The biggest risk to your client data might be someone who no longer works for you.
When a consultant leaves, their access often doesn’t leave with them. The client portal login still works, sensitive files still sit on a laptop, and an account stays active months after the final invoice. This is the offboarding gap, and for consultancy firms it’s one of the most overlooked sources of client data exposure.
The moment a consultant walks out the door is the moment your controls are tested, and most firms have no formal process for it.
Let’s explore what should happen to client data when a consultant leaves, why the risk is higher than most directors assume, what goes wrong when offboarding is left to memory, and how managed IT services close the gap.
Why Offboarding Is the Highest-Risk Moment
During an active engagement, access usually makes sense. The consultant needs the systems, the files, and the credentials to do the work. Oversight is reasonably tight because the relationship is live.
Departure changes that. Access that was justified yesterday becomes a liability today, and the responsibility for closing it down sits entirely with your firm. If the steps aren’t documented and owned by someone, they get missed.
For firms with project-based or high-turnover staffing, the problem multiplies. A steady flow of contractors, associates, and short-term specialists means a steady flow of access that needs removing. The volume alone makes informal offboarding unreliable.
Account Deprovisioning
When a consultant leaves, every account tied to client data needs to be deactivated. The accounts firms remember tend to be email and the primary file store. The accounts they forget are the ones that cause problems:
- SaaS and collaboration tools such as Slack, Teams, Asana, or Monday, where client material often sits in channels and project boards.
- Client-owned systems the consultant was given direct access to, including the client’s own portals, CRMs, or shared drives.
- Single sign-on and federated logins that grant access to multiple connected applications through one credential.
- Shared or generic accounts where a password was passed around rather than assigned individually.
Simply disabling a primary email account doesn’t close these. Each one is a separate door, and each needs to be shut deliberately.
Access Revocation Timelines
Speed is just as important as completeness. An account that stays live for three weeks after departure is a three-week window in which client data can be reached by someone unaccountable to you.
A formal process sets a clear standard, so access is revoked on the consultant’s final working day. That includes:
- Disabling sign-in immediately, before any slower cleanup begins
- Terminating active sessions, so existing logins don’t continue
- Reviewing and revoking application tokens and any saved credentials in browsers
Where access is revoked reactively, the timeline stretches and the exposure grows. The cleaner the process, the shorter that window.
Device Retrieval
Client data travels with people, across laptops, phones, and personal devices, through downloads, attachments, and synced folders. Reclaiming a company laptop doesn’t guarantee the data has gone with it.
A device retrieval process needs to account for:
- Company hardware returned, wiped, or reassigned with managed tooling
- Client data cleared from any personal devices, common where firms run a bring-your-own-device arrangement
- Synced cloud folders and local copies removed, not just the visible desktop files
Miss this and sensitive information walks out with a departing consultant who never intended to misuse it. It’s simply gone unmanaged.
Data Retention Obligations
Offboarding a person is also a data question. When a consultant leaves, you need to know what client data they held, along with where it currently lives and how long you’re permitted to keep it.
Under UK GDPR and the Data Protection Act 2018, personal data shouldn’t be held any longer than necessary for the purpose it was collected. A departing consultant’s local copies and personal storage usually fall outside any retention schedule, which means they’re held without a lawful basis or oversight.
A formal process answers two questions at the point of departure: what is retained, under whose control, and for how long; and what is securely deleted because it no longer needs to exist.
Getting this right protects both the client and your firm’s compliance position.
What Goes Wrong Without a Formal Process
When offboarding relies on memory and goodwill, the failures are predictable.
The 2026 Cost of Insider Risks Global Report put the average annual cost of insider-related security incidents at $19.5 million per organisation, with credential theft among the most expensive categories at roughly $4.5 million a year.
Stale credentials left behind after someone leaves are precisely the kind of opening that figure describes. In practice, the absence of a process tends to produce the following:
- Forgotten accounts that stay live for weeks or months, making them easy targets for external attackers who find an inactive login with a weak password and no multi-factor authentication (MFA).
- Data on unmanaged devices that you can’t see or control once the relationship ends.
- Compliance exposure where client data is held beyond its retention period or accessed by someone who has no current right to it.
- No audit trail to demonstrate to a client, or a regulator, that access was removed properly and on time.
On top of this sits the reputational cost. Clients in management, financial, HR, and strategy consultancy hand over confidential, commercially sensitive information because they trust the firm to handle it carefully.
A breach traced back to a consultant who left months ago is difficult to explain and harder to recover from.
The fix is structural. Making offboarding a defined checklist with a named owner, triggered the moment a departure is confirmed. Once it’s documented and consistent, protecting client data stops being a gamble.
Book a Consultation with Adam
If you’re not confident about what happens to your client data when a consultant leaves, it’s worth addressing before it becomes an incident.
Book a consultation with Adam to review your firm’s offboarding process.
Frequently Asked Questions
What happens to client data when a consultant leaves a firm?
When a consultant leaves, the client data they handled remains at risk until every account is deprovisioned, all devices are retrieved or wiped, and access is formally revoked. Without a structured offboarding process, that data can stay reachable long after departure.
What is account deprovisioning in consultancy offboarding?
Account deprovisioning is the process of deactivating every system login tied to a departing consultant, including email, SaaS tools, single sign-on, client-owned platforms, and any shared accounts, so they can no longer reach client data.
How quickly should access be revoked when a consultant leaves?
Access should be revoked on the consultant’s final working day. Sign-in should be disabled immediately, active sessions terminated, and application tokens reviewed, since every day of lingering access widens the window for a data breach.
What are the data retention obligations when a consultant departs?
Under UK GDPR and the Data Protection Act 2018, client and personal data shouldn’t be kept longer than necessary. At departure, a firm should confirm what data is retained and under whose control, and securely delete copies that aren’t needed.
What goes wrong without a formal consultant offboarding process?
Forgotten active accounts, client data left on unmanaged devices, compliance breaches, and no audit trail of access removal. These gaps create both security risk and reputational damage if a former consultant’s access is later exploited.

