Skip to content

Requirements & Obligations

In OrviQ, Requirements represent individual rules, clauses, or statutory mandates within a compliance framework.


Obligation Decomposition

Complex regulatory articles often contain multiple distinct requirements within a single text block. OrviQ supports decomposing a regulatory section into granular, independently verifiable sub-obligations.

Each requirement captures:

  • Framework & Clause Code: E.g., UAE-IA::5.1.2 or ISO-27001::A.8.1.
  • Title & Description: The exact statutory text and contextual intent.
  • Scoping Status: Applicability decision recorded in the Scope Registry.
  • Mapped Controls: Supporting internal controls linked via the Control Crosswalk.
  • Attached Evidence: Direct proof verifying obligation fulfillment.
  • Compliance Determination: The authoritative verdict on whether the requirement is satisfied.

Determination States

A requirement moves through the following compliance determination lifecycle:

  1. Unassessed / Not Assessed: The baseline state. No formal assessment has been performed.
  2. Under Assessment: The obligation is actively being evaluated against mapped controls and evidence.
  3. Compliant: Sufficient controls are verified as effective and supporting evidence is verified and fresh.
  4. Partially Compliant: Some required controls or evidence items exist, but notable gaps remain.
  5. Non-Compliant: Key controls are missing, ineffective, or critical evidence is absent.
  6. Not Applicable: The requirement is formally marked Out of Scope with an approved justification.

::: important Compliance Principle A requirement's determination is an authoritative human judgment supported by evidence. It is never automatically promoted to "Compliant" merely because a control has been linked. :::

OrviQ Enterprise Governance, Risk & Compliance Platform