Review cadence and 'Due for Review': when the next review starts and why the status changes
Every vendor runs on a Review Cycle — Yearly by default, or Half Yearly or Quarterly — and that cycle sets when its next review is due. The next-review date is one cycle after your last review's completion date, or one cycle after the date you added the vendor if it has never been reviewed. When that date arrives on a vendor you've reviewed before, its status becomes "Due for Review" — a prompt to run a fresh review, not a sign that anything was lost.
When the next review is due
You pick the pace with the Review Cycle field on the vendor: Yearly (the default), Half Yearly, or Quarterly. The platform then sets the next-review date for you — there's no field to type it in.
That date is always measured from an anchor, not from "now":
- After you complete a review, the next review is due one cycle after that review's completion date.
- For a vendor that has never been reviewed, the next review is due one cycle after the date you added the vendor.
So a Yearly vendor whose review you complete in March is due again next March — not a year from whatever day you happen to be looking. Change the Review Cycle later and the platform recomputes the next-review date automatically: shorten the cycle and the next review comes sooner, lengthen it and it moves out.
What 'Due for Review' means (and what it doesn't)
"Due for Review" means one specific thing: this vendor has been reviewed before, and its next-review date has arrived or passed. It's the platform telling you a review has come due again.
Here's the part people get wrong: a vendor you've already reviewed does not fall back to "Not Started" when it goes overdue. It becomes "Due for Review." "Not Started" only ever means a vendor that has never been reviewed. If you see "Due for Review," your past reviews are intact — the vendor just needs a fresh one.
Keeping the Vendor security reviews test passing
The Vendor security reviews test passes a vendor only while its next-review date is still in the future and its most recent review is complete. The rule follows from that: complete a fresh review before the next-review date passes. The day a review comes due, the vendor already counts as overdue for the test — don't wait for that day to start. See how to complete the next review.
What you can't edit
The next-review date and the review status are system-managed. There's no field to set either by hand, and trying to isn't the fix. The only two levers you control are the Review Cycle, which sets the pace, and completing a review, which resets the clock. To push the next review out, complete one — the date advances one cycle from that completion.
Examples
- A Yearly vendor reviewed and completed in March. Its next review is due next March. Complete a fresh review before then and it stays "Completed" and passing; let that date pass and it flips to "Due for Review."
- A vendor you added today, left on the default Yearly cycle, and haven't reviewed. It already has a next-review date one year out, but it shows "Not Started" until you complete its first review — because it has no review history yet.
- A Quarterly vendor whose next-review date passed last week. It now shows "Due for Review," not "Not Started." Its earlier reviews are still on record; completing a fresh review clears the status and sets the next date one quarter out.
Why it matters / what your auditor expects
Auditors expect you to reassess each vendor on a regular cadence — at least once a year for most, more often for higher-stakes ones. "Due for Review" is the platform surfacing exactly when that cadence lapses, and the Vendor security reviews test fails for any vendor that's overdue. Staying ahead of the next-review date is how you keep both the test and your auditor satisfied. For why the annual cadence exists in the first place, see Vendor Risk Assessment.
