Offboarding closed. Access ticket done. The vendor row flipped to inactive.
Somewhere, they still have a copy of your data — or a path back into a system that still trusts them — and your third-party risk program has already moved on.
That is the post-engagement blind spot: the moment TPRM treats “not a vendor anymore” as “not a risk anymore.” Attackers and error paths do not respect that spreadsheet status.
Where the process ends and the risk doesn’t
Vendor lifecycle thinking is usually strong on the way in: intake, due diligence, contracting, onboarding controls. It is weaker on the way out. Teams check the boxes that procurement and IT can see — disable SSO, revoke badges, recover laptops — and stop.
What often remains:
- Data that never came home — exports, backups, shared drives, tickets, model training sets, support attachments.
- Integrations that linger — API keys, service accounts, webhooks, “temporary” connectors nobody owned after the project ended.
- Trust that outlives the commercial relationship — allow-lists, mutual TLS trust stores, partner VPN profiles, SSO app assignments that were “paused” instead of removed.
- Subprocessors you never met — the former vendor’s own third parties who still process your information under their residual obligations.
None of that shows up in a questionnaire you are no longer sending. If your monitoring stops at offboarding, you have optimized for contract hygiene, not for supply-chain residual risk.
Who feels this pain
Security feels it when a former SaaS provider appears in an incident narrative — or when continuous monitoring tools still see a domain, certificate, or cloud footprint tied to an “inactive” relationship.
Legal and privacy feel it when retention, deletion, and subprocessors clauses need evidence after the commercial team has already celebrated churn or consolidation. “We terminated” is not the same as “we can prove return or destruction.”
Business owners feel it when a replacement vendor is live but the old one still receives automated data feeds because nobody owned the cutover end-to-end.
The common thread is accountability after the handshake ends. Post-engagement risk sits awkwardly between TPRM, ITAM, privacy, and procurement — which usually means it sits nowhere until something breaks.
Why annual reassessment never catches it
Annual (or even quarterly) reassessment is aimed at active vendors. Former vendors fall out of the queue by design. That is rational for questionnaire workload. It is dangerous for residual access and data.
Breach and exploitation news does not filter itself to “current suppliers only.” A vulnerability in a platform you exited last year still matters if that platform retains your records or if a forgotten integration still authenticates. Questionnaire-centric programs systematically under-weight that class of exposure because the entity is no longer “in scope” for the next campaign.
What good looks like (diagnostic, not a product tour)
Programs that take post-engagement seriously tend to share a few traits:
- Offboarding is a risk event, not only an IT event. TPRM and privacy have a defined checklist: data return/destruction evidence, subprocessor notification, integration kill-list, certificate and key retirement.
- “Former” stays observable for as long as residual access or data exists. Not forever for every low-risk contractor — for as long as the relationship’s residual footprint is real.
- Evidence beats affirmation. “We deleted it” from a former vendor is a claim until you have a standard for what proof you will accept.
- Ownership is named. Someone is accountable for residual third-party exposure the way someone is accountable for active critical vendors.
Continuous vendor monitoring, in this framing, is not only “watch the ones we still pay.” It is “keep watching anyone who can still hurt us.” That is a supply-chain and third-party risk posture, not a procurement status field.
A short diagnostic for your next offboarding
Use the next real exit as a test:
- List every system the vendor could touch (including the ones “only used once”).
- For each: revoke, confirm revoke, and record who verified.
- List data categories they held; require return or destruction evidence to a written standard.
- Ask whether their subprocessors still hold anything of yours — and who proves otherwise.
- Decide the residual monitoring window explicitly (90 days? until deletion attested? until keys expire?) instead of defaulting to “inactive = ignore.”
If that exercise feels heavier than your current offboarding checklist, you have found the blind spot.
Soft next step
If your security, legal, and risk owners want post-engagement risk on the same footing as onboarding — without turning every exit into a six-week forensic project — we are glad to compare how regulated teams are closing that gap.



