Skip to content

Compliance Officer Playbook

This playbook defines the operating rhythm, primary workspaces, approval boundaries, and governance principles for Compliance Officers and Compliance Managers in OrviQ.


1. What This Role Does in OrviQ

The Compliance Officer maintains the organization's regulatory boundary, manages the requirements pipeline, verifies control alignments, monitors horizon regulatory changes, and prepares defensible compliance determinations.

In OrviQ, the compliance role is split into two complementary authority levels:

  • Compliance Officer (compliance_officer): The primary maker and analyst. Ingests regulations, manages requirement details, reviews evidence, structures crosswalk mappings, runs policy assessments, and triages gaps.
  • Compliance Manager (compliance_manager): The primary checker and authority. Reviews proposed mappings, approves high-impact change dispositions, grants governed exception approvals, and makes final compliance determinations.

2. Primary Workspaces

Compliance personnel primarily operate across the following modules:

WorkspaceRouteKey Activities
Regulatory Library/libraryBrowse adopted frameworks, circulars, and statutes; ingest new regulations.
Requirements Register/requirementsInspect individual obligations, review owner assignments, and verify evidence.
Scope & Applicability/scope-applicabilityDetermine applicability of obligations across organizational entities and assets.
Control Crosswalk/crosswalkEstablish and maintain mappings between requirements and internal controls.
Policy Library & Assessments/governance, /governance/assessmentsOversee corporate policies, run existing-policy assessments, and triage gaps in /governance/gaps.
Regulatory Changes/reg-intel/changesReview regulatory change feed and horizon events; assess change impacts.
Approvals Hub/approvalsReview and sign off on submissions awaiting multi-eye compliance action.
GRC Calendar/calendarMonitor regulatory filing deadlines, review cadences, and statutory dates.

3. Typical Operating Workflow

Daily Cadence

  1. Check Workbench & Approvals: Open My Workbench (/my-work) and Approvals Hub (/approvals). Prioritize items with approaching SLA deadlines or returned-for-rework items.
  2. Review Triage Notifications: Review alerts regarding newly assigned requirements, evidence submissions, or regulatory change events.

Weekly & Bi-Weekly Cadence

  1. Review Regulatory Horizon: Open Regulatory Changes (/reg-intel/changes). Triage incoming regulatory alerts, circulars, and consultation papers. Link confirmed events to impacted requirements or policy statements.
  2. Crosswalk Maintenance: Open Control Crosswalk (/crosswalk). Evaluate proposed mappings between new requirements and internal controls. Verify that relationship types (satisfies, partially_satisfies) match control scope.
  3. Evidence Sufficiency Checks: In Requirements (/requirements), review linked evidence against expected evidence criteria. Reject insufficient or expired artifacts with clear written justification.

Monthly & Quarterly Cadence

  1. Execute Policy Assessments: In Policy Assessments (/governance/assessments), run coverage assessments between internal policies and target regulations. Review resulting gaps in the Gap Workbench (/governance/gaps).
  2. Conduct Compliance Determinations: For evaluated requirements, evaluate whether design adequacy and operating effectiveness criteria have been satisfied. Only a compliance_manager can finalize a compliant determination.
  3. Executive Reporting: Generate regulatory compliance status reports, Statement of Applicability (SoA) summaries, and board decks in Reports (/reports).

4. Approvals & Segregation-of-Duties (SoD) Boundaries

OrviQ strictly enforces maker-checker segregation of duties across all compliance workflows:

  • No Self-Approval: A Compliance Officer who creates or modifies a crosswalk mapping, proposes an exception, or submits an assessment cannot act as the approver for that action.
  • Compliance Determination Authority: Final compliance determination (compliant, partially_compliant, non_compliant) requires the compliance_manager role. Submissions are gated until all mandatory expected evidence is approved.
  • Exception Approval: Policy or requirement exceptions (EXC-YYYY-NNNN) must be approved by an authorized manager independent of the requester.
  • Assistant Read-Only Guard: The OrviQ AI Assistant (Ctrl+J) is strictly an advisory engine. It cannot bypass workflows, approve requirements, or mutate compliance records.

5. What the System Does NOT Imply

To preserve audit defensibility, Compliance Officers must observe these mandatory system boundaries:

Semantic Guardrails

  • Mapping $\neq$ Compliance: Linking a regulatory obligation (REQ-ACS-01.1) to an internal control (CTRL-IAM-01) records an architectural relationship. It does not establish that the requirement is satisfied or complied with.
  • Adoption $\neq$ Compliance: Adopting a certified Policy Pack from the Content Library instantiates baseline draft policies. It does not certify that your organization meets the underlying regulatory standard.
  • Evidence $\neq$ Effectiveness: An approved evidence upload proves that an artifact was submitted and reviewed; it does not guarantee that the control operated effectively throughout the audit period.
  • Gap Closure $\neq$ Compliance Determination: Resolving an open gap in the Gap Workbench remediates a specific deficiency; it does not automatically flip the parent requirement to compliant.
  • Attestation $\neq$ Compliance: High employee attestation percentages indicate successful communication; they do not prove operational compliance.

6. Where to Learn More

OrviQ Enterprise Governance, Risk & Compliance Platform