A free employee offboarding checklist template, with owners and proof
Eighteen steps, each with an owner and the proof it leaves. Free to copy, no email required.
This employee offboarding checklist template is free. Copy it, add your people’s names, and use it for every departure. Its job is simple: prove that access ended when employment did. An auditor checks that by putting two dates next to each other, the termination date and the time access was removed.1
What one missed step costs
Running this list costs about an hour per departure. Skipping a line costs more. A former engineer with a live cloud key is a real security risk, and in an examination it becomes a deviation printed in the report your buyer reads. No written explanation removes it. The only repair is a shorter gap on the next departure, with proof.
So the checklist below is ordered by risk. The doors that matter most close first.
The checklist
Eighteen steps in four stages. Give every line to one person by name, never to a team. The proof column is what you file. Keep it with the checklist, because the signed list on its own only shows that someone ticked boxes.
First hour: the doors that matter most
| # | Do this | Owner | Keep as proof |
|---|---|---|---|
| 1 | Fix the effective termination date and time in writing | Human resources | Personnel record carrying the effective date |
| 2 | Disable the identity provider account and revoke every live session and refresh token | IT owner | Directory log line with the timestamp, plus the session revocation record |
| 3 | Rotate any shared secret the person could still use from memory | Security lead | Rotation record naming the secret, dated |
| 4 | Remove production console and cloud access, including local accounts that never federated | Engineering lead | Exported change event from the cloud provider |
| 5 | Remove source control, pipeline and deploy rights, and revoke tokens and deploy keys | Engineering lead | Audit log showing each removal with its timestamp |
| 6 | Reassign what the person owned: on call, alert routing, named controls | Their manager | Updated rotation and ownership records, dated |
Same day: everything outside single sign on
| # | Do this | Owner | Keep as proof |
|---|---|---|---|
| 7 | Delete cloud access keys and command line credentials | Engineering lead | Key deletion event from the provider audit trail |
| 8 | Remove secure shell keys, bastion entries and virtual private network certificates | Engineering lead | The removed key fingerprint, with the commit or log line |
| 9 | Drop database and warehouse logins that were created by hand | Data owner | Console record or the executed statement, dated |
| 10 | Deprovision software bought on a card and never wired to single sign on | Finance and IT | Vendor register with a removal date beside each tool |
| 11 | Remove vault entries, shared mailboxes and guest access in external channels | IT owner | Membership export taken after removal |
| 12 | Remove customer facing access: support desk, admin panels, partner portals | Support lead | Removal record naming the tool and the date |
Within the week: devices and the building
| # | Do this | Owner | Keep as proof |
|---|---|---|---|
| 13 | Recover the laptop, phone and hardware security key | IT owner | Asset register row with the serial number and return date |
| 14 | Deactivate the building badge and collect any physical key | Office manager | Badge system record showing the deactivation date |
| 15 | Wipe or reimage before reissue, or log the remote wipe if it never comes back | IT owner | Wipe confirmation carrying the serial number and date |
Close out
| # | Do this | Owner | Keep as proof |
|---|---|---|---|
| 16 | Complete the checklist, name the person, date it, and have one person sign it | Human resources | The completed checklist itself, signed and dated |
| 17 | Reconcile your offboarding records against the human resources leaver list | Human resources | The two lists side by side, with counts and differences explained |
| 18 | File every artifact so it can be pulled a year later by date | Compliance owner | Stored evidence set, indexed by name and date |
The two dates that decide the test
HR supplies the termination date, and HR’s leaver list is the population an examiner samples from.2 The system log supplies the removal time. If the record says someone left on May 9 and the directory shows the account disabled on May 15, that is six days of access after employment ended. The SOC 2 evidence request list asks for exactly this pair.
No framework picks your window. Your policy does, and you are held to it. Also treat sessions as their own step: disabling an account does not end a session already open, and an older refresh token can keep working. That is why step 2 asks for the revoke record, not just a screenshot of a disabled user.
When someone is let go
A resignation gives you notice and time to hand over. A dismissal gives you a meeting, and access must be gone before it ends. Flip the order: cut access first, then talk, timed to the minute with the manager. Suspend accounts instead of deleting them, because deleting also erases the mailbox, files and audit trail. Write down who approved the timing. It is the same control under pressure, and on a small team the person leaving may be the one who usually runs offboarding, so rehearse it.
Checking you got everyone
A perfect checklist for nine leavers does not cover a tenth who has none. Once a quarter, pull the HR leaver list, match it against your filed checklists, and keep that comparison. Doing it quarterly is far easier than rebuilding a year of names at audit time. Include contractors who had production access. They count the same as employees. See what happens when an audit finds exceptions for how a late removal reads, and five common control failures for the failures that sit beside it.
Run it free, or let the software track it
This list works in a shared doc at no cost. If departures are frequent, or the person who runs them keeps changing, the cybersoftware software generates the checklist for each exit, tracks every step to done and files the proof, at $199 a month, cancel any time. Take the free readiness assessment first to see your other gaps, or read pricing.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
What belongs on an employee offboarding checklist?
How quickly must access be removed?
What proof does an auditor ask for?
Does the order change when someone is fired?
Can I run offboarding without software?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.