The baseline cadence
An annual assessment is the minimum sensible cadence for most organisations — frequent enough to catch drift before it becomes serious, infrequent enough to be practically sustainable. Organisations with higher inherent risk (financial institutions, healthcare providers) sometimes move to a more frequent baseline, but annual is the floor, not a target to reduce.
Trigger events that mean "now," not "wait for the annual cycle"
Certain events should prompt an assessment regardless of when the last one happened: deploying a new core system, a significant security incident (even a near-miss), entering a new regulatory environment, or a major change in third-party integrations or vendor relationships.
Why sector changes the answer
A fast-growing fintech accumulating technical debt month over month has a different effective cadence need than a stable, slower-moving enterprise. This is part of why RETIS scopes assessment cadence per organisation during a briefing call rather than applying one fixed schedule to everyone.
A practical checklist
- When was your last formal risk assessment — and can you name the date?
- Has anything changed since then that would count as a trigger event?
- Is your next assessment scheduled, or does it depend on someone remembering?
- Does your risk register get updated between full assessments, or only during them?
