Employee Offboarding Checklist
Purpose
Use this checklist whenever an employee, contractor, or other internal user leaves the company.
The objective is to remove access promptly, recover company assets, protect company information, and prevent forgotten accounts or credentials from remaining active.
The timing of access removal should reflect the circumstances of departure. For higher-risk or involuntary departures, access may need to be removed immediately and coordinated with HR, leadership, IT, and legal counsel.
Departure Information
Name: ____________________
Department: ____________________
Role: ____________________
Manager: ____________________
Last working date: ____________________
Departure type: ____________________
Offboarding owner: ____________________
Before Departure
- Manager informs HR and IT of departure.
- Required access removal time agreed.
- Sensitive or privileged access identified.
- Company-owned devices identified.
- Important files and business records identified.
- Ownership of company files, mailboxes, documents, or systems assigned to another person.
- Any unusual security concerns escalated appropriately.
Account Removal
Confirm removal or disabling of:
- Email account.
- Microsoft 365 or Google Workspace.
- VPN and remote access.
- Cloud systems.
- SaaS applications.
- CRM.
- Finance systems.
- Payroll or HR systems.
- File storage.
- Shared mailboxes.
- Source code repositories.
- Admin accounts.
- Security tools.
- Backup systems.
- Vendor portals.
- Remote support tools.
- Physical access systems.
Privileged and Shared Access
- Separate administrator accounts disabled.
- Shared credentials known to the departing user reviewed.
- Shared passwords rotated where necessary.
- API keys, tokens, certificates, or secrets controlled by the user reviewed.
- Emergency credentials reviewed if the employee had access.
- Password manager access removed.
- Vendor or customer system access removed where applicable.
Devices and Company Property
- Laptop returned.
- Mobile phone returned.
- Security keys returned.
- Access cards or keys returned.
- Storage devices returned.
- Other company equipment recovered.
- Remote wipe or device management action completed where required.
Data and Ownership
- Company data transferred to the appropriate owner.
- Mailbox retention or forwarding decision approved.
- Cloud file ownership transferred.
- Critical documentation transferred.
- Personal access to company data removed.
- Any approved data retention requirements recorded.
Third-Party Relationships
- Vendors informed of contact change where necessary.
- Supplier or customer administrator access updated.
- Domain, hosting, cloud, advertising, social media, or other third-party ownership transferred where applicable.
Verification
- Account disablement verified.
- Privileged access verified as removed.
- Remote access tested as unavailable.
- Important shared credentials rotated where required.
- Asset return confirmed.
- Access register updated.
- Asset inventory updated.
- Privileged Access Register updated.
Completed by: ____________________
HR confirmation: ____________________
Manager confirmation: ____________________
Completion date: ____________________
Evidence location: ____________________
Practical Rule
Offboarding is not complete when the person leaves.
It is complete when their access, credentials, devices, and information ownership have been controlled.