GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-007 Termination and Access Revocation

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Upon termination or role change, all logical access rights are revoked within a defined timeframe. The termination process includes retrieval of physical assets, disabling of authentication credentials, review of ongoing confidentiality obligations and a documented offboarding checklist. Asset return obligations are written into employment and contractor agreements. The same process applies to contractors and third-party personnel. Where an insider risk indicator against an individual is confirmed, that individual's accounts and sessions are disabled within a defined period of the confirmation, independently of any termination or role change.

Rationale

Access that persists after employment ends is a direct path for unauthorised access or data exfiltration, and a time-bound revocation process limits the exposure window and evidences completion. The insider risk clause covers the case the leaver process misses entirely: an individual who is still employed and still in role, against whom something has been confirmed. GOV-027 runs the programme that raises and confirms the indicator; HRS-007 carries the account action that follows and the clock on it.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (14)

HRS-05Asset returnsfull
HRS-06Employment Terminationfull
HRS-05Asset returnsfull
HRS-06Employment Terminationfull
HIPAA-164.308.a.3.ii.CTermination Proceduresfull
5.11Return of assetsfull
6.5Responsibilities after termination or change of employmentfull
NIS2-CIR-10.3Termination or Change of Employment Proceduresinformative
NIS2-CIR-12.5Deposit, Return or Deletion of Assets upon Termination of Employmentfull
AC-2(13)Account Management | Disable Accounts for High-risk Individualsfull
PS-4Personnel Terminationfull
PS-5Personnel Transferfull
PS-7External Personnel Securitypartial
CC6.2Prior to Issuing System Credentials and Granting System Accessinformative

Evidence (4)

contractdocumentmanual

Employment agreement clause or exit declaration confirming ongoing confidentiality obligations and asset return requirements are signed by the employee.

Example: Employment agreement template (legal counsel-approved document), Section on Termination Obligations, referencing: return of all company property, ongoing confidentiality obligations post-employment, and prohibitions on retaining copies of organisational data, signed by a sample of recent hires.

Test: Request the employment agreement template and a signed copy for a sample of three current employees and three recent terminations. Verify: (1) asset return obligation is explicitly stated, (2) ongoing confidentiality requirement post-employment is present, (3) the signed agreement is on file for each sampled individual.

recorddocumentmanual

Completed offboarding checklists confirming logical access revocation and physical asset retrieval were completed within the defined timeframe for a sample of terminated personnel.

Example: Offboarding workflow records (ServiceNow / Jira / HRIS offboarding module) for a sample of terminated employees and contractors, showing: termination date, access revocation date and time, asset return confirmation, and completed checklist sign-off.

Test: Request offboarding records for at least five terminations in the last 12 months (including at least one contractor). For each, verify: (1) access revocation occurred within the defined SLA (e.g. same-day for involuntary termination, by last day for voluntary), (2) physical asset return is confirmed, (3) the offboarding checklist is fully completed with a named verifier and date.

configurationtechnicalautomated

IAM system export showing no active accounts belong to terminated employees or contractors.

Example: Active user account export from Okta, Azure AD, or AWS IAM, cross-referenced against the HR termination log, showing no account is active for any individual whose termination date has passed.

Test: Export the list of active user accounts from the IAM system. Cross-reference against the HR list of terminations in the last 12 months. Verify: (1) no terminated employee or contractor has an active login-capable account, (2) any service accounts associated with terminated individuals are also disabled or re-owned, (3) the check is repeatable via a scheduled report or script.

recorddocumentmanual

Records of accounts disabled on a confirmed insider risk indicator, showing the elapsed time from confirmation to disablement.

Example: Insider risk account action log 2026, cross-referenced to GOV-027 case records

Test: Request the disablement records for confirmed insider risk indicators. Verify: (1) each confirmation raised in the period resolves to a disablement record, (2) the elapsed time from confirmation to disablement is within the defined period, (3) the disablement covered every account and active session the individual held rather than the primary account alone, (4) re-enablement, where it happened, carries a recorded decision and an approver, (5) where no indicator was confirmed in the period, the disablement path was exercised on a test account and the elapsed time recorded.

Questions (3)

boolean

Are all logical access rights revoked within a defined timeframe on termination or role change?

Completed offboarding checklists should show access revocation dates and confirm the SLA was met (typically same-day for involuntary terminations).

select

What is your defined maximum timeframe for revoking all logical access after an involuntary termination?

Immediately / same dayWithin 4 hoursWithin 24 hoursWithin 3 business daysNo defined SLA: access is revoked when IT processes the request

Same-day revocation for involuntary terminations is the expected standard. IAM export cross-referenced against the HR termination log is the verification evidence.

multi

Which of the following does your offboarding process cover?

Contractors and third-party personnel on the same terms as employeesDisabling of every authentication credential the individual heldRetrieval of physical assets, with the return obligation written into the agreementReview of ongoing confidentiality obligationsRe-owning or disabling service accounts the individual heldAccounts and sessions disabled within a defined period where an insider risk indicator against the individual is confirmedNone of the above

Options run from the most commonly covered to the least. Contractor access is the gap that outlives the engagement, because the trigger for offboarding sits with the engaging team rather than with human resources. The last item runs on its own trigger and does not wait for a termination.