Skip to content

Separation Principles

OrviQ is built around a small number of statements that look pedantic written down and turn out to be the difference between a compliance record you can defend and one you cannot.

Each principle below is enforced structurally — in the data model and the evaluation engines — not by convention, and not by asking users to be careful.


The eight non-equivalences

PrincipleThe tempting shortcutWhat OrviQ does instead
Mapping is not compliance"We mapped a control, so we comply"Mapping records a design intention; satisfaction is evaluated separately
Evidence availability is not evidence coverage"We have the report, so we are covered"Coverage is measured against a declared population denominator
Evidence coverage is not control effectiveness"100% covered, so the control works"Covered subjects can still be failing subjects
Applicability is not implementation"It applies to us, so we do it"Applicability is a scoping decision, nothing more
Implementation is not effectiveness"The control exists, so it works"Effectiveness requires evaluated, current evidence
Effectiveness is not requirement satisfaction"The control is effective, so the obligation is met"The obligation has its own coverage and evidence position
Risk acceptance is not risk elimination"We accepted it, so it is handled"The risk stays on the register with an expiry and an owner
Plan approval is not tested resilience"The plan is signed off, so we can recover"Untested plans are reported as not tested

Mapping is not compliance

A crosswalk mapping says: this control is intended to address this obligation, in this semantic relationship.

It does not say the control has been built, that it operates, that it covers the right population, or that anyone has looked at it this year.

Why it matters. Bulk-importing a framework crosswalk catalogue can create thousands of mappings in minutes. If mapping implied compliance, an import would produce instant, fictional compliance across an entire standard. In OrviQ, imported mappings enter as proposals awaiting review, and even once approved they advance nothing but the mapping stage.

Where you see it. The Control Crosswalk shows mapping status and relationship type. It does not show a compliance verdict, because it does not have one.

Related: Control Crosswalk, Crosswalk Import


Evidence availability is not evidence coverage

Availability is "an artefact exists." Coverage is "what proportion of the in-scope population does that artefact actually speak to?"

Why it matters. This is the most common way a compliance dashboard becomes untrue. An engineer uploads an MFA configuration export. The export covers one directory containing 40 of 512 in-scope accounts. Availability is 100%. Coverage is 7.8%.

How OrviQ handles it. Coverage is computed against effective-dated scope membership at the evaluation instant. Where the scope is qualitative — a board approval, a policy sign-off — the denominator is 1, and OrviQ does not manufacture a population that does not exist.

Related: Evidence Fabric, Scope Registry


Evidence coverage is not control effectiveness

You can have complete coverage of a population that is comprehensively failing.

Why it matters. Coverage answers "did we look everywhere?" Effectiveness answers "did we like what we saw?" A vulnerability scan covering all 512 servers and reporting 300 critical findings has 100% coverage and an ineffective control.

How OrviQ handles it. Coverage and effectiveness are separate dimensions with separate values. Indicator results carry both a coverage percentage and a result status, and a failing mandatory indicator drives effectiveness to ineffective regardless of coverage.

Related: Indicators, Control Effectiveness


Applicability is not implementation

Deciding an obligation applies to you is a scoping judgement. It creates an expectation, not a capability.

Why it matters. Newly adopted frameworks seed applicability records for every clause. If applicability implied implementation, adopting a standard would instantly claim you had implemented it.

How OrviQ handles it. An approved Applicable record means the obligation counts in your denominator. Its satisfaction begins at not_assessed and moves only when controls, evidence and evaluation exist.

Related: Scope & Applicability


Implementation is not effectiveness

A control can be documented, owned, approved and entirely non-operational.

Why it matters. Design assessment and operating effectiveness are separate audit concepts for good reason. A quarterly access review that is scheduled, assigned and never performed is implemented and ineffective.

How OrviQ handles it. Design adequacy and operating effectiveness are separate assessment types, and continuous indicators measure operation independently of either.

Related: Control Assessment, Design Adequacy


Effectiveness is not requirement satisfaction

An effective control contributes to satisfying an obligation. It does not conclude it.

Why it matters. One obligation is frequently addressed by several controls with different relationship semantics. A control mapped as subset explicitly covers only part of the obligation — declaring it effective leaves the rest unaddressed by construction.

How OrviQ handles it. Requirement satisfaction is evaluated at the requirement level across all its mapped controls, with its own evidence status and coverage, and is reported separately from any individual control effectiveness value.

Related: Requirement Assurance, Compliance Determination


Risk acceptance is not risk elimination

Accepting a risk is a decision to carry it knowingly. The exposure is unchanged.

Why it matters. If acceptance closed the risk, the register would systematically under-report exposure, and accepted risks would silently disappear from board reporting.

How OrviQ handles it. Accepted risks stay on the register with an acceptance status, an accepting authority, a justification and an expiry date. When the expiry passes, acceptance lapses and the risk returns to active governance. Choosing "Accept" as a treatment strategy is planning intent and does not, by itself, approve anything — governed acceptance requires its own maker-checker workflow.

Related: Risk Acceptance, Exceptions


Plan approval is not tested resilience

A signed continuity plan is a document. Recovery capability is a demonstrated fact.

Why it matters. Operational resilience supervision has converged on exactly this point: supervisors ask when you last tested, what the tested recovery time was, and how it compared with your stated objective.

How OrviQ handles it. Plans and exercises are separate records. An untested service reports not tested rather than being assumed resilient. When a tested recovery time exceeds the target, the target is preserved as the standard of record and the exercise is marked as a breach — the target is never quietly moved to match reality.

The full chain of non-equivalences in resilience:

Plan exists, is not plan approved, is not exercise scheduled, is not exercise completed, is not exercise passed, is not service resilient.

Related: Continuity Plans, Exercises


Two more the platform enforces

Incident occurrence is not financial loss. A severe incident may cause no loss; a loss may crystallise months later through a third-party claim. Loss is never inferred from severity. See Loss Events.

Action completion is not finding closure. Completing a remediation action does not close the finding it serves. Closure requires independent verification — and for audit findings, auditor retest. See Findings.


What this costs, and why it is worth it

These principles have a genuine cost: OrviQ will show you not_assessed where another platform would show you a comfortable number, and it will refuse to let an import turn a standard green.

The return is that every figure OrviQ does show can be traced to a named record, a named person and a timestamp — and survives the follow-up question.


OrviQ Enterprise Governance, Risk & Compliance Platform