Join our Newsletter — 33% off our NHI Course

What should teams do when former employees still appear in renewal counts?

Treat that as an offboarding and access cleanup problem, not a billing quirk. Remove the stale accounts, reclaim the licences, and verify that entitlement records match current employment status before the contract is renewed. Otherwise, the organisation keeps paying for access that no longer exists.

What makes former employees in renewal counts an access problem?

Renewal reports should reflect current entitlement, not historical headcount. If former employees still appear, the real issue is that joiner-mover-leaver controls have not fully closed the loop: the account, licence, or entitlement is still live somewhere in the stack, even though the person has left. Treat that as a governance and hygiene failure that needs cleanup before renewal, not after.

The key check is simple: a renewal count should map to an active business need, an active owner, and a current employment status. If those three do not line up, the count is overstating demand and hiding stale access. That is why offboarding reviews, access recertification, and licence reconciliation belong in the same workflow.

In practice, teams should ask whether the count is being driven by active use, inactive but still assigned access, or duplicate records across HR, IAM, and SaaS admin consoles. The answer determines whether you are looking at an entitlement problem, a discovery problem, or both. The remediation is the same directionally, but the source of truth may differ.

How should teams clean up the renewal signal?

Start by identifying every former employee still included in the vendor or internal renewal view, then trace each one back to the account or licence record that created the mismatch. Remove or disable the stale account where it is no longer required, reclaim the licence, and confirm that the entitlement record now matches the person’s employment status. For broader lifecycle control, the NHI Lifecycle Management Guide is useful because the same offboarding discipline applies to standing access and credential cleanup.

Where ownership is unclear, assign the record to the system owner or manager before the next renewal cycle. If an account is retained for a valid exception, document why it exists, who approved it, and when it will be reviewed again. That avoids “zombie” entitlements being carried forward simply because nobody wants to challenge the renewal list.

Teams also need to reconcile renewal counts against discovery data. If the vendor shows 120 licences used but only 108 active employees remain, investigate whether the gap is dormant access, shared accounts, delayed deprovisioning, or inaccurate reporting. The goal is not just to shrink spend, but to make the renewal figure operationally trustworthy.

Why this matters before the contract is renewed

If former employees remain in renewal counts, the organisation is likely paying for access that should have been removed and may also be carrying unneeded privilege. The same control failure can hide inactive accounts, weak offboarding, and delayed revocation, which creates avoidable exposure if a stale credential or account is later abused. The Top 10 NHI Issues covers the broader pattern of stale accounts, excessive permissions, and access governance drift.

This is especially important when licences or accounts grant access to production systems, data exports, admin functions, or integrations. In those cases, a renewal mistake is not only a financial waste, it can preserve access paths that should already have been closed. Treat the renewal review as a control point for both cost and exposure.

A useful signal is whether the renewal list changes when HR termination data is cross-checked. If the answer is no, the organisation is probably relying on manual clean-up instead of a reliable deprovisioning process. That is the point where the issue stops being a billing discrepancy and becomes a control gap.

Risk and Threat Considerations

Former employees in renewal counts often indicate more than excess spend. Stale accounts, unrevoked licences, or lingering entitlements can preserve a path for unauthorized use long after employment ends, especially if credentials were not rotated or the account was never actually disabled.

Failure mechanism: offboarding does not fully propagate into downstream systems, so the renewal view, the access view, and the HR view diverge. That leaves dormant access available for misuse, accidental retention, or repeated renewal of an unnecessary entitlement.

Impact: the organisation can overpay for licences, carry hidden access risk, and renew a contract on faulty inventory. In the worst case, a stale account becomes the easiest surviving path into a system that teams assumed had already been closed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Former employees in renewal counts signal stale access and incomplete offboarding.
NHI-05 — Overprivileged NHI Retained licences or entitlements can preserve unnecessary access beyond employment.
Recommendation — Reconcile offboarding records and revoke any lingering access before renewal. Review retained entitlements and remove excess access before extending contracts.
NIST SP 800-53 Rev 5 AC-2 — Account Management The issue is account lifecycle cleanup, removal, and validation of current status.
IA-5 — Authenticator Management Lingering access often involves unmanaged credentials or tokens tied to departed users.
Recommendation — Disable inactive accounts and verify account status against employment records. Revoke or rotate credentials associated with departed users and confirm removal.
ISO/IEC 27001:2022 A.5.16 — Identity management Identity records must match current personnel status to keep renewal counts accurate.
Recommendation — Align identity records with HR leaver data before approving renewal.

Practitioner Guidance

What to prioritise: treat any former employee in the renewal count as a deprovisioning exception first, and a procurement issue second. The fastest value comes from proving whether the record reflects a live account, a dormant licence, or a stale report row.

What to verify: confirm that the termination date, account disablement date, and licence removal date line up. If they do not, keep the renewal blocked until the discrepancy is explained and the entitlement owner signs off on the exception.

What good looks like: renewal counts should reconcile to active staff with a documented business need, and any retained access should have an explicit owner, justification, and expiry date. Where teams need a cryptographic or lifecycle discipline analogue for access material, NIST SP 800-57 Key Management is a useful reminder that lifecycle control matters as much as initial issuance.

Practitioner takeaway: do not let renewal reporting become a passive billing artefact; use it as an active test of whether offboarding, entitlement cleanup, and inventory accuracy are actually working.