Compliance Home page for the Compliance Manager
The compliance manager home page in the Compliance Workspace gives a complete overview of the compliance posture of the organization. The workspace helps the compliance manager to centrally manage internal standards, policies, and control processes that match the external regulatory standards.
Compliance manager most often reports to a compliance director and ensures that the company complies with organizational and industrial regulations and standards.
The user persona may vary across organizations, however, a corporate compliance manager, IT compliance manager, compliance manager, or compliance analyst, depending on the organizational structure, can be tasked with ensuring that the organization is complying with policies and regulations.
Responsibilities of a compliance manager
- Ensure that all policies and regulations are being followed.
- Create and maintain policies up to the level of defining and applying controls.
- Approve and track policy exceptions.
- Manage the team appropriately.
Compliance Workspace for compliance manager tasks
To fulfil the above responsibilities, a compliance manager has certain daily and weekly functional tasks that can be performed in the compliance workspace.
- Use the Overview section to review the authority documents, policies, and entities and know their compliant status. Get the list of least compliant authority documents, policies, and entities, and their compliance score.
- Review compliance tasks such as controls, control attestations, indicator tasks, ongoing and overdue control test count in the control assurance section.
- Monitor and analyze new key controls and track the performance of existing controls.
- Track the changes done to the authority documents, regulations, and policies.
As a compliance manager, you can create authority documents, citations, policies, control objectives, controls, indicator tasks, acknowledgement campaigns, policy exceptions, and engagements.
To help the compliance manager attend to tasks that need immediate action, the compliance records in the overview section are listed in an order starting from the least compliant ones. The data displayed for control tests, indicators, and attestations in the control assurance section help the compliance manager to prioritize the tasks as well. Tracking of acknowledgement campaigns and policy exceptions can be managed effectively.
Other GRC plugins for an overall view
- GRC: Audit Management for the control tests widget in the Control assurance section.
- GRC: Regulatory Change Management for the Regulatory changes widget in the Tracking section. The logged in user must also have the RCM manager role (sn_grc_reg_change.manager).
- GRC: Privacy Management for the Domain compliance status section. The logged in user must also have a privacy manager role (sn_privacy.manager).