Skip to content

Controls & Assurance

This domain covers what your organisation actually does about its obligations, and how you know it is working.

In the application it spans the Controls & Assurance navigation domain: Control Register, Control Crosswalk, Control Assessment, Evidence Register, Evidence Fabric and Continuous Assurance.


The shape of the domain


Controls

ArticleWhat it covers
Control RegisterThe canonical register: fields, statuses, ownership, lifecycle
Control SourcesTurning policy and procedure documents into candidate controls
Common Control LayerControl elements: the individually mappable clauses inside a control
Control AssessmentDesign assessment, operating effectiveness and control testing
Design AdequacyGoverned assessment of whether an approved mapping is adequate by design

Crosswalk

ArticleWhat it covers
Crosswalk OverviewWhat a mapping record is and what it asserts
Relationship TypesThe eight semantic relationships, with worked examples
Crosswalk LifecyclePropose, review, approve, adjust, retire, and versioning
Crosswalk ImportImporting external catalogues as governed proposals
AI Mapping SuggestionsDiscovery and AI proposal, and their strict limits
Historical CrosswalkPoint-in-time reconstruction of the mapping estate

Evidence

ArticleWhat it covers
Evidence RegisterManual evidence: upload, link, review
Evidence FabricThe whole evidence graph and how its pieces relate
Evidence ConnectionsExternal source connections
CollectorsAutomated collection definitions and runs
Evidence AssertionsThe atomic observation record
Expected Evidence & FreshnessWhat should exist, by when, and what happens when it goes stale

Assurance

ArticleWhat it covers
Continuous AssuranceThe deterministic assurance layer as a whole
IndicatorsIndicator definitions, rules, results and scheduling
Control EffectivenessHow effectiveness is derived, and mandatory failure gating

Entitlements

CapabilityEntitlement
Control register, crosswalk, assessment, manual evidencecontrol_assurance
Evidence Fabric connections, collectors, indicators, automated assurancecontinuous_assurance
AI proposals and AI-suggested expected evidenceai_risk_intelligence

Core GRC works without Continuous Assurance

With the Continuous Assurance entitlement off, the control register, crosswalk, manual evidence, evidence links and manual control assessments all continue to work in full. Continuous Assurance adds automated telemetry; it is not a prerequisite for governed compliance.


Who works in this domain

RoleTypical work
Control owner (Line 1)Maintaining controls, providing evidence, responding to indicator failures
Compliance AnalystProposing mappings, defining expected evidence, gathering evidence
Compliance ManagerReviewing and approving mappings, reviewing assessments
Security or IT OperationsConfiguring connections and collectors
Internal AuditorTesting controls, reviewing assurance evidence

OrviQ Enterprise Governance, Risk & Compliance Platform