Blog
Evidence calendars for third-party reviews
Most diligence folders fail quietly. Someone saves a SOC report in year one, the vendor renews a certificate in year two, and nobody notices the gap until an auditor asks for the current pack. An evidence calendar is the antidote: a living list of what you rely on, who owns it, and when it must be refreshed.
What belongs on the calendar
Not every email attachment earns a row. Include control claims you would defend to leadership — encryption statements, subprocessor lists, penetration test summaries, insurance certificates, and contract exhibits that define audit rights. Leave trivia out so the calendar stays short enough to maintain.
Owners beat shared inboxes
Assign a person, not a distribution list. When that person leaves, the calendar itself becomes the handover checklist. In our Fintech Vendor Audit Lab, Module 3 forces a dry run: participants pretend the owner is on leave and see what still opens.
Refresh dates with buffers
Set the refresh before the attestation expires. Thirty to forty-five days is a common buffer for critical cloud vendors in fintech. For lower-tier tools, semi-annual checks may be enough — say so explicitly so the desk does not over-promise.
Making drift visible
A calendar that only lives in a private spreadsheet helps one analyst. Publish a simple status view to the risk channel: green for current, amber for due within 30 days, red for overdue. The colors are not a risk score; they are a hygiene signal.
If you want guided practice building one, see the Fintech Vendor Audit Lab or related notes on vendor due diligence audits for fintech.