## Purpose

Use this checklist when a vendor relationship, project, contract, or support arrangement ends or when a vendor no longer requires access.

The objective is to make sure external access, integrations, credentials, devices, and company data do not remain behind after the business relationship ends.

## Vendor Information

Vendor: ____________________

Service provided: ____________________

Internal owner: ____________________

Contract/project end date: ____________________

Offboarding owner: ____________________

## Accounts and Access

- [ ]  Vendor user accounts identified.
- [ ]  Vendor administrator accounts identified.
- [ ]  VPN access removed.
- [ ]  Remote support access removed.
- [ ]  SaaS access removed.
- [ ]  Cloud access removed.
- [ ]  Server access removed.
- [ ]  Database access removed.
- [ ]  Backup access removed.
- [ ]  Security tool access removed.
- [ ]  Customer or vendor portal access reviewed.
- [ ]  Physical access removed where applicable.

## Credentials and Integrations

- [ ]  Shared passwords known to the vendor rotated where necessary.
- [ ]  API keys revoked.
- [ ]  Access tokens revoked.
- [ ]  OAuth integrations removed.
- [ ]  Certificates reviewed.
- [ ]  Service account access reviewed.
- [ ]  SSH keys removed where applicable.
- [ ]  Emergency credentials reviewed.
- [ ]  Password manager access removed.

## Company Data

**Confirm:**

- [ ]  Required company data returned or transferred.
- [ ]  Vendor-hosted company information identified.
- [ ]  Data deletion requirements confirmed.
- [ ]  Backup copies considered.
- [ ]  Retention requirements considered.
- [ ]  Sensitive files removed where appropriate.
- [ ]  Evidence of deletion or return obtained where required.

## Systems and Assets

- [ ]  Company-owned devices returned.
- [ ]  Security keys returned.
- [ ]  Storage devices returned.
- [ ]  Documentation transferred.
- [ ]  Administrative ownership transferred.
- [ ]  Configuration information transferred.
- [ ]  Source code or technical assets transferred where applicable.

## Business Continuity

**If the vendor supported a critical service:**

- [ ]  Replacement provider confirmed.
- [ ]  Internal ownership transferred.
- [ ]  Required credentials transferred securely.
- [ ]  Backups transferred or confirmed.
- [ ]  Recovery procedures updated.
- [ ]  Emergency contacts updated.
- [ ]  Dependency Register updated.

## Subcontractors

- [ ]  Known subcontractor access reviewed.
- [ ]  Subcontractor access removed where required.
- [ ]  Subcontractor-held company data addressed.

## Verification

- [ ]  Vendor cannot log into company systems.
- [ ]  Remote access has been tested as unavailable where practical.
- [ ]  Privileged access removed.
- [ ]  Integrations revoked.
- [ ]  Data disposition confirmed.
- [ ]  Vendor register updated.
- [ ]  Applications and Services Inventory updated.
- [ ]  Access Register updated.

Completed by: ____________________

Internal vendor owner confirmation: ____________________

IT/security confirmation: ____________________

Completion date: ____________________

Evidence location: ____________________

## Practical Rule

Ending the contract does not automatically end the access.

Verify that accounts, integrations, credentials, data, and dependencies have actually been removed or transferred.
