Appearance
Inspection Responses
A response package is the formal reply your organisation makes to a supervisory authority: your position on each observation, and what you commit to do about it.
It is one of the highest-stakes documents a compliance function produces, and OrviQ governs it accordingly.
What a response package contains
| Element | Purpose |
|---|---|
| Executive statement | The organisation's formal position |
| Per-item responses | Acceptance, partial acceptance or challenge, with reasoning |
| Remediation roadmap | Committed actions, owners and dates |
| Supporting evidence | Artefacts referenced in the response |
Commitments in the roadmap are backed by real action plans with named owners and due dates, not by prose. A commitment written only in a letter is a commitment nobody is tracking.
Governed sign-off
The default chain is draft and coordinate, then independent compliance or legal review, with an option to escalate to executive or committee approval.
Segregation of duties: the coordinator or preparer cannot approve their own response package. Six-eye and eight-eye chains are available through workflow template configuration where a regulatory response warrants board-level approval.
Requires inspection.signoff.
The immutable submission snapshot
What was submitted is frozen at submission
On formal submission, an immutable snapshot of the response package is written into the inspection's historical record.
Subsequent edits never alter what was submitted. If a commitment changes after submission, that becomes a follow-up communication with its own record — not a quiet revision of the original.
This matters because a submitted regulatory response is a representation to a supervisor. Being able to show exactly what was sent, when, and who approved it is not a convenience.
Responding and remediating are different
A submitted response may legitimately coexist with open findings and actions in progress. Submitting the response does not:
- Close the inspection
- Close the inspection items
- Close the linked findings
- Complete the action plans
Each of those has its own governed closure. See Inspection Items.
AI assistance
AI can generate an advisory draft response. It reads the observation and the linked records and proposes wording.
| AI does | AI does not |
|---|---|
| Draft response wording | Determine your position |
| Summarise the linked remediation | Submit anything |
| Suggest structure | Approve anything |
The draft is a starting point. Given what a regulatory response is, expect to rewrite most of it — but starting from a structured draft that already references the right findings and actions saves real time.
Requires inspection.ai_assist.
Regulator feedback
After submission, the authority's acknowledgement and feedback are recorded against the inspection: the acknowledgement date, the feedback, and which items the authority considers closed or under follow-up.
An inspection moves to follow_up where the authority continues to track items, and to closed when the interaction concludes.
How to prepare a response
- Confirm every observation is captured as an item with an owner. See Inspection Items.
- Agree the position on each item — accepted, partially accepted, or challenged with reasoning.
- Ensure every commitment has a real action plan with a named owner and a date the owner has agreed to.
- Draft the executive statement.
- Submit for review. Independent compliance or legal review, escalating to executive approval where warranted.
- Finalise submission. The snapshot freezes.
- Record the acknowledgement when it arrives.
Writing commitments you will meet
The most damaging thing in a regulatory response is a commitment that is missed.
| Weak commitment | Better |
|---|---|
| "We will strengthen our outsourcing governance." | "We will revise the materiality assessment criteria and reassess all 47 existing engagements against them by 30 September, tracked under ACT-2026-0242 and owned by the Head of Third-Party Risk." |
| "This will be addressed promptly." | Any actual date. |
The second column is harder to write because it requires deciding who will do it and by when — which is exactly what the supervisor is asking.
Permissions
| Action | Permission |
|---|---|
| View responses | inspection.read |
| Draft and coordinate the response | inspection.manage |
| Review and approve the response package | inspection.signoff |
| Generate an AI advisory draft | inspection.ai_assist |
| Record regulator feedback | inspection.manage |
All require the regulatory_inspections entitlement.
Example
Inspection INS-2026-0002, response submitted 24 April.
| Element | Content |
|---|---|
| Executive statement | Acknowledges the review, accepts seven observations in full, partially accepts one, challenges one with reasoning |
| Per-item responses | Nine, each referencing its finding and action plans |
| Remediation roadmap | Fourteen action plans, owners named, dates between 30 June and 31 December |
| Evidence | Eleven artefacts |
Governance: drafted by the Head of Compliance, reviewed by Legal, escalated to and approved by the Chief Risk Officer. Snapshot frozen at submission.
The challenged observation: the response argued that an observation about board reporting frequency was based on the committee's formal minutes rather than the standing monthly reporting pack, and provided the pack as evidence.
Acknowledgement, 19 May: the authority closed two observations including the challenged one, and placed seven under follow-up.
Status at 19 May: inspection follow_up; two items closed with independent_validated; seven items open; eleven action plans in progress; three completed.
Note that the response was submitted while eleven action plans were still open. That is normal — the response commits to remediation, it does not report it complete.
Troubleshooting
"I cannot approve a response I drafted." Segregation of duties. Independent review is required.
"Submitting did not close the inspection." Correct. Submission and closure are separate.
"I need to change a submitted response." Submitted snapshots are immutable. Issue a follow-up communication and log it in correspondence.
"AI draft is unavailable." Requires inspection.ai_assist and the AI entitlement.