Free template
IT offboarding checklist template
A leaver's last day is an evidence event. This free XLSX runs it like one: nineteen steps across access, hardware, and licenses, plus the two log sheets auditors actually sample, dated asset returns and dated access revocations. Direct download, no email gate.
Want to know when this template changes? Regulations and criteria move. Email sales@ontrackio.com and we will send the new version. Nothing else, no newsletter.
What is inside
Four sheets. The How to use sheet explains the evidence framing and the one rule that matters, real dates over ticks; the other three are the working record:
- Leaver checklist. Nineteen steps across access, hardware, licenses, and wrap-up, each with an owner, a status, a date, and an evidence field. Duplicate the sheet per leaver.
- Asset return log. Every returned item with serial, dated receipt, condition, who received it, and the wipe-certificate reference.
- Access revocation log. Every account revoked, when, by whom, and how: the sheet an auditor compares against the leaver's last working day.
Scope note: this is the leaver checklist. If you are looking for the form signed when equipment is first issued, that is the equipment handover form, a different document for a different day; in OnTrackio it exists as a two-party e-signed transfer agreement. The endpoint agent that keeps the register honest deploys through Intune or any MDM.
The test an auditor runs
Whatever the framework, the offboarding test is the same: pick leavers, compare dates. Last working day against access-revocation timestamps. Departure date against the hardware-return receipt. A week's gap is a question; a month's gap is a finding; no record at all is the bad meeting. The template's two log sheets exist so the comparison lands on your side, and the offboarding evidence guide walks the full request list framework by framework.
Frequently asked questions
Why does IT offboarding need a checklist at all?
Because the failure mode is silent. A missed SaaS seat bills quietly for a year; a laptop nobody collected surfaces in a breach assessment; an account that outlived its owner is a finding in every framework. Offboarding is a dozen small steps owned by different people under time pressure, which is exactly the shape of work checklists exist for.
What do auditors actually check about offboarding?
Dates against dates. They pick a sample of leavers and compare the last working day to the access-revocation timestamps and the hardware-return receipts. Gaps of weeks are findings; absence of any record is worse. The two log sheets in this template exist precisely for that comparison.
Does this cover NIS2 and ISO 27001 as well as SOC 2?
The obligations rhyme. SOC 2 samples leavers under the CC6 access criteria, ISO 27001 expects assets returned at termination, and the NIS2 Implementing Regulation asks for documented deposit, return, or deletion of assets when employment ends. One honest return-and-revocation record serves all three; only the vocabulary changes.
When does the spreadsheet stop being enough?
When leavers are frequent enough that the checklist depends on someone remembering to start it. OnTrackio runs the same discipline as a workflow: offboarding cannot be marked complete while the person still holds hardware, licenses, or loaner equipment, and SCIM leaver events from your identity provider start the clock automatically. Until that point, this file plus calendar discipline works.
Offboarding that cannot be quietly skipped
In OnTrackio, a leaver cannot be marked offboarded while they still hold hardware, licenses, or loaner kit. See it against your own leaver flow in 30 minutes.