Skip to main content

Compliance Analyst

Governance and compliance, an entry-level role

What does Compliance Analyst do?

Researches obligations, monitors change, maps requirements to controls, investigates issues and communicates findings. AI adds a new subject to a familiar discipline.

What it decides: Whether a requirement applies, and which control and owner it lands on.

The competencies employers name

  • Regulatory change managementcore, working knowledge

    Spots a regulatory change, decides applicability, assigns actions, updates controls and keeps the implementation evidence.

    7 graded topics teach this

  • Control design and operating-effectiveness testingcore, working knowledge

    Maps risks to preventive, detective and corrective controls, then tests design and operation with samples, evidence and defensible findings.

    12 graded topics teach this

  • Evidence collection and audit-ready documentationcore, working knowledge

    Collects, labels and preserves the evidence that a control operated, a decision was made, and a claim can be defended to an auditor or regulator.

    20 graded topics teach this

  • Framework crosswalking without false equivalencerequired, working knowledge

    Compares the EU AI Act, NIST AI RMF, ISO/IEC 42001 and sector rules by intent and control objective, and says where they do not overlap.

    5 graded topics teach this

  • EU AI Act obligations and timelinesrequired, working knowledge

    Classifies a system by role and risk tier, knows which obligations bind on which date after the Digital Omnibus, and what evidence conformity needs.

    24 graded topics teach this

  • US federal and state AI regulationrequired, working knowledge

    Tracks executive orders, OMB guidance, agency rules and the state patchwork, and knows which state laws reach hiring, insurance and consumer decisions.

    17 graded topics teach this

  • AI policy and standards writingpreferred, working knowledge

    Writes policies with scope, responsibilities, requirements, exceptions and evidence, so people can follow them and auditors can test them.

    10 graded topics teach this

  • Working AI fluencyrequired, working knowledge

    Uses generative AI tools daily, knows what a model can and cannot do, and can say where an output should not be trusted.

    21 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

Add what you already have (optional)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

  • Recent graduate in law or business
  • Operations analyst
  • Paralegal
  • Quality analyst

Where it leads

Backgrounds that reach it fastest

What postings tend to name

Frameworks: ISO 37301, EU AI Act, NIST AI RMF.

Credentials often listed: CCEP, CGRC, CIPP. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

Are compliance analysts already qualified for AI governance work?
Largely. Structured risk review with a documented outcome is the same discipline. What they add is the AI vocabulary and the specific frameworks, which takes far less time than learning compliance did.