The average company between 50 and 200 people is paying at least a few vendors it has effectively stopped using. The subscription is running. The licence fees are being deducted. Nobody has formally ended the relationship because it hasn't caused a problem yet.
It causes a problem eventually. Usually when someone notices the charge, or when a security audit finds that former employees still have active accounts with a vendor the company no longer uses, or when a vendor's auto-renewal fires and the contract extends for another 12 months.
Vendor offboarding is the process of formally ending a vendor relationship. Done well, it's straightforward. Done badly, or not at all, it creates security exposure, contract liability, and ongoing costs.
Why vendor offboarding gets forgotten
The immediate answer is prioritisation: onboarding a new vendor creates something useful, and offboarding an old one creates nothing visible. The business moves on.
The structural reason is that SaaS vendor relationships don't end automatically. A subscription continues until it's cancelled. Access credentials remain active until they're revoked. Data stored with the vendor doesn't disappear because you stopped using the service.
For businesses with more than a handful of vendors, this creates accumulation. Every vendor relationship that wasn't properly offboarded adds to the surface area the business is responsible for, even if nobody is actively managing it.
The security dimension is significant. Verizon's 2025 Data Breach Investigations Report found that:
Third parties were involved in 30% of data breaches in 2024, up from 15% the prior year. The doubling reflects the expansion of vendor access to business systems, and the inconsistency with which that access is managed when vendor relationships end.
The access point is almost always a credential that wasn't revoked. A former employee's login, an API key that continued to function, a service account that was never decommissioned.
The vendor offboarding checklist
This checklist applies to software vendors and, with adaptation, to agencies, contractors, and service providers. Work through it in order.
1. Confirm the notice period and provide formal written notice
Check the contract for the required notice period before cancellation. Many SaaS contracts require 30 or 60 days' notice before the renewal date. If the notice period is missed, the contract typically auto-renews. Send a written cancellation notice (email is usually sufficient if the contract doesn't specify otherwise) and keep a record of when it was sent.
If there is no formal contract, check the vendor's terms of service. Most SaaS platforms publish their cancellation and refund policies in their terms, and these are binding regardless of whether a separate contract exists.
2. Revoke user access
Identify every account associated with the vendor's platform. This includes current employees with active logins, former employees whose access was never revoked, service accounts, and API keys or integrations connecting to the vendor's system.
This step is harder than it sounds for SaaS platforms, because user provisioning is often decentralised. An app signed up for by one team member may have added users from multiple departments without being tracked centrally. Check the vendor's user management panel directly, not just your internal list.
Revoke access before the cancellation takes effect, not after. A pending cancellation doesn't automatically deactivate user accounts.
3. Retrieve or delete your data
Request an export of any data stored with the vendor before the account closes. This includes documents, records, configurations, and anything generated through the platform that you may need later. Most vendors provide data export functionality, but the format varies and some exports require a support request.
Once you've confirmed the export, request deletion of your data from the vendor's systems, particularly for any personally identifiable information (PII) related to your customers or employees. Under the Australian Privacy Act and GDPR for any EU data subjects, vendors are required to honour data deletion requests, though response times vary.
Check what the vendor's data retention policy says about how long they keep data after account closure. Some vendors retain data for 30 or 60 days to allow for account recovery. Others retain it longer by default unless explicitly requested to delete.
4. Settle final invoices and reconcile payments
Confirm any outstanding invoices with the vendor before the account closes. Check for charges that may be generated between the cancellation notice date and the effective end date, particularly for usage-based pricing where a final reconciliation is common.
If you've been paying by credit card or direct debit, cancel the payment authority with your bank or card provider after confirming the final invoice is settled. Vendors occasionally continue charging after cancellation due to system errors, and having a cancelled payment authority prevents ongoing deductions from going unnoticed.
5. Update your vendor registry
Mark the vendor as offboarded in your vendor records with the date the relationship formally ended. Note the reason for offboarding, the notice date, and the effective end date. If there are surviving obligations (confidentiality clauses, data retention commitments the vendor made to you), note these as well.
This record matters if questions arise later. A vendor claiming non-payment for a period after you cancelled is much easier to dispute with documented notice dates and any confirmation received.
The cost of poorly managed vendor access is not hypothetical. IBM's 2025 Cost of a Data Breach report found that:
The average cost of a data breach involving a supply chain compromise reached $4.91 million in 2025, making third-party vendor access one of the most expensive breach vectors for organisations of any size.
Most of those incidents trace back to access that should have been revoked.
The harder case: agencies and contractors
The checklist above focuses on SaaS vendors. Ending relationships with agencies, consultants, and contractors involves additional considerations.
Intellectual property assignment: confirm that any work product created during the engagement is assigned to your business, or clarify the licence terms if full assignment wasn't agreed. For creative work, software development, and strategy deliverables, this is frequently left ambiguous in the original contract and rarely clarified at offboarding.
System access: agencies and contractors often have access to your cloud platforms, code repositories, advertising accounts, social media profiles, or CRM. Revoke access to each of these directly, not through the agency's offboarding process (which may not actually remove their team's individual credentials).
Reference and portfolio agreements: if the agency or contractor plans to use the work in their portfolio or reference your business in their marketing, confirm what was agreed about this in the original contract. In the absence of an explicit agreement, IP ownership and usage rights vary by jurisdiction and by the nature of the engagement.
What this looks like as a standing practice
The businesses that handle vendor offboarding well don't do it better in the moment of cancellation. They have a vendor registry that makes each relationship visible: what's active, when it's up for renewal, who is responsible for it. When a relationship ends, the offboarding steps are known because the relationship was tracked from the start.
Ensurva builds the registry automatically from your accounting data. Every vendor you've paid appears in a single view, with spend history and contract status where recorded. When it's time to offboard a vendor, you start from an accurate picture of what you're ending, rather than working backward from a charge on the credit card statement.




