Back to blog
Guides

The compliance calendar: turning a framework into an operating rhythm

Certification is a moment; compliance is a cadence. What recurring activities belong on a monthly, quarterly and annual calendar - and why the ones with no calendar entry are the ones that fail at audit.
GRC Copilot Team
The compliance calendar: turning a framework into an operating rhythm

Almost every audit finding traces back to a recurring activity that had no owner and no date. The control existed, the policy described it, and nothing in anyone's calendar caused it to happen. A compliance calendar is the unglamorous fix, and it eliminates more findings than any tool.

Why the pre-audit scramble is unavoidable without one

Some evidence cannot be created retrospectively. You cannot produce four quarters of access reviews in the week before fieldwork, and an auditor can see the file creation dates. Anything that must accumulate has to be scheduled from day one:

  • Quarterly access reviews - four of them, dated across the year.
  • Management review minutes.
  • Risk register review records.
  • Awareness training completion, per intake.
  • Incident and change records - naturally occurring, but only if logged as they happen.
  • Backup restoration tests.
The uncomfortable rule: if the evidence has a date on it, the date is part of the evidence. Batch-produced records dated within days of each other tell the auditor exactly what happened.

A workable cadence

Monthly

  • Vulnerability scan review and remediation tracking.
  • Patch compliance reporting against your SLA.
  • New joiner and leaver checks - confirm offboarding actually completed.
  • Open findings and corrective actions review.
  • Security metrics collection.

Quarterly

  • User access review for in-scope systems - the single most sampled control there is.
  • Privileged account review.
  • Risk register review with owners; update scores and treatment progress.
  • Third-party and vendor review for critical suppliers.
  • Policy exception review - exceptions expire; check they have.
  • Backup restoration test.

Never miss a recurring control again

GRC Copilot schedules recurring control activities, assigns owners, chases them, and files the resulting evidence against the right controls automatically.

Semi-annual

  • Management review meeting - many organisations run this twice yearly rather than annually, which reads far better than a single rushed session.
  • Business continuity or disaster recovery exercise.
  • Incident response tabletop.
  • Internal audit of a subset of controls, per your audit plan.

Annual

  • Full risk assessment refresh.
  • Policy review and re-approval - almost every framework requires this and it is a routine finding when skipped.
  • Statement of Applicability review.
  • Penetration test.
  • Awareness training refresh for all staff.
  • Supplier assurance refresh - certificates, SOC reports, contract terms.
  • Internal audit programme plan for the coming year.
  • Surveillance or recertification audit.

Event-driven, not scheduled

Some activities are triggered rather than timed, and they need a defined trigger so they are not forgotten: significant change assessments, incidents, new supplier onboarding, new system deployments, and organisational restructures that redistribute access.

Making it stick

  • Name a person, not a team. Team-owned tasks are unowned tasks.
  • Put it in the system people actually use - your ticketing tool or GRC platform, not a spreadsheet nobody opens.
  • Define the output up front. "Access review completed" is ambiguous; "signed export listing every account with reviewer decision" is not.
  • File the evidence at the point of completion, mapped to the control. Evidence you have to hunt for later is evidence you will recreate.
  • Track completion as a metric. On-time completion rate is one of the few genuinely useful compliance KPIs, and it is exactly the measurement that moves controls up a maturity level.
  • Spread the load. If every quarterly task lands in the same week, they will all slip. Stagger them.

Multiple frameworks, one calendar

Do not run a calendar per framework. The same quarterly access review satisfies ISO 27001, SOC 2, the NCA ECC and most customer assessments simultaneously. Run the activity once at the highest frequency any framework demands, and map the output to every control it satisfies. Parallel calendars are how teams end up doing the same work three times.

Frequently asked questions

How do we choose frequencies?

Start with whatever the framework or your policy states, then adjust upward for high-risk systems. Where nothing is specified, quarterly for access-related activity and annual for reviews is a defensible baseline - and once you commit to a frequency in policy, missing it is a finding.

What if we miss one?

Record it as a nonconformity, do it late, and document why. A missed activity with a corrective action reads far better than a silent gap or a backdated record.

Is this the same as continuous compliance?

It is the manual foundation. Continuous monitoring automates the collection so the calendar covers only what genuinely needs human judgement - which shrinks it considerably.

Who should own the calendar?

Compliance owns the calendar; the business owns the tasks. Compliance schedules, chases and verifies - it does not perform them.

Key takeaways

  • Evidence that must accumulate cannot be produced retrospectively - dates give it away.
  • Name individuals, define the expected output, and file evidence at completion.
  • Stagger recurring tasks so they do not all land in one week.
  • One calendar across all frameworks; map each output to every control it satisfies.
#compliance-calendar #operating-rhythm #recurring-controls #evidence #cadence