosoft IntuneMicrosoft Purview or ForcepointSnipe-IT or FreshserviceDocuSign or IroncladMicrosoft Purview or Splunk
Mid-market (500-5000)Workday or SAPOkta or Azure ADVMware or IntuneSymantec or ForcepointServiceNow or LansweeperIronclad or DocuSignSplunk or Elastic
Enterprise (5000+)Workday or SAPOkta + Azure ADVMware + Intune + JamfSymantec + ForcepointServiceNowIronclad + DocuSignSplunk + Carbon Black + Varonis

Policy and Procedure Templates

Exit Security Policy (Key Sections)

Template

Exit Security Procedure

Template


Risk Assessment and Treatment

Key Risks Addressed by This Control

Risk IDRisk DescriptionLikelihoodImpactRisk LevelTreatment
R-001Ex-employee retains access to systemsMediumHighHighMitigate, Automated access revocation, verification, monitoring
R-002Ex-employee takes confidential data to competitorMediumHighHighMitigate, NDA, DLP, post-employment monitoring, legal enforcement
R-003Ex-employee shares login credentials with new employerMediumMediumMediumMitigate, Access revocation, shared password change, credential monitoring
R-004Ex-employee retains company assetsMediumMediumMediumMitigate, Asset tracking, return verification, settlement linkage
R-005Role change leaves old access intactMediumHighHighMitigate, Role-based access control, automated adjustment, access review
R-006Ex-employee data not managed under DPDPMediumMediumMediumMitigate, DPDP compliance program, retention justification, deletion
R-007Exit process delays create security gapMediumHighHighMitigate, Automation, SLA, escalation, rapid exit procedure
R-008Ex-employee sues for wrongful termination related to securityLowHighMediumMitigate, Legal compliance, due process, documentation
R-009Knowledge loss due to poor knowledge transferMediumMediumMediumMitigate, Knowledge transfer procedure, documentation, replacement training
R-010Ex-employee disparages company on social mediaMediumMediumLowMitigate, Non-disparagement clause, monitoring, legal action if breach
R-011Ex-employee solicits customers or employeesMediumHighMediumMitigate, Non-solicitation clause, monitoring, legal enforcement
R-012Data exfiltration during notice periodMediumHighHighMitigate, DLP monitoring, access restriction, activity monitoring
R-013Personal data on company devices not returnedLowMediumLowMitigate, Personal data separation, return to employee, privacy compliance
R-014Unreturned assets create security riskMediumMediumMediumMitigate, Asset tracking, inventory, return verification, recovery
R-015Contractual obligations not enforceableLowHighMediumMitigate, Legal review, reasonable scope, Indian law compliance

Audit and Compliance Checklist

Audit Questions (25 Questions)

#Audit QuestionExpected EvidenceRed Flags
1Is there a formal exit security procedure?Approved procedureNo formal procedure, ad-hoc exits
2Is the exit procedure triggered by all exit types?Procedure scopeOnly some exit types covered
3Is access revoked within defined timelines?Access revocation logs, SLA reportsAccess lingering for days/weeks
4Is asset return verified?Asset return records, inventory updatesUnreturned assets, no verification
5Is data deletion verified?Data deletion affidavit, DLP reportsNo verification, data on personal devices
6Is there an exit interview with security focus?Exit interview records, acknowledgmentNo exit interview, no security focus
7Are post-employment obligations in contracts?Employment contracts, NDANo NDA, no post-employment obligations
8Are obligations communicated at exit?Exit interview records, signed acknowledgmentNo communication, no acknowledgment
9Are exit security checks completed by the last working day, without delaying wages?Exit checklists, settlement datesChecks finished after exit, or wages held back for "clearance"
10Is there post-employment monitoring?Monitoring records, alertsNo monitoring, no detection
11Is there a role change security procedure?Role change procedureNo role change procedure
12Is access adjusted on role change?Access logs, role change recordsOld access retained after role change
13Are all systems included in access revocation?Access revocation checklist, verificationSome systems missed (Shadow IT, shared accounts)
14Is there a rapid exit procedure for involuntary termination?Rapid exit procedureNo rapid procedure, same as voluntary
15Is there DPDP compliance for ex-employee data?DPDP policy, retention justification, deletion recordsNo DPDP compliance, indefinite retention
16Are exit security records maintained?Exit records, checklists, certificatesNo records, no documentation
17Is there a legal enforcement mechanism for breaches?Legal framework, breach notices, litigation recordsNo enforcement, breaches ignored
18Is there knowledge transfer for critical roles?Knowledge transfer records, documentationNo knowledge transfer, critical knowledge lost
19Is there monitoring for data exfiltration during notice period?DLP logs, monitoring reportsNo monitoring during notice period
20Are shared account passwords changed on exit?Password change records, access logsShared passwords unchanged
21Are API keys and tokens revoked on exit?API key management records, revocation logsAPI keys still active
22Is there a garden leave policy for critical roles?Garden leave policyNo garden leave, critical roles exposed
23Is there remote worker exit procedure?Remote exit procedureNo remote procedure, remote assets unaccounted
24Is there contractor exit procedure?Contractor exit procedureNo contractor procedure, contractor risks
25Is the exit procedure reviewed annually?Management review minutes, audit reportsNo review, stale procedure

Metrics and KPIs

Figure · Measures

The measures that show A.6.5 is working

  • Access Revocation SLA Compliance>98%Per exit
  • Asset Return Rate>98%Per exit
  • Missing Asset Rate<2%Monthly
  • Exit Interview Completion100%Per exit
  • Security Clearance Completion100%Per exit
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Metrics Dashboard

KPIFormulaTargetFrequency
Access Revocation SLA Compliance(Access revoked within SLA / Total exits) × 100>98%Per exit
Asset Return Rate(Assets returned / Total assets due) × 100>98%Per exit
Missing Asset Rate(Missing assets / Total assets due) × 100<2%Monthly
Exit Interview Completion(Exit interviews completed / Total exits) × 100100%Per exit
Security Clearance Completion(Security clearances issued / Total exits) × 100100%Per exit
Data Deletion Affidavit Rate(Affidavits signed / Total exits) × 100100%Per exit
DLP Scan Completion(DLP scans completed / Total exits) × 100>95%Per exit
Post-Employment Monitoring AlertsNumber of alerts generated post-exitTrending downMonthly
Legal Enforcement ActionsNumber of legal actions for post-employment breachesTrending downQuarterly
Role Change Access Adjustment SLA(Access adjusted within SLA / Total role changes) × 100>98%Per role change
Excess Access After Role Change(Role changes with excess access / Total role changes) × 100<1%Quarterly
Knowledge Transfer Completion(Knowledge transfers completed / Critical role exits) × 100100%Per critical exit
Settlement Processing TimeAverage days from exit to settlement<15 daysMonthly
Employee Satisfaction (Exit)Exit survey satisfaction score>3.5/5Quarterly
Contractual Obligation Coverage(Employees with NDA / Total employees) × 100100%Annual
DPDP Compliance (Ex-Employee Data)DPDP audit score for ex-employee data>95%Quarterly
Lingering Access Detection(Exits with lingering access found / Total exits) × 100<1%Monthly
Shadow IT Access Revocation(Shadow IT accounts revoked / Shadow IT accounts identified) × 100100%Per exit
Exit Checks on Time(Exits with all security checks done by the last working day / Total exits) × 100100%Monthly
Notice Period Monitoring(Notice period employees monitored / Total notice period employees) × 100100%Monthly
Rapid Exit Procedure Compliance(Rapid exits completed per procedure / Total rapid exits) × 100100%Per rapid exit
Remote Exit Completion(Remote exits completed per procedure / Total remote exits) × 100100%Per remote exit
Contractor Exit Compliance(Contractor exits per procedure / Total contractor exits) × 100100%Per contractor exit
Post-Employment Breach Detection Rate(Breaches detected / Estimated breaches) × 100>80%Quarterly
Ex-Employee Data Retention Compliance(Ex-employee data deleted per schedule / Scheduled deletions) × 100100%Quarterly

Common Pitfalls and How to Avoid Them

#PitfallWhy It HappensHow to Avoid
1No formal exit procedureSmall company, informal cultureCreate simple exit checklist even for small teams
2Access not revoked promptlyManual process, multiple systems, lack of automationAutomate access revocation, SLA, escalation, verification
3Shadow IT access missedUnmanaged accounts, personal accounts for workShadow IT discovery, SSO, complete access inventory
4Shared passwords not changedForgotten, no process, assumption of securityAutomated shared password change on exit, checklist item
5Assets not trackedNo asset inventory, no tracking systemAsset inventory, barcode/RFID, tracking system, return verification
6No exit interviewTime pressure, assumption of unnecessaryMandatory exit interview, security questions, obligation reminder
7Post-employment obligations not in contractsOutdated contracts, no legal reviewContract review, NDA addendum, IP assignment, non-solicitation
8No post-employment monitoringCost, privacy concerns, assumption of complianceDLP review, login monitoring, competitive intelligence, legal framework
9Role change leaves old accessNo role change procedure, manual processRole-based access control, automated adjustment, access review
10Exit checks left until after the employee has goneTime pressure, no exit timelineStart the checklist when notice is given; finish by the last working day; never hold back wages
11No DPDP compliance for ex-employee dataUnawareness, no retention policyDPDP program, retention schedule, deletion justification, audit
12Remote worker assets not returnedRemote location, shipping logistics, no processPrepaid shipping labels, tracking, remote exit procedure, deposit
13No knowledge transferTime pressure, departure urgency, no processKnowledge transfer requirement, documentation, handover sessions
14No rapid exit procedureAssumption that all exits are sameSeparate rapid exit procedure for involuntary termination
15Contractor exit ignoredContract not employment, assumption of less riskContractor exit procedure, same rigor as employee
16No monitoring during notice periodTrust, assumption of good behavior, no toolsDLP monitoring, access restriction, activity monitoring during notice
17Personal data on company devices lostNo separation process, no return policyPersonal data identification, separation, return to employee
18Non-compete clauses that are unenforceableCopying foreign contracts, no legal reviewIndian law compliance, focus on NDA and non-solicitation instead
19No legal enforcement when breach detectedCost, effort, assumption of futilityLegal framework, breach notice template, litigation budget, monitoring
20Exit records not maintainedInformality, no record-keeping cultureMandatory documentation, case management system, audit trail
21Garden leave not used for critical rolesCost, assumption of unnecessaryGarden leave policy for critical roles (BFSI, senior execs, technical)
22No integration between HR and ITSilos, no system integration, manual handoffHRIS-IT integration, automated ticketing, SSO, lifecycle management
23BYOD devices not addressedNo MDM, no BYOD policy, assumption of no riskMDM, BYOD policy, remote wipe, data deletion verification
24No forensics for termination for causeNo process, no tools, no expertiseForensic image procedure, incident response, evidence preservation
25Social media admin access forgottenNot in standard access list, personal accounts usedSocial media access inventory, admin access revocation, monitoring

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian SaaS Company, CloudSync Solutions

Company Profile:

  • Size: 220 employees
  • Industry: B2B SaaS, Cloud Integration Platform
  • Location: Hyderabad, India
  • Customers: 350 enterprise clients globally
  • Regulatory Scope: DPDP Act 2023, SOC 2 Type II, ISO 27001, GDPR

Challenge: CloudSync had a serious post-employment security problem:

  • When a senior developer resigned to join a competitor, his access was "revoked" but only his AD account was disabled
  • His GitHub access, AWS console access, and database access were never revoked (no one knew he had them)
  • He had cloned the entire source code repository to his personal GitHub account 2 weeks before resigning
  • He had downloaded customer database schemas and API documentation
  • He joined a direct competitor and launched a similar product in 6 months
  • CloudSync discovered the product similarity and investigated
  • Forensic analysis showed he had taken 80% of the source code and all API documentation
  • CloudSync sued for breach of NDA and trade secret misappropriation
  • The case was ongoing but legal fees had already reached
  • The competitor product was eroding CloudSync's market share (15% revenue decline in 6 months)
  • Customer trust was damaged; 3 major customers cited "security concerns" and churned
  • The company had no formal exit procedure, no asset tracking, no DLP, no post-employment monitoring
  • The employee had never signed a proper NDA (his offer letter had a vague "confidentiality" clause)
  • The company had no IP assignment agreement
  • There was no exit interview, no security clearance, no data deletion verification

Solution:

  1. Week 1-2: Emergency Exit Procedure

    • Engaged an external security consultant for emergency exit security redesign
    • Created formal Exit Security Procedure with complete checklist
    • Implemented automated access revocation through Azure AD lifecycle management
    • Created complete access inventory (all systems, all accounts, all employees)
    • Identified 47 "forgotten" accounts that ex-employees still had access to
    • Revoked all lingering access immediately
    • Created asset inventory and tracking system
  2. Week 3-4: Contract and Legal Framework

    • Drafted complete NDA for all employees (new and existing)
    • Drafted IP Assignment Agreement (all work product owned by company)
    • Drafted Non-Solicitation Agreement (customers and employees, 18 months)
    • Drafted Data Deletion Obligation Clause
    • Updated employment contracts for all new hires
    • Obtained signed NDA addendum from all 220 existing employees
    • Created legal enforcement framework (breach notice, injunction, litigation)
    • Created settlement agreement template with security terms
  3. Week 5-6: DLP and Monitoring

    • Implemented Microsoft Purview DLP across all endpoints and cloud
    • Configured DLP for source code, customer data, API documentation
    • Set up 30-day pre-exit monitoring for all resignations (DLP alert on data exfiltration)
    • Implemented email forwarding rule monitoring
    • Created post-employment monitoring framework (login attempts, competitive intelligence)
    • Trained security team on DLP and monitoring tools
  4. Week 7-8: Exit Procedure Implementation

    • Implemented HRIS-IT integration (BambooHR → Azure AD → IT ticket)
    • Created exit security checklist with 50+ items
    • Implemented exit interview with security focus (15 questions)
    • Created data deletion affidavit
    • Created security clearance certificate
    • Built exit security checks into the notice period
    • Created rapid exit procedure for involuntary termination
    • Processed first 5 exits with new procedure successfully
  5. Week 9-12: Metrics and Legal Action

    • Created quarterly metrics dashboard
    • 100% exit interview completion achieved
    • 100% security clearance completion achieved
    • Average access revocation: 2 hours (down from 7 days)
    • Zero lingering access incidents detected
    • DLP detected 3 data exfiltration attempts during notice periods (prevented)
    • Legal team sent breach notice to the ex-developer with evidence
    • Filed for injunction to stop competitor product launch
    • Negotiated settlement with ex-developer (return of code, damages, confidentiality and non-solicitation undertakings)
    • Won 2 major customers back after demonstrating improved security

Results:

  • Post-employment breaches: Zero in 6 months (vs. 1 catastrophic breach before)
  • Access revocation: 100% within 4 hours (vs. 7 days before)
  • Asset return: 98% (vs. 60% before)
  • Lingering access: Zero detected (47 were found and revoked initially)
  • DLP alerts: 3 data exfiltration attempts prevented during notice periods
  • Legal risk: Breach notice sent, injunction filed, settlement reached
  • Revenue: Stabilized after initial decline; won back 2 customers
  • Customer trust: Restored after demonstrating exit security program
  • Legal fees: for initial case; prevented future cases
  • Competitive advantage: Exit security became a sales differentiator

Illustrative Scenario 2: Large BFSI, Bharat Financial Services (BFS)

Company Profile:

  • Size: 6,500 employees, 5,800 frontline staff
  • Industry: Retail Banking and Financial Services
  • Location: Mumbai, India (branches nationwide)
  • Customers: 4.2 million retail customers, 15,000 corporate clients
  • Regulatory Scope: RBI, SEBI, IRDAI, DPDP Act 2023, ISO 27001, PCI DSS
  • Union: Frontline staff union (strong); CBA every 3 years

Challenge: BFS had a massive post-employment risk exposure:

  • Bank employees had access to customer financial data, KYC documents, loan details, and account information
  • When a relationship manager left, his access was revoked "within 24 hours" but this was only the core banking system
  • He still had access to 12 other systems (CRM, loan management, reporting, email, VPN) for days after exit
  • He had downloaded customer KYC documents and account statements to his personal laptop
  • He joined a competing bank and used the customer data to solicit high-net-worth clients
  • 18 customers complained about "unauthorized contact" from the ex-employee
  • RBI cyber security audit flagged "inadequate access revocation" as a major finding
  • The incident was a personal data breach: BFS had to report to CERT-In within 6 hours and inform affected customers, and RBI's inspection raised it with the bank
  • The ex-employee was not bound by a non-solicitation agreement (no such clause in contract)
  • The bank had 2,000+ exits per year (high turnover in frontline staff) with no formal exit security procedure
  • Exit interviews were just "how was your experience?" with no security focus
  • Exit security steps were not completed by the last working day
  • Role changes were common (promotion to branch manager, transfer to new branch) but old access was never removed
  • The bank had 47,000+ active accounts for 6,500 employees (massive over-provisioning)
  • Shadow IT was rampant: employees used personal WhatsApp, Google Drive, and personal email for work

Solution:

  1. Months 1-2: Crisis Assessment and Rapid Fix

    • Engaged an external security consultant for emergency exit security redesign
    • Conducted complete access audit: 47,000 accounts for 6,500 employees
    • Identified 12,000 orphaned accounts (ex-employees, role changes, contractors)
    • Revoked all 12,000 orphaned accounts immediately (emergency fix)
    • Identified 800 employees with excess access (not needed for their role)
    • Created emergency access revocation procedure for all exits (48-hour SLA)
    • Created RBI compliance remediation plan
  2. Months 3-4: Enterprise Exit Framework

    • Designed enterprise exit security framework for 6,500 employees
    • Created role-based access control (RBAC) for 200+ roles in banking
    • Created complete access inventory (all 47+ systems, all 6,500 employees)
    • Implemented automated access revocation through core banking system integration
    • Created exit security checklist (70+ items for banking context)
    • Created garden leave policy for relationship managers and senior roles (RBI requirement)
    • Implemented 30-day garden leave for all customer-facing roles
  3. Months 5-6: DLP and Monitoring

    • Implemented Symantec DLP across all endpoints and email
    • Configured DLP for customer data, KYC, financial data, RBI reports
    • Implemented 30-day pre-exit monitoring for all resignations (high-risk in banking)
    • Set up email forwarding rule monitoring
    • Implemented UEBA for behavioral anomaly detection
    • Created post-employment monitoring framework (customer contact detection, competitive intelligence)
    • Created RBI reporting dashboard for exit security metrics
  4. Months 7-8: Union and Contract Alignment

    • Engaged union for exit security alignment (CBA renewal was upcoming)
    • Union initially resisted "surveillance" but agreed after security risk education
    • Negotiated: exit security training is paid, security equipment provided, no personal surveillance, due process for all exits
    • CBA updated with security exit terms: asset return, access revocation, data obligations, garden leave
    • Updated employment contracts for all new hires with complete NDA, IP, non-solicitation
    • Obtained NDA addendum from 6,000 existing employees (98% compliance)
    • Created legal enforcement framework for banking context (RBI reporting, customer notification)
  5. Months 9-12: Implementation and RBI Compliance

    • Implemented HRIS-IT integration (Workday → core banking → IT ticket)
    • Trained 600 branch managers on exit security procedures (2-hour session)
    • Trained 50 HR staff on exit security coordination
    • Created exit interview with security focus for banking (20 questions)
    • Implemented security clearance certificate for all exits
    • Built exit security checks into the notice period, completed before the last working day
    • Created role change access adjustment procedure (remove old branch access, add new branch access)
    • Processed 2,000 exits with new procedure in first year
    • RBI audit: zero findings on exit security; commendation for improvement

Results:

  • Orphaned accounts: Zero (from 12,000)
  • Access revocation: 100% within 48 hours (from 7+ days)
  • Excess access: Reduced from 800 employees to 50 employees (ongoing cleanup)
  • Garden leave: 100% compliance for customer-facing roles (RBI requirement)
  • DLP alerts: 45 data exfiltration attempts detected and prevented in first year
  • Post-employment breaches: Zero detected (vs. 1 major before)
  • RBI audit: Zero findings on exit security; penalty avoided
  • Customer complaints: Zero unauthorized contact complaints (from 18 before)
  • Role change access: 98% adjusted within 24 hours (from no adjustment before)
  • Union relations: First bank with union-approved exit security terms
  • Cost: program investment vs. RBI penalty + reputational damage + customer loss
  • Industry recognition: Featured in RBI cybersecurity best practices for exit management

Multi-Framework Mapping

The references below genuinely overlap with A.6.5. Use them when one set of evidence must satisfy several frameworks.

FrameworkReferenceHow it relates
NIST SP 800-53 Rev 5PS-4 Personnel termination; PS-5 Personnel transferRevoke access, recover assets and remind leavers of continuing duties
PCI DSS v4.0.18.2.5Access for terminated users is revoked immediately
SOC 2 (2017 TSC)CC6.2, CC6.3Access removed or changed when people leave or change roles
CIS Controls v86.2 Establish an access revoking process; 5.3 Disable dormant accountsTimely removal of access
DPDP Act 2023s.8(7) erasure; s.8(5) safeguardsEx-employee data deleted once no longer needed (subject to other laws' retention)
Indian labour lawCode on Wages 2019 s.17(2) (wages within two working days of exit), s.18 (deductions); Code on Social Security 2020 s.53(6) (gratuity forfeiture)Exit checks must not delay statutory dues

Regulatory and Industry Context

India Regulatory Framework

RegulationExit RequirementPenalty
DPDP Act 2023Delete ex-employee data when purpose fulfilled; retention justifiedUp to ₹50 crore (residual penalty; ₹250 crore if safeguards fail)
IT Act 2000 (Section 43A)Reasonable security includes exit proceduresCompensation claims
Indian Contract Act 1872NDA, IP assignment, non-solicitation enforceableBreach of contract damages
Companies Act 2013Director resignation obligationsDirector liability
Code on Wages 2019 (s.17(2), s.18)Wages due within two working days of exit; deductions only on listed grounds and within limitsPenalties, claims
Industrial Relations Code 2020 (replaced the Industrial Disputes Act 1947)Notice, retrenchment and dismissal procedureLabor disputes
Code on Social Security 2020 (replaced the Payment of Gratuity Act 1972)Gratuity may be forfeited only on the grounds in s.53(6)Penalties
Code on Social Security 2020 (replaced the EPF Act 1952)PF cannot be withheldPenalties
Trade SecretsCommon law protectionCivil damages, injunctions
Copyright Act 1957Employee work product ownershipCopyright disputes
Patents Act 1970Employee inventionsPatent disputes
RBI Cyber Security FrameworkExit procedures for banking systems; garden leaveLicense restrictions
SEBI CSCRF (2024)Access revocation for departing personnel at regulated entitiesSupervisory action
IRDAI GuidelinesExit procedures for insurance dataLicense suspension
Official Secrets Act 1923Continuing secrecy obligationsCriminal prosecution
Code on Wages 2019 (replaced the Payment of Wages Act 1936)Wage deductions for asset recovery limitedPenalties
Code on Wages 2019 (replaced the Minimum Wages Act 1948)No deductions for asset recovery beyond limitsPenalties

International Regulations

RegulationExit Requirement
GDPR (EU)Article 17, Right to erasure (ex-employee data); Article 5, Purpose limitation
HIPAA (US)§164.308(a)(3)(ii)(C), Termination procedures; access revocation
SOX (US)Internal controls including access revocation upon termination
UK Employment Rights Act 1996Fair termination procedures; notice period; settlement
EU Whistleblower DirectiveProtection for employees reporting violations; anti-retaliation
ILO ConventionWorker rights and fair treatment upon termination
FCRA (US)Adverse action notice for background checks
CCPA (California)Employee data privacy; deletion rights

Sector-Specific Requirements

SectorExit-Specific Requirements
BFSIRBI-mandated exit procedures; garden leave for customer-facing roles; access revocation within 24 hours; customer data return; fraud response; integrity committee
HealthcareClinical staff exit; patient data return; access revocation; clinical handover
TelecomDOT security clearance revocation; subscriber data return; network access revocation; lawful interception access removal
ManufacturingOT system access revocation; IP return; standing orders compliance; union CBA exit terms; safety equipment return
GovernmentService rules exit; classified data return; Official Secrets Act; security clearance revocation; CVC clearance
DefenceSecurity clearance revocation; classified data return; export control compliance; foreign contact review; debriefing
AviationDGCA security clearance; airside access revocation; substance testing records; safety-critical role handover
EducationStudent data return; FERPA/GDPR compliance; IP return; research data transfer; POCSO obligations
SaaS / B2BSource code return; customer data deletion; cloud access revocation; SOC 2 compliance; developer code of conduct
E-commerceCustomer data return; payment data deletion; warehouse access revocation; delivery personnel asset return
PharmaDrug formula/data return; clinical trial records (NDCT Rules); IP return; patent data transfer
ConsultingClient deliverables return; confidential information; client relationship handover; non-solicitation; professional liability

Roles and Responsibilities (RACI)

ActivityAccountableResponsibleConsultedInformed
Exit PolicyCISOHR HeadLegalBoard
Exit TriggerHRHR ManagerCISO, ITEmployee
Access RevocationCISOIT TeamHR, SecurityEmployee
Asset ReturnCISOIT/AdminHR, FinanceEmployee
Data DeletionCISOIT SecurityLegalEmployee
Exit InterviewHRHR ManagerCISOEmployee
Security ClearanceCISOHR ManagerIT, LegalEmployee, Finance
Full and Final SettlementHRFinanceLegal, CISOEmployee
Post-Employment MonitoringCISOSecurity TeamLegalManagement
Contract EnforcementLegalLegal TeamCISO, HRBoard
NDA ManagementLegalHRCISOAll Employees
IP AssignmentLegalHRCISOAll Employees
Role Change AccessCISOIT TeamHR, ManagerEmployee
Knowledge TransferLine ManagerDeparting EmployeeHR, CISOReplacement
DPDP ComplianceLegalCompliance ManagerHR, CISOPrivacy contact (s.8(9))
Garden LeaveHRHR ManagerLegal, CISOEmployee
Rapid ExitCISOHR, IT, SecurityLegalManagement
Contractor ExitHRHR ManagerCISO, LegalContractor
Remote ExitHRHR ManagerIT, CISOEmployee
Forensic ImageCISOIT SecurityLegalManagement
Metrics and ReportingCISOHR AnalystComplianceBoard
Audit and ComplianceInternal AuditHR, CISO, ITLegalBoard
Union LiaisonLegalHR HeadCISOUnion
Policy ReviewCISOHR HeadLegalBoard
DLP MonitoringCISOSecurity TeamITHR

Documentation and Evidence Requirements

Required Documents

DocumentOwnerRetention PeriodFormat
Exit Security PolicyCISO7 yearsPDF + Word
Exit Security ProcedureHR7 yearsPDF + Word
Exit Security ChecklistHRPer exitDigital form / paper
Access Revocation ChecklistITPer exitSystem records
Asset Return RecordIT7 yearsSystem records
Data Deletion AffidavitHR7 yearsSigned form
Exit Interview RecordHR7 yearsRecorded / documented
Security Clearance CertificateHR7 yearsCertificate
Full and Final Settlement RecordFinance7 yearsFinancial records
Relieving LetterHR7 yearsLetter
Experience CertificateHR7 yearsCertificate
Settlement AgreementLegal7 yearsAgreement
NDA / Employment ContractLegal7 yearsContract
IP Assignment AgreementLegal7 yearsAgreement
Non-Solicitation AgreementLegal7 yearsAgreement
Post-Employment Monitoring RecordsCISO3 yearsReports, alerts
DLP Scan ReportsCISO3 yearsReports
Access Revocation LogsIT3 yearsSystem logs
Role Change Access RecordsIT3 yearsSystem records
Knowledge Transfer DocumentationLine Manager3 yearsDocuments, recordings
Forensic Image (if applicable)CISO7 yearsForensic image
DPDP Ex-Employee Data RecordsLegalPer DPDP retentionRecords
Garden Leave RecordsHR3 yearsRecords
Rapid Exit RecordsCISO7 yearsRecords
Audit EvidenceInternal Audit5 yearsAudit reports
Metrics and ReportsCISO3 yearsDashboard, reports
Lessons LearnedCISO3 yearsDocumentation
Union/CBA Exit TermsLegalDuration of CBA + 7 yearsAgreement
Breach Notice RecordsLegal7 yearsNotices, responses
Legal Action RecordsLegal7 yearsCase files
Exit Survey ResultsHR3 yearsSurvey data
Employee AcknowledgmentHR7 yearsSigned forms
Contract RepositoryLegal7 yearsRepository
Access InventoryIT3 yearsInventory
Asset InventoryIT7 yearsInventory
Shadow IT InventoryCISO3 yearsInventory
Training Records (Exit Security)HR5 yearsLMS records
Metrics DashboardCISO3 yearsDashboard
Case Management RecordsHR7 yearsSystem records
Email ArchiveIT7 yearsArchive
DLP Alert RecordsCISO3 yearsAlert logs
Incident Response RecordsCISO7 yearsIncident records
Compliance EvidenceCompliance5 yearsEvidence package
Management Review MinutesCISO5 yearsMinutes
Policy Review RecordsCISO5 yearsReview records
Evidence RepositoryCompliance7 yearsRepository
Audit ReportsInternal Audit5 yearsReports
Penetration Test ReportsCISO3 yearsReports
Vulnerability Scan ReportsCISO3 yearsReports
Risk Assessment RecordsCISO3 yearsAssessments
Gap Analysis RecordsCISO3 yearsGap analysis
Improvement RecordsCISO3 yearsImprovements
Communication RecordsHR3 yearsCommunication
Employee FAQHR3 yearsFAQ document
Quick Reference CardHR3 yearsCard
Tool ComparisonCISO3 yearsComparison
Vendor GuideProcurement3 yearsGuide
Assessment GuideCISO3 yearsGuide
Documentation TemplateHR3 yearsTemplate
KPI TrackerCISO3 yearsTracker
Incident Response GuideCISO3 yearsGuide
Training PlanHR3 yearsPlan
Communication TemplateHR3 yearsTemplate
Vendor Management GuideProcurement3 yearsGuide
Risk Assessment TemplateCISO3 yearsTemplate
Compliance ChecklistCompliance3 yearsChecklist
Procedure TemplateHR3 yearsTemplate
Policy TemplateCISO3 yearsTemplate
Audit ChecklistInternal Audit3 yearsChecklist
RACI MatrixCISO3 yearsMatrix
Maturity ModelCISO3 yearsModel
value AnalysisFinance3 yearsAnalysis
Quick Reference CardHR3 yearsCard

Continuous Improvement

Figure · Tiers

Maturity levels for responsibilities after termination or change of employment

Maturity levels for ISO 27001 A.6.5, responsibilities after termination or change of employment, from most to least mature: Optimizing, predictive exit analytics; Quantitatively Managed, consistent enforcement; Defined, formal exit procedure; Managed, basic exit checklist; Initial, ad-hoc exits; no formal procedure.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Maturity Model (Level 1-5)

LevelNameDescription
1InitialAd-hoc exits; no formal procedure; access revoked manually; no asset tracking; no post-employment obligations
2ManagedBasic exit checklist; some access revocation; informal asset return; basic NDA; no monitoring
3DefinedFormal exit procedure; automated access revocation; asset tracking; complete NDA; exit interview; security clearance; post-employment monitoring; DPDP compliance; role change procedure
4Quantitatively ManagedConsistent enforcement; automated lifecycle; metrics-driven; DLP monitoring; legal enforcement; 30-60-90 day monitoring; RBAC; garden leave; exit checks completed within the notice period
5OptimizingPredictive exit analytics; AI-driven insider threat detection; continuous post-employment monitoring; automated legal enforcement; blockchain asset provenance; zero-defect exit; industry leadership

Improvement Cycle

  • Plan: Annual review of exit policy; quarterly metrics; industry benchmarking; regulatory updates; employee feedback; legal trend analysis
  • Do: Deploy new tools; update access matrices; train managers; enhance monitoring; improve automation; update contracts; refine DLP
  • Check: Measure access revocation speed; audit asset return; verify DPDP compliance; benchmark; gather feedback; review legal cases; analyze breaches
  • Act: Standardize; communicate; update procedures; report to management; share best practices; union collaboration; legal framework refinement
  • AI Exit Risk Scoring: AI predicting which departing employees pose highest data theft risk
  • Automated Forensics: Automated forensic imaging and analysis of departing employee devices
  • Blockchain Asset Provenance: Blockchain tracking of asset ownership and return
  • Predictive Analytics: Predicting employee departure before resignation (behavioral indicators)
  • Digital Exit Assistant: AI-powered chatbot guiding employees through exit process
  • Continuous Access Verification: Real-time verification that all access is revoked across all systems
  • Post-Employment Digital Footprint Monitoring: AI monitoring ex-employee digital footprint for IP violations
  • Smart Contracts for Enforcement: Blockchain-based smart contracts for post-employment obligations
  • Integrated Lifecycle Management: Single platform managing employee from onboarding to exit
  • Zero-Trust Exit: Zero-trust architecture ensuring no lingering trust relationships post-exit

FAQ

Frequently Asked Questions (20 Questions)

Q1: Is a formal exit security procedure required for ISO 27001 certification? A: Not automatically. No Annex A control is mandatory. Under clause 6.1.3 you choose the controls your risk assessment calls for, then record A.6.5 in your Statement of Applicability as included (and how) or excluded (and why). Almost every organisation with leavers or role changes includes it. If you include it, auditors will look at how post-exit obligations are defined and communicated, and will usually sample leavers to check access removal and asset return (which also touch A.5.11 and A.5.18).

Q2: What is the timeline for access revocation after termination? A: For involuntary termination or suspension, access should be revoked within 1-4 hours. For voluntary resignation, access should be revoked on the last working day. Critical systems (admin, customer data, financial) should be revoked immediately upon notice of resignation for customer-facing roles.

Q3: Can we withhold full and final settlement if an employee doesn't return assets? A: Not the wages. Wages due on exit must be paid within two working days (Code on Wages 2019, s.17(2)). You may deduct for an unreturned asset only if it was expressly entrusted to the employee and the loss is due to their neglect or default, within the s.18 limits. Gratuity can be forfeited only on the narrow s.53(6) grounds of the Code on Social Security 2020, and PF cannot be withheld. Otherwise, recover the asset or its value through a demand notice or civil claim. Consult Legal first.

Q4: Are non-compete clauses enforceable in India? A: Generally, post-employment non-compete clauses are void under Section 27 of the Indian Contract Act (restraint of trade). However, non-compete may be enforceable during employment and for sale of goodwill. Focus on enforceable tools: NDA, non-solicitation, IP assignment, and garden leave.

Q5: What is garden leave and when should it be used? A: Garden leave is a period where the employee is paid but does not work. All access is revoked. It's commonly used in BFSI (RBI requirement) and for senior technical/customer-facing roles. It reduces data exfiltration risk during the notice period.

Q6: Do we need to monitor ex-employees after they leave? A: Yes, but within legal and privacy limits. You can monitor for violations of contractual obligations (NDA, non-solicitation, IP). You cannot conduct surveillance of personal life. DPDP compliance is required. Monitoring should be documented and justified.

Q7: What should we do if an ex-employee takes confidential data to a competitor? A: (1) Gather evidence of breach, (2) Send breach notice (cease and desist), (3) Attempt settlement, (4) Seek court injunction if urgent, (5) File civil suit for breach of contract and trade secret misappropriation, (6) If criminal, file police complaint, (7) Notify regulator if required (RBI, SEBI, etc.).

Q8: How do we handle remote worker exits? A: Remote worker exits require: (1) prepaid shipping labels for device return, (2) video call exit interview, (3) remote access revocation (same timeline), (4) remote data deletion guidance, (5) BYOD device verification (if MDM), (6) home office equipment return, (7) courier tracking for asset return.

Q9: What is the difference between exit for voluntary resignation and involuntary termination? A: Voluntary resignation: notice period, gradual access restriction, knowledge transfer, exit interview, standard timeline. Involuntary termination: immediate access revocation, no exit interview (if for cause), forensic image, rapid asset collection, potential legal action.

Q10: Do we need an exit interview for every departing employee? A: Yes. The exit interview should include security-focused questions (obligations reminder, asset verification, data deletion). Even for involuntary termination, a security reminder can be communicated (though not a traditional "interview"). Document the security communication.

Q11: How do we handle role changes (promotion, transfer)? A: Role changes require: (1) access revocation for old role, (2) access provisioning for new role, (3) asset return/reassignment, (4) new role security training, (5) knowledge transfer, (6) verification that old access is removed. Use RBAC to automate.

Q12: What is a data deletion affidavit and is it required? A: A data deletion affidavit is a signed statement by the departing employee confirming that all company data has been deleted from personal devices and accounts. It is not legally required but is strong evidence in case of future breach. Highly recommended for all exits.

Q13: How do we handle BYOD devices at exit? A: If the device is enrolled in MDM, the company data container can be remotely wiped. If not enrolled, the employee must sign a data deletion affidavit. For high-risk exits, you may request a device scan (with consent). Include BYOD obligations in the employment contract.

Q14: What is the DPDP requirement for ex-employee data? A: Ex-employee personal data must be retained only for legal and compliance purposes (tax, labor law, legal claims). You must delete data when the legal retention period expires. You must justify retention. Ex-employees have DPDP rights (access, correction, grievance) unless exempted.

Q15: Can we change shared passwords when an employee leaves? A: Yes, and you should. If the departing employee knew shared account passwords (e.g., admin accounts, service accounts), those passwords must be changed immediately. Include this in the access revocation checklist.

Q16: What happens if an employee dies? A: Exit procedure for death: (1) Immediate access revocation (no family authorisation is needed), (2) Asset collection from family (with sensitivity), (3) Data recovery and transfer, (4) Personal data separation and return to family, (5) Settlement processing per labor law, (6) Legal compliance for estate. Under the DPDP Act, a person's nominee (s.14) can exercise their data rights after death.

Q17: How do we handle contractor exits? A: Contractor exits should follow the same procedure as employees: (1) Access revocation, (2) Asset return, (3) Data deletion, (4) Contractual obligation reminder, (5) Notify contractor's employer (if applicable), (6) Settlement per contract terms. No gratuity or PF for contractors.

Q18: What is the role of CISO in exit security? A: CISO is accountable for: access revocation, security assessment, device forensics, data deletion verification, post-employment monitoring, incident investigation, DLP monitoring, and security clearance. CISO does not manage HR or settlement but ensures security aspects are complete.

Q19: Can we recover costs for unreturned assets? A: Yes, but within legal limits. You can deduct the cost of unreturned assets from the final salary (with legal compliance). You cannot deduct from gratuity or PF. The deduction must be documented and justified. Consult Legal.

Q20: What will an ISO 27001 auditor look for in A.6.5? A: The auditor will verify: (1) formal exit procedure exists, (2) procedure covers all exit types, (3) access is revoked within defined timelines, (4) assets are returned and verified, (5) data deletion is verified, (6) exit interview includes security focus, (7) post-employment obligations are in contracts, (8) obligations are communicated at exit, (9) full and final settlement is linked to security clearance, (10) role change procedure exists, (11) there is evidence of use (records, checklists, certificates), and (12) DPDP compliance is maintained.


References and Further Reading

ISO Standards

  • ISO 27001:2022: Information Security Management Systems
  • ISO 27002:2022: Information Security Controls
  • ISO/IEC 27701:2025: Privacy information management systems

Indian Law

  • Indian Contract Act 1872: Section 27 (restraint of trade)
  • Industrial Relations Code 2020 (from 21 Nov 2025 replaced the Industrial Disputes Act 1947 and the Industrial Employment (Standing Orders) Act 1946)
  • Code on Social Security 2020 (replaced the Payment of Gratuity Act 1972)
  • Code on Social Security 2020 (replaced the EPF Act 1952)
  • Code on Wages 2019: Sections 17(2) and 18 (wages due within two working days of exit; permitted deductions)
  • Code on Wages 2019 (replaced the Minimum Wages Act 1948)
  • Companies Act 2013
  • DPDP Act 2023
  • IT Act 2000
  • Copyright Act 1957
  • Patents Act 1970
  • Trade Secrets (common law)
  • Official Secrets Act 1923
  • POSH Act 2013

International

  • GDPR (EU): Articles 5, 17, 32
  • HIPAA (US): §164.308(a)(3)(ii)(C), Termination procedures
  • SOX (US): Internal controls
  • UK Employment Rights Act 1996
  • EU Whistleblower Directive
  • ILO Convention: Worker rights
  • FCRA (US): Adverse action
  • CCPA (California): Employee data privacy

Industry

  • RBI Cyber Security Framework: Exit procedures for banking
  • SEBI CSCRF (2024): Access revocation
  • IRDAI Guidelines: Exit procedures for insurance
  • NASSCOM: IT industry employment practices
  • ISACA: Security and governance guidance
  • Data Security Council of India: Data protection best practices
  • Verizon DBIR: Data breach investigations
  • Symantec: Insider threat reports
  • Kaspersky: Employee data theft statistics

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.