The Business Analyst GRC is responsible for analyzing, designing, and implementing business processes and systems that support the organization's Governance, Risk, and Compliance framework. This role bridges the gap between business requirements and technical solutions, ensuring that compliance, risk management, and governance objectives are met efficiently and effectively.
Key Responsibilities
- Collaborate with business and IT stakeholders to define and document GRC requirements, processes, and workflows.
- Conduct gap analyses between current-state and target-state GRC processes.
- Support the implementation, configuration, and optimization of GRC tools (e.g., ServiceNow GRC, RSA Archer, MetricStream).
- Gather and analyze data to identify control weaknesses, risks, and compliance gaps.
- Assist in developing key risk indicators (KRIs), key performance indicators (KPIs), and control testing procedures.
- Support audits, assessments, and regulatory reporting by providing data and analysis.
- Create and maintain documentation, including process maps, business requirements documents (BRDs), and functional specifications.
- Work closely with security, compliance, audit, and IT teams to ensure alignment between business and regulatory objectives.
- Provide training and support to end-users on GRC processes and systems.