S shape representing Sattrix
We Serve, We Prove, We Repeat
The Annual Compliance Workload: What Your Team Will Actually Spend Time On

Most compliance staffing decisions are made without anyone first calculating how much work the compliance function actually handles over a full year. Leadership sees the external audit, the certificate, and a few customer questionnaires. What it rarely sees is the steady flow of evidence requests, reviews, follow-ups, and coordination that fills the remaining months.

That gap matters. A misjudged workload leads to a misjudged team size, the wrong mix of skills, and a higher chance that something slips at the worst possible moment.

This article lays out a realistic 12-month view of recurring compliance work. It is meant as a starting point for your own capacity assessment, not a verdict on how compliance should be staffed.

Why Annual Compliance Effort Is Often Underestimated

Compliance is often budgeted as an event rather than a cycle. The audit has a date, a fee, and a visible outcome, so it becomes the reference point for planning.

The annual compliance workload is different. Much of it is spread across the year, shared with other departments, and never logged as a project. Three patterns explain most of the underestimation:

  • Counting frameworks instead of activities. “We have ISO 27001 and SOC 2” says little about how many evidence cycles, reviews, and assessments those frameworks generate.
  • Planning for average months. Annual totals hide the months when several deadlines land together.
  • Ignoring coordination time. Much of the effort sits in waiting for, chasing, and checking other people’s input.

What Compliance Teams Actually Spend Time On

A typical compliance function handles a set of recurring operational activities, each with its own rhythm:

  • Evidence collection, validation, and refresh cycles
  • Control testing and sampling
  • Policy review, approval, and version control
  • Vendor and third-party risk assessments
  • Inbound customer security questionnaires
  • Internal audit preparation and management reviews
  • External audit fieldwork support
  • Exception handling, corrective actions, and remediation tracking
  • Audit findings and closure
  • Recurring reporting and stakeholder updates

None of these is unusual on its own. The pressure comes from how they stack up across the calendar.

A 12-Month Compliance Workload Example

The table below shows how work might fall across a year for an organization with one certification audit in the autumn, an internal audit in mid-year, and a steady flow of enterprise customers.

Month Main activities Overlapping pressures Relative load
Jan Annual compliance calendar, carried-over remediation New-year customer questionnaires Medium
Feb Policy review cycle starts, quarterly access review Questionnaires continue Medium
Mar Policy approvals and version control, Q1 control testing Customer renewals in some sectors High
Apr Vendor risk assessment cycle starts, evidence refresh Policy follow-ups Medium
May Vendor reviews continue, quarterly access review Steady questionnaire volume Medium
Jun Internal audit preparation, Q2 control testing Vendor review closures High
Jul Internal audit fieldwork, findings logged Remediation deadlines from earlier exceptions High
Aug Management review, internal audit remediation External audit readiness checks High
Sep External audit fieldwork, evidence requests, sampling Rising questionnaires, Q3 control testing Peak
Oct Fieldwork close-out, responses to findings Enterprise customer assessments, contract renewals Peak
Nov Corrective action plans, finding closure, access review Next-year budgeting and planning High
Dec Remediation follow-up, leadership reporting Reduced availability over holidays Medium

This is an illustration, not a universal schedule. Real timing depends on your frameworks, industry, audit cycle, customer base, and regulatory changes. The useful point is the shape: workload rises and falls, and several activities often peak together.

Evidence Collection and Control Testing

Evidence collection is rarely a single pull before the audit. Access reviews, change approvals, backup checks, and training records often need refreshing quarterly or monthly, so the cycle repeats all year.

Control testing adds sampling work. Someone selects samples, requests the records, checks them against the control, and documents the result. When a sample fails, the work extends into exception handling and corrective action.

Most of this depends on control owners in IT, HR, finance, and engineering. Their availability, not the compliance team’s, often sets the pace.

Policies, Reviews, and Version Control

Policies need periodic review even when nothing has changed, and immediate updates when something has. Each update moves through drafting, stakeholder comments, approval, publication, and communication to staff.

Version control is easy to overlook. Auditors and customers expect the current version, a clear approval trail, and consistency between the policy and the procedures that support it. Keeping a large policy set aligned takes steady effort, especially when a new framework or regulation adds requirements mid-year.

Vendor Risk and Customer Security Questionnaires

These two activities run in opposite directions. Vendor risk assessment means sending questionnaires out, reviewing responses, and following up on gaps. Customer security questionnaires mean answering them, often against a sales deadline.

Inbound questionnaires are hard to plan because customers set the timing. Volume tends to rise with new deals and contract renewals, and enterprise customers frequently ask for custom formats, supporting documents, or calls with the security team. Many questions repeat, but each still needs checking against current controls before it goes out.

Internal Audit, Management Review, and Audit Fieldwork

Compliance audit preparation starts well before the auditor arrives. Internal audits need scoping, scheduling, interviews, and findings reports. Management reviews need data on incidents, risks, objectives, and open actions, summarized for senior leaders.

During external fieldwork, the compliance team becomes the coordination point. It schedules walkthroughs, answers evidence requests within agreed turnaround times, clarifies findings, and keeps control owners available. Fieldwork can occupy most of a small team’s capacity for several weeks.

Remediation Tracking and Follow-Up

Compliance remediation outlasts the audit. Findings from internal audits, external audits, control tests, and vendor reviews all produce actions with owners and deadlines.

The compliance team usually does not fix the issue itself, but it tracks progress, chases updates, validates closure evidence, and reports status. At any point in the year, several remediation items are likely open, and each one needs attention until it is formally closed.

Why Concurrency Creates More Pressure Than Total Volume

A lean team can often handle each activity comfortably when it arrives alone. The strain appears when several arrive at once. Common collisions include:

  • An external audit running while customer questionnaires increase
  • Vendor risk assessments overlapping with annual control testing
  • Policy reviews landing as remediation deadlines approach
  • Management review preparation coinciding with audit evidence requests
  • Several enterprise customers requesting custom security documentation during audit season

Concurrency also raises the effort per task. Every switch between an auditor request and a customer questionnaire costs time to reload context. Follow-ups multiply, approvals queue behind each other, and control owners receive overlapping requests from the same team.

This is why compliance team capacity should be judged against peak periods, not annual totals.

The Impact of Attrition, Leave, and Single-Person Dependency

A compliance plan that looks manageable on paper often assumes everyone is available all year. Real conditions are less tidy:

  • Single-person dependency. One specialist knows where the evidence lives, how controls map, and what the auditor asked last year.
  • Attrition. When that person leaves, much of the knowledge leaves too, and a replacement needs time to learn the environment.
  • Leave and absence. Planned leave can be scheduled around audits. Unplanned absence cannot.
  • Competing priorities. Compliance staff are often pulled into security or IT projects.
  • External demands. New framework requirements and growing customer expectations add work without removing any.

Other teams add friction too. Control owners have their own deadlines, evidence arrives late or incomplete, and rework follows. The result is more time spent coordinating than doing substantive compliance work.

Hidden Work That Rarely Appears in Compliance Plans

Some of the most time-consuming GRC workload never shows up as a deliverable:

  • Chasing evidence owners and re-requesting missing documents
  • Reviewing evidence for completeness and date accuracy
  • Mapping one piece of evidence to controls across several frameworks
  • Answering the same customer questions in slightly different formats
  • Updating trackers, spreadsheets, and audit trails
  • Scheduling meetings with busy control owners
  • Explaining requirements to internal teams
  • Coordinating with auditors on requests and clarifications
  • Preparing management summaries
  • Maintaining versions of policies and supporting documents

Each item is small. Together, they can consume a large share of the team’s week, and they rarely appear in staffing estimates.

Building a Realistic Compliance Capacity Model

“How many compliance tasks do we have?” is the wrong starting question for compliance staffing. A task count treats a one-hour policy sign-off and a six-week audit the same way. Better questions are:

  • How many recurring activities occur each year?
  • How many require coordination with other teams?
  • How many happen at the same time?
  • How much work depends on specific individuals?
  • Which activities need specialist knowledge?
  • How much time goes into collecting and validating evidence?
  • How often do customer assessments arrive?
  • How much remediation is open at any given time?
  • What happens when a key team member is unavailable?
  • How much capacity is needed in peak months rather than average months?

The last question introduces the idea of peak workload capacity. A team sized for the average month may look efficient for most of the year, then fall behind exactly when audits, customers, and deadlines converge. Effective compliance workload management plans for those peaks, whether through internal staff, external support, or both.

What to Measure Before Weighing GRC as a Service vs In-House Compliance

Before choosing a GRC operating model, build a workload inventory. One row per compliance activity, with these fields:

# Field What it tells you
1 Compliance activity What the work is
2 Frequency How often it recurs
3 Estimated effort Hours or days per cycle, including follow-ups
4 Required skills Generalist, specialist, or technical knowledge
5 Internal stakeholders Who must contribute evidence or approvals
6 Peak-period timing Which months it lands in
7 Dependencies What must happen first, and who it waits on
8 Current owner Who does it today
9 Backup owner Who covers if that person is unavailable
10 Business impact if delayed Lost deal, audit finding, regulatory exposure, or minor delay

This gives a far better basis for decisions than counting frameworks or certifications. It shows where capacity tightens, which skills are scarce, and where a single absence would stall delivery.

With that picture in hand, leadership can evaluate the realistic options: a fully in-house team, GRC as a service, a hybrid model, or specialist support for selected activities. Each can work. The right fit depends on your workload profile, internal capabilities, risk environment, compliance requirements, growth plans, and available resources.

Conclusion

Compliance operations are a year-round cycle of evidence, testing, reviews, assessments, and follow-up, with peaks that rarely line up neatly. The real constraint is usually concurrency and dependency on a few people, not the annual total.

Before deciding who should perform compliance work, leadership should first understand how much work exists, when it occurs, what skills it requires, and where capacity becomes constrained. In the operating-model reviews Sattrix supports, a workload inventory like the one above is typically the first exercise, because it turns a staffing debate into a decision based on evidence.

Frequently Asked Questions

1. What does a compliance team do throughout the year?

It runs recurring evidence collection, control testing, policy reviews, vendor assessments, customer questionnaires, internal audits, management reviews, audit support, and remediation tracking. Most of this happens outside the external audit window.

2. Why does compliance workload increase during audit season?

Audit fieldwork adds evidence requests, walkthroughs, and findings responses on top of work that does not pause, such as customer questionnaires and remediation. The overlap, not the audit alone, drives the increase.

3. What activities consume the most compliance team time?

Evidence collection and validation, coordination with control owners, and customer security questionnaires usually take the largest share, along with the follow-up work each one creates.

4. How should organizations calculate annual compliance workload?

List every recurring activity with its frequency, effort per cycle, timing, stakeholders, and owner. Then map it across a 12-month calendar to see where activities overlap.

5. Why is peak workload more important than average workload?

Teams fall behind in peak months, not average ones. A team sized for the average may miss deadlines exactly when audits, customers, and remediation converge.

6. What causes compliance teams to become dependent on one person?

Knowledge of evidence locations, control mappings, and auditor history often builds up with one specialist and is not documented or shared. Without a named backup owner, that person becomes a single point of failure.

7. What should organizations evaluate before choosing an in-house, outsourced, or hybrid compliance model?

The actual workload, peak periods, required skills, dependencies on individuals and other teams, and the business impact of delays. These inputs matter more than the number of frameworks held.

Share It Now: