Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Vendor offboarding checklist phases: transition, access removal and close out

Vendor Offboarding Checklist: The Complete 2026 Guide to Exiting a Vendor

A vendor offboarding checklist makes sure that when a relationship ends, the vendor’s access ends with it, your data comes back or is destroyed, and nothing breaks for customers in the process. Most third-party programmes put their effort into onboarding and forget the exit, which is where orphaned accounts, forgotten data copies and unpaid obligations come from. This guide sets out a vendor offboarding checklist by phase, and what each standard expects.

Vendor offboarding checklist phases: transition, access removal and close out

What the Standards Expect

NIST CSF 2.0 includes a dedicated outcome, GV.SC-10: supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement. ISO/IEC 27001:2022 control A.5.22 covers monitoring and change of supplier services, including their end, and A.5.20 expects agreements to address the return or destruction of information. For financial entities, DORA Article 28(8) requires exit strategies for ICT services supporting critical or important functions, and Article 30 requires contracts to cover termination rights and transition. See the NIST Cybersecurity Framework for the GV.SC outcomes.

Vendor Offboarding Checklist: Before Notice

  • Confirm the reason and the decision, with the relationship owner and procurement.
  • Read the contract: notice period, termination fees, transition assistance, data return and deletion terms.
  • Identify everything the vendor touches: data, systems, integrations, accounts, physical access and subcontractors.
  • Line up the replacement, or confirm the service is no longer needed.
  • For a critical service, follow the exit plan and tell the regulator if your rules require it.

Vendor Offboarding Checklist: Transition

  • Give notice in the form the contract requires, and agree a transition timetable.
  • Run the old and new services in parallel where the function is critical.
  • Export your data in a usable, agreed format, and check it is complete before anything is deleted.
  • Transfer documentation, configuration and knowledge the new provider or your team needs.
  • Tell affected customers or staff where the change touches them.

Vendor Offboarding Checklist: Access Removal

AccessAction
User accountsDisable every vendor account, including shared and break-glass accounts
Remote accessRemove VPN profiles, remote support tools and jump host access
IntegrationsRevoke API keys, OAuth grants, service accounts and certificates
Single sign-onRemove the application from SSO and deprovision users
NetworkClose firewall rules and allow-listed IP ranges for the vendor
PhysicalCollect badges, keys and equipment; remove building access
SecretsRotate any passwords or keys the vendor ever knew

Removing access is the step most often left half done. Check it against the vendor’s access list from your last access review, not from memory.

Vendor Offboarding Checklist: Data Return and Deletion

  • Confirm the vendor has returned everything it should, including copies held by its subcontractors.
  • Instruct deletion, including backups, as the contract and your data processing agreement allow.
  • Obtain a written certificate of deletion that names the data, systems and date.
  • Record any data the vendor must keep by law, and for how long.

Vendor Offboarding Checklist: Close Out

  • Settle final invoices, credits and any service level penalties.
  • Mark the vendor as exited in your third-party inventory and, for DORA entities, in the register of information.
  • Archive the contract, assessments and deletion certificate for your retention period.
  • Close or transfer open issues and risks linked to the vendor.
  • Hold a short lessons-learned review: what the exit revealed about the contract and the exit plan.

Who Owns Each Step of the Vendor Offboarding Checklist

StepUsual owner
Decision, notice and contract termsRelationship owner with procurement and legal
Transition and replacement serviceRelationship owner and IT
Access removal and secret rotationIT and security
Data export, return and deletion evidenceData owner with the privacy lead
Final payments and creditsFinance
Inventory, register and recordsThird-party risk or procurement

Give one person, usually the relationship owner, the job of confirming every row is complete before the vendor is marked as exited.

Offboarding a Critical Vendor

For a vendor that supports a critical function, the vendor offboarding checklist runs inside the exit plan rather than on its own. Expect a longer transition, a period of running both services, a rehearsal of the cut-over, and regulator engagement where your rules require it. If the exit is forced by the vendor’s failure rather than chosen, the order changes: secure your data and keep the service running first, and deal with commercial matters afterwards.

Common Mistakes

  • Deleting before verifying the export. Once the vendor deletes, missing data is gone.
  • Forgetting integrations. API tokens and OAuth grants survive long after user accounts are disabled.
  • No deletion certificate. Without one, you cannot show the data was destroyed.
  • Treating exit as procurement’s job. Security, privacy, IT and the business owner each hold part of the vendor offboarding checklist.
  • No exit terms in the contract. Offboarding is only as good as the terms signed at the start.

Frequently Asked Questions

When should the vendor offboarding checklist be planned?

At onboarding. The contract should already say how data comes back, how long transition support lasts and what deletion evidence you get.

Is an exit plan the same as offboarding?

No. An exit plan is prepared in advance for a critical service, including a forced or sudden exit. Offboarding is carrying out the exit. Our guide to the DORA exit strategy covers the planning side.

What about fourth parties?

Ask the vendor to confirm its subcontractors have returned or deleted your data too, and cover that in the certificate. Our guide to fourth-party risk explains why.

The time to plan the exit is when you assess the vendor. Our free third-party risk assessment template checks for an exit plan and data return terms during due diligence and flags a critical vendor without one. The TPRM Toolkit includes an exit plan template, a termination procedure and checklist, and data return and deletion records.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.