The Roles · Who defends it

Governance, risk and compliance analyst

Written from published sources

The role that writes down what the organisation has decided to require of itself, and then finds out whether it is true. Governance is the deciding, risk is the accounting for what could go wrong, and compliance is the evidence that the decisions are being followed. The framework literature separates governance from management for a reason: this role serves the people who set direction, not the people who implement it.

What the day looks like

  • Turning an obligation written in legal language into a control somebody can actually operate.
  • Maintaining the risk register, which means chasing owners who did not ask to own anything.
  • Collecting evidence, and discovering that a control everyone believed in has no record of running.
  • Answering a customer security questionnaire, honestly, without losing the deal.
  • Preparing for an audit, which is mostly finding out what will not survive one.

What it answers for

  • Policy that is specific enough to follow and general enough to survive a product change.
  • A risk register that reflects the organisation rather than a template.
  • Evidence that exists before it is asked for.

What it is measured on

  • Audit findings, and whether last year's were genuinely closed.
  • Certification maintained without a crisis in the month before assessment.
  • Exceptions with owners and expiry dates rather than an unbounded list.

Who it receives from

Legal and regulators
Obligations, with deadlines that do not negotiate.
Security architecture and engineering
What is actually implemented, which is the input compliance most often lacks.
The business
Appetite for risk, usually stated only after an incident.

Who it serves

Executives and the board
An account of exposure they can act on.
Sales
The answers that unblock an enterprise customer's review.
Engineering teams
Requirements stated once, rather than rediscovered per project.

Who else has a stake

  • Customers, whose contracts increasingly specify controls this role has to evidence.
  • Insurers, who now ask the same questions with money attached.
  • Every team that inherits a requirement written here.

What it takes

  • Enough technical literacy to know when an implementation claim is not true.
  • Writing that survives being read by a lawyer, an engineer and an auditor.
  • The stubbornness to keep asking for evidence after being told it exists.
  • Judgement about proportion, since a control programme that ignores cost is ignored in turn.

What the job turns on

Compliance measures whether a control is documented and operating. Whether it works is a separate question with a separate answer, and a programme that treats the two as one produces certificates and incidents at the same time.

The published sources

Where it leads

The work itself

The Practice covers how this work is done — triage, escalation, evidence, handover — across the whole corpus.

Read The Practice