Skip to content

Control Owner Playbook

This playbook defines the operational workflows, key workspaces, approval boundaries, and governance principles for Control Owners (control_owner) and evidence contributors in OrviQ.


1. What This Role Does in OrviQ

The Control Owner is directly accountable for operating, maintaining, and evidencing internal controls (CTRL-XXX) within their operational domain (e.g., IT Security, Operations, Human Resources, Finance).

In OrviQ, Control Owners ensure that organizational standards and regulatory mandates are practically implemented:

  • Control Owners operate assigned preventive, detective, and corrective controls.
  • They collect and upload verifiable evidence artifacts matching configured Expected Evidence criteria.
  • They participate in control testing, design adequacy evaluations, and RCSA questionnaires.
  • They execute action plan milestones to remediate identified control deficiencies.

2. Primary Workspaces

Control Owners primarily operate across the following modules:

WorkspaceRouteKey Activities
My Workbench/my-workThe primary daily dashboard for assigned tasks, evidence requests, reviews, and approaching deadlines.
Control Register/controlsView owned controls, inspect control descriptions, frequencies, functions, and effective dates.
Evidence Register/evidenceUpload evidence artifacts, manage draft evidence links, and verify hash integrity.
Control Assessment/assessPerform self-assessments, review design adequacy findings, and review operating effectiveness.
Action Plans/action-plansReview and update assigned remediation tasks, milestone progress, and evidence of closure.
My Policies/my-policiesReview and acknowledge mandatory corporate policies assigned to your user profile.

3. Typical Operating Workflow

Daily & Weekly Cadence

  1. Check My Workbench: Open My Workbench (/my-work). Review the "My Assigned Tasks" tab for overdue or upcoming evidence submission deadlines, RCSA questionnaires, or action plan updates.
  2. Review SLA Timers: Monitor countdown indicators on active tasks. Submit required artifacts before deadlines breach SLA thresholds.

Periodic Evidence Collection Cadence (Monthly / Quarterly)

  1. Locate Expected Evidence Requirements: In Control Register (/controls), open your assigned control drawer and inspect the Expected Evidence section. Note the required evidence type (documentary, operational, performance), frequency, and mandatory status.
  2. Collect and Upload Artifacts: Open Evidence Register (/evidence) or the control's evidence drawer. Click Upload Evidence. Select the file, provide a clear business title, specify the observation period, and submit.
  3. Verify Cryptographic Stamping: Confirm the system generates a SHA-256 hash and immutable timestamp for the uploaded artifact.
  4. Link to Control & Purpose: Link the uploaded evidence to the target control, selecting the appropriate contribution purpose (Design Adequacy, Operating Effectiveness, or Outcome Efficiency).
  5. Submit for Review: Submit the draft evidence link. The link enters a governed review queue for checker verification.

Periodic Remediation Cadence

  1. Update Action Plan Milestones: If a control assessment or audit produces a finding, navigate to Risk Management > Action Plans (/action-plans).
  2. Attach Completion Evidence: Upload evidence proving that remediation steps have been executed (e.g., configuration change ticket, training attendance log). Mark milestones as completed.

4. Approvals & Segregation-of-Duties (SoD) Boundaries

OrviQ maintains strict independent verification rules for control operation:

  • No Self-Approval of Evidence: A Control Owner who uploads an evidence file or creates an evidence link cannot approve that evidence link. Evidence approval requires an independent reviewer (Compliance Officer or Manager).
  • No Self-Sign-Off on Effectiveness: While Control Owners can perform operational self-assessments, authoritative operating effectiveness determinations require independent assessment or audit verification.
  • Exceptions Require Approval: If a control cannot be operated as designed, the Control Owner can draft an exception request (EXC-YYYY-NNNN) via /exceptions, but cannot approve it.

5. What the System Does NOT Imply

Control Owners must uphold OrviQ's semantic principles:

Semantic Guardrails

  • Evidence Collected $\neq$ Evidence Sufficient: Successfully uploading a requested file satisfies the collection step. It does not mean the evidence is substantively sufficient to prove compliance.
  • Evidence $\neq$ Effectiveness: Providing an execution log or configuration screenshot proves that an artifact was captured. It does not prove the control operated effectively across the entire assessment period.
  • Control Active $\neq$ Control Effective: An "Active" control status indicates that the control is officially chartered in the register; it does not mean it has been tested and proved effective.
  • Milestone Closed $\neq$ Finding Dismissed: Completing an action plan milestone reports progress; the parent finding remains open until independently verified and closed by compliance or audit authorities.

6. Where to Learn More

OrviQ Enterprise Governance, Risk & Compliance Platform