Vendor assurance — DPA coverage, expiry exposure and overdue vendor reviews.
Last updated: July 30, 2026 by Steve
Vendor Assurance Report
The Vendor Assurance report is where you check third-party exposure: which processors you actually rely on, whether each one is covered by a valid data processing agreement, and where a review or a contract is about to lapse.

What This Report Shows
- Processors you rely on — the vendors linked from the vendor register across your privacy subjects.
- DPA coverage — whether a data processing agreement (DPA) is in place and unexpired for each processor.
- DPAs and contracts expiring in the next 90 days — the forward-looking exposure window, so renewals can be chased before they lapse.
- Overdue vendor reviews — processors due for a periodic review that hasn't happened.
- The risk mix — how vendors are distributed across risk levels.
- Vendors not linked to any processing activity — processors sitting in the register without a linked activity, a gap worth investigating rather than a compliance figure in itself.
Reading the As-Of Banner
Vendor Assurance is one of the reports that describes a current position rather than activity inside the reporting period. The panel carries a banner stating the as-of date, and the period selector at the top of the Reports panel does not narrow these headline figures — a DPA that lapsed last quarter is a gap today regardless of what range is showing.
Using This Report
Work the expiring and overdue figures first — they carry a clock that is actively running. Then check vendors not linked to any processing activity: it usually means a vendor record was created without being tied to the subject it actually serves, so linking it is the fix rather than treating it as a finding on its own.
Related Pages
- Privacy Subjects — the vendor register and the subjects it's linked from.
- Privacy Subject Details — the Processors/Vendors tab where a vendor is linked to a specific processing activity.
- Reports — the reports menu this report opens from.