An audit-rights deliverability review determines whether the proposed service can support each inspection, information and follow-up right in the issued tender. Its work product is a decision record linking the rights-holder and clause to the evidence, people, systems, supplier permissions, timing, safeguards, cost and remediation arrangements required. A row is resolved by proof that the right can be performed or by an authorized treatment whose prerequisites are explicit. Legal advisers decide the meaning and applicability of disputed rights; delivery and commercial owners decide whether the resulting commitment can be supplied and funded.
The contract allows the buyer to inspect records at a hosting provider and copy relevant evidence. The provider’s standard package offers an annual assurance report and no customer access to the site. The bid team accepts the clause because the provider is certified. That answer leaves a gap between the right promised to the buyer and the permission available to the supplier. An evidence report can be useful without giving anyone the access the contract requires.
Begin with the issued right and follow it to the person who must perform it. This is a pre-bid feasibility review, not an audit programme, a security certification checklist or legal advice. Sources were checked on 6 September 2026. EU privacy rules, DORA and an England and Wales government model illustrate specific regimes; none is a universal tender default. All examples and prices are fictional. Use authorized references for protected evidence, keep other customers’ information out of the bid record, and reserve legal acceptance and disclosure decisions for the appropriate people.
Contract baseline
Read the rights before counting expected audits
Create a register from the complete issued package, not from the paragraph headed Audit. Open-book pricing, workforce compliance, security, data processing, service performance and exit schedules can contain different inspection and information rights. Keep the document title, version, exact clause reference and stated hierarchy beside each row. An unavailable linked policy is a missing input, not permission to apply the supplier’s usual practice.
For each provision, name the rights-holder and the basis of authority. A buyer employee, its appointed independent auditor and a public authority may reach similar records through different rights. Record identity and mandate checks, the responsible contact and the escalation route. Do not turn an ordinary auditor-appointment procedure into an invented veto over a regulator acting under law. Where legal scope is unclear, the record should say what counsel must resolve before acceptance.
The Cabinet Office Model Services Contract separates records, open-book reporting and audit provisions across its core terms and schedules. That structure is a useful warning to follow cross-references. It is a model for particular complex services, requiring tailoring; its conditions do not enter a different tender merely because the bidder uses it as a review aid. Keep the buyer’s actual clauses as the operative baseline.
Write the obligation as an observable action. “Cooperate with audit” is too broad for a delivery decision. “Make the named incident records available to the buyer’s appointed auditor, including permitted copies, within the applicable notice arrangement” exposes the object, recipient and task. Preserve qualifications from the source, and mark your wording as a working paraphrase so that it cannot silently replace the legal text.
| Record element | Evidence needed | Reason to keep the row open |
|---|---|---|
| Authority and scope | Clause, actor, purpose, object and method | Unclear mandate or conflicting annex |
| Delivery route | Record owner, site, system and supplier permission | Access exists only in a proposed contract change |
| Timing and protection | Trigger, notice, period, safeguards and exceptions | Normal operating policy conflicts with the right |
| Decision and handover | Cost, accountable owner, treatment and approval proof | Condition has no deadline or completion evidence |
Supplier permissions
Follow the access request beyond the prime contractor
Trace an audit request as a delivery team would receive it. Who owns the source record? Which entity operates the system? Where is the relevant equipment? Who can explain the control or approve an extract? A contract with a reseller may not itself obtain cooperation from the entity operating the service. Record the whole route, its contractual basis and any step that still depends on consent. A helpful account manager’s email is not equivalent to an enforceable downstream obligation.
Compare permissions by object and action. Access to a shared report may cover the provider’s general controls but omit the buyer’s specific configuration, subcontractor activity or audit period. A report restricted to reading may not satisfy a right to take copies. A remote interview may not meet a required site visit. Keep a provider certificate or assurance report as evidence with its own scope; link to the separate assurance review for its period, exclusions and distribution limits.
Article 28(3)(h) GDPR includes controller audit cooperation in processor arrangements, and Article 28(4) addresses downstream obligations. That is an EU processing context, not a rule for every commercial inspection. The controller-processor clauses in Decision 2021/915 also distinguish consideration of certification from audit arrangements. Their existence does not prove that a buyer has incorporated them or that a particular provider contract complies.
Where the route fails, state a specific treatment. The prime might secure an appropriate supplier amendment, use an alternative service design, obtain an expressly permitted buyer clarification, or decline to accept the commitment. Do not mark the row complete while the amendment is merely requested. Record the latest date at which the change must be binding and operational, and compare it with bid acceptance and service-start obligations.
Evidence handling
Design a route that lets the audit reach the evidence
An access plan should explain how inspection works without exposing unrelated material. Start with a segregated evidence set, an index to the source records and an accountable evidence custodian. Use a controlled review room or secure exchange when suitable. Record who may read, copy, export and retain each item. If a proposed safeguard reduces an issued right, it needs the correct contractual or legal decision; a supplier policy cannot silently narrow the obligation.
Keep original evidence and a record of any approved redaction. State what was withheld, why, who authorized it and how the auditor can challenge the treatment. Never remove an adverse finding simply because it is commercially uncomfortable. Information belonging to other clients, personal data and potentially privileged material need qualified review. An auditor’s nondisclosure agreement does not by itself extinguish those interests or settle a public body’s disclosure duties.
NIST SP 800-53A distinguishes examination, interview and testing as assessment methods. Use those categories to expose differences in effort and access, not to imply authorization for every test. An invitation to examine records does not automatically permit a destructive probe, a live penetration test or access with shared administrator credentials. Specify a permitted test environment and change-control route when testing is part of the required assessment; keep any uncertainty visible.
DORA Article 30(3)(e) is relevant to ICT supporting critical or important functions at financial entities within its scope. It addresses access and audit rights and the ability to agree alternative assurance where other clients’ rights are affected. This is not a general licence for any supplier to replace an inspection with a report. Counsel must determine applicability and whether a proposed arrangement preserves the required right. The pre-bid record should identify that decision rather than announcing compliance.
Operating clocks
Test the notice exceptions and the duties after exit
Record when a notice clock starts, how notice is served, whether days are working or calendar days, and what counts as an urgent trigger. A target of fifteen days is different from a guaranteed minimum. Read frequency limits together with exceptions for suspected noncompliance, incidents or regulatory activity. The September 2025 England and Wales Model Services Contract illustrates this distinction: its ordinary audit arrangements contain exceptions, and an effort to give notice is not an unconditional waiting period.
Use that distinction to test staffing. If the same security engineer is needed for incident response and an investigation audit, adding their annual hours does not prove availability during the incident. Model the overlap, appoint a qualified deputy and identify work that can safely be rescheduled. A capacity conflict needs escalation and an operating plan; it does not authorize obstructing an otherwise valid inspection.
Separate the period in which a right can be exercised from the period for retaining the underlying records. The UK model places different periods in its audit and open-book provisions. For the actual tender, identify each survival clause, any longer legal retention duty and the required method of access after exit. Keeping an encrypted archive is insufficient if no one can retrieve it, explain the records or provide permitted copies.
The post-exit owner needs an entity, a contact route, funding and access to the necessary records. Check what happens when a subprovider agreement ends, an employee leaves or a system is retired. Include lawful disposal and any preservation hold in the plan. Do not retain personal data indefinitely merely because an audit is conceivable, and do not destroy relevant evidence to avoid an outstanding request. Legal and privacy owners must resolve conflicts between applicable duties.
Worked decision
Price the work and keep the unresolved permission visible
The fictional Westmere support tender contains two routine audits a year and additional triggered inspections. Its review has already identified a supplier access amendment that is not signed. For costing only, assume a routine audit needs the work below, with fully loaded internal rates and a quoted external access charge. These are teaching assumptions, not market benchmarks or a prediction of what a buyer will request.
One routine audit costs GBP 5,940: GBP 1,320 for extraction, GBP 1,100 for security review, GBP 1,200 for interviews and escorts, GBP 520 for commercial review and GBP 1,800 for provider support. Two cost GBP 11,880. A separately quoted annual archive arrangement adds GBP 900, producing GBP 12,780 of annual planned cooperation and archive cost. The bid contains GBP 9,000, so the routine plan is underfunded by GBP 3,780 before any triggered audit.
A separate incident-year scenario adds 24 security hours at GBP 110, 18 delivery hours at GBP 75 and GBP 2,400 of provider charges. Its extra cooperation cost is GBP 6,390. Assume, solely for this scenario, that the contract also requires reimbursement of GBP 4,500 of buyer audit costs after an established material breach. The resulting year costs GBP 23,670: GBP 12,780 plus GBP 6,390 plus GBP 4,500. The shortfall against the existing allowance is GBP 14,670. Remediation, retesting, repayments, interest, damages, travel and tax are excluded and require separate assessed rows; this is not maximum exposure.
The decision remains on hold for two independent reasons: the current allowance is insufficient and the provider has not granted the required access. Increasing the price solves neither the legal permission nor the peak staffing problem. Westmere’s review owner must obtain the amendment, an approved staffing arrangement and a commercial decision on the additional costs. If the procurement allows a departure, its proposed wording belongs in the prescribed location and needs acceptance; an internal risk note cannot amend the buyer’s contract.
| Work | Quantity and rate | Cost |
|---|---|---|
| Evidence extraction | 22 hours × GBP 60 | GBP 1,320 |
| Security review | 10 hours × GBP 110 | GBP 1,100 |
| Interviews and escorts | 16 hours × GBP 75 | GBP 1,200 |
| Commercial review | 4 hours × GBP 130 | GBP 520 |
| Provider support | One assumed charge | GBP 1,800 |
| Total | 52 internal hours plus provider work | GBP 5,940 |
Remediation
Carry findings through to an authorized closure
Check what happens after the auditor reports a problem. The contract may require a response, a corrective plan, an actual correction, reimbursement or another remedy, each on a different clock. A deadline to submit a plan is not the deadline to complete the repair. Record who receives the report and who may agree the timetable. Supplier responsibility for subcontractors must continue through corrective work, not end when evidence has been supplied.
Design a findings record with the applicable criterion, evidence reference, factual response, accepted or disputed status, severity basis, accountable owner, due date, corrective proof, retest and closure authority. A disagreement should identify the contested fact or interpretation and the permitted dispute route. Preserve evidence and perform undisputed duties while that process runs. Do not relabel a contested finding as closed because the supplier has sent an objection.
Keep commercial consequences separate from the correction itself. An overpayment repayment, the buyer’s audit expenses, repair work and possible interest have different bases. Read the contract before assuming one offsets another or falls within a liability cap. The Cabinet Office model’s audit schedule illustrates how findings can lead to financial consequences as well as corrective action; it is not evidence that the same remedy applies to Westmere or another buyer.
Test the handover using one finding before accepting the terms. Ask the proposed service owner to identify the source record, permitted recipients, response authority, cost owner and closure evidence. If no one can answer who commissions a retest after the prime’s subprovider fixes the issue, the delivery arrangement is incomplete. Assign that duty and include its cost before the bid claims that audit cooperation is fully supported.
Acceptance evidence
Release the decision against the exact service and clauses
The final record should let an approver distinguish available capability, a funded change that still needs completion, a buyer clarification, a permitted departure and a commitment the bidder cannot accept. Avoid a single compliance percentage. One unresolved right to inspect a critical supplier can control the whole decision even when dozens of reporting rows are complete.
For Westmere, the supplier amendment reference, effective date and proof of operational readiness must close the access row. Security signs off the controlled evidence route; delivery confirms specialist cover; finance approves the revised cost assumptions and triggered scenario. Counsel resolves interpretation and statutory questions. The delegated contract authority makes the acceptance decision. A review meeting or a conditional budget approval does not by itself authorize an unconditional offer.
Attach the decision to the exact contract version, supplier chain, service design and priced offer. Reopen affected rows after an addendum, a provider change, a new inspection method or an altered survival period. At handover, preserve the rights record, its protected evidence references and its unresolved conditions in the operating team’s controlled system. Keep public bid text limited to approved, relevant claims.
An agent can extract clauses from authorized material, compare source versions, draft questions and check the disclosed arithmetic. It must mark missing permission as missing rather than infer it from a certificate. It cannot accept rights, sign amendments, contact the buyer, release confidential records, enter systems or conduct tests without explicit authority. The useful automated output is a reviewable decision record with evidence locations and holds, not an assertion that an audit has already been performed.
The following extract adds invented clause identifiers and terms to the Westmere teaching case. It illustrates a completed review with a hold decision, not a compliant service. All stated prerequisites must be satisfied before an unconditional offer in this example. The extract is not a complete register for another contract.
| Clause and right | Current evidence | Treatment and owner | Release condition |
|---|---|---|---|
| A2: buyer-appointed auditor inspects relevant provider records and takes permitted copies | Provider terms offer report access only | Procurement obtains matching provider amendment; security approves segregation | Binding amendment and usable evidence route, otherwise hold |
| A4: two routine audits; additional incident audit may proceed without routine notice | Routine cost modeled; incident cover not confirmed | Delivery names a deputy; finance decides GBP 23,670 scenario and excluded exposures | Staffing proof and commercial approval before acceptance |
| A6: corrective plan within ten working days after receipt of findings | Service owner named; subprovider response route missing | Contract lead assigns downstream response and separate correction timetable | Agreed response route; plan deadline must not be called a repair deadline |
| A8: audit access for twelve months after service exit | Annual archive service priced; post-exit custodian not appointed | Operations appoints custodian and tests retrieval with a synthetic record | Access demonstration and ownership through the required period |
What good looks like
Useful outcomes from review tender audit rights
- The review identifies who may exercise each right and under which authority.
- Access promises match the proposed service and the relevant supplier permissions.
- Routine and triggered audits have separate timing and resource assumptions.
- Confidentiality safeguards preserve the audit purpose without promising unrestricted disclosure.
- Every unresolved right has a named treatment, owner and release condition.
Operating model
How to run the work
- 01
Locate the full rights package
Collect the main terms, audit schedule, security and processing annexes, record-retention duties, supplier policies and formal clarifications. Record versions and precedence.
- 02
Describe each exercisable right
Identify the actor, purpose, evidence object, inspection method, trigger, timing, notice and any exception. Keep statutory authority separate from the buyer’s contractual permission.
- 03
Prove access through delivery
Trace the requested record, site, system or person through the proposed supplier chain. Check enforceable permissions and current capability rather than accepting a report as an access substitute.
- 04
Design controlled cooperation
Specify the evidence route, identity checks, confidentiality controls, staffing and escalation. Obtain decisions on any conflict between audit access and protected information.
- 05
Calculate and resolve gaps
Cost routine and triggered scenarios, including buyer-cost reimbursement where relevant. Assign supplier changes, permitted clarifications, departures, legal review or a bid hold.
- 06
Approve a bounded decision
Reconcile the audit record with price and delivery promises. Bind approval to exact terms and service versions, retain unresolved prerequisites and hand obligations to their operating owners.
Evaluation
Questions that change the decision
- What does this clause let this actor inspect or obtain?
- Can the necessary permission be secured throughout the supplier chain?
- Which notice or frequency exception changes the staffing assumption?
- Does a proposed safeguard preserve the required evidence?
- Who funds an audit triggered by a material breach?
- What evidence must exist before the offer can accept these terms?
Failure modes
Where teams lose control
A certificate is treated as permission to enter a supplier’s premises.
A normal audit frequency is priced as an absolute annual limit.
A confidentiality clause is used to promise information belonging to another customer.
Records are retained but cannot be retrieved or explained after exit.
A cost allowance is described as a contractual cap.
A disputed finding disappears from the handover instead of retaining its status.
Measurement
Measure the finished job
Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.
- Rights without a matching evidence route
- Supplier permissions still unsigned
- Peak hours required from scarce specialists
- Unfunded routine and triggered cooperation costs
- Post-exit access duties without an owner
- Release conditions without dated completion evidence
Questions
Common questions
Does an assurance report replace a buyer audit?
Only if the applicable terms and law allow that treatment and the required authority agrees. Check the report’s scope, period, exclusions and disclosure limits separately. A report may inform the audit without providing the contractual right to inspect people, premises or particular records.
Can we promise access our subprovider does not permit?
Treat that as an unresolved supplier dependency. Obtain a binding, workable permission, change the delivery arrangement or use an authorized contractual treatment before accepting the commitment. The prime’s willingness to cooperate does not create a right against a separate provider.
Is the ordinary notice period guaranteed?
Read the exact language and its exceptions. An obligation to try to provide notice differs from a minimum notice condition, and incidents or statutory powers can have separate rules. Cost and staff the relevant urgent case without inventing a right to delay a valid inspection.
Can we redact information about other customers?
Identify the conflict and the lawful, contractually valid evidence route. Redaction may be appropriate, but its basis and effect need review. Keep originals and an authorized redaction record, and do not use confidentiality to hide adverse evidence or defeat a valid audit purpose.
Does the priced audit allowance limit our duty?
No. A budget assumption limits neither a contractual right nor a statutory duty. Record any actual contractual cap separately, including exceptions, buyer-cost reimbursement and remedies. Price the modeled scenarios and keep unquantified exposures visible.
What proves the review is ready for acceptance?
Each material right needs an evidenced delivery route or an authorized treatment with explicit prerequisites. The approval must cover the exact service, supplier permissions, costs and clauses. Unresolved legal meaning or access remains a hold; finishing this review does not confer signature or submission authority.
Sources
Primary references
- GDPR: processor audit cooperation and supervisory powers, Articles 28 and 58 European Union
- Decision 2021/915: controller-processor clauses 7.6 and 7.7 European Commission
- DORA: Article 30(3)(e), ICT supporting critical or important functions European Union
- Model Services Contract core terms, England and Wales, v2.2A Cabinet Office
- Model Services Contract schedules, England and Wales: Schedule 15 audit provisions Cabinet Office
- SP 800-53A Rev. 5: assessment methods and current release information National Institute of Standards and Technology
Zelius
Managed tender intelligence and bid execution for teams that want the commercial outcome.
Suppliers, founders and commercial teams pursuing public or private opportunities. Start with the workflow, constraints and evidence you already have.