The Compliance Calendar answers one question every morning: what has to be done, by whom, and how urgent is it. It gathers three kinds of dated work into one list, keeps the dates true without anyone editing a spreadsheet, and turns each item into a task with a reminder.

What is on the calendar
- Control reviews. Every implemented or partially implemented requirement control has a review cadence (from the control catalogue: monthly, quarterly, every six months or yearly; controls that operate continuously are reviewed quarterly) and a review date. The first review is never scheduled sooner than 30 days after the control is implemented.
- Control tests. Library controls carry a testing cadence, yearly by default, and a next-test date computed from the last closed test. Recording a newer test moves the date on automatically.
- Framework obligations. The recurring things each framework expects: the DORA register of information submission, the ISO 27001 internal audit and management review, the NDPA compliance audit return by 31 March, PCI DSS quarterly ASV scans, the CMMC annual affirmation and so on. Venvera ships 67 of them across the 20 frameworks, each with its legal basis and cadence, and schedules the ones for the frameworks your organisation runs. Fixed calendar deadlines (31 March) are anchored; the rest start 60 days out and then repeat on their cadence from the day you complete them.
Urgency and risk
The four counters at the top are filters: overdue, due in 7 days, due in 30 days, due in 90 days. The fifth, critical and high risk, narrows the list to items that protect a critical or high residual risk. Each control's risk level comes from the risks linked to it in the risk register (the highest residual rating wins); an obligation's level is its regulatory severity. Combine the filters: overdue items on critical risks is the list a CISO reads first. Filters live in the URL, so a filtered view can be bookmarked or sent to a colleague.
Tasks and reminders
Every night at 07:00 UTC Venvera schedules new items, and for anything due within 30 days or overdue it creates a task for the owner (the control owner, or the person holding the responsible role under Responsibilities), sends an in-app notification and one digest e-mail per person. Reminders repeat weekly while an item stays open; overdue items are flagged separately. An admin can run the same job on demand with Run now.
Adjusting an obligation
Administrators can change an obligation's owner or next due date, add notes, or switch an obligation off if it does not apply to the organisation (for example TLPT for an entity outside its scope). Obligations for frameworks you stop running disappear from the calendar automatically.
Where it connects
- Tasks: calendar tasks are ordinary tasks with the calendar as their source; they sync to Jira like any other.
- Evidence: evidence freshness is tracked separately; a control review is the moment to confirm the evidence is still current.
- Risk register: linking risks to controls is what gives the calendar its risk filter.