Appearance
GRC Calendar
Where to find it: Work & Decisions, then GRC Calendar (/calendar).
The GRC Calendar holds every meaningful future governance obligation with a date.
What belongs on it
Any meaningful future GRC obligation, review, reassessment, reporting deadline, expiry, attestation, renewal, exercise or other required time-bound action.
| Source | Events projected |
|---|---|
| Requirements and activities | Compliance deadlines, obligation due dates |
| Evidence | Expected evidence due dates, freshness expiry |
| Exceptions | Validity expiry, reassessment dates |
| Risk | Scheduled review cadence, acceptance expiry, treatment target dates |
| Action plans | Due dates and milestones |
| Policies | Review dates, expiry dates, attestation deadlines |
| Audit | Report due dates, plan milestones |
| Inspections | Response deadlines, report dates, commitment milestones |
| Resilience | BIA review dates, plan update dates, scheduled exercises |
| Incidents | Regulatory reporting deadlines |
| Third-party | Engagement review dates, contract expiry, renewal notice dates |
What deliberately does not belong on it
Technical schedules never appear on the GRC Calendar
| Belongs on the calendar | Belongs to the technical scheduler |
|---|---|
| Evidence expiry | Collector runs |
| Review dates | Indicator evaluations |
| Reassessment dates | Freshness sweeps |
| Reporting deadlines | Regulatory source checks |
| Attestation due dates | Scheduled recalculations |
| Temporary mapping expiry | Hourly and daily jobs |
A calendar containing 40,000 hourly collector runs is a calendar nobody opens.
The distinction is the same one that governs Workbench tasks: the calendar holds obligations a person must meet, not executions a machine performs.
Reading the calendar
The calendar aggregates live from source records. It is not a separate store you maintain.
That has a useful consequence: a date changed on a source record is reflected immediately, and a date removed disappears. There is no synchronisation to drift.
It also has a demanding one: if a date is not recorded on the source record, it is not on the calendar. There are no fabricated dates.
Dates that are missing rather than fabricated
Throughout the platform, a missing date is reported as missing:
- A TPRM engagement with no review date reports
none, not overdue. Reassessment frequency is guidance and is never used to derive a date. - A crosswalk mapping retired with no end date is shown as "ended, date not recorded" rather than being given one.
- An obligation with no deadline has no calendar entry.
A missing date is a finding, not a display problem
An engagement with no next review date is not being reviewed on any schedule. Showing it as none makes that visible. Deriving a date from a frequency field would hide it behind a plausible-looking entry nobody set.
Calendar entitlement
Where the regulatory calendar feature is separately entitled, module dates aggregate into the global calendar when it is enabled. Modules maintain their own dates natively regardless.
Using the calendar well
Look forward, not at today. The value is in the next 30 to 90 days, where there is still time to act.
Watch clusters. Three policy reviews, two BIA reviews and an exercise all falling in the same fortnight is a resourcing problem that is only visible on a calendar.
Reconcile against the Workbench. A calendar entry with no corresponding Workbench task means the obligation has a date but nobody is being asked to act on it.
Treat missing dates as work. Filter your registers for records with no review date. That list is usually more interesting than the calendar itself.
Permissions
| Action | Permission |
|---|---|
| View the calendar | work.read, plus read access to the source modules |
| Set requirement and framework deadlines | deadline.configure |
| Configure SLA and deadline policy | sla.configure |
You see calendar entries for records you have permission to see.
Example
A Compliance Manager's next 60 days.
| Date | Event | Source |
|---|---|---|
| +6 days | EXC-2026-0031 reassessment due | Exception |
| +11 days | Information Security Policy attestation deadline | Policy attestation |
| +14 days | ENG-2026-0041 engagement review due | Third-party |
| +19 days | ACT-2026-0289 action plan due | Action plan |
| +23 days | Q2 access recertification expected evidence due | Expected evidence |
| +28 days | BIA-2026-0003 review date | Resilience |
| +31 days | AUD-2026-0003 report due | Audit |
| +44 days | RSK-2026-0022 acceptance expiry | Risk acceptance |
| +52 days | Third-Party Risk Management Policy review | Policy |
| +58 days | EXE-2026-0018 scheduled exercise | Resilience |
The cluster at days 23 to 31 is three obligations in nine days, two of which need the same team. Seeing it six weeks out is the difference between rescheduling and missing one.
What is not on this calendar: approximately 2,800 collector runs, 4,400 indicator evaluations and 60 freshness sweeps over the same period.
Troubleshooting
"An obligation is missing from the calendar." No date is recorded on the source record.
"An engagement shows no review status." No review date has been set. Frequency guidance does not produce one.
"I see fewer events than a colleague." Calendar visibility follows module permissions.
"Collector runs are not appearing." Correct. They are technical executions and are deliberately excluded.