Cyber Prepared
← Third-Party Risk
Version 1.4Updated May 27, 2026

SaaS Vendor Offboarding Protocol

Close the security gaps that appear when a SaaS relationship ends. This protocol coordinates business owners, identity teams, procurement, privacy, and the vendor around access revocation, integration shutdown, data disposition, retention exceptions, and evidence of completion.

saasoffboardingdata-deletionaccess
Inside the document
  1. 01Exit trigger and ownership model
  2. 02Account and integration inventory
  3. 03Access revocation checklist
  4. 04Data return and deletion evidence
  5. 05Residual-risk closure record

Make the exit verifiable

Assign evidence to every offboarding action so completion means more than a closed procurement ticket.

Covers the long tail

The protocol includes service accounts, API keys, exports, retained backups, legal holds, and downstream subprocessors.