The Roles · Who defends it
Governance, risk and compliance analyst
Written from published sources
The role that writes down what the organisation has decided to require of itself, and then finds out whether it is true. Governance is the deciding, risk is the accounting for what could go wrong, and compliance is the evidence that the decisions are being followed. The framework literature separates governance from management for a reason: this role serves the people who set direction, not the people who implement it.
Who it receives from
- Legal and regulators
- Obligations, with deadlines that do not negotiate.
- Security architecture and engineering
- What is actually implemented, which is the input compliance most often lacks.
- The business
- Appetite for risk, usually stated only after an incident.
Who it serves
- Executives and the board
- An account of exposure they can act on.
- Sales
- The answers that unblock an enterprise customer's review.
- Engineering teams
- Requirements stated once, rather than rediscovered per project.
What the job turns on
Compliance measures whether a control is documented and operating. Whether it works is a separate question with a separate answer, and a programme that treats the two as one produces certificates and incidents at the same time.