All resources
Evidence6 min read

Evidence expiry: the quiet failure mode of third-party programs

ISO 27001 certificates, SOC 2 reports, penetration test summaries, insurance certificates and business continuity test results all expire. A folder full of documents collected during onboarding tells you nothing about whether your providers are covered today.

Marieke de Vries · Head of Regulatory Content

Track validity, not receipt

The useful state of an evidence item is not whether it was received but whether it is valid now. That requires the issue date, expiry date, scope and issuer to be recorded as fields, not buried in a PDF.

Once those fields exist, expiry reporting is trivial: valid, expiring soon, expired, missing, under review.

Check scope, not just the logo

A certificate that covers a different legal entity, a different data centre or a subset of services is common and easy to miss. Record the scope statement alongside the dates and compare it to the service you actually consume.

Automate the request cycle

Renewal requests should be generated from the expiry date, not from a person's calendar. A request sent sixty days before expiry, with a reminder cadence and a portal upload link, keeps the file current without a chase list.

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.