Governance, risk and compliance

SmartSuite for the Regulatory Change Manager

The Regulatory Change Manager monitors new and amended laws, regulations and standards, assesses their impact on the organisation's obligations, policies and controls, and drives the changes through to implementation. They keep the obligations library current as the regulatory landscape moves.

What you own

  • Monitor regulatory sources for new and amended requirements
  • Assess the applicability and impact of each change on obligations, policies and controls
  • Route changes to owners for implementation and track completion
  • Update the obligations register and framework mappings
  • Maintain horizon-scanning reports for leadership
  • Evidence the organisation's response to each regulatory change

Where the role sits

Each name opens that role's page.

Reports to

Compliance Director

Compliance Director

See the role

Direct reports

Works closely with

Regulatory Affairs Manager

Regulatory Affairs Manager

See the role
Policy and Governance Manager

Policy and Governance Manager

See the role
Compliance Manager

Compliance Manager

See the role
Control Owner

Control Owner

See the role
General Counsel

General Counsel

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

compliance

Touches

contributes or approves

policy, issues-actions, reporting

Depends on

consumes its output

risk

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

No items found.

Suites that serve this role

How SmartSuite supports this role

Compliance management. Logs each regulatory change, assesses applicability and impact, and links it to the obligations, policies and controls it affects.

Policy management. Triggers policy reviews when a change requires an update and tracks the revision to approval.

Issues and actions. Routes implementation tasks to owners with due dates and evidence requirements.

Reporting. Produces horizon-scanning and implementation-status reports for compliance leadership.

Industry reference

ISO 37301:2021 requires an organisation to identify its compliance obligations and keep them current as laws change, which is the manager's core duty. Regulators expect a documented change process: the CFPB and FFIEC describe it as part of a compliance management system, and the OCC's heightened standards expect it for large banks.

The change volume varies by sector. Financial firms track prudential, conduct and sanctions rules across jurisdictions; healthcare organisations track CMS payment rules and HIPAA updates; public bodies track statutes and OMB circulars; technology companies track privacy laws, the EU AI Act, NIS2 and DORA.

In their words

Related roles

Compliance Director

Compliance Director

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.