ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Contractor Offboarding Checklist

Contractor Offboarding Checklist

1. Purpose

The Contractor Offboarding Checklist ensures that information security requirements are completed when a contractor, consultant, freelancer, outsourced resource, or other third-party personnel finishes their engagement or no longer requires access.

The objective is to prevent:

  • Unauthorized access after the engagement ends
  • Retention of company or customer information
  • Continued access to cloud, SaaS, source code, or production systems
  • Retention of credentials, tokens, keys, or authentication devices
  • Loss of organizational assets
  • Unauthorized copying or disclosure of information
  • Uncontrolled third-party access

Key principle:

Contractor Exit → Identify → Revoke → Collect → Transfer → Verify → Evidence → Close


2. Scope

This checklist applies to:

  • Contractors
  • Consultants
  • Freelancers
  • Temporary resources
  • Outsourced personnel
  • Managed service personnel
  • Third-party technical resources
  • Vendor personnel
  • Project-based resources
  • External developers
  • External auditors or specialists, where applicable

It should be used when:

  • The contract ends
  • The project is completed
  • The contractor resigns
  • The contractor is replaced
  • Access is no longer required
  • The contractor changes role
  • A supplier relationship ends
  • Management requires immediate access termination

3. Contractor Offboarding Information

FieldDetails
Contractor Name
Contractor ID
Company / Supplier
Engagement TypeContractor / Consultant / Freelancer / Vendor
Project / Service
Business Owner
Supplier Owner
Contractor Manager
Start Date
Contract End Date
Actual Access End Date/Time
Security Owner
IT Owner
Checklist ID
Risk LevelLow / Medium / High
StatusOpen / In Progress / Completed

4. Offboarding Process

Contract/Engagement End Notification
↓
Identify Systems, Information & Assets
↓
Review Contractor Access
↓
Revoke Digital Access
↓
Revoke Privileged/Cloud Access
↓
Collect Organizational Assets
↓
Recover/Transfer Information
↓
Remove Physical Access
↓
Verify Confidentiality & Contractual Obligations
↓
Update Registers
↓
Final Verification
↓
Close Offboarding


5. Contract and Supplier Review

Before closing the engagement:

CheckCompletedEvidence / Remarks
Contract end date confirmed☐
Statement of Work reviewed☐
Contractor’s responsibilities identified☐
Supplier relationship owner notified☐
Access termination date confirmed☐
Confidentiality obligations reviewed☐
Data return/deletion obligations reviewed☐
Intellectual property obligations reviewed☐
Customer contractual requirements reviewed☐
Security requirements reviewed☐
Subcontractor involvement reviewed☐

Where the contractor is supplied through a vendor, the organization should coordinate the offboarding with the supplier relationship owner.


6. Access Inventory

Before access is removed, identify all systems and services the contractor could access.

System / ServiceAccess TypePrivileged?RevokeVerified By
Corporate Email☐
SSO / Identity Provider
VPN
AWS / Cloud
GitHub / GitLab
Jira / Project Tools
Slack / Teams
Customer Systems
CRM
Support Platform
Security Tools
HR/Finance Systems
Other SaaS

7. Identity and Account Revocation

Verify:

  • ☐ Contractor account disabled
  • ☐ SSO access removed
  • ☐ MFA methods removed
  • ☐ VPN access revoked
  • ☐ Application accounts disabled
  • ☐ Group memberships removed
  • ☐ Privileged groups removed
  • ☐ Active sessions terminated where applicable
  • ☐ Personal access tokens revoked
  • ☐ API tokens revoked
  • ☐ SSH keys removed
  • ☐ Digital certificates revoked where applicable
  • ☐ Recovery methods reviewed
  • ☐ Shared credentials accessible to contractor reviewed

Important: Removing the contractor from one system does not prove that all third-party access has been removed.


8. Cloud and AWS Access

For contractors with cloud access:

  • ☐ AWS/Azure/GCP account access revoked
  • ☐ Cloud SSO access removed
  • ☐ IAM roles reviewed
  • ☐ Privileged roles removed
  • ☐ Access keys revoked
  • ☐ Temporary credentials/session access terminated where applicable
  • ☐ SSH keys reviewed
  • ☐ Production access removed
  • ☐ Development/test access removed
  • ☐ Database access removed
  • ☐ S3/object-storage access reviewed
  • ☐ CI/CD access removed
  • ☐ Secrets accessible to contractor reviewed
  • ☐ Cloud administration access removed
  • ☐ Relevant access logs reviewed where required

AWS SaaS Example

A contracted developer had:

SSO → AWS Development Account → IAM Role → GitHub → CI/CD

If the contractor also had production permissions, the organization should separately verify:

Production AWS Account → IAM Role → Production Resources

The offboarding record should demonstrate that each relevant access path was addressed.


9. Source Code and Development Access

For external developers or technical contractors:

  • ☐ GitHub/GitLab/Bitbucket access removed
  • ☐ Repository permissions removed
  • ☐ Organization membership removed
  • ☐ Personal access tokens revoked
  • ☐ SSH keys removed
  • ☐ CI/CD permissions removed
  • ☐ Deployment permissions removed
  • ☐ Production access removed
  • ☐ Infrastructure-as-Code access reviewed
  • ☐ Cloud development access revoked
  • ☐ Secrets accessible to contractor reviewed
  • ☐ Open pull requests reassigned
  • ☐ Code ownership transferred
  • ☐ Outstanding security tasks reassigned

10. SaaS Application Access

Review all SaaS applications used by the contractor.

Examples:

  • Microsoft 365 / Google Workspace
  • GitHub
  • Jira
  • Slack
  • Teams
  • Salesforce
  • Zendesk
  • Confluence
  • Project management tools
  • Security platforms
  • Password managers
  • Customer portals
  • Cloud management platforms

For each relevant application:

  • ☐ User disabled/deleted
  • ☐ Admin privileges removed
  • ☐ Groups removed
  • ☐ API integrations reviewed
  • ☐ Tokens revoked
  • ☐ Ownership transferred
  • ☐ Business information transferred
  • ☐ Customer information reviewed

11. Organizational Asset Return

Verify return of:

  • ☐ Laptop
  • ☐ Desktop
  • ☐ Mobile phone
  • ☐ Tablet
  • ☐ Monitor
  • ☐ Docking station
  • ☐ Security key
  • ☐ USB/removable media
  • ☐ Access card
  • ☐ Physical keys
  • ☐ SIM/company phone
  • ☐ Network equipment
  • ☐ Other company equipment

For each asset:

  • ☐ Asset ID recorded
  • ☐ Condition verified
  • ☐ Return date recorded
  • ☐ Custodian updated
  • ☐ Asset register updated

If the contractor never possessed organizational hardware, this should be recorded as Not Applicable, rather than left unexplained.


12. Information and Data Return

Identify organizational information held by the contractor.

Check:

  • ☐ Customer information
  • ☐ Employee information
  • ☐ Source code
  • ☐ Technical documentation
  • ☐ Architecture diagrams
  • ☐ Security documentation
  • ☐ Credentials/configuration information
  • ☐ Project documentation
  • ☐ Contracts
  • ☐ Business information
  • ☐ Audit evidence
  • ☐ Security reports
  • ☐ Personal data
  • ☐ Backup copies

Verify that:

  • ☐ Required business information has been returned
  • ☐ Information has been transferred to an authorized owner
  • ☐ Unauthorized copies have been removed where applicable
  • ☐ Customer information has been handled according to contract
  • ☐ Confidential/restricted information has been addressed
  • ☐ Data deletion/return obligations have been completed where required

13. Third-Party Data Deletion / Return

Where the contract requires the contractor or supplier to return or delete organizational information:

RequirementCompletedEvidence
Data identified☐
Data returned☐
Data deleted☐
Backup copies addressed☐
Cloud storage addressed☐
Local copies addressed☐
Subcontractor copies addressed☐
Deletion confirmation obtained☐
Contractual requirement verified☐

Where technically or contractually appropriate, obtain a written confirmation or certificate of deletion.


14. Subcontractor / Supplier Personnel

If the contractor worked through a supplier:

  • ☐ Supplier notified of access termination
  • ☐ Supplier confirmed personnel exit
  • ☐ Supplier access removed
  • ☐ Subcontractor access reviewed
  • ☐ Supplier-managed accounts reviewed
  • ☐ Supplier-issued credentials revoked
  • ☐ Supplier-owned devices addressed
  • ☐ Supplier data return/deletion requirements verified
  • ☐ Supplier confirmation retained where required

The organization should not assume that terminating the primary contractor automatically removes all downstream access.


15. Customer System Access

If the contractor accessed customer environments:

  • ☐ Customer system access removed
  • ☐ Customer VPN access removed
  • ☐ Customer credentials revoked
  • ☐ Customer portal access removed
  • ☐ Customer cloud access removed
  • ☐ Customer-specific accounts disabled
  • ☐ Customer-owned assets returned
  • ☐ Customer notification completed where contractually required

16. Physical Access

Verify:

  • ☐ Office access card returned
  • ☐ Building access disabled
  • ☐ Data center access removed
  • ☐ Physical keys returned
  • ☐ Visitor authorization removed
  • ☐ Restricted-area access removed
  • ☐ Supplier/contractor badges disabled

17. Confidentiality and Contractual Obligations

Confirm:

  • ☐ NDA/confidentiality requirements reviewed
  • ☐ Confidentiality obligations continue after engagement where applicable
  • ☐ Intellectual property obligations reviewed
  • ☐ Customer confidentiality requirements reviewed
  • ☐ Data protection obligations reviewed
  • ☐ Information return/deletion obligations reviewed
  • ☐ Restrictions on disclosure communicated
  • ☐ Post-engagement obligations documented where required

18. Privileged Contractor Offboarding

For contractors with administrative, security, development, or production privileges:

  • ☐ Privileged access identified
  • ☐ Production access removed
  • ☐ Cloud administrator roles removed
  • ☐ Security-tool administrator access removed
  • ☐ Database administrator access removed
  • ☐ Network administrator access removed
  • ☐ Source-code administrator access removed
  • ☐ CI/CD administrator access removed
  • ☐ Secrets/credentials reviewed
  • ☐ SSH keys revoked
  • ☐ API credentials revoked
  • ☐ Relevant privileged activity reviewed where required
  • ☐ Security exceptions reviewed

19. BYOD / Personal Device

If the contractor used a personal device:

  • ☐ Corporate accounts removed
  • ☐ Corporate applications removed where applicable
  • ☐ Corporate data removed where authorized
  • ☐ VPN access removed
  • ☐ MDM/MAM enrollment removed where applicable
  • ☐ Certificates removed
  • ☐ Corporate credentials removed
  • ☐ Cloud sessions terminated
  • ☐ Data return/deletion obligations verified

Personal information unrelated to the organization’s systems should not be accessed as part of the offboarding process.


20. Security Review

A risk-based security review should be considered for contractors who had access to:

  • Production systems
  • Customer information
  • Restricted information
  • Security infrastructure
  • Administrative accounts
  • Source code
  • Encryption keys
  • Secrets
  • Financial systems
  • Large volumes of personal data

Where required:

  • ☐ Access logs reviewed
  • ☐ Privileged activity reviewed
  • ☐ Recent data transfers reviewed
  • ☐ Security incidents associated with access reviewed
  • ☐ Suspicious activity escalated
  • ☐ Relevant evidence preserved
  • ☐ Incident created where appropriate

This review should be based on documented risk and contractual/security requirements.


21. Missing or Unreturned Assets

If an asset or information is not returned:

  • ☐ Missing item identified
  • ☐ Contractor/supplier contacted
  • ☐ Manager notified
  • ☐ Security notified
  • ☐ Access disabled
  • ☐ Credentials reviewed
  • ☐ Remote wipe/lock performed where applicable
  • ☐ Security incident assessed
  • ☐ Asset register updated
  • ☐ Incident record created where required
  • ☐ Corrective action assigned

22. Business and Project Handover

Before closure:

AreaActionNew OwnerCompleted
ProjectsHandover completed☐
Source CodeOwnership transferred☐
DocumentationHandover completed☐
Customer WorkResponsibility transferred☐
Supplier WorkResponsibility transferred☐
Security TasksResponsibility transferred☐
Open VulnerabilitiesReassigned☐
Open IncidentsReassigned☐
Open RisksReassigned☐
Cloud ResourcesOwnership transferred☐
SaaS AccountsOwnership transferred☐

23. Final Access Verification

The IT/Security reviewer should confirm:

  • ☐ All known contractor accounts identified
  • ☐ Accounts disabled
  • ☐ Privileged access removed
  • ☐ Cloud access removed
  • ☐ SaaS access removed
  • ☐ Source-code access removed
  • ☐ Customer-system access removed
  • ☐ Physical access removed
  • ☐ Tokens/keys/certificates addressed
  • ☐ Assets returned
  • ☐ Information returned/deleted where required
  • ☐ Ownership transferred
  • ☐ Supplier/subcontractor access addressed
  • ☐ Exceptions documented
  • ☐ Evidence retained

24. Contractor Offboarding Register

ContractorSupplierExit DateAccess RevokedAssets ReturnedData Returned/DeletedVerified ByStatus
☐☐☐

This register provides management with a consolidated view of contractor exits.


25. Exceptions

Any incomplete activity should be formally recorded.

Exception IDRequirementReasonRiskCompensating ControlOwnerDue DateStatus

Exceptions should remain open until the risk is addressed or formally accepted.


26. Roles and Responsibilities

Business Owner

  • Initiates contractor exit
  • Identifies business responsibilities
  • Confirms handover
  • Identifies systems and information accessed

Supplier/Contract Owner

  • Coordinates with the external organization
  • Confirms contractual requirements
  • Obtains required supplier confirmation

IT

  • Disables accounts
  • Revokes technical access
  • Collects organizational assets
  • Updates technical records

Security / ISMS

  • Reviews privileged/high-risk access
  • Coordinates security verification
  • Assesses security incidents where required
  • Maintains security evidence

Asset Owner

  • Confirms asset return
  • Verifies ownership transfer
  • Updates asset records

Contractor / Supplier

  • Returns organizational assets
  • Returns/deletes information as required
  • Transfers business information
  • Complies with continuing contractual obligations

27. Audit Evidence

Useful evidence may include:

  • Contractor offboarding checklist
  • Contract/SOW
  • Supplier correspondence
  • Access revocation records
  • SSO/IAM records
  • AWS/cloud access removal
  • GitHub/GitLab access removal
  • SaaS access removal
  • VPN removal
  • Asset return records
  • Device wipe/reimage records
  • Data return/deletion confirmation
  • Supplier confirmation
  • Customer access removal
  • Physical access records
  • Token/key revocation evidence
  • Ownership transfer records
  • Exception records
  • Security review records
  • Incident records where applicable

An auditor should be able to trace the contractor’s access → revocation → verification rather than relying only on a signed checklist.


28. Common Contractor Offboarding Mistakes

1. Treating contractors like employees but ignoring supplier responsibilities

If a contractor comes through a vendor, the supplier may have additional obligations for access removal and data handling.

2. Forgetting subcontractors

A contractor may have provided access to another person. Downstream access should be identified and addressed.

3. Leaving cloud access active

A contractor may still have AWS/Azure/GCP roles, keys, or tokens even after their corporate account is disabled.

4. Forgetting source-code access

GitHub/GitLab access, SSH keys, personal access tokens, and CI/CD permissions require separate verification.

5. Not addressing copies of company data

Contractor laptops, personal devices, cloud storage, backups, and supplier systems may contain organizational information.

6. No evidence of deletion

Where contractual deletion is required, obtain appropriate evidence or confirmation.

7. Not transferring ownership

Projects, repositories, documentation, SaaS accounts, and customer activities can remain dependent on the departing contractor.


29. Startup-Friendly Contractor Offboarding

For a small SaaS organization, a simple workflow is sufficient if it is consistently followed:

Business Owner → Supplier/HR → IT → Security → Asset Owner → Final Verification

Minimum controls:

  1. Identify contractor and end date
  2. Identify all systems and information accessed
  3. Revoke identity and application access
  4. Revoke cloud and privileged access
  5. Revoke tokens, keys, and certificates
  6. Collect organizational assets
  7. Return/delete organizational information as required
  8. Transfer project/business ownership
  9. Address supplier/subcontractor access
  10. Verify completion
  11. Retain evidence

30. Relationship With Other ISMS Documents

The Contractor Offboarding Checklist should work together with:

  • Supplier Security Policy
  • Supplier Security Assessment
  • Third-Party Access Procedure
  • Access Control Policy
  • Asset Return Checklist
  • Asset Inventory
  • Asset Ownership Register
  • Asset Lifecycle Management Procedure
  • Information Classification Policy
  • Data Inventory
  • Cloud Asset Inventory
  • SaaS Application Register
  • Acceptable Use Policy
  • Remote Working Policy
  • BYOD Policy
  • Incident Management Procedure
  • Security Incident Management Procedure
  • Risk Assessment and Risk Register
  • Contract/Supplier Management Procedure

The overall relationship is:

Contractor Exit → Contract Review → Access Review → Access Revocation → Asset/Data Return → Ownership Transfer → Verification → Evidence → Closure


31. ISO 27001 Connection

Contractor offboarding supports the organization’s information security controls relating to:

  • Supplier and third-party security
  • Access rights
  • Authentication information
  • Privileged access
  • Asset management
  • Return of organizational assets
  • Information classification and handling
  • Secure disposal
  • Remote working
  • Cloud and SaaS access

The organization should determine which controls apply based on its risk assessment, contractual requirements, business context, and Statement of Applicability (SoA).


32. Final Audit Trail

For a sample contractor who has left, the organization should be able to demonstrate:

Contract / SOW
↓
Contractor Exit Notification
↓
Access Inventory
↓
Account & Access Revocation
↓
Cloud/SaaS/Source-Code Access Removal
↓
Asset & Information Return
↓
Ownership Transfer
↓
Supplier/Subcontractor Verification
↓
Final Security Verification
↓
Evidence & Closure

Final Principle

Identify → Review → Revoke → Collect → Return/Delete → Transfer → Verify → Evidence → Close

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *