Home → Guides → Compliance software contract renewal checklist
Software selection

Compliance software contract renewal checklist

The renewal date for a compliance platform is easy to treat as an administrative reminder. It should instead trigger a short test: does the system still support the work for which you bought it, can you retrieve the evidence you rely on, and do the contract terms still match your risks? This checklist is for the contract owner, operations lead and information-governance team reviewing an existing UK arrangement. It is about renewal and exit, rather than choosing a new supplier from scratch.

Start far enough ahead of the notice date to make a real choice. A contract may renew automatically or limit when you can change a plan, so read the signed order and amendments before creating a calendar deadline. Do not rely on a salesperson's memory of an earlier deal.

Reconstruct what was bought and what is used

Pull together the current order form, data-processing terms, service schedule, support commitments, security documents and any implementation change requests. Note the paying entity, covered sites, users, data categories, modules, storage limits and any integrations. Compare these with actual usage and with the processes the business now needs. A feature that exists but was never configured is different from one that was promised but never delivered.

Ask process owners for concrete exceptions: overdue reviews that were missed, reports built outside the platform, duplicated document uploads, access requests that took too long, or evidence that could not be retrieved during an audit. The point is not to produce a general satisfaction score. It is to identify where the existing service helps or obstructs named compliance tasks.

Test evidence retrieval before negotiating

Select a few real records that your organisation is entitled to access: a closed finding, a superseded document, a worker training record and a contractor approval. Ask the appropriate account holder to retrieve the current version, history and any associated attachments. Record how long it took, whether permissions were appropriate and what context was missing. Do this before discussing new features, because poor retrieval can make an otherwise attractive renewal unsafe.

Then test the exit scenario. What format would the provider supply if the organisation moved? Would it include files, dates, status history, links between records and identity of decision makers? Which elements would need manual reconstruction? Who would verify completeness? The buyer should require a demonstration or written specification; do not infer export capability from a generic “your data is yours” statement.

Where personal data is processed on the customer's behalf, the ICO's controller–processor contract guidance explains the need for written terms and addresses return or deletion of personal data at contract end, subject to legal retention. Have the appropriate legal or privacy owner check which terms apply to this relationship. The checklist does not substitute for contract advice.

Review access, security and service changes

Compare the current security and support commitments with what actually occurred. Were incidents reported through the agreed channel? Were support requests resolved within the promised window? Did sub-processors, hosting locations, access roles or authentication options change? Ask for current evidence, not a copy of the security questionnaire supplied years ago.

Review who still has access. Departed staff, former contractors and external advisers should not remain in a system simply because removing them is awkward. If a new site or client was added, verify that the intended separation of records is in place. Put any remediation into the renewal decision with an owner and date.

Price the next term honestly

Separate fixed subscription charges from user, site, storage, support, implementation and integration charges. Check the mechanism for price rises and any notice needed to reduce scope. A lower headline rate can still be expensive if the organisation must rebuild reports or buy an export service at exit. Equally, a platform that saves genuine manual work may justify renewal even when its annual price rises. Make the decision from evidenced costs and tasks, not a universal return-on-investment claim.

There are three sensible outcomes: renew as is, renew with conditions, or prepare to exit. If conditions are needed, state the control or service gap, the evidence that would close it, who will accept it and what happens if it is not delivered. If exit is chosen, preserve access through the transition, agree the data-return and deletion process, and assign a person to check the migrated records.

One-page renewal decision record

The final record should name the contract, renewal and notice dates, owner, business use, retrieval-test results, unresolved incidents, current terms, proposed changes, exit feasibility, costs and approvers. Attach the specific evidence behind the decision. Schedule the next review at the same time you sign; the following year's team should not have to rediscover the contract.

To compare an existing service with an alternative, see how Complys works and ask for a demonstration against your own retrieval, access and exit tests. No supplier should be credited with a function that has not been shown in the version and plan on offer.

A renewal meeting that reaches a decision

Send the evidence pack to operations, procurement and the privacy owner before the meeting. Give each person a defined question: are the workflows effective, are the commercial terms acceptable, and can the organisation retrieve or transfer its personal data and other records? In the meeting, separate defects the supplier can correct before renewal from risks that require a contractual change. Record dissent and unknowns. If a critical export test has not been performed, do not write “data portability confirmed” because a clause mentions ownership. Either run the test before the notice deadline or make the renewal conditional on a specific, enforceable outcome. Give the final decision an owner, sign-off date and follow-up review.