What should supplier termination and offboarding cover?
Create a before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036-2:2022 requires the supplier relationship agreement to contain a termination process and plan. At termination, the parties decide whether supply is cancelled, returned to the acquirer, or transferred to another supplier; maintain an asset inventory; agree asset return, transfer, destruction, or retention; remove access; communicate with affected parties; and confirm completion. The standard does not set a universal notice period, deletion deadline, or retention period; the agreement and applicable law supply those dates.
- Before signing, define notice, sudden-termination handling, transition assistance, data format and export, asset handling, access removal, retention and deletion, surviving duties, evidence, acceptance, cost, timing, and escalation.
- At exit, appoint an owner, assess any security reason for termination, activate continuity arrangements if sudden loss affects a critical service, and decide whether to cancel, bring the work back, or transfer it.
- Close the relationship only after the parties verify the agreed outcome and an authorized owner approves any retained asset, unresolved action, or residual risk.
Part 2 requires termination planning in the agreement and specifies risk assessment, ownership, communication, asset inventory, transfer or cancellation, access removal, and completion agreement.
Part 4 adds cloud guidance for customer asset transition, return or disposal, disposal confirmation, and disposal logs.