Skip to content

GRC Calendar

Where to find it: Work & Decisions, then GRC Calendar (/calendar).

The GRC Calendar holds every meaningful future governance obligation with a date.


What belongs on it

Any meaningful future GRC obligation, review, reassessment, reporting deadline, expiry, attestation, renewal, exercise or other required time-bound action.

SourceEvents projected
Requirements and activitiesCompliance deadlines, obligation due dates
EvidenceExpected evidence due dates, freshness expiry
ExceptionsValidity expiry, reassessment dates
RiskScheduled review cadence, acceptance expiry, treatment target dates
Action plansDue dates and milestones
PoliciesReview dates, expiry dates, attestation deadlines
AuditReport due dates, plan milestones
InspectionsResponse deadlines, report dates, commitment milestones
ResilienceBIA review dates, plan update dates, scheduled exercises
IncidentsRegulatory reporting deadlines
Third-partyEngagement review dates, contract expiry, renewal notice dates

What deliberately does not belong on it

Technical schedules never appear on the GRC Calendar

Belongs on the calendarBelongs to the technical scheduler
Evidence expiryCollector runs
Review datesIndicator evaluations
Reassessment datesFreshness sweeps
Reporting deadlinesRegulatory source checks
Attestation due datesScheduled recalculations
Temporary mapping expiryHourly and daily jobs

A calendar containing 40,000 hourly collector runs is a calendar nobody opens.

The distinction is the same one that governs Workbench tasks: the calendar holds obligations a person must meet, not executions a machine performs.


Reading the calendar

The calendar aggregates live from source records. It is not a separate store you maintain.

That has a useful consequence: a date changed on a source record is reflected immediately, and a date removed disappears. There is no synchronisation to drift.

It also has a demanding one: if a date is not recorded on the source record, it is not on the calendar. There are no fabricated dates.


Dates that are missing rather than fabricated

Throughout the platform, a missing date is reported as missing:

  • A TPRM engagement with no review date reports none, not overdue. Reassessment frequency is guidance and is never used to derive a date.
  • A crosswalk mapping retired with no end date is shown as "ended, date not recorded" rather than being given one.
  • An obligation with no deadline has no calendar entry.

A missing date is a finding, not a display problem

An engagement with no next review date is not being reviewed on any schedule. Showing it as none makes that visible. Deriving a date from a frequency field would hide it behind a plausible-looking entry nobody set.


Calendar entitlement

Where the regulatory calendar feature is separately entitled, module dates aggregate into the global calendar when it is enabled. Modules maintain their own dates natively regardless.


Using the calendar well

Look forward, not at today. The value is in the next 30 to 90 days, where there is still time to act.

Watch clusters. Three policy reviews, two BIA reviews and an exercise all falling in the same fortnight is a resourcing problem that is only visible on a calendar.

Reconcile against the Workbench. A calendar entry with no corresponding Workbench task means the obligation has a date but nobody is being asked to act on it.

Treat missing dates as work. Filter your registers for records with no review date. That list is usually more interesting than the calendar itself.


Permissions

ActionPermission
View the calendarwork.read, plus read access to the source modules
Set requirement and framework deadlinesdeadline.configure
Configure SLA and deadline policysla.configure

You see calendar entries for records you have permission to see.


Example

A Compliance Manager's next 60 days.

DateEventSource
+6 daysEXC-2026-0031 reassessment dueException
+11 daysInformation Security Policy attestation deadlinePolicy attestation
+14 daysENG-2026-0041 engagement review dueThird-party
+19 daysACT-2026-0289 action plan dueAction plan
+23 daysQ2 access recertification expected evidence dueExpected evidence
+28 daysBIA-2026-0003 review dateResilience
+31 daysAUD-2026-0003 report dueAudit
+44 daysRSK-2026-0022 acceptance expiryRisk acceptance
+52 daysThird-Party Risk Management Policy reviewPolicy
+58 daysEXE-2026-0018 scheduled exerciseResilience

The cluster at days 23 to 31 is three obligations in nine days, two of which need the same team. Seeing it six weeks out is the difference between rescheduling and missing one.

What is not on this calendar: approximately 2,800 collector runs, 4,400 indicator evaluations and 60 freshness sweeps over the same period.


Troubleshooting

"An obligation is missing from the calendar." No date is recorded on the source record.

"An engagement shows no review status." No review date has been set. Frequency guidance does not produce one.

"I see fewer events than a colleague." Calendar visibility follows module permissions.

"Collector runs are not appearing." Correct. They are technical executions and are deliberately excluded.


OrviQ Enterprise Governance, Risk & Compliance Platform