A vendor calendar for compliance isn’t just a list of contract end dates or invoices to pay. It’s an operational register that connects each verification to an owner, the acceptance criteria and the evidence needed to prove the check was actually performed. That distinction becomes obvious in an audit: marking a date as “completed” isn’t enough if you cannot show what was checked, against which document and with what conclusion.
This article offers a pragmatic approach to organizing periodic checks, documentary renewals and event-driven controls — and to keeping document collection separate from verification closure.
Start with the service, not just the supplier
Map the services you purchase rather than relying only on the supplier name. The same vendor can deliver both a low-impact service and a core system; the verification approach should reflect that difference. For every calendar entry, link the activity to the specific service, the relevant contract and the risk being addressed.
Regulatory frameworks provide useful guardrails but do not prescribe a one‑size‑fits‑all calendar:
- GDPR: when a provider processes personal data on your behalf, Article 28 requires sufficient guarantees, contractual obligations and the availability of information needed to demonstrate compliance, including audits.
- NIS2: provisions around supply‑chain security and procedures to evaluate the effectiveness of risk management measures emphasize vendor oversight obligations.
- DORA: sets out proportional requirements for managing risks from third‑party ICT providers.
These references help define applicability and obligations, but they don’t impose an identical verification frequency for every supplier. Record the legal or contractual origin of each verification — applicable regulation, contract clause, risk treatment decision or internal procedure — so this can be justified during review.
Assign different frequencies to different checks
A defensible frequency requires a documented rationale. Consider service criticality, data access, operational dependencies, replaceability and past findings. You don’t need to replicate the full risk assessment in the calendar; reference the approved classification and note why you chose the frequency.
Categorize deadlines into three practical types:
- Periodic verification: scheduled, recurring checks (e.g., quarterly review of service reports).
- Document/contract expiry: externally driven dates like certificate validity or contract termination windows.
- Event‑driven verification: triggered by incidents, changes in sub‑processors or substantial service modifications.
As an internal example (not a regulatory prescription): a high‑criticality ICT service might receive focused quarterly checks on selected indicators and a comprehensive annual review. A low‑impact service may only need an annual check. Define what happens after an event: who assesses impact, within which timeframe, and whether the regular calendar should be adjusted. An extraordinary check does not automatically replace the scheduled verification; any substitution should be documented and approved.
Make each calendar line represent a single verification
Model one row per verification, not one row per supplier. A supplier can host multiple verifications with different frequencies, owners and evidence requirements. This avoids a single “supplier verified” label that masks outstanding activities.
Suggested operational fields for each verification:
- Verification ID: stable identifier distinct from the supplier ID
- Supplier and service: legal name, service description and contract reference
- Control and origin: what is being checked and which requirement/contract clause it follows
- Frequency and rationale: interval, risk level and reason for the chosen cadence
- Dates: intended due date, collection start, execution date and next scheduled check
- Responsibilities: internal owner, verifier and approver
- Expected evidence: document type, period covered, version and acceptance criteria
- Status and outcome: progress state separated from pass/fail result
- Exceptions and actions: finding, remediation owner, target date and approvals
The commercial contact at the supplier is not the internal owner. The owner is accountable for completing the verification even if procurement or an external consultant performs the collection. Define an alternate owner for absences and role changes.
Be explicit about the evidence you expect; don’t ask for a vague “security report.” Specify the report type, the service it covers, the period and the criteria you will use to accept it. Link to the specific file version examined — not merely to a folder that changes over time. If you use AuditReady, for example, the platform can centralize evidence with ownership, versions and an audit trail so the examined version is unambiguous.
Move activities from request to verified closure
Start collecting well before the due date
The due date is not the day to send the first request. Work backwards to allow time to obtain documents, review them and manage possible follow‑ups. If a vendor typically needs weeks to respond, an initial request too close to the due date makes a delay predictable.
Adopt internal timing rules (illustrative): first request 30 days before, reminder at 15 days and escalation at the due date. Adjust intervals by service criticality.
Keep records of requests and responses. A sent reminder proves you started collection, but it does not prove the check was successful. If calendar and document systems differ, maintain the same verification ID across tools to reconcile activities.
Separate progress, outcome and risk acceptance
Use distinct states such as: pending, requested, received, under review, closed and overdue. Outcome (conformant, partially conformant, non‑conformant) is a separate field. A received document might be incomplete or cover the wrong service.
A verification can be closed while remediation remains open. Capture the finding, impact, planned action and target date. Temporary risk acceptance must include an authorized decision, justification and a review date; it is not the same as compliance and does not eliminate the finding. Link verifications to your non‑conformity and corrective action register (/en/blog/how-to-structure-nonconformities-and-corrective-actions) so audit evidence is consistent.
Example: a quarterly check closed late
Scenario: a supplier provides a critical ICT service and the agreed quarterly check is to review the service level report. The check is due on 30 September, with collection opened on 1 September.
The vendor delivers an incomplete report. The verifier requests an update and closes the verification on 8 October after receiving the completed report. The integrated report shows an SLA breach that triggers a remediation due 31 October.
Record the original due date (30 September), the actual close date (8 October), the delay and the remediation due date (31 October). Keep the next scheduled verification at 31 December if the calendar uses fixed quarters — don’t move it automatically to 8 January. Shifting the original date to the completion date erases information auditors need to evaluate process performance.
If your process uses a rolling interval from the previous execution, document that rule up front. Both fixed‑date and rolling‑interval logics are acceptable — do not mix them to hide delays.

Handle renewals and urgent requests without losing the calendar
Distinguish document validity from verification date
A document can still be valid yet no longer cover the current service. Conversely, a verification performed against a valid document may be later superseded by a new version. Record the evidence’s coverage period, any declared validity and the date you verified it. For contracts, separate the contract expiry from the date by which you must decide to renew or terminate — waiting until expiry can be too late to exercise options.
Treat extraordinary requests as separate activities
Customer questionnaires, additional audits and urgent requests should not overwrite routine verifications. Create a linked activity and assess which existing evidence is reusable, up‑to‑date and shareable.
This also applies when your organization is itself a vendor responding to large customers: keep supplier oversight activities separate from the evidence you provide to customers. For preparing evidence under time pressure, use an inventory‑gap‑remediation approach (identify evidence, find gaps, assign owners and deadlines). The goal is reuse of verified evidence, not shortcutting verifications that remain open.
Prepare an audit‑ready view, not just a to‑do list
An auditor needs to follow the trail from due date to outcome. Produce a period‑based view that lists scheduled, completed, overdue and missed verifications, plus cancelled activities showing authorizations and reasons.
For each sampled item, provide the control criteria, the exact evidence examined, the verifier and the final decision. Where documents contain sensitive data, prepare a redacted shareable copy while preserving the link to the original and to the verified version.
Maintain an audit trail of decisions and updates (/en/blog/audit-trail-best-practices): changes to owner, frequency or due date must be logged, especially when they occur after a delay.
Track at minimum: overdue items, verifications closed without acceptable evidence and remediations past their target dates, with focus on critical services. As a basic internal control, review open items monthly and use exceptions to correct collection times, responsibilities or unclear acceptance criteria rather than to remove problematic activities from the register.
Frequently asked questions
Q: Can a spreadsheet be enough? A: Yes, for a small perimeter if you define responsibilities, access, version control and stable links to evidence. The limitation isn’t the tool but the ability to reconstruct changes, examined documents and decisions as the number of suppliers and verifiers grows.
Q: How often should each supplier be verified? A: There is no universal answer. Frequency depends on risk, service criticality, applicable obligations and contract terms. Document the rationale and reassess when conditions change.
Q: Does an expired document mean the supplier is automatically non‑compliant? A: Not always. Determine which requirement the document supported and what the contractual or operational implications are. Record the gap and the resulting decision; don’t assume that requesting a renewal alone closes the issue.
Link deadlines to verifiable evidence
If your calendar exists but evidence is scattered, consider AuditReady to centralize controls and evidence for NIS2 and other frameworks (/en/auditready/lp/nis2). The key test is concrete: can you reconstruct every verification from initial responsibility through to the exact examined evidence and the final decision?
audit-ready evidence pack demo — not legal advice