A vendor offboarding checklist makes sure that when a relationship ends, the vendor’s access ends with it, your data comes back or is destroyed, and nothing breaks for customers in the process. Most third-party programmes put their effort into onboarding and forget the exit, which is where orphaned accounts, forgotten data copies and unpaid obligations come from. This guide sets out a vendor offboarding checklist by phase, and what each standard expects.

What the Standards Expect
NIST CSF 2.0 includes a dedicated outcome, GV.SC-10: supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement. ISO/IEC 27001:2022 control A.5.22 covers monitoring and change of supplier services, including their end, and A.5.20 expects agreements to address the return or destruction of information. For financial entities, DORA Article 28(8) requires exit strategies for ICT services supporting critical or important functions, and Article 30 requires contracts to cover termination rights and transition. See the NIST Cybersecurity Framework for the GV.SC outcomes.
Vendor Offboarding Checklist: Before Notice
- Confirm the reason and the decision, with the relationship owner and procurement.
- Read the contract: notice period, termination fees, transition assistance, data return and deletion terms.
- Identify everything the vendor touches: data, systems, integrations, accounts, physical access and subcontractors.
- Line up the replacement, or confirm the service is no longer needed.
- For a critical service, follow the exit plan and tell the regulator if your rules require it.
Vendor Offboarding Checklist: Transition
- Give notice in the form the contract requires, and agree a transition timetable.
- Run the old and new services in parallel where the function is critical.
- Export your data in a usable, agreed format, and check it is complete before anything is deleted.
- Transfer documentation, configuration and knowledge the new provider or your team needs.
- Tell affected customers or staff where the change touches them.
Vendor Offboarding Checklist: Access Removal
| Access | Action |
|---|---|
| User accounts | Disable every vendor account, including shared and break-glass accounts |
| Remote access | Remove VPN profiles, remote support tools and jump host access |
| Integrations | Revoke API keys, OAuth grants, service accounts and certificates |
| Single sign-on | Remove the application from SSO and deprovision users |
| Network | Close firewall rules and allow-listed IP ranges for the vendor |
| Physical | Collect badges, keys and equipment; remove building access |
| Secrets | Rotate any passwords or keys the vendor ever knew |
Removing access is the step most often left half done. Check it against the vendor’s access list from your last access review, not from memory.
Vendor Offboarding Checklist: Data Return and Deletion
- Confirm the vendor has returned everything it should, including copies held by its subcontractors.
- Instruct deletion, including backups, as the contract and your data processing agreement allow.
- Obtain a written certificate of deletion that names the data, systems and date.
- Record any data the vendor must keep by law, and for how long.
Vendor Offboarding Checklist: Close Out
- Settle final invoices, credits and any service level penalties.
- Mark the vendor as exited in your third-party inventory and, for DORA entities, in the register of information.
- Archive the contract, assessments and deletion certificate for your retention period.
- Close or transfer open issues and risks linked to the vendor.
- Hold a short lessons-learned review: what the exit revealed about the contract and the exit plan.
Who Owns Each Step of the Vendor Offboarding Checklist
| Step | Usual owner |
|---|---|
| Decision, notice and contract terms | Relationship owner with procurement and legal |
| Transition and replacement service | Relationship owner and IT |
| Access removal and secret rotation | IT and security |
| Data export, return and deletion evidence | Data owner with the privacy lead |
| Final payments and credits | Finance |
| Inventory, register and records | Third-party risk or procurement |
Give one person, usually the relationship owner, the job of confirming every row is complete before the vendor is marked as exited.
Offboarding a Critical Vendor
For a vendor that supports a critical function, the vendor offboarding checklist runs inside the exit plan rather than on its own. Expect a longer transition, a period of running both services, a rehearsal of the cut-over, and regulator engagement where your rules require it. If the exit is forced by the vendor’s failure rather than chosen, the order changes: secure your data and keep the service running first, and deal with commercial matters afterwards.
Common Mistakes
- Deleting before verifying the export. Once the vendor deletes, missing data is gone.
- Forgetting integrations. API tokens and OAuth grants survive long after user accounts are disabled.
- No deletion certificate. Without one, you cannot show the data was destroyed.
- Treating exit as procurement’s job. Security, privacy, IT and the business owner each hold part of the vendor offboarding checklist.
- No exit terms in the contract. Offboarding is only as good as the terms signed at the start.
Frequently Asked Questions
When should the vendor offboarding checklist be planned?
At onboarding. The contract should already say how data comes back, how long transition support lasts and what deletion evidence you get.
Is an exit plan the same as offboarding?
No. An exit plan is prepared in advance for a critical service, including a forced or sudden exit. Offboarding is carrying out the exit. Our guide to the DORA exit strategy covers the planning side.
What about fourth parties?
Ask the vendor to confirm its subcontractors have returned or deleted your data too, and cover that in the certificate. Our guide to fourth-party risk explains why.
The time to plan the exit is when you assess the vendor. Our free third-party risk assessment template checks for an exit plan and data return terms during due diligence and flags a critical vendor without one. The TPRM Toolkit includes an exit plan template, a termination procedure and checklist, and data return and deletion records.