Skip to main content

There is no single correct answer to how often operational due diligence (ODD) should be refreshed, but there is a defensible one. Most institutional investors settle on a full reassessment every 12 to 36 months, set by how much risk each manager relationship carries, supported by event-driven reviews when something material changes and continuous monitoring of the signals that move fastest in between. The calendar decides when the formal review happens; the risk profile decides how often; and events decide when you cannot wait.

That answer is simple to state and harder to run. This article sets out a practical, five-step framework for setting ODD review frequency across a manager roster, explains why a single fixed cycle tends to fail, and highlights the mistakes that most often leave allocators relying on a picture of a manager that is already out of date.

Why a single review cycle rarely works

Many ODD programmes began with a straightforward rule: every manager is reviewed once a year. It is easy to administer and easy to explain to an investment committee. In practice, it creates two problems at once.

First, it spreads resource evenly across relationships that are not evenly risky. A large, complex allocation to an illiquid credit strategy with a newly formed management company receives the same attention as a small, long-standing mandate with a well-established manager whose operational profile has barely changed in years. The first is probably under-reviewed; the second is probably over-reviewed.

Second, and more importantly, a fixed calendar says nothing about when risk actually changes. As we set out in From RFP to Ongoing ODD: Closing the Monitoring Gap, financial stress, cyber exposure, key-person departures and reputational issues tend to develop between review cycles, not in time for them. A review that happens on schedule can still be the first time an ODD team learns about a change that occurred ten months earlier.

A better approach separates three questions that a single annual cycle tends to blur together: how often should the full review happen, what should trigger an unscheduled review, and what should be watched continuously in between?

A five-step framework for setting ODD review frequency

Step 1: Tier your managers by operational risk

Start by grouping managers into risk tiers, rather than treating the roster as one list. The criteria will vary by institution, but they commonly include:

  • Size and concentration of the allocation, relative to the total portfolio and to the manager's own assets under management.
  • Strategy and liquidity profile. Illiquid, leveraged or hard-to-value strategies generally carry more operational complexity than liquid, long-only mandates.
  • Structural complexity, including the number of vehicles, jurisdictions, side letters and service providers involved.
  • Manager maturity and stability, such as the age of the firm, recent growth, ownership changes and depth of the operations team.
  • Findings from the last review. Open remediation items or unresolved concerns should move a manager up a tier until they are closed.

The output should be a documented tier for each manager, with a short rationale, reviewed at least annually. Tiering is only useful if it is revisited: a manager that sat comfortably in a low-risk tier three years ago may no longer belong there.

Step 2: Set a full-review cadence for each tier

With tiers in place, assign each one a baseline cadence for a full reassessment: a refreshed due diligence questionnaire (DDQ), document review, and, where appropriate, an onsite or virtual meeting with the manager's operations team. The table below shows an illustrative starting point. It is not a regulatory standard, and each institution should calibrate it to its own risk appetite, resourcing and governance requirements.

Risk Tier
Typical Profile
Full Reassessment
Interim Touchpoint
HighLarge or concentrated allocation; illiquid, leveraged or complex strategy; newer or fast-growing manager; open findings Every 12 months, often with an onsite visit Quarterly check-in or targeted update 
MediumModerate allocation; established manager; some structural complexity Every 18 to 24 months Annual abbreviated update
LowSmaller allocation; liquid, simple strategy; long, stable relationship with no open findings Every 24 to 36 months Annual attestation of material changes 

The interim touchpoint matters as much as the full review. An abbreviated update, sometimes no more than a short attestation that nothing material has changed, keeps the relationship on record between reassessments and gives the manager a formal opportunity to disclose changes before they are discovered elsewhere.

Step 3: Refresh components at different speeds

Not every part of an ODD file ages at the same rate. Treating the whole assessment as one block to refresh on one date means some elements are checked too often and others far too rarely. A more efficient approach sets a refresh rate for each component:

ODD Component
How Quickly It Can Change
Sensible Refresh Point
Governance, ownership and key personnelCan change suddenlyAt each full review, plus immediately on any reported or detected change
Audited financial statementsAnnually, on publicationOn each new set of accounts, rather than at the next review date
Valuation policy and pricing sourcesUsually slow, but material when it movesAt each full review, and whenever the policy or a pricing source changes 
Service providers (administrator, auditor, custodian, prime broker)OccasionalConfirm external monitoring, supported by questionnaire evidence at review
Cybersecurity postureContinuouslyOngoing external monitoring, supported by questionnaire evidence at review
Business continuity and disaster recoveryModerateAnnually, including evidence that plans have been tested 
Regulatory standing and media coverageContinuously Ongoing monitoring, with alerts on material developments 

 

This is where the question of how often ODD should be refreshed becomes more useful. The better question is how often each piece of evidence should be refreshed, and the answer ranges from continuously to every few years.

Step 4: Define the triggers for an unscheduled review

Event-driven triggers are what stop a well-designed calendar from becoming a blind spot. They should be written down, agreed with the investment committee and, where possible, reflected in side letters or reporting obligations so that managers are expected to notify you. Common triggers include:

  • Departure of a key person, such as a CIO, COO, CFO, CCO or head of technology
  • A change of ownership, a material stake sale or a merger
  • Replacement of a core service provider, particularly the fund administrator or auditor
  • A qualified audit opinion, a delayed audit or a restatement
  • A regulatory inquiry, enforcement action or significant litigation
  • A reported cyber incident or data breach at the manager or a key vendor
  • Significant redemptions, gating, rapid asset growth or a change in strategy
  • Material adverse media coverage concerning the firm or its principals

Each trigger should map to a defined response. Not every event needs a full reassessment; a service provider change might warrant a targeted review of that relationship alone, while a change of ownership may justify a complete one.

Step 5: Monitor continuously between reviews

Triggers only work if you find out about the events that set them off. Relying on managers to self-report is necessary, but it is not sufficient: the issues allocators most need to know about are often the ones a manager is least inclined to volunteer promptly.

This is why many ODD teams now layer independent, ongoing monitoring across the whole roster, regardless of tier. Financial statement analysis, external cyber risk evaluation and news and media surveillance each provide a read on a manager that does not depend on what the manager chooses to disclose. We explore each of these in more depth in Why Cyber Risk Belongs in Operational Due Diligence and Media Monitoring as an ODD Signal. 

Continuous monitoring also changes the role of the scheduled review. Rather than being the moment a problem is first discovered, the formal reassessment becomes the point at which the ODD team confirms what monitoring has already surfaced, tests the manager's response, and updates the baseline. It can also make tiering more responsive: a low-tier manager showing deteriorating signals can be moved up for closer attention without waiting for its next scheduled review.

Common mistakes when setting ODD review frequency

  • Treating tiers as permanent. Tiering decisions should be revisited at least annually and whenever a trigger event occurs.
  • Letting a lower tier mean no oversight. A 36-month review cycle is reasonable only if something is watching the manager in between.
  • Refreshing the questionnaire without verifying the answers. A new DDQ response is still self-reported. Check key statements against audited financials, regulatory records and service provider confirmations.
  • Not documenting the rationale. Trustees, investment committees and, in some cases, supervisors may ask why a manager was reviewed when it was. A written policy with a clear rationale for each tier is far easier to defend than an informal practice.
  • Ignoring the backlog. A policy that the team cannot resource will slip. It is better to set a realistic cadence and supplement it with monitoring than to set an ambitious one and miss it. 

Putting the framework into practice

Setting ODD review frequency well is less about choosing the right number of months and more about building a system in which the calendar, the risk profile and real-world events all play their part. Tier the roster, set a cadence for each tier, refresh each component at the speed it changes, write down your triggers, and make sure something is watching in between. The result is an oversight programme that is proportionate, defensible to trustees and investment committees, and far less likely to be caught out by what happened between reviews.

For a fuller view of how review cadence fits within a complete ODD programme, from governance and personnel risk through to cybersecurity and financial health monitoring, Thomas Murray's Operational Due Diligence: A Playbook for Asset Owners and Allocators sets out the fundamentals in detail. You can also explore our wider library of operational due diligence insights and guides.


Want to see how continuous monitoring could support your review calendar? Speak to our experts about how Orbit Risk tracks financial, cyber and media signals across your manager roster between scheduled reviews.

Operational Due Diligence

Operational Due Diligence

Automate your operational due diligence with Orbit Risk technology. 

Get ongoing monitoring of your investment managers, track adverse media, and receive cyber risk alerts as they happen.

Learn more