ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Contractor Offboarding Procedure

Contractor Offboarding Procedure

1. Purpose

The Contractor Offboarding Procedure defines the process for securely ending a contractor, consultant, freelancer, temporary worker, or external individual’s access to organizational systems, information, facilities, and services when their engagement ends or their access is no longer required.

The procedure is intended to ensure that:

  • Contractor access is removed in a timely manner
  • Organizational information is protected
  • Privileged and production access is revoked
  • Company assets are recovered
  • Credentials, keys, and tokens are addressed
  • Customer and supplier access is removed
  • Confidential information is returned or securely deleted where required
  • Business information and responsibilities are transferred
  • Security incidents or investigation requirements are considered
  • Offboarding activities are documented and verified

Core Principle

Notify → Identify → Assess → Revoke → Recover → Protect → Transfer → Verify → Record → Close


2. Scope

This procedure applies to:

  • Contractors
  • Consultants
  • Freelancers
  • Temporary workers
  • Contract developers
  • Contract administrators
  • External IT personnel
  • Managed service personnel
  • Security consultants
  • Project-based resources
  • Agency personnel
  • Other non-employees with organizational access

It applies to contractors working:

  • On-site
  • Remotely
  • Through a staffing agency
  • Through a supplier
  • From customer locations
  • Through third-party platforms

3. When the Procedure Applies

The procedure shall be initiated when:

☐ Contract expires
☐ Project is completed
☐ Contractor resigns
☐ Contractor engagement is terminated
☐ Contractor changes role
☐ Contractor no longer requires access
☐ Supplier engagement ends
☐ Security concern arises
☐ Contractor access must be revoked immediately
☐ Other: __________________________

The procedure may also be initiated when a contractor’s access requirements materially change.


4. Roles and Responsibilities

RoleResponsibility
Business OwnerConfirms engagement end and business requirements
Contractor ManagerCoordinates contractor offboarding
HR/People TeamMaintains contractor records where applicable
IT/IAMRemoves identity and system access
Security TeamReviews security risks and privileged access
System OwnerConfirms application/system access removal
Cloud OwnerRemoves cloud access
Asset OwnerRecovers organizational assets
Procurement/Supplier OwnerCoordinates external supplier requirements
LegalAdvises on contractual/legal requirements where necessary
ContractorReturns assets and organizational information
Independent ReviewerVerifies critical access removal where required

Responsibilities may be combined in a small organization, provided appropriate review and verification are maintained.


5. Contractor Offboarding Information

FieldDetails
Offboarding ID
Contractor Name
Contractor ID
Supplier/Agency
Role
Business Owner
Manager
Contract Start Date
Contract End Date
Actual End Date
Offboarding Reason
Risk Level☐ Low ☐ Medium ☐ High ☐ Critical
Privileged Access☐ Yes ☐ No
Production Access☐ Yes ☐ No
Customer Data Access☐ Yes ☐ No
Personal Data Access☐ Yes ☐ No
Security Reviewer
Completion Date

6. Offboarding Notification

The business owner or authorized person shall notify relevant teams when the contractor engagement is ending.

Notify, as applicable:

☐ Contractor manager
☐ HR/People team
☐ IT/IAM
☐ Security
☐ Cloud/platform owner
☐ Application owners
☐ System owners
☐ Procurement
☐ Supplier/agency
☐ Facilities/security
☐ Finance
☐ Legal
☐ Customer owner

Notification Information

The notification should include:

  • Contractor name
  • Supplier/agency
  • Effective termination date
  • Effective termination time where applicable
  • Reason where appropriate
  • Required access-revocation timing
  • Asset-return requirements
  • Business continuity requirements
  • Any special security instructions

7. Determine Offboarding Risk

Before access removal, assess whether the contractor presents elevated offboarding risk.

Consider:

☐ Privileged access
☐ Production access
☐ Customer environment access
☐ Personal-data access
☐ Confidential/restricted information
☐ Source-code access
☐ Cloud administration
☐ Database administration
☐ Security-system access
☐ Physical facility access
☐ Knowledge of shared credentials
☐ Access to encryption keys
☐ Access to API keys/secrets
☐ Security incident involvement
☐ Dispute/termination concern
☐ Remote/BYOD access

Risk Level

☐ Low
☐ Medium
☐ High
☐ Critical

High-risk contractor offboarding should receive priority and additional verification.


8. Access Inventory

Identify all access provided to the contractor.

Review:

☐ Corporate identity
☐ Email
☐ SSO
☐ MFA
☐ VPN
☐ Wi-Fi
☐ Cloud platforms
☐ AWS
☐ Azure
☐ Google Cloud
☐ Production systems
☐ Development systems
☐ Test systems
☐ Databases
☐ Source code
☐ GitHub/GitLab/Bitbucket
☐ CI/CD
☐ SaaS applications
☐ Security tools
☐ Monitoring systems
☐ Ticketing systems
☐ Customer environments
☐ Supplier environments
☐ Physical access
☐ API credentials
☐ SSH keys
☐ Service accounts
☐ Shared accounts

Access Inventory

SystemAccessPrivilegeOwnerActionVerified

9. Access Revocation

At the approved effective time:

☐ Corporate account disabled
☐ SSO access removed
☐ MFA methods revoked
☐ VPN access removed
☐ Cloud access removed
☐ Application access removed
☐ Production access removed
☐ Database access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ SaaS access removed
☐ Security-tool access removed
☐ Customer-system access removed
☐ Supplier-system access removed
☐ Physical access removed

Access should be removed according to the risk and timing requirements defined by the organization.


10. Cloud and AWS Access

If the contractor has cloud access:

AWS

☐ IAM Identity Center access removed
☐ IAM roles removed
☐ IAM groups removed
☐ Access keys disabled/revoked
☐ Temporary credentials expired
☐ Cross-account access reviewed
☐ Production account access removed
☐ Administrative roles removed
☐ MFA/authentication methods addressed
☐ CloudTrail activity reviewed where required

Other Cloud Platforms

☐ Azure access removed
☐ GCP access removed
☐ Subscription/project roles removed
☐ Administrative access removed
☐ Service-account relationships reviewed
☐ API credentials revoked


11. Privileged Access

If the contractor had elevated access:

☐ Privileged accounts identified
☐ Administrative roles removed
☐ Production privileges removed
☐ Database administrator access removed
☐ Cloud administrator access removed
☐ Security administrator access removed
☐ Network administrator access removed
☐ Source-code administrator access removed
☐ CI/CD administrator access removed
☐ Break-glass access reviewed
☐ Shared administrator credentials assessed
☐ Credentials rotated where required
☐ Independent verification completed

For high-risk privileged contractors, follow the organization’s Privileged User Offboarding Checklist.


12. Source Code and Development Access

Review:

☐ GitHub
☐ GitLab
☐ Bitbucket
☐ Azure DevOps
☐ Repository access
☐ Organization administration
☐ Branch protection
☐ CI/CD
☐ Package registries
☐ Container registries

Verify:

☐ User removed
☐ Repository permissions removed
☐ Organization roles removed
☐ SSH keys revoked
☐ Personal access tokens revoked
☐ OAuth authorizations revoked
☐ Deployment access removed
☐ Code ownership updated
☐ Secrets reviewed


13. Production Access

If the contractor accessed production:

☐ Production account disabled
☐ Production VPN access removed
☐ Bastion access removed
☐ Kubernetes access removed
☐ Production server access removed
☐ Production database access removed
☐ Production deployment access removed
☐ Monitoring access removed
☐ Administrative console access removed
☐ Emergency access reviewed

For sensitive environments, recent privileged activity may be reviewed before closure.


14. Customer and Client Access

Determine whether the contractor accessed customer environments.

☐ Customer cloud environment
☐ Customer application
☐ Customer database
☐ Customer support platform
☐ Customer source code
☐ Customer documents
☐ Customer credentials
☐ Customer communication systems

Actions:

☐ Access revoked
☐ Customer owner notified where required
☐ Customer credentials rotated where necessary
☐ Customer information returned/deleted where required
☐ Evidence retained where required


15. Information Protection

Identify organizational information held by the contractor.

Examples include:

  • Source code
  • Architecture documentation
  • Customer information
  • Personal data
  • Credentials
  • Security reports
  • Vulnerability information
  • Business documents
  • Contracts
  • Financial information
  • Internal procedures
  • Confidential communications

Verify:

☐ Information identified
☐ Business information transferred
☐ Organizational copies recovered
☐ Unauthorized copies addressed
☐ Information returned where required
☐ Information securely deleted where required
☐ Deletion confirmation obtained where appropriate


16. Contractor-Owned Devices

If the contractor used their own device:

☐ BYOD arrangement identified
☐ Organizational information identified
☐ Organizational accounts removed
☐ Sessions terminated
☐ Tokens revoked
☐ Certificates addressed
☐ Local organizational data addressed
☐ Approved deletion process followed
☐ Evidence obtained where required

The organization should not unnecessarily access or delete unrelated personal information on contractor-owned devices.


17. Company-Owned Assets

Recover organizational assets provided to the contractor.

Examples:

☐ Laptop
☐ Desktop
☐ Mobile phone
☐ Tablet
☐ Monitor
☐ Security key
☐ Access card
☐ ID card
☐ Tokens
☐ Removable media
☐ Network equipment
☐ Development equipment
☐ Other: ______________________

Record:

Asset IDAssetConditionReturnedVerified

Use the organization’s Asset Return Checklist where applicable.


18. Credentials and Secrets

Determine whether the contractor had access to:

☐ Passwords
☐ API keys
☐ Cloud access keys
☐ SSH keys
☐ Database credentials
☐ Service-account credentials
☐ CI/CD secrets
☐ Certificates
☐ Encryption keys
☐ Signing keys
☐ Shared administrator passwords

Actions:

☐ Credentials revoked
☐ Tokens invalidated
☐ Keys revoked
☐ Shared credentials rotated where required
☐ Secret ownership transferred
☐ Vault access removed

Do not rely only on removing the contractor’s personal account when a shared credential was known to the contractor.


19. Service Accounts and Technical Ownership

If the contractor created or managed service accounts:

☐ Service accounts identified
☐ Business owner identified
☐ Technical owner identified
☐ Ownership transferred
☐ Personal dependencies removed
☐ Credentials reviewed
☐ Unnecessary accounts disabled
☐ Secrets rotated where required
☐ Documentation updated

Service accounts should not be disabled without confirming whether operational services depend on them.


20. Physical Access

Where applicable:

☐ Building access removed
☐ Office access removed
☐ Data-center access removed
☐ Server-room access removed
☐ Restricted-area access removed
☐ Access card recovered
☐ Keys recovered
☐ Visitor privileges removed
☐ Biometric access removed


21. Supplier or Agency Coordination

If the contractor is supplied through another organization:

☐ Supplier notified
☐ Supplier confirmed end date
☐ Supplier access confirmed removed
☐ Supplier assets addressed
☐ Supplier credentials addressed
☐ Customer access addressed
☐ Confidential information obligations reinforced
☐ Supplier confirmation obtained where appropriate

Supplier

Name: __________________________

Contact: ________________________

Confirmation Date: ______________


22. Confidentiality and Contractual Obligations

Before closure, verify applicable contractual requirements.

☐ NDA/confidentiality agreement
☐ IP ownership obligations
☐ Data protection requirements
☐ Information-return requirements
☐ Information-deletion requirements
☐ Non-disclosure obligations
☐ Customer confidentiality requirements
☐ Intellectual-property obligations
☐ Continuing confidentiality obligations

Contractual obligations that survive the end of the engagement should be communicated to the contractor where appropriate.


23. Business and Knowledge Transfer

Identify information necessary for business continuity.

☐ Current projects
☐ Technical documentation
☐ Architecture documentation
☐ Operational procedures
☐ Customer information
☐ Supplier information
☐ Security information
☐ Open tickets
☐ Open vulnerabilities
☐ Pending changes
☐ Deployment information
☐ Recovery information
☐ Key contacts

Knowledge Transfer Owner

Name: __________________________

Date: __________________________


24. Security Investigation Check

Before deleting or destroying accounts, devices, logs, or information, determine whether the contractor is associated with:

☐ Security incident
☐ Data breach
☐ Suspicious activity
☐ Policy violation
☐ Insider-risk concern
☐ Legal dispute
☐ Regulatory investigation
☐ Customer investigation
☐ Litigation hold

If applicable:

☐ Evidence preservation initiated
☐ Relevant logs preserved
☐ Account activity preserved
☐ Device preservation considered
☐ Security/Legal/HR consulted
☐ Investigation owner assigned

Important

Offboarding should not unintentionally destroy evidence required for an investigation, legal matter, or regulatory obligation.


25. Final Verification

A responsible reviewer should verify that required access has actually been removed.

Verify:

☐ Corporate identity
☐ Email
☐ SSO
☐ MFA
☐ VPN
☐ AWS/cloud
☐ Production
☐ Database
☐ Source code
☐ CI/CD
☐ SaaS
☐ Security systems
☐ Customer environments
☐ Supplier environments
☐ Physical access
☐ API keys/tokens
☐ SSH keys
☐ Shared credentials
☐ Service accounts

Verification

Reviewed By: __________________________

Date: _________________________________

Result: ☐ Complete ☐ Exception


26. Exceptions

Any access or activity that cannot be completed immediately shall be documented.

ExceptionReasonRiskTemporary ControlOwnerDue Date

Exceptions should have:

  • A defined owner
  • A documented risk
  • A temporary control where appropriate
  • A target completion date

27. Evidence Retention

Retain appropriate evidence such as:

☐ Offboarding notification
☐ Contractor record
☐ Access inventory
☐ Access-revocation evidence
☐ Cloud access-removal evidence
☐ Privileged-access evidence
☐ Asset-return evidence
☐ Credential-rotation evidence
☐ Supplier confirmation
☐ Information-return/deletion confirmation
☐ Investigation records where applicable
☐ Final verification
☐ Exception approval
☐ Completion record

Do not retain passwords, private keys, API secrets, recovery codes, or other authentication secrets as evidence.


28. Contractor Offboarding Register

Offboarding IDContractorSupplierEnd DateAccess RemovedAssets ReturnedReviewerStatus

Status

☐ Open
☐ In Progress
☐ Verification Pending
☐ Exception
☐ Completed
☐ Closed


29. Completion Criteria

Contractor offboarding is complete when:

☐ Engagement end confirmed
☐ Access inventory completed
☐ Required access revoked
☐ Privileged access removed
☐ Cloud access removed
☐ Production access removed
☐ Source-code access removed
☐ Customer access removed
☐ Supplier access addressed
☐ Credentials/tokens/keys addressed
☐ Shared credentials assessed
☐ Service accounts reviewed
☐ Assets recovered or accounted for
☐ Organizational information transferred
☐ Information return/deletion completed where required
☐ Physical access removed
☐ Confidentiality obligations addressed
☐ Investigation requirements considered
☐ Independent verification completed where required
☐ Exceptions documented
☐ Evidence retained
☐ Offboarding register updated
☐ Final approval completed


30. Final Approval

Contractor: ______________________________

Supplier/Agency: ______________________________

Business Owner: ______________________________

Offboarding Effective Date: ______________________________

Completed By: ______________________________

Security Reviewer: ______________________________

Final Status: ☐ Completed ☐ Completed with Exception

Completion Date: ______________________________

Comments


31. AWS SaaS Startup Example

A SaaS startup uses a contract DevOps engineer for a six-month project.

The contractor has:

  • AWS access
  • Production Kubernetes access
  • GitHub repository access
  • CI/CD access
  • Production database access
  • VPN access
  • Monitoring access
  • Access to deployment secrets

The contract ends on 31 December at 6:00 PM.

Before 6:00 PM

The business owner confirms the contract end and informs:

  • IT/IAM
  • Security
  • Engineering manager
  • Cloud owner
  • Relevant system owners

The team prepares the access inventory and identifies:

  • AWS accounts and roles
  • GitHub permissions
  • Kubernetes permissions
  • Database access
  • CI/CD permissions
  • VPN access
  • Secrets known to the contractor

At 6:00 PM

The organization:

  1. Disables the contractor’s corporate identity.
  2. Removes AWS roles and permissions.
  3. Revokes cloud credentials.
  4. Removes GitHub access.
  5. Revokes SSH keys and tokens.
  6. Removes Kubernetes privileges.
  7. Removes production database access.
  8. Removes CI/CD access.
  9. Removes VPN access.
  10. Revokes SaaS/security-tool access.
  11. Rotates shared production credentials where required.

After Access Removal

The organization:

  • Recovers company assets.
  • Transfers project documentation.
  • Confirms service-account ownership.
  • Checks whether investigation/evidence preservation is required.
  • Performs independent verification.
  • Obtains supplier confirmation if applicable.
  • Updates the contractor register.
  • Closes the offboarding record.

Audit Trail

Contract End → Risk Assessment → Access Inventory → Access Revocation → Credential/Secret Review → Asset Recovery → Information Transfer → Verification → Evidence → Closure


32. Startup-Friendly Contractor Offboarding Model

A startup can implement the process using eight practical steps:

1. Notify

Confirm exactly when the contractor’s access must end.

2. Identify

Determine what systems, information, assets, and facilities the contractor can access.

3. Revoke

Remove access at the required time.

4. Recover

Recover company-owned assets and organizational information.

5. Protect

Rotate credentials, secrets, tokens, and keys where necessary.

6. Transfer

Transfer business knowledge, documentation, responsibilities, and system ownership.

7. Verify

Have another responsible person verify critical access removal.

8. Close

Record evidence, exceptions, approvals, and completion.


33. Common Mistakes

Avoid:

  • Treating contractors differently from employees when they have similar security access.
  • Removing only email access.
  • Forgetting AWS or other cloud access.
  • Forgetting GitHub/GitLab access.
  • Forgetting VPN access.
  • Forgetting customer environments.
  • Forgetting production databases.
  • Forgetting API keys and SSH keys.
  • Forgetting shared passwords.
  • Forgetting service-account ownership.
  • Failing to recover company equipment.
  • Ignoring BYOD requirements.
  • Deleting accounts before checking investigation requirements.
  • Failing to obtain supplier confirmation.
  • Allowing exceptions without an owner and due date.
  • Assuming asset recovery means access revocation is complete.

34. Relationship With Other ISMS Documents

DocumentRelationship
Employee Offboarding PolicyDefines broader personnel exit requirements
Employee Termination Security ChecklistCovers employee termination security
Access Revocation ChecklistProvides detailed access-removal controls
Privileged User Offboarding ChecklistHandles privileged contractor access
Asset Return ChecklistHandles company asset recovery
Supplier Offboarding ChecklistHandles supplier-level termination
Contractor Screening ProcedureAddresses contractor onboarding screening
Contractor Security AgreementDefines contractor security obligations
Access Management ProcedureDefines access lifecycle
Joiner-Mover-Leaver ProcedureManages identity lifecycle
Incident Response ProcedureHandles security-related offboarding incidents
Evidence Preservation ProcedureProtects relevant investigation evidence
Asset RegisterRecords company assets
Access RegisterRecords user access
Supplier RegisterRecords external suppliers

35. ISO 27001 / SOC 2 Connection

Contractor offboarding supports the organization’s controls for:

  • Removal or adjustment of access
  • Identity and access management
  • Privileged access
  • Personnel security
  • Information protection
  • Asset management
  • Supplier relationships
  • Confidentiality
  • Incident management
  • Business continuity

For ISO 27001, the exact applicable controls should be determined through the organization’s risk assessment and Statement of Applicability.

For SOC 2, contractor offboarding can provide evidence that access is removed when no longer required and that changes to access are controlled and reviewed.

The procedure should operate together with the organization’s access-control, personnel-security, supplier-management, asset-management, and incident-management processes.


36. Quick Audit Checklist

☐ Contractor engagement end documented
☐ Effective date/time confirmed
☐ Business owner identified
☐ Supplier/agency identified
☐ Risk assessed
☐ Access inventory completed
☐ Corporate access removed
☐ MFA addressed
☐ VPN removed
☐ Cloud access removed
☐ AWS access removed
☐ Production access removed
☐ Database access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ SaaS access removed
☐ Customer access removed
☐ Supplier access addressed
☐ Privileged access removed
☐ API keys/tokens revoked
☐ SSH keys addressed
☐ Shared credentials assessed
☐ Secrets rotated where required
☐ Service accounts reviewed
☐ Assets recovered
☐ Information transferred
☐ Information returned/deleted where required
☐ Physical access removed
☐ Confidentiality obligations addressed
☐ Investigation requirements considered
☐ Supplier confirmation obtained where applicable
☐ Independent verification completed
☐ Exceptions documented
☐ Evidence retained
☐ Register updated
☐ Final approval completed


37. Final Audit Trail

For every significant contractor relationship, the organization should be able to demonstrate:

When did the contractor’s engagement end?
Who authorized the offboarding?
What systems and information could the contractor access?
Was the access inventory complete?
Was cloud and production access removed?
Were privileged accounts addressed?
Were credentials, tokens, keys, and shared secrets reviewed?
Were organizational assets recovered?
Was organizational information returned, transferred, or deleted as required?
Were customer and supplier environments addressed?
Were investigation and evidence-preservation requirements considered?
Who verified access removal?
Were exceptions documented and controlled?
What evidence proves the contractor was successfully offboarded?

Final Principle

Contractor offboarding is not simply the end of a contract. It is the controlled termination of the contractor’s digital, physical, informational, and operational relationship with the organization while preserving business continuity and security evidence.