An audit-rights deliverability review determines whether the proposed service can support each inspection, information and follow-up right in the issued tender. Its work product is a decision record linking the rights-holder and clause to the evidence, people, systems, supplier permissions, timing, safeguards, cost and remediation arrangements required. A row is resolved by proof that the right can be performed or by an authorized treatment whose prerequisites are explicit. Legal advisers decide the meaning and applicability of disputed rights; delivery and commercial owners decide whether the resulting commitment can be supplied and funded.

The contract allows the buyer to inspect records at a hosting provider and copy relevant evidence. The provider’s standard package offers an annual assurance report and no customer access to the site. The bid team accepts the clause because the provider is certified. That answer leaves a gap between the right promised to the buyer and the permission available to the supplier. An evidence report can be useful without giving anyone the access the contract requires.

Begin with the issued right and follow it to the person who must perform it. This is a pre-bid feasibility review, not an audit programme, a security certification checklist or legal advice. Sources were checked on 6 September 2026. EU privacy rules, DORA and an England and Wales government model illustrate specific regimes; none is a universal tender default. All examples and prices are fictional. Use authorized references for protected evidence, keep other customers’ information out of the bid record, and reserve legal acceptance and disclosure decisions for the appropriate people.

Read the rights before counting expected audits

Create a register from the complete issued package, not from the paragraph headed Audit. Open-book pricing, workforce compliance, security, data processing, service performance and exit schedules can contain different inspection and information rights. Keep the document title, version, exact clause reference and stated hierarchy beside each row. An unavailable linked policy is a missing input, not permission to apply the supplier’s usual practice.

For each provision, name the rights-holder and the basis of authority. A buyer employee, its appointed independent auditor and a public authority may reach similar records through different rights. Record identity and mandate checks, the responsible contact and the escalation route. Do not turn an ordinary auditor-appointment procedure into an invented veto over a regulator acting under law. Where legal scope is unclear, the record should say what counsel must resolve before acceptance.

The Cabinet Office Model Services Contract separates records, open-book reporting and audit provisions across its core terms and schedules. That structure is a useful warning to follow cross-references. It is a model for particular complex services, requiring tailoring; its conditions do not enter a different tender merely because the bidder uses it as a review aid. Keep the buyer’s actual clauses as the operative baseline.

Write the obligation as an observable action. “Cooperate with audit” is too broad for a delivery decision. “Make the named incident records available to the buyer’s appointed auditor, including permitted copies, within the applicable notice arrangement” exposes the object, recipient and task. Preserve qualifications from the source, and mark your wording as a working paraphrase so that it cannot silently replace the legal text.

Fields in an audit-rights decision record
Record elementEvidence neededReason to keep the row open
Authority and scopeClause, actor, purpose, object and methodUnclear mandate or conflicting annex
Delivery routeRecord owner, site, system and supplier permissionAccess exists only in a proposed contract change
Timing and protectionTrigger, notice, period, safeguards and exceptionsNormal operating policy conflicts with the right
Decision and handoverCost, accountable owner, treatment and approval proofCondition has no deadline or completion evidence

Follow the access request beyond the prime contractor

Trace an audit request as a delivery team would receive it. Who owns the source record? Which entity operates the system? Where is the relevant equipment? Who can explain the control or approve an extract? A contract with a reseller may not itself obtain cooperation from the entity operating the service. Record the whole route, its contractual basis and any step that still depends on consent. A helpful account manager’s email is not equivalent to an enforceable downstream obligation.

Compare permissions by object and action. Access to a shared report may cover the provider’s general controls but omit the buyer’s specific configuration, subcontractor activity or audit period. A report restricted to reading may not satisfy a right to take copies. A remote interview may not meet a required site visit. Keep a provider certificate or assurance report as evidence with its own scope; link to the separate assurance review for its period, exclusions and distribution limits.

Article 28(3)(h) GDPR includes controller audit cooperation in processor arrangements, and Article 28(4) addresses downstream obligations. That is an EU processing context, not a rule for every commercial inspection. The controller-processor clauses in Decision 2021/915 also distinguish consideration of certification from audit arrangements. Their existence does not prove that a buyer has incorporated them or that a particular provider contract complies.

Where the route fails, state a specific treatment. The prime might secure an appropriate supplier amendment, use an alternative service design, obtain an expressly permitted buyer clarification, or decline to accept the commitment. Do not mark the row complete while the amendment is merely requested. Record the latest date at which the change must be binding and operational, and compare it with bid acceptance and service-start obligations.

Design a route that lets the audit reach the evidence

An access plan should explain how inspection works without exposing unrelated material. Start with a segregated evidence set, an index to the source records and an accountable evidence custodian. Use a controlled review room or secure exchange when suitable. Record who may read, copy, export and retain each item. If a proposed safeguard reduces an issued right, it needs the correct contractual or legal decision; a supplier policy cannot silently narrow the obligation.

Keep original evidence and a record of any approved redaction. State what was withheld, why, who authorized it and how the auditor can challenge the treatment. Never remove an adverse finding simply because it is commercially uncomfortable. Information belonging to other clients, personal data and potentially privileged material need qualified review. An auditor’s nondisclosure agreement does not by itself extinguish those interests or settle a public body’s disclosure duties.

NIST SP 800-53A distinguishes examination, interview and testing as assessment methods. Use those categories to expose differences in effort and access, not to imply authorization for every test. An invitation to examine records does not automatically permit a destructive probe, a live penetration test or access with shared administrator credentials. Specify a permitted test environment and change-control route when testing is part of the required assessment; keep any uncertainty visible.

DORA Article 30(3)(e) is relevant to ICT supporting critical or important functions at financial entities within its scope. It addresses access and audit rights and the ability to agree alternative assurance where other clients’ rights are affected. This is not a general licence for any supplier to replace an inspection with a report. Counsel must determine applicability and whether a proposed arrangement preserves the required right. The pre-bid record should identify that decision rather than announcing compliance.

Test the notice exceptions and the duties after exit

Record when a notice clock starts, how notice is served, whether days are working or calendar days, and what counts as an urgent trigger. A target of fifteen days is different from a guaranteed minimum. Read frequency limits together with exceptions for suspected noncompliance, incidents or regulatory activity. The September 2025 England and Wales Model Services Contract illustrates this distinction: its ordinary audit arrangements contain exceptions, and an effort to give notice is not an unconditional waiting period.

Use that distinction to test staffing. If the same security engineer is needed for incident response and an investigation audit, adding their annual hours does not prove availability during the incident. Model the overlap, appoint a qualified deputy and identify work that can safely be rescheduled. A capacity conflict needs escalation and an operating plan; it does not authorize obstructing an otherwise valid inspection.

Separate the period in which a right can be exercised from the period for retaining the underlying records. The UK model places different periods in its audit and open-book provisions. For the actual tender, identify each survival clause, any longer legal retention duty and the required method of access after exit. Keeping an encrypted archive is insufficient if no one can retrieve it, explain the records or provide permitted copies.

The post-exit owner needs an entity, a contact route, funding and access to the necessary records. Check what happens when a subprovider agreement ends, an employee leaves or a system is retired. Include lawful disposal and any preservation hold in the plan. Do not retain personal data indefinitely merely because an audit is conceivable, and do not destroy relevant evidence to avoid an outstanding request. Legal and privacy owners must resolve conflicts between applicable duties.

Price the work and keep the unresolved permission visible

The fictional Westmere support tender contains two routine audits a year and additional triggered inspections. Its review has already identified a supplier access amendment that is not signed. For costing only, assume a routine audit needs the work below, with fully loaded internal rates and a quoted external access charge. These are teaching assumptions, not market benchmarks or a prediction of what a buyer will request.

One routine audit costs GBP 5,940: GBP 1,320 for extraction, GBP 1,100 for security review, GBP 1,200 for interviews and escorts, GBP 520 for commercial review and GBP 1,800 for provider support. Two cost GBP 11,880. A separately quoted annual archive arrangement adds GBP 900, producing GBP 12,780 of annual planned cooperation and archive cost. The bid contains GBP 9,000, so the routine plan is underfunded by GBP 3,780 before any triggered audit.

A separate incident-year scenario adds 24 security hours at GBP 110, 18 delivery hours at GBP 75 and GBP 2,400 of provider charges. Its extra cooperation cost is GBP 6,390. Assume, solely for this scenario, that the contract also requires reimbursement of GBP 4,500 of buyer audit costs after an established material breach. The resulting year costs GBP 23,670: GBP 12,780 plus GBP 6,390 plus GBP 4,500. The shortfall against the existing allowance is GBP 14,670. Remediation, retesting, repayments, interest, damages, travel and tax are excluded and require separate assessed rows; this is not maximum exposure.

The decision remains on hold for two independent reasons: the current allowance is insufficient and the provider has not granted the required access. Increasing the price solves neither the legal permission nor the peak staffing problem. Westmere’s review owner must obtain the amendment, an approved staffing arrangement and a commercial decision on the additional costs. If the procurement allows a departure, its proposed wording belongs in the prescribed location and needs acceptance; an internal risk note cannot amend the buyer’s contract.

Westmere: one routine audit, fictional GBP inputs
WorkQuantity and rateCost
Evidence extraction22 hours × GBP 60GBP 1,320
Security review10 hours × GBP 110GBP 1,100
Interviews and escorts16 hours × GBP 75GBP 1,200
Commercial review4 hours × GBP 130GBP 520
Provider supportOne assumed chargeGBP 1,800
Total52 internal hours plus provider workGBP 5,940

Carry findings through to an authorized closure

Check what happens after the auditor reports a problem. The contract may require a response, a corrective plan, an actual correction, reimbursement or another remedy, each on a different clock. A deadline to submit a plan is not the deadline to complete the repair. Record who receives the report and who may agree the timetable. Supplier responsibility for subcontractors must continue through corrective work, not end when evidence has been supplied.

Design a findings record with the applicable criterion, evidence reference, factual response, accepted or disputed status, severity basis, accountable owner, due date, corrective proof, retest and closure authority. A disagreement should identify the contested fact or interpretation and the permitted dispute route. Preserve evidence and perform undisputed duties while that process runs. Do not relabel a contested finding as closed because the supplier has sent an objection.

Keep commercial consequences separate from the correction itself. An overpayment repayment, the buyer’s audit expenses, repair work and possible interest have different bases. Read the contract before assuming one offsets another or falls within a liability cap. The Cabinet Office model’s audit schedule illustrates how findings can lead to financial consequences as well as corrective action; it is not evidence that the same remedy applies to Westmere or another buyer.

Test the handover using one finding before accepting the terms. Ask the proposed service owner to identify the source record, permitted recipients, response authority, cost owner and closure evidence. If no one can answer who commissions a retest after the prime’s subprovider fixes the issue, the delivery arrangement is incomplete. Assign that duty and include its cost before the bid claims that audit cooperation is fully supported.

Release the decision against the exact service and clauses

The final record should let an approver distinguish available capability, a funded change that still needs completion, a buyer clarification, a permitted departure and a commitment the bidder cannot accept. Avoid a single compliance percentage. One unresolved right to inspect a critical supplier can control the whole decision even when dozens of reporting rows are complete.

For Westmere, the supplier amendment reference, effective date and proof of operational readiness must close the access row. Security signs off the controlled evidence route; delivery confirms specialist cover; finance approves the revised cost assumptions and triggered scenario. Counsel resolves interpretation and statutory questions. The delegated contract authority makes the acceptance decision. A review meeting or a conditional budget approval does not by itself authorize an unconditional offer.

Attach the decision to the exact contract version, supplier chain, service design and priced offer. Reopen affected rows after an addendum, a provider change, a new inspection method or an altered survival period. At handover, preserve the rights record, its protected evidence references and its unresolved conditions in the operating team’s controlled system. Keep public bid text limited to approved, relevant claims.

An agent can extract clauses from authorized material, compare source versions, draft questions and check the disclosed arithmetic. It must mark missing permission as missing rather than infer it from a certificate. It cannot accept rights, sign amendments, contact the buyer, release confidential records, enter systems or conduct tests without explicit authority. The useful automated output is a reviewable decision record with evidence locations and holds, not an assertion that an audit has already been performed.

The following extract adds invented clause identifiers and terms to the Westmere teaching case. It illustrates a completed review with a hold decision, not a compliant service. All stated prerequisites must be satisfied before an unconditional offer in this example. The extract is not a complete register for another contract.

Westmere decision extract: fictional audit schedule revision 3
Clause and rightCurrent evidenceTreatment and ownerRelease condition
A2: buyer-appointed auditor inspects relevant provider records and takes permitted copiesProvider terms offer report access onlyProcurement obtains matching provider amendment; security approves segregationBinding amendment and usable evidence route, otherwise hold
A4: two routine audits; additional incident audit may proceed without routine noticeRoutine cost modeled; incident cover not confirmedDelivery names a deputy; finance decides GBP 23,670 scenario and excluded exposuresStaffing proof and commercial approval before acceptance
A6: corrective plan within ten working days after receipt of findingsService owner named; subprovider response route missingContract lead assigns downstream response and separate correction timetableAgreed response route; plan deadline must not be called a repair deadline
A8: audit access for twelve months after service exitAnnual archive service priced; post-exit custodian not appointedOperations appoints custodian and tests retrieval with a synthetic recordAccess demonstration and ownership through the required period

Useful outcomes from review tender audit rights

  • The review identifies who may exercise each right and under which authority.
  • Access promises match the proposed service and the relevant supplier permissions.
  • Routine and triggered audits have separate timing and resource assumptions.
  • Confidentiality safeguards preserve the audit purpose without promising unrestricted disclosure.
  • Every unresolved right has a named treatment, owner and release condition.

How to run the work

  1. 01

    Locate the full rights package

    Collect the main terms, audit schedule, security and processing annexes, record-retention duties, supplier policies and formal clarifications. Record versions and precedence.

  2. 02

    Describe each exercisable right

    Identify the actor, purpose, evidence object, inspection method, trigger, timing, notice and any exception. Keep statutory authority separate from the buyer’s contractual permission.

  3. 03

    Prove access through delivery

    Trace the requested record, site, system or person through the proposed supplier chain. Check enforceable permissions and current capability rather than accepting a report as an access substitute.

  4. 04

    Design controlled cooperation

    Specify the evidence route, identity checks, confidentiality controls, staffing and escalation. Obtain decisions on any conflict between audit access and protected information.

  5. 05

    Calculate and resolve gaps

    Cost routine and triggered scenarios, including buyer-cost reimbursement where relevant. Assign supplier changes, permitted clarifications, departures, legal review or a bid hold.

  6. 06

    Approve a bounded decision

    Reconcile the audit record with price and delivery promises. Bind approval to exact terms and service versions, retain unresolved prerequisites and hand obligations to their operating owners.

Questions that change the decision

  • What does this clause let this actor inspect or obtain?
  • Can the necessary permission be secured throughout the supplier chain?
  • Which notice or frequency exception changes the staffing assumption?
  • Does a proposed safeguard preserve the required evidence?
  • Who funds an audit triggered by a material breach?
  • What evidence must exist before the offer can accept these terms?

Where teams lose control

01

A certificate is treated as permission to enter a supplier’s premises.

02

A normal audit frequency is priced as an absolute annual limit.

03

A confidentiality clause is used to promise information belonging to another customer.

04

Records are retained but cannot be retrieved or explained after exit.

05

A cost allowance is described as a contractual cap.

06

A disputed finding disappears from the handover instead of retaining its status.

Measure the finished job

Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.

  • Rights without a matching evidence route
  • Supplier permissions still unsigned
  • Peak hours required from scarce specialists
  • Unfunded routine and triggered cooperation costs
  • Post-exit access duties without an owner
  • Release conditions without dated completion evidence

Common questions

Does an assurance report replace a buyer audit?

Only if the applicable terms and law allow that treatment and the required authority agrees. Check the report’s scope, period, exclusions and disclosure limits separately. A report may inform the audit without providing the contractual right to inspect people, premises or particular records.

Can we promise access our subprovider does not permit?

Treat that as an unresolved supplier dependency. Obtain a binding, workable permission, change the delivery arrangement or use an authorized contractual treatment before accepting the commitment. The prime’s willingness to cooperate does not create a right against a separate provider.

Is the ordinary notice period guaranteed?

Read the exact language and its exceptions. An obligation to try to provide notice differs from a minimum notice condition, and incidents or statutory powers can have separate rules. Cost and staff the relevant urgent case without inventing a right to delay a valid inspection.

Can we redact information about other customers?

Identify the conflict and the lawful, contractually valid evidence route. Redaction may be appropriate, but its basis and effect need review. Keep originals and an authorized redaction record, and do not use confidentiality to hide adverse evidence or defeat a valid audit purpose.

Does the priced audit allowance limit our duty?

No. A budget assumption limits neither a contractual right nor a statutory duty. Record any actual contractual cap separately, including exceptions, buyer-cost reimbursement and remedies. Price the modeled scenarios and keep unquantified exposures visible.

What proves the review is ready for acceptance?

Each material right needs an evidenced delivery route or an authorized treatment with explicit prerequisites. The approval must cover the exact service, supplier permissions, costs and clauses. Unresolved legal meaning or access remains a hold; finishing this review does not confer signature or submission authority.

Primary references

Tony Kim

Tony Kim

Founder and CEO

Tony writes about applied AI, dependable product engineering and the systems that turn complex response work into controlled delivery.

Managed tender intelligence and bid execution for teams that want the commercial outcome.

Suppliers, founders and commercial teams pursuing public or private opportunities. Start with the workflow, constraints and evidence you already have.