Vendor Offboarding Checklist

Purpose

Use this checklist when a vendor relationship, project, contract, or support arrangement ends or when a vendor no longer requires access.

The objective is to make sure external access, integrations, credentials, devices, and company data do not remain behind after the business relationship ends.

Vendor Information

Vendor: ____________________

Service provided: ____________________

Internal owner: ____________________

Contract/project end date: ____________________

Offboarding owner: ____________________

Accounts and Access

  • Vendor user accounts identified.
  • Vendor administrator accounts identified.
  • VPN access removed.
  • Remote support access removed.
  • SaaS access removed.
  • Cloud access removed.
  • Server access removed.
  • Database access removed.
  • Backup access removed.
  • Security tool access removed.
  • Customer or vendor portal access reviewed.
  • Physical access removed where applicable.

Credentials and Integrations

  • Shared passwords known to the vendor rotated where necessary.
  • API keys revoked.
  • Access tokens revoked.
  • OAuth integrations removed.
  • Certificates reviewed.
  • Service account access reviewed.
  • SSH keys removed where applicable.
  • Emergency credentials reviewed.
  • Password manager access removed.

Company Data

Confirm:

  • Required company data returned or transferred.
  • Vendor-hosted company information identified.
  • Data deletion requirements confirmed.
  • Backup copies considered.
  • Retention requirements considered.
  • Sensitive files removed where appropriate.
  • Evidence of deletion or return obtained where required.

Systems and Assets

  • Company-owned devices returned.
  • Security keys returned.
  • Storage devices returned.
  • Documentation transferred.
  • Administrative ownership transferred.
  • Configuration information transferred.
  • Source code or technical assets transferred where applicable.

Business Continuity

If the vendor supported a critical service:

  • Replacement provider confirmed.
  • Internal ownership transferred.
  • Required credentials transferred securely.
  • Backups transferred or confirmed.
  • Recovery procedures updated.
  • Emergency contacts updated.
  • Dependency Register updated.

Subcontractors

  • Known subcontractor access reviewed.
  • Subcontractor access removed where required.
  • Subcontractor-held company data addressed.

Verification

  • Vendor cannot log into company systems.
  • Remote access has been tested as unavailable where practical.
  • Privileged access removed.
  • Integrations revoked.
  • Data disposition confirmed.
  • Vendor register updated.
  • Applications and Services Inventory updated.
  • Access Register updated.

Completed by: ____________________

Internal vendor owner confirmation: ____________________

IT/security confirmation: ____________________

Completion date: ____________________

Evidence location: ____________________

Practical Rule

Ending the contract does not automatically end the access.

Verify that accounts, integrations, credentials, data, and dependencies have actually been removed or transferred.