FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ Termination and Offboarding

What should supplier termination and offboarding cover?

Part 2 contains supplier and acquirer relationship requirements; the other parts provide concepts or guidance. Apply the relevant part proportionately and verify contractual, legal, and customer duties separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Create a before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should supplier termination and offboarding cover?

Create a before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.

ISO/IEC 27036-2:2022 requires the supplier relationship agreement to contain a termination process and plan. At termination, the parties decide whether supply is cancelled, returned to the acquirer, or transferred to another supplier; maintain an asset inventory; agree asset return, transfer, destruction, or retention; remove access; communicate with affected parties; and confirm completion. The standard does not set a universal notice period, deletion deadline, or retention period; the agreement and applicable law supply those dates.

  • Before signing, define notice, sudden-termination handling, transition assistance, data format and export, asset handling, access removal, retention and deletion, surviving duties, evidence, acceptance, cost, timing, and escalation.
  • At exit, appoint an owner, assess any security reason for termination, activate continuity arrangements if sudden loss affects a critical service, and decide whether to cancel, bring the work back, or transfer it.
  • Close the relationship only after the parties verify the agreed outcome and an authorized owner approves any retained asset, unresolved action, or residual risk.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires termination planning in the agreement and specifies risk assessment, ownership, communication, asset inventory, transfer or cancellation, access removal, and completion agreement.

Question 2

What should the offboarding checklist verify?

Verify the service outcome and every access, asset, information, integration, and dependency affected by exit. The checklist should identify the responsible acquirer and supplier roles, due date, evidence, exception route, and completion approver for each item.

Return or deletion must follow the agreement and applicable retention, legal-hold, recordkeeping, and technical constraints. Distinguish active data, replicas, backups, logs, physical media, devices, source material, and records that must survive termination. Do not promise deletion where a binding duty requires retention.

  • Revoke named and shared accounts, privileged roles, physical access, keys, tokens, certificates, federation, remote support, network routes, and application integrations; rotate secrets exposed to the supplier.
  • Reconcile the asset inventory and document return, transfer, permitted retention, sanitization or destruction, chain of custody, and any required confirmation or disposal log.
  • Resolve or transfer open incidents, vulnerabilities, findings, corrective actions, tickets, changes, backups, continuity actions, intellectual-property material, and subcontractor obligations.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 makes an up-to-date asset inventory, agreed asset disposition, timely access removal, communication, execution, and completion confirmation part of termination.

Question 3

What evidence closes the relationship?

Retain the termination decision, risk assessment, current agreement and plan, communication record, named owner, asset inventory, access-removal results, transfer or cancellation acceptance, data export and integrity checks, return or disposal records, approved retention, exception decisions, and confirmation that the parties agree the supplied product or service has ended.

Evidence must match the actual scope. A generic deletion statement does not show which tenant, system, copy, backup, log, device, or subcontractor it covers. Record technical limits, scheduled expiry, continuing safeguards, and the person who accepted any remaining exposure.

  • Verify surviving confidentiality, audit, incident-cooperation, intellectual-property, warranty, retention, and deletion duties.
  • Do not let contract expiry automatically close operational access or open actions.
  • If termination is disputed or involves legal, regulatory, employment, insolvency, or evidence-preservation issues, obtain case-specific advice; ISO/IEC 27036 does not decide those rights.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 defines required termination activities and outputs but leaves case-specific legal rights and duties to the agreement and applicable law.

Primary sources

References and citations

iso.org
Referenced sections
  • Part 2 defines required termination activities and outputs but leaves case-specific legal rights and duties to the agreement and applicable law.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.