A free employee offboarding checklist template, with owners and proof

Eighteen steps, each with an owner and the proof it leaves. Free to copy, no email required.

This employee offboarding checklist template is free. Copy it, add your people’s names, and use it for every departure. Its job is simple: prove that access ended when employment did. An auditor checks that by putting two dates next to each other, the termination date and the time access was removed.1

What one missed step costs

Running this list costs about an hour per departure. Skipping a line costs more. A former engineer with a live cloud key is a real security risk, and in an examination it becomes a deviation printed in the report your buyer reads. No written explanation removes it. The only repair is a shorter gap on the next departure, with proof.

So the checklist below is ordered by risk. The doors that matter most close first.

The checklist

Eighteen steps in four stages. Give every line to one person by name, never to a team. The proof column is what you file. Keep it with the checklist, because the signed list on its own only shows that someone ticked boxes.

First hour: the doors that matter most

#Do thisOwnerKeep as proof
1Fix the effective termination date and time in writingHuman resourcesPersonnel record carrying the effective date
2Disable the identity provider account and revoke every live session and refresh tokenIT ownerDirectory log line with the timestamp, plus the session revocation record
3Rotate any shared secret the person could still use from memorySecurity leadRotation record naming the secret, dated
4Remove production console and cloud access, including local accounts that never federatedEngineering leadExported change event from the cloud provider
5Remove source control, pipeline and deploy rights, and revoke tokens and deploy keysEngineering leadAudit log showing each removal with its timestamp
6Reassign what the person owned: on call, alert routing, named controlsTheir managerUpdated rotation and ownership records, dated

Same day: everything outside single sign on

#Do thisOwnerKeep as proof
7Delete cloud access keys and command line credentialsEngineering leadKey deletion event from the provider audit trail
8Remove secure shell keys, bastion entries and virtual private network certificatesEngineering leadThe removed key fingerprint, with the commit or log line
9Drop database and warehouse logins that were created by handData ownerConsole record or the executed statement, dated
10Deprovision software bought on a card and never wired to single sign onFinance and ITVendor register with a removal date beside each tool
11Remove vault entries, shared mailboxes and guest access in external channelsIT ownerMembership export taken after removal
12Remove customer facing access: support desk, admin panels, partner portalsSupport leadRemoval record naming the tool and the date

Within the week: devices and the building

#Do thisOwnerKeep as proof
13Recover the laptop, phone and hardware security keyIT ownerAsset register row with the serial number and return date
14Deactivate the building badge and collect any physical keyOffice managerBadge system record showing the deactivation date
15Wipe or reimage before reissue, or log the remote wipe if it never comes backIT ownerWipe confirmation carrying the serial number and date

Close out

#Do thisOwnerKeep as proof
16Complete the checklist, name the person, date it, and have one person sign itHuman resourcesThe completed checklist itself, signed and dated
17Reconcile your offboarding records against the human resources leaver listHuman resourcesThe two lists side by side, with counts and differences explained
18File every artifact so it can be pulled a year later by dateCompliance ownerStored evidence set, indexed by name and date

The two dates that decide the test

HR supplies the termination date, and HR’s leaver list is the population an examiner samples from.2 The system log supplies the removal time. If the record says someone left on May 9 and the directory shows the account disabled on May 15, that is six days of access after employment ended. The SOC 2 evidence request list asks for exactly this pair.

No framework picks your window. Your policy does, and you are held to it. Also treat sessions as their own step: disabling an account does not end a session already open, and an older refresh token can keep working. That is why step 2 asks for the revoke record, not just a screenshot of a disabled user.

When someone is let go

A resignation gives you notice and time to hand over. A dismissal gives you a meeting, and access must be gone before it ends. Flip the order: cut access first, then talk, timed to the minute with the manager. Suspend accounts instead of deleting them, because deleting also erases the mailbox, files and audit trail. Write down who approved the timing. It is the same control under pressure, and on a small team the person leaving may be the one who usually runs offboarding, so rehearse it.

Checking you got everyone

A perfect checklist for nine leavers does not cover a tenth who has none. Once a quarter, pull the HR leaver list, match it against your filed checklists, and keep that comparison. Doing it quarterly is far easier than rebuilding a year of names at audit time. Include contractors who had production access. They count the same as employees. See what happens when an audit finds exceptions for how a late removal reads, and five common control failures for the failures that sit beside it.

Run it free, or let the software track it

This list works in a shared doc at no cost. If departures are frequent, or the person who runs them keeps changing, the cybersoftware software generates the checklist for each exit, tracks every step to done and files the proof, at $199 a month, cancel any time. Take the free readiness assessment first to see your other gaps, or read pricing.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

What belongs on an employee offboarding checklist?
Four stages. In the first hour, the identity account, live sessions, shared secrets and production and code access. The same day, everything outside single sign on, such as cloud keys, SSH keys, database logins and tools bought on a card. Within the week, devices and building access. At close out, the signed checklist and a check against the HR leaver list.
How quickly must access be removed?
No standard gives a number. Your policy sets it, and you are tested against that number. Choose a window you can meet on a busy day with someone out sick, not the fastest one you can imagine.
What proof does an auditor ask for?
The termination date from the HR record and the time access was removed from the system log, side by side. A ticket marked done shows a status, not a time, so it does not replace the log.
Does the order change when someone is fired?
Yes. Access goes first and the conversation second, timed with the manager. Suspend accounts rather than deleting them so the mailbox, files and logs survive, and write down who approved the timing.
Can I run offboarding without software?
Yes. This checklist in a shared document or spreadsheet works. Software helps when departures pile up, by keeping each checklist, log export and sign off together and flagging a step that was missed.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.