Short answer: vendor offboarding should confirm the end date and scope, complete or transfer open work, reconcile invoices, recover physical assets, revoke digital and property access, disable integrations, return or delete data under approved terms, preserve required records, notify affected people, and verify every removal. The process is not complete when the final invoice is paid.
NIST supply-chain guidance emphasizes understanding and mitigating risk across acquired products and services. Its access guidance states that prompt revocation matters when suppliers and service providers no longer require access. CISA similarly recommends least privilege and separation of duties for third parties. This independent checklist is operational guidance, not legal, employment, contract, privacy, cybersecurity, insurance, accounting, or records-retention advice.
Confirm authority, timing, and scope
Record the vendor entity, agreement, properties, services, effective end date, termination authority, notice evidence, reason category, and any disputed obligations. Restrict sensitive reason details to appropriate roles. A vendor employee leaving and the vendor relationship ending are different events and may require different actions.
Inventory open property work
List work orders, inspections, recurring services, scheduled visits, resident appointments, estimates, warranties, parts, permits, safety issues, and incomplete evidence. Decide whether each item will be completed, canceled, reassigned, or disputed. Use the maintenance vendor scorecard to preserve performance evidence without rewriting history after termination.
Reconcile financial obligations
Verify approved work, purchase orders, invoices, credits, deposits, retainage, recurring charges, payment status, tax records, and disputed amounts. Separate service completion from payment authorization. Qualified accounting and legal reviewers should handle material disputes or specialized requirements.
Recover physical access and assets
Inventory keys, fobs, remotes, badges, lockbox access, parking credentials, devices, documents, tools, and owner property. Record identifier, assigned person, returned status, condition, disabling action, and evidence. Change shared codes when individual revocation cannot be proved.
Remove digital access everywhere
Review software users, mobile sessions, shared links, email groups, cloud folders, portals, support identities, API keys, OAuth grants, webhooks, calendars, messaging, remote support, and network access. Test denied behavior after revocation with the software permissions matrix.
Download the vendor offboarding checklist
Download the editable vendor offboarding and access-removal checklist (CSV). It covers agreement closure, open work, invoices, property access, digital identities, integrations, data, records, communication, validation, and sign-off.
Close integrations and service accounts
Identify credentials, tokens, certificates, webhook endpoints, file transfers, scheduled jobs, and vendor-owned automation. Pause flows, preserve required evidence, reconcile the final period, rotate shared secrets, and verify no new records arrive. Use the integration reconciliation playbook for identifiers and final control totals.
Handle vendor-held data deliberately
Identify property, resident, owner, financial, access, media, document, and log data held by the vendor or subcontractors. Follow approved contract, law, policy, litigation-hold, return, export, deletion, and certification requirements. A verbal statement that data was deleted is not the same as required evidence.
Communicate operational changes
Notify staff, residents, owners, replacement vendors, accounting, security, and emergency contacts only as needed. State the new service path, effective time, open-work owner, and urgent contact. Do not disclose unnecessary personnel, dispute, or security details.
Run a final access and recurrence review
Search for recent logins, active sessions, new API calls, scheduled deliveries, retained keys, shared credentials, orphaned work, and recurring payments. Review whether onboarding created access that was difficult to remove and improve the vendor inventory and agreement controls.
Frequently asked questions
Can the team delete the vendor account immediately?
Disable or restrict access promptly as required, but preserve approved records and audit evidence. Deletion, retention, and account handling should follow the agreement, policy, system capability, and qualified advice.
Who owns vendor offboarding?
Assign one accountable coordinator. Operations, property staff, accounting, security, records, legal reviewers, and the replacement vendor may own individual actions.