Vendor Offboarding: The Forgotten Control
An Internal Audit Perspective
It's 2:47 p.m. on an unremarkable Thursday, and you are not expecting to find anything.
You're closing out a routine checklist item — reconciling the vendor contract register against active system accounts. It's a task you've run so many times it barely registers as work anymore. Match. Match. Match. Then three names that don't match anything at all.
All three belong to a technology vendor whose contract ended eighteen months ago — quietly, the way these things usually do. No breach. No incident. No red flag ever pointed here. You almost close the file.
Then you pull the login history.
One of the three accounts was used three weeks ago. From an IP address nobody on your team recognizes.
Every onboarding control had worked exactly as designed. Every access review before this one had passed. The vendor hadn't done anything malicious — they had simply never been asked to leave.
Weeks later, the rest of the story comes together. The vendor had suffered a security incident of its own — completely unrelated to your engagement. In the scramble to contain it, someone on their side stumbled onto an old integration, still quietly connected to a client that, on paper, no longer existed.
That client was you.
The relationship had ended in practice eighteen months earlier. On paper, and inside the vendor's systems, it had never ended at all.
This is the good version of this story — the one where internal audit finds the loose thread before anyone else does. The bad version is a regulator, a journalist, or the vendor's own breach notification finding it first.
The Forgotten Half of Third-Party Risk
Every audit universe has its glamorous risks — cybersecurity, fraud, third-party financial exposure. Vendor onboarding usually gets its fair share of attention too: due diligence questionnaires, contract reviews, risk tiering, background checks. Everyone wants to be there for the wedding.
Almost nobody shows up at the time of divorce.
Or, to borrow a homelier image: organisations are diligent about changing the locks when they move into a new house. Far fewer think to ask the previous tenant for the keys back. Vendor offboarding — the process of formally, completely, and securely ending a vendor relationship — is one of the most under-audited controls in the third-party risk lifecycle. It doesn't get a line item in the board deck. But it is exactly the kind of quiet, procedural gap that turns into a headline.
Why Offboarding Gets Ignored
A vendor relationship rarely ends as a clean, planned event. Contracts lapse quietly. Projects wind down. A department stops using a tool but nobody tells IT. A vendor is replaced by a competitor, and the old one just fades away. There's no ribbon-cutting for an ending, so there's no urgency behind it.
The reasons this control consistently breaks down are structural, not personal:
- The ownership vacuum. Procurement owns the contract, IT owns system access, and the business unit owns the day-to-day relationship. When no single role is explicitly accountable for the exit checklist, the process defaults to nobody.
- Out of sight, out of mind. Once a vendor delivers the final product, the business manager's focus shifts immediately to the next priority. Nobody is pushing for an ending the way a sponsor pushes for onboarding speed.
- De-coupled systems. In most organisations, the procurement or vendor management system doesn't automatically talk to IT's identity infrastructure. A contract expiring should trigger de-provisioning — instead it triggers a manual ticket that may or may not get raised.
Ask yourself, as an auditor: does your organisation have a defined, owned, monitored offboarding checklist with the same rigour as onboarding? For most organisations, the honest answer is "sort of," which in audit language means "no."
Why It Matters: The Risks in Play
Vendor offboarding isn't an administrative afterthought — it's a control that touches nearly every corner of the risk universe:
- Information security risk — Former vendors may retain application access, VPN connectivity, API keys, or badge access to physical premises.
- Data privacy risk — Customer or employee data provided to the vendor during the engagement may remain on their systems, unmonitored and undestroyed.
- Compliance risk — Regulatory and contractual obligations — NDAs, data protection clauses — often survive termination and continue to require tracking.
- Operational risk — Poorly managed transitions and incomplete knowledge transfer can disrupt business services that depended on the vendor.
- Financial risk — Unused licences, subscriptions, or service fees keep getting paid long after anyone is using the service.
That's the essence of the forgotten control: risk doesn't stop when the business relationship stops. It stops when the access stops, when the data stops, and when the contract stops — three separate events that only rigorous offboarding ties together.
What Good Offboarding Looks Like
A robust offboarding process should address, at minimum:
- Access revocation — Application accounts, VPN access, API keys, shared credentials, and badge access to physical premises are revoked — not left to lapse on their own.
- Data return or destruction — Confirmed, certified deletion of company data held by the vendor, and return of any company-owned physical assets (laptops, tokens, badges).
- Contractual closure — Formal termination notice, settlement of final invoices, and confirmation that post-termination obligations — NDAs, data protection clauses — survive and are actively tracked, not filed and forgotten.
- Integration teardown — APIs, SFTP connections, data feeds, and single sign-on configurations are formally decommissioned.
- Knowledge transfer — Documentation, credentials, and institutional knowledge are captured before they walk out the door.
- Vendor risk register update — The vendor is removed or archived from active monitoring, with a historical record retained for the audit trail.
Miss any one of these and you have a live risk masquerading as a closed file.
What Internal Audit Should Be Testing
For auditors looking to build or strengthen coverage of this area, five procedures deliver disproportionate assurance:
- Reconcile identities to contracts. Pull the vendor master list and reconcile it against active contracts. Any vendor with no active contract but live system access is an immediate finding.
- Trace the offboarding trail. Sample terminated vendors and trace the full offboarding trail — access revocation timestamps, data destruction certificates, and final settlement documentation.
- Test the de-provisioning lag. Check the time lag between "business use stopped" and "access revoked." This gap is often measured in months, not days.
- Verify ownership. Confirm who actually owns the offboarding process — procurement, IT, the business unit, or nobody. A control with no owner is not a control.
- Test surviving obligations. Are NDAs and data protection clauses actively tracked post-termination, or filed and forgotten?
Quick Reference: Key Risk Indicators
| Metric | Red Flag Level | Audit Action Required |
|---|---|---|
| Orphaned accounts | Any active vendor ID with no matching active contract | Immediate revocation; forensic log review of recent activity |
| Late de-provisioning | Access revoked more than 48 hours after contract end / business use stop | Sample the process to find workflow bottlenecks; assign clear ownership |
| Missing destruction evidence | Zero certificates of data destruction on file for terminated vendors | Raise a non-compliance finding against procurement / vendor owner |
| Dormant integrations | APIs, SFTP feeds or SSO configs still live with no corresponding active vendor | Escalate for immediate teardown; review data exposure during the gap |
The Takeaway
Vendor offboarding doesn't fail loudly. It fails silently, for years, until a completely unrelated event — a vendor breach, a regulatory inquiry, a routine access review — shines a light on a door that was never actually locked.
For an internal audit function, that makes it a near-perfect candidate for proactive coverage: low visibility, meaningful risk, and — unlike many emerging risk areas — a control environment that's often genuinely fixable with a documented process, a clear owner, and a checklist that gets used every single time a vendor relationship ends.
A vendor relationship officially ends when the contract is terminated. A vendor risk officially ends only when access is revoked, data is secured, assets are recovered, and obligations are closed.
The new beginning gets all the attention. Audit should make sure that ending partnerships gets some too.
Need to strengthen your vendor offboarding controls?
Our Risk Advisory team designs internal audit programmes, vendor risk frameworks and IFC controls that close exactly these gaps — before they become findings.
Explore Risk Advisory →