Hi Natalia, GM
ongoing monitoring (OGM) frequency is set on inherent risk. It is consistent, unless the service changes. Also Residul Risk is a snap shot of control strength and controls are dependent on people, budgets, technology and a vendors overall strategic objectives. Therefore, a vendor's control framework is fluid.
Also, if you use residual risk, you could overlook high risk vendors (not have them on annual OGM), since their residual risk may end up with a low rating. In that case, high risk vendors may be set to a 3 year OGM frequency. Certainly, this would catch the attention of Regulators.
Regards, John - happy to chat