The risk does not end when someone leaves.
In many cases, it increases.
Annex A 6.5 exists to ensure organisations define, communicate, and enforce information security responsibilities that continue after employment or contractual relationships end or change.
This control protects the organisation during one of the highest-risk transition points in the people lifecycle.

Annex A 6.5 of ISO 27001:2022 focuses on information security responsibilities that remain in force after termination or change of employment.
At a practical level, this means:
The control does not assume bad intent. It assumes risk exists unless responsibilities and access are managed deliberately.
When people leave or change roles, they often retain:
If responsibilities are unclear or unenforced:
Annex A 6.5 ensures organisations retain control beyond the employment relationship, not just during it.
This control applies to:
A pragmatic approach to Annex A 6.5 typically includes the following elements.
Organisations should identify which responsibilities continue after:
These responsibilities commonly relate to:
Clarity prevents dispute later.
Responsibilities that extend beyond employment should be:
Relying on policy alone weakens enforceability.
Responsibilities should not remain implicit.
Organisations typically:
Clear communication reduces “I didn’t realise” risk.
Responsibilities alone are not sufficient.
Organisations should ensure:
Responsibility without access control is ineffective.
When individuals move roles internally:
Role change is a common source of excessive or inappropriate access.
Where contractors or third parties depart, organisations should consider:
Third-party exits are often less controlled than employee exits — and therefore higher risk.
Annex A 6.5 does not require:
It does require organisations to:
Most failures occur not through malice, but through assumption and omission.
Transitions expose gaps quickly.
Annex A 6.5 is about protecting information beyond the employment relationship.
When responsibilities after termination or change are managed effectively:
People move on.
Information should not move with them unintentionally.
That is exactly what Annex A 6.5 is designed to prevent.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today