Appearance
Compliance Officer Playbook
This playbook defines the operating rhythm, primary workspaces, approval boundaries, and governance principles for Compliance Officers and Compliance Managers in OrviQ.
1. What This Role Does in OrviQ
The Compliance Officer maintains the organization's regulatory boundary, manages the requirements pipeline, verifies control alignments, monitors horizon regulatory changes, and prepares defensible compliance determinations.
In OrviQ, the compliance role is split into two complementary authority levels:
- Compliance Officer (
compliance_officer): The primary maker and analyst. Ingests regulations, manages requirement details, reviews evidence, structures crosswalk mappings, runs policy assessments, and triages gaps. - Compliance Manager (
compliance_manager): The primary checker and authority. Reviews proposed mappings, approves high-impact change dispositions, grants governed exception approvals, and makes final compliance determinations.
2. Primary Workspaces
Compliance personnel primarily operate across the following modules:
| Workspace | Route | Key Activities |
|---|---|---|
| Regulatory Library | /library | Browse adopted frameworks, circulars, and statutes; ingest new regulations. |
| Requirements Register | /requirements | Inspect individual obligations, review owner assignments, and verify evidence. |
| Scope & Applicability | /scope-applicability | Determine applicability of obligations across organizational entities and assets. |
| Control Crosswalk | /crosswalk | Establish and maintain mappings between requirements and internal controls. |
| Policy Library & Assessments | /governance, /governance/assessments | Oversee corporate policies, run existing-policy assessments, and triage gaps in /governance/gaps. |
| Regulatory Changes | /reg-intel/changes | Review regulatory change feed and horizon events; assess change impacts. |
| Approvals Hub | /approvals | Review and sign off on submissions awaiting multi-eye compliance action. |
| GRC Calendar | /calendar | Monitor regulatory filing deadlines, review cadences, and statutory dates. |
3. Typical Operating Workflow
Daily Cadence
- Check Workbench & Approvals: Open My Workbench (
/my-work) and Approvals Hub (/approvals). Prioritize items with approaching SLA deadlines or returned-for-rework items. - Review Triage Notifications: Review alerts regarding newly assigned requirements, evidence submissions, or regulatory change events.
Weekly & Bi-Weekly Cadence
- Review Regulatory Horizon: Open Regulatory Changes (
/reg-intel/changes). Triage incoming regulatory alerts, circulars, and consultation papers. Link confirmed events to impacted requirements or policy statements. - Crosswalk Maintenance: Open Control Crosswalk (
/crosswalk). Evaluate proposed mappings between new requirements and internal controls. Verify that relationship types (satisfies,partially_satisfies) match control scope. - Evidence Sufficiency Checks: In Requirements (
/requirements), review linked evidence against expected evidence criteria. Reject insufficient or expired artifacts with clear written justification.
Monthly & Quarterly Cadence
- Execute Policy Assessments: In Policy Assessments (
/governance/assessments), run coverage assessments between internal policies and target regulations. Review resulting gaps in the Gap Workbench (/governance/gaps). - Conduct Compliance Determinations: For evaluated requirements, evaluate whether design adequacy and operating effectiveness criteria have been satisfied. Only a
compliance_managercan finalize a compliant determination. - Executive Reporting: Generate regulatory compliance status reports, Statement of Applicability (SoA) summaries, and board decks in Reports (
/reports).
4. Approvals & Segregation-of-Duties (SoD) Boundaries
OrviQ strictly enforces maker-checker segregation of duties across all compliance workflows:
- No Self-Approval: A Compliance Officer who creates or modifies a crosswalk mapping, proposes an exception, or submits an assessment cannot act as the approver for that action.
- Compliance Determination Authority: Final compliance determination (
compliant,partially_compliant,non_compliant) requires thecompliance_managerrole. Submissions are gated until all mandatory expected evidence is approved. - Exception Approval: Policy or requirement exceptions (
EXC-YYYY-NNNN) must be approved by an authorized manager independent of the requester. - Assistant Read-Only Guard: The OrviQ AI Assistant (
Ctrl+J) is strictly an advisory engine. It cannot bypass workflows, approve requirements, or mutate compliance records.
5. What the System Does NOT Imply
To preserve audit defensibility, Compliance Officers must observe these mandatory system boundaries:
Semantic Guardrails
- Mapping $\neq$ Compliance: Linking a regulatory obligation (
REQ-ACS-01.1) to an internal control (CTRL-IAM-01) records an architectural relationship. It does not establish that the requirement is satisfied or complied with. - Adoption $\neq$ Compliance: Adopting a certified Policy Pack from the Content Library instantiates baseline draft policies. It does not certify that your organization meets the underlying regulatory standard.
- Evidence $\neq$ Effectiveness: An approved evidence upload proves that an artifact was submitted and reviewed; it does not guarantee that the control operated effectively throughout the audit period.
- Gap Closure $\neq$ Compliance Determination: Resolving an open gap in the Gap Workbench remediates a specific deficiency; it does not automatically flip the parent requirement to compliant.
- Attestation $\neq$ Compliance: High employee attestation percentages indicate successful communication; they do not prove operational compliance.