ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Offboarding Confidentiality Checklist

Offboarding Confidentiality Checklist

1. Purpose

The Offboarding Confidentiality Checklist provides a structured process for protecting confidential, sensitive, personal, customer, proprietary, and security information when an employee, contractor, consultant, supplier personnel, or other authorized individual leaves the organization or no longer requires access.

The objective is to ensure that:

  • Confidentiality obligations continue after access ends
  • Access to confidential information is removed
  • Company and customer information is returned or securely deleted
  • Information stored on personal or company devices is addressed
  • Confidential information is not retained without authorization
  • Credentials and secrets are protected
  • Intellectual property remains with the organization where applicable
  • Continuing confidentiality obligations are communicated
  • Evidence of the offboarding process is retained
  • Any confidentiality risks are identified and addressed

Core Principle

Identify → Protect → Revoke → Recover → Return/Delete → Verify → Acknowledge → Record → Close


2. When to Use

Use this checklist when:

  • An employee leaves
  • A contractor engagement ends
  • A consultant completes an assignment
  • A temporary worker leaves
  • Supplier personnel are replaced
  • A role changes and confidential access is no longer required
  • Privileged access is removed
  • A project ends
  • A customer engagement ends
  • An individual is terminated
  • Access is suspended because of a security concern

For high-risk or involuntary termination, the process should be coordinated with HR, Legal, Security, IT, and the relevant business owner as appropriate.


3. Offboarding Information

FieldDetails
Offboarding ID
Person Name
Employee/Contractor ID
Organization/Agency
Role
Department/Project
Manager/Business Owner
Information Owner
Employment/Contract End Date
Last Working Date
Effective Access Termination
Offboarding Type
Risk Level
Reviewer
Completion Date

4. Offboarding Type

☐ Employee resignation
☐ Employee termination
☐ Contractor completion
☐ Consultant completion
☐ Temporary worker completion
☐ Supplier personnel replacement
☐ Project completion
☐ Contract expiry
☐ Role change
☐ Access reduction
☐ Emergency access removal
☐ Other: ______________________


5. Confidentiality Obligations

Confirm the individual’s continuing confidentiality obligations.

☐ NDA identified
☐ NDA remains applicable after termination
☐ Employment/contract confidentiality clause reviewed
☐ Customer confidentiality obligations reviewed
☐ Intellectual-property obligations reviewed
☐ Personal-data confidentiality obligations reviewed
☐ Security-information confidentiality reviewed
☐ Post-termination obligations communicated
☐ Continuing confidentiality acknowledgement completed where required

Agreement Details

NDA/Agreement ID: ______________________

Effective Date: ______________________

Confidentiality Period: ______________________

Post-Termination Obligations: ______________________


6. Information Access Inventory

Identify all confidential information the individual could access.

☐ Customer information
☐ Personal data
☐ Financial information
☐ Source code
☐ Intellectual property
☐ Product information
☐ Business plans
☐ Pricing information
☐ Contracts
☐ Security architecture
☐ Vulnerability information
☐ Credentials/secrets
☐ Cloud configuration
☐ Employee information
☐ Legal information
☐ Other: ______________________

Information Inventory

InformationSystem/LocationClassificationOwnerAction

7. Access Revocation

Confidentiality protection requires removal of access, not simply a reminder about confidentiality.

☐ Corporate identity disabled
☐ Email disabled
☐ SSO access removed
☐ VPN access removed
☐ Cloud access removed
☐ AWS access removed
☐ Azure access removed
☐ GCP access removed
☐ Source-code access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Security-tool access removed
☐ Customer-system access removed
☐ File-sharing access removed
☐ Collaboration access removed
☐ Physical access removed

Access Evidence


8. Shared and Delegated Access

Review access that may not be directly associated with the individual’s primary account.

☐ Shared accounts reviewed
☐ Delegated mailbox access removed
☐ Shared drive access removed
☐ Shared application access reviewed
☐ Group memberships removed
☐ Distribution groups reviewed
☐ Service-account access reviewed
☐ API access reviewed
☐ Delegated administrative access removed

Any shared credentials that the individual knew should be assessed for rotation.


9. Credentials and Secrets

Determine whether the individual had access to credentials or secrets.

☐ Passwords reviewed
☐ API keys reviewed
☐ Tokens reviewed
☐ SSH keys reviewed
☐ Certificates reviewed
☐ Cloud credentials reviewed
☐ Database credentials reviewed
☐ CI/CD secrets reviewed
☐ Encryption-key access reviewed
☐ Shared administrative credentials reviewed

Where required:

☐ Credentials rotated
☐ Tokens revoked
☐ API keys revoked
☐ SSH keys removed
☐ Certificates replaced
☐ Shared secrets changed

Never record actual passwords, private keys, API secrets, or authentication values in the offboarding record.


10. Source Code and Intellectual Property

For developers, engineers, product personnel, or other IP-sensitive roles:

☐ Source repositories identified
☐ Repository access revoked
☐ Organization access revoked
☐ Branch permissions reviewed
☐ Deployment permissions removed
☐ Code-signing access reviewed
☐ CI/CD access removed
☐ Personal repository copies addressed
☐ Local source-code copies addressed
☐ Proprietary documentation recovered
☐ Intellectual-property obligations confirmed


11. Cloud Environment

Where cloud access existed:

☐ Cloud accounts identified
☐ IAM access removed
☐ IAM roles reviewed
☐ Group membership removed
☐ SSO assignment removed
☐ Production permissions removed
☐ Administrative permissions removed
☐ Cloud console access removed
☐ CLI/API access removed
☐ Access keys revoked
☐ Temporary credentials invalidated where appropriate
☐ Cloud activity reviewed where necessary


12. AWS SaaS Offboarding

For an AWS SaaS startup, review:

☐ AWS IAM/SSO identity disabled
☐ IAM roles reviewed
☐ IAM groups reviewed
☐ Access keys revoked
☐ Console access removed
☐ CLI access removed
☐ Production access removed
☐ S3 access reviewed
☐ Database access removed
☐ Secrets Manager access reviewed
☐ KMS/key access reviewed
☐ CloudWatch access removed
☐ CI/CD access removed
☐ Security-tool access removed

High-Risk Access

If the individual had administrative or production access:

☐ Privileged activity reviewed
☐ Security team notified where appropriate
☐ Credentials/secrets rotated
☐ Break-glass access reviewed
☐ Potential security impact assessed


13. Information Stored on Company Devices

Identify confidential information stored on company-owned devices.

☐ Laptop reviewed
☐ Desktop reviewed
☐ Mobile device reviewed
☐ Tablet reviewed
☐ Removable media reviewed
☐ Local documents reviewed
☐ Downloaded customer data reviewed
☐ Source-code copies reviewed
☐ Credentials/secrets reviewed
☐ Browser-stored credentials addressed
☐ Cloud synchronization reviewed

Before wiping a device, consider legal, regulatory, retention, and security-investigation requirements.


14. Information Stored on Personal Devices

If BYOD was permitted:

☐ Personal device identified
☐ Company data location identified
☐ Corporate applications removed
☐ Corporate accounts removed
☐ Company files removed where permitted/required
☐ Corporate synchronization disabled
☐ Company credentials removed
☐ Tokens revoked
☐ Company data deletion confirmed where appropriate
☐ Legal/investigation requirements considered

Do not access or delete personal information beyond what is authorized and legally permissible.


15. Cloud Storage and File Sharing

Review:

☐ Google Drive
☐ OneDrive
☐ SharePoint
☐ Dropbox
☐ Company file servers
☐ S3/cloud storage
☐ Confluence
☐ Notion
☐ Project repositories
☐ Collaboration platforms
☐ Other: ______________________

Confirm:

☐ Ownership transferred
☐ Access removed
☐ Shared links reviewed
☐ External sharing reviewed
☐ Personal copies addressed
☐ Confidential documents retained appropriately
☐ Unnecessary copies deleted where required


16. Email and Communication

Review:

☐ Corporate email disabled
☐ Email forwarding disabled
☐ Delegated access removed
☐ Mobile email access removed
☐ Email sessions revoked where appropriate
☐ Confidential attachments reviewed where necessary
☐ Shared mailbox access removed
☐ Distribution-list membership reviewed
☐ Auto-forwarding rules reviewed
☐ External forwarding reviewed


17. Collaboration Platforms

Review applicable platforms:

☐ Slack
☐ Microsoft Teams
☐ Zoom
☐ Jira
☐ Confluence
☐ GitHub/GitLab/Bitbucket
☐ CRM
☐ Project-management systems
☐ Security platforms
☐ Other: ______________________

☐ Account disabled
☐ Group memberships removed
☐ Administrative roles removed
☐ Shared access reviewed
☐ Confidential project access removed


18. Customer Information

If the individual handled customer information:

☐ Customer systems identified
☐ Customer access removed
☐ Customer data access reviewed
☐ Local customer-data copies addressed
☐ Customer documents recovered
☐ Customer confidentiality obligations confirmed
☐ Customer notification considered where required
☐ Security incident assessment completed if necessary


19. Personal Data

If the individual handled personal data:

☐ Personal-data access removed
☐ Local copies addressed
☐ Downloads addressed
☐ Personal-device copies addressed where applicable
☐ Data-retention requirements considered
☐ Data-deletion requirements completed
☐ Privacy incident assessment completed where necessary


20. Confidential Documents

Recover or appropriately address:

☐ Printed documents
☐ Contracts
☐ Customer reports
☐ Security reports
☐ Architecture documents
☐ Source-code documentation
☐ Product documents
☐ Financial documents
☐ Strategy documents
☐ Security assessments
☐ Vulnerability reports
☐ Incident records
☐ Other: ______________________


21. Removable Media

Review:

☐ USB drives
☐ External hard drives
☐ Memory cards
☐ Backup media
☐ Security keys
☐ Other removable media

For each:

☐ Returned
☐ Data transferred
☐ Data securely deleted where appropriate
☐ Device securely wiped
☐ Asset register updated
☐ Investigation/retention requirements considered


22. Physical Confidentiality

Where applicable:

☐ Access card returned
☐ Building access removed
☐ Office keys returned
☐ Data-center access removed
☐ Secure-area access removed
☐ Visitor privileges removed
☐ Physical documents recovered
☐ Storage locations reviewed


23. Intellectual Property

Confirm that organizational intellectual property remains protected.

☐ Source code retained by organization
☐ Documentation transferred
☐ Design files transferred
☐ Product information transferred
☐ Customer deliverables transferred
☐ Credentials transferred securely where appropriate
☐ Work product ownership confirmed
☐ Personal copies addressed
☐ IP/confidentiality obligations confirmed


24. Knowledge Transfer

Where appropriate:

☐ Business information transferred
☐ Project documentation transferred
☐ System knowledge transferred
☐ Customer knowledge transferred
☐ Supplier knowledge transferred
☐ Operational procedures transferred
☐ Security information transferred
☐ Critical dependencies documented
☐ Outstanding tasks transferred

Knowledge transfer should not result in unnecessary duplication or uncontrolled copying of confidential information.


25. High-Risk Offboarding

Perform enhanced review when the individual had:

☐ Privileged access
☐ Production access
☐ Customer-data access
☐ Security administration access
☐ Source-code access
☐ Cloud administrator access
☐ Database administrator access
☐ Encryption-key access
☐ Incident-response access
☐ Financial-system access
☐ High-value intellectual property access

Enhanced Actions

☐ Immediate access revocation
☐ Security team involvement
☐ Privileged activity review
☐ Credential rotation
☐ Data-access review
☐ Customer impact assessment
☐ Legal review where appropriate
☐ Incident assessment where appropriate


26. Involuntary Termination

For involuntary or high-risk termination:

☐ Termination risk assessed
☐ HR/Legal involved as appropriate
☐ Security involved as appropriate
☐ Access termination timing coordinated
☐ Immediate access revocation considered
☐ Active sessions terminated
☐ Privileged credentials reviewed
☐ Shared credentials rotated
☐ Physical access removed
☐ Corporate devices secured
☐ Evidence preservation considered
☐ Investigation requirements assessed

The process should be handled discreetly and proportionately.


27. Contractor/Supplier Personnel

Where the departing individual belongs to an external organization:

☐ Supplier notified
☐ Contractor identity confirmed
☐ Access list reviewed
☐ Corporate access removed
☐ Customer access removed
☐ Cloud access removed
☐ Source-code access removed
☐ Supplier-managed accounts addressed
☐ Confidentiality obligations confirmed
☐ Replacement personnel reviewed
☐ Supplier confirmation obtained where required


28. Exit Confidentiality Acknowledgement

The individual should acknowledge, where appropriate:

☐ Confidentiality obligations continue
☐ Company information must not be retained without authorization
☐ Customer information must not be retained
☐ Personal data must not be retained
☐ Source code must not be retained
☐ Credentials must not be retained or reused
☐ Company property must be returned
☐ Unauthorized access after termination is prohibited
☐ Security incidents must continue to be reported
☐ Legal/contractual obligations continue after exit

Acknowledgement

Name: ______________________

Date: ______________________

Signature/Confirmation: ______________________


29. Information Return and Deletion

Determine what must be returned or deleted.

InformationLocationActionCompletedEvidence
Return/Delete

Possible actions:

☐ Return to organization
☐ Transfer to authorized owner
☐ Secure deletion
☐ Secure disposal
☐ Retain under approved retention requirement
☐ Legal hold
☐ Investigation hold

Do not delete information that must be preserved for legal, regulatory, contractual, or security-investigation reasons.


30. Confidentiality Risk Assessment

Assess whether offboarding creates additional confidentiality risk.

RiskLikelihoodImpactRisk LevelTreatmentOwner

Consider:

  • Knowledge of confidential information
  • Knowledge of credentials
  • Knowledge of security architecture
  • Customer-data exposure
  • Source-code exposure
  • Privileged access
  • Remaining copies
  • Personal-device storage
  • Third-party systems
  • Potential unauthorized disclosure

31. Post-Offboarding Monitoring

For higher-risk departures:

☐ Authentication activity reviewed
☐ Failed login attempts reviewed
☐ Cloud activity reviewed
☐ Source-code activity reviewed
☐ VPN activity reviewed
☐ Customer-system activity reviewed
☐ Data-transfer activity reviewed
☐ Security alerts reviewed

Monitoring should be proportionate to risk and applicable legal requirements.


32. Confidentiality Incident Check

Determine whether any confidentiality issue occurred during or immediately before offboarding.

☐ No issue identified
☐ Unauthorized disclosure
☐ Data copied
☐ Data transferred externally
☐ Lost device
☐ Unauthorized access
☐ Suspicious download
☐ Credential exposure
☐ Confidential information retained
☐ Other

If an issue is identified:

☐ Incident reported
☐ Incident assessed
☐ Evidence preserved
☐ Access reviewed
☐ Risk assessed
☐ Corrective action initiated


33. Exceptions

Document any incomplete or exceptional requirements.

RequirementExceptionReasonRiskCompensating ControlApproverExpiry

Exceptions should not become permanent undocumented practices.


34. Final Verification

Before closing the offboarding:

☐ All known access removed
☐ Active sessions addressed
☐ Privileged access removed
☐ Cloud access removed
☐ Source-code access removed
☐ Customer access removed
☐ SaaS access removed
☐ Shared/delegated access removed
☐ Credentials reviewed/rotated
☐ Company assets recovered
☐ Confidential information returned/deleted/addressed
☐ Personal-device information addressed where applicable
☐ Confidentiality obligations confirmed
☐ Exit acknowledgement completed
☐ Incidents assessed
☐ Evidence collected
☐ Exceptions documented
☐ Asset records updated
☐ Access-revocation evidence recorded


35. Independent Verification

Where appropriate, a second person should verify critical offboarding activities.

Primary Operator

Name: ______________________

Date: ______________________

Independent Reviewer

Name: ______________________

Date: ______________________

Verification Result

☐ Complete
☐ Complete with Exceptions
☐ Further Action Required


36. Offboarding Evidence Register

Evidence IDActivitySystemEvidence TypeDateReviewerLocation

Evidence may include:

  • Access-revocation screenshots
  • IAM records
  • Account-disabled confirmation
  • Credential-rotation evidence
  • Asset-return record
  • Data-deletion confirmation
  • Supplier confirmation
  • Exit acknowledgement
  • Security review record

Evidence should not contain actual credentials or secrets.


37. Offboarding Closure

Final Result

☐ Completed
☐ Completed with Exceptions
☐ Further Action Required
☐ Security Investigation Required
☐ Legal Review Required

Outstanding Actions

Closure Approval

Business Owner: ______________________

Security Reviewer: ______________________

HR/Supplier Owner: ______________________

Closure Date: ______________________


38. Startup-Friendly Offboarding Model

A startup can maintain strong confidentiality controls without creating excessive administrative work.

Standard Exit

Use:

  1. Confirm exit
  2. Identify confidential information
  3. Revoke access
  4. Recover assets
  5. Transfer business information
  6. Return/delete information
  7. Confirm continuing confidentiality
  8. Verify
  9. Record evidence

High-Risk Exit

Add:

  • Immediate access revocation
  • Privileged-access review
  • Credential rotation
  • Cloud activity review
  • Source-code review
  • Customer-data review
  • Security investigation assessment
  • Legal/HR coordination
  • Enhanced post-exit monitoring

39. AWS SaaS Startup Example

Scenario

A DevOps engineer leaves an AWS SaaS startup.

The engineer had access to:

  • AWS production
  • GitHub
  • CI/CD
  • Production database
  • S3 customer-data storage
  • CloudWatch
  • Secrets Manager
  • Jira
  • Slack

Offboarding

Immediate Actions

☐ Disable corporate identity
☐ Remove AWS access
☐ Revoke access keys
☐ Remove GitHub access
☐ Disable CI/CD access
☐ Remove database access
☐ Remove S3 access
☐ Remove Secrets Manager access
☐ Remove Jira/Slack access

Confidentiality Actions

☐ Review source-code copies
☐ Review customer-data access
☐ Address local confidential files
☐ Confirm NDA continues
☐ Recover company laptop
☐ Review credentials/secrets
☐ Rotate shared credentials where necessary

Verification

Revoke → Rotate → Recover → Return/Delete → Verify → Record


40. Common Mistakes

Avoid:

  • Treating an exit interview as confidentiality offboarding.
  • Assuming disabling the email account removes all access.
  • Forgetting cloud accounts.
  • Forgetting GitHub/GitLab access.
  • Forgetting API keys and tokens.
  • Forgetting shared credentials.
  • Forgetting delegated access.
  • Forgetting customer environments.
  • Forgetting personal devices.
  • Wiping devices before checking legal/investigation requirements.
  • Failing to confirm continuing confidentiality.
  • Failing to recover confidential documents.
  • Failing to review source-code copies.
  • Failing to document evidence.
  • Failing to coordinate supplier/contractor exits.
  • Assuming an NDA alone prevents post-exit access or disclosure.

41. Relationship With Other ISMS Documents

DocumentRelationship
Employee Offboarding PolicyDefines overall employee exit requirements
Employee Termination Security ChecklistControls security during employee termination
Contractor Offboarding ProcedureControls contractor exit
Privileged User Offboarding ChecklistControls privileged-user exits
Access Revocation ChecklistControls removal of system access
Access Revocation Evidence RegisterRecords evidence of access removal
Asset Return ChecklistControls recovery of organizational assets
Exit Security AcknowledgementRecords continuing security obligations
Confidentiality and NDA PolicyDefines confidentiality requirements
Employee NDAEstablishes employee confidentiality obligations
Contractor NDAEstablishes contractor confidentiality obligations
Supplier Confidentiality AgreementEstablishes supplier obligations
Information Classification PolicyDetermines protection requirements
Information Retention PolicyDetermines what must be retained
Secure Disposal ProcedureControls secure information disposal
Incident Response ProcedureHandles suspected confidentiality incidents
Source Code Access ReviewReviews source-code access
Cloud Access ReviewReviews cloud access
Supplier Offboarding ChecklistControls supplier relationship exit

42. ISO 27001 / SOC 2 Connection

Offboarding confidentiality activities support:

  • Access control
  • Identity lifecycle management
  • Information classification
  • Confidentiality obligations
  • Asset management
  • Information transfer
  • Supplier security
  • Personnel security
  • Cloud security
  • Incident management
  • Information retention and disposal
  • Protection of customer information

For SOC 2, these activities can provide evidence supporting:

  • Logical access removal
  • User lifecycle management
  • Confidentiality
  • Protection of customer information
  • Vendor/contractor management
  • Access monitoring
  • Security incident management

The exact controls and evidence should be determined according to the organization’s risk assessment, ISMS scope, contractual commitments, and Statement of Applicability.


43. Quick Audit Checklist

☐ Exit identified
☐ Confidentiality obligations reviewed
☐ NDA reviewed
☐ Information identified
☐ Information classification reviewed
☐ Access inventory completed
☐ Corporate access removed
☐ Cloud access removed
☐ Production access removed
☐ Privileged access removed
☐ Source-code access removed
☐ Customer access removed
☐ SaaS access removed
☐ Shared/delegated access removed
☐ Credentials reviewed
☐ Secrets rotated where required
☐ Company assets recovered
☐ Confidential documents recovered
☐ Personal-device data addressed
☐ Information returned/deleted
☐ Legal/retention requirements considered
☐ Exit confidentiality acknowledgement completed
☐ Security incident assessed
☐ Evidence retained
☐ Independent verification completed where required
☐ Offboarding closed


44. Document Control

FieldDetails
Document NameOffboarding Confidentiality Checklist
Document Owner
Security Owner
Version
Effective Date
Review Frequency
ClassificationInternal
Approved By
Next Review Date

45. Final Audit Trail

For every significant departure, the organization should be able to demonstrate:

Who left or lost authorization?
What confidential information could they access?
What confidentiality obligations applied?
What systems and applications could they access?
When was access removed?
Were privileged and cloud credentials addressed?
Were shared credentials reviewed?
Were company assets recovered?
Were confidential documents returned or securely deleted?
Were personal-device copies addressed where applicable?
Did the individual acknowledge continuing confidentiality obligations?
Was any confidentiality incident identified?
Who independently verified the critical actions?
What evidence proves the offboarding was completed?

Final Principle

Confidentiality does not end when employment or a contract ends. Access must end, information must be recovered or appropriately disposed of, credentials must be addressed, and continuing confidentiality obligations must remain enforceable.

The complete offboarding cycle should be:

Identify → Assess → Revoke → Recover → Return/Delete → Protect → Acknowledge → Verify → Record → Close