The employee offboarding checklist, in the order it gets tested

Eighteen steps, an owner on every line, and the artifact each one has to produce. The whole thing is on this page rather than behind a form.

An employee offboarding checklist template earns its keep in one place: the sample. The control says access ends when employment ends1, and the test behind it is a comparison of two dates. Human resources gives the termination date. The system gives the revocation timestamp. Read in that order, they either agree or they do not.

The checklist is printed below in full, numbered, with a named owner and the artifact each step has to leave behind. No form to fill in. Copy it, put your own people in the owner column, and run it the same way every time.

The checklist, in the order it gets tested

Eighteen steps, grouped the way the evidence groups. The first block is the clock, and it runs on the day itself. The second is everything that does not sit behind your identity provider, so disabling one account does not touch it. Then hardware, then the record. Assign every line to a person by name rather than to a team.

Block one, the clock

No.StepOwnerEvidence it has to produce
1Fix the effective termination date and time in writingHuman resourcesPersonnel record carrying the effective date
2Disable the identity provider account and revoke every live session and refresh tokenIT ownerDirectory log line with the timestamp, plus the session revocation record
3Rotate any shared secret the person could still use from memorySecurity leadRotation record naming the secret, dated
4Remove production console and cloud access, including local accounts that never federatedEngineering leadExported change event from the cloud provider
5Remove source control, pipeline and deploy rights, and revoke tokens and deploy keysEngineering leadAudit log showing each removal with its timestamp
6Reassign what the person owned: on call, alert routing, named controlsTheir managerUpdated rotation and ownership records, dated

Block two, the systems outside your identity provider

No.StepOwnerEvidence it has to produce
7Delete cloud access keys and command line credentialsEngineering leadKey deletion event from the provider audit trail
8Remove secure shell keys, bastion entries and virtual private network certificatesEngineering leadThe removed key fingerprint, with the commit or log line
9Drop database and warehouse logins that were created by handData ownerConsole record or the executed statement, dated
10Deprovision software bought on a card and never wired to single sign onFinance and ITVendor register with a removal date beside each tool
11Remove vault entries, shared mailboxes and guest access in external channelsIT ownerMembership export taken after removal
12Remove customer facing access: support desk, admin panels, partner portalsSupport leadRemoval record naming the tool and the date

Block three, hardware and physical access

No.StepOwnerEvidence it has to produce
13Recover the laptop, phone and hardware security keyIT ownerAsset register row with the serial number and return date
14Deactivate the building badge and collect any physical keyOffice managerBadge system record showing the deactivation date
15Wipe or reimage before reissue, or log the remote wipe if it never comes backIT ownerWipe confirmation carrying the serial number and date

Block four, the record

No.StepOwnerEvidence it has to produce
16Complete the checklist, name the person, date it, and have one person sign itHuman resourcesThe completed checklist itself, signed and dated
17Reconcile your offboarding records against the human resources leaver listHuman resourcesThe two lists side by side, with counts and differences explained
18File every artifact so it can be pulled a year later by dateCompliance ownerStored evidence set, indexed by name and date
What a failed sample looks like

Termination date on the personnel record: March 4. Directory log line disabling the account: March 11. Nothing else in the file changes that. Seven days of live access after employment ended is a deviation, and it reaches the report as one. The repair is a shorter gap next time, evidenced.

The two timestamps this control lives on

Neither of them is the ticket status. The first is the effective termination date, which comes from human resources and defines the population an examination samples from.2 The second is the revocation timestamp, from the system that held the access. A ticket marked done is a status. The test wants a date. Request 4 on a SOC 2 evidence request list asks for exactly that pair.

No standard sets your revocation window.1 Your own policy does, and the number you publish is the one you get held to. Write a window you can hit on a Friday with someone out sick, not the one that sounds good in a security questionnaire.

Session revocation is its own step. Disabling an account or changing a password does not end a session that is already open, and a refresh token issued before the change can keep working after it. None of that shows in a screenshot of a disabled account, which is why step 2 above asks for the session revocation record next to the directory log line. Revoke sessions and tokens explicitly, then capture the record that says you did.

When the departure is not voluntary

The sequence inverts. A resignation gives you notice, so the checklist runs beside a handover and the clock is generous. A termination gives you a meeting, and access has to be gone before that meeting ends.

Revocation runs first and notification second, timed with the manager to the minute. Suspend the accounts rather than deleting them, because deletion takes the mailbox, the files and the trail with it. Record who authorized the timing, since that is the decision somebody asks about afterwards.

None of that is a different control. It is the same two timestamps under pressure, which is why the involuntary case is worth rehearsing. Small teams feel it hardest: the person leaving is often the person who normally runs the offboarding.

The record the checklist has to leave behind

A completed checklist evidences a process. It does not evidence that the access is gone. Keep both: the signed form, and the system record sitting behind each line of it. One without the other answers half a request.

The population is where this breaks. An examination takes the leaver list for the period from human resources, then looks for your record against each name on it. A departure with no record is a finding, and nine clean files do not repair the tenth. Reconcile the two lists yourself and keep the reconciliation, quarterly against one export rather than at the end against a year of names you no longer remember.

Contractors count. If they held production access they sit in the same population as employees, and this checklist covers them too. What happens when an examination finds exceptions explains how a late revocation reads on the page a buyer sees, and five common control failures covers the ones standing next to it.

Where this sits in the wider job

Offboarding is one control. The rest want the same treatment: a named owner, a date, an artifact the system generated. A Security scoped SOC 2 Type 1 through Polara G.R.C. is $4,000 one time, with the first examination and the independent partner auditor fee included. The checklist above is yours regardless.

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

What should an employee offboarding checklist include?
Four blocks. The revocation clock, which covers the identity provider account, active sessions and tokens, production and source control access. The systems that do not federate, which covers cloud access keys, secure shell keys, hand made database logins and any tool bought outside single sign on. Hardware and physical access, which covers the laptop, the security key and the building badge. Then the record, which is the completed checklist plus the system evidence behind each line.
How fast does access have to be revoked after an employee leaves?
No standard sets the number. Your own policy does, and that is the number you are measured against. Pick a window you can hit on a bad day with someone out sick, write it down, and hold to it. A policy that promises immediate removal against logs that show the next morning is a gap you created for yourself.
What evidence does an auditor want for employee offboarding?
Two dates that can be read side by side. The effective termination date from the human resources record, and the revocation timestamp from the system that held the access. A ticket marked done is a status rather than a date, so it does not satisfy the request on its own. The system record has to come from the system.
How is an involuntary termination handled differently?
The sequence inverts. Revocation runs first and notification runs second, timed with the manager to the minute. Suspend the accounts rather than deleting them, because deletion takes the mailbox, the files and the trail with it. Record who authorized the timing, since that is the decision someone asks about later.
What happens if access was revoked after the termination date?
It is a deviation and it goes into the report as one. The gap is visible because both dates are visible, and no explanation removes it from the file. The response is to fix the process, shorten the gap, and evidence the shorter gap on the departures that follow.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team.

$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Get started

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

polara labs

Polara Labs builds both sides of the small end of the compliance market: the readiness platform startups use to earn a SOC 2, and the practice software boutique firms use to run the examination. Prices are published on each product page.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.

Built by Surya Shetty