1. Purpose
The Employee Offboarding Checklist ensures that when an employee leaves the organization or changes role, all necessary information security, access control, asset, data protection, and confidentiality activities are completed.
The objective is to prevent:
- Unauthorized access after employment ends
- Loss or retention of company assets
- Continued access to customer or confidential information
- Retention of credentials, keys, or authentication devices
- Unauthorized copying or transfer of information
- Uncontrolled access to cloud, SaaS, source code, or production systems
Key principle:
Employee Exit → Identify → Collect → Revoke → Verify → Secure → Update → Evidence → Close
2. When to Use This Checklist
Use the checklist for:
- Employee resignation
- Termination
- Contract completion
- Retirement
- Role transfer
- Long-term leave where access must be suspended
- Internal transfer requiring access changes
- Contractor/consultant exit, where applicable
- Emergency access termination
For involuntary or high-risk termination, access may need to be revoked before or immediately at the time of notification, based on management/security requirements.
3. Employee Offboarding Information
| Field | Details |
|---|---|
| Employee Name | |
| Employee ID | |
| Department | |
| Job Title | |
| Manager | |
| Employment Type | Employee / Contractor / Consultant |
| Last Working Date | |
| Effective Exit Time | |
| Reason / Exit Type | Resignation / Termination / Contract End / Transfer |
| HR Owner | |
| Manager | |
| IT Owner | |
| Security Owner | |
| Offboarding Date | |
| Checklist ID | |
| Risk Level | Low / Medium / High |
| Status | Open / In Progress / Completed |
4. Offboarding Process
The organization should follow a controlled sequence:
HR Notification
↓
Identify Employee Access & Assets
↓
Review Security Risk
↓
Disable/Revoke Access
↓
Collect Assets
↓
Secure Company Information
↓
Transfer Business Ownership
↓
Review Cloud/SaaS/Production Access
↓
Update Registers
↓
Verify Completion
↓
Close Offboarding Record
5. HR and Management Notification
| Check | Completed | Evidence / Remarks |
|---|---|---|
| HR has formally initiated offboarding | ☐ | |
| Manager has confirmed last working date | ☐ | |
| IT has received offboarding request | ☐ | |
| Security team has been notified where required | ☐ | |
| Required access termination time has been defined | ☐ | |
| Employee’s role and business responsibilities identified | ☐ | |
| Critical responsibilities identified for transfer | ☐ | |
| High-risk termination requirements assessed | ☐ |
6. Identity and User Account Revocation
All organizational accounts should be identified and reviewed.
| Account / System | Access Removed | Date/Time | Verified By |
|---|---|---|---|
| Corporate Email | ☐ | ||
| Identity Provider / SSO | ☐ | ||
| VPN / Remote Access | ☐ | ||
| HR System | ☐ | ||
| Finance Systems | ☐ | ||
| CRM | ☐ | ||
| Ticketing System | ☐ | ||
| Collaboration Tools | ☐ | ||
| Source Code Repository | ☐ | ||
| Project Management Tools | ☐ | ||
| Security Tools | ☐ | ||
| Cloud Platforms | ☐ | ||
| Customer Systems | ☐ | ||
| Other SaaS Applications | ☐ |
Verify
- ☐ User account disabled
- ☐ SSO access removed
- ☐ MFA methods removed
- ☐ Recovery email/phone reviewed
- ☐ Personal access tokens revoked
- ☐ API tokens revoked
- ☐ SSH keys removed
- ☐ Active sessions terminated where applicable
- ☐ VPN access revoked
- ☐ Remote access removed
- ☐ Password reset performed for shared/service accounts where necessary
7. Privileged and Production Access
For employees with administrative or production access:
- ☐ Production access revoked
- ☐ AWS/Azure/GCP access revoked
- ☐ Privileged roles removed
- ☐ Administrator groups reviewed
- ☐ Break-glass/emergency access reviewed
- ☐ SSH keys/certificates revoked
- ☐ API credentials associated with the employee revoked
- ☐ CI/CD credentials reviewed
- ☐ Secrets accessible to the employee reviewed
- ☐ Database access removed
- ☐ Security-tool administrator access removed
- ☐ Firewall/network administration access removed
- ☐ Cloud console sessions terminated where applicable
- ☐ Privileged access logs reviewed where required
Important: Disabling the employee’s email account alone does not prove that all privileged or cloud access has been removed.
8. AWS / Cloud Offboarding
For employees with AWS or other cloud access:
| Check | Completed |
|---|---|
| Cloud console access removed | ☐ |
| IAM user/role access reviewed | ☐ |
| SSO/cloud identity access removed | ☐ |
| Privileged IAM roles removed | ☐ |
| Access keys disabled/revoked | ☐ |
| SSH keys reviewed/revoked | ☐ |
| Temporary credentials/session access terminated where applicable | ☐ |
| Production account access removed | ☐ |
| Development/test access reviewed | ☐ |
| CI/CD permissions reviewed | ☐ |
| Secrets/credentials accessible to employee reviewed | ☐ |
| Cloud security logs reviewed if required | ☐ |
AWS SaaS Example
An engineer leaving the company had access to:
AWS SSO → Production Account → IAM Role → RDS / S3 / EC2
Offboarding should verify the complete access chain rather than simply disabling the employee’s corporate email.
9. SaaS Application Access
Review the employee’s access to all business SaaS applications.
Examples:
- Microsoft 365 / Google Workspace
- GitHub/GitLab
- Jira
- Slack/Teams
- Salesforce
- Zendesk
- HR platforms
- Finance applications
- Security platforms
- Password managers
- Documentation platforms
- Customer portals
For each application:
- ☐ User account disabled/deleted
- ☐ Admin privileges removed
- ☐ Group memberships removed
- ☐ API integrations reviewed
- ☐ Personal tokens revoked
- ☐ Ownership transferred where necessary
- ☐ Shared files reviewed
- ☐ Customer/business information transferred to authorized owner
10. Asset Return
Use the Asset Return Checklist together with this checklist.
Verify:
- ☐ Laptop returned
- ☐ Desktop returned
- ☐ Mobile phone returned
- ☐ Tablet returned
- ☐ Monitor/docking station returned
- ☐ Security key returned
- ☐ USB/removable media returned
- ☐ Access card returned
- ☐ Physical keys returned
- ☐ SIM/company phone returned
- ☐ Other company equipment returned
- ☐ Asset condition verified
- ☐ Asset register updated
- ☐ Missing/lost assets escalated
Important: Physical asset return and digital access revocation are separate activities.
11. Company Information and Data
Verify whether the employee has organizational information stored or accessible on:
- ☐ Company laptop
- ☐ Company mobile
- ☐ Personal device
- ☐ Personal cloud storage
- ☐ USB/removable media
- ☐ Collaboration platforms
- ☐ Local folders
- ☐ Source-code repositories
- ☐ Customer systems
- ☐ Cloud storage
- ☐ Paper documents
Check:
- ☐ Business information transferred to authorized personnel
- ☐ Customer information retained only where authorized
- ☐ Confidential information identified
- ☐ Restricted information identified
- ☐ Unauthorized copies removed where applicable
- ☐ Personal storage locations reviewed where permitted
- ☐ Data transfer obligations completed
- ☐ Confidentiality obligations communicated
12. Source Code and Development Assets
For developers and technical personnel:
- ☐ Repository access revoked
- ☐ Organization repositories reviewed
- ☐ Personal access tokens revoked
- ☐ SSH keys removed
- ☐ Deployment permissions removed
- ☐ CI/CD access reviewed
- ☐ Cloud development access revoked
- ☐ Production access revoked
- ☐ Code ownership transferred
- ☐ Open pull requests reassigned
- ☐ Outstanding security tasks reassigned
- ☐ Infrastructure-as-Code access reviewed
- ☐ Secrets accessible to employee reviewed
13. Business Responsibilities and Ownership Transfer
Before closure:
| Area | Action | New Owner | Completed |
|---|---|---|---|
| Projects | Transfer responsibility | ☐ | |
| Customer Accounts | Transfer ownership | ☐ | |
| Supplier Relationships | Transfer ownership | ☐ | |
| Documents | Transfer ownership | ☐ | |
| SaaS Applications | Transfer ownership | ☐ | |
| Cloud Resources | Transfer ownership | ☐ | |
| Security Tasks | Transfer ownership | ☐ | |
| Open Incidents | Transfer ownership | ☐ | |
| Open Risks | Transfer ownership | ☐ | |
| Audit Activities | Transfer ownership | ☐ |
14. Confidentiality and Continuing Obligations
Before departure, where applicable:
- ☐ Employee reminded of confidentiality obligations
- ☐ NDA/confidentiality agreement reviewed
- ☐ Intellectual property obligations communicated
- ☐ Customer confidentiality obligations communicated
- ☐ Information retention requirements communicated
- ☐ Restrictions on unauthorized disclosure communicated
- ☐ Post-employment obligations documented where applicable
15. Email and Communication Handling
- ☐ Email account disabled
- ☐ Mail forwarding reviewed and approved where required
- ☐ Automatic response configured where appropriate
- ☐ Business-critical emails transferred/retained appropriately
- ☐ Shared mailbox ownership updated
- ☐ Distribution lists updated
- ☐ Collaboration groups updated
- ☐ Customer communication responsibilities transferred
- ☐ Unauthorized forwarding disabled/reviewed
Email retention and transfer should follow the organization’s legal, privacy, contractual, and retention requirements.
16. Physical Access
- ☐ Office access card disabled
- ☐ Building access removed
- ☐ Data center access removed where applicable
- ☐ Physical keys returned
- ☐ Visitor/access permissions removed
- ☐ Security system access removed
- ☐ Assigned locker/storage access addressed
17. BYOD / Personal Device
If the employee used a personal device:
- ☐ Corporate accounts removed
- ☐ Organization-managed applications removed where applicable
- ☐ Corporate data removed where authorized
- ☐ VPN access removed
- ☐ MDM/MAM enrollment removed where applicable
- ☐ Corporate certificates removed
- ☐ Organization credentials removed
- ☐ Corporate cloud sessions terminated
- ☐ Data transfer requirements verified
The organization should avoid accessing unrelated personal information on the employee’s personal device.
18. Security Review
For sensitive or privileged roles, Security/IT should determine whether additional review is necessary:
- ☐ Access logs reviewed
- ☐ Privileged activity reviewed
- ☐ Recent production activity reviewed
- ☐ Unusual downloads/transfers reviewed
- ☐ Security incidents associated with the account reviewed
- ☐ Suspicious activity escalated
- ☐ Open security findings transferred
- ☐ Relevant evidence preserved
This should be risk-based, not automatically treated as an investigation of every departing employee.
19. Lost or Missing Assets
If an asset is not returned:
- ☐ Asset identified as missing
- ☐ Manager/HR notified
- ☐ Security notified
- ☐ Device/account access disabled
- ☐ Remote lock/wipe performed where available
- ☐ Credentials/tokens reviewed
- ☐ Security incident assessed
- ☐ Asset register updated
- ☐ Incident record created where required
- ☐ Investigation/corrective action completed where necessary
20. Offboarding Verification
The IT/Security reviewer should verify that:
- ☐ All known accounts have been addressed
- ☐ Privileged access has been removed
- ☐ Cloud access has been removed
- ☐ SaaS access has been removed
- ☐ Physical access has been removed
- ☐ Assets have been returned or accounted for
- ☐ Business information has been transferred
- ☐ Credentials/tokens/keys have been addressed
- ☐ Ownership has been transferred
- ☐ Required records have been updated
- ☐ Exceptions have been documented
- ☐ Required evidence has been retained
21. Offboarding Completion Record
| Activity | Owner | Completed Date | Evidence | Verified By |
|---|---|---|---|---|
| HR Exit | HR | |||
| Account Revocation | IT | |||
| Privileged Access | Security/IT | |||
| Cloud Access | IT/Cloud | |||
| SaaS Access | IT | |||
| Asset Return | IT | |||
| Data Transfer | Manager | |||
| Source Code Transfer | Engineering | |||
| Physical Access | Facilities | |||
| Confidentiality Reminder | HR/Manager | |||
| Security Review | Security | |||
| Register Updates | IT/Asset Owner | |||
| Final Verification | Security/IT |
22. Exceptions
If an activity cannot be completed:
| Exception ID | Activity | Reason | Risk | Compensating Control | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
Exceptions should be formally reviewed and tracked until closure.
23. Roles and Responsibilities
HR
- Initiate offboarding
- Confirm exit date/time
- Coordinate with manager and IT
- Maintain employment records
- Communicate applicable continuing obligations
Manager
- Identify business responsibilities
- Confirm information/assets
- Transfer ownership
- Identify critical systems and customer responsibilities
IT
- Disable accounts
- Revoke access
- Collect devices
- Update asset records
- Remove technical access
Security / ISMS
- Review privileged/high-risk access
- Coordinate security verification
- Assess suspicious activity where required
- Maintain security evidence
Asset Owner
- Confirm assigned assets
- Verify ownership transfer
- Update asset records
Employee
- Return assets
- Transfer business information
- Return company information
- Follow confidentiality and security requirements
24. Audit Evidence
An auditor may expect evidence such as:
- Completed offboarding checklist
- HR exit record
- Access revocation records
- Identity provider logs
- IAM records
- AWS/cloud access removal
- SaaS access removal
- Asset return records
- Device wipe/reimage records
- Access-card revocation
- Source-code ownership transfer
- Token/key revocation
- Email/account closure records
- Exception records
- Security review records
- Incident records, where applicable
The objective is not simply to show that a checklist exists, but to demonstrate that the required actions were actually completed.
25. Common Offboarding Mistakes
Mistake 1: Disabling email only
An employee may still have access to cloud, GitHub, VPN, SaaS, or production systems.
Mistake 2: Forgetting API keys and tokens
Personal access tokens, SSH keys, API keys, and cloud credentials may remain active.
Mistake 3: Not transferring ownership
Projects, documents, SaaS accounts, repositories, or customer relationships may remain associated with the departing employee.
Mistake 4: Treating asset return as complete offboarding
Returning a laptop does not revoke digital access.
Mistake 5: No evidence
Access may have been removed, but the organization cannot demonstrate when or by whom.
Mistake 6: Ignoring contractors
Contractors and consultants can have the same security exposure as employees.
Mistake 7: No high-risk termination process
Privileged or sensitive roles may require immediate access termination and additional security review.
26. Startup-Friendly Offboarding Process
A small SaaS company does not need a complicated workflow.
A practical model is:
HR Exit Notification
→ Manager Identifies Access & Assets
→ IT Revokes Accounts
→ Security Reviews Privileged Access
→ Assets Returned
→ Business Ownership Transferred
→ Registers Updated
→ Manager + IT Verification
→ Checklist Closed
For a 25-person startup, the same person may perform multiple activities, but the organization should still clearly define who performs and who verifies the critical steps.
27. Minimum Offboarding Checklist
For a small organization, the minimum control set should normally cover:
- ☐ Confirm exit date/time
- ☐ Disable corporate account
- ☐ Revoke SSO/MFA access
- ☐ Revoke VPN access
- ☐ Revoke cloud access
- ☐ Revoke SaaS access
- ☐ Revoke privileged access
- ☐ Revoke tokens/keys where applicable
- ☐ Collect company assets
- ☐ Transfer business information
- ☐ Transfer ownership
- ☐ Remove physical access
- ☐ Address confidential information
- ☐ Update asset/access records
- ☐ Verify completion
- ☐ Retain evidence
28. Relationship With Other ISMS Documents
The Employee Offboarding Checklist should work together with:
- Access Control Policy
- Asset Return Checklist
- Asset Inventory
- Asset Ownership Register
- Asset Lifecycle Management Procedure
- Acceptable Use Policy
- Employee IT Usage Policy
- Information Classification Policy
- Data Inventory
- Remote Working Policy
- BYOD Policy
- SaaS Application Register
- Cloud Asset Inventory
- Incident Management Procedure
- Security Incident Management Procedure
- HR Joiner/Mover/Leaver Procedure
- Supplier/Third-Party Security Procedure
- Risk Assessment and Risk Register
The overall relationship is:
Employee Exit → Access Review → Access Revocation → Asset Return → Data Protection → Ownership Transfer → Verification → Evidence
29. ISO 27001 Connection
Employee offboarding supports several areas of an ISO 27001 ISMS, particularly controls concerning:
- Employee responsibilities and terms
- Information security awareness
- Access rights
- Return of organizational assets
- Information classification and handling
- Authentication information
- Privileged access
- Secure disposal
- Remote working
- Asset management
The exact controls applicable to an organization should be determined through its risk assessment and Statement of Applicability (SoA) rather than treating the checklist as a standalone compliance requirement.
30. Final Audit Check
An auditor should be able to select a departed employee and trace:
HR Exit Record
↓
Offboarding Request
↓
Access Revocation Evidence
↓
Cloud/SaaS/Privileged Access Removal
↓
Asset Return Evidence
↓
Data/Ownership Transfer
↓
Verification
↓
Completed Offboarding Record
If this trail is available, the organization can demonstrate that employee termination is not merely an HR activity but a controlled information security process.
Final Principle
Identify → Revoke → Collect → Transfer → Secure → Verify → Update → Evidence → Close
