Governance, risk and compliance

SmartSuite for the Compliance Analyst

The Compliance Analyst performs compliance assessments, collects and evaluates evidence, executes control tests, documents results and prepares reporting. They do the detailed work that keeps the compliance programme evidenced and the findings log current.

What you own

  • Perform compliance assessments against mapped requirements
  • Evaluate evidence submissions for completeness and accuracy
  • Execute control tests and record results
  • Log findings and track remediation activities
  • Maintain the obligations and control library data
  • Prepare compliance reports and dashboards

Where the role sits

Each name opens that role's page.

Reports to

Compliance Manager

Compliance Manager

See the role
Compliance Officer

Compliance Officer

See the role

Direct reports

Works closely with

Control Owner

Control Owner

See the role
Internal Auditor

Internal Auditor

See the role
Risk Analyst

Risk Analyst

See the role
Controls Testing Lead

Controls Testing Lead

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

Touches

contributes or approves

compliance, issues-actions, reporting

Depends on

consumes its output

audit, policy

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use the Compliance Management suite

Evidence review

Evaluates submissions for completeness and accuracy.

Testing execution

Conducts control tests and records results.

Issue logging

Documents findings and tracks remediation activities.

Suites that serve this role

How SmartSuite supports this role

Compliance management. Streamlines assessments with templates and workflows, evaluating submissions for completeness and recording control test results in one place.

Issues and actions. Documents findings and tracks remediation activities with automated reminders to owners.

Reporting. Prepares compliance dashboards and status reports from assessment and testing data.

Industry reference

ISO 37301:2021 and ISACA guidance set the standard the analyst works to: documented test procedures, evidence that is complete and dated, and findings logged with owners. Audit standards such as the AICPA's Trust Services Criteria define what evidence an assessor will accept.

The frameworks under test vary by sector: HIPAA safeguards in healthcare, FFIEC and NYDFS requirements in financial services, NIST SP 800-53 controls in the public sector, and SOC 2, ISO/IEC 27001 and PCI DSS 4.0 in technology. In each, the analyst's workpapers are what the external assessor samples.

In their words

Related roles

Compliance Manager

Compliance Manager

See the role
Compliance Officer

Compliance Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.