---
title: What are the main components of Compliance Manager?
subject: Compliance Manager in Microsoft 365 is vital for organizations. Adopting best practices, conducting regular evaluations, and training personnel will ensure that compliance remains a priority across the enterprise.
author: IGOR
source: brtko.io
article_id: 71604
last_updated: 2026-09-05
url: https://brtko.io/article/71604.md
original_url: https://brtko.io/ords/r/ask/ai-ask/detail?doc_id=71604
---

# What are the main components of Compliance Manager?

# Microsoft Compliance Manager: Managing Compliance and Regulatory Requirements

## Learning Objectives

By the end of this training, participants will be able to:

- Understand the purpose and capabilities of Microsoft Compliance Manager within Microsoft 365.
- Explain how Compliance Manager helps organizations manage regulatory, legal, and industry-specific compliance requirements.
- Navigate the Compliance Manager interface and understand its key components.
- Create and manage compliance assessments using built-in regulatory templates.
- Utilize control mapping to align organizational controls with compliance standards.
- Monitor compliance initiatives through remediation actions and improvement tracking.
- Generate meaningful reports and compliance insights for stakeholders and auditors.
- Apply Compliance Manager to common regulatory frameworks such as GDPR, HIPAA, ISO 27001, and NIST.
- Implement best practices for maintaining an effective compliance management program.
- Understand the role of Compliance Manager within broader governance, risk, and compliance (GRC) strategies.

---

# Introduction

Organizations today operate in increasingly regulated environments where compliance with laws, regulations, industry standards, and internal policies is essential. Failure to maintain compliance can result in financial penalties, reputational damage, legal consequences, and operational disruptions.

As regulations such as the General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), ISO/IEC 27001, and various regional privacy laws continue to evolve, organizations need effective tools to manage compliance activities and demonstrate adherence to regulatory requirements.

Microsoft Compliance Manager is a solution within Microsoft Purview that helps organizations simplify compliance management by providing tools for assessments, control implementation tracking, risk visibility, and reporting. Rather than relying solely on manual spreadsheets and disconnected processes, Compliance Manager centralizes compliance activities in a single location.

This training provides a comprehensive overview of Compliance Manager, covering its major features, practical applications, and best practices for maintaining a strong compliance posture.

---

# What is Microsoft Compliance Manager?

## Overview

Microsoft Compliance Manager is a compliance management solution available through Microsoft Purview. It helps organizations:

- Assess compliance posture.
- Identify compliance risks.
- Track improvement actions.
- Map controls to regulations.
- Monitor progress toward compliance goals.
- Generate reports and documentation for auditors and stakeholders.

Compliance Manager provides an ongoing compliance score, helping organizations understand their current level of compliance and prioritize remediation efforts.

---

# Why Compliance Management Matters

Organizations face numerous compliance challenges:

- Constantly changing regulations.
- Increasing data protection requirements.
- Complex audit processes.
- Operational risks related to non-compliance.
- Limited visibility into compliance activities.

Effective compliance management helps organizations:

- Reduce regulatory risk.
- Strengthen data protection practices.
- Improve governance processes.
- Enhance customer trust.
- Simplify audit preparation.
- Demonstrate accountability.

Compliance Manager provides structured tools and workflows that help organizations address these challenges efficiently.

---

# Key Features of Compliance Manager

Microsoft Compliance Manager includes several important components that work together to support compliance programs.

## Assessments

Assessments evaluate how well an organization aligns with specific compliance requirements.

Each assessment includes:

- Regulatory requirements
- Control objectives
- Improvement actions
- Compliance scores
- Progress tracking

Organizations can use assessments to measure readiness against specific regulations or standards.

---

## Control Mapping

Control mapping connects organizational controls to regulatory requirements.

This allows organizations to:

- Identify control coverage.
- Reduce duplicated effort.
- Understand compliance gaps.
- Demonstrate control effectiveness.

Control mapping provides a clear relationship between business controls and compliance obligations.

---

## Improvement Actions

Improvement actions are recommended activities that help organizations strengthen compliance.

Examples include:

- Implementing retention policies.
- Configuring data loss prevention rules.
- Enabling audit logging.
- Reviewing access controls.
- Updating security procedures.

Each improvement action includes implementation guidance and tracking status.

---

## Compliance Score

Compliance Manager calculates a compliance score based on completed actions and implemented controls.

The score helps organizations:

- Measure progress.
- Prioritize remediation efforts.
- Monitor compliance maturity.
- Communicate status to management.

A higher score generally indicates stronger compliance alignment.

---

## Reporting and Auditing

Compliance Manager provides reporting capabilities that simplify audit preparation.

Benefits include:

- Centralized compliance documentation.
- Evidence collection.
- Regulatory reporting.
- Executive summaries.
- Audit readiness monitoring.

These capabilities reduce administrative effort while improving transparency.

---

# Understanding Regulatory Frameworks

Compliance Manager supports numerous regulations, standards, and frameworks.

Examples include:

- GDPR
- HIPAA
- ISO/IEC 27001
- NIST 800-53
- CCPA
- SOC 2
- PCI DSS
- FedRAMP

Organizations can manage multiple frameworks simultaneously from a single platform.

---

# Core Concepts

## Assessments

An assessment measures organizational compliance against a chosen framework.

### Benefits

- Identifies compliance gaps.
- Provides readiness measurements.
- Prioritizes remediation activities.
- Tracks progress over time.

Assessments can be customized to reflect organizational requirements.

---

## Controls

Controls are safeguards or measures implemented to reduce risk and support compliance objectives.

Examples include:

- Access management controls
- Data protection controls
- Security monitoring controls
- Encryption controls
- Incident response procedures

Controls may be technical, administrative, or operational.

---

## Control Mapping

Control mapping simplifies compliance management by linking controls to regulatory requirements.

### Example

A single encryption control may satisfy requirements for:

- GDPR
- HIPAA
- ISO 27001
- NIST

This reduces duplicate work and improves visibility.

---

## Remediation Tracking

Remediation tracking helps organizations:

- Assign tasks.
- Monitor progress.
- Manage deadlines.
- Verify completion.

This functionality supports accountability throughout the compliance lifecycle.

---

# Navigating Compliance Manager

## Accessing Compliance Manager

1. Sign in to Microsoft 365.
2. Open the **Microsoft Purview Portal**.
3. Navigate to **Compliance Manager**.
4. Review the compliance dashboard.

The dashboard provides visibility into assessments, scores, risks, and ongoing improvement actions.

---

# Understanding the Dashboard

The Compliance Manager dashboard typically displays:

- Compliance score
- Assessment summary
- Improvement actions
- Regulatory frameworks
- Risk indicators
- Recent activity

This centralized view helps compliance teams prioritize efforts and monitor progress.

---

# Conducting Compliance Assessments

## Step 1: Create a New Assessment

1. Open Compliance Manager.
2. Select **Assessments**.
3. Choose **Create Assessment**.
4. Select a compliance template.

Examples:

- GDPR
- ISO 27001
- HIPAA
- NIST

---

## Step 2: Configure Assessment Details

Define:

- Assessment name
- Regulatory framework
- Scope
- Responsible owners

Save the assessment configuration.

---

## Step 3: Review Controls

Compliance Manager automatically populates required controls.

Review:

- Microsoft-managed controls
- Customer-managed controls
- Shared responsibilities

Document current implementation status.

---

## Step 4: Complete Improvement Actions

Review recommended actions and update their status.

Typical statuses include:

- Not Started
- In Progress
- Complete

Document evidence where required.

---

# Practical Example: GDPR Assessment

## Business Scenario

An organization processes personal information of European Union citizens and must comply with GDPR.

### Objectives

The organization wants to evaluate:

- Data protection policies
- User privacy rights
- Data retention procedures
- Breach notification processes

---

## Assessment Process

1. Select the **GDPR Assessment Template**.
2. Review GDPR control requirements.
3. Assign responsible compliance personnel.
4. Upload supporting evidence.
5. Track outstanding improvement actions.

---

## Expected Outcomes

The assessment will help identify:

- Compliance strengths
- Areas requiring improvement
- Regulatory risks
- Documentation gaps

---

# Practical Example: ISO 27001 Assessment

## Business Scenario

An organization plans to pursue ISO/IEC 27001 certification.

### Objectives

Evaluate:

- Information security controls
- Risk management practices
- Access control procedures
- Incident management processes

---

## Assessment Process

1. Create an ISO 27001 assessment.
2. Map current controls to standard requirements.
3. Review identified compliance gaps.
4. Assign remediation actions.
5. Monitor progress toward readiness.

---

## Expected Outcomes

The organization gains visibility into:

- Control effectiveness
- Missing requirements
- Certification preparation status
- Improvement priorities

---

# Hands-On Exercises

## Exercise 1: Conduct a GDPR Assessment

### Objective

Launch a GDPR compliance assessment.

### Tasks

1. Access Microsoft Compliance Manager.
2. Create a new GDPR assessment.
3. Review applicable controls.
4. Identify three improvement actions.
5. Record assessment observations.

---

## Exercise 2: Map Organizational Controls

### Objective

Align existing controls with ISO 27001 requirements.

### Tasks

1. Open the Control Mapping section.
2. Review existing security controls.
3. Link controls to relevant ISO requirements.
4. Identify gaps.
5. Document recommended remediation actions.

---

## Exercise 3: Review Compliance Score

### Objective

Understand compliance scoring.

### Tasks

1. Access the dashboard.
2. Review the current compliance score.
3. Identify actions affecting the score.
4. Determine which improvement actions should be prioritized.

---

## Exercise 4: Generate Compliance Reports

### Objective

Practice reporting and audit preparation.

### Tasks

1. Open reporting features.
2. Generate an assessment report.
3. Review identified risks.
4. Export the report for stakeholder review.

---

# Using Compliance Manager for Governance

Compliance Manager should not operate in isolation.

It works best when integrated with:

- Governance frameworks
- Risk management processes
- Security operations
- Internal audit programs
- Data protection strategies

Organizations that align compliance activities with broader governance initiatives can improve efficiency and reduce risk.

---

# Knowledge Check

## Questions

1. What is Microsoft Compliance Manager?
2. What are the primary components of Compliance Manager?
3. How does control mapping support compliance efforts?
4. What is the purpose of a compliance assessment?
5. What does the compliance score represent?
6. Why is remediation tracking important?
7. Name three regulatory frameworks supported by Compliance Manager.
8. How can Compliance Manager simplify audit preparation?

---

# Answer Guide

1. Compliance Manager is a Microsoft solution that helps organizations assess, manage, and improve compliance activities.
2. Assessments, control mapping, improvement actions, compliance scoring, and reporting.
3. It aligns organizational controls with regulatory requirements and identifies compliance gaps.
4. To evaluate compliance posture against a selected regulation or framework.
5. It reflects progress toward implementing required controls and improvement actions.
6. It helps organizations monitor corrective actions and ensure accountability.
7. Examples include GDPR, HIPAA, ISO 27001, NIST, and PCI DSS.
8. It centralizes documentation, reporting, evidence collection, and compliance tracking.

---

# Best Practices

## Conduct Regular Assessments

Periodically review compliance status as regulations evolve.

## Maintain Accurate Documentation

Document controls, evidence, policies, and remediation activities.

## Assign Clear Ownership

Ensure compliance actions have designated owners and accountability.

## Prioritize High-Risk Areas

Focus efforts on controls that address the greatest business and regulatory risks.

## Integrate Compliance with Security

Align compliance objectives with cybersecurity and governance initiatives.

## Monitor Compliance Scores

Use scoring trends to identify areas requiring additional attention.

## Train Compliance Teams

Provide regular training on regulatory requirements and Compliance Manager functionality.

## Prepare Continuously for Audits

Maintain evidence and documentation throughout the year rather than preparing only when audits occur.

---

# Summary

Microsoft Compliance Manager is a powerful compliance management solution that helps organizations evaluate, monitor, and improve regulatory compliance across multiple frameworks and standards. Through assessments, control mapping, remediation tracking, compliance scoring, and reporting, organizations gain visibility into their compliance posture and can proactively address gaps before they become significant risks.

By leveraging Compliance Manager effectively, organizations can reduce compliance complexity, improve governance, streamline audit preparation, and strengthen overall risk management. Regular assessments, continuous monitoring, and adherence to best practices ensure that compliance remains an ongoing business capability rather than a reactive exercise.

As regulatory expectations continue to increase globally, Compliance Manager provides organizations with a structured and scalable approach to maintaining compliance and protecting critical information assets.

---

# Additional Resources

- [Microsoft Learn: Compliance Manager](https://learn.microsoft.com/microsoft-365/compliance/compliance-manager-overview)
- [Microsoft Purview Documentation](https://learn.microsoft.com/purview/)
- [GDPR Information Portal](https://gdpr.eu/)
- https://www.iso.org/isoiec-27001-information-security.html
- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)
- [Microsoft Security, Compliance, and Identity Training](https://learn.microsoft.com/training/)
