1. Purpose
The Contractor Offboarding Checklist ensures that information security requirements are completed when a contractor, consultant, freelancer, outsourced resource, or other third-party personnel finishes their engagement or no longer requires access.
The objective is to prevent:
- Unauthorized access after the engagement ends
- Retention of company or customer information
- Continued access to cloud, SaaS, source code, or production systems
- Retention of credentials, tokens, keys, or authentication devices
- Loss of organizational assets
- Unauthorized copying or disclosure of information
- Uncontrolled third-party access
Key principle:
Contractor Exit → Identify → Revoke → Collect → Transfer → Verify → Evidence → Close
2. Scope
This checklist applies to:
- Contractors
- Consultants
- Freelancers
- Temporary resources
- Outsourced personnel
- Managed service personnel
- Third-party technical resources
- Vendor personnel
- Project-based resources
- External developers
- External auditors or specialists, where applicable
It should be used when:
- The contract ends
- The project is completed
- The contractor resigns
- The contractor is replaced
- Access is no longer required
- The contractor changes role
- A supplier relationship ends
- Management requires immediate access termination
3. Contractor Offboarding Information
| Field | Details |
|---|---|
| Contractor Name | |
| Contractor ID | |
| Company / Supplier | |
| Engagement Type | Contractor / Consultant / Freelancer / Vendor |
| Project / Service | |
| Business Owner | |
| Supplier Owner | |
| Contractor Manager | |
| Start Date | |
| Contract End Date | |
| Actual Access End Date/Time | |
| Security Owner | |
| IT Owner | |
| Checklist ID | |
| Risk Level | Low / Medium / High |
| Status | Open / In Progress / Completed |
4. Offboarding Process
Contract/Engagement End Notification
↓
Identify Systems, Information & Assets
↓
Review Contractor Access
↓
Revoke Digital Access
↓
Revoke Privileged/Cloud Access
↓
Collect Organizational Assets
↓
Recover/Transfer Information
↓
Remove Physical Access
↓
Verify Confidentiality & Contractual Obligations
↓
Update Registers
↓
Final Verification
↓
Close Offboarding
5. Contract and Supplier Review
Before closing the engagement:
| Check | Completed | Evidence / Remarks |
|---|---|---|
| Contract end date confirmed | ☐ | |
| Statement of Work reviewed | ☐ | |
| Contractor’s responsibilities identified | ☐ | |
| Supplier relationship owner notified | ☐ | |
| Access termination date confirmed | ☐ | |
| Confidentiality obligations reviewed | ☐ | |
| Data return/deletion obligations reviewed | ☐ | |
| Intellectual property obligations reviewed | ☐ | |
| Customer contractual requirements reviewed | ☐ | |
| Security requirements reviewed | ☐ | |
| Subcontractor involvement reviewed | ☐ |
Where the contractor is supplied through a vendor, the organization should coordinate the offboarding with the supplier relationship owner.
6. Access Inventory
Before access is removed, identify all systems and services the contractor could access.
| System / Service | Access Type | Privileged? | Revoke | Verified By |
|---|---|---|---|---|
| Corporate Email | ☐ | |||
| SSO / Identity Provider | ||||
| VPN | ||||
| AWS / Cloud | ||||
| GitHub / GitLab | ||||
| Jira / Project Tools | ||||
| Slack / Teams | ||||
| Customer Systems | ||||
| CRM | ||||
| Support Platform | ||||
| Security Tools | ||||
| HR/Finance Systems | ||||
| Other SaaS |
7. Identity and Account Revocation
Verify:
- ☐ Contractor account disabled
- ☐ SSO access removed
- ☐ MFA methods removed
- ☐ VPN access revoked
- ☐ Application accounts disabled
- ☐ Group memberships removed
- ☐ Privileged groups removed
- ☐ Active sessions terminated where applicable
- ☐ Personal access tokens revoked
- ☐ API tokens revoked
- ☐ SSH keys removed
- ☐ Digital certificates revoked where applicable
- ☐ Recovery methods reviewed
- ☐ Shared credentials accessible to contractor reviewed
Important: Removing the contractor from one system does not prove that all third-party access has been removed.
8. Cloud and AWS Access
For contractors with cloud access:
- ☐ AWS/Azure/GCP account access revoked
- ☐ Cloud SSO access removed
- ☐ IAM roles reviewed
- ☐ Privileged roles removed
- ☐ Access keys revoked
- ☐ Temporary credentials/session access terminated where applicable
- ☐ SSH keys reviewed
- ☐ Production access removed
- ☐ Development/test access removed
- ☐ Database access removed
- ☐ S3/object-storage access reviewed
- ☐ CI/CD access removed
- ☐ Secrets accessible to contractor reviewed
- ☐ Cloud administration access removed
- ☐ Relevant access logs reviewed where required
AWS SaaS Example
A contracted developer had:
SSO → AWS Development Account → IAM Role → GitHub → CI/CD
If the contractor also had production permissions, the organization should separately verify:
Production AWS Account → IAM Role → Production Resources
The offboarding record should demonstrate that each relevant access path was addressed.
9. Source Code and Development Access
For external developers or technical contractors:
- ☐ GitHub/GitLab/Bitbucket access removed
- ☐ Repository permissions removed
- ☐ Organization membership removed
- ☐ Personal access tokens revoked
- ☐ SSH keys removed
- ☐ CI/CD permissions removed
- ☐ Deployment permissions removed
- ☐ Production access removed
- ☐ Infrastructure-as-Code access reviewed
- ☐ Cloud development access revoked
- ☐ Secrets accessible to contractor reviewed
- ☐ Open pull requests reassigned
- ☐ Code ownership transferred
- ☐ Outstanding security tasks reassigned
10. SaaS Application Access
Review all SaaS applications used by the contractor.
Examples:
- Microsoft 365 / Google Workspace
- GitHub
- Jira
- Slack
- Teams
- Salesforce
- Zendesk
- Confluence
- Project management tools
- Security platforms
- Password managers
- Customer portals
- Cloud management platforms
For each relevant application:
- ☐ User disabled/deleted
- ☐ Admin privileges removed
- ☐ Groups removed
- ☐ API integrations reviewed
- ☐ Tokens revoked
- ☐ Ownership transferred
- ☐ Business information transferred
- ☐ Customer information reviewed
11. Organizational Asset Return
Verify return of:
- ☐ Laptop
- ☐ Desktop
- ☐ Mobile phone
- ☐ Tablet
- ☐ Monitor
- ☐ Docking station
- ☐ Security key
- ☐ USB/removable media
- ☐ Access card
- ☐ Physical keys
- ☐ SIM/company phone
- ☐ Network equipment
- ☐ Other company equipment
For each asset:
- ☐ Asset ID recorded
- ☐ Condition verified
- ☐ Return date recorded
- ☐ Custodian updated
- ☐ Asset register updated
If the contractor never possessed organizational hardware, this should be recorded as Not Applicable, rather than left unexplained.
12. Information and Data Return
Identify organizational information held by the contractor.
Check:
- ☐ Customer information
- ☐ Employee information
- ☐ Source code
- ☐ Technical documentation
- ☐ Architecture diagrams
- ☐ Security documentation
- ☐ Credentials/configuration information
- ☐ Project documentation
- ☐ Contracts
- ☐ Business information
- ☐ Audit evidence
- ☐ Security reports
- ☐ Personal data
- ☐ Backup copies
Verify that:
- ☐ Required business information has been returned
- ☐ Information has been transferred to an authorized owner
- ☐ Unauthorized copies have been removed where applicable
- ☐ Customer information has been handled according to contract
- ☐ Confidential/restricted information has been addressed
- ☐ Data deletion/return obligations have been completed where required
13. Third-Party Data Deletion / Return
Where the contract requires the contractor or supplier to return or delete organizational information:
| Requirement | Completed | Evidence |
|---|---|---|
| Data identified | ☐ | |
| Data returned | ☐ | |
| Data deleted | ☐ | |
| Backup copies addressed | ☐ | |
| Cloud storage addressed | ☐ | |
| Local copies addressed | ☐ | |
| Subcontractor copies addressed | ☐ | |
| Deletion confirmation obtained | ☐ | |
| Contractual requirement verified | ☐ |
Where technically or contractually appropriate, obtain a written confirmation or certificate of deletion.
14. Subcontractor / Supplier Personnel
If the contractor worked through a supplier:
- ☐ Supplier notified of access termination
- ☐ Supplier confirmed personnel exit
- ☐ Supplier access removed
- ☐ Subcontractor access reviewed
- ☐ Supplier-managed accounts reviewed
- ☐ Supplier-issued credentials revoked
- ☐ Supplier-owned devices addressed
- ☐ Supplier data return/deletion requirements verified
- ☐ Supplier confirmation retained where required
The organization should not assume that terminating the primary contractor automatically removes all downstream access.
15. Customer System Access
If the contractor accessed customer environments:
- ☐ Customer system access removed
- ☐ Customer VPN access removed
- ☐ Customer credentials revoked
- ☐ Customer portal access removed
- ☐ Customer cloud access removed
- ☐ Customer-specific accounts disabled
- ☐ Customer-owned assets returned
- ☐ Customer notification completed where contractually required
16. Physical Access
Verify:
- ☐ Office access card returned
- ☐ Building access disabled
- ☐ Data center access removed
- ☐ Physical keys returned
- ☐ Visitor authorization removed
- ☐ Restricted-area access removed
- ☐ Supplier/contractor badges disabled
17. Confidentiality and Contractual Obligations
Confirm:
- ☐ NDA/confidentiality requirements reviewed
- ☐ Confidentiality obligations continue after engagement where applicable
- ☐ Intellectual property obligations reviewed
- ☐ Customer confidentiality requirements reviewed
- ☐ Data protection obligations reviewed
- ☐ Information return/deletion obligations reviewed
- ☐ Restrictions on disclosure communicated
- ☐ Post-engagement obligations documented where required
18. Privileged Contractor Offboarding
For contractors with administrative, security, development, or production privileges:
- ☐ Privileged access identified
- ☐ Production access removed
- ☐ Cloud administrator roles removed
- ☐ Security-tool administrator access removed
- ☐ Database administrator access removed
- ☐ Network administrator access removed
- ☐ Source-code administrator access removed
- ☐ CI/CD administrator access removed
- ☐ Secrets/credentials reviewed
- ☐ SSH keys revoked
- ☐ API credentials revoked
- ☐ Relevant privileged activity reviewed where required
- ☐ Security exceptions reviewed
19. BYOD / Personal Device
If the contractor used a personal device:
- ☐ Corporate accounts removed
- ☐ Corporate applications removed where applicable
- ☐ Corporate data removed where authorized
- ☐ VPN access removed
- ☐ MDM/MAM enrollment removed where applicable
- ☐ Certificates removed
- ☐ Corporate credentials removed
- ☐ Cloud sessions terminated
- ☐ Data return/deletion obligations verified
Personal information unrelated to the organization’s systems should not be accessed as part of the offboarding process.
20. Security Review
A risk-based security review should be considered for contractors who had access to:
- Production systems
- Customer information
- Restricted information
- Security infrastructure
- Administrative accounts
- Source code
- Encryption keys
- Secrets
- Financial systems
- Large volumes of personal data
Where required:
- ☐ Access logs reviewed
- ☐ Privileged activity reviewed
- ☐ Recent data transfers reviewed
- ☐ Security incidents associated with access reviewed
- ☐ Suspicious activity escalated
- ☐ Relevant evidence preserved
- ☐ Incident created where appropriate
This review should be based on documented risk and contractual/security requirements.
21. Missing or Unreturned Assets
If an asset or information is not returned:
- ☐ Missing item identified
- ☐ Contractor/supplier contacted
- ☐ Manager notified
- ☐ Security notified
- ☐ Access disabled
- ☐ Credentials reviewed
- ☐ Remote wipe/lock performed where applicable
- ☐ Security incident assessed
- ☐ Asset register updated
- ☐ Incident record created where required
- ☐ Corrective action assigned
22. Business and Project Handover
Before closure:
| Area | Action | New Owner | Completed |
|---|---|---|---|
| Projects | Handover completed | ☐ | |
| Source Code | Ownership transferred | ☐ | |
| Documentation | Handover completed | ☐ | |
| Customer Work | Responsibility transferred | ☐ | |
| Supplier Work | Responsibility transferred | ☐ | |
| Security Tasks | Responsibility transferred | ☐ | |
| Open Vulnerabilities | Reassigned | ☐ | |
| Open Incidents | Reassigned | ☐ | |
| Open Risks | Reassigned | ☐ | |
| Cloud Resources | Ownership transferred | ☐ | |
| SaaS Accounts | Ownership transferred | ☐ |
23. Final Access Verification
The IT/Security reviewer should confirm:
- ☐ All known contractor accounts identified
- ☐ Accounts disabled
- ☐ Privileged access removed
- ☐ Cloud access removed
- ☐ SaaS access removed
- ☐ Source-code access removed
- ☐ Customer-system access removed
- ☐ Physical access removed
- ☐ Tokens/keys/certificates addressed
- ☐ Assets returned
- ☐ Information returned/deleted where required
- ☐ Ownership transferred
- ☐ Supplier/subcontractor access addressed
- ☐ Exceptions documented
- ☐ Evidence retained
24. Contractor Offboarding Register
| Contractor | Supplier | Exit Date | Access Revoked | Assets Returned | Data Returned/Deleted | Verified By | Status |
|---|---|---|---|---|---|---|---|
| ☐ | ☐ | ☐ |
This register provides management with a consolidated view of contractor exits.
25. Exceptions
Any incomplete activity should be formally recorded.
| Exception ID | Requirement | Reason | Risk | Compensating Control | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
Exceptions should remain open until the risk is addressed or formally accepted.
26. Roles and Responsibilities
Business Owner
- Initiates contractor exit
- Identifies business responsibilities
- Confirms handover
- Identifies systems and information accessed
Supplier/Contract Owner
- Coordinates with the external organization
- Confirms contractual requirements
- Obtains required supplier confirmation
IT
- Disables accounts
- Revokes technical access
- Collects organizational assets
- Updates technical records
Security / ISMS
- Reviews privileged/high-risk access
- Coordinates security verification
- Assesses security incidents where required
- Maintains security evidence
Asset Owner
- Confirms asset return
- Verifies ownership transfer
- Updates asset records
Contractor / Supplier
- Returns organizational assets
- Returns/deletes information as required
- Transfers business information
- Complies with continuing contractual obligations
27. Audit Evidence
Useful evidence may include:
- Contractor offboarding checklist
- Contract/SOW
- Supplier correspondence
- Access revocation records
- SSO/IAM records
- AWS/cloud access removal
- GitHub/GitLab access removal
- SaaS access removal
- VPN removal
- Asset return records
- Device wipe/reimage records
- Data return/deletion confirmation
- Supplier confirmation
- Customer access removal
- Physical access records
- Token/key revocation evidence
- Ownership transfer records
- Exception records
- Security review records
- Incident records where applicable
An auditor should be able to trace the contractor’s access → revocation → verification rather than relying only on a signed checklist.
28. Common Contractor Offboarding Mistakes
1. Treating contractors like employees but ignoring supplier responsibilities
If a contractor comes through a vendor, the supplier may have additional obligations for access removal and data handling.
2. Forgetting subcontractors
A contractor may have provided access to another person. Downstream access should be identified and addressed.
3. Leaving cloud access active
A contractor may still have AWS/Azure/GCP roles, keys, or tokens even after their corporate account is disabled.
4. Forgetting source-code access
GitHub/GitLab access, SSH keys, personal access tokens, and CI/CD permissions require separate verification.
5. Not addressing copies of company data
Contractor laptops, personal devices, cloud storage, backups, and supplier systems may contain organizational information.
6. No evidence of deletion
Where contractual deletion is required, obtain appropriate evidence or confirmation.
7. Not transferring ownership
Projects, repositories, documentation, SaaS accounts, and customer activities can remain dependent on the departing contractor.
29. Startup-Friendly Contractor Offboarding
For a small SaaS organization, a simple workflow is sufficient if it is consistently followed:
Business Owner → Supplier/HR → IT → Security → Asset Owner → Final Verification
Minimum controls:
- Identify contractor and end date
- Identify all systems and information accessed
- Revoke identity and application access
- Revoke cloud and privileged access
- Revoke tokens, keys, and certificates
- Collect organizational assets
- Return/delete organizational information as required
- Transfer project/business ownership
- Address supplier/subcontractor access
- Verify completion
- Retain evidence
30. Relationship With Other ISMS Documents
The Contractor Offboarding Checklist should work together with:
- Supplier Security Policy
- Supplier Security Assessment
- Third-Party Access Procedure
- Access Control Policy
- Asset Return Checklist
- Asset Inventory
- Asset Ownership Register
- Asset Lifecycle Management Procedure
- Information Classification Policy
- Data Inventory
- Cloud Asset Inventory
- SaaS Application Register
- Acceptable Use Policy
- Remote Working Policy
- BYOD Policy
- Incident Management Procedure
- Security Incident Management Procedure
- Risk Assessment and Risk Register
- Contract/Supplier Management Procedure
The overall relationship is:
Contractor Exit → Contract Review → Access Review → Access Revocation → Asset/Data Return → Ownership Transfer → Verification → Evidence → Closure
31. ISO 27001 Connection
Contractor offboarding supports the organization’s information security controls relating to:
- Supplier and third-party security
- Access rights
- Authentication information
- Privileged access
- Asset management
- Return of organizational assets
- Information classification and handling
- Secure disposal
- Remote working
- Cloud and SaaS access
The organization should determine which controls apply based on its risk assessment, contractual requirements, business context, and Statement of Applicability (SoA).
32. Final Audit Trail
For a sample contractor who has left, the organization should be able to demonstrate:
Contract / SOW
↓
Contractor Exit Notification
↓
Access Inventory
↓
Account & Access Revocation
↓
Cloud/SaaS/Source-Code Access Removal
↓
Asset & Information Return
↓
Ownership Transfer
↓
Supplier/Subcontractor Verification
↓
Final Security Verification
↓
Evidence & Closure
Final Principle
Identify → Review → Revoke → Collect → Return/Delete → Transfer → Verify → Evidence → Close
