Try this before you read any further

Pick somebody who left in the last twelve months. Write down every system they could log into on their last day. Then check each one.

In a company of forty people that exercise takes about an hour, and it almost never comes back clean. The usual result is two or three live accounts, one shared password nobody has changed, and at least one service nobody knew the company was still paying for.

What “removing access” actually covers

Most offboarding checklists give IT a single line: disable the email account. That is the smallest part of it. The real surface in a mid-sized company looks more like this.

  • Email, and any mail still syncing to a personal phone
  • VPN, remote desktop and anything reachable from outside the office
  • The accounting system, and the e-invoicing portal login
  • Online banking, including any physical token or approver role
  • Shared drives, and the personal cloud folder they kept work files in
  • WhatsApp groups with customers, suppliers and staff in them
  • Subscriptions bought on a personal card and expensed
  • The CCTV app, the door system and the office Wi-Fi password
  • Code repositories, hosting panels and the domain registrar
  • Any phone number or personal address still receiving password resets

Why it survives every policy you write

The checklist lives with HR, because leaving is an HR event. But HR cannot list systems they have never used, and the list changes every time somebody signs up for a new tool. So it ages badly, quietly, and nobody notices until a real departure tests it.

The fix is not a better form. It is keeping the list somewhere that is maintained for a different reason, and reusing it here.

The four we find most often

1. Shared accounts

The info@ mailbox, the accounting login four people use, the admin password on the server. You cannot remove one person from a shared password, so in practice nobody tries. Everybody who ever knew it still knows it, including the people who left. Shared accounts also destroy any ability to say who did something, which is the first question asked after anything goes wrong.

2. Mail still signed in on a personal phone

The account was disabled on the laptop. The phone held a token and kept syncing, sometimes for weeks. Without mobile device management you cannot see this and you cannot stop it remotely. Forcing a password reset and revoking active sessions is the step people skip.

3. Services bought on a personal card

Somebody needed a tool, expensed it, and became the only account holder. When they leave you do not merely fail to remove their access — you lose the service, along with whatever company data sits inside it. This is a continuity problem before it is a security one, and it is the one that costs real money to unpick.

4. Password resets pointing at the leaver

The recovery number on a critical account is still theirs. The two-factor codes still arrive on their handset. Every other control you have can be correct, and that one line undoes them.

Why this is a compliance problem too

It is tempting to file this under IT housekeeping. Nobody assessing you files it there.

  • ISO 27001. Access management and return of assets are explicit control areas. An auditor will ask for your leaver list and sample it. There is nowhere to hide in that test, because the evidence is a date next to a name.
  • Data protection. If a former employee can still reach personal data — and employee records count — you no longer control who processes it. That is precisely the position the law exists to prevent.
  • Financial records. A leaver with a live login to the accounting system or the e-invoicing portal is an audit finding waiting to happen, and a genuinely bad answer to give an inspector.

Half a day of work, then a habit

  • Write the system register: every system, who owns it, who can log in, what it costs and whose card pays for it. A data protection exercise needs this same register, so build it once and use it twice.
  • Kill shared accounts wherever a named login is possible. Where it genuinely is not, put the password in a shared vault so it can be rotated the day somebody leaves.
  • Move the leaver checklist so it starts with IT and is signed off by IT, with HR notifying rather than owning.
  • Revoke sessions, not just passwords. A disabled account with a live token on a phone is still an open door.
  • Review access quarterly. Print who can reach each system, hand it to the manager who owns that system, and make them confirm the list. Twenty minutes, and it catches what offboarding missed.
  • Check the recovery numbers and addresses on your most critical accounts today.

The point

Nobody is doing this badly on purpose. It falls down because it sits between three departments — HR knows who left, IT knows what the systems are, finance knows whose card is paying for them — and the work only makes sense when those three lists are in the same room.

That gap is the reason we put technology, compliance and accounting under one roof. More on the access side under Technology & Security.

No client of ours is described in this article.