Skip to content

Incidents & Loss Events

Where to find it: Incidents & Loss Events, then Incidents (/incidents).

This domain governs material business, operational, technology, security, compliance, third-party, conduct, fraud and privacy incidents and the losses that may follow them.


The invariant distinctions

Seven things are frequently treated as one. OrviQ keeps them separate.

Incident occurrence is not financial loss, is not risk realisation, is not a finding, is not an action, is not control failure, is not regulatory reportability, is not incident closure.

DistinctionWhy it matters
Occurrence is not lossA severe outage may cause no loss; a loss may crystallise months later through a third-party claim or forensic accounting. Loss is never inferred from severity
Occurrence is not risk realisationAn incident may involve realised risks, but it is not a risk register record. It links to canonical risks
Occurrence is not a findingAn incident is an operational event; findings are deficiencies identified during investigation, created by explicit human action
Occurrence is not an actionRemediation commitments are governed action plans with owners and dates
Occurrence is not control failureControls may have operated exactly as designed. Detective controls firing correctly is a control success inside an incident
Occurrence is not reportabilityRegulatory reporting is governed by materiality thresholds, jurisdictions and statutory deadlines — not by severity
Closure is not finding or action closureClosing an incident does not auto-close its findings or actions, and closing those does not close the incident

Articles

ArticleWhat it covers
Incident RegisterThe register, fields, severity, categories and deep links
ClassificationCategory, severity, impact and regulatory reportability
Investigation & Root CauseNarrative, timeline, root cause and contributing factors
Loss EventsThe financial ledger, currency handling and net loss
Closure GovernanceThe state machine, review approval and the immutable snapshot

The lifecycle

The state machine is enforced on the backend across every entry point. Direct bypasses — draft straight to closed, triage straight to closed — are rejected. closed and cancelled are terminal.

Transitioning to closed requires governed review approval. It cannot be set directly.


Categories

CategoryCovers
operationalProcess and operational disruption
cyber_technologySecurity and technology events
fraud_financial_crimeInternal and external fraud
compliance_regulatoryRegulatory breaches
privacy_data_protectionPersonal data events
third_partyProvider-originated events
conduct_marketConduct and market events

Entitlement and permissions

Requires the incident_management entitlement.

PermissionGrants
incident.readView the register, loss assessments, investigations and remediation status
incident.manageReport, triage and update details, classifications and impact
incident.investigateRecord investigation narratives, root causes and contributing factors
incident.reviewGoverned review, sign-off and closure
incident.ai_assistGenerate advisory drafts and hypotheses

OrviQ Enterprise Governance, Risk & Compliance Platform