Appearance
Key Concepts
Understanding OrviQ's data models and terminology is essential for navigating compliance workflows effectively.
1. Requirement & Obligation
A Requirement represents a specific mandate from a regulation, standard, or law (e.g., UAE IA Regulation clause 5.1.2 or ISO 27001 A.8.1). In OrviQ, complex requirements can be scoped and split into discrete, measurable sub-obligations.
2. Scope & Applicability
Not all regulations apply equally to every entity. The Scope Registry allows organizations to mark requirements as In Scope, Out of Scope, or Conditionally Applicable, backed by mandatory justification.
3. Internal Control
An Internal Control is an organizational policy, operational procedure, or technical safeguard designed to meet regulatory obligations and mitigate risks. Controls are identified by canonical business references (e.g., CTL-2026-0004).
4. Control Crosswalk & Mapping
A Crosswalk Mapping establishes the relationship between a Requirement and an Internal Control. OrviQ supports distinct semantic relationship types:
- Equivalent: The control fully satisfies the mandate.
- Subset: The control satisfies a portion of the mandate.
- Superset: The control satisfies the mandate and additional requirements.
- Intersection: The control partially overlaps with the mandate.
- Compensating: The control provides alternative risk mitigation when standard implementation is infeasible.
5. Evidence Fabric
Evidence consists of verified documentation, technical configurations, audit logs, or operational records demonstrating that a control is operating effectively. Evidence items track file assets, validity periods, and review dates.
6. Continuous Assurance
Rather than relying on point-in-time audits, OrviQ tracks Assurance continuously through automated freshness monitors, periodic review cadences, and indicator evaluations.
7. Risks & Findings
- Finding (
FND-YYYY-NNNN): A documented deficiency, gap, or control failure identified during an audit, assessment, or automated check. - Risk (
RSK-YYYY-NNNN): An identified vulnerability or threat with inherent and residual risk scores, linked mitigating controls, and treatment plans.
8. Governed Approvals
Sensitive changes—such as approving crosswalk mappings, granting risk exceptions, or publishing corporate policies—follow formal approval paths (maker-checker, 4-eye, 6-eye) routed to the Approvals Hub.