An annual cycle that was only annual on paper
Aurea Bio reviewed every vendor once a year. The calendar said so, the policy said so, and the auditor was shown a spreadsheet that said so.
What actually happened is that a reminder fired twelve months after the last review, someone opened the vendor’s file, and discovered the SOC 2 report had expired four months earlier. The vendor had been operating outside the policy for a third of the year, and nothing in the process was capable of noticing. In the worst case found during the first migration, a sub-processor had changed eight months before anyone re-read the DPA.
The trigger is the evidence, not the date
Every artefact in the vault now carries its own expiry, and the review is scheduled against that rather than against the anniversary of the last one. A report due to lapse in March starts its renewal in January, whatever the calendar says.
Alongside it, three signals reopen a closed review on their own: a certification expiring or being withdrawn, a change to the vendor’s published sub-processor list, and a breach disclosure. None of those wait for a human to notice.
“The annual review was the thing we could prove we did. It was not the thing that kept us safe.”
A full cycle later
- 130 renewals, all completed before the previous evidence expired. The old process averaged eleven that ran late each year, two of them by more than a quarter.
- Nineteen reviews were reopened early by a signal rather than a date. Four of those were sub-processor changes that would not have surfaced until the next anniversary.
- The auditor’s third-party sampling moved from “show me the review” to “show me the trigger”, which is a question the vault answers with a timestamp.
What’s next
Aurea Bio is pushing the same expiry model into supplier quality agreements, which live in a different system and still run on the calendar.
About Aurea Bio
Aurea Bio develops clinical diagnostics for hospital laboratories across Europe. 620 people in Copenhagen and Basel, ISO 13485 and ISO 27001 certified. Henrik Sund runs the quality and compliance function.


