Skip to content

Regulatory Sources

Where to find it: Regulatory Compliance, then Regulatory Sources (/reg-intel/sources).

The Source Registry is the record of what OrviQ watches on your behalf. It is also, in its own right, evidence that you maintain a regulatory horizon-scanning process — which many supervisory regimes expect you to demonstrate.


What a source record contains

FieldPurpose
AuthorityThe supervisory body or standards organisation that publishes here
NameA human-recognisable label, for example "Circulars and Notices"
Source typewebpage, document_feed or manual
LocationThe address or feed being monitored
Statusactive, paused or retired
Last checkedWhen the source was last swept
OwnerWho is accountable for this source remaining correct

Choosing a source type

TypeUse whenTrade-off
document_feedThe authority publishes a structured feedMost reliable; least noise
webpageOnly a human-readable page existsCan generate change events for cosmetic edits
manualUpdates arrive by email, portal login or postNo automated detection; a person records the update, which is still fully audited

Prefer feeds where they exist

A page monitored as webpage will report a change when the authority updates a footer or rotates a banner. If the same content is available as a feed, register the feed instead and retire the page.


How to register a source

  1. Open Regulatory Sources.
  2. Select Add source.
  3. Choose the authority. If it is not listed, the authority set is administered centrally.
  4. Give the source a clear name — something a colleague will recognise in two years.
  5. Choose the source type and provide the location.
  6. Set the status to active.
  7. Save, then use Check now to establish a baseline.

Requires reg_intel.manage.


Maintaining the register

Review it on a cadence. Authorities reorganise their websites. A source that has reported no change in eighteen months is more likely broken than the authority silent.

Pause rather than delete. Setting a source to paused keeps the record and its history while stopping sweeps. Use it for seasonal or consultation-specific sources.

Retire deliberately. retired records why monitoring stopped and preserves the historical trail — useful when an auditor asks how far back your scanning coverage extends.


Sweeps

A sweep runs across active sources for your tenant and produces change events where something is detected.

  • Check now sweeps a single source immediately.
  • Sweep runs across all active sources. Requires reg_intel.sweep.

Sweeps are technical executions. They do not appear on the GRC Calendar, which is reserved for meaningful governance obligations rather than machine schedules.


Permissions

ActionPermission
View the registerreg_intel.read
Add, edit, pause or retire a sourcereg_intel.manage
Run a sweepreg_intel.sweep

Example

A regional bank supervised in two jurisdictions maintains fourteen sources:

AuthoritySourceType
Primary prudential supervisorCircularsdocument_feed
Primary prudential supervisorConsultation paperswebpage
Primary prudential supervisorEnforcement actionsdocument_feed
Data protection authorityGuidancewebpage
Payments schemeOperating bulletinsmanual

The payments scheme publishes only to an authenticated member portal, so it is registered as manual: the Operations lead records each bulletin as it arrives. The record is no less auditable for being manually maintained — it carries the same actor, timestamp and triage history.


Troubleshooting

"Last checked has not moved." The source is paused or retired, or no sweep has run. Check the status first.

"A source reports change constantly." It is a webpage with dynamic content. Switch to a feed if one exists, or to manual.

"I cannot add a source." You need reg_intel.manage. Read access alone does not permit registration.


OrviQ Enterprise Governance, Risk & Compliance Platform