Appearance
Control Owner Playbook
This playbook defines the operational workflows, key workspaces, approval boundaries, and governance principles for Control Owners (control_owner) and evidence contributors in OrviQ.
1. What This Role Does in OrviQ
The Control Owner is directly accountable for operating, maintaining, and evidencing internal controls (CTRL-XXX) within their operational domain (e.g., IT Security, Operations, Human Resources, Finance).
In OrviQ, Control Owners ensure that organizational standards and regulatory mandates are practically implemented:
- Control Owners operate assigned preventive, detective, and corrective controls.
- They collect and upload verifiable evidence artifacts matching configured Expected Evidence criteria.
- They participate in control testing, design adequacy evaluations, and RCSA questionnaires.
- They execute action plan milestones to remediate identified control deficiencies.
2. Primary Workspaces
Control Owners primarily operate across the following modules:
| Workspace | Route | Key Activities |
|---|---|---|
| My Workbench | /my-work | The primary daily dashboard for assigned tasks, evidence requests, reviews, and approaching deadlines. |
| Control Register | /controls | View owned controls, inspect control descriptions, frequencies, functions, and effective dates. |
| Evidence Register | /evidence | Upload evidence artifacts, manage draft evidence links, and verify hash integrity. |
| Control Assessment | /assess | Perform self-assessments, review design adequacy findings, and review operating effectiveness. |
| Action Plans | /action-plans | Review and update assigned remediation tasks, milestone progress, and evidence of closure. |
| My Policies | /my-policies | Review and acknowledge mandatory corporate policies assigned to your user profile. |
3. Typical Operating Workflow
Daily & Weekly Cadence
- Check My Workbench: Open My Workbench (
/my-work). Review the "My Assigned Tasks" tab for overdue or upcoming evidence submission deadlines, RCSA questionnaires, or action plan updates. - Review SLA Timers: Monitor countdown indicators on active tasks. Submit required artifacts before deadlines breach SLA thresholds.
Periodic Evidence Collection Cadence (Monthly / Quarterly)
- Locate Expected Evidence Requirements: In Control Register (
/controls), open your assigned control drawer and inspect the Expected Evidence section. Note the required evidence type (documentary, operational, performance), frequency, and mandatory status. - Collect and Upload Artifacts: Open Evidence Register (
/evidence) or the control's evidence drawer. Click Upload Evidence. Select the file, provide a clear business title, specify the observation period, and submit. - Verify Cryptographic Stamping: Confirm the system generates a SHA-256 hash and immutable timestamp for the uploaded artifact.
- Link to Control & Purpose: Link the uploaded evidence to the target control, selecting the appropriate contribution purpose (Design Adequacy, Operating Effectiveness, or Outcome Efficiency).
- Submit for Review: Submit the draft evidence link. The link enters a governed review queue for checker verification.
Periodic Remediation Cadence
- Update Action Plan Milestones: If a control assessment or audit produces a finding, navigate to Risk Management > Action Plans (
/action-plans). - Attach Completion Evidence: Upload evidence proving that remediation steps have been executed (e.g., configuration change ticket, training attendance log). Mark milestones as completed.
4. Approvals & Segregation-of-Duties (SoD) Boundaries
OrviQ maintains strict independent verification rules for control operation:
- No Self-Approval of Evidence: A Control Owner who uploads an evidence file or creates an evidence link cannot approve that evidence link. Evidence approval requires an independent reviewer (Compliance Officer or Manager).
- No Self-Sign-Off on Effectiveness: While Control Owners can perform operational self-assessments, authoritative operating effectiveness determinations require independent assessment or audit verification.
- Exceptions Require Approval: If a control cannot be operated as designed, the Control Owner can draft an exception request (
EXC-YYYY-NNNN) via/exceptions, but cannot approve it.
5. What the System Does NOT Imply
Control Owners must uphold OrviQ's semantic principles:
Semantic Guardrails
- Evidence Collected $\neq$ Evidence Sufficient: Successfully uploading a requested file satisfies the collection step. It does not mean the evidence is substantively sufficient to prove compliance.
- Evidence $\neq$ Effectiveness: Providing an execution log or configuration screenshot proves that an artifact was captured. It does not prove the control operated effectively across the entire assessment period.
- Control Active $\neq$ Control Effective: An "Active" control status indicates that the control is officially chartered in the register; it does not mean it has been tested and proved effective.
- Milestone Closed $\neq$ Finding Dismissed: Completing an action plan milestone reports progress; the parent finding remains open until independently verified and closed by compliance or audit authorities.