Skip to content

Applicability & Scoping

Not every clause of an adopted regulatory framework applies to every organization, legal entity, or technology system. The Scope Registry (/scope-registry) is where compliance officers govern framework applicability.


Scoping Classifications

  • In Scope (Applicable): The mandate applies fully to the organization or designated organizational units.
  • Out of Scope (Not Applicable): The mandate does not apply due to organizational context (e.g., cloud-specific mandates for an on-premises deployment, or payment processing rules for non-financial entities).
  • Conditionally In Scope: The mandate applies under specific operational triggers or to a subset of systems/regions.

Mandatory Rationale & Governance

OrviQ enforces governance on scoping decisions:

  • Mandatory Justification: An obligation cannot be designated Out of Scope without a documented rationale explaining why the mandate is inapplicable.
  • Auditor Traceability: Every scoping decision records the decision maker, timestamp, and justification in the immutable audit trail.
  • Periodic Review: Scoping decisions should be reviewed periodically during annual governance reviews to account for organizational changes.

OrviQ Enterprise Governance, Risk & Compliance Platform