Skip to content

Compliance Determination

A compliance determination is OrviQ's answer to the only question a regulator, board or external auditor actually asks: are you meeting this obligation, and how do you know?

Most GRC platforms answer that question with a single number. OrviQ answers it with a structured set of independent facts, because a single number cannot be defended and, when it is wrong, cannot be explained.


What a determination is

A determination is produced by the Requirement Assurance engine for one obligation, evaluated at one instant in time. It returns:

ComponentWhat it tells you
ApplicabilityWhether this obligation applies here at all, and under whose approved decision
ScopeThe declared boundary and the population denominator used
Evidence statusWhether supporting evidence is current, mixed, stale, incomplete or missing
Evidence coverageWhat proportion of the in-scope population is actually covered
Control effectivenessWhether the mapped implementing controls are operating
Requirement satisfactionThe objective verdict on the obligation itself
Governance dispositionYour organisation's formal position, including accepted deviations
Exception postureWhether an approved exception is in force, and which one
Review stateWhether a person has signed off, who, and when
ExplanationA plain-language sentence stating why the verdict is what it is

Every determination is reproducible. Given an as_of timestamp, OrviQ reconstructs the answer using the scope membership, mappings, evidence and approvals that existed at that moment — not today's.


The two verdicts: satisfaction and disposition

This is the distinction most compliance teams find genuinely useful, and it is the one that most tooling gets wrong.

Requirement satisfaction is the objective verdict. It answers: given the controls, evidence and coverage in front of us, is the obligation met?

SatisfactionMeaning
satisfiedAll mapped controls effective, evidence current, coverage complete
partially_satisfiedGenuine but incomplete assurance — partial effectiveness, or coverage gaps
not_satisfiedA mapped implementing control is ineffective, or direct evidence failed
not_assessedThere is not enough evaluated information to reach a verdict

Governance disposition is your organisation's position. It answers: what stance has the organisation formally taken about this obligation?

DispositionMeaning
compliantSatisfaction is satisfied and no deviation applies
accepted_deviationAn approved exception is in force covering the gap
remediation_requiredThe obligation is partially or not satisfied and remediation is owed
unassessedNo determination has been reached

An exception never rewrites satisfaction

If a control is ineffective and an approved exception EXC-2026-0012 covers it, OrviQ records:

  • satisfaction = not_satisfied
  • disposition = accepted_deviation, referencing EXC-2026-0012

It does not flip satisfaction to satisfied, and it does not replace satisfaction with a value like "exception applied". The exception is a governance decision about an unmet obligation — the obligation stays unmet, and the record says so plainly. That is what makes the exception defensible rather than a way of hiding a gap.


What feeds a determination

1. Applicability — the first gate

Before anything else is evaluated, OrviQ resolves the authoritative applicability of the obligation in its declared scope.

  • Approved Applicable — the obligation proceeds through full evaluation.
  • Approved Not Applicable — the obligation is authoritatively excluded from the denominator. It is never marked satisfied or compliant. It returns satisfaction not_applicable with the approved justification attached, and is retained in full historical detail.
  • Draft, pending review, rejected or under review — the obligation is an unresolved obligation. It is never silently excluded. An unapproved applicability decision cannot quietly change your compliance position.

That last rule matters more than it first appears. If drafting a "Not Applicable" note were enough to remove an obligation from your denominator, the fastest route to 100% compliance would be to mark everything out of scope. Approval is the control that prevents this.

2. Scope and the denominator

The population denominator comes from effective-dated scope membership at the evaluation instant. For qualitative scopes the denominator is 1 — OrviQ does not invent a number where none exists.

3. Mapped controls

Approved crosswalk mappings identify the implementing controls. For each, OrviQ derives control assurance independently, then combines:

Situation across mapped controlsResulting control effectiveness
Any mapped control is ineffectiveineffective
All mapped controls are effectiveeffective
Any control is effective or partially_effectivepartially_effective
Otherwisenot_assessed

4. Evidence status and coverage

Evidence status is derived from the freshness of the underlying telemetry:

Underlying evidenceEvidence status
All active and currentcurrent
A mixture of active and stale/missingmixed
All stalestale
None presentmissing
Otherwise inconsistentincomplete

Coverage is a percentage of the in-scope population, averaged across the mapped controls, with the covered and uncovered counts reported alongside it so the percentage is never presented on its own.

5. Obligations with no control at all

Not every obligation is control-addressable. Filing a return, obtaining board approval, publishing a notice — these are satisfied by evidence of the act, not by a control operating continuously.

OrviQ evaluates these as non-control obligations using direct evidence assertions:

  • Any failed assertion → not_satisfied
  • All assertions passing and current → satisfied
  • All passing but stale or mixed → partially_satisfied
  • Otherwise → not_assessed

Control effectiveness for these obligations is reported as not_assessed with the reason "non-control obligation: assessed via direct evidence assertions and attestations". OrviQ does not fabricate a placeholder control just to have something to point at.

6. Governed exceptions

An active, approved exception attaches to the determination as exception posture — its reference, status, approval rationale, validity window and reassessment date — and drives disposition to accepted_deviation. Expired exceptions stop being effective automatically once the validity window passes.

7. Review state

Review stateMeaning
reviewedA person has signed off, recorded with reviewer identity, timestamp and notes
manual_review_requiredSatisfaction is partial or not satisfied, or an exception is active — human attention is owed
automatedThe evaluation stands on deterministic telemetry with no outstanding review requirement

What does not feed a determination

These are deliberate omissions, not gaps:

  • The existence of a mapping. A mapping is a design intention. It never advances satisfaction on its own.
  • The existence of an evidence file. An uploaded document that no rule has evaluated contributes nothing to satisfaction.
  • Control effectiveness alone. An effective control does not by itself satisfy a requirement; the requirement's own coverage and evidence status still apply.
  • AI output. No AI model determines pass, fail, effectiveness, satisfaction or compliance. AI drafts rationale and suggests candidates; deterministic rules and human approvals decide. See AI Authority Boundaries.
  • An approved exception. It changes your position, not the underlying fact.
  • A risk acceptance. Accepting a risk does not eliminate it, and does not satisfy the obligation the risk relates to.
  • An approved plan. A signed business continuity plan is not a tested one.

Assessed versus unassessed

not_assessed is a first-class, meaningful answer in OrviQ, and it is never displayed as if it were not_satisfied.

The distinction matters because the remediation is different:

StateWhat it meansWhat to do
not_assessedWe do not yet knowMap a control, attach evidence, or define an indicator
not_satisfiedWe know, and the answer is noRaise a finding, open an action plan, or request an exception

An obligation with no mapped control and no direct evidence is not_assessed — never automatically not_satisfied. Assuming failure where nothing has been measured is as untruthful as assuming success.


Current versus historical state

Every determination carries an as_of timestamp. Requesting a determination as of a past date reconstructs:

  • The scope membership that was effective then
  • The mappings whose validity window covered that instant
  • The indicator results recorded at or before that instant
  • The applicability decisions approved by then
  • The exceptions in force then

It does not apply today's evidence to a past date. An external auditor asking "what did you know in March, and on what basis?" gets March's answer, including March's gaps.

See Historical Reconstruction.


How incomplete information is represented

OrviQ's default posture toward missing information is to say so:

  • No indicators defined → effectiveness is not_assessed, with the reason "no active indicators defined for this control".
  • Indicators defined but never evaluated → the result is not_determined, not fail.
  • Coverage 62% → shown as 62% with the covered and uncovered counts, never rounded up to a green badge.
  • Qualitative scope with no attestation → coverage 0% and evidence missing, not "compliant by default".

Why OrviQ avoids fabricated percentages

A "compliance score" that mixes together applicable and inapplicable obligations, assessed and unassessed ones, and mapped and evidenced ones is a number nobody can defend under questioning. Three specific failure modes are designed out:

1. Averaging away a critical failure. If a control has nine passing indicators and one failing indicator marked mandatory, a naive average reports 90%. OrviQ reports ineffective. A mandatory failure is a gate, not a term in a mean.

2. Silent denominator manipulation. Unapproved "Not Applicable" decisions do not shrink the denominator. Only approved ones do, and each carries a justification and an approver.

3. Presenting absence as success. Unassessed obligations are counted as unassessed. They are not quietly excluded, and they are not quietly counted as compliant.

Where OrviQ does present percentages — evidence coverage, indicator pass rates — the percentage is always accompanied by its numerator, denominator and the rule that produced it.


Worked examples

Example A — genuinely satisfied

ISO 27001-style control on antivirus deployment across 120 endpoints.

Scope SCP-2026-0011 holds 120 effective-dated endpoint members. Indicator IND-2026-0033 (all_pass, mandatory, daily) evaluates the endpoint management platform feed: 120 observed, 120 fresh, 120 pass. Coverage 100%, effectiveness effective, evidence current.

Determination: satisfaction satisfied, disposition compliant, review state automated.

Example B — coverage gap

Same control, but the feed covers 104 of 120 endpoints; the remaining 16 are a newly acquired subsidiary not yet onboarded.

Coverage 86.7%, evidence mixed, effectiveness partially_effective.

Determination: satisfaction partially_satisfied, disposition remediation_required, review state manual_review_required. The explanation names the coverage figure and the evidence status.

What good looks like here

The right response is not to change the scope so the number improves. It is to raise a finding against onboarding the 16 endpoints, and to leave the determination honest until they are covered.

Example C — accepted deviation

A legacy trading system cannot support the required password rotation. Effectiveness on the mapped control is ineffective. The CRO approves exception EXC-2026-0012 valid for nine months with a compensating control and a reassessment date.

Determination: satisfaction not_satisfied, disposition accepted_deviation, exception posture active referencing EXC-2026-0012.

The board pack shows an accepted deviation with an owner and an expiry — not a green tick, and not an unexplained red one.

Example D — approved not applicable

An institution with no card acquiring business adopts a framework containing card-data clauses. Applicability records for those clauses are set to Not Applicable with the justification "The institution does not store, process or transmit cardholder data; no card acquiring or issuing business line exists", submitted by the Compliance Analyst and approved by the Compliance Manager.

Determination: satisfaction not_applicable, excluded from the denominator, retained in full in the Statement of Applicability with the justification and approver visible.

Example E — non-control obligation

An obligation requires an annual board-approved risk appetite statement. There is no continuously operating control here. A governance attestation is recorded as a direct evidence assertion with an observed state of pass and a 12-month freshness window.

Determination: obligation type non_control, effectiveness not_assessed (correctly — no control is involved), satisfaction satisfied while the attestation remains fresh, moving to partially_satisfied once it goes stale.


Who can do what

ActionPermission
View assurance posture and explainabilityassurance.read
Re-evaluate supporting evidence and snapshotassurance.read plus module access
Record a governed requirement assurance reviewassurance.review
Trigger automated assurance recalculationassurance.evaluate (requires the Continuous Assurance entitlement)
View compliance statuscompliance.read
Validate submissionscompliance.validate
Final compliance approvalcompliance.mark_complied

Requirement Assurance is part of core compliance and does not require the Continuous Assurance licence. Continuous Assurance enriches determinations with automated telemetry where it is enabled; without it, manual evidence and manual control assessments continue to work.


Troubleshooting

"Everything shows Not Assessed." Most often no indicators are defined and no direct evidence assertions exist. Determination is refusing to guess. Define an indicator on the mapped control, or record a direct assertion for a non-control obligation.

"My control passes but the requirement is only partially satisfied." Check coverage. Passing on 40 of 120 in-scope subjects is a real pass on a partial population, and the requirement reflects the whole population.

"I approved an exception but the requirement still says not satisfied." That is correct and intentional. Look at the disposition — it will read accepted_deviation. See the boxed note above.

"A Not Applicable decision is not taking effect." It is almost certainly still in draft or pending_review. Only approved applicability decisions are authoritative.

"The historical view differs from what I remember reporting." The historical view reconstructs from records as they stood. If mappings were retired or scope members removed since, the past view legitimately differs from a recollection based on the current register.


OrviQ Enterprise Governance, Risk & Compliance Platform