> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Run a quarterly compliance posture review

> A four-check quarterly operator cadence for your tenant-owned compliance controls: read the health score, re-verify consent, recording announcements, time windows, attestation, and suppression, exercise the DSAR pipeline end to end, and close the quarter with the evidence binder.

# Run a quarterly compliance posture review

Your posture was set deliberately once — at launch, market by market, through the [first-run configuration guide](/compliance/tenant-posture-first-run). This runbook is the recurring half of that discipline: a four-check quarterly review that re-verifies the [per-control surfaces](/compliance/posture-overview) after a quarter of traffic, and closes with evidence. It assumes the controls are set; it asks whether they are still set *correctly*.

<Note>
  Every control re-verified here is tenant-owned. Orbit provides the
  surfaces and defaults them open; you configure them and you own the
  posture. This page is an operational runbook, not legal advice —
  confirm which obligations apply to your traffic with counsel.
</Note>

***

## Why posture decays between audits

Compliance configuration behaves like a garden, not a vault. The toggles you set at launch are point-in-time decisions, and four forces move them without touching a toggle:

* **Traffic drift.** You launched with one SMS campaign; by Q3 you run WhatsApp, a dialer, and a reactivation flow a teammate added. A 12,000-recipient import quietly lowers consent coverage from 98% to 81% — and the first place that registers is not a carrier throttle, it is your [compliance-health score](/compliance/compliance-health).
* **Jurisdiction drift.** A US SMS program expands to Brazil (LGPD, a 15-day DSAR clock) and the UK. Each market re-asks the consent, disclosure, and announcement questions you last answered at launch.
* **Consent staleness.** Captured consent ages — the `valid_until` on a receipt expires, the `consent_text_version` on an old CSV import no longer matches the policy page a new contact actually saw, and a proof URL nobody archived is a proof you cannot produce.
* **DSAR pipeline decay.** An intake portal nobody filed through, an OTP sender no one configured, an export link that expired before anyone downloaded it. The time to find a broken fulfilment path is a drill, not a live request with a statutory clock running.

Quarterly works because it matches how the reference data ages: consent windows expire on 90-day and annual boundaries, carrier score windows top out at 90 days, and a statutory DSAR clock is short enough that discovering a broken pipeline during a live request is a breach you chose.

***

## The quarterly cadence — four checks

An hour-ish per quarter for a single-market tenant; wider portfolios budget proportionally. Run the checks in order — each one narrows the next.

| # | Check                                              | Surface it reads                                                                                                                                                                                                                                                                                                                               | Failure it catches                                         |
| - | -------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- |
| 1 | Read the health score                              | [Compliance health scores](/compliance/compliance-health)                                                                                                                                                                                                                                                                                      | Drift arriving before a carrier acts on it                 |
| 2 | Re-verify consent, recording, and channel coverage | [Consent management](/compliance/consent-management), [BAA](/compliance/baa), [recording consent](/compliance/recording-consent), [quiet hours](/guides/quiet-hours-configuration), [state calling windows](/compliance/state-calling-windows), [attestation](/compliance/attestation), [opt-out suppression](/compliance/opt-out-suppression) | An enforcement surface that no longer matches your traffic |
| 3 | Exercise the DSAR pipeline                         | [DSAR](/compliance/dsar)                                                                                                                                                                                                                                                                                                                       | A fulfilment path discovered broken during a live request  |
| 4 | Close with evidence                                | [Evidence binder](/compliance/evidence-binder)                                                                                                                                                                                                                                                                                                 | A quarter that ended done but not provable                 |

### Check 1 — Read the health score (15 minutes)

Open the [compliance-health score](/compliance/compliance-health) per organization, sender, and campaign, with the window set to the quarter. The score blends four signals — consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections — and none of them gates a send; a low score is advisory until you act on it. That is the point of the review: it is the early-warning read before a carrier throttle or a rejection spike becomes the message.

Flag for Check 2:

* `consent_coverage` sliding from `ok` toward `warn` while volume grows — a list import or capture path that never wrote consent records.
* Opt-out velocity climbing on a specific sender or campaign — wording, frequency, or audience drift worth fixing before the carrier notices.

### Check 2 — Re-verify consent and channel coverage (30 minutes)

The correct-at-launch pairing decays in specific, checkable places. Work down the list against the markets and channels you actually ran this quarter:

* **Consent records and receipts** — confirm capture points still write consent on every collection path, and that the channel mix you now run is covered by the records you hold. For HIPAA-adjacent audiences, confirm the [BAA](/compliance/baa) is signed and current. Reference: [Consent Management & Receipts](/compliance/consent-management).
* **Recording announcement coverage** — list the jurisdictions you placed or received calls in this quarter (call logs group by destination), then compare the announcement pairing saved in **Voice → Calls → Recording settings** — `settings.recording.{eligibility_mode, consent_announcement_mode}` — against the strictest of them. Dialing into an all-party-consent jurisdiction with `announce_caller` set, or auto-recording with `consent_announcement_mode: none` (an in-app warning Orbit surfaces — this check is where a dismissed warning gets caught), is exactly the drift this audit exists to find. Reference: [Call Recording Consent](/compliance/recording-consent).
* **Time-window gates** — re-read your [quiet hours](/guides/quiet-hours-configuration) per channel against current sending patterns, and the [US state calling windows](/compliance/state-calling-windows) against the states you actually dialed. A seasonal override set for one campaign and never lifted is a six-month posture change nobody decided on.
* **STIR/SHAKEN attestation** — review the per-number attestation posture of your outbound voice in [Attestation posture](/compliance/attestation), not only at onboarding. Numbers provisioned mid-quarter inherit posture separately.
* **Suppression enforcement** — confirm opt-out suppression is still enforced, end to end, by running a pre-send check on a sample known-suppressed contact and watching it hold. Reference: [Opt-Out & Suppression Lists](/compliance/opt-out-suppression).

### Check 3 — Exercise the DSAR pipeline (15 minutes)

The failure this check catches is not a late request — it is a pipeline you never exercised, discovered live. Once a quarter, against the [DSAR surface](/compliance/dsar):

1. **File one request against your own contact record** — the fire drill. Verify it enters the operator queue alongside real traffic and that the portal path (or operator intake) marks verification the way you expect.
2. **Read the SLA snapshot.** Per-request `days_remaining` and severity tier are scaled to each jurisdiction's deadline — GDPR 30 days, CCPA/CPRA 45, LGPD 15. Anything breached, or an `approaching` count that keeps growing, is a staffing problem surfacing a quarter early.
3. **Download one export.** Signed export links expire — open one, confirm the file contains what you would actually hand a data subject, and confirm your team knows where the row counts per table are described.
4. **Re-set the jurisdiction mix at intake.** If you launched GDPR-only and now market into California or Brazil, requests arriving under the wrong `applicable_jurisdiction` grade against the wrong clock. Intake accuracy is part of the review.

### Check 4 — Close with evidence (10 minutes)

End the quarter provable, not just done:

1. **Archive the quarter's consent and suppression exports** — both of them, at `status=all` so revoked rows are preserved and the file proves re-permissioning, not just the active blocklist.
2. **Generate a binder** — **Settings → Compliance → Binder**, pick the framework your auditor or buyer asks for (SOC 2 for procurement, GDPR for the privacy file), and the format. The walkthrough is in [Assemble and seal an evidence binder](/guides/compliance-evidence-binder); the framework tables in the [binder reference](/compliance/evidence-binder). A quarterly generation builds the habit *and* a comparable archive: two generations over the same data are byte-identical and carry a SHA-256 checksum, so quarter-over-quarter diffs are mechanical and a tamper-flagged generation surfaces while there is still time to investigate.

The binder only assembles what your workspace already produced; if Checks 1–3 found drift, remediate first and regenerate — the row an auditor reads should quote the workspace that moved forward.

***

## Override file + sign-off

Overrides are legitimate posture — a seasonal window lift, a manual-only recording designation, a dialer exemption — as long as someone can name its expiry. Keep them out of memory and in one file; the review then costs minutes.

```text theme={null}
COMPLIANCE OVERRIDE FILE — <workspace> — <YYYY-QN>
# One line per deliberate deviation from the default or launch posture.
# If it is not in this file, it reverts to default next review.

override:      <surface / setting / value>
reason:        <why this deviation is intentional>
approved_by:   <name, date>
expires:       <date or event — never blank>
review_status: <active / expired / reverted>

# Example
override:      quiet hours SMS lifted to 22:30 local
reason:        Black Friday campaign window
approved_by:   A. Okoro, 2026-11-20
expires:       2026-12-01
review_status: expired — reverted 2026-12-02
```

Quarterly sign-off checklist — attach it to the binder generation record in your audit log:

* [ ] Health score reviewed per org, sender, and campaign; findings logged
* [ ] Overrides above re-confirmed or reverted
* [ ] Consent coverage confirmed for every capture path and channel in use
* [ ] Recording `eligibility_mode` × `consent_announcement_mode` pairing confirmed against the quarter's actual call destinations
* [ ] Quiet hours and state calling windows confirmed against actual traffic
* [ ] Attestation posture reviewed on numbers provisioned this quarter
* [ ] Suppression enforcement verified on a known-suppressed sample contact
* [ ] DSAR fire drill filed, SLA snapshot clean, one export downloaded
* [ ] Consent and suppression exports archived for the quarter
* [ ] Binder generated and checksum recorded

Sign-off: \_\_\_\_\_\_\_\_\_ (name)  \_\_\_\_\_\_\_\_\_ (role)  \_\_\_\_\_\_\_\_\_ (date)

Keep the chain — checklist, override file, binder checksum — in your own records. Orbit's audit log records generation and remediation; the sign-off artifact is yours.

***

## Related

* [Compliance posture overview](/compliance/posture-overview) — the per-control surfaces this cadence re-verifies
* [First-run tenant posture](/compliance/tenant-posture-first-run) — the launch-time counterpart; run it once per market, run this review every quarter
* [Assemble and seal an evidence binder](/guides/compliance-evidence-binder) — the binder walkthrough, incl. gated-surface verdicts
* [Compliance posture FAQ](/compliance/posture-faq) — the tenant-owned-controls mental model
