Skip to content

Risk Manager Playbook

This playbook defines the operational workflows, key workspaces, approval boundaries, and governance principles for Risk Managers (risk_manager) in OrviQ.


1. What This Role Does in OrviQ

The Risk Manager maintains the organization's enterprise risk posture, oversees the Risk and Control Self-Assessment (RCSA) lifecycle, tracks Key Risk Indicators (KRIs), evaluates escalated findings, and governs formal risk acceptance requests.

In OrviQ, risk management is not an isolated spreadsheet activity; it is structurally connected to the internal control layer, compliance obligations, and incident records:

  • Risks (RSK-YYYY-NNNN) link directly to the internal controls (CTRL-XXX) designed to mitigate them.
  • KRIs (KRI-YYYY-NNNN) provide quantified telemetry to detect threshold breaches before incidents occur.
  • Operational incidents (INC-YYYY-NNNN) feed back into risk assessments to recalibrate inherent and residual ratings.

2. Primary Workspaces

Risk Managers primarily operate across the following modules:

WorkspaceRouteKey Activities
Enterprise Risk Register/risksMaintain enterprise risks, score inherent/residual exposure, and review control linkages.
KRI Register/krisTrack leading risk indicators, monitor threshold breaches, and review data frequencies.
RCSA Campaigns/rcsaLaunch, coordinate, and review department-level Risk and Control Self-Assessments.
Findings Register/findingsReview control deficiencies, audit observations, and scanner findings escalated to risk.
Action Plans/action-plansOversee remediation milestones and due dates for high-risk findings.
Exceptions & Risk Acceptance/exceptions, /settings/workflowReview, challenge, and govern time-bound risk acceptance and policy exceptions.
Third-Party Risk (TPRM)/third-party-riskAssess vendor risk profiles, engagements, and third-party control posture.
Risk Methodology Settings/settings/risk-methodologyConfigure scoring matrices, likelihood/impact criteria, and appetite thresholds.

3. Typical Operating Workflow

Daily & Weekly Cadence

  1. Monitor KRI Thresholds: Open Risk Management > KRI Register (/kris). Review indicators that have entered amber (warning) or red (critical breach) zones. Trigger investigation workflows for breached indicators.
  2. Triage Escalated Findings: In Risk Management > Findings (/findings), review newly raised deficiencies from automated tests, continuous assurance, or audit fieldwork. Assess whether unmitigated findings warrant inclusion in the Enterprise Risk Register.
  3. Review Incident Escalations: Open Incidents & Loss Events (/incidents). Check for major incidents or operational losses that challenge current residual risk assumptions.

Monthly & Quarterly Cadence

  1. Execute RCSA Campaigns: Open Risk Management > RCSA (/rcsa). Initiate scheduled RCSA cycles targeting operational departments. Monitor submission progress from control owners and business leads.
  2. Evaluate Control Effectiveness Impact: Review control assessment results from /assess. If a mitigating control fails operating effectiveness testing, recalibrate the residual risk score accordingly.
  3. Risk Acceptance Governance: In Risk Management > Exceptions (/exceptions) and Approvals Hub (/approvals), evaluate formal risk acceptance requests. Verify business justifications, compensating controls, and hard expiration dates.
  4. Executive & Board Reporting: Prepare enterprise risk heatmaps, top-10 risk profiles, and appetite alignment reports via Reports (/reports).

4. Approvals & Segregation-of-Duties (SoD) Boundaries

OrviQ enforces strict separation of duties to prevent unscrutinized risk acceptance:

  • Dual-Control on High/Critical Risks: Accepting high or critical residual risks requires multi-eye review (e.g., Risk Manager endorsement followed by executive or committee approval in /approvals).
  • No Self-Approval of Risk Acceptance: A Risk Manager who authors or sponsors an exception or risk acceptance proposal cannot approve that proposal.
  • Deterministic Scoring Enforcement: Residual risk scores are derived deterministically from inherent risk ratings and assessed control effectiveness. Risk scores cannot be manually edited to bypass escalation thresholds.
  • Mandatory Expiration: Every approved risk acceptance or exception must have a defined valid_until date. The system automatically surfaces expiring exceptions for renewal or closure.

5. What the System Does NOT Imply

Risk Managers must adhere to OrviQ's semantic governance rules:

Semantic Guardrails

  • Risk Acceptance $\neq$ Control Effectiveness: Formally accepting a risk acknowledges executive tolerance of an unmitigated condition. It does not remediate the vulnerability, eliminate the hazard, or make the underlying control effective.
  • Green KRI $\neq$ Zero Exposure: A KRI operating within normal boundaries indicates that monitored parameters are stable; it does not guarantee the absence of unmeasured or emerging risks.
  • Residual Risk Calculation $\neq$ Guaranteed Protection: Mathematical reduction of inherent risk via control mapping is valid only if mitigating controls have verified, active operating effectiveness.
  • Exception Approved $\neq$ Compliance: Approving an exception provides internal governance authorization to operate temporarily outside standard; it does not grant statutory immunity or regulatory compliance.

6. Where to Learn More

OrviQ Enterprise Governance, Risk & Compliance Platform