Appearance
External Standards & Further Reading
OrviQ implements concepts that come from established professional and standards bodies. This page points to authoritative public sources for those concepts.
What these references mean, and do not
External references explain concepts. They do not certify the platform.
Listing a standards body here means OrviQ's documentation uses vocabulary or concepts that body has defined. It does not mean:
- OrviQ is certified against any standard
- OrviQ implements every requirement of any standard
- Using OrviQ makes an organisation compliant with any standard
Compliance is a property of your organisation, evidenced by your controls and your evidence. A platform records and governs that; it does not confer it.
Information security management
ISO/IEC 27001 — Information security management systems. Source of the Statement of Applicability concept, the applicability determination model, and the requirement that exclusions be justified.
Published by the International Organization for Standardization: iso.org
NIST Cybersecurity Framework — Source of widely used control-function vocabulary and the concept of framework-to-framework crosswalks.
Published by the US National Institute of Standards and Technology: nist.gov
NIST SP 800-53 — Control catalogue and control-baseline concepts, and a common target for crosswalk mapping.
Risk management
ISO 31000 — Risk management principles and guidelines. Source of the inherent and residual risk model, risk treatment options (mitigate, avoid, transfer, accept) and the risk appetite concept.
COSO Enterprise Risk Management Framework — Source of the enterprise risk management vocabulary widely used in financial services.
Committee of Sponsoring Organizations of the Treadway Commission: coso.org
Internal control and audit
COSO Internal Control — Integrated Framework — Source of the design-versus-operating-effectiveness distinction that OrviQ models as separate assessment types.
IIA International Professional Practices Framework — Source of internal audit terminology: engagement, workpaper, procedure, opinion, and the independence and quality-review requirements OrviQ enforces as segregation of duties.
The Institute of Internal Auditors: theiia.org
Three Lines Model — The IIA's model of first, second and third line responsibilities, which OrviQ implements in findings, action plans and assessment permissions.
Business continuity and operational resilience
ISO 22301 — Business continuity management systems. Source of the RTO, RPO, MTPD and MBCO vocabulary, and the business impact analysis concept.
Business Continuity Institute Good Practice Guidelines — Practitioner guidance on exercise types and testing regimes.
Operational risk and loss
Basel Committee on Banking Supervision — Source of the operational risk event categorisation and loss data collection concepts underlying the incident and loss event model, and of the Principles for Operational Resilience.
Bank for International Settlements: bis.org
Third-party and outsourcing risk
Supervisory expectations for outsourcing and third-party arrangements differ by jurisdiction. The concepts OrviQ models — materiality classification, criticality determination, exit planning, concentration risk and the register of arrangements — appear across most regimes, with different thresholds and definitions.
Consult your own supervisor's published requirements. OrviQ's regulatory classification records the framework code and rule version applied, precisely because these definitions vary.
Audit evidence and assurance reporting
ISAE 3402 / SSAE 18 SOC 2 — Service organisation control reporting. Relevant when assessing whether a third party's assurance report covers the service you actually consume.
The distinction between a report existing and its scope covering your engagement is a recurring theme in third-party assessment.
On copyright
This documentation does not reproduce standard text
OrviQ's documentation describes concepts and uses vocabulary. It does not reproduce the text of any standard.
Where you bring a standard into your OrviQ library, you are responsible for holding the appropriate licence for that content. The platform stores what you load; it does not supply licensed standard text.