River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Contractor Onboarding Checklist Template

An audit of 14 contractors found 3 with system access still active, one of them a full year past its contract end date.

Free download  ·  No account needed

This pack builds a Contractor Register from the contract, W-9 and scope of work, then runs two checks a start-date checklist never gets to. The Access Matrix cross-references every expired contract's end date against the identity provider's log, catching access that survives the paperwork. The Classification Risk Flags sheet scores each engagement against five behavioral, financial and relationship factors, flagging anyone at three or more before a renewal streak makes the question hard to raise.

A downloadable checklist stops at the start date, because a static file has no way to check an access log months later. In the worked example, a fictional media agency's audit of 14 contractor engagements found 5 already past their contracted end date. Of those 5, 3 still had active access, averaging 198 days past the end date, one of them a full year. That is a 60 percent lingering-access rate among expired contracts, not a single overlooked account.

Written for people ops and finance leads who onboard contractors regularly enough that a start-date-only checklist has already let something slip. One contractor in the worked example, renewed seven times over two years, scored four of five classification factors under the IRS common-law test. Full-time hires still run through 30-60-90 onboarding, and a transfer between teams runs through the internal transfer pack instead of this one. The same lingering-access pattern shows up on the employee side too, covered by the offboarding checklist.

Access that outlived the contract, and the one flag that matters

Access Matrix cross-checks end dates against the identity log. Classification Risk Flags scores five factors per engagement.

Access Matrix

Illustrative for a fictional media agency, Thornbury Media Group. 5 of 14 contractor engagements had already passed their end date.

NameContracted end dateSystems grantedAccess statusDays past end date
Priya Nair2026-06-30Slack, Google DriveStill active42
Owen Castellan2026-02-28Slack, Asset Library, VPNStill active187
Dana Whitfield2025-03-01Slack, Asset Library, Design Suite, VPNStill active365
Ines Torfason2026-01-10SlackRevoked on schedule0
Rafael Nunes2025-12-05Slack, Google DriveRevoked on schedule0

3 of 5 expired contracts, 60 percent, still had active access. Average lingering access: 198 days.

Classification Risk Flags

Five factors per engagement, from the IRS common-law categories. Flag at 3 or more.

NameBehavioral controlIntegrationExclusivityRenewal beyond scopeCompany equipmentCountFlag
Dana WhitfieldYesYesYesNoYes4High risk
Priya NairNoNoYesNoNo1ok
Owen CastellanNoNoNoNoYes1ok
Marcus IlvesNoNoNoNoNo0ok
Sofia ReyesNoYesNoNoNo1ok

1 of 14 engagements, 7.1 percent, flagged at 3 or more factors: seven consecutive renewals, daily standups, exclusive for two years, company laptop.

What is in the pack

01

Contractor Register

One row per engagement: function, start and end date, renewal count, and the manager who owns it, built from the contract, W-9 and scope of work.

02

Access Matrix

Every expired contract's end date cross-checked against the identity provider's log, reporting the share still carrying live access and how many days it ran.

03

Classification Risk Flags

Five behavioral, financial and relationship factors scored per engagement, flagging anyone at three or more with the specific factors named.

04

Onboarding Procedure

Access provisioned to the scope of work rather than a standard bundle, with the classification score run at start rather than after a renewal streak.

05

Classification Note

The scoring results written out for whoever makes classification calls, naming the specific factors rather than asserting a determination this pack does not make.

How it works

  1. 1

    Send the contracts and access export

    The signed contracts or statements of work, W-9s, and whatever export your identity provider gives of who currently has access to what.

  2. 2

    Get the access cross-check

    Every expired contract's end date checked against live access, with the lingering-access share and average overdue days reported as a rate, not an anecdote.

  3. 3

    Get the classification score

    Every engagement scored against five factors, with anyone at three or more flagged by name and by the specific factors that drove the flag.

  4. 4

    Route what gets flagged

    The Classification Note hands the flagged engagements to whoever makes the call, and the Access Policy fixes lingering access going forward.

Frequently asked questions

Why would access outlive a contract in the first place?

Because revocation depends on someone remembering a date that was never tied to a system check. In the worked example, 60 percent of expired contracts still had active access, averaging 198 days, which is what happens by default rather than the rare exception it feels like from inside one contractor's file.

Does a classification flag mean we have to convert the contractor to an employee?

No. It means the engagement goes to whoever makes classification calls with the specific factors named. The IRS test weighs the whole relationship, and no single factor is disqualifying on its own; the flag starts a deliberate review, not an automatic conversion.

What if a contractor genuinely needs broad system access for the work?

Then grant it and document why in the register. The point is not to minimize access on principle, it is to provision against the scope of work rather than a standard bundle, and to make sure that access ends when the scope does.

How is this different from onboarding a new full-time hire?

A full-time hire runs through 30-60-90 onboarding, which assumes an indefinite relationship and a competency ramp. A contractor engagement has a stated end date from day one, and this pack is built around that end date actually meaning something.

What about a contractor being converted to an internal transfer or full hire?

That is a different process with its own paperwork and a different register. Track it as a new entry once the conversion is agreed rather than editing the contractor row, so the history of the original engagement stays intact for the classification record.

Find out which contractors still have access they should not

Send your contractor register and an access export. The first thing back is who is past their end date with access still live, and who scores as a classification risk.

Build my contractor register