1. Purpose
The Contractor Offboarding Procedure defines the process for securely ending a contractor, consultant, freelancer, temporary worker, or external individual’s access to organizational systems, information, facilities, and services when their engagement ends or their access is no longer required.
The procedure is intended to ensure that:
- Contractor access is removed in a timely manner
- Organizational information is protected
- Privileged and production access is revoked
- Company assets are recovered
- Credentials, keys, and tokens are addressed
- Customer and supplier access is removed
- Confidential information is returned or securely deleted where required
- Business information and responsibilities are transferred
- Security incidents or investigation requirements are considered
- Offboarding activities are documented and verified
Core Principle
Notify → Identify → Assess → Revoke → Recover → Protect → Transfer → Verify → Record → Close
2. Scope
This procedure applies to:
- Contractors
- Consultants
- Freelancers
- Temporary workers
- Contract developers
- Contract administrators
- External IT personnel
- Managed service personnel
- Security consultants
- Project-based resources
- Agency personnel
- Other non-employees with organizational access
It applies to contractors working:
- On-site
- Remotely
- Through a staffing agency
- Through a supplier
- From customer locations
- Through third-party platforms
3. When the Procedure Applies
The procedure shall be initiated when:
☐ Contract expires
☐ Project is completed
☐ Contractor resigns
☐ Contractor engagement is terminated
☐ Contractor changes role
☐ Contractor no longer requires access
☐ Supplier engagement ends
☐ Security concern arises
☐ Contractor access must be revoked immediately
☐ Other: __________________________
The procedure may also be initiated when a contractor’s access requirements materially change.
4. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Business Owner | Confirms engagement end and business requirements |
| Contractor Manager | Coordinates contractor offboarding |
| HR/People Team | Maintains contractor records where applicable |
| IT/IAM | Removes identity and system access |
| Security Team | Reviews security risks and privileged access |
| System Owner | Confirms application/system access removal |
| Cloud Owner | Removes cloud access |
| Asset Owner | Recovers organizational assets |
| Procurement/Supplier Owner | Coordinates external supplier requirements |
| Legal | Advises on contractual/legal requirements where necessary |
| Contractor | Returns assets and organizational information |
| Independent Reviewer | Verifies critical access removal where required |
Responsibilities may be combined in a small organization, provided appropriate review and verification are maintained.
5. Contractor Offboarding Information
| Field | Details |
|---|---|
| Offboarding ID | |
| Contractor Name | |
| Contractor ID | |
| Supplier/Agency | |
| Role | |
| Business Owner | |
| Manager | |
| Contract Start Date | |
| Contract End Date | |
| Actual End Date | |
| Offboarding Reason | |
| Risk Level | ☐ Low ☐ Medium ☐ High ☐ Critical |
| Privileged Access | ☐ Yes ☐ No |
| Production Access | ☐ Yes ☐ No |
| Customer Data Access | ☐ Yes ☐ No |
| Personal Data Access | ☐ Yes ☐ No |
| Security Reviewer | |
| Completion Date |
6. Offboarding Notification
The business owner or authorized person shall notify relevant teams when the contractor engagement is ending.
Notify, as applicable:
☐ Contractor manager
☐ HR/People team
☐ IT/IAM
☐ Security
☐ Cloud/platform owner
☐ Application owners
☐ System owners
☐ Procurement
☐ Supplier/agency
☐ Facilities/security
☐ Finance
☐ Legal
☐ Customer owner
Notification Information
The notification should include:
- Contractor name
- Supplier/agency
- Effective termination date
- Effective termination time where applicable
- Reason where appropriate
- Required access-revocation timing
- Asset-return requirements
- Business continuity requirements
- Any special security instructions
7. Determine Offboarding Risk
Before access removal, assess whether the contractor presents elevated offboarding risk.
Consider:
☐ Privileged access
☐ Production access
☐ Customer environment access
☐ Personal-data access
☐ Confidential/restricted information
☐ Source-code access
☐ Cloud administration
☐ Database administration
☐ Security-system access
☐ Physical facility access
☐ Knowledge of shared credentials
☐ Access to encryption keys
☐ Access to API keys/secrets
☐ Security incident involvement
☐ Dispute/termination concern
☐ Remote/BYOD access
Risk Level
☐ Low
☐ Medium
☐ High
☐ Critical
High-risk contractor offboarding should receive priority and additional verification.
8. Access Inventory
Identify all access provided to the contractor.
Review:
☐ Corporate identity
☐ Email
☐ SSO
☐ MFA
☐ VPN
☐ Wi-Fi
☐ Cloud platforms
☐ AWS
☐ Azure
☐ Google Cloud
☐ Production systems
☐ Development systems
☐ Test systems
☐ Databases
☐ Source code
☐ GitHub/GitLab/Bitbucket
☐ CI/CD
☐ SaaS applications
☐ Security tools
☐ Monitoring systems
☐ Ticketing systems
☐ Customer environments
☐ Supplier environments
☐ Physical access
☐ API credentials
☐ SSH keys
☐ Service accounts
☐ Shared accounts
Access Inventory
| System | Access | Privilege | Owner | Action | Verified |
|---|---|---|---|---|---|
9. Access Revocation
At the approved effective time:
☐ Corporate account disabled
☐ SSO access removed
☐ MFA methods revoked
☐ VPN access removed
☐ Cloud access removed
☐ Application access removed
☐ Production access removed
☐ Database access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ SaaS access removed
☐ Security-tool access removed
☐ Customer-system access removed
☐ Supplier-system access removed
☐ Physical access removed
Access should be removed according to the risk and timing requirements defined by the organization.
10. Cloud and AWS Access
If the contractor has cloud access:
AWS
☐ IAM Identity Center access removed
☐ IAM roles removed
☐ IAM groups removed
☐ Access keys disabled/revoked
☐ Temporary credentials expired
☐ Cross-account access reviewed
☐ Production account access removed
☐ Administrative roles removed
☐ MFA/authentication methods addressed
☐ CloudTrail activity reviewed where required
Other Cloud Platforms
☐ Azure access removed
☐ GCP access removed
☐ Subscription/project roles removed
☐ Administrative access removed
☐ Service-account relationships reviewed
☐ API credentials revoked
11. Privileged Access
If the contractor had elevated access:
☐ Privileged accounts identified
☐ Administrative roles removed
☐ Production privileges removed
☐ Database administrator access removed
☐ Cloud administrator access removed
☐ Security administrator access removed
☐ Network administrator access removed
☐ Source-code administrator access removed
☐ CI/CD administrator access removed
☐ Break-glass access reviewed
☐ Shared administrator credentials assessed
☐ Credentials rotated where required
☐ Independent verification completed
For high-risk privileged contractors, follow the organization’s Privileged User Offboarding Checklist.
12. Source Code and Development Access
Review:
☐ GitHub
☐ GitLab
☐ Bitbucket
☐ Azure DevOps
☐ Repository access
☐ Organization administration
☐ Branch protection
☐ CI/CD
☐ Package registries
☐ Container registries
Verify:
☐ User removed
☐ Repository permissions removed
☐ Organization roles removed
☐ SSH keys revoked
☐ Personal access tokens revoked
☐ OAuth authorizations revoked
☐ Deployment access removed
☐ Code ownership updated
☐ Secrets reviewed
13. Production Access
If the contractor accessed production:
☐ Production account disabled
☐ Production VPN access removed
☐ Bastion access removed
☐ Kubernetes access removed
☐ Production server access removed
☐ Production database access removed
☐ Production deployment access removed
☐ Monitoring access removed
☐ Administrative console access removed
☐ Emergency access reviewed
For sensitive environments, recent privileged activity may be reviewed before closure.
14. Customer and Client Access
Determine whether the contractor accessed customer environments.
☐ Customer cloud environment
☐ Customer application
☐ Customer database
☐ Customer support platform
☐ Customer source code
☐ Customer documents
☐ Customer credentials
☐ Customer communication systems
Actions:
☐ Access revoked
☐ Customer owner notified where required
☐ Customer credentials rotated where necessary
☐ Customer information returned/deleted where required
☐ Evidence retained where required
15. Information Protection
Identify organizational information held by the contractor.
Examples include:
- Source code
- Architecture documentation
- Customer information
- Personal data
- Credentials
- Security reports
- Vulnerability information
- Business documents
- Contracts
- Financial information
- Internal procedures
- Confidential communications
Verify:
☐ Information identified
☐ Business information transferred
☐ Organizational copies recovered
☐ Unauthorized copies addressed
☐ Information returned where required
☐ Information securely deleted where required
☐ Deletion confirmation obtained where appropriate
16. Contractor-Owned Devices
If the contractor used their own device:
☐ BYOD arrangement identified
☐ Organizational information identified
☐ Organizational accounts removed
☐ Sessions terminated
☐ Tokens revoked
☐ Certificates addressed
☐ Local organizational data addressed
☐ Approved deletion process followed
☐ Evidence obtained where required
The organization should not unnecessarily access or delete unrelated personal information on contractor-owned devices.
17. Company-Owned Assets
Recover organizational assets provided to the contractor.
Examples:
☐ Laptop
☐ Desktop
☐ Mobile phone
☐ Tablet
☐ Monitor
☐ Security key
☐ Access card
☐ ID card
☐ Tokens
☐ Removable media
☐ Network equipment
☐ Development equipment
☐ Other: ______________________
Record:
| Asset ID | Asset | Condition | Returned | Verified |
|---|---|---|---|---|
Use the organization’s Asset Return Checklist where applicable.
18. Credentials and Secrets
Determine whether the contractor had access to:
☐ Passwords
☐ API keys
☐ Cloud access keys
☐ SSH keys
☐ Database credentials
☐ Service-account credentials
☐ CI/CD secrets
☐ Certificates
☐ Encryption keys
☐ Signing keys
☐ Shared administrator passwords
Actions:
☐ Credentials revoked
☐ Tokens invalidated
☐ Keys revoked
☐ Shared credentials rotated where required
☐ Secret ownership transferred
☐ Vault access removed
Do not rely only on removing the contractor’s personal account when a shared credential was known to the contractor.
19. Service Accounts and Technical Ownership
If the contractor created or managed service accounts:
☐ Service accounts identified
☐ Business owner identified
☐ Technical owner identified
☐ Ownership transferred
☐ Personal dependencies removed
☐ Credentials reviewed
☐ Unnecessary accounts disabled
☐ Secrets rotated where required
☐ Documentation updated
Service accounts should not be disabled without confirming whether operational services depend on them.
20. Physical Access
Where applicable:
☐ Building access removed
☐ Office access removed
☐ Data-center access removed
☐ Server-room access removed
☐ Restricted-area access removed
☐ Access card recovered
☐ Keys recovered
☐ Visitor privileges removed
☐ Biometric access removed
21. Supplier or Agency Coordination
If the contractor is supplied through another organization:
☐ Supplier notified
☐ Supplier confirmed end date
☐ Supplier access confirmed removed
☐ Supplier assets addressed
☐ Supplier credentials addressed
☐ Customer access addressed
☐ Confidential information obligations reinforced
☐ Supplier confirmation obtained where appropriate
Supplier
Name: __________________________
Contact: ________________________
Confirmation Date: ______________
22. Confidentiality and Contractual Obligations
Before closure, verify applicable contractual requirements.
☐ NDA/confidentiality agreement
☐ IP ownership obligations
☐ Data protection requirements
☐ Information-return requirements
☐ Information-deletion requirements
☐ Non-disclosure obligations
☐ Customer confidentiality requirements
☐ Intellectual-property obligations
☐ Continuing confidentiality obligations
Contractual obligations that survive the end of the engagement should be communicated to the contractor where appropriate.
23. Business and Knowledge Transfer
Identify information necessary for business continuity.
☐ Current projects
☐ Technical documentation
☐ Architecture documentation
☐ Operational procedures
☐ Customer information
☐ Supplier information
☐ Security information
☐ Open tickets
☐ Open vulnerabilities
☐ Pending changes
☐ Deployment information
☐ Recovery information
☐ Key contacts
Knowledge Transfer Owner
Name: __________________________
Date: __________________________
24. Security Investigation Check
Before deleting or destroying accounts, devices, logs, or information, determine whether the contractor is associated with:
☐ Security incident
☐ Data breach
☐ Suspicious activity
☐ Policy violation
☐ Insider-risk concern
☐ Legal dispute
☐ Regulatory investigation
☐ Customer investigation
☐ Litigation hold
If applicable:
☐ Evidence preservation initiated
☐ Relevant logs preserved
☐ Account activity preserved
☐ Device preservation considered
☐ Security/Legal/HR consulted
☐ Investigation owner assigned
Important
Offboarding should not unintentionally destroy evidence required for an investigation, legal matter, or regulatory obligation.
25. Final Verification
A responsible reviewer should verify that required access has actually been removed.
Verify:
☐ Corporate identity
☐ Email
☐ SSO
☐ MFA
☐ VPN
☐ AWS/cloud
☐ Production
☐ Database
☐ Source code
☐ CI/CD
☐ SaaS
☐ Security systems
☐ Customer environments
☐ Supplier environments
☐ Physical access
☐ API keys/tokens
☐ SSH keys
☐ Shared credentials
☐ Service accounts
Verification
Reviewed By: __________________________
Date: _________________________________
Result: ☐ Complete ☐ Exception
26. Exceptions
Any access or activity that cannot be completed immediately shall be documented.
| Exception | Reason | Risk | Temporary Control | Owner | Due Date |
|---|---|---|---|---|---|
Exceptions should have:
- A defined owner
- A documented risk
- A temporary control where appropriate
- A target completion date
27. Evidence Retention
Retain appropriate evidence such as:
☐ Offboarding notification
☐ Contractor record
☐ Access inventory
☐ Access-revocation evidence
☐ Cloud access-removal evidence
☐ Privileged-access evidence
☐ Asset-return evidence
☐ Credential-rotation evidence
☐ Supplier confirmation
☐ Information-return/deletion confirmation
☐ Investigation records where applicable
☐ Final verification
☐ Exception approval
☐ Completion record
Do not retain passwords, private keys, API secrets, recovery codes, or other authentication secrets as evidence.
28. Contractor Offboarding Register
| Offboarding ID | Contractor | Supplier | End Date | Access Removed | Assets Returned | Reviewer | Status |
|---|---|---|---|---|---|---|---|
Status
☐ Open
☐ In Progress
☐ Verification Pending
☐ Exception
☐ Completed
☐ Closed
29. Completion Criteria
Contractor offboarding is complete when:
☐ Engagement end confirmed
☐ Access inventory completed
☐ Required access revoked
☐ Privileged access removed
☐ Cloud access removed
☐ Production access removed
☐ Source-code access removed
☐ Customer access removed
☐ Supplier access addressed
☐ Credentials/tokens/keys addressed
☐ Shared credentials assessed
☐ Service accounts reviewed
☐ Assets recovered or accounted for
☐ Organizational information transferred
☐ Information return/deletion completed where required
☐ Physical access removed
☐ Confidentiality obligations addressed
☐ Investigation requirements considered
☐ Independent verification completed where required
☐ Exceptions documented
☐ Evidence retained
☐ Offboarding register updated
☐ Final approval completed
30. Final Approval
Contractor: ______________________________
Supplier/Agency: ______________________________
Business Owner: ______________________________
Offboarding Effective Date: ______________________________
Completed By: ______________________________
Security Reviewer: ______________________________
Final Status: ☐ Completed ☐ Completed with Exception
Completion Date: ______________________________
Comments
31. AWS SaaS Startup Example
A SaaS startup uses a contract DevOps engineer for a six-month project.
The contractor has:
- AWS access
- Production Kubernetes access
- GitHub repository access
- CI/CD access
- Production database access
- VPN access
- Monitoring access
- Access to deployment secrets
The contract ends on 31 December at 6:00 PM.
Before 6:00 PM
The business owner confirms the contract end and informs:
- IT/IAM
- Security
- Engineering manager
- Cloud owner
- Relevant system owners
The team prepares the access inventory and identifies:
- AWS accounts and roles
- GitHub permissions
- Kubernetes permissions
- Database access
- CI/CD permissions
- VPN access
- Secrets known to the contractor
At 6:00 PM
The organization:
- Disables the contractor’s corporate identity.
- Removes AWS roles and permissions.
- Revokes cloud credentials.
- Removes GitHub access.
- Revokes SSH keys and tokens.
- Removes Kubernetes privileges.
- Removes production database access.
- Removes CI/CD access.
- Removes VPN access.
- Revokes SaaS/security-tool access.
- Rotates shared production credentials where required.
After Access Removal
The organization:
- Recovers company assets.
- Transfers project documentation.
- Confirms service-account ownership.
- Checks whether investigation/evidence preservation is required.
- Performs independent verification.
- Obtains supplier confirmation if applicable.
- Updates the contractor register.
- Closes the offboarding record.
Audit Trail
Contract End → Risk Assessment → Access Inventory → Access Revocation → Credential/Secret Review → Asset Recovery → Information Transfer → Verification → Evidence → Closure
32. Startup-Friendly Contractor Offboarding Model
A startup can implement the process using eight practical steps:
1. Notify
Confirm exactly when the contractor’s access must end.
2. Identify
Determine what systems, information, assets, and facilities the contractor can access.
3. Revoke
Remove access at the required time.
4. Recover
Recover company-owned assets and organizational information.
5. Protect
Rotate credentials, secrets, tokens, and keys where necessary.
6. Transfer
Transfer business knowledge, documentation, responsibilities, and system ownership.
7. Verify
Have another responsible person verify critical access removal.
8. Close
Record evidence, exceptions, approvals, and completion.
33. Common Mistakes
Avoid:
- Treating contractors differently from employees when they have similar security access.
- Removing only email access.
- Forgetting AWS or other cloud access.
- Forgetting GitHub/GitLab access.
- Forgetting VPN access.
- Forgetting customer environments.
- Forgetting production databases.
- Forgetting API keys and SSH keys.
- Forgetting shared passwords.
- Forgetting service-account ownership.
- Failing to recover company equipment.
- Ignoring BYOD requirements.
- Deleting accounts before checking investigation requirements.
- Failing to obtain supplier confirmation.
- Allowing exceptions without an owner and due date.
- Assuming asset recovery means access revocation is complete.
34. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Offboarding Policy | Defines broader personnel exit requirements |
| Employee Termination Security Checklist | Covers employee termination security |
| Access Revocation Checklist | Provides detailed access-removal controls |
| Privileged User Offboarding Checklist | Handles privileged contractor access |
| Asset Return Checklist | Handles company asset recovery |
| Supplier Offboarding Checklist | Handles supplier-level termination |
| Contractor Screening Procedure | Addresses contractor onboarding screening |
| Contractor Security Agreement | Defines contractor security obligations |
| Access Management Procedure | Defines access lifecycle |
| Joiner-Mover-Leaver Procedure | Manages identity lifecycle |
| Incident Response Procedure | Handles security-related offboarding incidents |
| Evidence Preservation Procedure | Protects relevant investigation evidence |
| Asset Register | Records company assets |
| Access Register | Records user access |
| Supplier Register | Records external suppliers |
35. ISO 27001 / SOC 2 Connection
Contractor offboarding supports the organization’s controls for:
- Removal or adjustment of access
- Identity and access management
- Privileged access
- Personnel security
- Information protection
- Asset management
- Supplier relationships
- Confidentiality
- Incident management
- Business continuity
For ISO 27001, the exact applicable controls should be determined through the organization’s risk assessment and Statement of Applicability.
For SOC 2, contractor offboarding can provide evidence that access is removed when no longer required and that changes to access are controlled and reviewed.
The procedure should operate together with the organization’s access-control, personnel-security, supplier-management, asset-management, and incident-management processes.
36. Quick Audit Checklist
☐ Contractor engagement end documented
☐ Effective date/time confirmed
☐ Business owner identified
☐ Supplier/agency identified
☐ Risk assessed
☐ Access inventory completed
☐ Corporate access removed
☐ MFA addressed
☐ VPN removed
☐ Cloud access removed
☐ AWS access removed
☐ Production access removed
☐ Database access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ SaaS access removed
☐ Customer access removed
☐ Supplier access addressed
☐ Privileged access removed
☐ API keys/tokens revoked
☐ SSH keys addressed
☐ Shared credentials assessed
☐ Secrets rotated where required
☐ Service accounts reviewed
☐ Assets recovered
☐ Information transferred
☐ Information returned/deleted where required
☐ Physical access removed
☐ Confidentiality obligations addressed
☐ Investigation requirements considered
☐ Supplier confirmation obtained where applicable
☐ Independent verification completed
☐ Exceptions documented
☐ Evidence retained
☐ Register updated
☐ Final approval completed
37. Final Audit Trail
For every significant contractor relationship, the organization should be able to demonstrate:
When did the contractor’s engagement end?
Who authorized the offboarding?
What systems and information could the contractor access?
Was the access inventory complete?
Was cloud and production access removed?
Were privileged accounts addressed?
Were credentials, tokens, keys, and shared secrets reviewed?
Were organizational assets recovered?
Was organizational information returned, transferred, or deleted as required?
Were customer and supplier environments addressed?
Were investigation and evidence-preservation requirements considered?
Who verified access removal?
Were exceptions documented and controlled?
What evidence proves the contractor was successfully offboarded?
Final Principle
Contractor offboarding is not simply the end of a contract. It is the controlled termination of the contractor’s digital, physical, informational, and operational relationship with the organization while preserving business continuity and security evidence.
