Skip to content

Gap Workbench

Where to find it: Policy Governance, then Gap Workbench (/governance/gaps).

The Gap Workbench is OrviQ's dedicated management interface for tracking, prioritizing, and resolving policy coverage deficiencies identified during Policy Assessments or regulatory change events.

Requires the policy_governance entitlement.


Gap Lifecycle States

Every policy gap record tracks an authoritative remediation lifecycle:

Lifecycle StateMeaning
openInitial state; gap identified, awaiting triage, priority scoring, and owner assignment
in_remediationActive remediation underway; linked to policy revisions, engineering tasks, or exceptions
ready_for_validationRemediation owner reports work complete; pending independent validation before gap closure
closedFormally closed after independent validation confirms the deficiency is resolved
deferredRemediation temporarily postponed to a future governance cycle (requires documented rationale)
accepted_riskFormal risk acceptance recorded in the Enterprise Risk Register (RSK-)
not_applicableDocumented determination that the underlying requirement is not applicable
cancelledWithdrawn or superseded by structural reorganization

Remediation Strategies

The workbench supports 12 structured remediation pathways:

Remediation TypeDescriptionPrimary Target Artifact
amend_statementUpdate existing policy statement text to close the clause gapPolicy Statement edit in draft PolicyVersion
add_statementDraft a new atomic requirement into an existing policy sectionNew PolicyStatement
add_sectionIntroduce an entire thematic section into the policy documentNew PolicySection
create_policyAuthor a new corporate policy instrumentNew PolicyRecord (draft)
adopt_templateAdopt a certified template from the Content LibraryNew adopted PolicyRecord
standard_procedureDefine standard operating procedures or baseline guidesStandard Operating Procedure document
create_taskDispatch an operational task to IT or engineering teamsAction Plan (ACT-YYYY-NNNN)
link_riskAssociate the gap with an existing or new operational riskRisk Register entry (RSK-YYYY-NNNN)
request_exceptionSubmit a formal, time-bound policy exceptionGoverned Exception (EXC-YYYY-NNNN)
mark_naFormally record an out-of-scope non-applicability determinationGovernance Justification
accepted_riskTransfer deficiency to formal business risk acceptanceApproved Risk Acceptance record
no_actionConclude that no modification is required following reviewReviewer Justification

Policy gaps do not exist in isolation. The Gap Workbench establishes bi-directional, immutable linkages across platform modules:

  • Policy Revisions: Directly opens a draft version of the target policy, carrying the gap context and suggested text.
  • Action Plans (ACT-): Generates trackable engineering milestones assigned to technical owners with explicit SLAs.
  • Risk Register (RSK-): Escalate significant compliance gaps to the Enterprise Risk Register, triggering inherent and residual risk evaluations.
  • Exceptions (EXC-): Submits a governed, time-bound exception with compensating controls, preventing unapproved non-compliance.

The Closure Rule

Semantic Doctrine: Action Completion != Gap Closure | Gap Closure != Compliance Determination

A core principle of the Gap Workbench is that completing a remediation action does not close the gap:

  1. When a policy editor drafts an amendment or an IT team finishes an action plan, the gap transitions to ready_for_validation.
  2. Independent Validation Required: A compliance reviewer holding policy.review must independently evaluate the work to confirm the deficiency is genuinely resolved before gap closure.
  3. Formal Closure: The reviewer records an immutable closure rationale before the gap moves to closed. If the remediation is insufficient, the reviewer sends the gap back to in_remediation.
  4. Gap closure does NOT equal compliance determination: Closing an internal policy gap establishes that written policy coverage exists or an operational gap was closed; it does not by itself establish regulatory compliance or replace formal supervisory determination.

Re-Assessment & Validation

When policies are amended to address gaps, the Gap Workbench supports formal Re-Assessment:

  • Running a re-assessment links the existing gap to the new Policy Assessment result.
  • If the new assessment confirms the expectation is now addressed, the gap automatically progresses toward validation and closure.
  • Historical assessment links are preserved forever; re-assessment never overwrites past evaluation snapshots.

Permissions Reference

ActionPermission KeyRequired Role(s)
View policy gaps, remediation plans, and statuspolicy.readAll roles
Assign gap owners, update remediation plans, request validationpolicy.writeTenant Admin, Compliance Manager, Compliance Officer
Validate remediation, accept risk, defer, or close gapspolicy.reviewTenant Admin, Compliance Manager

OrviQ Enterprise Governance, Risk & Compliance Platform