Employee offboarding and access removal
This is the procedure most often requested in diligence and most often missing. An ex-employee who still has access to a customer database three months after leaving is both a security incident waiting to happen and an immediate finding in any audit. It is also cheap to document and easy to evidence, which makes it the best place to start.
- 1
HR Lead records the confirmed last working day in the HR system and notifies the Line Manager, IT Administrator, and Finance in a single message.
HR Lead
Timing: Within one working day of confirmation
One notification to all three at once, not a chain. A sequential handoff is where offboarding stalls, because each party waits on the previous one.
- 2
HR Lead confirms whether the departure is voluntary or involuntary.
HR Lead
This determines the access-removal timing, which is the single most consequential decision in this procedure.
Involuntary: go to step 3
Voluntary: go to step 4
- 3
IT Administrator revokes all system access immediately, before or at the moment the departure is communicated to the employee.
IT Administrator
Timing: Immediately, coordinated with the notification meeting
For an involuntary departure, access removal happens first and is coordinated with the conversation itself. Continue to step 5 afterwards.
- 4
Line Manager and the departing employee agree a handover plan covering the processes only that person performs.
Line Manager
Timing: Within three working days of notification
Prioritise anything with an external deadline, anything where they are the sole approver or account holder, and recovery procedures for rare failures. Do not attempt to cover everything.
- 5
IT Administrator produces a written list of every system, account, shared credential, and physical access method held by the departing person.
IT Administrator
Include the systems that are not in the standard onboarding set: vendor portals, a domain registrar, a payment provider, a social account, anything with a shared login. These are the ones that get missed.
- 6
Line Manager identifies a named owner for each item on that list.
Line Manager
Every item needs a person, not a team. An item assigned to a team is an item assigned to nobody.
- 7
IT Administrator revokes access to every item on the list and records the date and time of each revocation.
IT Administrator
Timing: By end of the last working day
The record is the point. Being able to show that access was removed, and when, is what turns this from a claim into evidence.
- 8
IT Administrator rotates every shared credential the departing person had access to.
IT Administrator
Removing their account does not help if they know a password that still works. This step is skipped more often than any other in this procedure.
- 9
Finance confirms final pay, expense settlement, and the cancellation of any company card or subscription in the person's name.
Finance
Subscriptions billed to an individual's card are a recurring source of surprise service interruptions after someone leaves.
- 10
Line Manager confirms return of all physical assets against the asset register.
Line Manager
Laptop, phone, access card, keys, hardware security keys, and anything held at home.
- 11
Line Manager has another team member perform each handed-over procedure from the written version while the departing person is still available.
Line Manager
Timing: Before the last working day
Perform, not read. This is the only real test of a handover document and it reliably finds a missing permission or an assumed step. Doing it before the last day makes the fix a conversation instead of an incident.
- 12
HR Lead confirms every step above is complete and closes the offboarding record.
HR Lead
If any item is outstanding, it needs a named owner and a date rather than being closed optimistically.
All items complete: the procedure ends
Items outstanding: go to step 6
Change these before you use it
- Replace the role names with your own job functions. Keep them as functions rather than individuals so the procedure survives a reorganisation.
- Add your actual system list to step 5 as a standing checklist, rather than rebuilding it from memory each time.
- If you are regulated, add the notification and record-retention obligations that apply to you. This template does not cover them.
- If you use single sign-on, step 7 gets much shorter, but the non-SSO systems in step 5 still need enumerating individually.
This is a starting point, not compliance advice. It is written to be adapted, and a procedure that touches access, money, or customer data needs to match how your business actually operates and whatever rules apply to you. Use it as a first draft to edit, not a policy to adopt.
Make it yours in a couple of minutes
Rather than retyping this and editing it, describe your own version of the process out loud or click through it once, and get a first draft with your actual steps, roles, and systems in it. No account needed to see the result.
No account neededNo credit cardSee the whole SOP before you sign up