Skip to content
atlas

Compliance and risk coordinator

Also known as: compliance coordinator, risk coordinator

A role, often a first job in the field, that tracks which rules apply, where the organisation falls short, and how its risks are handled.

Draft - this entry has not been reviewed yet.

Formal

A role that maps legal and standard requirements to the organisation's practice, runs gap analyses and risk assessments, keeps the evidence in order and reports progress and open risks to management.

In plain English

Like a bookkeeper for rules - keeping the list of what is owed, what is paid and what is overdue, so there are no surprises when the inspector comes.

In practice

Two weeks before an ISO 27001 audit at a Danish energy company, the coordinator checks each requirement against the evidence folder and chases three risk owners for missing records.

Why it matters

Rules like NIS2 and GDPR expect proof, not good intentions, and this role is what turns scattered work into something the organisation can show.

Technical deep dive

The compliance half of the role starts with a requirements register, which ISO/IEC 27001:2022 Annex A control 5.31 demands: legal, statutory, regulatory and contractual requirements relevant to information security must be identified, documented and kept up to date. For a Danish organisation this typically includes the NIS2-loven and its executive orders, GDPR and databeskyttelsesloven, sector rules such as DORA for finance, the CER-loven for designated critical entities, bookkeeping rules on retention, and security clauses in customer contracts and data processing agreements. Each requirement is decomposed and mapped to internal controls, so one control, for example quarterly access reviews, can be shown to satisfy several sources. Control 5.36 then requires regular review of compliance with the organisation's own policies and standards.

The risk half follows ISO/IEC 27001 clause 6.1.2 and ISO/IEC 27005:2022. The coordinator maintains the risk criteria, including acceptance criteria and criteria for performing assessments, that make results consistent, valid and comparable, runs assessments at planned intervals and on significant change (clause 8.2), and keeps the risk register: risk statement, owner, likelihood and consequence ratings, existing controls, treatment decision, planned actions and residual risk. The coordinator facilitates but does not own the risks; clause 6.1.3 f requires risk owners to approve the treatment plan and accept residual risk. A methodological trap worth knowing is multiplying ordinal scores on a 5x5 heat map, which produces rankings that look precise but can misorder risks; better practice anchors each scale level to concrete ranges such as downtime hours or financial loss bands.

Evidence management is the operational core. Auditors and supervisory authorities test what can be shown: tickets, logs, signed approvals, training records, restore-test reports and supplier assessments. The coordinator defines for each control what evidence is expected, at what frequency and where it is stored, so that retained documented information (clause 7.5) is produced as a by-product of normal work rather than assembled before an audit. Key risk indicators, such as the share of critical vulnerabilities past deadline or the number of accounts without MFA, turn the register into something management can monitor.

In the IIA Three Lines Model the role is a second-line function: it supports and challenges operational management (first line) and is itself reviewed by internal audit or an independent review under Annex A 5.35 (third line), so it should not audit its own work. The closest ECSF profiles are the Cyber Legal, Policy and Compliance Officer and the Cybersecurity Risk Manager. Compared with the information security coordinator, which runs the entire programme, this role is narrower and more evidence- and requirement-centred; in small organisations the two are frequently held by the same person.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Compliance
  3. →Threat
  4. →Asset
  5. →Vulnerability
  6. →Impact
  7. →Likelihood
  8. →Risk
  9. →Risk management
  10. →Compliance and risk coordinator

Relationships

A kind of
Grey roles

Sources & further reading

Course material

  • Cyber Security Fast Track - Kursuskompendium, Kursistens udbytte

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.