Skip to content

Loss Events

Every incident carries a financial ledger. Most incidents have a net loss of zero, and recording that honestly is as important as recording the ones that do not.


The ledger

FieldMeaning
Estimated lossInitial or unadjusted exposure estimate
Actual lossVerified realised financial loss
Recovery amountVerified insurance, clawback or other recovery
Net lossDerived
CurrencyThe single currency for this incident

Net loss derivation

Net loss is max(0, (actual loss if greater than zero, otherwise estimated loss) minus recovery amount).

Two properties follow:

  • Actual supersedes estimated. Once a verified figure exists, the estimate stops driving the net.
  • Net loss never goes negative. A recovery exceeding the loss produces zero, not a gain.

Loss is never inferred from severity

A Critical incident with no financial loss records 0.00

Loss is never derived from severity, category, customer count or duration.

A severe outage may cause no financial loss. A minor process error may crystallise a substantial loss months later through a third-party claim or forensic accounting.

Recording an estimated loss because an incident "feels expensive" produces an operational loss dataset that cannot be used for anything.


Timing

Loss frequently materialises long after the incident.

StageTypical ledger state
At reportEstimated loss only, often zero
During investigationEstimated loss refined
At closureActual loss where known; estimate retained where not
Months laterActual loss and recovery updated as claims settle

An incident closed with an estimated loss and no actual figure is a normal and honest state. The alternative — holding incidents open for years awaiting claim settlement — makes closure meaningless.


Currency handling

Each incident carries one currency.

Tenant default. The tenant's reporting currency is configured at platform level and exposed through tenant settings. New incidents inherit it unless specified otherwise. It is validated against ISO 4217 three-letter codes and may only be changed by a user holding settings.manage.

Historical invariance. Changing the tenant reporting currency preserves existing incident currencies. Prior incidents are not silently converted or restated.

No silent conversion

Different currencies are never summed together

If historical records contain mixed currencies, executive metrics isolate calculations per currency and flag that mixed currencies are present.

An aggregate number produced by converting several currencies at an unstated rate on an unstated date is a number nobody can reproduce. OrviQ declines to produce one.

Multi-currency itemised loss sub-ledgers are recorded as a future enhancement; the current model holds one currency per incident.


The frozen ledger

On approved closure, the financial ledger is written into the incident's immutable historical snapshot: actual loss, estimated loss, recovery, net loss and currency, exactly as they stood at closure.

Later updates to the live record do not alter the snapshot. If a claim settles differently a year after closure, both the closure position and the current position are available — which is what an operational loss dataset needs.


Permissions

ActionPermission
View the ledgerincident.read
Record and update loss figuresincident.manage
Change the tenant reporting currencysettings.manage

Example

Four incidents, one quarter.

IncidentSeverityEstimatedActualRecoveryNetCurrency
INC-2026-0014 Payment duplicationHigh0.000.000.000.00USD
INC-2026-0019 Misdirected correspondenceMedium0.000.000.000.00USD
INC-2026-0021 Vendor billing errorLow84,000.0091,340.0091,340.000.00USD
INC-2026-0027 Fraudulent transfersCritical450,000.00512,700.00380,000.00132,700.00USD

Reading the table:

  • The High severity incident had zero loss. All 1,412 duplicates were reversed within the business day.
  • The Low severity incident had the second-largest gross loss and a full recovery. Severity reflected operational impact; the financial exposure was recovered in full from the vendor.
  • Only INC-2026-0027 carries a net loss.

Quarterly net operational loss: 132,700.00 USD, from one of four incidents — and any correlation between severity and loss in this quarter would be coincidental.

A note on INC-2026-0027: it closed with recovery at 380,000.00 while an insurance claim was outstanding. The closure snapshot holds that figure. Four months later the claim settled at 425,000.00 and the live record was updated, giving a current net loss of 87,700.00.

Both numbers are correct for their purpose: 132,700.00 was the position at closure, 87,700.00 is the position now. The snapshot is what makes it possible to say which is which.


Troubleshooting

"Net loss shows zero despite an actual loss." Recovery equals or exceeds the loss. Net loss does not go negative.

"Estimated loss is being ignored." Once actual loss is greater than zero, actual supersedes estimated in the net derivation.

"Executive metrics show a mixed-currency flag." Incidents in the period carry different currencies. Figures are isolated per currency deliberately; no conversion is applied.

"Changing the tenant currency did not restate history." Correct. Historical currencies are preserved.


OrviQ Enterprise Governance, Risk & Compliance Platform