Skip to content

External Standards & Further Reading

OrviQ implements concepts that come from established professional and standards bodies. This page points to authoritative public sources for those concepts.


What these references mean, and do not

External references explain concepts. They do not certify the platform.

Listing a standards body here means OrviQ's documentation uses vocabulary or concepts that body has defined. It does not mean:

  • OrviQ is certified against any standard
  • OrviQ implements every requirement of any standard
  • Using OrviQ makes an organisation compliant with any standard

Compliance is a property of your organisation, evidenced by your controls and your evidence. A platform records and governs that; it does not confer it.


Information security management

ISO/IEC 27001 — Information security management systems. Source of the Statement of Applicability concept, the applicability determination model, and the requirement that exclusions be justified.

Published by the International Organization for Standardization: iso.org

NIST Cybersecurity Framework — Source of widely used control-function vocabulary and the concept of framework-to-framework crosswalks.

Published by the US National Institute of Standards and Technology: nist.gov

NIST SP 800-53 — Control catalogue and control-baseline concepts, and a common target for crosswalk mapping.

csrc.nist.gov


Risk management

ISO 31000 — Risk management principles and guidelines. Source of the inherent and residual risk model, risk treatment options (mitigate, avoid, transfer, accept) and the risk appetite concept.

iso.org

COSO Enterprise Risk Management Framework — Source of the enterprise risk management vocabulary widely used in financial services.

Committee of Sponsoring Organizations of the Treadway Commission: coso.org


Internal control and audit

COSO Internal Control — Integrated Framework — Source of the design-versus-operating-effectiveness distinction that OrviQ models as separate assessment types.

coso.org

IIA International Professional Practices Framework — Source of internal audit terminology: engagement, workpaper, procedure, opinion, and the independence and quality-review requirements OrviQ enforces as segregation of duties.

The Institute of Internal Auditors: theiia.org

Three Lines Model — The IIA's model of first, second and third line responsibilities, which OrviQ implements in findings, action plans and assessment permissions.

theiia.org


Business continuity and operational resilience

ISO 22301 — Business continuity management systems. Source of the RTO, RPO, MTPD and MBCO vocabulary, and the business impact analysis concept.

iso.org

Business Continuity Institute Good Practice Guidelines — Practitioner guidance on exercise types and testing regimes.

thebci.org


Operational risk and loss

Basel Committee on Banking Supervision — Source of the operational risk event categorisation and loss data collection concepts underlying the incident and loss event model, and of the Principles for Operational Resilience.

Bank for International Settlements: bis.org


Third-party and outsourcing risk

Supervisory expectations for outsourcing and third-party arrangements differ by jurisdiction. The concepts OrviQ models — materiality classification, criticality determination, exit planning, concentration risk and the register of arrangements — appear across most regimes, with different thresholds and definitions.

Consult your own supervisor's published requirements. OrviQ's regulatory classification records the framework code and rule version applied, precisely because these definitions vary.


Audit evidence and assurance reporting

ISAE 3402 / SSAE 18 SOC 2 — Service organisation control reporting. Relevant when assessing whether a third party's assurance report covers the service you actually consume.

The distinction between a report existing and its scope covering your engagement is a recurring theme in third-party assessment.


This documentation does not reproduce standard text

OrviQ's documentation describes concepts and uses vocabulary. It does not reproduce the text of any standard.

Where you bring a standard into your OrviQ library, you are responsible for holding the appropriate licence for that content. The platform stores what you load; it does not supply licensed standard text.


OrviQ Enterprise Governance, Risk & Compliance Platform