1. Purpose
The Access Revocation Checklist ensures that user access to organizational information, systems, applications, cloud platforms, networks, and physical facilities is removed or adjusted when access is no longer required.
The objective is to prevent:
- Unauthorized access after employment or engagement ends
- Excessive or obsolete access
- Continued privileged access
- Unauthorized access to customer information
- Continued access through forgotten accounts, tokens, or keys
- Access remaining active after role changes
- Security risks caused by dormant accounts
Key principle:
Identify → Review → Revoke → Verify → Record → Close
2. When to Use This Checklist
Use this checklist for:
- Employee termination
- Employee resignation
- Contractor/consultant exit
- Supplier personnel exit
- Internal role change
- Department transfer
- Project completion
- Temporary access expiry
- Privilege reduction
- Long-term leave where access must be suspended
- Security incidents
- Lost or compromised credentials
- Administrative access changes
- Emergency access termination
For high-risk or involuntary termination, access may need to be revoked immediately or before notification, according to the organization’s approved procedure.
3. Access Revocation Information
| Field | Details |
|---|---|
| Revocation ID | |
| User Name | |
| Employee/Contractor ID | |
| Department / Supplier | |
| Role | |
| Manager / Business Owner | |
| Access Type | Employee / Contractor / Privileged / Temporary |
| Reason for Revocation | Exit / Transfer / Expiry / Security / Other |
| Effective Date | |
| Effective Time | |
| Requested By | |
| Approved By | |
| IT/Security Owner | |
| Risk Level | Low / Medium / High / Critical |
| Status | Open / In Progress / Completed |
4. Access Revocation Process
Access Revocation Request
↓
Identify All User Access
↓
Determine Required Revocation
↓
Disable/Revoke Access
↓
Revoke Credentials, Tokens & Keys
↓
Review Privileged/Cloud Access
↓
Terminate Active Sessions Where Applicable
↓
Verify Revocation
↓
Update Access Records
↓
Retain Evidence
↓
Close Request
5. Identity and Authentication
| Requirement | Completed | Evidence / Remarks |
|---|---|---|
| Corporate user account disabled | ☐ | |
| Identity Provider account disabled | ☐ | |
| SSO access revoked | ☐ | |
| MFA methods removed | ☐ | |
| Recovery email reviewed | ☐ | |
| Recovery phone reviewed | ☐ | |
| Password reset where required | ☐ | |
| Active sessions terminated where applicable | ☐ | |
| Authentication tokens revoked | ☐ | |
| Personal access tokens revoked | ☐ | |
| Digital certificates revoked | ☐ |
6. Email and Collaboration Access
Verify access to:
- ☐ Corporate email
- ☐ Shared mailboxes
- ☐ Distribution groups
- ☐ Microsoft 365 / Google Workspace
- ☐ Teams / Slack
- ☐ SharePoint / Google Drive
- ☐ Confluence
- ☐ Collaboration platforms
- ☐ Customer communication platforms
Check:
- ☐ User account disabled
- ☐ Group memberships removed
- ☐ Shared mailbox permissions removed
- ☐ Delegated access removed
- ☐ Email forwarding reviewed
- ☐ External forwarding disabled where required
- ☐ Shared documents reviewed
- ☐ Ownership transferred where required
7. VPN and Remote Access
- ☐ VPN account disabled
- ☐ VPN certificate revoked
- ☐ Remote access permissions removed
- ☐ Remote desktop access removed
- ☐ Zero Trust/remote access permissions removed
- ☐ Network access policies updated
- ☐ Remote access sessions terminated where applicable
- ☐ Remote administration access removed
8. SaaS Application Access
Review all applications associated with the user.
| Application | Access Removed | Admin Access Removed | Verified By |
|---|---|---|---|
| CRM | ☐ | ☐ | |
| HR System | ☐ | ☐ | |
| Finance System | ☐ | ☐ | |
| Project Management | ☐ | ☐ | |
| Support Platform | ☐ | ☐ | |
| Documentation Platform | ☐ | ☐ | |
| Security Platform | ☐ | ☐ | |
| Password Manager | ☐ | ☐ | |
| Communication Platform | ☐ | ☐ | |
| Other SaaS | ☐ | ☐ |
Also verify:
- ☐ Application-specific accounts disabled
- ☐ Group memberships removed
- ☐ Admin privileges removed
- ☐ API tokens revoked
- ☐ OAuth authorizations reviewed
- ☐ Integrations owned by the user transferred
- ☐ Customer-facing access removed
9. Source Code and Development Access
For developers and technical personnel:
- ☐ GitHub/GitLab/Bitbucket access revoked
- ☐ Repository access removed
- ☐ Organization membership removed
- ☐ Repository administrator access removed
- ☐ Personal access tokens revoked
- ☐ SSH keys removed
- ☐ CI/CD access removed
- ☐ Deployment permissions removed
- ☐ Infrastructure-as-Code access removed
- ☐ Package registry access removed
- ☐ Code-signing access reviewed
- ☐ Development environment access removed
- ☐ Production access removed
10. AWS / Cloud Access
For AWS, Azure, GCP, or other cloud environments:
| Access Area | Revoked | Verified |
|---|---|---|
| Cloud SSO | ☐ | ☐ |
| IAM User | ☐ | ☐ |
| IAM Roles | ☐ | ☐ |
| Administrator Role | ☐ | ☐ |
| Production Account | ☐ | ☐ |
| Development Account | ☐ | ☐ |
| Database Access | ☐ | ☐ |
| S3/Object Storage | ☐ | ☐ |
| EC2/Compute | ☐ | ☐ |
| Kubernetes | ☐ | ☐ |
| CI/CD | ☐ | ☐ |
| Secrets Manager | ☐ | ☐ |
| Key Management | ☐ | ☐ |
| Network Administration | ☐ | ☐ |
| Security Tools | ☐ | ☐ |
Verify
- ☐ IAM access removed
- ☐ Access keys disabled/revoked
- ☐ IAM roles reviewed
- ☐ Privileged roles removed
- ☐ Temporary credentials addressed
- ☐ SSH keys revoked
- ☐ API credentials revoked
- ☐ Cloud console access removed
- ☐ Production access removed
- ☐ Cloud security logs reviewed where required
11. Privileged Access
Privileged access requires additional verification.
Check:
- ☐ Domain administrator access removed
- ☐ Cloud administrator access removed
- ☐ Database administrator access removed
- ☐ Network administrator access removed
- ☐ Security administrator access removed
- ☐ Server administrator access removed
- ☐ Application administrator access removed
- ☐ Source-code administrator access removed
- ☐ CI/CD administrator access removed
- ☐ Backup administrator access removed
- ☐ Password-manager administrator access removed
- ☐ Privileged Access Management access removed
Privileged Credential Review
- ☐ Shared administrator credentials reviewed
- ☐ Credentials changed where required
- ☐ Secrets accessible to user reviewed
- ☐ API keys reviewed
- ☐ SSH keys reviewed
- ☐ Emergency/break-glass access reviewed
- ☐ Relevant privileged activity reviewed where required
12. Database and Data Access
Review access to:
- ☐ Production databases
- ☐ Development databases
- ☐ Test databases
- ☐ Data warehouses
- ☐ Analytics platforms
- ☐ Customer data stores
- ☐ File shares
- ☐ Object storage
- ☐ Backup repositories
Verify:
- ☐ Database account disabled
- ☐ Database roles removed
- ☐ Direct access revoked
- ☐ Read/write permissions removed
- ☐ Export permissions removed
- ☐ Administrative permissions removed
- ☐ Data-sharing permissions removed
13. Security Tools
For security/IT personnel, review:
- ☐ SIEM
- ☐ EDR
- ☐ Vulnerability management platform
- ☐ Firewall
- ☐ WAF
- ☐ Cloud security platform
- ☐ Security monitoring platform
- ☐ Incident management platform
- ☐ Password manager
- ☐ Security ticketing system
- ☐ Backup platform
- ☐ Certificate management
- ☐ Key management
Verify both normal and administrative access.
14. Physical Access
Where applicable:
- ☐ Building access card disabled
- ☐ Office access removed
- ☐ Data center access removed
- ☐ Restricted-area access removed
- ☐ Physical keys returned
- ☐ Security badge disabled
- ☐ Visitor privileges removed
- ☐ Physical security system access removed
15. Mobile and Device Access
Review:
- ☐ Corporate laptop access
- ☐ Corporate mobile
- ☐ Tablet
- ☐ MDM/MAM
- ☐ Endpoint management
- ☐ Device certificates
- ☐ Corporate applications
- ☐ VPN profiles
- ☐ Wi-Fi certificates
- ☐ Device-based authentication
For BYOD:
- ☐ Corporate applications removed where applicable
- ☐ Corporate account access revoked
- ☐ Corporate certificates removed
- ☐ VPN access removed
- ☐ Organization data removed where authorized
- ☐ Device management enrollment removed where applicable
16. API Keys, Tokens and Credentials
A common source of incomplete access revocation is failure to identify non-user credentials.
Review:
- ☐ API keys
- ☐ Personal access tokens
- ☐ OAuth tokens
- ☐ SSH keys
- ☐ Cloud access keys
- ☐ Service credentials
- ☐ Database credentials
- ☐ Certificates
- ☐ Signing keys
- ☐ CI/CD credentials
- ☐ Automation credentials
Where credentials are shared or embedded:
- ☐ Credential ownership identified
- ☐ Credential rotated where required
- ☐ Dependent systems tested
- ☐ New credential securely distributed
- ☐ Old credential disabled
17. Active Sessions
Where technically possible:
- ☐ Web sessions terminated
- ☐ VPN sessions terminated
- ☐ Cloud console sessions terminated
- ☐ SSO sessions terminated
- ☐ Mobile sessions removed
- ☐ SaaS sessions terminated
- ☐ Remote desktop sessions terminated
- ☐ API tokens invalidated
The exact capability depends on the system.
18. Role Change / Internal Transfer
Access revocation is also required when an employee changes roles.
Verify:
- ☐ Previous role identified
- ☐ Previous access reviewed
- ☐ Access no longer required removed
- ☐ New access separately approved
- ☐ Privileged access reassessed
- ☐ Group memberships updated
- ☐ Cloud roles updated
- ☐ SaaS permissions updated
- ☐ Source-code permissions updated
- ☐ Access review completed
Principle:
Do not simply add new access. Remove access that is no longer required.
19. Temporary Access Expiry
For temporary access:
| Field | Details |
|---|---|
| User | |
| System | |
| Access Granted | |
| Expiry Date | |
| Business Owner | |
| Approval | |
| Revocation Date | |
| Verified By |
Verify:
- ☐ Expiry date reached
- ☐ Access automatically expired where supported
- ☐ Access manually revoked if necessary
- ☐ Owner notified
- ☐ Evidence retained
20. Emergency Access Revocation
Emergency revocation may be required for:
- Compromised credentials
- Suspected account compromise
- Lost/stolen device
- Security incident
- Unauthorized access
- Insider-risk event
- Management-directed emergency termination
Immediate actions may include:
- ☐ Disable account
- ☐ Revoke sessions
- ☐ Revoke MFA/token access
- ☐ Revoke cloud access
- ☐ Rotate credentials
- ☐ Revoke API keys
- ☐ Block VPN
- ☐ Restrict network access
- ☐ Preserve relevant logs
- ☐ Escalate to incident management
Emergency actions should subsequently be documented and reviewed.
21. Access Revocation Verification
The person performing the revocation should not simply mark the checklist complete without evidence where evidence is available.
Verify:
- ☐ Account shows disabled
- ☐ Access groups removed
- ☐ Privileged roles removed
- ☐ Cloud roles removed
- ☐ SaaS access removed
- ☐ VPN access removed
- ☐ Tokens/keys revoked
- ☐ Physical access removed
- ☐ Active sessions terminated where applicable
- ☐ Access records updated
- ☐ Required logs/evidence retained
22. Access Revocation Evidence
Examples of evidence include:
- Identity Provider screenshot/report
- IAM records
- SSO logs
- Access-management ticket
- Application user status
- AWS IAM evidence
- VPN access records
- GitHub/GitLab membership records
- SaaS administration records
- Token/key revocation records
- MDM records
- Physical access records
- Security ticket
- Approval record
- Audit log
- Completed checklist
Evidence should demonstrate what was revoked, when, and by whom, where applicable.
23. Exceptions
If access cannot be revoked immediately:
| Exception ID | System | Access Remaining | Reason | Risk | Compensating Control | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|---|
Exceptions should be formally approved and tracked to closure.
24. Final Access Revocation Record
| Item | Status |
|---|---|
| User identity disabled | ☐ |
| SSO revoked | ☐ |
| MFA removed | ☐ |
| Email access removed | ☐ |
| VPN removed | ☐ |
| SaaS access removed | ☐ |
| Source-code access removed | ☐ |
| Cloud access removed | ☐ |
| Privileged access removed | ☐ |
| Database access removed | ☐ |
| API tokens revoked | ☐ |
| SSH keys revoked | ☐ |
| Certificates revoked | ☐ |
| Physical access removed | ☐ |
| Device access addressed | ☐ |
| Active sessions terminated | ☐ |
| Business ownership transferred | ☐ |
| Exceptions documented | ☐ |
| Evidence retained | ☐ |
| Final verification completed | ☐ |
25. Roles and Responsibilities
Manager / Business Owner
- Request access revocation
- Confirm reason and effective date
- Identify systems and information accessed
- Confirm business ownership transfer
IT
- Disable accounts
- Revoke technical access
- Remove device/network access
- Maintain access records
Security / ISMS
- Review privileged and high-risk access
- Coordinate emergency revocation
- Review security implications
- Verify evidence where required
System/Application Owner
- Remove application-specific access
- Remove privileged permissions
- Confirm revocation
Cloud Administrator
- Revoke cloud roles, keys, and permissions
- Review production access
- Maintain cloud evidence
HR / Supplier Owner
- Coordinate employee/contractor exit
- Confirm termination or engagement end
- Notify relevant teams
26. Audit Sampling Approach
During an ISO 27001 audit, the organization may demonstrate effectiveness by selecting samples such as:
- Recent employee exits
- Recent contractor exits
- Recent internal transfers
- Recent privileged-access removals
- Recently expired temporary access
For each sample, demonstrate:
Access Request / Exit Event
→ User/System Identified
→ Access Revoked
→ Verification
→ Evidence
This provides stronger evidence than simply showing an access-control policy.
27. Common Mistakes
1. Only disabling the email account
The user may still have cloud, SaaS, VPN, GitHub, or production access.
2. Forgetting API tokens
Tokens can remain active even after the primary account is disabled.
3. Forgetting SSH keys
Technical users may retain server or cloud access through SSH keys.
4. Not reviewing privileged access
Administrative access requires separate verification.
5. Adding new access without removing old access
Role changes can create excessive privileges over time.
6. No expiry for temporary access
Temporary access should have defined expiry or periodic review.
7. No evidence
The organization may revoke access correctly but fail to demonstrate when and how it happened.
8. Ignoring physical access
Digital access and physical access should be addressed separately.
28. Startup-Friendly Implementation
A startup can implement a simple centralized workflow:
HR / Manager / Security Request
↓
Access Inventory
↓
IT Revocation
↓
System Owner Verification
↓
Security Verification for Privileged Access
↓
Evidence Attached to Ticket
↓
Access Record Updated
↓
Closed
A centralized IT/security ticket can be the primary record, with screenshots, logs, or system reports attached as evidence.
29. Minimum Access Revocation Checklist
For a small organization, the minimum process should cover:
- ☐ Confirm user and effective date/time
- ☐ Disable identity/SSO account
- ☐ Remove MFA/authentication methods
- ☐ Disable email
- ☐ Revoke VPN/remote access
- ☐ Remove SaaS access
- ☐ Remove source-code access
- ☐ Remove cloud access
- ☐ Remove privileged access
- ☐ Revoke tokens/keys
- ☐ Remove physical access
- ☐ Terminate sessions where applicable
- ☐ Verify revocation
- ☐ Retain evidence
- ☐ Close the request
30. Relationship With Other ISMS Documents
The Access Revocation Checklist should work together with:
- Access Control Policy
- Joiner-Mover-Leaver Procedure
- Employee Offboarding Checklist
- Contractor Offboarding Checklist
- IT Asset Handover Form
- Asset Return Checklist
- Asset Inventory
- Asset Ownership Register
- SaaS Application Register
- Cloud Asset Inventory
- Information Classification Policy
- Acceptable Use Policy
- Employee IT Usage Policy
- Remote Working Policy
- BYOD Policy
- Privileged Access Management Procedure
- Security Incident Management Procedure
- Risk Assessment and Risk Register
The overall relationship is:
User Lifecycle → Access Request → Approval → Provisioning → Review → Change/Transfer → Revocation → Verification → Evidence
31. ISO 27001 Connection
Access revocation supports the organization’s access-control processes, particularly activities concerning:
- Access rights
- Identity management
- Authentication information
- Access restriction
- Privileged access
- Information access
- Cloud services
- User endpoint access
- Supplier/third-party access
The specific controls applicable to the organization should be determined through its risk assessment and Statement of Applicability (SoA).
32. Final Audit Trail
An auditor should be able to select a departed employee, contractor, transferred employee, or expired temporary account and trace:
Access Request / Exit Event
↓
User & Access Inventory
↓
Approval
↓
Account Revocation
↓
Cloud/SaaS/VPN/Source-Code Revocation
↓
Token/Key Revocation
↓
Verification
↓
Evidence
↓
Closure
Final Principle
Identify → Approve → Revoke → Verify → Record → Evidence → Close
