Most compliance staffing decisions are made without anyone first calculating how much work the compliance function actually handles over a full year. Leadership sees the external audit, the certificate, and a few customer questionnaires. What it rarely sees is the steady flow of evidence requests, reviews, follow-ups, and coordination that fills the remaining months.
That gap matters. A misjudged workload leads to a misjudged team size, the wrong mix of skills, and a higher chance that something slips at the worst possible moment.
This article lays out a realistic 12-month view of recurring compliance work. It is meant as a starting point for your own capacity assessment, not a verdict on how compliance should be staffed.
Compliance is often budgeted as an event rather than a cycle. The audit has a date, a fee, and a visible outcome, so it becomes the reference point for planning.
The annual compliance workload is different. Much of it is spread across the year, shared with other departments, and never logged as a project. Three patterns explain most of the underestimation:
A typical compliance function handles a set of recurring operational activities, each with its own rhythm:
None of these is unusual on its own. The pressure comes from how they stack up across the calendar.
The table below shows how work might fall across a year for an organization with one certification audit in the autumn, an internal audit in mid-year, and a steady flow of enterprise customers.
| Month | Main activities | Overlapping pressures | Relative load |
|---|---|---|---|
| Jan | Annual compliance calendar, carried-over remediation | New-year customer questionnaires | Medium |
| Feb | Policy review cycle starts, quarterly access review | Questionnaires continue | Medium |
| Mar | Policy approvals and version control, Q1 control testing | Customer renewals in some sectors | High |
| Apr | Vendor risk assessment cycle starts, evidence refresh | Policy follow-ups | Medium |
| May | Vendor reviews continue, quarterly access review | Steady questionnaire volume | Medium |
| Jun | Internal audit preparation, Q2 control testing | Vendor review closures | High |
| Jul | Internal audit fieldwork, findings logged | Remediation deadlines from earlier exceptions | High |
| Aug | Management review, internal audit remediation | External audit readiness checks | High |
| Sep | External audit fieldwork, evidence requests, sampling | Rising questionnaires, Q3 control testing | Peak |
| Oct | Fieldwork close-out, responses to findings | Enterprise customer assessments, contract renewals | Peak |
| Nov | Corrective action plans, finding closure, access review | Next-year budgeting and planning | High |
| Dec | Remediation follow-up, leadership reporting | Reduced availability over holidays | Medium |
This is an illustration, not a universal schedule. Real timing depends on your frameworks, industry, audit cycle, customer base, and regulatory changes. The useful point is the shape: workload rises and falls, and several activities often peak together.
Evidence collection is rarely a single pull before the audit. Access reviews, change approvals, backup checks, and training records often need refreshing quarterly or monthly, so the cycle repeats all year.
Control testing adds sampling work. Someone selects samples, requests the records, checks them against the control, and documents the result. When a sample fails, the work extends into exception handling and corrective action.
Most of this depends on control owners in IT, HR, finance, and engineering. Their availability, not the compliance team’s, often sets the pace.
Policies need periodic review even when nothing has changed, and immediate updates when something has. Each update moves through drafting, stakeholder comments, approval, publication, and communication to staff.
Version control is easy to overlook. Auditors and customers expect the current version, a clear approval trail, and consistency between the policy and the procedures that support it. Keeping a large policy set aligned takes steady effort, especially when a new framework or regulation adds requirements mid-year.
These two activities run in opposite directions. Vendor risk assessment means sending questionnaires out, reviewing responses, and following up on gaps. Customer security questionnaires mean answering them, often against a sales deadline.
Inbound questionnaires are hard to plan because customers set the timing. Volume tends to rise with new deals and contract renewals, and enterprise customers frequently ask for custom formats, supporting documents, or calls with the security team. Many questions repeat, but each still needs checking against current controls before it goes out.
Compliance audit preparation starts well before the auditor arrives. Internal audits need scoping, scheduling, interviews, and findings reports. Management reviews need data on incidents, risks, objectives, and open actions, summarized for senior leaders.
During external fieldwork, the compliance team becomes the coordination point. It schedules walkthroughs, answers evidence requests within agreed turnaround times, clarifies findings, and keeps control owners available. Fieldwork can occupy most of a small team’s capacity for several weeks.
Compliance remediation outlasts the audit. Findings from internal audits, external audits, control tests, and vendor reviews all produce actions with owners and deadlines.
The compliance team usually does not fix the issue itself, but it tracks progress, chases updates, validates closure evidence, and reports status. At any point in the year, several remediation items are likely open, and each one needs attention until it is formally closed.
A lean team can often handle each activity comfortably when it arrives alone. The strain appears when several arrive at once. Common collisions include:
Concurrency also raises the effort per task. Every switch between an auditor request and a customer questionnaire costs time to reload context. Follow-ups multiply, approvals queue behind each other, and control owners receive overlapping requests from the same team.
This is why compliance team capacity should be judged against peak periods, not annual totals.
A compliance plan that looks manageable on paper often assumes everyone is available all year. Real conditions are less tidy:
Other teams add friction too. Control owners have their own deadlines, evidence arrives late or incomplete, and rework follows. The result is more time spent coordinating than doing substantive compliance work.
Some of the most time-consuming GRC workload never shows up as a deliverable:
Each item is small. Together, they can consume a large share of the team’s week, and they rarely appear in staffing estimates.
“How many compliance tasks do we have?” is the wrong starting question for compliance staffing. A task count treats a one-hour policy sign-off and a six-week audit the same way. Better questions are:
The last question introduces the idea of peak workload capacity. A team sized for the average month may look efficient for most of the year, then fall behind exactly when audits, customers, and deadlines converge. Effective compliance workload management plans for those peaks, whether through internal staff, external support, or both.
Before choosing a GRC operating model, build a workload inventory. One row per compliance activity, with these fields:
| # | Field | What it tells you |
|---|---|---|
| 1 | Compliance activity | What the work is |
| 2 | Frequency | How often it recurs |
| 3 | Estimated effort | Hours or days per cycle, including follow-ups |
| 4 | Required skills | Generalist, specialist, or technical knowledge |
| 5 | Internal stakeholders | Who must contribute evidence or approvals |
| 6 | Peak-period timing | Which months it lands in |
| 7 | Dependencies | What must happen first, and who it waits on |
| 8 | Current owner | Who does it today |
| 9 | Backup owner | Who covers if that person is unavailable |
| 10 | Business impact if delayed | Lost deal, audit finding, regulatory exposure, or minor delay |
This gives a far better basis for decisions than counting frameworks or certifications. It shows where capacity tightens, which skills are scarce, and where a single absence would stall delivery.
With that picture in hand, leadership can evaluate the realistic options: a fully in-house team, GRC as a service, a hybrid model, or specialist support for selected activities. Each can work. The right fit depends on your workload profile, internal capabilities, risk environment, compliance requirements, growth plans, and available resources.
Compliance operations are a year-round cycle of evidence, testing, reviews, assessments, and follow-up, with peaks that rarely line up neatly. The real constraint is usually concurrency and dependency on a few people, not the annual total.
Before deciding who should perform compliance work, leadership should first understand how much work exists, when it occurs, what skills it requires, and where capacity becomes constrained. In the operating-model reviews Sattrix supports, a workload inventory like the one above is typically the first exercise, because it turns a staffing debate into a decision based on evidence.
It runs recurring evidence collection, control testing, policy reviews, vendor assessments, customer questionnaires, internal audits, management reviews, audit support, and remediation tracking. Most of this happens outside the external audit window.
Audit fieldwork adds evidence requests, walkthroughs, and findings responses on top of work that does not pause, such as customer questionnaires and remediation. The overlap, not the audit alone, drives the increase.
Evidence collection and validation, coordination with control owners, and customer security questionnaires usually take the largest share, along with the follow-up work each one creates.
List every recurring activity with its frequency, effort per cycle, timing, stakeholders, and owner. Then map it across a 12-month calendar to see where activities overlap.
Teams fall behind in peak months, not average ones. A team sized for the average may miss deadlines exactly when audits, customers, and remediation converge.
Knowledge of evidence locations, control mappings, and auditor history often builds up with one specialist and is not documented or shared. Without a named backup owner, that person becomes a single point of failure.
The actual workload, peak periods, required skills, dependencies on individuals and other teams, and the business impact of delays. These inputs matter more than the number of frameworks held.