Operational controls in an environmental management system (EMS) reduce the risk that the organization will not achieve its environmental objectives. Operational controls are the processes that management implements to provide reasonable assurances that the organization will achieve its environmental objectives.
Risks and business conditions change all the time, so an annual plan or even one that is updated quarterly won’t lead to auditing what matters today. You audit what used to matter.
The majority of internal audit functions perform a variety of audits every year and provide an opinion (ideally) or at least a list of risk-ranked weaknesses (far less than ideally) on the scope of each audit.