5.2.2. Compliance Manager
💡 First Principle: Compliance Manager is Purview's workflow tool for managing regulatory and industry compliance — it provides pre-built assessment templates for specific regulations or standards, tracks recommended "improvement actions" needed to satisfy each control, and assigns those actions to the people responsible for completing them.
| Aspect | Compliance Manager | Compliance Score |
|---|---|---|
| What it is | The workflow tool: assessments + improvement actions | A numeric output generated by that workflow |
| Answers | "What do we need to do, and who owns it?" | "How are we doing, overall, right now?" |
| Granularity | Per-control, per-assessment detail | One summarizing number |
Each assessment maps to a specific regulation or standard (say, a specific national data-protection law) and breaks it down into individual improvement actions — some fully managed by Microsoft, some shared, and some entirely the customer's responsibility to implement, echoing the shared responsibility model (Phase 2.1.1) applied specifically to compliance controls.
⚠️ Exam Trap: Compliance Manager doesn't make an organization compliant by itself — it tracks and organizes the work; the organization still has to actually complete the improvement actions assigned to them.
Reflection Question: Why does Compliance Manager assign some improvement actions to Microsoft and others to the customer, rather than treating every control as entirely one party's responsibility?