Governance, risk and compliance

SmartSuite for the IT Risk Manager

The IT Risk Manager coordinates technology and cyber risk within broader IT governance, operations and resilience programmes. They maintain the IT risk register across assets and systems, link risks and incidents to mitigation owners and timelines and produce exposure analytics for leadership.

What you own

  • Maintain the IT and cyber risk register across assets and systems
  • Run technology risk assessments with asset and application owners
  • Link risks and incidents to mitigation actions, owners and timelines
  • Monitor key risk indicators for technology
  • Align IT risk with enterprise risk, resilience and compliance programmes
  • Produce risk trends and exposure analytics for leadership reviews

Where the role sits

Each name opens that role's page.

Reports to

Chief Information Security Officer

Chief Information Security Officer

See the role
Enterprise Risk Director

Enterprise Risk Director

See the role

Direct reports

Works closely with

IT Compliance Manager

IT Compliance Manager

See the role
Security Operations Manager

Security Operations Manager

See the role
IT Operations Director

IT Operations Director

See the role
Risk Manager

Risk Manager

See the role
IT Asset Manager

IT Asset Manager

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

risk

Touches

contributes or approves

issues-actions, resilience, compliance, reporting

Depends on

consumes its output

third-party, audit

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use the IT Operations Management suite

Risk review

Reviews high-risk changes and records the risk assessment alongside the change.

Audit support

Validates that change governance was followed and produces the evidence auditors ask for.

Control alignment

Ensures changes follow the policies and controls that apply to each system.

How they use SmartSuite

Impact analysis
‍

‍

Risk reviews

‍

Change validation

‍

How they use the Cyber & IT Risk suite

IT risk register

Documents and assesses technology risks across assets and systems.

Remediation oversight

Links risks and incidents to mitigation actions, owners, and timelines.

Reporting

Produces risk trends and exposure analytics for leadership reviews.

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

Risk management. Documents and assesses technology risks across assets and systems with risk scoring models and remediation tracking.

Issues and actions. Links risks and incidents to mitigation actions, owners and timelines.

Operational resilience. Connects technology risks to the IT services and recovery plans they affect.

Compliance management. Shares the control mapping used by IT compliance so risks and controls stay aligned.

Reporting. Produces risk trends and exposure analytics for leadership reviews.

Industry reference

ISACA's CRISC job practice describes the role; NIST SP 800-30 and the NIST Risk Management Framework (SP 800-37) and ISO/IEC 27005:2022 define the assessment method. NIST CSF 2.0's Identify function and ISO/IEC 27001:2022 clause 6.1 require the risk assessment and treatment plan the manager owns.

Sector regulation prescribes it: the FFIEC IT Handbook and NYDFS 23 NYCRR 500.9 require periodic risk assessments at financial firms, and DORA requires an ICT risk management framework; the HIPAA Security Rule requires a risk analysis; FISMA and FedRAMP require NIST-based assessments for federal systems; NIS2 requires risk management measures across EU essential entities.

In their words

Related roles

Chief Information Security Officer

Chief Information Security Officer

See the role
Enterprise Risk Director

Enterprise Risk Director

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.