Yes. New integrations, additional data access, privileged access, critical-service use, geographic changes or shared dependencies can change inherent risk. Programmes should re-score after material changes rather than waiting only for the next annual review.
FAQ
Third-Party Risk Management