Governance, risk and compliance

SmartSuite for the Policy Analyst

The Policy Analyst supports the policy programme: drafting and formatting documents, running review and attestation workflows, maintaining the policy register and its mappings, and chasing overdue acknowledgements. They keep the policy library accurate and searchable.

What you own

  • Draft and format policy documents to the house standard
  • Run review, approval and attestation workflows
  • Maintain the policy register, metadata and mappings to controls
  • Chase overdue reviews and acknowledgements
  • Prepare policy status and attestation reports
  • Answer policy queries from the business

Where the role sits

Each name opens that role's page.

Reports to

Policy and Governance Manager

Policy and Governance Manager

See the role

Direct reports

Works closely with

Compliance Analyst

Compliance Analyst

See the role
Regulatory Change Manager

Regulatory Change Manager

See the role
HR Operations Manager

HR Operations Manager

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

Touches

contributes or approves

policy, issues-actions, reporting

Depends on

consumes its output

compliance

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

Suites that serve this role

How SmartSuite supports this role

Policy management. Runs review and attestation workflows, maintains the policy register and keeps mappings to controls current.

Issues and actions. Tracks overdue reviews and acknowledgements with automated reminders.

Reporting. Produces attestation and policy status reports by department.

Industry reference

ISO 37301:2021 clause 7.5 sets the documentation standard the analyst maintains: controlled versions, approvals on record and periodic review. ISO/IEC 27001 clause 7.5 and NIST SP 800-53's policy controls carry the same requirement into security programmes, so one policy register usually serves several frameworks.

Sector rules set the detail. HIPAA requires policies to be retained for six years from their last effective date; FINRA expects written supervisory procedures to be current; FedRAMP and PCI DSS assessors check review dates and acknowledgement records; public bodies often publish policies under freedom-of-information rules, which raises the bar on accuracy.

In their words

Related roles

Policy and Governance Manager

Policy and Governance Manager

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.