You revoked their email, not their company card

By Rajith Shaji, Co-Founder and CEO of Volopay

Want to hear a six-word horror story? Former employee, still approving your invoices.

A typical offboarding runs smoothly, with email cut off within the hour and Slack closed by evening. The laptop usually comes back before the farewell cake is finished. However, in many Indian organisations, spending authority follows a completely separate path because finance owns different systems, workflows, and access records.

Former employees retaining enough authority to approve financial activity sounds extreme, but the CAG has already documented it.

In its 2025 audit of United India Insurance Company, 39 retired-employee credentials generated 196 approval requests across intermediaries, discounts, claims, and related activity. Two additional retired-user credentials were also used for five claim approvals.

Corporate cards create another version of the same exposure. A 2025 Canadian government audit found 5% of deactivated acquisition cards remained open for more than 30 days after departure.
You probably run a solid access process already, so this article looks at the part of offboarding that sits with finance.

We will cover:
Why spending authority escapes the usual checklist.
How a live subscription keeps your data within reach of someone who has moved on.
What a combined checklist should contain.

I’ve also prepared a simple audit you can run on your own to find orphaned cards, subscriptions, and approval rights before they create a wider access problem.

Financial Access Sits Outside the Identity Stack
In general, offboarding checklists are built around identity, so they cover whatever your directory or single sign-on can reach. Spending authority sits outside that reach for three reasons:

The trigger goes to IT – HR raises the exit ticket with IT, while finance usually hears later through a separate message, if it hears at all.

The systems are separate – Cards live with the issuing bank and approver roles live inside the ERP, so disabling an email address leaves both untouched.

The owners differ – Finance or procurement runs these tools, so IT has no view of them, and finance has no prompt to act.

Because no single trigger reaches both teams, each one finishes its checklist without knowing what the other left open.

Residual Data Exposure Through Orphaned Subscriptions
Now, picture a leaver who signed up for an analytics tool and paid for it on the corporate card. If ownership stayed with the departing employee, nobody inside IT may have the permissions required to inspect the account before closing it.

The card keeps billing as usual, the account stays open, and any files or customer records uploaded there remain accessible. API keys and connected apps stay active too, which means the tool can keep pulling data from your systems.

A survey of 1,200 US workers found around 40% had used passwords from a former employer after leaving the company. The findings also pointed to weak controls around password reuse and post-employment access.

The DPDP Act, 2023 expects reasonable security safeguards over the personal data companies hold. The 2025 Rules name access controls among them, and a lapse can draw a penalty of up to ₹250 crore.
A subscription still being charged is the clearest sign that the access behind it still works.

For your offboarding review, a post-exit subscription charge should therefore lead to four checks:

Current owner.
Active administrators.
Connected integrations.
Data retained inside the service.

Components of an Integrated Offboarding Framework
An integrated process should protect continuity as carefully as it removes access.
If you cancel a card before identifying recurring payments, essential services can fail. If you disable a SaaS administrator too early, nobody may retain the permissions needed to manage the account.

The correct sequence of actions is important here.

Start with one trigger, so the HR exit date notifies IT and finance on the same day. Next, freeze the leaver’s card and move any recurring charges to a team-owned card to keep necessary tools running.

For those tools, transfer admin rights to a shared mailbox and revoke connected apps and tokens. Then remove the leaver from approver chains, reroute pending requests and name a delegate, so purchases do not stall.

Settle pending reimbursements and close the claim profile, so no payment is left open.

Finally, name one owner and keep one closure record that both teams can see, which gives auditors a clear trail.

A Simple Offboarding Control Test You Can Run Today

You can test the finance side of offboarding with data already sitting inside HR and your existing systems.

1. Export all leavers from the previous 12 months, including their last working date.
2. Compare those names with active corporate cards and payment profiles.
3. Check approver and user lists across ERP, expense, procurement, and finance platforms.
4. Review card statements for recurring charges still tied to former employees.
5. Search audit logs for post-departure logins, approvals, payments, or account changes.
6. Resolve every exception and record the time taken from departure to final revocation.

Keep this as a recurring control rather than a one-off exercise. The time-to-revoke figure will give you a simple way to see if offboarding is improving across teams.

One Exit, Fewer Loose Ends
The best offboarding process is the one nobody has to revisit later. If access, ownership, and spending authority close together, the business carries less residual risk into the months ahead. Plus, you get clearer ownership, fewer orphaned accounts, and less clean-up later. More importantly, the departure ends where it should, with the person fully out of the business systems.

Comments (0)
Add Comment