Offboarding Controls
Definition
The set of actions taken when a vendor relationship ends: revoking access credentials, recovering or destroying shared data, terminating network connectivity, and documenting completion. Inadequate offboarding that leaves credentials active or data unreturned is one of the most frequently cited third-party risk findings in security audits.
- Scope
- Access revocation, data recovery, connectivity termination
- Trigger
- End of a vendor or third-party relationship
- Common failure
- Credentials left active after contract end
Common questions
Why do offboarding failures show up so often in audits?+
Offboarding is a low-visibility, end-of-relationship task with no ongoing owner once the business need ends, so it is easy for an organization to close a contract without a corresponding checklist to revoke access.
What is the practical risk of incomplete offboarding?+
A former vendor with live credentials or unreturned data becomes a persistent access point that internal monitoring does not expect to see used, making any later activity through it harder to attribute and investigate.
Related terms
- Due Diligence Questionnaire (DDQ)
- A structured questionnaire sent to a prospective vendor before onboarding, asking the vendor to describe its security controls, certifications, incident history, subprocessor...
- Right-to-Audit Clause
- A contractual provision that gives the organisation the right to audit or assess the vendor's security controls, either directly or through a...
- Subprocessor
- A third party engaged by a vendor (the processor) to perform part of the service that involves the organisation's data. Under GDPR...
- Third-Party Risk
- The information security, operational, legal, or reputational risk introduced to an organisation by its relationships with external parties including vendors, suppliers, cloud...
- Vendor Tiering
- The classification of vendors into risk tiers, typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low), based on factors such...