Skip to content

Policy Owner & Reviewer Playbook

This playbook defines the operational workflows, key workspaces, approval boundaries, and governance principles for Policy Owners, Authors, and Reviewers in OrviQ.


1. What This Role Does in OrviQ

The Policy Owner is accountable for the complete lifecycle of corporate policies and governance instruments (POL-YYYY-NNNN).

Rather than treating policies as static PDF documents filed away in document stores, OrviQ treats policies as structured governance engines:

  • Policies are decomposed into ordered sections and atomic statements, each tagged with explicit obligation levels (mandatory or recommendation).
  • Policy statements are operationalized by linking them directly to operating controls, enterprise risks, accountable owners, and evidence expectations.
  • Policy Owners manage formal review cadences, monitor upcoming expirations, evaluate regulatory change impacts, and coordinate workforce attestation campaigns.

2. Primary Workspaces

Policy Owners operate primarily within the Policy Governance domain:

WorkspaceRouteKey Activities
Policy Overview/governanceMonitor enterprise policy KPI counters, review cadences, operationalization coverage, and active exceptions.
Policy Library/governance/libraryAuthor, edit, structure, and maintain internal corporate policies and versions.
Content Library (Policy Packs)/governance/packsBrowse and adopt certified out-of-the-box governance packs (Content 2.0).
Operationalization Workspace/governance/operationalizationMap atomic policy statements to controls, risks, scopes, tasks, and evidence expectations.
Gap Workbench/governance/gapsIdentify unmapped policy statements, missing controls, and failed evidence expectations.
Change Impact Workspace/governance/change-impactTriage upstream regulatory updates and assess impacts on internal policy statements.
Expiry Monitor/governance/expiryTrack policies approaching annual review cadences or expiration dates.
Policy Exceptions/governance/exceptionsReview, endorse, or manage temporary policy departure requests.

3. Typical Operating Workflow

Policy Authoring & Decomposition Cadence

  1. Adopt or Author Draft Policy:
    • Option A (Content Library): Navigate to /governance/packs. Browse certified packs (e.g., Commercial Banking, Core Governance), preview statements, and click Adopt Policy.
    • Option B (In-Tenant Authoring): Navigate to /governance/library. Click + New Policy. Complete metadata: title, category, owner, effective date, review cadence.
  2. Decompose into Atomic Statements: In the policy editor, structure the document into clear sections. Under each section, add discrete statements with explicit obligation levels:
    • mandatory: Strict organizational requirement that must be operationalized.
    • recommendation: Recommended guidance or best-practice statement.
  3. Operationalize Statements: Navigate to /governance/operationalization or the statement operationalization tab. Connect each mandatory statement to:
    • Mitigating internal controls (CTRL-XXX).
    • Mapped enterprise risks (RSK-YYYY-NNNN).
    • Expected evidence items.
    • Accountable functional owner.

Review, Revision & Publication Cadence

  1. Submit for Governed Review: Once authoring and operationalization are complete, submit the draft policy for review.
  2. Execute Governed Publication: Multi-eye reviewers evaluate the policy in Approvals Hub (/approvals). Upon approval, the policy enters published status and receives an immutable version identifier (v1.0).
  3. Controlled Revisions: Once published, policy content is permanently immutable (PUBLISHED_CONTENT_IMMUTABLE). Making modifications requires clicking Create Revision, which creates a new draft version (v1.1 or v2.0) while the current version remains published.

Horizon Change & Attestation Cadence

  1. Triage Regulatory Change Impact: When upstream regulations change, open Change Impact Workspace (/governance/change-impact). Review generated impact candidates. Record assessment dispositions (amend policy, create exception, no impact).
  2. Coordinate Workforce Attestations: For published policies requiring staff acknowledgment, configure an attestation campaign targeting relevant employee groups. Monitor completion rates on the Policy Overview dashboard.

4. Approvals & Segregation-of-Duties (SoD) Boundaries

OrviQ enforces strict lifecycle and mutation guardrails:

  • Immutability of Published Content: No user, including administrators, can edit text in a published policy version. Edits require initiating a formal revision workflow.
  • Author-Approver Separation: The user who drafts or revises a policy cannot grant terminal approval to publish that version. Independent checker approval (compliance_manager or committee sign-off) is mandatory.
  • Exception Authority: Policy Owners can review or endorse policy exception requests, but final exception approval requires independent managerial authorization.

5. What the System Does NOT Imply

Policy Owners must communicate system states accurately:

Semantic Guardrails

  • Published $\neq$ Compliant: Publishing an approved policy establishes the formal rule of the organization; it does not prove that employees or technical systems comply with the policy.
  • Policy Coverage $\neq$ Operationalization: Having a policy document registered in the library does not mean its statements are operationalized into controls, risks, or evidence.
  • Adoption $\neq$ Compliance: Adopting a certified template from Policy Packs copies baseline language into your tenant; it does not establish compliance with the underlying regulation.
  • Attestation $\neq$ Control Effectiveness: Achieving 100% employee attestation proves document distribution and signature acknowledgment; it does not prove operational control effectiveness.
  • Exception Approved $\neq$ Policy Satisfied: Approving an exception documents formal tolerance for non-adherence; it does not make the organization compliant with the exempted obligation.

6. Where to Learn More

OrviQ Enterprise Governance, Risk & Compliance Platform