Appearance
Policy Governance
Where to find it: Policy Governance (/governance).
Policies are how an organisation tells its people what is required. Policy governance is how it proves the policy exists, is current, was approved by someone entitled to approve it, and has been acknowledged by the people it binds.
The workspace
| Page | Route | Purpose |
|---|---|---|
| Policy Overview | /governance | Dashboard of the policy estate, review cadence, and operationalization posture |
| Policy Library | /governance/library | Internal policy register, version histories, redline comparisons, and exports |
| Content Library | /governance/packs | Authoritative Content 2.0 catalog: 110 certified governance instruments and 5 domain packs |
| Policy Assessments | /governance/assessments | Upload & Assess engine: structural extraction, target expectation snapshots, and coverage evaluation |
| Gap Workbench | /governance/gaps | Unified deficiency triage, remediation planning, and multi-module validation |
| Operationalization | /governance/operationalization | Statement-level mapping to controls, risks, owners, evidence expectations, and scopes |
| Change Impact | /governance/change-impact | Horizon change events, automated candidate generation, and maker-checker impact assessments |
| Policy Exceptions | /governance/exceptions | Time-bound, governed deviation register with compensating control evaluations |
| Expiry Monitor | /governance/expiry | Automated tracking of approaching and overdue periodic review milestones |
| Policy Comparison | /governance/compare | Deterministic structural comparison between policy versions |
| Employee Portal | /my-policies | Self-service employee attestation portal for version-pinned acknowledgement |
Articles
| Article | What it covers |
|---|---|
| Policy Register | Fields, statuses, versions, ownership, sections, and atomic statements |
| Content Library | The 110 certified governance instruments, pack memberships, and decoupled adoption |
| Policy Assessments | Upload & Assess workflow, segment extraction, and coverage determination |
| Gap Workbench | 12 remediation pathways, lifecycle states, and independent closure validation |
| Operationalization | Atomic statements, 10 target types, forward/reverse traceability, and invariants |
| Change Impact | Change events (CHG-), candidate triage, and maker-checker impact assessments (IMP-) |
| Policy Exceptions | Governed deviations (EXC-), raw vs derived labels, and compensating controls |
| Policy Lifecycle | Draft to published to revision, review dates, and renewal |
| Review and Publication | Governed multi-eye approval chains, redline reviews, and publication locking |
| Policy Attestation | Administrative campaign orchestration, target groups, and progress monitoring |
| Employee Portal | Self-service /my-policies experience, reading verification, and reasoned declines |
Where policy sits in the platform
Semantic Doctrine
Semantic Doctrine: Policy Governance
Enterprise compliance in OrviQ enforces strict separation between written policy documentation and operational assurance:
- Mapping != compliance: Linking a policy clause to a regulatory standard demonstrates structural intent; it does not certify operational compliance.
- Adoption != compliance: Adopting Content 2.0 governance packs instantiates draft internal policies; it does not prove adherence.
- Published != compliant: Having an approved, published policy establishes that an internal rule exists; it does not prove personnel or systems comply with it.
- Attestation != effectiveness/compliance: An employee signing an attestation confirms document acknowledgement; it does not prove operational control effectiveness.
- Traceability != compliance/effectiveness: Complete bi-directional traceability demonstrates governance architecture; control effectiveness requires testing, indicator evaluation, and evidence.
- Evidence != effectiveness: Having observation records demonstrates telemetry; operating effectiveness is established only through indicator thresholds and human verification.
Entitlements
- Policy Governance (
policy_governance): Core corporate policy authoring, atomic statements, review, approval, operationalization, assessments, and lifecycle tracking. - Content Library (
content_library): Access to browse and adopt certified Content 2.0 governance packs and templates into the tenant.
Permissions Reference
| Permission Key | Functional Scope | Primary Roles |
|---|---|---|
policy.read | View policies, sections, statements, gaps, and dashboards | All roles |
policy.write | Create, edit, and revise policies; manage attestation campaigns | Tenant Admin, Compliance Manager, Compliance Officer |
policy.review | Approve policy revisions, record periodic reviews, validate gaps | Tenant Admin, Compliance Manager |
policy.operationalize | Map atomic statements to controls, risks, owners, evidence expectations | Tenant Admin, Compliance Manager, Compliance Officer |
policy.attest | Access /my-policies and acknowledge assigned policies | All platform users |
policy_pack.read | Browse Content 2.0 packs, versions, and adoptions | All compliance roles, Auditor |
policy_pack.adopt | Adopt certified governance packs into tenant policies | Tenant Admin, Compliance Manager, Compliance Officer |
policy_assessment.run | Create policy assessments, upload documents, run extraction | Tenant Admin, Compliance Manager, Compliance Officer |
policy_assessment.review | Accept/reject mappings, assign coverage results, complete assessments | Tenant Admin, Compliance Manager |
change_impact.assess | Assess change events, candidate impact, and propose remediation | Tenant Admin, Compliance Manager, Compliance Officer |
change_impact.approve | Approve impact assessments and close change events (Maker-Checker) | Tenant Admin, Compliance Manager |
exception.create | Request time-bound policy exceptions | All operational roles |
exception.approve | Formally approve policy exceptions (Maker-Checker) | Tenant Admin, Compliance Manager |
Who works here
| Role | Typical work |
|---|---|
| Policy owner | Drafting, revising, submitting for approval |
| Compliance Manager | Reviewing and approving publication |
| Executive or CCO | Sign-off on the six-eye chain |
| Every employee | Attesting to policies addressed to them |
| Internal Auditor | Testing policy currency, approval and attestation coverage |
Related domains
- Regulatory & Compliance — the obligations policies address
- Controls & Assurance — the controls policies mandate
- Enterprise Workflow — the approval chains