Appearance
Requirement Assurance
Where to find it: Regulatory Compliance, then Requirement Assurance (/ncap), and within each requirement workspace.
Requirement Assurance is where the platform answers, for one obligation: what do we actually know, on what basis, and who has signed it?
The cockpit
The cockpit presents assurance posture across your adopted frameworks in one place, so a compliance manager can see the estate rather than clicking through it requirement by requirement.
For each requirement it shows the current satisfaction status, the dimensions behind it, whether an exception is in force, and whether a human review is outstanding.
The five dimensions
Assurance is deliberately not a single number. Each dimension answers a different question and can move independently of the others.
1. Evidence status
Is the supporting evidence there, and is it current?
| Value | Meaning |
|---|---|
current | All supporting evidence is active and fresh |
mixed | Some evidence is fresh, some stale or missing |
stale | Evidence exists but is beyond its freshness window |
missing | No supporting evidence |
incomplete | Evidence is present but inconsistent across the supporting controls |
2. Evidence coverage
What proportion of the in-scope population does the evidence speak to?
Reported as a percentage together with its expected, observed, covered and uncovered counts. The counts matter more than the percentage — "87%" tells you less than "104 of 120 covered, 16 uncovered".
For qualitative scopes the expected count is 1.
3. Control effectiveness
Are the mapped implementing controls operating?
| Value | Meaning |
|---|---|
effective | All mapped controls are operating effectively |
partially_effective | Partial effectiveness or coverage gaps across mapped controls |
ineffective | At least one mapped control is ineffective |
not_assessed | Mapped controls have not been evaluated, or the obligation is not control-addressable |
4. Requirement satisfaction
Is the obligation met?
| Value | Meaning |
|---|---|
satisfied | Controls effective, evidence current, coverage complete |
partially_satisfied | Genuine but incomplete assurance |
not_satisfied | A mapped control is ineffective, or direct evidence failed |
not_assessed | Insufficient evaluated information to conclude |
not_applicable | Governed as excluded through an approved applicability decision |
5. Review state
Has a person signed this?
| Value | Meaning |
|---|---|
reviewed | Signed off, with reviewer identity, timestamp and notes |
manual_review_required | Satisfaction is partial or negative, or an exception is active |
automated | Standing on deterministic telemetry with no outstanding review |
Alongside these, assurance reports governance disposition and exception posture — see Compliance Determination.
Two kinds of obligation
Control-addressable obligations
The requirement is addressed by one or more controls. Assurance evaluates each mapped control's posture, then combines them.
"Multi-factor authentication shall be enforced for all administrative access." This is a control operating continuously across a population.
Non-control obligations
The requirement is discharged by an act, an attestation or a governance decision — there is no control operating continuously.
"The board shall approve the risk appetite statement annually."
OrviQ evaluates these through direct evidence assertions attached to the requirement:
| Situation | Satisfaction |
|---|---|
| Any assertion failed | not_satisfied |
| All assertions pass and are current | satisfied |
| All pass but stale or mixed | partially_satisfied |
| Otherwise | not_assessed |
Control effectiveness for these obligations reports not_assessed with the reason recorded as non-control obligation, assessed via direct evidence assertions and attestations. This is correct, not a gap.
Why this matters
Platforms that require every obligation to have a control force compliance teams to invent placeholder controls for filing duties and board approvals. Those placeholders then need owners, assessments and evidence of their own — bureaucracy generated purely by a data model. OrviQ evaluates the act directly.
The doctrine the engine enforces
- Never defaults to compliant. The starting state of everything is
not_assessed. - No mapped control is not the same as not satisfied. An obligation with no mapping and no direct evidence is
not_assessed. Assuming failure where nothing was measured is as untruthful as assuming success. - Mapping is not satisfaction. Mapped controls are a precondition for evaluating a control-addressable obligation, not proof of anything.
- Evidence existence is not compliance. An uploaded file that no rule evaluated contributes nothing.
- A mandatory ineffective control gates satisfaction. If any mapped implementing control is ineffective, satisfaction is
not_satisfied. It cannot be averaged away. - Exceptions do not rewrite satisfaction. An approved exception sets disposition to
accepted_deviationwhile satisfaction stays objectively evaluated. - Everything is reproducible as of a past date.
Governed review sign-off
Deterministic evaluation produces the objective picture. A person signs the organisational position.
Recording a review captures the reviewer identity, the timestamp and the review notes, and moves the review state to reviewed. The review is snapshotted as RAS-YYYY-NNNN, so what was signed and when remains reconstructable.
Requires assurance.review.
A review signs the position, not the facts
Signing off a requirement whose satisfaction is partially_satisfied does not make it satisfied. It records that a named person has reviewed an honest partial position and accepted it as the organisation's current stance. That is a meaningful, defensible act — and quite different from overriding the evaluation.
Refresh and history
Refresh re-evaluates supporting evidence and snapshots the resulting posture. Use it after evidence arrives or an indicator runs.
History shows the timeline of evaluations for a requirement, so you can see when posture changed and what changed it.
Licensing
Requirement Assurance is part of core compliance. It does not require the Continuous Assurance entitlement.
| Continuous Assurance | What you get |
|---|---|
| Off | Full requirement assurance driven by manual evidence, manual control assessments and direct assertions |
| On | The same, enriched by automated collectors and deterministic indicators |
Permissions
| Action | Permission |
|---|---|
| View assurance posture and explainability | assurance.read |
| Refresh supporting evidence | assurance.read plus module access |
| Record a governed review sign-off | assurance.review |
| Trigger automated recalculation across controls | assurance.evaluate plus the Continuous Assurance entitlement |
| Use AI rationale drafting | ai.use plus the AI entitlement |
Example
Requirement: "Access rights shall be reviewed at planned intervals and after any change of employment."
Assurance posture:
| Dimension | Value | Detail |
|---|---|---|
| Applicability | Applicable | Approved, APP-2026-0088 |
| Scope | SCP-2026-0007 | Population, 63 members |
| Evidence status | mixed | Quarterly review evidence current for 58 systems, stale for 5 |
| Evidence coverage | 92.1% | 58 covered, 5 uncovered |
| Control effectiveness | partially_effective | CTL-2026-0044 passing on 58 of 63 |
| Requirement satisfaction | partially_satisfied | "Control effectiveness is partially_effective, evidence coverage is 92.1%, evidence status is mixed" |
| Governance disposition | remediation_required | — |
| Review state | manual_review_required | — |
The Compliance Manager reviews it, agrees the position, raises a finding against the five uncovered systems and signs off. Review state moves to reviewed; satisfaction stays partially_satisfied, because it is.
The board pack reports 92% coverage with five named systems outstanding and a remediation owner. Nobody has to defend a number they cannot explain.
Troubleshooting
"Everything shows not_assessed." No indicators are defined and no direct assertions exist. The engine is refusing to guess. Define an indicator on a mapped control, or record a direct assertion for a non-control obligation.
"Control effectiveness says not_assessed but the control has evidence." Evidence that no indicator evaluates does not produce effectiveness. Define an indicator with a rule.
"Satisfaction did not improve after I attached evidence." Attaching evidence is stage 9 of twelve. It has to be evaluated by an indicator before it moves effectiveness, and effectiveness has to move before satisfaction does. See The Requirement Pipeline.
"I signed off but the state reverted to manual_review_required." Posture was re-evaluated and satisfaction moved back to partial or negative, which re-raises the review requirement. Check the history timeline for what changed.
"Requirement Assurance is not visible." Requires the compliance core entitlement and assurance.read.