Skip to content

Policy Governance

Where to find it: Policy Governance (/governance).

Policies are how an organisation tells its people what is required. Policy governance is how it proves the policy exists, is current, was approved by someone entitled to approve it, and has been acknowledged by the people it binds.


The workspace

PageRoutePurpose
Policy Overview/governanceDashboard of the policy estate, review cadence, and operationalization posture
Policy Library/governance/libraryInternal policy register, version histories, redline comparisons, and exports
Content Library/governance/packsAuthoritative Content 2.0 catalog: 110 certified governance instruments and 5 domain packs
Policy Assessments/governance/assessmentsUpload & Assess engine: structural extraction, target expectation snapshots, and coverage evaluation
Gap Workbench/governance/gapsUnified deficiency triage, remediation planning, and multi-module validation
Operationalization/governance/operationalizationStatement-level mapping to controls, risks, owners, evidence expectations, and scopes
Change Impact/governance/change-impactHorizon change events, automated candidate generation, and maker-checker impact assessments
Policy Exceptions/governance/exceptionsTime-bound, governed deviation register with compensating control evaluations
Expiry Monitor/governance/expiryAutomated tracking of approaching and overdue periodic review milestones
Policy Comparison/governance/compareDeterministic structural comparison between policy versions
Employee Portal/my-policiesSelf-service employee attestation portal for version-pinned acknowledgement

Articles

ArticleWhat it covers
Policy RegisterFields, statuses, versions, ownership, sections, and atomic statements
Content LibraryThe 110 certified governance instruments, pack memberships, and decoupled adoption
Policy AssessmentsUpload & Assess workflow, segment extraction, and coverage determination
Gap Workbench12 remediation pathways, lifecycle states, and independent closure validation
OperationalizationAtomic statements, 10 target types, forward/reverse traceability, and invariants
Change ImpactChange events (CHG-), candidate triage, and maker-checker impact assessments (IMP-)
Policy ExceptionsGoverned deviations (EXC-), raw vs derived labels, and compensating controls
Policy LifecycleDraft to published to revision, review dates, and renewal
Review and PublicationGoverned multi-eye approval chains, redline reviews, and publication locking
Policy AttestationAdministrative campaign orchestration, target groups, and progress monitoring
Employee PortalSelf-service /my-policies experience, reading verification, and reasoned declines

Where policy sits in the platform


Semantic Doctrine

Semantic Doctrine: Policy Governance

Enterprise compliance in OrviQ enforces strict separation between written policy documentation and operational assurance:

  • Mapping != compliance: Linking a policy clause to a regulatory standard demonstrates structural intent; it does not certify operational compliance.
  • Adoption != compliance: Adopting Content 2.0 governance packs instantiates draft internal policies; it does not prove adherence.
  • Published != compliant: Having an approved, published policy establishes that an internal rule exists; it does not prove personnel or systems comply with it.
  • Attestation != effectiveness/compliance: An employee signing an attestation confirms document acknowledgement; it does not prove operational control effectiveness.
  • Traceability != compliance/effectiveness: Complete bi-directional traceability demonstrates governance architecture; control effectiveness requires testing, indicator evaluation, and evidence.
  • Evidence != effectiveness: Having observation records demonstrates telemetry; operating effectiveness is established only through indicator thresholds and human verification.

Entitlements

  • Policy Governance (policy_governance): Core corporate policy authoring, atomic statements, review, approval, operationalization, assessments, and lifecycle tracking.
  • Content Library (content_library): Access to browse and adopt certified Content 2.0 governance packs and templates into the tenant.

Permissions Reference

Permission KeyFunctional ScopePrimary Roles
policy.readView policies, sections, statements, gaps, and dashboardsAll roles
policy.writeCreate, edit, and revise policies; manage attestation campaignsTenant Admin, Compliance Manager, Compliance Officer
policy.reviewApprove policy revisions, record periodic reviews, validate gapsTenant Admin, Compliance Manager
policy.operationalizeMap atomic statements to controls, risks, owners, evidence expectationsTenant Admin, Compliance Manager, Compliance Officer
policy.attestAccess /my-policies and acknowledge assigned policiesAll platform users
policy_pack.readBrowse Content 2.0 packs, versions, and adoptionsAll compliance roles, Auditor
policy_pack.adoptAdopt certified governance packs into tenant policiesTenant Admin, Compliance Manager, Compliance Officer
policy_assessment.runCreate policy assessments, upload documents, run extractionTenant Admin, Compliance Manager, Compliance Officer
policy_assessment.reviewAccept/reject mappings, assign coverage results, complete assessmentsTenant Admin, Compliance Manager
change_impact.assessAssess change events, candidate impact, and propose remediationTenant Admin, Compliance Manager, Compliance Officer
change_impact.approveApprove impact assessments and close change events (Maker-Checker)Tenant Admin, Compliance Manager
exception.createRequest time-bound policy exceptionsAll operational roles
exception.approveFormally approve policy exceptions (Maker-Checker)Tenant Admin, Compliance Manager

Who works here

RoleTypical work
Policy ownerDrafting, revising, submitting for approval
Compliance ManagerReviewing and approving publication
Executive or CCOSign-off on the six-eye chain
Every employeeAttesting to policies addressed to them
Internal AuditorTesting policy currency, approval and attestation coverage

OrviQ Enterprise Governance, Risk & Compliance Platform