Before their last day, transfer ownership of everything only they could touch: GRC platform admin (and add a second admin while you’re at it), the auditor’s portal, evidence folders, the policy repository, and any password-manager vaults. Then run your own offboarding checklist on them, carefully — their departure will sit in the auditor’s next leaver sample, and it would be a bad irony for the compliance manager’s offboarding to become the finding.
Next, reconstruct the calendar. List everything due in the next ninety days: access reviews, vendor reviews, training assignments, evidence requests, questionnaire deadlines, audit milestones, renewals. Compliance programs rarely fail in the week someone leaves; they fail two quarters later, one silently missed cadence at a time.
Then tell the auditor. A named interim contact offered before fieldwork reads as a managed transition; unexplained silence reads as a program adrift. Auditors don’t penalize turnover — they penalize controls that stopped operating while nobody owned them.
The departure exposed the real defect: the program lived in one head. You can rehire — a scarce role, months to fill, and the same single point of failure at the end — or move the function to a standing team, the model described at outsourced compliance team; the full trade-off is worked through in hire versus outsource. Whichever way you go, make the program legible this time: named control owners, shared runbooks, no map that exists only in memory. Managed compliance services can also hold the interim while you decide.
Not by itself — auditors see turnover constantly. Findings come from controls that quietly stopped: reviews missed, alerts unwatched, evidence uncollected. Keep the cadence running and document the handover, and the departure stays a footnote.
Days, not months, for the operating baseline — access transferred, the control calendar rebuilt, urgent items triaged. A replacement hire typically takes a quarter or more; interim coverage exists precisely to make that timeline safe.