Appearance
Incidents & Loss Events
Where to find it: Incidents & Loss Events, then Incidents (/incidents).
This domain governs material business, operational, technology, security, compliance, third-party, conduct, fraud and privacy incidents and the losses that may follow them.
The invariant distinctions
Seven things are frequently treated as one. OrviQ keeps them separate.
Incident occurrence is not financial loss, is not risk realisation, is not a finding, is not an action, is not control failure, is not regulatory reportability, is not incident closure.
| Distinction | Why it matters |
|---|---|
| Occurrence is not loss | A severe outage may cause no loss; a loss may crystallise months later through a third-party claim or forensic accounting. Loss is never inferred from severity |
| Occurrence is not risk realisation | An incident may involve realised risks, but it is not a risk register record. It links to canonical risks |
| Occurrence is not a finding | An incident is an operational event; findings are deficiencies identified during investigation, created by explicit human action |
| Occurrence is not an action | Remediation commitments are governed action plans with owners and dates |
| Occurrence is not control failure | Controls may have operated exactly as designed. Detective controls firing correctly is a control success inside an incident |
| Occurrence is not reportability | Regulatory reporting is governed by materiality thresholds, jurisdictions and statutory deadlines — not by severity |
| Closure is not finding or action closure | Closing an incident does not auto-close its findings or actions, and closing those does not close the incident |
Articles
| Article | What it covers |
|---|---|
| Incident Register | The register, fields, severity, categories and deep links |
| Classification | Category, severity, impact and regulatory reportability |
| Investigation & Root Cause | Narrative, timeline, root cause and contributing factors |
| Loss Events | The financial ledger, currency handling and net loss |
| Closure Governance | The state machine, review approval and the immutable snapshot |
The lifecycle
The state machine is enforced on the backend across every entry point. Direct bypasses — draft straight to closed, triage straight to closed — are rejected. closed and cancelled are terminal.
Transitioning to closed requires governed review approval. It cannot be set directly.
Categories
| Category | Covers |
|---|---|
operational | Process and operational disruption |
cyber_technology | Security and technology events |
fraud_financial_crime | Internal and external fraud |
compliance_regulatory | Regulatory breaches |
privacy_data_protection | Personal data events |
third_party | Provider-originated events |
conduct_market | Conduct and market events |
Entitlement and permissions
Requires the incident_management entitlement.
| Permission | Grants |
|---|---|
incident.read | View the register, loss assessments, investigations and remediation status |
incident.manage | Report, triage and update details, classifications and impact |
incident.investigate | Record investigation narratives, root causes and contributing factors |
incident.review | Governed review, sign-off and closure |
incident.ai_assist | Generate advisory drafts and hypotheses |
Related domains
- Risk & Remediation — findings, actions and risk linkage
- Operational Resilience — when the incident is a disruption
- Third-Party Risk — provider-originated events
- Audit & Oversight — regulatory notification and inspection follow-up