ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee Offboarding Checklist

Employee Offboarding Checklist

1. Purpose

The Employee Offboarding Checklist ensures that when an employee leaves the organization or changes role, all necessary information security, access control, asset, data protection, and confidentiality activities are completed.

The objective is to prevent:

  • Unauthorized access after employment ends
  • Loss or retention of company assets
  • Continued access to customer or confidential information
  • Retention of credentials, keys, or authentication devices
  • Unauthorized copying or transfer of information
  • Uncontrolled access to cloud, SaaS, source code, or production systems

Key principle:

Employee Exit → Identify → Collect → Revoke → Verify → Secure → Update → Evidence → Close


2. When to Use This Checklist

Use the checklist for:

  • Employee resignation
  • Termination
  • Contract completion
  • Retirement
  • Role transfer
  • Long-term leave where access must be suspended
  • Internal transfer requiring access changes
  • Contractor/consultant exit, where applicable
  • Emergency access termination

For involuntary or high-risk termination, access may need to be revoked before or immediately at the time of notification, based on management/security requirements.


3. Employee Offboarding Information

FieldDetails
Employee Name
Employee ID
Department
Job Title
Manager
Employment TypeEmployee / Contractor / Consultant
Last Working Date
Effective Exit Time
Reason / Exit TypeResignation / Termination / Contract End / Transfer
HR Owner
Manager
IT Owner
Security Owner
Offboarding Date
Checklist ID
Risk LevelLow / Medium / High
StatusOpen / In Progress / Completed

4. Offboarding Process

The organization should follow a controlled sequence:

HR Notification
↓
Identify Employee Access & Assets
↓
Review Security Risk
↓
Disable/Revoke Access
↓
Collect Assets
↓
Secure Company Information
↓
Transfer Business Ownership
↓
Review Cloud/SaaS/Production Access
↓
Update Registers
↓
Verify Completion
↓
Close Offboarding Record


5. HR and Management Notification

CheckCompletedEvidence / Remarks
HR has formally initiated offboarding☐
Manager has confirmed last working date☐
IT has received offboarding request☐
Security team has been notified where required☐
Required access termination time has been defined☐
Employee’s role and business responsibilities identified☐
Critical responsibilities identified for transfer☐
High-risk termination requirements assessed☐

6. Identity and User Account Revocation

All organizational accounts should be identified and reviewed.

Account / SystemAccess RemovedDate/TimeVerified By
Corporate Email☐
Identity Provider / SSO☐
VPN / Remote Access☐
HR System☐
Finance Systems☐
CRM☐
Ticketing System☐
Collaboration Tools☐
Source Code Repository☐
Project Management Tools☐
Security Tools☐
Cloud Platforms☐
Customer Systems☐
Other SaaS Applications☐

Verify

  • ☐ User account disabled
  • ☐ SSO access removed
  • ☐ MFA methods removed
  • ☐ Recovery email/phone reviewed
  • ☐ Personal access tokens revoked
  • ☐ API tokens revoked
  • ☐ SSH keys removed
  • ☐ Active sessions terminated where applicable
  • ☐ VPN access revoked
  • ☐ Remote access removed
  • ☐ Password reset performed for shared/service accounts where necessary

7. Privileged and Production Access

For employees with administrative or production access:

  • ☐ Production access revoked
  • ☐ AWS/Azure/GCP access revoked
  • ☐ Privileged roles removed
  • ☐ Administrator groups reviewed
  • ☐ Break-glass/emergency access reviewed
  • ☐ SSH keys/certificates revoked
  • ☐ API credentials associated with the employee revoked
  • ☐ CI/CD credentials reviewed
  • ☐ Secrets accessible to the employee reviewed
  • ☐ Database access removed
  • ☐ Security-tool administrator access removed
  • ☐ Firewall/network administration access removed
  • ☐ Cloud console sessions terminated where applicable
  • ☐ Privileged access logs reviewed where required

Important: Disabling the employee’s email account alone does not prove that all privileged or cloud access has been removed.


8. AWS / Cloud Offboarding

For employees with AWS or other cloud access:

CheckCompleted
Cloud console access removed☐
IAM user/role access reviewed☐
SSO/cloud identity access removed☐
Privileged IAM roles removed☐
Access keys disabled/revoked☐
SSH keys reviewed/revoked☐
Temporary credentials/session access terminated where applicable☐
Production account access removed☐
Development/test access reviewed☐
CI/CD permissions reviewed☐
Secrets/credentials accessible to employee reviewed☐
Cloud security logs reviewed if required☐

AWS SaaS Example

An engineer leaving the company had access to:

AWS SSO → Production Account → IAM Role → RDS / S3 / EC2

Offboarding should verify the complete access chain rather than simply disabling the employee’s corporate email.


9. SaaS Application Access

Review the employee’s access to all business SaaS applications.

Examples:

  • Microsoft 365 / Google Workspace
  • GitHub/GitLab
  • Jira
  • Slack/Teams
  • Salesforce
  • Zendesk
  • HR platforms
  • Finance applications
  • Security platforms
  • Password managers
  • Documentation platforms
  • Customer portals

For each application:

  • ☐ User account disabled/deleted
  • ☐ Admin privileges removed
  • ☐ Group memberships removed
  • ☐ API integrations reviewed
  • ☐ Personal tokens revoked
  • ☐ Ownership transferred where necessary
  • ☐ Shared files reviewed
  • ☐ Customer/business information transferred to authorized owner

10. Asset Return

Use the Asset Return Checklist together with this checklist.

Verify:

  • ☐ Laptop returned
  • ☐ Desktop returned
  • ☐ Mobile phone returned
  • ☐ Tablet returned
  • ☐ Monitor/docking station returned
  • ☐ Security key returned
  • ☐ USB/removable media returned
  • ☐ Access card returned
  • ☐ Physical keys returned
  • ☐ SIM/company phone returned
  • ☐ Other company equipment returned
  • ☐ Asset condition verified
  • ☐ Asset register updated
  • ☐ Missing/lost assets escalated

Important: Physical asset return and digital access revocation are separate activities.


11. Company Information and Data

Verify whether the employee has organizational information stored or accessible on:

  • ☐ Company laptop
  • ☐ Company mobile
  • ☐ Personal device
  • ☐ Personal cloud storage
  • ☐ USB/removable media
  • ☐ Email
  • ☐ Collaboration platforms
  • ☐ Local folders
  • ☐ Source-code repositories
  • ☐ Customer systems
  • ☐ Cloud storage
  • ☐ Paper documents

Check:

  • ☐ Business information transferred to authorized personnel
  • ☐ Customer information retained only where authorized
  • ☐ Confidential information identified
  • ☐ Restricted information identified
  • ☐ Unauthorized copies removed where applicable
  • ☐ Personal storage locations reviewed where permitted
  • ☐ Data transfer obligations completed
  • ☐ Confidentiality obligations communicated

12. Source Code and Development Assets

For developers and technical personnel:

  • ☐ Repository access revoked
  • ☐ Organization repositories reviewed
  • ☐ Personal access tokens revoked
  • ☐ SSH keys removed
  • ☐ Deployment permissions removed
  • ☐ CI/CD access reviewed
  • ☐ Cloud development access revoked
  • ☐ Production access revoked
  • ☐ Code ownership transferred
  • ☐ Open pull requests reassigned
  • ☐ Outstanding security tasks reassigned
  • ☐ Infrastructure-as-Code access reviewed
  • ☐ Secrets accessible to employee reviewed

13. Business Responsibilities and Ownership Transfer

Before closure:

AreaActionNew OwnerCompleted
ProjectsTransfer responsibility☐
Customer AccountsTransfer ownership☐
Supplier RelationshipsTransfer ownership☐
DocumentsTransfer ownership☐
SaaS ApplicationsTransfer ownership☐
Cloud ResourcesTransfer ownership☐
Security TasksTransfer ownership☐
Open IncidentsTransfer ownership☐
Open RisksTransfer ownership☐
Audit ActivitiesTransfer ownership☐

14. Confidentiality and Continuing Obligations

Before departure, where applicable:

  • ☐ Employee reminded of confidentiality obligations
  • ☐ NDA/confidentiality agreement reviewed
  • ☐ Intellectual property obligations communicated
  • ☐ Customer confidentiality obligations communicated
  • ☐ Information retention requirements communicated
  • ☐ Restrictions on unauthorized disclosure communicated
  • ☐ Post-employment obligations documented where applicable

15. Email and Communication Handling

  • ☐ Email account disabled
  • ☐ Mail forwarding reviewed and approved where required
  • ☐ Automatic response configured where appropriate
  • ☐ Business-critical emails transferred/retained appropriately
  • ☐ Shared mailbox ownership updated
  • ☐ Distribution lists updated
  • ☐ Collaboration groups updated
  • ☐ Customer communication responsibilities transferred
  • ☐ Unauthorized forwarding disabled/reviewed

Email retention and transfer should follow the organization’s legal, privacy, contractual, and retention requirements.


16. Physical Access

  • ☐ Office access card disabled
  • ☐ Building access removed
  • ☐ Data center access removed where applicable
  • ☐ Physical keys returned
  • ☐ Visitor/access permissions removed
  • ☐ Security system access removed
  • ☐ Assigned locker/storage access addressed

17. BYOD / Personal Device

If the employee used a personal device:

  • ☐ Corporate accounts removed
  • ☐ Organization-managed applications removed where applicable
  • ☐ Corporate data removed where authorized
  • ☐ VPN access removed
  • ☐ MDM/MAM enrollment removed where applicable
  • ☐ Corporate certificates removed
  • ☐ Organization credentials removed
  • ☐ Corporate cloud sessions terminated
  • ☐ Data transfer requirements verified

The organization should avoid accessing unrelated personal information on the employee’s personal device.


18. Security Review

For sensitive or privileged roles, Security/IT should determine whether additional review is necessary:

  • ☐ Access logs reviewed
  • ☐ Privileged activity reviewed
  • ☐ Recent production activity reviewed
  • ☐ Unusual downloads/transfers reviewed
  • ☐ Security incidents associated with the account reviewed
  • ☐ Suspicious activity escalated
  • ☐ Open security findings transferred
  • ☐ Relevant evidence preserved

This should be risk-based, not automatically treated as an investigation of every departing employee.


19. Lost or Missing Assets

If an asset is not returned:

  • ☐ Asset identified as missing
  • ☐ Manager/HR notified
  • ☐ Security notified
  • ☐ Device/account access disabled
  • ☐ Remote lock/wipe performed where available
  • ☐ Credentials/tokens reviewed
  • ☐ Security incident assessed
  • ☐ Asset register updated
  • ☐ Incident record created where required
  • ☐ Investigation/corrective action completed where necessary

20. Offboarding Verification

The IT/Security reviewer should verify that:

  • ☐ All known accounts have been addressed
  • ☐ Privileged access has been removed
  • ☐ Cloud access has been removed
  • ☐ SaaS access has been removed
  • ☐ Physical access has been removed
  • ☐ Assets have been returned or accounted for
  • ☐ Business information has been transferred
  • ☐ Credentials/tokens/keys have been addressed
  • ☐ Ownership has been transferred
  • ☐ Required records have been updated
  • ☐ Exceptions have been documented
  • ☐ Required evidence has been retained

21. Offboarding Completion Record

ActivityOwnerCompleted DateEvidenceVerified By
HR ExitHR
Account RevocationIT
Privileged AccessSecurity/IT
Cloud AccessIT/Cloud
SaaS AccessIT
Asset ReturnIT
Data TransferManager
Source Code TransferEngineering
Physical AccessFacilities
Confidentiality ReminderHR/Manager
Security ReviewSecurity
Register UpdatesIT/Asset Owner
Final VerificationSecurity/IT

22. Exceptions

If an activity cannot be completed:

Exception IDActivityReasonRiskCompensating ControlOwnerDue DateStatus

Exceptions should be formally reviewed and tracked until closure.


23. Roles and Responsibilities

HR

  • Initiate offboarding
  • Confirm exit date/time
  • Coordinate with manager and IT
  • Maintain employment records
  • Communicate applicable continuing obligations

Manager

  • Identify business responsibilities
  • Confirm information/assets
  • Transfer ownership
  • Identify critical systems and customer responsibilities

IT

  • Disable accounts
  • Revoke access
  • Collect devices
  • Update asset records
  • Remove technical access

Security / ISMS

  • Review privileged/high-risk access
  • Coordinate security verification
  • Assess suspicious activity where required
  • Maintain security evidence

Asset Owner

  • Confirm assigned assets
  • Verify ownership transfer
  • Update asset records

Employee

  • Return assets
  • Transfer business information
  • Return company information
  • Follow confidentiality and security requirements

24. Audit Evidence

An auditor may expect evidence such as:

  • Completed offboarding checklist
  • HR exit record
  • Access revocation records
  • Identity provider logs
  • IAM records
  • AWS/cloud access removal
  • SaaS access removal
  • Asset return records
  • Device wipe/reimage records
  • Access-card revocation
  • Source-code ownership transfer
  • Token/key revocation
  • Email/account closure records
  • Exception records
  • Security review records
  • Incident records, where applicable

The objective is not simply to show that a checklist exists, but to demonstrate that the required actions were actually completed.


25. Common Offboarding Mistakes

Mistake 1: Disabling email only

An employee may still have access to cloud, GitHub, VPN, SaaS, or production systems.

Mistake 2: Forgetting API keys and tokens

Personal access tokens, SSH keys, API keys, and cloud credentials may remain active.

Mistake 3: Not transferring ownership

Projects, documents, SaaS accounts, repositories, or customer relationships may remain associated with the departing employee.

Mistake 4: Treating asset return as complete offboarding

Returning a laptop does not revoke digital access.

Mistake 5: No evidence

Access may have been removed, but the organization cannot demonstrate when or by whom.

Mistake 6: Ignoring contractors

Contractors and consultants can have the same security exposure as employees.

Mistake 7: No high-risk termination process

Privileged or sensitive roles may require immediate access termination and additional security review.


26. Startup-Friendly Offboarding Process

A small SaaS company does not need a complicated workflow.

A practical model is:

HR Exit Notification
→ Manager Identifies Access & Assets
→ IT Revokes Accounts
→ Security Reviews Privileged Access
→ Assets Returned
→ Business Ownership Transferred
→ Registers Updated
→ Manager + IT Verification
→ Checklist Closed

For a 25-person startup, the same person may perform multiple activities, but the organization should still clearly define who performs and who verifies the critical steps.


27. Minimum Offboarding Checklist

For a small organization, the minimum control set should normally cover:

  • ☐ Confirm exit date/time
  • ☐ Disable corporate account
  • ☐ Revoke SSO/MFA access
  • ☐ Revoke VPN access
  • ☐ Revoke cloud access
  • ☐ Revoke SaaS access
  • ☐ Revoke privileged access
  • ☐ Revoke tokens/keys where applicable
  • ☐ Collect company assets
  • ☐ Transfer business information
  • ☐ Transfer ownership
  • ☐ Remove physical access
  • ☐ Address confidential information
  • ☐ Update asset/access records
  • ☐ Verify completion
  • ☐ Retain evidence

28. Relationship With Other ISMS Documents

The Employee Offboarding Checklist should work together with:

  • Access Control Policy
  • Asset Return Checklist
  • Asset Inventory
  • Asset Ownership Register
  • Asset Lifecycle Management Procedure
  • Acceptable Use Policy
  • Employee IT Usage Policy
  • Information Classification Policy
  • Data Inventory
  • Remote Working Policy
  • BYOD Policy
  • SaaS Application Register
  • Cloud Asset Inventory
  • Incident Management Procedure
  • Security Incident Management Procedure
  • HR Joiner/Mover/Leaver Procedure
  • Supplier/Third-Party Security Procedure
  • Risk Assessment and Risk Register

The overall relationship is:

Employee Exit → Access Review → Access Revocation → Asset Return → Data Protection → Ownership Transfer → Verification → Evidence


29. ISO 27001 Connection

Employee offboarding supports several areas of an ISO 27001 ISMS, particularly controls concerning:

  • Employee responsibilities and terms
  • Information security awareness
  • Access rights
  • Return of organizational assets
  • Information classification and handling
  • Authentication information
  • Privileged access
  • Secure disposal
  • Remote working
  • Asset management

The exact controls applicable to an organization should be determined through its risk assessment and Statement of Applicability (SoA) rather than treating the checklist as a standalone compliance requirement.


30. Final Audit Check

An auditor should be able to select a departed employee and trace:

HR Exit Record
↓
Offboarding Request
↓
Access Revocation Evidence
↓
Cloud/SaaS/Privileged Access Removal
↓
Asset Return Evidence
↓
Data/Ownership Transfer
↓
Verification
↓
Completed Offboarding Record

If this trail is available, the organization can demonstrate that employee termination is not merely an HR activity but a controlled information security process.

Final Principle

Identify → Revoke → Collect → Transfer → Secure → Verify → Update → Evidence → Close

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *