IPO AdvisoryValue at the CoreVirtual CFOValue at the CoreRisk AdvisoryValue at the CoreFamily Office & SuccessionValue at the CoreDue DiligenceValue at the CoreGlobal Accounting & ComplianceValue at the CoreGCC & Global Support ServicesValue at the CorePrivate EquityValue at the CoreDebt SyndicationValue at the CoreIPO AdvisoryValue at the CoreVirtual CFOValue at the CoreRisk AdvisoryValue at the CoreFamily Office & SuccessionValue at the CoreDue DiligenceValue at the CoreGlobal Accounting & ComplianceValue at the CoreGCC & Global Support ServicesValue at the CorePrivate EquityValue at the CoreDebt SyndicationValue at the Core
Home/Insights/Risk Advisory

Vendor Offboarding: The Forgotten Control

An Internal Audit Perspective

It's 2:47 p.m. on an unremarkable Thursday, and you are not expecting to find anything.

You're closing out a routine checklist item — reconciling the vendor contract register against active system accounts. It's a task you've run so many times it barely registers as work anymore. Match. Match. Match. Then three names that don't match anything at all.

All three belong to a technology vendor whose contract ended eighteen months ago — quietly, the way these things usually do. No breach. No incident. No red flag ever pointed here. You almost close the file.

Then you pull the login history.

One of the three accounts was used three weeks ago. From an IP address nobody on your team recognizes.

Every onboarding control had worked exactly as designed. Every access review before this one had passed. The vendor hadn't done anything malicious — they had simply never been asked to leave.

Weeks later, the rest of the story comes together. The vendor had suffered a security incident of its own — completely unrelated to your engagement. In the scramble to contain it, someone on their side stumbled onto an old integration, still quietly connected to a client that, on paper, no longer existed.

That client was you.

The relationship had ended in practice eighteen months earlier. On paper, and inside the vendor's systems, it had never ended at all.

This is the good version of this story — the one where internal audit finds the loose thread before anyone else does. The bad version is a regulator, a journalist, or the vendor's own breach notification finding it first.

The Forgotten Half of Third-Party Risk

Every audit universe has its glamorous risks — cybersecurity, fraud, third-party financial exposure. Vendor onboarding usually gets its fair share of attention too: due diligence questionnaires, contract reviews, risk tiering, background checks. Everyone wants to be there for the wedding.

Almost nobody shows up at the time of divorce.

Or, to borrow a homelier image: organisations are diligent about changing the locks when they move into a new house. Far fewer think to ask the previous tenant for the keys back. Vendor offboarding — the process of formally, completely, and securely ending a vendor relationship — is one of the most under-audited controls in the third-party risk lifecycle. It doesn't get a line item in the board deck. But it is exactly the kind of quiet, procedural gap that turns into a headline.

Why Offboarding Gets Ignored

A vendor relationship rarely ends as a clean, planned event. Contracts lapse quietly. Projects wind down. A department stops using a tool but nobody tells IT. A vendor is replaced by a competitor, and the old one just fades away. There's no ribbon-cutting for an ending, so there's no urgency behind it.

The reasons this control consistently breaks down are structural, not personal:

Ask yourself, as an auditor: does your organisation have a defined, owned, monitored offboarding checklist with the same rigour as onboarding? For most organisations, the honest answer is "sort of," which in audit language means "no."

Why It Matters: The Risks in Play

Vendor offboarding isn't an administrative afterthought — it's a control that touches nearly every corner of the risk universe:

That's the essence of the forgotten control: risk doesn't stop when the business relationship stops. It stops when the access stops, when the data stops, and when the contract stops — three separate events that only rigorous offboarding ties together.

What Good Offboarding Looks Like

A robust offboarding process should address, at minimum:

Miss any one of these and you have a live risk masquerading as a closed file.

What Internal Audit Should Be Testing

For auditors looking to build or strengthen coverage of this area, five procedures deliver disproportionate assurance:

Quick Reference: Key Risk Indicators

Metric Red Flag Level Audit Action Required
Orphaned accounts Any active vendor ID with no matching active contract Immediate revocation; forensic log review of recent activity
Late de-provisioning Access revoked more than 48 hours after contract end / business use stop Sample the process to find workflow bottlenecks; assign clear ownership
Missing destruction evidence Zero certificates of data destruction on file for terminated vendors Raise a non-compliance finding against procurement / vendor owner
Dormant integrations APIs, SFTP feeds or SSO configs still live with no corresponding active vendor Escalate for immediate teardown; review data exposure during the gap

The Takeaway

Vendor offboarding doesn't fail loudly. It fails silently, for years, until a completely unrelated event — a vendor breach, a regulatory inquiry, a routine access review — shines a light on a door that was never actually locked.

For an internal audit function, that makes it a near-perfect candidate for proactive coverage: low visibility, meaningful risk, and — unlike many emerging risk areas — a control environment that's often genuinely fixable with a documented process, a clear owner, and a checklist that gets used every single time a vendor relationship ends.

A vendor relationship officially ends when the contract is terminated. A vendor risk officially ends only when access is revoked, data is secured, assets are recovered, and obligations are closed.

The new beginning gets all the attention. Audit should make sure that ending partnerships gets some too.

Need to strengthen your vendor offboarding controls?

Our Risk Advisory team designs internal audit programmes, vendor risk frameworks and IFC controls that close exactly these gaps — before they become findings.

Explore Risk Advisory →

← Back to all insights