BG Beter Geregeld ICT
Offboarding · 2 min leestijd · 10 November 2025 · ★ Pillar-gids

Watertight Offboarding in 12 Steps

Someone is leaving. In SMEs, this is where most data breaches begin. Here is a checklist that covers what you actually need to do — with deadlines, owners, and pitfalls.

For onboarding, business owners happily schedule 3 hours. For offboarding, it's often 20 minutes on the last day. That's where things go wrong.

\n \n

The 12 steps — in order of importance

\n
    \n
  1. Disable first, delete later. On the last working day: set the account to disabled, not deleted. You may still need to read emails or recover files.
  2. \n
  3. Revoke privileged access immediately. Global Admin, AWS root, accounting admin — those go straight away, not on the final day. See privileged access.
  4. \n
  5. Change shared passwords. Everything in your password vault this person had access to. Yes, all of it. See shared password management.
  6. \n
  7. Set up email forwarding. To the manager or successor, for 30 days. See email forwarding after departure.
  8. \n
  9. Set an auto-reply. "I no longer work here. Please contact X."
  10. \n
  11. Collect the laptop. See device retrieval.
  12. \n
  13. Disable MFA tokens. Authenticator apps, hardware tokens, SMS numbers.
  14. \n
  15. Revoke individual SaaS accounts. Everything not covered by SSO (see SaaS inventory).
  16. \n
  17. Hand over clients and projects. See client handover.
  18. \n
  19. Transfer vault items.
  20. \n
  21. 30 days later: archive email and delete the account. See the 30-day rule.
  22. \n
  23. Log what you did. One page per offboarding, kept as audit evidence.
  24. \n
\n \n

Who does what?

\n

HR triggers the process. IT / office manager executes it. The line manager handles the client and project handover. Leadership signs off on steps 1–3 (the high-impact ones).

\n \n

Make it a process, not just a checklist

\n

Set it up as a process in your tool, with each step assigned an owner, an SLA, and required evidence.

\n \n

Further reading: legal framework, onboarding-offboarding parity, script for the last working day.

Onderwerpen

#iam #governance #checklist #offboarding

Volledige gids: Offboarding hermético en 12 pasos

Dit artikel is onderdeel van onze uitgebreide Offboarding-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →