FillTrust

How to answer

How quickly is access revoked when someone leaves?

The strongest version of this answer is not a time. It is a single action that covers everything, plus a list of what it does not.

A model answerConfirmed in your documents

Access is revoked on the employee's last working day. Accounts are disabled through [your identity provider], which removes access to all connected systems in a single action, and the offboarding checklist covers any system not behind it.

Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.

Answered from
Your offboarding checklist and your access control policy.
Evidence to attach
Sometimes a copy of the offboarding checklist itself, which is usually fine to share once names are removed.
Where it is asked
CAIQ v4.0 · IAM-07SIG LiteISO 27001 Annex A · A.5.18

Reviewers ask this because departing staff are the most common source of forgotten access, and because the answer is easy to verify later: they can ask for the last three offboardings and the dates access was removed.

A time on its own is a weak answer. "Immediately" prompts the obvious question of what starts the clock, and "within 24 hours" is fine only if something makes it happen. The strong version names the trigger and the mechanism: on the last working day, by disabling the account in the identity provider.

Single sign-on is the reason this question is easy or hard. If your systems are behind one identity provider, disabling one account is the whole control and the answer is short and convincing. If they are not, offboarding is a list of eleven things somebody has to remember, and the honest answer is a checklist. A checklist is acceptable. A checklist you can produce is better than a claim you cannot.

Name the exceptions. There is always at least one system outside SSO: the cloud provider's root account, a domain registrar, a payment processor, a shared entry in a password manager. Reviewers know this and are more reassured by an answer that names the exceptions and says how they are handled than by a blanket claim that everything is centralised.

Contractors and long absences. Two edge cases worth a sentence. Contractors often have no payroll event to trigger anything, so their access should be time-bound at the point it is granted. Long leave is a different question from leaving, and most companies do not revoke for it, which is fine to say.

The one thing to fix if it is broken. Personal accounts on shared services, where the leaver's own email address is the login. These outlive offboarding by years, and the question that surfaces them is usually this one. Moving them to a role account is worth doing regardless of who is asking.

How this one goes wrong

Specific to this question, not general advice.

  • Answering "immediately" without saying what triggers it. Immediately after what, and who does it?
  • Forgetting the systems outside your identity provider. There is always one: a shared password manager entry, a cloud provider root account, a vendor portal with its own login.
  • Not covering contractors, whose end date is often the day work stops rather than a payroll event anybody is tracking.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.