Direct answer
Retain the vendor’s current criticality, evidence inventory and freshness, open findings and remediation commitments, incidents or material changes, exceptions, review decisions, resilience/exercise results where relevant, and the next review trigger. Ongoing assurance should show how new information changes or confirms the risk decision.
Evidence to retain
Freshness evidence
EvidenceEvidence inventory
EvidenceLast review date
EvidenceScope covered
EvidenceExpiry or refresh date
Change evidence
EvidenceMaterial service change
EvidenceOwnership/change notice
EvidenceAccess/integration change
EvidenceNew data or dependency scope
Performance evidence
EvidenceOpen findings
EvidenceRemediation commitments
EvidenceIncident history
EvidenceResilience/exercise findings where applicable
Governance evidence
EvidenceReassessment decision
EvidenceResidual-risk decision
EvidenceEscalation/exception
EvidenceNext review trigger and owner
Relevant Cybatar sources
Cybatar sourcehttps://crgexplore.com/platform/resilience-vendor-assuranceCybatar sourcehttps://crgexplore.com/platform/reporting-governanceCybatar sourcehttps://crgexplore.com/platform/risk-compliance-assuranceCybatar sourcehttps://crgexplore.com/security-operations-maturity-model
External references
NIST SP 800-161 Rev. 1https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/finalNIST SP 800-160 Vol. 2 Rev. 1https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final
Claim boundary
Ongoing assurance can show that defined reviews and evidence checks occur; it cannot guarantee that the organisation knows every supplier vulnerability, sub-tier dependency, control failure or undisclosed incident.