The employee offboarding checklist, in the order it gets tested
Eighteen steps, an owner on every line, and the artifact each one has to produce. The whole thing is on this page rather than behind a form.
An employee offboarding checklist template earns its keep in one place: the sample. The control says access ends when employment ends1, and the test behind it is a comparison of two dates. Human resources gives the termination date. The system gives the revocation timestamp. Read in that order, they either agree or they do not.
The checklist is printed below in full, numbered, with a named owner and the artifact each step has to leave behind. No form to fill in. Copy it, put your own people in the owner column, and run it the same way every time.
The checklist, in the order it gets tested
Eighteen steps, grouped the way the evidence groups. The first block is the clock, and it runs on the day itself. The second is everything that does not sit behind your identity provider, so disabling one account does not touch it. Then hardware, then the record. Assign every line to a person by name rather than to a team.
Block one, the clock
| No. | Step | Owner | Evidence it has to produce |
|---|---|---|---|
| 1 | Fix the effective termination date and time in writing | Human resources | Personnel record carrying the effective date |
| 2 | Disable the identity provider account and revoke every live session and refresh token | IT owner | Directory log line with the timestamp, plus the session revocation record |
| 3 | Rotate any shared secret the person could still use from memory | Security lead | Rotation record naming the secret, dated |
| 4 | Remove production console and cloud access, including local accounts that never federated | Engineering lead | Exported change event from the cloud provider |
| 5 | Remove source control, pipeline and deploy rights, and revoke tokens and deploy keys | Engineering lead | Audit log showing each removal with its timestamp |
| 6 | Reassign what the person owned: on call, alert routing, named controls | Their manager | Updated rotation and ownership records, dated |
Block two, the systems outside your identity provider
| No. | Step | Owner | Evidence it has to produce |
|---|---|---|---|
| 7 | Delete cloud access keys and command line credentials | Engineering lead | Key deletion event from the provider audit trail |
| 8 | Remove secure shell keys, bastion entries and virtual private network certificates | Engineering lead | The removed key fingerprint, with the commit or log line |
| 9 | Drop database and warehouse logins that were created by hand | Data owner | Console record or the executed statement, dated |
| 10 | Deprovision software bought on a card and never wired to single sign on | Finance and IT | Vendor register with a removal date beside each tool |
| 11 | Remove vault entries, shared mailboxes and guest access in external channels | IT owner | Membership export taken after removal |
| 12 | Remove customer facing access: support desk, admin panels, partner portals | Support lead | Removal record naming the tool and the date |
Block three, hardware and physical access
| No. | Step | Owner | Evidence it has to produce |
|---|---|---|---|
| 13 | Recover the laptop, phone and hardware security key | IT owner | Asset register row with the serial number and return date |
| 14 | Deactivate the building badge and collect any physical key | Office manager | Badge system record showing the deactivation date |
| 15 | Wipe or reimage before reissue, or log the remote wipe if it never comes back | IT owner | Wipe confirmation carrying the serial number and date |
Block four, the record
| No. | Step | Owner | Evidence it has to produce |
|---|---|---|---|
| 16 | Complete the checklist, name the person, date it, and have one person sign it | Human resources | The completed checklist itself, signed and dated |
| 17 | Reconcile your offboarding records against the human resources leaver list | Human resources | The two lists side by side, with counts and differences explained |
| 18 | File every artifact so it can be pulled a year later by date | Compliance owner | Stored evidence set, indexed by name and date |
Termination date on the personnel record: March 4. Directory log line disabling the account: March 11. Nothing else in the file changes that. Seven days of live access after employment ended is a deviation, and it reaches the report as one. The repair is a shorter gap next time, evidenced.
The two timestamps this control lives on
Neither of them is the ticket status. The first is the effective termination date, which comes from human resources and defines the population an examination samples from.2 The second is the revocation timestamp, from the system that held the access. A ticket marked done is a status. The test wants a date. Request 4 on a SOC 2 evidence request list asks for exactly that pair.
No standard sets your revocation window.1 Your own policy does, and the number you publish is the one you get held to. Write a window you can hit on a Friday with someone out sick, not the one that sounds good in a security questionnaire.
Session revocation is its own step. Disabling an account or changing a password does not end a session that is already open, and a refresh token issued before the change can keep working after it. None of that shows in a screenshot of a disabled account, which is why step 2 above asks for the session revocation record next to the directory log line. Revoke sessions and tokens explicitly, then capture the record that says you did.
When the departure is not voluntary
The sequence inverts. A resignation gives you notice, so the checklist runs beside a handover and the clock is generous. A termination gives you a meeting, and access has to be gone before that meeting ends.
Revocation runs first and notification second, timed with the manager to the minute. Suspend the accounts rather than deleting them, because deletion takes the mailbox, the files and the trail with it. Record who authorized the timing, since that is the decision somebody asks about afterwards.
None of that is a different control. It is the same two timestamps under pressure, which is why the involuntary case is worth rehearsing. Small teams feel it hardest: the person leaving is often the person who normally runs the offboarding.
The record the checklist has to leave behind
A completed checklist evidences a process. It does not evidence that the access is gone. Keep both: the signed form, and the system record sitting behind each line of it. One without the other answers half a request.
The population is where this breaks. An examination takes the leaver list for the period from human resources, then looks for your record against each name on it. A departure with no record is a finding, and nine clean files do not repair the tenth. Reconcile the two lists yourself and keep the reconciliation, quarterly against one export rather than at the end against a year of names you no longer remember.
Contractors count. If they held production access they sit in the same population as employees, and this checklist covers them too. What happens when an examination finds exceptions explains how a late revocation reads on the page a buyer sees, and five common control failures covers the ones standing next to it.
Offboarding is one control. The rest want the same treatment: a named owner, a date, an artifact the system generated. A Security scoped SOC 2 Type 1 through Polara G.R.C. is $4,000 one time, with the first examination and the independent partner auditor fee included. The checklist above is yours regardless.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
What should an employee offboarding checklist include?
How fast does access have to be revoked after an employee leaves?
What evidence does an auditor want for employee offboarding?
How is an involuntary termination handled differently?
What happens if access was revoked after the termination date?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.