Skip to content

Cross-Module Journeys

Individual module documentation tells you what each register does. These articles show what happens when a real situation moves through several of them.

Each journey is a single worked example, followed end to end, with the records that get created at each step and the decisions that get made.


The journeys

JourneyStarts withEnds with
Regulation to ComplianceA regulator publishesA governed compliance determination
Framework Adoption to SoAA decision to adopt a standardA Statement of Applicability for an assessor
Control Failure to RemediationAn indicator failsA verified fix, or an accepted deviation
Incident to RiskSomething goes wrongA closed incident and an updated risk position
Audit JourneyAn audit planA signed opinion and validated finding closure
Third-Party OnboardingA proposed supplier arrangementAn approved engagement under lifecycle governance

What these examples are

The organisations, records and figures are fictional, constructed to illustrate the platform. They use realistic enterprise situations — a bank adopting a standard, a regulator publishing a circular, a payments incident — because those are the situations the platform is built for.

Where a journey references a specific standard's structure, it is labelled as an illustrative example rather than a claim about that standard.


The pattern they all share

Every journey shows the same underlying discipline:

  1. Something happens — externally, or in the control environment
  2. A person decides what it means — the platform surfaces, it does not conclude
  3. Governed records are created with owners, dates and references
  4. Approval routes through the organisational workflow layer with segregation of duties
  5. The position updates truthfully, including where the truthful position is "we do not know"
  6. The whole chain remains reconstructable afterwards

If you read only one, read Regulation to Compliance — it traverses the most modules.


OrviQ Enterprise Governance, Risk & Compliance Platform