Skip to content

Requirement Assurance

Where to find it: Regulatory Compliance, then Requirement Assurance (/ncap), and within each requirement workspace.

Requirement Assurance is where the platform answers, for one obligation: what do we actually know, on what basis, and who has signed it?


The cockpit

The cockpit presents assurance posture across your adopted frameworks in one place, so a compliance manager can see the estate rather than clicking through it requirement by requirement.

For each requirement it shows the current satisfaction status, the dimensions behind it, whether an exception is in force, and whether a human review is outstanding.


The five dimensions

Assurance is deliberately not a single number. Each dimension answers a different question and can move independently of the others.

1. Evidence status

Is the supporting evidence there, and is it current?

ValueMeaning
currentAll supporting evidence is active and fresh
mixedSome evidence is fresh, some stale or missing
staleEvidence exists but is beyond its freshness window
missingNo supporting evidence
incompleteEvidence is present but inconsistent across the supporting controls

2. Evidence coverage

What proportion of the in-scope population does the evidence speak to?

Reported as a percentage together with its expected, observed, covered and uncovered counts. The counts matter more than the percentage — "87%" tells you less than "104 of 120 covered, 16 uncovered".

For qualitative scopes the expected count is 1.

3. Control effectiveness

Are the mapped implementing controls operating?

ValueMeaning
effectiveAll mapped controls are operating effectively
partially_effectivePartial effectiveness or coverage gaps across mapped controls
ineffectiveAt least one mapped control is ineffective
not_assessedMapped controls have not been evaluated, or the obligation is not control-addressable

4. Requirement satisfaction

Is the obligation met?

ValueMeaning
satisfiedControls effective, evidence current, coverage complete
partially_satisfiedGenuine but incomplete assurance
not_satisfiedA mapped control is ineffective, or direct evidence failed
not_assessedInsufficient evaluated information to conclude
not_applicableGoverned as excluded through an approved applicability decision

5. Review state

Has a person signed this?

ValueMeaning
reviewedSigned off, with reviewer identity, timestamp and notes
manual_review_requiredSatisfaction is partial or negative, or an exception is active
automatedStanding on deterministic telemetry with no outstanding review

Alongside these, assurance reports governance disposition and exception posture — see Compliance Determination.


Two kinds of obligation

Control-addressable obligations

The requirement is addressed by one or more controls. Assurance evaluates each mapped control's posture, then combines them.

"Multi-factor authentication shall be enforced for all administrative access." This is a control operating continuously across a population.

Non-control obligations

The requirement is discharged by an act, an attestation or a governance decision — there is no control operating continuously.

"The board shall approve the risk appetite statement annually."

OrviQ evaluates these through direct evidence assertions attached to the requirement:

SituationSatisfaction
Any assertion failednot_satisfied
All assertions pass and are currentsatisfied
All pass but stale or mixedpartially_satisfied
Otherwisenot_assessed

Control effectiveness for these obligations reports not_assessed with the reason recorded as non-control obligation, assessed via direct evidence assertions and attestations. This is correct, not a gap.

Why this matters

Platforms that require every obligation to have a control force compliance teams to invent placeholder controls for filing duties and board approvals. Those placeholders then need owners, assessments and evidence of their own — bureaucracy generated purely by a data model. OrviQ evaluates the act directly.


The doctrine the engine enforces

  1. Never defaults to compliant. The starting state of everything is not_assessed.
  2. No mapped control is not the same as not satisfied. An obligation with no mapping and no direct evidence is not_assessed. Assuming failure where nothing was measured is as untruthful as assuming success.
  3. Mapping is not satisfaction. Mapped controls are a precondition for evaluating a control-addressable obligation, not proof of anything.
  4. Evidence existence is not compliance. An uploaded file that no rule evaluated contributes nothing.
  5. A mandatory ineffective control gates satisfaction. If any mapped implementing control is ineffective, satisfaction is not_satisfied. It cannot be averaged away.
  6. Exceptions do not rewrite satisfaction. An approved exception sets disposition to accepted_deviation while satisfaction stays objectively evaluated.
  7. Everything is reproducible as of a past date.

Governed review sign-off

Deterministic evaluation produces the objective picture. A person signs the organisational position.

Recording a review captures the reviewer identity, the timestamp and the review notes, and moves the review state to reviewed. The review is snapshotted as RAS-YYYY-NNNN, so what was signed and when remains reconstructable.

Requires assurance.review.

A review signs the position, not the facts

Signing off a requirement whose satisfaction is partially_satisfied does not make it satisfied. It records that a named person has reviewed an honest partial position and accepted it as the organisation's current stance. That is a meaningful, defensible act — and quite different from overriding the evaluation.


Refresh and history

Refresh re-evaluates supporting evidence and snapshots the resulting posture. Use it after evidence arrives or an indicator runs.

History shows the timeline of evaluations for a requirement, so you can see when posture changed and what changed it.


Licensing

Requirement Assurance is part of core compliance. It does not require the Continuous Assurance entitlement.

Continuous AssuranceWhat you get
OffFull requirement assurance driven by manual evidence, manual control assessments and direct assertions
OnThe same, enriched by automated collectors and deterministic indicators

Permissions

ActionPermission
View assurance posture and explainabilityassurance.read
Refresh supporting evidenceassurance.read plus module access
Record a governed review sign-offassurance.review
Trigger automated recalculation across controlsassurance.evaluate plus the Continuous Assurance entitlement
Use AI rationale draftingai.use plus the AI entitlement

Example

Requirement: "Access rights shall be reviewed at planned intervals and after any change of employment."

Assurance posture:

DimensionValueDetail
ApplicabilityApplicableApproved, APP-2026-0088
ScopeSCP-2026-0007Population, 63 members
Evidence statusmixedQuarterly review evidence current for 58 systems, stale for 5
Evidence coverage92.1%58 covered, 5 uncovered
Control effectivenesspartially_effectiveCTL-2026-0044 passing on 58 of 63
Requirement satisfactionpartially_satisfied"Control effectiveness is partially_effective, evidence coverage is 92.1%, evidence status is mixed"
Governance dispositionremediation_required
Review statemanual_review_required

The Compliance Manager reviews it, agrees the position, raises a finding against the five uncovered systems and signs off. Review state moves to reviewed; satisfaction stays partially_satisfied, because it is.

The board pack reports 92% coverage with five named systems outstanding and a remediation owner. Nobody has to defend a number they cannot explain.


Troubleshooting

"Everything shows not_assessed." No indicators are defined and no direct assertions exist. The engine is refusing to guess. Define an indicator on a mapped control, or record a direct assertion for a non-control obligation.

"Control effectiveness says not_assessed but the control has evidence." Evidence that no indicator evaluates does not produce effectiveness. Define an indicator with a rule.

"Satisfaction did not improve after I attached evidence." Attaching evidence is stage 9 of twelve. It has to be evaluated by an indicator before it moves effectiveness, and effectiveness has to move before satisfaction does. See The Requirement Pipeline.

"I signed off but the state reverted to manual_review_required." Posture was re-evaluated and satisfaction moved back to partial or negative, which re-raises the review requirement. Check the history timeline for what changed.

"Requirement Assurance is not visible." Requires the compliance core entitlement and assurance.read.


OrviQ Enterprise Governance, Risk & Compliance Platform