Employee Leavers, Resignations and Offboarding Procedures

Offboarding in Brief

Leavers need their access revoked, their equipment returned and any handover documented before they leave. A brief exit conversation often surfaces useful information about how the business is actually being run.

Leavers and Offboarding

Leavers and offboarding covers everything that needs to happen when an employee leaves the organisation - whether they resign, are dismissed, retire, or their fixed-term contract ends. A structured process makes sure the handover is complete, access is removed, records are updated and final pay and documents are dealt with correctly.

Good offboarding also protects the management system. Key knowledge, passwords, equipment and documentation all need to be accounted for. Done well, it leaves the organisation ready to carry on. Done badly, it creates information security risks, operational gaps and data protection issues.

When a Leaver is Identified

The process usually starts with one of three triggers: an employee resigning (typically with written notice), an employer-initiated end of employment (such as redundancy or dismissal at the end of a disciplinary process), or the natural end of a fixed-term arrangement. Retirement and mutually agreed departures also sit here.

Once a leaving date is confirmed, the clock starts on a set of tasks that need to be complete by or shortly after the last day. A simple checklist helps make sure nothing is missed, particularly where several different teams (line manager, HR, IT, finance, facilities) each have responsibilities.

Knowledge Transfer and Handover

For most roles, the biggest offboarding risk is loss of knowledge. Key responsibilities, in-progress work, relationships with clients or suppliers, and where things are kept should all be handed over before the person leaves. A written handover document, reviewed with the line manager, is usually enough for most roles. Longer or more complex handovers may need a proper overlap with a successor.

Where the leaver holds specific management system responsibilities (for example an internal auditor, a site H&S lead or an information security officer), the transition needs to be captured in the relevant register or competency matrix. Gaps in responsibility after a key person leaves are a common finding in audits.

Removing Access and Recovering Assets

Offboarding needs to systematically remove access and recover organisation property:

  • IT access - email, systems, shared drives, VPN, cloud services, software licences, multi-factor authentication tokens. Access should be revoked on or before the last day (earlier for higher-risk departures).
  • Physical access - keys, fobs, passes, alarm codes, vehicle keys.
  • Equipment - laptops, phones, tools, PPE, uniforms, ID cards.
  • Information - any physical files, notebooks, or records returned. Personal copies of company information should be deleted in line with policy.

For roles with access to sensitive data, this step is particularly important. Information security management relies on access being actively managed across the whole employee lifecycle, including the exit. Where an IT account is no longer needed but may hold evidence needed later (for example, during an investigation), it should be disabled rather than deleted and retention managed accordingly.

Final Administrative Steps

The last steps in offboarding are administrative but matter to the leaver and the business equally:

  • Final salary calculated, including holiday pay owing and any notice-related payments.
  • Pension and benefits arrangements closed off or continued as required.
  • Tax documents issued in line with local requirements (in the UK, a P45 from HMRC payroll).
  • References policy communicated - whether the organisation provides references, who signs them, and what they include.
  • Personnel records retained for the period required by data protection and employment law, then securely deleted.

Exit Interviews and Learning from Leavers

An exit interview captures why the person is leaving and what they would change about working there. It is one of the few moments where someone can speak honestly without worrying about consequences. Feedback should be collected, anonymised where appropriate, and reviewed for patterns at management level. Recurring themes in exit interviews are a useful input to management review and to the organisation's approach to people management.

Some leavers decline to give feedback at exit interviews, and that is their right. Written surveys with an option to remain anonymous often get better responses than face-to-face interviews.

From an ISO perspective, offboarding touches several clauses. Clause 7.1.2 covers the people resource needed, which includes managing transitions. Clause 7.5 covers the documented information that needs to be retained or disposed of. For ISO 27001, offboarding is specifically called out under access control. A checklist that pulls all of this together is much simpler than trying to run each as a separate process.

We use a leaver checklist signed off by HR, line manager and IT. It covers handover, access removal, equipment return, final pay and references policy. The last day includes a formal confirmation that everything has been returned and access is disabled.

Exit interviews are done by someone outside the direct reporting line. Line managers often get more honest feedback through a written survey a week after the person has left than they would face-to-face on the last day.

When auditing information security I check offboarding against specific cases. A current list of live accounts cross-referenced with current employees quickly shows whether access is being removed promptly. Accounts for people who left months ago are one of the most common findings I see.

Offboarding does not need to be complicated. Handover, access off, kit back, final pay, references sorted. A one-page checklist per leaver with dates and signatures gives you everything you need. Keep the exit interview short and make the questions open.

Practical Compliance Guidance

Section 3.1 of the IMS1 IMS Manual covers the management of staff, including the arrangements for handling leavers as the final stage of the employee lifecycle.

Several alphaZ documents support a structured approach to leavers and offboarding:

alphaZ document How to use it
ISO 9001, 14001 & 45001 IMS Toolkit The complete toolkit for an integrated management system covering quality, environment and health and safety.
PP-1-11 Employee Recruitment, Onboarding and Leaving Policy Policy and procedure covering the full employee lifecycle, including the steps required when someone leaves the organisation.
F-HR13 Staff Exit Interview Structured exit interview form to capture feedback from leavers about their experience and reasons for leaving.
ER2 Staff Training Competency Matrix Register used to identify where a leaver's competence needs to be replaced or covered, and to update records on departure.
GEN1-1 General Staff Handbook Consolidated staff handbook covering company policies, including the processes and expectations around leaving employment.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

On or before the last working day for most leavers, and immediately for higher-risk situations such as dismissal or where the departure is not on good terms. Information security management requires access to be removed promptly. A shared leaver notification process between HR and IT avoids accounts being left active after the person has gone.
Retention periods vary by jurisdiction and record type. In the UK, HMRC records typically need to be kept for six years, while other records have different retention periods. The organisation's data retention schedule should set out what is kept, for how long, and when it is securely deleted. Employment-related records that may be needed for references or disputes are usually kept for at least six years.
No. Exit interviews are good practice but not legally required. The leaver can decline to participate. Where one is offered, it should be voluntary, not used to raise last-minute concerns that have not been dealt with through other channels, and the feedback should be acted on at management level rather than filed and forgotten.
Usually a combination of HR, the line manager and IT, coordinated through a leaver checklist. HR typically owns the overall process, the line manager handles handover and knowledge transfer, and IT handles access and equipment. In smaller organisations one person may cover all three, but the steps remain the same.

UK Legislation

The following UK legislation is relevant to leavers and offboarding. Organisations outside the UK should identify the equivalent legislation applicable in their jurisdiction.

Further Resources

payment logos