Skip to content

Compliance Activities

Where to find it: Regulatory Compliance, then Compliance Activities (/activities).

A requirement states what the regulator wants. An activity is a piece of work a named person can actually do about it.


Why activities exist

Consider a clause reading: "The institution shall maintain a documented access control policy, review privileged access at least quarterly, and retain evidence of each review for five years."

That is one requirement and three duties. They belong to three functions — Policy, IT Security Operations, and Records Management — with three different cadences. Assigning the whole clause to one person guarantees that at least two of the three duties will be under-served.

Decomposing the requirement into activities makes each duty ownable, schedulable and individually evidenced.


What an activity carries

FieldPurpose
Parent requirementThe obligation it serves
DescriptionThe specific duty
OwnerThe accountable person or team
DepartmentThe owning function
Due dateWhere the duty is time-bound
StatusProgress through the work and review chain
ResponseThe owner's recorded position and narrative
EvidenceAttached supporting artefacts

Activities and requirements

The requirement's compliance position reflects its activities, but the relationship is not arithmetic. Two completed activities out of three is not "67% compliant" — the requirement's position depends on which duty is outstanding and what the assurance evidence shows.


Working an activity

  1. Receive it. Assigned activities appear in your Workbench.
  2. Do the work. The actual compliance activity happens in your business systems.
  3. Record the response. Describe what was done and what the position is.
  4. Attach evidence. Link supporting artefacts from the Evidence Register.
  5. Submit. The activity enters the review chain.
  6. Respond to returns. A reviewer may return it with comments; it comes back to your Workbench.

The review chain

Activities and their parent requirements move through a governed chain configured for your tenant. The default requirement chain is:

Work then Department Review then Compliance Review then Management Approval then Closed

Lighter chains are available and can be bound by tenant and routing tier. Every review stage enforces segregation of duties: the person who did the work cannot be the person who reviews it.

See Workflow Templates and Segregation of Duties.


Assignment

Activities can be assigned to an individual or to a team. As with requirements, assignment is an offer the recipient accepts.

Requires obligations.assign or work.assign. Accepting requires ownership.accept.


Deadlines

Where an activity carries a due date, it appears on the GRC Calendar and drives reminder and escalation behaviour through your tenant's SLA policy.

Setting requirement and framework compliance deadlines requires deadline.configure. SLA policy is configured under Administration and requires sla.configure.


Permissions

ActionPermission
View activitiesobligations.read
Update responsesobligations.update
Assign owners and split obligationsobligations.assign or work.assign
Review submissionsobligations.review
Act on assigned workwork.act
Participate in the review chainwork.review
Escalate within the chainwork.escalate

Example

An outsourcing requirement reads: "Institutions shall notify the supervisor at least 30 days before entering a material outsourcing arrangement and shall maintain a register of all such arrangements."

Two activities:

ActivityOwnerCadence
Pre-notification process for material outsourcingProcurementPer arrangement
Maintain and reconcile the material outsourcing registerThird-Party RiskQuarterly

The Procurement activity is evidenced by notification records for each arrangement entered in the period. The Third-Party Risk activity is evidenced by the quarterly reconciliation between the register and the TPRM engagement register.

When the reconciliation finds three arrangements missing from the register, that is a genuine gap. The activity is submitted with an honest response, a finding is raised, and the requirement's compliance position moves to Partially Complied — not Complied because the notification duty was met.


Troubleshooting

"I cannot submit an activity." Check that a response is recorded and required evidence is attached. Chains can require both.

"An activity came back to me." It was returned by a reviewer. The return reason is on the activity timeline.

"I cannot review an activity I worked on." That is segregation of duties operating as designed. A different reviewer is required.

"An activity has no due date and no reminders." Due dates are set deliberately, not derived. A missing date means no deadline was captured — never a fabricated one.


OrviQ Enterprise Governance, Risk & Compliance Platform