Vendor Offboarding Checklist
Purpose
Use this checklist when a vendor relationship, project, contract, or support arrangement ends or when a vendor no longer requires access.
The objective is to make sure external access, integrations, credentials, devices, and company data do not remain behind after the business relationship ends.
Vendor Information
Vendor: ____________________
Service provided: ____________________
Internal owner: ____________________
Contract/project end date: ____________________
Offboarding owner: ____________________
Accounts and Access
- Vendor user accounts identified.
- Vendor administrator accounts identified.
- VPN access removed.
- Remote support access removed.
- SaaS access removed.
- Cloud access removed.
- Server access removed.
- Database access removed.
- Backup access removed.
- Security tool access removed.
- Customer or vendor portal access reviewed.
- Physical access removed where applicable.
Credentials and Integrations
- Shared passwords known to the vendor rotated where necessary.
- API keys revoked.
- Access tokens revoked.
- OAuth integrations removed.
- Certificates reviewed.
- Service account access reviewed.
- SSH keys removed where applicable.
- Emergency credentials reviewed.
- Password manager access removed.
Company Data
Confirm:
- Required company data returned or transferred.
- Vendor-hosted company information identified.
- Data deletion requirements confirmed.
- Backup copies considered.
- Retention requirements considered.
- Sensitive files removed where appropriate.
- Evidence of deletion or return obtained where required.
Systems and Assets
- Company-owned devices returned.
- Security keys returned.
- Storage devices returned.
- Documentation transferred.
- Administrative ownership transferred.
- Configuration information transferred.
- Source code or technical assets transferred where applicable.
Business Continuity
If the vendor supported a critical service:
- Replacement provider confirmed.
- Internal ownership transferred.
- Required credentials transferred securely.
- Backups transferred or confirmed.
- Recovery procedures updated.
- Emergency contacts updated.
- Dependency Register updated.
Subcontractors
- Known subcontractor access reviewed.
- Subcontractor access removed where required.
- Subcontractor-held company data addressed.
Verification
- Vendor cannot log into company systems.
- Remote access has been tested as unavailable where practical.
- Privileged access removed.
- Integrations revoked.
- Data disposition confirmed.
- Vendor register updated.
- Applications and Services Inventory updated.
- Access Register updated.
Completed by: ____________________
Internal vendor owner confirmation: ____________________
IT/security confirmation: ____________________
Completion date: ____________________
Evidence location: ____________________
Practical Rule
Ending the contract does not automatically end the access.
Verify that accounts, integrations, credentials, data, and dependencies have actually been removed or transferred.