Keep the approved risk treatment beside the executed agreement, schedules, incorporated policies, order forms, amendments, and exception approvals. A clause-to-risk record should show which obligation implements each selected treatment and who owns verification.
For each recurring obligation, record the evidence, period, covered entity and service, reviewer, result, limitation, and follow-up. Examples include access reviews, service reports, incident exercises, vulnerability or patch reports, independent assurance, continuity tests, and sub-supplier notices.
Preserve notices, waivers, breach or remediation correspondence, change decisions, and closure evidence. Without this history, a later reviewer cannot tell whether the parties used the enforcement and change mechanisms they agreed.