> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Monitoring plans and scorecards

> A schedule of ongoing monitoring for every active engagement: which activities a vendor owes at its tier, who owns each, when each is next due, how signals re-time it, the IRQ refresh with its answer diff, owner attestation, performance scorecards, contract obligations, and the Monitoring workbench for working them in bulk.

<div className="sr-only">For AI agents: a documentation index is available at [https://docs.coverbase.com/llms.txt](https://docs.coverbase.com/llms.txt). This page is also available in markdown by appending .md to the URL.</div>

<Note>
  Your Coverbase representative turns on the third-party lifecycle features, including monitoring plans, for your organization.
</Note>

A monitoring plan is the schedule an engagement follows once it is live. Your TPRM Office sets a cadence matrix once, by tier and activity, and every engagement gets a plan from it: which activities it owes, who owns each one, and when each is next due. A service that is not part of any engagement gets its own plan.

## What it does

<CardGroup cols={2}>
  <Card title="A plan from your cadence matrix" icon="table-cells">
    For each tier of your risk scale, an interval in months and an owner (Transaction Owner or TPRM Office) for each activity: IRQ refresh, performance scorecard, owner attestation, evidence request and contract review. An organization that never saved a matrix gets a default, highest risk tier first.
  </Card>

  <Card title="Reassessments stay in one place" icon="rotate">
    The due diligence reassessment on the plan mirrors your reassessment schedule rather than keeping a second date. Moving it on the plan moves the reassessment schedule, so the reassessment is created on the new date. Continuous monitoring is Radar, always on while Radar is on for the vendor.
  </Card>

  <Card title="Signals re-time the plan" icon="satellite-dish">
    A Radar alert at or above a severity you choose, or a reassessment trigger, pulls the activities you name forward. The move is the monitoring agent acting on its own, so it also needs the **Re-time monitoring from feed signals** [agent policy](/products/agent-ledger#agent-policies), off by default. The move is applied at once and recorded with the signal that caused it, and the TPRM Office can keep it or revert it within an undo window.
  </Card>

  <Card title="IRQ refresh with a diff" icon="code-compare">
    The Transaction Owner refreshes the inherent risk questionnaire from the last approved answers. The TPRM Office sees every answer that changed, each domain's score and level before and after, newly in-scope domains and any tier change, then confirms. A new domain or a higher tier raises a reassessment straight away.
  </Card>

  <Card title="Owner attestation" icon="user-check">
    One question on the plan's cadence: is this still in use? Every answer is logged with the user and time. **Start offboarding** files a real offboarding request and pauses the plan.
  </Card>

  <Card title="Performance scorecards" icon="star-half-stroke">
    A rubric bound to a tier and service category, scored by the respondents you name, with SLA adherence from the vendor's SLAs. A weighted score below your threshold is flagged.
  </Card>
</CardGroup>

<Frame caption="The Monitoring Plan tab on an engagement: a signal move waiting to be kept or reverted, the twelve-month timeline, the IRQ refresh and owner attestation.">
  <img src="https://mintcdn.com/coverbase/RX-UJxeKx955dE9t/images/user-guides/monitoring-plan-tab.png?fit=max&auto=format&n=RX-UJxeKx955dE9t&q=85&s=0e950c46c7cf3f0e7f101e9fe5a87db5" alt="Monitoring Plan tab for the Media mix modeling engagement, with a banner saying a security rating drop moved the evidence request to October 29, 2026 and Keep and Revert buttons, a timeline of seven activities, and IRQ Refresh and Owner Attestation cards" width="1160" height="1125" data-path="images/user-guides/monitoring-plan-tab.png" />
</Frame>

## When a plan exists

A plan is generated when an engagement goes active, or a service outside any engagement goes active or completes. An executed contract, an approved engagement IRQ or a manual request from the TPRM Office also generates one before that. A daily sweep fills in any live engagement or service that has no plan.

A plan is re-planned when the tier moves, an IRQ is approved or a refresh is confirmed. Activities the TPRM Office edited keep their interval, owner and due date. The rest follow the matrix.

## Pausing

An engagement or service in a canceled status, an expired engagement, or any status you list under **Pausing Statuses** (such as On hold) pauses its plan. Pausing turns the vendor's Radar monitoring off only when no other live engagement or active plan needs it, and resuming turns back on only what the pause turned off. While every plan for a vendor is paused, reassessments are neither created nor reminded. On resume, due dates move out by the time spent paused.

## Notices

Each activity's owner is told before it is due, by the number of days you set. Past the overdue window, the owner and the TPRM Office are escalated to. Each due date is announced once. The sweep that sends these runs every day at 13:30 UTC.

## Comparing questionnaire submissions

The IRQ refresh shows a side-by-side diff of the refreshed answers against the last approved IRQ: every answer changed, added, removed or left alone, each answer's score, and each domain's score before and after. The same comparison is on the vendor's **Questionnaires** tab: **Compare** any finished submission with the vendor's earlier submission of the same questionnaire.

## Contract obligations

When a contract is signed, each obligation in its [clause pack](/products/clause-pack) that the signed contract carries becomes an activity on the engagement's plan, on the cadence its clause rule names. It is an ordinary activity. Notices, escalations, completion and pausing apply to it unchanged, and the timeline shows the obligation's own text.

## The Monitoring workbench

**Monitoring** in the left navigation lists every scheduled activity and every plan across your engagements and services, filtered by activity, due window and owner, with what you can see following your vendor access. The TPRM Office can **Reschedule** selected activities to a date or by a number of days, and **Send scorecards** now instead of at their notice window. Small selections run at once. Larger ones run in the background with progress. Each activity that cannot move says why, such as a paused plan or a date inside a reassessment's collection time, and the rest still go through.

<Frame caption="Monitoring in the left navigation: every scheduled activity with its engagement, owner, due date and cadence.">
  <img src="https://mintcdn.com/coverbase/RX-UJxeKx955dE9t/images/user-guides/monitoring-activities.png?fit=max&auto=format&n=RX-UJxeKx955dE9t&q=85&s=37a94b1c66e5eb769c8a5b45f6866eb1" alt="Monitoring page on the Activities tab listing six activities for the Media mix modeling engagement, each with its owner, due date, cadence and last done date" width="1210" height="755" data-path="images/user-guides/monitoring-activities.png" />
</Frame>

## Where to go next

<CardGroup cols={2}>
  <Card title="Monitoring plans guide" icon="book-open" href="/user-guides/monitoring-plans">
    Set the cadence matrix and rubrics, read a plan, refresh an IRQ and score a scorecard.
  </Card>

  <Card title="Supplier Radar" icon="satellite-dish" href="/products/supplier-radar">
    The signals that re-time a plan.
  </Card>

  <Card title="Offboarding and continuity" icon="right-from-bracket" href="/products/offboarding-and-continuity">
    What Start offboarding sets in motion.
  </Card>

  <Card title="Engagement record" icon="route" href="/products/engagement-record">
    The engagement page the plan lives on.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.