Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Reassessment Cadence
Governance, Ownership & Risk

Reassessment Cadence

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: Governance, Ownership & Risk

Reassessment cadence is the schedule on which a previously approved vendor is reviewed again. It matters because vendor risk changes as contracts, controls, data scope, and business dependency change, and a static assessment cannot show whether the original decision still holds.

What reassessment cadence means in vendor risk

Reassessment cadence is the rhythm of vendor re-review after initial approval. Its purpose is to keep the risk decision current as the vendor’s controls, data access, service scope, subcontractors, and operational dependence evolve.

Why cadence matters more than a one-time approval

A vendor can be acceptable at onboarding and later become misaligned with policy if the relationship changes. The cadence should reflect the vendor’s risk tier, the sensitivity of the data or systems involved, and how quickly the vendor’s environment or services tend to change.

In practice, shorter intervals are usually warranted when a vendor supports critical services, handles regulated or sensitive data, or has broad connectivity into internal systems. Longer intervals can be reasonable for low-risk providers, but only when the original assumptions remain stable and the business can tolerate slower detection of drift.

What a reassessment should review

A useful reassessment looks beyond the original questionnaire and asks whether the prior approval still holds. Common review points include material contract changes, scope creep, security control changes, incident history, access path changes, evidence of remediation, and whether the vendor’s own subcontractors or hosting model have changed.

Because reassessment is about continuity of assurance, it should include the factors most likely to change the answer over time. That often means reviewing NIST Cybersecurity Framework 2.0 for governance and risk review structure, and, where technical controls are central, NIST SP 800-53 Rev 5 Security and Privacy Controls for access control, audit, and configuration expectations.

How cadence supports ongoing vendor governance

Reassessment cadence is a governance control, not a paperwork exercise. It gives the organisation a formal checkpoint for confirming owner accountability, deciding whether risk acceptance still makes sense, and identifying when a vendor should move to a more frequent review cycle.

It is also a practical way to avoid stale approvals. If the cadence is too slow, organisations may miss control drift and business dependency creep; if it is too aggressive, teams can drown in reviews that add little decision value. The right schedule is the one that tracks change rate and consequence.

For broader control mapping, NIST Cybersecurity Framework 2.0 supports governance and risk review, while NIST SP 800-53 Rev 5 Security and Privacy Controls helps translate cadence into reviewable control expectations.

Risk and Threat Considerations

Reassessment cadence creates risk when it is too slow to catch meaningful vendor change. A vendor may accumulate new access, shift infrastructure, add subcontractors, or suffer an incident long before the next review, leaving the original approval outdated.

Failure mechanism: Approval drift develops when the business continues relying on an old risk assessment after the vendor’s controls, access, or dependencies have materially changed.

Impact: The organisation can retain an unacceptable vendor longer than intended, increasing exposure to service disruption, data loss, compliance failure, and trusted-path abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyReassessment cadence operationalizes recurring vendor risk review.
GV.OV-01 — Oversight of Risk ManagementCadence is an oversight mechanism for checking whether prior approvals still hold.
Recommendation — Align vendor review intervals to risk strategy and change rate. Use recurring oversight to confirm vendor risk decisions remain valid.
NIST SP 800-53 Rev 5CA-7 — Continuous MonitoringVendor reassessment is a periodic monitoring activity over time.
SA-9 — External System ServicesVendor cadence governs continued trust in externally provided services.
Recommendation — Monitor supplier security posture on a recurring schedule. Review external service providers at intervals matched to service criticality.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsSupplier relationships require ongoing security review, not one-time approval.
Recommendation — Review supplier security terms and evidence throughout the relationship.

Practitioner Guidance

Why practitioners should care: Set cadence by change rate and consequence, not by calendar habit. High-impact vendors should be reviewed often enough that the organisation can detect material drift before it becomes an accepted dependency.

Common misunderstanding: A scheduled reassessment is only useful if it is tied to decision-making. If no one can act on what changed, the review becomes a ritual rather than a control.

Practitioner takeaway: Reassessment cadence should answer one question clearly, namely whether the vendor is still acceptable under the assumptions that justified approval in the first place.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org