Hi Natalia, GM
ongoing monitoring (OGM) frequency is set on inherent risk. It is consistent, unless the service changes. Also Residul Risk is a snap shot of control strength and controls are dependent on people, budgets, technology and a vendors overall strategic objectives. Therefore, a vendor's control framework is fluid.
Also, if you use residual risk, you could overlook high risk vendors (not have them on annual OGM), since their residual risk may end up with a low rating. In that case, high risk vendors may be set to a 3 year OGM frequency. Certainly, this would catch the attention of Regulators.
Regards, John - happy to chat
Original Message:
Sent: 11-29-2022 02:02 PM
From: Natalia Weems
Subject: Monitoring Frequency: based on inherent or residual risk?
Hi!
could you please share your thoughts and experince on the following:
Do you schedule the frequency of the vendors' review based on the inherent risk or residual? and why?
Thank you