Trending Topics

Unwinding compliance’s role: Why compliance doesn’t belong to security alone
This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
Compliance has long been treated as if it were another function of the security organisation. It reports through security leadership, is managed by GRC teams, funded from security budgets, and measured by security outcomes. That structure makes sense on paper. Strong security programs are what make successful audits possible, and security teams naturally become the stewards of compliance efforts.
The problem is that many organisations have mistaken ownership for purpose.
Compliance is about trust, not just controls
Compliance depends on security as its steward, but it doesn’t exist solely to serve security. Its role is much broader than proving controls are in place or satisfying an auditor. The purpose of every certification, assessment, and audit exists to create confidence between organisations. It gives customers confidence to buy, regulators confidence to oversee, boards confidence to govern, and investors confidence that risk is being managed appropriately. It is one of the few business functions that touches nearly every part of an organisation while also being viewed through a single departmental lens.
Building trust with customers is foundational to protect market share and drive new sales. When compliance is viewed exclusively as a security responsibility, decisions about where to invest, which certifications to pursue, and how success is measured become disconnected from the rest of the business. The result is that compliance is frequently managed as a cost of doing business instead of a strategic capability that supports growth.
That shift in thinking starts with one simple question: who should have a voice in deciding what your compliance roadmap looks like? For many organisations, the answer begins and ends with security. I would argue that’s only part of the conversation.
Why revenue leadership has to be part of the conversation
One of the most overlooked stakeholders in compliance planning is the Chief Revenue Officer.
The CISO is a business partner with the CRO and should develop a compliance strategy that not only delivers a solid security posture, but also supports the growth of the company. Security understands the effort required to achieve a certification. The CRO understands whether achieving that certification actually changes the company’s ability to compete.
Those are two very different perspectives, yet both are necessary.
Before pursuing any new framework or certification, leadership should ask a simple business question: if we invest in this certification, how does it change our position in the market?
Sometimes the answer is obvious. Customers have consistently requested a particular certification during procurement. A regulated industry requires it before conversations can even begin. A geographic market has different trust expectations than the one you serve today. In those situations, the certification is less about satisfying an auditor than it is about removing friction between your business and your next customer.
The invisible pipeline most companies ignore
The challenge is that many organisations only measure the opportunities they can see. Sales teams often know which deals were lost because a customer required a certification the company didn’t have. Those lessons should be tracked and find their way into pipeline reviews and postmortems. Doing so creates clarity and purpose for a compliance strategy.
Organisations not tracking this data are analogous to a hamster wheel, running faster without a plan.
Enterprise procurement increasingly relies on standardised security requirements to narrow the field before vendors are ever invited into a conversation. Entire sectors operate with baseline expectations that determine who gets considered and who doesn’t. If your organisation doesn’t meet those expectations, there may never be an opportunity for an account executive to explain why your product is better; the conversation simply never happens.
That invisible pipeline is difficult to quantify, but it changes the way leaders should think about compliance. Certifications are not only mechanisms for demonstrating trust after a sales process begins; in many markets they determine whether the sales process begins at all.
Compliance as a market entry strategy
Viewed through that lens, compliance planning becomes less about asking which framework comes next and more about asking where the business intends to compete next.
Organisations expanding into healthcare will encounter different trust expectations than those entering financial services. Companies pursuing government contracts face entirely different requirements than those selling commercial software. International expansion often introduces another set of regulatory and customer expectations altogether.
Those are strategic business decisions, and compliance is one of the mechanisms that enables them.
This is why compliance works best when it is viewed as a shared organisational capability rather than a security initiative. Security provides the governance and technical foundation. Engineering operationalises controls. Legal and privacy help interpret regulatory obligations. Finance evaluates investments. Sales provides insight into customer expectations and competitive dynamics. Executive leadership determines where the business is headed next.
Each function contributes a different perspective, and none of them, including security, should define the roadmap in isolation.
This also changes how engineering teams experience compliance.
One of the most common frustrations I hear from engineers is that compliance feels like an endless stream of documentation requests and audit preparation exercises with little connection to the work they’re trying to accomplish. That perception is understandable when compliance is presented in a vacuum or as another requirement imposed by auditors.
The conversation becomes much different when engineering understands how those same efforts reduce customer friction, open new markets, or allow the company to pursue opportunities that previously weren’t available. The underlying work hasn’t changed, but its purpose has become clearer.
The same applies at the executive level. Boards increasingly ask security leaders to discuss resilience, operational risk, customer trust, and business continuity alongside technical controls. Compliance naturally belongs in those conversations because its value has never been limited to passing audits but instead lies in creating confidence across the business ecosystem.
That confidence is difficult to assign to a single department because it was never intended to belong to one.
The final misconception: who compliance really belongs to
Compliance doesn’t belong to the security organisation alone, it’s a shared business outcome driven throughout the organisation. Executives, Regulators, and BOD’s rely on these different governance components.
The organisations getting the most out of compliance view trust as something the entire business can rely on, whether that’s accelerating sales, strengthening customer relationships, or entering new markets with confidence.
