The bean counters also play a big role. Most companies aren't ready for big bounty payouts when a program first starts. They set a fixed budget and are more likely to end a program completely if the bottom line cost is too high, regardless of the security impact. Security teams are aware of this and try to walk a fine line.
For researchers who are having problems with programs I'd suggest trying to form a better relationship with the triage teams and security teams. Be helpful, not confrontational. Companies get their best bang-for-buck when they can court good researchers. They love getting quality researchers who report multiple findings and they'll do quite a lot to make them happy, including paying bonus bounties for future reports and being far more transparent with triage status.
At the beginning of a high profile bug bounty program I'd expect higher expenditure than in the following fiscal year due to the backlog of researchers who really want to "sell" to an official channel, not a slow start.