Ask most allocators to describe their manager selection process and you'll get a confident, detailed answer. Ask the same allocators to describe what happens to that same manager's operational oversight eighteen months into the relationship, and the answer is often considerably vaguer.
This is not because ODD teams don't care about existing managers. It's because the structure of most due diligence programmes concentrates intensity at the start of a relationship and lets it taper off from there. The request for proposal, or RFP process is rigorous by design: multiple bidders, structured scoring, reference checks, sign-off from an investment committee. Once a manager is selected and onboarded, that same rigour rarely carries through at the same intensity. It resolves into an annual, sometimes 18-month, review cycle, and the operational relationship spends most of its life outside the periods when anyone is looking closely.
This article sets out what a robust RFP process looks like, maps the full manager relationship lifecycle it sits within, and examines the gap that tends to open once selection is complete, along with what closing it actually requires.
What a Robust RFP Process Looks Like
A well-run RFP is more than a questionnaire sent to a shortlist. Done properly, it has a handful of distinct stages, each producing something the next stage depends on.
Scoping and requirements definition. Before any manager sees a document, the allocator needs to be precise about what it is assessing and why. That means defining the mandate, the risk tolerances specific to the strategy and asset class, and the operational criteria that matter most for this particular allocation, not a generic checklist reused from the last search. A cybersecurity-heavy scope for a systematic quant strategy looks different to the governance and valuation focus appropriate for an illiquid credit fund.
Questionnaire design and weighting. The DDQ itself should be structured so that responses are comparable across bidders, with weighting that reflects what actually matters for the mandate rather than treating every section as equally important. Industry-standard templates are a sensible starting point, but a process that never customises beyond the template will miss the risks specific to the strategy in question.
Structured evaluation and scoring. Responses need to be assessed against consistent criteria, not read in isolation by whichever analyst happens to pick up each file. A defensible RFP process produces a scorecard, not just a narrative summary, and that scorecard should be auditable back to the underlying evidence.
Independent verification. This is where many RFP processes fall short even when the questionnaire stage is strong. Self-reported answers need to be checked against primary sources: regulatory filings, audited financials, reference calls with the manager's own service providers, and, increasingly, independent technical evidence on cyber posture. A scoring exercise built entirely on unverified manager responses is measuring how well a manager completes a form, not how sound their operations are.
Decision, documentation, and contracting. The final stage should leave a clear audit trail: why this manager was selected over the alternatives, what conditions or follow-up items were attached to the decision, and what the baseline operational profile looked like at the point of selection. That baseline matters more than it usually gets credit for, because it's the reference point everything afterwards should be measured against.
Get these stages right and the RFP does what it's supposed to do: it produces a well-evidenced, defensible selection decision. What it does not do, on its own, is tell you anything about how that manager's operations will evolve over the years that follow.
None of this is abstract for us. It's the same discipline Thomas Murray has applied for years to RFP processes for global custodians, one of the more heavily scrutinised selection decisions in institutional investing, and in practice the process for running a manager RFP well is very similar. The stages don't change; only the risk categories being scored do.
The Full Relationship Lifecycle
The RFP is one stage in a longer relationship, and it's worth setting out the full sequence, because the monitoring gap only becomes visible when you look at the whole thing rather than any single stage in isolation.
1. Selection (the RFP stage). Manager identification, questionnaire-based evaluation, scoring, verification, and the final selection decision, as above.
2. Onboarding and initial due diligence. Once a manager is selected, onboarding due diligence goes deeper than the RFP could afford to, given the RFP typically runs across multiple bidders simultaneously. This is where governance structures, key-person arrangements, service provider independence, and technology and cybersecurity posture get examined in full, and where the operational baseline established at selection gets formally documented and agreed.
3. Mobilisation and initial monitoring set-up. Reporting lines, escalation protocols, and the cadence of future reviews get agreed and, in a well-run programme, the monitoring framework itself, what will be tracked, how often, and what triggers an ad hoc review, gets defined at this point rather than left implicit.
4. Ongoing monitoring. This is the longest stage of the relationship by a wide margin, and structurally the one most programmes under-invest in relative to its duration. It should mean continuous or near-continuous visibility into the operational signals that matter: financial health, cyber exposure, governance changes, and reputational developments, not a dormant period between scheduled check-ins.
5. Periodic formal review. The scheduled annual or 18-month reassessment, where the questionnaire is refreshed, and the manager's current position is compared against the baseline. Done well, this stage should confirm what continuous monitoring has already surfaced, not be the first point at which a material change comes to light.
6. Renewal, escalation, or exit. Every relationship eventually reaches a decision point: continue as is, escalate for closer scrutiny or remediation, or terminate the mandate. An offboarding process, closing accounts, transferring assets, confirming final reporting, deserves nearly as much structure as onboarding did, and is frequently given far less.
Laid out this way, the RFP is stage one of six. But in terms of where allocator resource and attention actually goes, it's common to see it consume a disproportionate share of total effort, with stage four, ongoing monitoring, the longest stage by far, receiving comparatively little structured attention until the next scheduled review brings it briefly back into focus.
Where the Gap Opens
The monitoring gap isn't really about effort or intent. ODD teams monitor existing managers because that is the job. The gap is structural: it opens at the boundary between stage three and stage four, the point where the intensity, rigour, and independent verification built into selection and onboarding gives way to a lighter-touch cadence built around calendar dates rather than events.
We've written previously about why this matters for specific risk categories. Financial stress, cyber exposure, and reputational and personnel risk each tend to develop between review cycles rather than at the point a questionnaire happens to be refreshed. A manager under redemption pressure, a deteriorating attack surface, an unfolding leadership dispute: none of these wait politely for the next scheduled review, and a monitoring cadence built around review dates rather than events will, by design, see them late.
The deeper issue is that the scorecard produced at RFP stage and the baseline established at onboarding often sit disconnected from whatever happens next. A rigorous selection process generates a rich, evidenced picture of a manager's operational profile at a single point in time. If that picture isn't carried forward and actively compared against over the life of the relationship, all that early rigour depreciates. Two years on, the ODD team is often working from what the manager currently says, not from what has changed since the baseline was set.
Closing the Gap
Closing the monitoring gap isn't a case of running the RFP process on a loop, that would be neither practical nor proportionate. It's a case of carrying the discipline of selection, structured criteria, independent verification, and a defensible evidence trail, into the stage of the relationship that lasts the longest.
In practice, that means a few things. The categories scored at RFP and onboarding, governance, financial health, cyber posture, business continuity, service provider independence, should be the same categories tracked continuously afterwards, so that a change is visible against a known baseline rather than assessed fresh each time. Verification shouldn't stop once a manager is selected: financial statement analysis, independent cyber risk evaluation, and media and news surveillance can each provide an ongoing, independent read that doesn't rely solely on what the manager chooses to report at the next scheduled review. And the monitoring itself needs to be structured well enough that a material change is flagged when it happens, rather than rediscovered at the next review date.
This is also where technology genuinely changes what's operationally realistic, and it's worth being specific about the mechanism rather than gesturing at “a single platform.” The scorecard produced during an RFP shouldn't be a document that gets filed away once a decision is made, it should become the entity's baseline record. Inside Orbit, that's the practical effect of the design: the categories scored at selection, governance, financial health, cyber posture, business continuity, service provider independence, are the same categories Orbit Risk tracks on an ongoing basis, against the same entity profile. A change doesn't require an analyst to reconstruct what was agreed eighteen months ago from a shared drive or a legacy DDQ; it shows up as a change against a record that was already there. Orbit Diligence carries the RFP, DDQ and RFI workflow itself; Orbit Risk carries the financial, cyber and media monitoring that runs continuously afterwards. The reason for building them on the same entity record is that neither end of the lifecycle is starting from scratch.
None of this replaces analyst judgement, and none of it guarantees that every material issue will be caught before it becomes visible elsewhere. What it does is close the distance between the standard applied at selection and the standard applied for the years that follow, so the most rigorous point in the relationship isn't also the only one.
Where This Leaves the RFP
A strong RFP process remains essential. It's the foundation the rest of the relationship is built on, and none of the argument here suggests cutting corners at selection. But an RFP is a point-in-time exercise, and the managers allocators hold for years need an oversight standard that doesn't quietly step down the moment the contract is signed.
For a fuller view of how selection, onboarding, and ongoing monitoring fit together across a complete ODD programme, Thomas Murray's Operational Due Diligence: A Playbook for Asset Owners and Allocators sets out the fundamentals in detail, from governance and personnel risk through to the technology now reshaping what continuous oversight looks like in practice.

Operational Due Diligence
Automate your operational due diligence with Orbit Risk technology.
Get ongoing monitoring of your investment managers, track adverse media, and receive cyber risk alerts as they happen.
Insights

From RFP to Ongoing ODD: Closing the Monitoring Gap
RFP rigour rarely survives past manager selection. What a robust RFP process looks like, and how to close the monitoring gap that opens once it's over.

Media Monitoring as an ODD Signal: What to Watch For
Reputational signals move faster than annual reviews. Here's what real-time media monitoring should catch in operational due diligence, and why.

Financial Statement Red Flags: An Operational Due Diligence Perspective
Audited financial statements are one of the richest, most under-used sources of insight into a manager's financial health. Here's what actually predicts stress, and how financial analysis fits within a broader operational due diligence framework.

Why Cyber Risk Belongs in Operational Due Diligence
Cyber risk is still treated as an IT checkbox in operational due diligence. Here's why it needs to be a continuous monitoring signal.

