1. Purpose
The Offboarding Confidentiality Checklist provides a structured process for protecting confidential, sensitive, personal, customer, proprietary, and security information when an employee, contractor, consultant, supplier personnel, or other authorized individual leaves the organization or no longer requires access.
The objective is to ensure that:
- Confidentiality obligations continue after access ends
- Access to confidential information is removed
- Company and customer information is returned or securely deleted
- Information stored on personal or company devices is addressed
- Confidential information is not retained without authorization
- Credentials and secrets are protected
- Intellectual property remains with the organization where applicable
- Continuing confidentiality obligations are communicated
- Evidence of the offboarding process is retained
- Any confidentiality risks are identified and addressed
Core Principle
Identify → Protect → Revoke → Recover → Return/Delete → Verify → Acknowledge → Record → Close
2. When to Use
Use this checklist when:
- An employee leaves
- A contractor engagement ends
- A consultant completes an assignment
- A temporary worker leaves
- Supplier personnel are replaced
- A role changes and confidential access is no longer required
- Privileged access is removed
- A project ends
- A customer engagement ends
- An individual is terminated
- Access is suspended because of a security concern
For high-risk or involuntary termination, the process should be coordinated with HR, Legal, Security, IT, and the relevant business owner as appropriate.
3. Offboarding Information
| Field | Details |
|---|---|
| Offboarding ID | |
| Person Name | |
| Employee/Contractor ID | |
| Organization/Agency | |
| Role | |
| Department/Project | |
| Manager/Business Owner | |
| Information Owner | |
| Employment/Contract End Date | |
| Last Working Date | |
| Effective Access Termination | |
| Offboarding Type | |
| Risk Level | |
| Reviewer | |
| Completion Date |
4. Offboarding Type
☐ Employee resignation
☐ Employee termination
☐ Contractor completion
☐ Consultant completion
☐ Temporary worker completion
☐ Supplier personnel replacement
☐ Project completion
☐ Contract expiry
☐ Role change
☐ Access reduction
☐ Emergency access removal
☐ Other: ______________________
5. Confidentiality Obligations
Confirm the individual’s continuing confidentiality obligations.
☐ NDA identified
☐ NDA remains applicable after termination
☐ Employment/contract confidentiality clause reviewed
☐ Customer confidentiality obligations reviewed
☐ Intellectual-property obligations reviewed
☐ Personal-data confidentiality obligations reviewed
☐ Security-information confidentiality reviewed
☐ Post-termination obligations communicated
☐ Continuing confidentiality acknowledgement completed where required
Agreement Details
NDA/Agreement ID: ______________________
Effective Date: ______________________
Confidentiality Period: ______________________
Post-Termination Obligations: ______________________
6. Information Access Inventory
Identify all confidential information the individual could access.
☐ Customer information
☐ Personal data
☐ Financial information
☐ Source code
☐ Intellectual property
☐ Product information
☐ Business plans
☐ Pricing information
☐ Contracts
☐ Security architecture
☐ Vulnerability information
☐ Credentials/secrets
☐ Cloud configuration
☐ Employee information
☐ Legal information
☐ Other: ______________________
Information Inventory
| Information | System/Location | Classification | Owner | Action |
|---|---|---|---|---|
7. Access Revocation
Confidentiality protection requires removal of access, not simply a reminder about confidentiality.
☐ Corporate identity disabled
☐ Email disabled
☐ SSO access removed
☐ VPN access removed
☐ Cloud access removed
☐ AWS access removed
☐ Azure access removed
☐ GCP access removed
☐ Source-code access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Security-tool access removed
☐ Customer-system access removed
☐ File-sharing access removed
☐ Collaboration access removed
☐ Physical access removed
Access Evidence
8. Shared and Delegated Access
Review access that may not be directly associated with the individual’s primary account.
☐ Shared accounts reviewed
☐ Delegated mailbox access removed
☐ Shared drive access removed
☐ Shared application access reviewed
☐ Group memberships removed
☐ Distribution groups reviewed
☐ Service-account access reviewed
☐ API access reviewed
☐ Delegated administrative access removed
Any shared credentials that the individual knew should be assessed for rotation.
9. Credentials and Secrets
Determine whether the individual had access to credentials or secrets.
☐ Passwords reviewed
☐ API keys reviewed
☐ Tokens reviewed
☐ SSH keys reviewed
☐ Certificates reviewed
☐ Cloud credentials reviewed
☐ Database credentials reviewed
☐ CI/CD secrets reviewed
☐ Encryption-key access reviewed
☐ Shared administrative credentials reviewed
Where required:
☐ Credentials rotated
☐ Tokens revoked
☐ API keys revoked
☐ SSH keys removed
☐ Certificates replaced
☐ Shared secrets changed
Never record actual passwords, private keys, API secrets, or authentication values in the offboarding record.
10. Source Code and Intellectual Property
For developers, engineers, product personnel, or other IP-sensitive roles:
☐ Source repositories identified
☐ Repository access revoked
☐ Organization access revoked
☐ Branch permissions reviewed
☐ Deployment permissions removed
☐ Code-signing access reviewed
☐ CI/CD access removed
☐ Personal repository copies addressed
☐ Local source-code copies addressed
☐ Proprietary documentation recovered
☐ Intellectual-property obligations confirmed
11. Cloud Environment
Where cloud access existed:
☐ Cloud accounts identified
☐ IAM access removed
☐ IAM roles reviewed
☐ Group membership removed
☐ SSO assignment removed
☐ Production permissions removed
☐ Administrative permissions removed
☐ Cloud console access removed
☐ CLI/API access removed
☐ Access keys revoked
☐ Temporary credentials invalidated where appropriate
☐ Cloud activity reviewed where necessary
12. AWS SaaS Offboarding
For an AWS SaaS startup, review:
☐ AWS IAM/SSO identity disabled
☐ IAM roles reviewed
☐ IAM groups reviewed
☐ Access keys revoked
☐ Console access removed
☐ CLI access removed
☐ Production access removed
☐ S3 access reviewed
☐ Database access removed
☐ Secrets Manager access reviewed
☐ KMS/key access reviewed
☐ CloudWatch access removed
☐ CI/CD access removed
☐ Security-tool access removed
High-Risk Access
If the individual had administrative or production access:
☐ Privileged activity reviewed
☐ Security team notified where appropriate
☐ Credentials/secrets rotated
☐ Break-glass access reviewed
☐ Potential security impact assessed
13. Information Stored on Company Devices
Identify confidential information stored on company-owned devices.
☐ Laptop reviewed
☐ Desktop reviewed
☐ Mobile device reviewed
☐ Tablet reviewed
☐ Removable media reviewed
☐ Local documents reviewed
☐ Downloaded customer data reviewed
☐ Source-code copies reviewed
☐ Credentials/secrets reviewed
☐ Browser-stored credentials addressed
☐ Cloud synchronization reviewed
Before wiping a device, consider legal, regulatory, retention, and security-investigation requirements.
14. Information Stored on Personal Devices
If BYOD was permitted:
☐ Personal device identified
☐ Company data location identified
☐ Corporate applications removed
☐ Corporate accounts removed
☐ Company files removed where permitted/required
☐ Corporate synchronization disabled
☐ Company credentials removed
☐ Tokens revoked
☐ Company data deletion confirmed where appropriate
☐ Legal/investigation requirements considered
Do not access or delete personal information beyond what is authorized and legally permissible.
15. Cloud Storage and File Sharing
Review:
☐ Google Drive
☐ OneDrive
☐ SharePoint
☐ Dropbox
☐ Company file servers
☐ S3/cloud storage
☐ Confluence
☐ Notion
☐ Project repositories
☐ Collaboration platforms
☐ Other: ______________________
Confirm:
☐ Ownership transferred
☐ Access removed
☐ Shared links reviewed
☐ External sharing reviewed
☐ Personal copies addressed
☐ Confidential documents retained appropriately
☐ Unnecessary copies deleted where required
16. Email and Communication
Review:
☐ Corporate email disabled
☐ Email forwarding disabled
☐ Delegated access removed
☐ Mobile email access removed
☐ Email sessions revoked where appropriate
☐ Confidential attachments reviewed where necessary
☐ Shared mailbox access removed
☐ Distribution-list membership reviewed
☐ Auto-forwarding rules reviewed
☐ External forwarding reviewed
17. Collaboration Platforms
Review applicable platforms:
☐ Slack
☐ Microsoft Teams
☐ Zoom
☐ Jira
☐ Confluence
☐ GitHub/GitLab/Bitbucket
☐ CRM
☐ Project-management systems
☐ Security platforms
☐ Other: ______________________
☐ Account disabled
☐ Group memberships removed
☐ Administrative roles removed
☐ Shared access reviewed
☐ Confidential project access removed
18. Customer Information
If the individual handled customer information:
☐ Customer systems identified
☐ Customer access removed
☐ Customer data access reviewed
☐ Local customer-data copies addressed
☐ Customer documents recovered
☐ Customer confidentiality obligations confirmed
☐ Customer notification considered where required
☐ Security incident assessment completed if necessary
19. Personal Data
If the individual handled personal data:
☐ Personal-data access removed
☐ Local copies addressed
☐ Downloads addressed
☐ Personal-device copies addressed where applicable
☐ Data-retention requirements considered
☐ Data-deletion requirements completed
☐ Privacy incident assessment completed where necessary
20. Confidential Documents
Recover or appropriately address:
☐ Printed documents
☐ Contracts
☐ Customer reports
☐ Security reports
☐ Architecture documents
☐ Source-code documentation
☐ Product documents
☐ Financial documents
☐ Strategy documents
☐ Security assessments
☐ Vulnerability reports
☐ Incident records
☐ Other: ______________________
21. Removable Media
Review:
☐ USB drives
☐ External hard drives
☐ Memory cards
☐ Backup media
☐ Security keys
☐ Other removable media
For each:
☐ Returned
☐ Data transferred
☐ Data securely deleted where appropriate
☐ Device securely wiped
☐ Asset register updated
☐ Investigation/retention requirements considered
22. Physical Confidentiality
Where applicable:
☐ Access card returned
☐ Building access removed
☐ Office keys returned
☐ Data-center access removed
☐ Secure-area access removed
☐ Visitor privileges removed
☐ Physical documents recovered
☐ Storage locations reviewed
23. Intellectual Property
Confirm that organizational intellectual property remains protected.
☐ Source code retained by organization
☐ Documentation transferred
☐ Design files transferred
☐ Product information transferred
☐ Customer deliverables transferred
☐ Credentials transferred securely where appropriate
☐ Work product ownership confirmed
☐ Personal copies addressed
☐ IP/confidentiality obligations confirmed
24. Knowledge Transfer
Where appropriate:
☐ Business information transferred
☐ Project documentation transferred
☐ System knowledge transferred
☐ Customer knowledge transferred
☐ Supplier knowledge transferred
☐ Operational procedures transferred
☐ Security information transferred
☐ Critical dependencies documented
☐ Outstanding tasks transferred
Knowledge transfer should not result in unnecessary duplication or uncontrolled copying of confidential information.
25. High-Risk Offboarding
Perform enhanced review when the individual had:
☐ Privileged access
☐ Production access
☐ Customer-data access
☐ Security administration access
☐ Source-code access
☐ Cloud administrator access
☐ Database administrator access
☐ Encryption-key access
☐ Incident-response access
☐ Financial-system access
☐ High-value intellectual property access
Enhanced Actions
☐ Immediate access revocation
☐ Security team involvement
☐ Privileged activity review
☐ Credential rotation
☐ Data-access review
☐ Customer impact assessment
☐ Legal review where appropriate
☐ Incident assessment where appropriate
26. Involuntary Termination
For involuntary or high-risk termination:
☐ Termination risk assessed
☐ HR/Legal involved as appropriate
☐ Security involved as appropriate
☐ Access termination timing coordinated
☐ Immediate access revocation considered
☐ Active sessions terminated
☐ Privileged credentials reviewed
☐ Shared credentials rotated
☐ Physical access removed
☐ Corporate devices secured
☐ Evidence preservation considered
☐ Investigation requirements assessed
The process should be handled discreetly and proportionately.
27. Contractor/Supplier Personnel
Where the departing individual belongs to an external organization:
☐ Supplier notified
☐ Contractor identity confirmed
☐ Access list reviewed
☐ Corporate access removed
☐ Customer access removed
☐ Cloud access removed
☐ Source-code access removed
☐ Supplier-managed accounts addressed
☐ Confidentiality obligations confirmed
☐ Replacement personnel reviewed
☐ Supplier confirmation obtained where required
28. Exit Confidentiality Acknowledgement
The individual should acknowledge, where appropriate:
☐ Confidentiality obligations continue
☐ Company information must not be retained without authorization
☐ Customer information must not be retained
☐ Personal data must not be retained
☐ Source code must not be retained
☐ Credentials must not be retained or reused
☐ Company property must be returned
☐ Unauthorized access after termination is prohibited
☐ Security incidents must continue to be reported
☐ Legal/contractual obligations continue after exit
Acknowledgement
Name: ______________________
Date: ______________________
Signature/Confirmation: ______________________
29. Information Return and Deletion
Determine what must be returned or deleted.
| Information | Location | Action | Completed | Evidence |
|---|---|---|---|---|
| Return/Delete |
Possible actions:
☐ Return to organization
☐ Transfer to authorized owner
☐ Secure deletion
☐ Secure disposal
☐ Retain under approved retention requirement
☐ Legal hold
☐ Investigation hold
Do not delete information that must be preserved for legal, regulatory, contractual, or security-investigation reasons.
30. Confidentiality Risk Assessment
Assess whether offboarding creates additional confidentiality risk.
| Risk | Likelihood | Impact | Risk Level | Treatment | Owner |
|---|---|---|---|---|---|
Consider:
- Knowledge of confidential information
- Knowledge of credentials
- Knowledge of security architecture
- Customer-data exposure
- Source-code exposure
- Privileged access
- Remaining copies
- Personal-device storage
- Third-party systems
- Potential unauthorized disclosure
31. Post-Offboarding Monitoring
For higher-risk departures:
☐ Authentication activity reviewed
☐ Failed login attempts reviewed
☐ Cloud activity reviewed
☐ Source-code activity reviewed
☐ VPN activity reviewed
☐ Customer-system activity reviewed
☐ Data-transfer activity reviewed
☐ Security alerts reviewed
Monitoring should be proportionate to risk and applicable legal requirements.
32. Confidentiality Incident Check
Determine whether any confidentiality issue occurred during or immediately before offboarding.
☐ No issue identified
☐ Unauthorized disclosure
☐ Data copied
☐ Data transferred externally
☐ Lost device
☐ Unauthorized access
☐ Suspicious download
☐ Credential exposure
☐ Confidential information retained
☐ Other
If an issue is identified:
☐ Incident reported
☐ Incident assessed
☐ Evidence preserved
☐ Access reviewed
☐ Risk assessed
☐ Corrective action initiated
33. Exceptions
Document any incomplete or exceptional requirements.
| Requirement | Exception | Reason | Risk | Compensating Control | Approver | Expiry |
|---|---|---|---|---|---|---|
Exceptions should not become permanent undocumented practices.
34. Final Verification
Before closing the offboarding:
☐ All known access removed
☐ Active sessions addressed
☐ Privileged access removed
☐ Cloud access removed
☐ Source-code access removed
☐ Customer access removed
☐ SaaS access removed
☐ Shared/delegated access removed
☐ Credentials reviewed/rotated
☐ Company assets recovered
☐ Confidential information returned/deleted/addressed
☐ Personal-device information addressed where applicable
☐ Confidentiality obligations confirmed
☐ Exit acknowledgement completed
☐ Incidents assessed
☐ Evidence collected
☐ Exceptions documented
☐ Asset records updated
☐ Access-revocation evidence recorded
35. Independent Verification
Where appropriate, a second person should verify critical offboarding activities.
Primary Operator
Name: ______________________
Date: ______________________
Independent Reviewer
Name: ______________________
Date: ______________________
Verification Result
☐ Complete
☐ Complete with Exceptions
☐ Further Action Required
36. Offboarding Evidence Register
| Evidence ID | Activity | System | Evidence Type | Date | Reviewer | Location |
|---|---|---|---|---|---|---|
Evidence may include:
- Access-revocation screenshots
- IAM records
- Account-disabled confirmation
- Credential-rotation evidence
- Asset-return record
- Data-deletion confirmation
- Supplier confirmation
- Exit acknowledgement
- Security review record
Evidence should not contain actual credentials or secrets.
37. Offboarding Closure
Final Result
☐ Completed
☐ Completed with Exceptions
☐ Further Action Required
☐ Security Investigation Required
☐ Legal Review Required
Outstanding Actions
Closure Approval
Business Owner: ______________________
Security Reviewer: ______________________
HR/Supplier Owner: ______________________
Closure Date: ______________________
38. Startup-Friendly Offboarding Model
A startup can maintain strong confidentiality controls without creating excessive administrative work.
Standard Exit
Use:
- Confirm exit
- Identify confidential information
- Revoke access
- Recover assets
- Transfer business information
- Return/delete information
- Confirm continuing confidentiality
- Verify
- Record evidence
High-Risk Exit
Add:
- Immediate access revocation
- Privileged-access review
- Credential rotation
- Cloud activity review
- Source-code review
- Customer-data review
- Security investigation assessment
- Legal/HR coordination
- Enhanced post-exit monitoring
39. AWS SaaS Startup Example
Scenario
A DevOps engineer leaves an AWS SaaS startup.
The engineer had access to:
- AWS production
- GitHub
- CI/CD
- Production database
- S3 customer-data storage
- CloudWatch
- Secrets Manager
- Jira
- Slack
Offboarding
Immediate Actions
☐ Disable corporate identity
☐ Remove AWS access
☐ Revoke access keys
☐ Remove GitHub access
☐ Disable CI/CD access
☐ Remove database access
☐ Remove S3 access
☐ Remove Secrets Manager access
☐ Remove Jira/Slack access
Confidentiality Actions
☐ Review source-code copies
☐ Review customer-data access
☐ Address local confidential files
☐ Confirm NDA continues
☐ Recover company laptop
☐ Review credentials/secrets
☐ Rotate shared credentials where necessary
Verification
Revoke → Rotate → Recover → Return/Delete → Verify → Record
40. Common Mistakes
Avoid:
- Treating an exit interview as confidentiality offboarding.
- Assuming disabling the email account removes all access.
- Forgetting cloud accounts.
- Forgetting GitHub/GitLab access.
- Forgetting API keys and tokens.
- Forgetting shared credentials.
- Forgetting delegated access.
- Forgetting customer environments.
- Forgetting personal devices.
- Wiping devices before checking legal/investigation requirements.
- Failing to confirm continuing confidentiality.
- Failing to recover confidential documents.
- Failing to review source-code copies.
- Failing to document evidence.
- Failing to coordinate supplier/contractor exits.
- Assuming an NDA alone prevents post-exit access or disclosure.
41. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Offboarding Policy | Defines overall employee exit requirements |
| Employee Termination Security Checklist | Controls security during employee termination |
| Contractor Offboarding Procedure | Controls contractor exit |
| Privileged User Offboarding Checklist | Controls privileged-user exits |
| Access Revocation Checklist | Controls removal of system access |
| Access Revocation Evidence Register | Records evidence of access removal |
| Asset Return Checklist | Controls recovery of organizational assets |
| Exit Security Acknowledgement | Records continuing security obligations |
| Confidentiality and NDA Policy | Defines confidentiality requirements |
| Employee NDA | Establishes employee confidentiality obligations |
| Contractor NDA | Establishes contractor confidentiality obligations |
| Supplier Confidentiality Agreement | Establishes supplier obligations |
| Information Classification Policy | Determines protection requirements |
| Information Retention Policy | Determines what must be retained |
| Secure Disposal Procedure | Controls secure information disposal |
| Incident Response Procedure | Handles suspected confidentiality incidents |
| Source Code Access Review | Reviews source-code access |
| Cloud Access Review | Reviews cloud access |
| Supplier Offboarding Checklist | Controls supplier relationship exit |
42. ISO 27001 / SOC 2 Connection
Offboarding confidentiality activities support:
- Access control
- Identity lifecycle management
- Information classification
- Confidentiality obligations
- Asset management
- Information transfer
- Supplier security
- Personnel security
- Cloud security
- Incident management
- Information retention and disposal
- Protection of customer information
For SOC 2, these activities can provide evidence supporting:
- Logical access removal
- User lifecycle management
- Confidentiality
- Protection of customer information
- Vendor/contractor management
- Access monitoring
- Security incident management
The exact controls and evidence should be determined according to the organization’s risk assessment, ISMS scope, contractual commitments, and Statement of Applicability.
43. Quick Audit Checklist
☐ Exit identified
☐ Confidentiality obligations reviewed
☐ NDA reviewed
☐ Information identified
☐ Information classification reviewed
☐ Access inventory completed
☐ Corporate access removed
☐ Cloud access removed
☐ Production access removed
☐ Privileged access removed
☐ Source-code access removed
☐ Customer access removed
☐ SaaS access removed
☐ Shared/delegated access removed
☐ Credentials reviewed
☐ Secrets rotated where required
☐ Company assets recovered
☐ Confidential documents recovered
☐ Personal-device data addressed
☐ Information returned/deleted
☐ Legal/retention requirements considered
☐ Exit confidentiality acknowledgement completed
☐ Security incident assessed
☐ Evidence retained
☐ Independent verification completed where required
☐ Offboarding closed
44. Document Control
| Field | Details |
|---|---|
| Document Name | Offboarding Confidentiality Checklist |
| Document Owner | |
| Security Owner | |
| Version | |
| Effective Date | |
| Review Frequency | |
| Classification | Internal |
| Approved By | |
| Next Review Date |
45. Final Audit Trail
For every significant departure, the organization should be able to demonstrate:
Who left or lost authorization?
What confidential information could they access?
What confidentiality obligations applied?
What systems and applications could they access?
When was access removed?
Were privileged and cloud credentials addressed?
Were shared credentials reviewed?
Were company assets recovered?
Were confidential documents returned or securely deleted?
Were personal-device copies addressed where applicable?
Did the individual acknowledge continuing confidentiality obligations?
Was any confidentiality incident identified?
Who independently verified the critical actions?
What evidence proves the offboarding was completed?
Final Principle
Confidentiality does not end when employment or a contract ends. Access must end, information must be recovered or appropriately disposed of, credentials must be addressed, and continuing confidentiality obligations must remain enforceable.
The complete offboarding cycle should be:
Identify → Assess → Revoke → Recover → Return/Delete → Protect → Acknowledge → Verify → Record → Close
