KITE 2025 New Product Award — Local IT | SACEEC

What Is a Compliance Calendar and How Do You Build One?

A missed filing deadline is one of the most avoidable compliance failures there is. A compliance calendar is how disciplined teams make sure it never happens.

Free PDF GuideDownload this guide as a PDF

Most serious compliance failures are not the result of complex judgment calls. They are missed dates. A licence that lapsed, a return filed a week late, a mandatory training cycle that quietly slipped. These failures are entirely preventable, and the tool that prevents them is humble but powerful: a compliance calendar.

Watch: What a compliance calendar is and how to build one Watch: Building a compliance calendar (short explainer)
i

What You'll Learn

By the end of this article you will understand what a compliance calendar is, what it should track, how to build and maintain one, how to assign ownership and reminders, and the practices that ensure no deadline is ever missed again.

What Is a Compliance Calendar?

A compliance calendar is a single, maintained schedule of every recurring compliance obligation that has a date attached to it. Where a compliance register tells you what your obligations are, the compliance calendar tells you when each one must be acted on, and who is responsible for acting.

It is the time dimension of your compliance program. Many obligations are not one-off; they recur on fixed cycles, such as monthly filings, annual renewals, and quarterly reviews. A register captures the obligation once. The calendar makes sure it actually gets done every cycle, on time, by someone accountable.

Done well, the compliance calendar is the operational backbone that connects obligations to action. It pairs naturally with tracking compliance obligations and feeds the deadlines you report on when you describe how you track and report compliance status.

What a Compliance Calendar Tracks

A compliance calendar should capture every dated obligation, not just the obvious regulatory filings. The most common categories are below.

Filing and Reporting Deadlines

Statutory returns, regulatory submissions, tax filings, and mandatory reports. These usually carry the harshest penalties for lateness, so they are the calendar's highest priority.

Licence and Registration Renewals

Operating licences, permits, certifications, and registrations that expire and must be renewed. A lapsed licence can halt operations entirely, so renewals often need lead time, not just a deadline.

Periodic Reviews

Policy reviews, control testing, access reviews, risk assessments, and register updates that must happen on a cycle. These keep the rest of your program current rather than letting it drift.

Training and Awareness

Mandatory training cycles, such as anti-money-laundering, privacy, health and safety, and code of conduct, that must be completed and evidenced within set windows.

Attestations and Sign-Offs

Periodic management attestations, conflict-of-interest declarations, and certifications that controls operated. These often feed directly into board compliance reporting.

Category Examples Typical Cadence Penalty for Lateness
Filings & reporting Tax returns, regulatory submissions Monthly / annual Fines, interest, enforcement
Renewals Licences, permits, certifications Annual / multi-year Loss of authorization to operate
Periodic reviews Policy review, access review Quarterly / annual Stale controls, audit findings
Training AML, privacy, safety training Annual Regulatory exposure, gaps
Attestations Management sign-offs, COI declarations Quarterly / annual Weak accountability trail

Want the full framework with worked examples?

How to Build a Compliance Calendar

Building the calendar is a structured exercise, not a one-afternoon job. Work through it methodically so nothing slips through the gaps.

Step 1: Start from the Obligation Register

Pull every obligation that has a recurring date from your compliance register. The register is your source of truth; the calendar is its time-based view. If an obligation is not in the register, fix the register first.

Step 2: Capture the Real Deadline and the Lead Time

For each entry, record the actual due date and the work required beforehand. A return due on the 25th may need data gathered by the 15th and reviewed by the 20th. Calendars that only show the final date cause last-minute scrambles.

Step 3: Assign a Single Owner

Every entry needs one accountable owner, a named person, not a department. Shared ownership means no ownership. The owner is responsible for completing the obligation and confirming it was done.

Step 4: Set Reminders with Buffer

Configure reminders well ahead of each deadline, with escalation if the task is not confirmed complete. A reminder that fires on the due date is useless. Build in buffer to act.

Step 5: Link Each Entry to Its Evidence

When a task completes, the calendar should capture or link to the proof. This ties the calendar to your compliance evidence, so completing the task and evidencing it become a single step rather than two.

Example

A Calendar Entry Built Properly

Obligation: Quarterly VAT return.

Final deadline: 25th of the month following quarter-end.

Lead-time tasks: Data compiled by the 12th; reviewed by finance by the 18th; submitted by the 22nd (buffer before the 25th).

Owner: Tax Manager (named individual).

Reminders: Alerts on the 5th, 12th, and 18th; escalation to the CFO if not confirmed submitted by the 22nd.

Evidence: Submission confirmation receipt linked to the entry on completion.

Reminders, Ownership, and Escalation

A calendar that simply lists dates is a wish list. What turns it into a control is the layer of ownership, reminders, and escalation around each entry.

One Accountable Owner per Entry

Accountability must be unambiguous. When a deadline approaches, exactly one person should know it is theirs. If that person is on leave, the calendar should have a documented backup, not a silent gap.

Layered Reminders

Use more than one reminder, spaced before the deadline: early enough to start the work, again to check progress, and a final prompt before the cut-off. Critical, high-penalty obligations warrant earlier and more frequent prompts.

Escalation When Tasks Stall

If an obligation is not confirmed complete by a checkpoint, the calendar should escalate to the owner's manager automatically. Quiet reminders that no one is forced to answer are how deadlines slip unnoticed.

i

Pro Tip

Require explicit confirmation of completion, not just an unactioned reminder. "Mark as done with evidence attached" is a far stronger control than an email that silently expires. A task is not complete until someone confirms it and the proof is captured.

Example Calendar Entries

Here is how a slice of a working compliance calendar might look. The discipline is consistency: every entry has a clear deadline, an owner, a reminder cadence, and a status.

Obligation Frequency Next Due Owner Reminder Status
VAT return Quarterly 25 Apr 2026 Tax Manager -20, -7, -3 days On track
Operating licence renewal Annual 30 Jun 2026 Compliance Officer -60, -30, -7 days In progress
AML training cycle Annual 15 May 2026 HR Lead -30, -14, -3 days On track
Access review Quarterly 31 Mar 2026 IT Manager -14, -3 days Due soon
Privacy policy review Annual 01 Aug 2026 DPO -45, -14 days Scheduled

Maintaining the Calendar and Avoiding Missed Deadlines

A calendar is only as good as its upkeep. Obligations change, regulations shift, and owners move on. Without maintenance, the calendar quietly drifts out of date until it fails when you most need it.

Review and Reconcile Regularly

At a set cadence, at least quarterly, reconcile the calendar against the obligation register and against any regulatory changes. New obligations get added, obsolete ones get retired, and owners get reassigned when people change roles.

Roll Recurring Dates Forward Automatically

When a recurring obligation completes, the next occurrence should appear immediately. A calendar that only shows the current cycle hides what is coming and invites surprises.

Track and Learn from Near-Misses

If a deadline was met only at the last minute, treat that as a warning. Adjust lead times and reminders before the next cycle. Near-misses are free lessons; ignore them and the next one becomes a real miss.

!

Important

Do not let the compliance calendar live only in one person's head or personal calendar. When that person leaves or is unavailable, every deadline they carried becomes invisible. The calendar must be a shared, owned, and maintained system, resilient to any single individual's absence.

Common Mistakes to Avoid

1. Tracking Only Final Deadlines

Recording only the due date, with no lead-time tasks, guarantees last-minute scrambles and rushed, error-prone work. Capture the preparation, not just the cut-off.

2. Shared or Vague Ownership

"The finance team owns it" means no one owns it. Assign a single named individual to every entry, with a documented backup.

3. Reminders That Are Too Late or Ignored

A reminder on the due date cannot prevent a miss, and a reminder no one must answer is easily ignored. Use early, layered reminders that require confirmation.

4. Letting the Calendar Go Stale

An unmaintained calendar omits new obligations and points to people who have left. Reconcile it against the register on a regular cycle.

5. Keeping It in One Person's Head

A calendar that depends on a single individual fails the moment they are absent. Make it a shared, resilient system.

6. No Evidence of Completion

Marking a task done without capturing proof leaves you unable to demonstrate the obligation was met. Link completion to evidence every time.

Key Takeaways

Summary

  • A compliance calendar is the time dimension of your program: the schedule of every dated, recurring obligation.
  • It should track filings, renewals, periodic reviews, training, and attestations.
  • Build it from the obligation register, capturing real deadlines, lead times, owners, and reminders.
  • Assign one accountable owner per entry, with layered reminders and automatic escalation.
  • Link each completed task to its evidence so doing and proving are a single step.
  • Maintain it continuously, roll dates forward, and never let it live in one person's head.

Frequently Asked Questions

How is a compliance calendar different from a compliance register?

The register tells you what your obligations are; the calendar tells you when each recurring one must be acted on and by whom. The register is the source of truth, and the calendar is its time-based view. You build the calendar from the dated obligations in the register.

What should the calendar track besides filing deadlines?

Beyond filings and reporting, it should track licence and registration renewals, periodic reviews (policy, control testing, access, risk assessment), mandatory training cycles, and attestations or sign-offs. Any recurring obligation with a date attached belongs on the calendar.

How far in advance should reminders fire?

It depends on the lead time the task requires, but reminders should always fire early enough to actually complete the work, not just to note the deadline. Use layered reminders, an early prompt to start, a mid-point check, and a final prompt before the cut-off, with longer lead times for high-penalty obligations like licence renewals.

Who should own the compliance calendar?

The compliance function typically owns the calendar as a whole and maintains it, but each individual entry must have its own named owner, the person responsible for completing that obligation. Central ownership ensures the calendar stays current; per-entry ownership ensures each deadline actually gets met.

How do we stop deadlines from being missed?

Combine four practices: a single named owner per entry, layered reminders with built-in buffer, automatic escalation when a task is not confirmed complete, and explicit confirmation of completion with evidence attached. Treat any near-miss as a signal to adjust lead times before the next cycle.

Can we just use a shared spreadsheet or team calendar?

A spreadsheet or shared calendar can work when you are starting out, provided it is genuinely shared and maintained. As the program grows, dedicated tooling adds automatic reminders, escalation, evidence linking, and an audit trail that manual approaches struggle to sustain, removing the dependence on any single person remembering to update it.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.