Skip to content
    July 31, 2026| Top Floor Team| 9 min read

    Who Owns Compliance When Nobody Owns Compliance?

    Somebody at your company owns compliance right now. If you never chose that person, they were chosen by accident: usually whoever answered the first security questionnaire, an IT director or senior engineer who happened to be cc'd on the email. The fix is not complicated, but it is uncomfortable. Name one accountable owner. Give them a written mandate and an escalation path that ends at the executive team. Budget the real hours the job takes. And if nobody on staff can actually carry it, hire a fractional owner instead of pretending. Here's how to tell whether you have the accidental-owner problem, and what to do once you admit it.

    Key takeaways

    • Somebody owns compliance at your company right now. If you never chose that person, they were chosen by accident, usually whoever answered the first security questionnaire.
    • The failure is structural, not a talent problem: a cross-functional program handed to someone with authority over none of the functions it touches.
    • Four symptoms diagnose it: questionnaires answered from memory, evidence living everywhere and nowhere, paper controls nobody operates, and an audit that arrives as an annual emergency.
    • The fix is a RACI with exactly one accountable name, responsibility assigned per control family to whoever already runs that part of the business, and an escalation path written down before anyone misses a deadline.
    • Price the job honestly before you assign it. Steady state runs roughly 10 to 15 hours a month for the owner plus distributed hours, spiking to 60 to 100 hours in the audit window.

    How the accidental owner gets appointed

    We see the same origin story in most first audits. Three years ago a big prospect sent over a 280-question security questionnaire. Sales forwarded it to the IT director because it looked technical. He spent a weekend answering it, the deal closed, and a precedent was quietly set. Every questionnaire since has landed on his desk. When the company later decided to pursue SOC 2, he was the obvious person to run it, because he was already "doing compliance."

    Nobody ever actually gave him the job. There's no budget line for it, no time carved out of his real responsibilities, and, most damaging, no authority over the peer teams whose cooperation compliance requires. He can't make engineering prioritize an offboarding fix over a feature. He can't make HR change its onboarding checklist. He can ask. That's the whole toolkit.

    This is not a talent problem. Most accidental owners are competent, conscientious people, which is exactly why the questionnaire landed on them in the first place. It's a structure problem. Compliance is a cross-functional program that touches engineering, HR, finance, legal, and sales, and it got handed to someone with authority over none of those functions.

    The symptoms, in case the diagnosis stings

    You probably recognize some of these. Most companies we meet before their first audit recognize all of them.

    Questionnaires get answered from memory. The answers were true once, back when someone actually checked. Nobody verifies them anymore because verification takes hours the owner doesn't have, so the responses drift away from reality one optimistic answer at a time. "Yes, we perform quarterly access reviews" was accurate in 2024. That drift is a misrepresentation risk sitting in your sales pipeline, attached to contracts with security exhibits.

    Evidence lives everywhere and nowhere. Screenshots in someone's Downloads folder. Access lists in a spreadsheet last touched two quarters ago. Policies in a Google Drive folder with permissions nobody has reviewed since the folder was created. When an auditor or a customer asks for proof, the answer is a scavenger hunt across whatever tools happened to accumulate, and the person running the hunt is the same overloaded owner who never had time to centralize any of it.

    Controls exist on paper that nobody operates. The access control policy says user access is reviewed quarterly. The last review was fourteen months ago, and it was really just the IT director skimming the Google Workspace admin console. The vendor management policy requires security review of new vendors; procurement has never heard of it. Paper controls that nobody runs are the exact controls that fail when it matters, and failure is expensive: the average breach now costs $4.99 million globally and $11.5 million in the US, according to IBM's 2026 Cost of a Data Breach report.

    The audit is an annual emergency. Six weeks before the auditor arrives, normal work stops and the scramble begins. Everyone resents it, the evidence is thin, and by the time the report lands, the program has already started decaying toward next year's scramble.

    If three or more of those describe your company, you don't have a compliance tooling problem. You have an ownership problem, and no platform purchase will fix it.

    The RACI fix, with teeth

    The repair is old-fashioned: a RACI (Responsible, Accountable, Consulted, Informed) matrix over your control set, plus an escalation path that actually gets used. The escalation path is the part everyone skips, and it's the part that matters.

    Accountable is exactly one name. Not a committee, not "the leadership team." One person answers for the state of the program, and that person is either an executive or reports directly to one. If the accountable person can be overruled by the heads of the teams they depend on, you've rebuilt the accidental-owner problem with extra paperwork.

    Responsible is assigned per control family, to the person who already runs that part of the business. A workable split for a typical mid-sized company looks like this:

    • Access reviews and offboarding: IT operations manager
    • Secure development and change management: engineering lead
    • Background checks and security training completion: HR
    • Vendor security reviews: whoever owns procurement or finance
    • Customer security questionnaires: the compliance owner, with named subject-matter reviewers

    The principle is that the compliance owner coordinates and verifies; they do not personally operate controls in departments they don't run. An owner who tries to do everything themselves becomes the single point of failure the program was supposed to eliminate.

    The escalation path is written down before anyone misses a deadline. Ours usually looks like: responsible party misses a control deadline, owner sends a reminder with a five-business-day window; second miss goes to that person's manager; third miss, or any miss on a high-risk control, goes to the accountable executive, who makes the trade-off explicitly and in writing. The point is not punishment. The point is that "we skipped the Q3 access review" becomes a decision an executive consciously made and documented, rather than a default nobody chose. Auditors treat those two situations very differently. So do lawyers, after an incident.

    What ownership costs in honest hours

    Part of why the accidental owner fails is that nobody priced the job. Here's rough arithmetic for a 50-person SaaS company maintaining SOC 2 Type II, drawn from our own client engagements rather than any survey, so weight it accordingly:

    ActivityHours it takes
    Quarterly access reviews across ten or so systems12 to 16 hours per quarter
    Vendor security reviews, at two or three new vendors a quarter4 to 6 hours
    Evidence collection, control monitoring, and policy upkeep6 to 10 hours a month
    Customer security questionnaires3 to 8 hours each, and growth-stage companies often see several a month
    Audit fieldwork window60 to 100 hours concentrated in six to eight weeks

    Steady state, that's roughly 10 to 15 hours a month for the owner plus distributed hours across the responsible parties. Call it 0.15 to 0.25 of a full-time role, spiking hard around the audit, and rising with each added framework (HIPAA, ISO 27001, and CMMC each bring their own evidence cadence).

    Run that math against your IT director's calendar. If you handed them the program without removing anything else from their plate, you've already decided the work won't get done. You just haven't told them yet.

    When the right owner is fractional

    For companies under a couple hundred employees, the arithmetic above creates an awkward gap: too much work to absorb invisibly, too little to justify a full-time compliance hire whose loaded cost runs well into six figures. That gap is exactly where a fractional model fits. A vCISO gives you a named accountable owner with security leadership experience and, importantly, the standing to escalate to your executives as a peer. A compliance as a service engagement goes further and operates the program itself: the evidence calendar, the reviews, the questionnaires, the audit liaison work.

    Two honest caveats before you buy either from us or anyone else. First, you cannot outsource accountability, only operation. Your executives still make the risk decisions, and your teams still operate the controls that live inside their departments; a fractional owner without an internal escalation path fails exactly the way the IT director did, just at a higher hourly rate. Second, if you already have a full-time security leader and a GRC analyst, you don't need an outsourced owner. You need the RACI and the escalation path from the previous section, and you can build those in a week without paying anyone.

    The test we'd apply to your company is the one we'd apply to our own: can you name, right now, the one person accountable for compliance, and would every executive give the same name? If yes, tune the machine. If no, that's the whole problem, and it costs nothing to fix on paper this week.

    Frequently asked questions

    Should compliance report to IT or legal?

    It matters less than people think, and the wrong question is usually being asked. Reporting to IT gives the owner proximity to the systems where most controls live, but it risks the fox-and-henhouse problem: the function being audited grades its own homework, and compliance loses every priority fight against uptime and shipping. Reporting to legal gives independence but often too much distance from technical operations. The pattern we see work best is compliance reporting to a COO, CEO, or CISO where one exists; what actually matters is that the owner is not subordinate to the leaders whose work they have to challenge.

    What authority does the compliance owner need?

    Four things, in writing: a mandate from the executive team stating that the owner sets compliance deadlines; a budget line, even a small one, for tooling and the audit; the ability to place tasks in other teams' queues with an agreed SLA rather than begging for favors; and an escalation path that ends with an executive who will actually enforce it. An owner with all four can run the program from a mid-level seat. An owner with none of them will fail from any seat, including a C-level one.

    Can our IT director still be the owner?

    Yes, if you make it official. The failure mode is not who the person is; it's that the role was never defined. Give them the written mandate, carve the hours out of their existing workload instead of stacking on top, and connect them to the escalation path. If their calendar genuinely can't absorb 10 to 15 hours a month plus audit spikes, keep them as the responsible party for technical controls and put the accountable ownership elsewhere, internal or fractional.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.