The Offboarding Checklist Most Businesses Get Wrong
Someone resigns on a Tuesday. HR updates the record, the manager arranges a handover, the laptop comes back, and the building pass goes in a drawer. Six weeks later nobody can say for certain whether that person can still open the shared drive, the CRM, the booking system or the account they set up for a project in 2023.
This is one of the most common gaps in small and mid sized businesses, and it has very little to do with technology. It is a list problem.
Why the list is always incomplete
Most offboarding checklists were written when the business ran on three systems. They cover the obvious things, equipment, email, payroll, and they were accurate at the time.
Then the business grew. Marketing signed up for a scheduling tool. Operations added an inventory app. Somebody started a shared folder for the annual audit. Each of those was a sensible decision taken quickly, and none of them made it back onto the checklist, because nobody owned the checklist.
The result is predictable. Access accumulates and never gets cleaned up, and the people who could tell you about the forgotten accounts are the ones who just left.
Start by finding out what you actually have
Before you rewrite anything, spend an hour building a list of every system the business pays for or depends on. Three sources will get you most of the way there.
- The card statement. Twelve months of subscriptions tells you more than any internal survey.
- Your password manager or browser saved logins. Uncomfortable reading, but useful.
- Ask each team what they open in a normal week. People name tools they never think of as systems.
Expect surprises. Most businesses find at least a few accounts nobody remembers creating, and at least one tool that is still being paid for and no longer used.
The parts a good checklist covers
Once you know what exists, the checklist itself is straightforward. It needs to cover five categories, and each line needs a named owner and a deadline.
- Identity. Email, single sign on, VPN, anything that is the front door to everything else. This one is same day.
- Applications. Every system on your list, including the ones only one person used.
- Shared credentials. Any account the person knew the password to, even if it was not theirs. Those get rotated, not just revoked.
- Physical. Keys, passes, hardware, anything stored at home.
- Data and relationships. Files on personal devices, customer contacts, vendor relationships, and the things only that person knew how to do.
Revoking an account and rotating a shared password are two different tasks. Most checklists only do the first.
The cases that break the process
A planned resignation with four weeks notice is the easy version. The checklist earns its keep in the awkward cases.
Contractors and temporary staff. Often onboarded informally, often never offboarded at all, because there was no end date in a system anywhere. Give every non permanent account an expiry date on the day it is created.
Immediate departures. Somebody needs the authority to cut access within the hour, without waiting for a manager who is on a flight. Decide who that is now, not on the day.
Internal moves. The quietest gap of all. People change roles and pick up new access, but nothing is ever removed, so after a few years a handful of staff can reach almost everything.
Vendors and partners. The consultant who needed access for one project. The agency that is no longer retained. These accounts sit open for years because no internal process was ever triggered.
Make it verifiable
A checklist that nobody checks is a document, not a control. Two habits turn it into something real.
First, evidence. Each line gets ticked by a named person with a date. Not because you expect to be audited, but because it forces the step to actually happen.
Second, a review. Once a quarter, pick the list of systems and confirm that everyone with access still works there and still needs it. This takes less time than people fear, and it catches the internal moves and the forgotten contractors that offboarding alone never will.
What it costs and what it saves
Building this properly takes a couple of afternoons. Maintaining it takes an hour a quarter.
In return you stop paying for licences nobody uses, you can answer the access question when a customer or an insurer asks it, and you close the single most common route to a problem that looks like a security incident but started as an admin oversight.
This is process work, and it is exactly the kind of thing we help businesses document and keep current. Not tooling, not monitoring, just a clear list, a named owner and a review that happens whether or not anyone remembers.
If you do only one thing from this piece, go and find out how many accounts are still open for people who left in the last two years. The number is usually the argument.
Need a second pair of eyes on your onboarding and offboarding steps? Book a consultation, or visit www.expertechsolution.com.