The baseline cadence

An annual assessment is the minimum sensible cadence for most organisations — frequent enough to catch drift before it becomes serious, infrequent enough to be practically sustainable. Organisations with higher inherent risk (financial institutions, healthcare providers) sometimes move to a more frequent baseline, but annual is the floor, not a target to reduce.

Trigger events that mean "now," not "wait for the annual cycle"

Certain events should prompt an assessment regardless of when the last one happened: deploying a new core system, a significant security incident (even a near-miss), entering a new regulatory environment, or a major change in third-party integrations or vendor relationships.

Why sector changes the answer

A fast-growing fintech accumulating technical debt month over month has a different effective cadence need than a stable, slower-moving enterprise. This is part of why RETIS scopes assessment cadence per organisation during a briefing call rather than applying one fixed schedule to everyone.

A practical checklist

  • When was your last formal risk assessment — and can you name the date?
  • Has anything changed since then that would count as a trigger event?
  • Is your next assessment scheduled, or does it depend on someone remembering?
  • Does your risk register get updated between full assessments, or only during them?

Frequently asked questions