Appearance
Gap Workbench
Where to find it: Policy Governance, then Gap Workbench (/governance/gaps).
The Gap Workbench is OrviQ's dedicated management interface for tracking, prioritizing, and resolving policy coverage deficiencies identified during Policy Assessments or regulatory change events.
Requires the policy_governance entitlement.
Gap Lifecycle States
Every policy gap record tracks an authoritative remediation lifecycle:
| Lifecycle State | Meaning |
|---|---|
open | Initial state; gap identified, awaiting triage, priority scoring, and owner assignment |
in_remediation | Active remediation underway; linked to policy revisions, engineering tasks, or exceptions |
ready_for_validation | Remediation owner reports work complete; pending independent validation before gap closure |
closed | Formally closed after independent validation confirms the deficiency is resolved |
deferred | Remediation temporarily postponed to a future governance cycle (requires documented rationale) |
accepted_risk | Formal risk acceptance recorded in the Enterprise Risk Register (RSK-) |
not_applicable | Documented determination that the underlying requirement is not applicable |
cancelled | Withdrawn or superseded by structural reorganization |
Remediation Strategies
The workbench supports 12 structured remediation pathways:
| Remediation Type | Description | Primary Target Artifact |
|---|---|---|
amend_statement | Update existing policy statement text to close the clause gap | Policy Statement edit in draft PolicyVersion |
add_statement | Draft a new atomic requirement into an existing policy section | New PolicyStatement |
add_section | Introduce an entire thematic section into the policy document | New PolicySection |
create_policy | Author a new corporate policy instrument | New PolicyRecord (draft) |
adopt_template | Adopt a certified template from the Content Library | New adopted PolicyRecord |
standard_procedure | Define standard operating procedures or baseline guides | Standard Operating Procedure document |
create_task | Dispatch an operational task to IT or engineering teams | Action Plan (ACT-YYYY-NNNN) |
link_risk | Associate the gap with an existing or new operational risk | Risk Register entry (RSK-YYYY-NNNN) |
request_exception | Submit a formal, time-bound policy exception | Governed Exception (EXC-YYYY-NNNN) |
mark_na | Formally record an out-of-scope non-applicability determination | Governance Justification |
accepted_risk | Transfer deficiency to formal business risk acceptance | Approved Risk Acceptance record |
no_action | Conclude that no modification is required following review | Reviewer Justification |
Cross-Module Governance Links
Policy gaps do not exist in isolation. The Gap Workbench establishes bi-directional, immutable linkages across platform modules:
- Policy Revisions: Directly opens a draft version of the target policy, carrying the gap context and suggested text.
- Action Plans (
ACT-): Generates trackable engineering milestones assigned to technical owners with explicit SLAs. - Risk Register (
RSK-): Escalate significant compliance gaps to the Enterprise Risk Register, triggering inherent and residual risk evaluations. - Exceptions (
EXC-): Submits a governed, time-bound exception with compensating controls, preventing unapproved non-compliance.
The Closure Rule
Semantic Doctrine: Action Completion != Gap Closure | Gap Closure != Compliance Determination
A core principle of the Gap Workbench is that completing a remediation action does not close the gap:
- When a policy editor drafts an amendment or an IT team finishes an action plan, the gap transitions to
ready_for_validation. - Independent Validation Required: A compliance reviewer holding
policy.reviewmust independently evaluate the work to confirm the deficiency is genuinely resolved before gap closure. - Formal Closure: The reviewer records an immutable closure rationale before the gap moves to
closed. If the remediation is insufficient, the reviewer sends the gap back toin_remediation. - Gap closure does NOT equal compliance determination: Closing an internal policy gap establishes that written policy coverage exists or an operational gap was closed; it does not by itself establish regulatory compliance or replace formal supervisory determination.
Re-Assessment & Validation
When policies are amended to address gaps, the Gap Workbench supports formal Re-Assessment:
- Running a re-assessment links the existing gap to the new Policy Assessment result.
- If the new assessment confirms the expectation is now
addressed, the gap automatically progresses toward validation and closure. - Historical assessment links are preserved forever; re-assessment never overwrites past evaluation snapshots.
Permissions Reference
| Action | Permission Key | Required Role(s) |
|---|---|---|
| View policy gaps, remediation plans, and status | policy.read | All roles |
| Assign gap owners, update remediation plans, request validation | policy.write | Tenant Admin, Compliance Manager, Compliance Officer |
| Validate remediation, accept risk, defer, or close gaps | policy.review | Tenant Admin, Compliance Manager |