Appearance
Risk Manager Playbook
This playbook defines the operational workflows, key workspaces, approval boundaries, and governance principles for Risk Managers (risk_manager) in OrviQ.
1. What This Role Does in OrviQ
The Risk Manager maintains the organization's enterprise risk posture, oversees the Risk and Control Self-Assessment (RCSA) lifecycle, tracks Key Risk Indicators (KRIs), evaluates escalated findings, and governs formal risk acceptance requests.
In OrviQ, risk management is not an isolated spreadsheet activity; it is structurally connected to the internal control layer, compliance obligations, and incident records:
- Risks (
RSK-YYYY-NNNN) link directly to the internal controls (CTRL-XXX) designed to mitigate them. - KRIs (
KRI-YYYY-NNNN) provide quantified telemetry to detect threshold breaches before incidents occur. - Operational incidents (
INC-YYYY-NNNN) feed back into risk assessments to recalibrate inherent and residual ratings.
2. Primary Workspaces
Risk Managers primarily operate across the following modules:
| Workspace | Route | Key Activities |
|---|---|---|
| Enterprise Risk Register | /risks | Maintain enterprise risks, score inherent/residual exposure, and review control linkages. |
| KRI Register | /kris | Track leading risk indicators, monitor threshold breaches, and review data frequencies. |
| RCSA Campaigns | /rcsa | Launch, coordinate, and review department-level Risk and Control Self-Assessments. |
| Findings Register | /findings | Review control deficiencies, audit observations, and scanner findings escalated to risk. |
| Action Plans | /action-plans | Oversee remediation milestones and due dates for high-risk findings. |
| Exceptions & Risk Acceptance | /exceptions, /settings/workflow | Review, challenge, and govern time-bound risk acceptance and policy exceptions. |
| Third-Party Risk (TPRM) | /third-party-risk | Assess vendor risk profiles, engagements, and third-party control posture. |
| Risk Methodology Settings | /settings/risk-methodology | Configure scoring matrices, likelihood/impact criteria, and appetite thresholds. |
3. Typical Operating Workflow
Daily & Weekly Cadence
- Monitor KRI Thresholds: Open Risk Management > KRI Register (
/kris). Review indicators that have entered amber (warning) or red (critical breach) zones. Trigger investigation workflows for breached indicators. - Triage Escalated Findings: In Risk Management > Findings (
/findings), review newly raised deficiencies from automated tests, continuous assurance, or audit fieldwork. Assess whether unmitigated findings warrant inclusion in the Enterprise Risk Register. - Review Incident Escalations: Open Incidents & Loss Events (
/incidents). Check for major incidents or operational losses that challenge current residual risk assumptions.
Monthly & Quarterly Cadence
- Execute RCSA Campaigns: Open Risk Management > RCSA (
/rcsa). Initiate scheduled RCSA cycles targeting operational departments. Monitor submission progress from control owners and business leads. - Evaluate Control Effectiveness Impact: Review control assessment results from
/assess. If a mitigating control fails operating effectiveness testing, recalibrate the residual risk score accordingly. - Risk Acceptance Governance: In Risk Management > Exceptions (
/exceptions) and Approvals Hub (/approvals), evaluate formal risk acceptance requests. Verify business justifications, compensating controls, and hard expiration dates. - Executive & Board Reporting: Prepare enterprise risk heatmaps, top-10 risk profiles, and appetite alignment reports via Reports (
/reports).
4. Approvals & Segregation-of-Duties (SoD) Boundaries
OrviQ enforces strict separation of duties to prevent unscrutinized risk acceptance:
- Dual-Control on High/Critical Risks: Accepting high or critical residual risks requires multi-eye review (e.g., Risk Manager endorsement followed by executive or committee approval in
/approvals). - No Self-Approval of Risk Acceptance: A Risk Manager who authors or sponsors an exception or risk acceptance proposal cannot approve that proposal.
- Deterministic Scoring Enforcement: Residual risk scores are derived deterministically from inherent risk ratings and assessed control effectiveness. Risk scores cannot be manually edited to bypass escalation thresholds.
- Mandatory Expiration: Every approved risk acceptance or exception must have a defined
valid_untildate. The system automatically surfaces expiring exceptions for renewal or closure.
5. What the System Does NOT Imply
Risk Managers must adhere to OrviQ's semantic governance rules:
Semantic Guardrails
- Risk Acceptance $\neq$ Control Effectiveness: Formally accepting a risk acknowledges executive tolerance of an unmitigated condition. It does not remediate the vulnerability, eliminate the hazard, or make the underlying control effective.
- Green KRI $\neq$ Zero Exposure: A KRI operating within normal boundaries indicates that monitored parameters are stable; it does not guarantee the absence of unmeasured or emerging risks.
- Residual Risk Calculation $\neq$ Guaranteed Protection: Mathematical reduction of inherent risk via control mapping is valid only if mitigating controls have verified, active operating effectiveness.
- Exception Approved $\neq$ Compliance: Approving an exception provides internal governance authorization to operate temporarily outside standard; it does not grant statutory immunity or regulatory compliance.