The most common failure for a first compliance hire is not moving too slowly - it is absorbing work that belongs to other people. Within six months you are personally performing access reviews, chasing evidence and answering questionnaires, with no capacity to build anything. Avoiding that is mostly a first-90-days problem.
Days 1-30: understand and inventory
Resist the urge to produce a policy set in week one. Spend the first month finding out what actually exists.
- Establish why you were hired. A blocked deal, a regulator, an incident, an investor? The driver determines your sequencing, and it is rarely written in the job description.
- Inventory obligations - frameworks, contractual commitments, regulations, customer promises. Read the security schedules in your top customer contracts; organisations routinely commit to things nobody tracks.
- Inventory what exists - policies, prior assessments, past audit findings, the risk register if there is one.
- Meet the control operators. Not the managers - the people who actually grant access, deploy code, run backups.
- Find the informal controls. Engineering teams usually have good practices nobody has documented. That is a documentation gap, not a control gap, and it is your cheapest early progress.
Write down, in one page, what you found. The gap between what leadership believes is in place and what you observed is your most valuable early artefact - and it will never be as visible to you again as it is in month one.
Days 31-60: foundations and ownership
- Asset inventory. Everything downstream depends on it, and its absence blocks more work than anything else.
- Risk assessment - a first honest pass, not a perfect one. It justifies everything you will ask for later.
- Assign control owners in the business. This is the decision that determines whether you build a function or a bottleneck. Access reviews belong to system owners; change control belongs to engineering. You coordinate and verify - you do not perform.
- Pick the target framework based on the driver you identified. One framework. Others map on later.
- Run a gap analysis and produce a sequenced plan with effort estimates.
Start with structure instead of spreadsheets
GRC Copilot gives you a control library, gap assessment and evidence tracking from day one - so a one-person function scales instead of drowning.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Days 61-90: deliver something visible
You need credibility before you need completeness. Pick work that is visibly useful to someone other than you:
- The questionnaire answer library, if sales is being slowed. It buys goodwill faster than anything else you can do.
- Fix offboarding. Cheap, high-risk, and the most sampled control in every audit.
- Publish a short policy set that describes what you actually do - not aspirational templates.
- First report to leadership: current posture, top risks, decisions needed. Establish the rhythm early.
- A realistic roadmap with dates, so expectations are anchored to something.
What to postpone deliberately
- Tooling until you know your control set. Buying first means configuring around assumptions.
- Multiple frameworks. Certify one; the second costs a fraction once controls are mapped.
- Perfect documentation. A working control with rough documentation beats a beautiful policy nobody follows.
- Broad scope. Narrow and complete first.
- An audit date until the gap analysis tells you what is realistic. Committing early is how programmes fail publicly.
The trap, restated
If compliance performs the controls, three things follow: the business never takes ownership, you become the single point of failure, and you have no independence to review anything. Frameworks assume separation between operating and overseeing - and so does your own sanity.
When someone says "can you just do the access review?", the answer is "I will set it up, send it to you, and check it happened". Every time.
When to add people
Usually at the second framework, or when questionnaire volume becomes constant. The first addition is typically an analyst for evidence and questionnaires rather than another generalist - it removes the work that scales with revenue rather than with risk.
Frequently asked questions
Should GRC report to the CISO or elsewhere?
Either works, provided there is a route to escalate independently. What matters more is that internal audit does not report to the person whose controls it examines.
What if leadership will not assign control owners?
Surface it as a risk with the consequence stated plainly - unowned controls fail, and certification requires demonstrated leadership commitment. It is not something the compliance function can solve alone.
How technical does the role need to be?
Enough to ask credible questions and recognise a non-answer. Deep technical skill helps; the ability to get engineers to engage matters more.
Consultants or in-house first?
In-house for ownership and continuity; consultants for a first certification where framework familiarity accelerates things. The risk of outsourcing entirely is an ISMS nobody internally understands.
Key takeaways
- Find the real driver - it determines your sequencing.
- Assign control owners in the business, or you become the bottleneck.
- Deliver something visibly useful before pursuing completeness.
- Postpone tooling, extra frameworks and audit dates until the gap analysis is done.