Join our Newsletter — 33% off our NHI Course

Post-Termination Access Audit

A post-termination access audit is a review of every system, application, and account a former employee could access before and after departure. It helps teams identify hidden privileges, shared credentials, vendor connections, and lingering access that could allow unauthorized entry, data removal, or misuse after employment ends.

What a post-termination access audit actually examines

A post-termination access audit is not just a badge review. It checks whether the former worker still had valid pathways into systems, applications, shared tools, vendor portals, and any delegated access that should have ended with employment.

The core value is completeness. Teams look beyond the obvious employee account to find secondary access paths such as shared credentials, group memberships, recovery methods, admin consoles, and third-party integrations that can survive a normal offboarding flow.

Why lingering access becomes a security control problem

Lingering access turns a personnel event into an access-control gap. If termination is not followed by verification, residual privileges can remain usable even when HR records, directory status, and manager expectations all say the person is gone.

This is especially important where the departed user had broad entitlements, access through another team’s application, or access to shared operational accounts. A clean offboarding workflow can still miss inherited roles, cached sessions, or alternate authentication paths.

Post-termination review also helps expose account sprawl. It is common for former staff to retain access through legacy systems, vendor-managed tools, or long-forgotten exceptions that were never folded back into a formal access register. NHIMG’s IAM and IGA Basics is a useful companion for understanding how entitlement review and governance fit that problem.

What auditors and security teams are looking for

The audit typically asks three questions: what access existed before termination, what access was removed at departure, and what still works after the departure date. That means comparing identity records, privilege assignments, application access, shared account usage, and any recovery or delegation paths that can re-enable entry.

Teams also look for evidence of control failure, not just absence of revocation. For example, a terminated employee might no longer have a primary login but could still use a federated session, a shared service credential, or a vendor account tied to a business process. NHIMG’s Joiner-Mover-Leaver (JML) Guide is closely related because post-termination review is often the verification step after deprovisioning.

Where the audit touches machine or non-human access, the same logic applies to keys, tokens, and service credentials that outlive the human owner. NHIMG’s NHI Lifecycle Management Guide explains why offboarding must include credential rotation, ownership cleanup, and visibility into dormant access paths.

Why the issue matters after departure, not just during offboarding

Termination is a high-risk transition because trust is being withdrawn at the same time that systems may still be carrying stale permissions. A missed access path can enable unauthorized entry, data removal, policy circumvention, or misuse of internal tools after the employment relationship ends.

That risk is not limited to malicious insiders. It also covers benign but dangerous leftovers, such as an ex-employee who can still open a ticketing platform, export records from a business app, or use a shared admin login that was never rekeyed. In practice, the audit is a way to prove that access removal was effective everywhere it mattered.

NHIMG’s Top 10 NHI Issues is a broader reference for the kinds of excessive permission, stale account, and shared access patterns that post-termination review is designed to catch.

Risk and Threat Considerations

A post-termination access audit addresses the gap between formal departure and actual access removal. If former users still retain active entitlements, the organisation may not notice until data is accessed, altered, or exfiltrated through a path that was assumed to be closed.

Failure mechanism: Offboarding removes the primary account but leaves behind secondary access paths, such as shared credentials, cached sessions, inherited roles, vendor logins, or unrotated keys and tokens.

Impact: A departed user, or anyone who obtains the leftover access, can still enter systems, misuse trust, and create post-employment exposure that is harder to detect because the access looks familiar or legitimate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Post-termination audits verify accounts are removed or disabled after exit.
IA-5 — Authenticator Management The term includes lingering credentials, tokens, and keys that outlive departure.
AC-6 — Least Privilege The audit checks whether residual permissions exceed what is still justified after exit.
Recommendation — Review and disable any lingering accounts or access after termination. Rotate or revoke authenticators and secrets that a former user could still use. Remove any remaining permissions that are no longer required.
CIS Controls v8 CIS-5 — Account Management CIS account management directly supports finding and removing orphaned or stale access after termination.
Recommendation — Verify that stale, shared, or orphaned accounts are removed promptly.
ISO/IEC 27001:2022 A.5.16 — Identity management Identity management covers lifecycle control of user access before and after departure.
A.8.2 — Privileged access rights Post-termination audits often uncover residual admin or elevated access that should have ended.
Recommendation — Ensure identity records are updated when a user leaves. Revoke privileged access that remains after termination.

Practitioner Guidance

What to watch for: The most common failure is partial deprovisioning, where one identity is closed but the real access path survives elsewhere. Treat any mismatch between HR departure records and actual system reachability as a control exception, especially when shared accounts, contractors, vendors, or administrative roles are involved.

Governance implication: Make the audit a formal post-exit control, not an informal cleanup task. The point is to confirm that access removal is complete across systems, not just to verify that a ticket was closed.