Appearance
Frequently Asked Questions
Compliance position
Why does everything show Not Assessed when we first start?
Because it is true. Adoption creates obligations, not compliance. Determinations move once controls are mapped and evidence is evaluated. See The Requirement Pipeline.
We mapped controls to every requirement. Why hasn't the compliance position changed?
Mapping is a statement of design intention. It says a control is intended to address an obligation — not that the control exists in practice, operates, or works. See Separation Principles.
We uploaded evidence. Why is coverage still zero?
An artefact in the Evidence Register is a document. Coverage counts distinct in-scope subjects with fresh assertions. Record assertions from the artefact, stating what it demonstrates about which subjects.
Our control passes but the requirement is only partially satisfied. Why?
Check coverage. Passing on 40 of 120 in-scope subjects is a real pass on a partial population, and the requirement reflects the whole population.
Why is a control with nine passing indicators and one failure reported as ineffective?
The failing indicator is marked mandatory. A mandatory failure is a gate, not a term in an average. See Control Effectiveness.
Our posture figure fell after we cleaned up the register. Is that a defect?
Usually not. Resolving unapproved "Not Applicable" decisions moves obligations back into the applicable population, which is the correct effect.
Exceptions and acceptance
We approved an exception. Why does the requirement still say Not Satisfied?
That is intentional. Satisfaction stays objectively evaluated; the governance disposition changes to accepted_deviation. An exception is a decision about an unmet obligation, and the obligation stays unmet. See Exceptions.
We set the risk treatment strategy to Accept. Why is the risk still open?
Setting the strategy is planning intent. Governed acceptance requires a request, a justification, an expiry and independent approval. See Risk Acceptance.
An accepted risk reappeared. Why?
Its acceptance expired. Acceptance is time-bound by design; renewal is a decision, not automatic.
Approvals and segregation
Why can't I approve my own work?
Segregation of duties. The maker cannot be the checker, on every governed decision. See Segregation of Duties.
I'm a Tenant Administrator. Why can't I approve a third-party engagement?
tprm.assess, tprm.classify and tprm.decide are never auto-granted, including to administrators. Administering the platform is not the same as exercising governance judgement within it. Assign them deliberately to a role.
Our six-eye chain only seems to involve two people. Why?
One individual holds two consecutive stage roles. The engine blocks the same person acting twice; it cannot know two roles are the same person. Review role assignments against your chain configuration.
I approved something and the business state didn't change.
In a multi-stage chain, only the terminal stage updates the business state. Intermediate approvals advance the stage.
A configuration change didn't affect an approval already in progress.
Correct. Workflow runs complete on the template they started with, so a decision part-way through a chain never silently loses a stage.
AI
Does AI decide anything in OrviQ?
No. AI assists, suggests, extracts, drafts and summarises. Determinations are deterministic computations; approvals are human acts. See AI Principles.
Can I turn AI off and still use the platform?
Yes, entirely. Every governed workflow, register, determination, report and reconstruction works with AI disabled. This is worth verifying during evaluation.
Can I bulk-approve AI proposals above a confidence threshold?
The platform will not stop you approving them individually, but doing so reproduces exactly the problem maker-checker exists to prevent. Confidence expresses pattern-match strength, not correctness. See AI Limitations.
Is our data used to train models?
No. Tenant data is not used to train models, and no cross-tenant data is visible to any AI operation. See Tenant Data Boundaries.
Why did an AI draft state something untrue about our organisation?
The model reads the requirement text; it has no way to know facts about your business. Every factual claim in a draft needs verification. See AI Applicability Rationale.
Evidence and assurance
Coverage dropped but nothing failed. What happened?
Either assertions went stale, a collector run was partial_success, or scope members were added. All three reduce coverage without any observation changing.
A collector succeeds but produces no assertions.
Subject resolution is not matching. The identifiers the source returns must resolve to scope members. This is the most common setup problem in the platform.
Do I need Continuous Assurance to get requirement determinations?
No. Requirement Assurance is part of Compliance Core. Continuous Assurance adds automated telemetry; the five-dimension determination model works on manual evidence and periodic assessment.
Why do stale indicators show Not Assessed rather than Ineffective?
Aged evidence is an information gap, not a control failure. Reporting it as a failure would misattribute a broken data feed to the control.
Findings and remediation
The action plan is complete but the finding is still open.
Closure requires independent verification, and for audit findings, auditor retest. The person who fixed something is not the right person to confirm it is fixed.
A finding reopened after we closed it.
The auditor's retest failed. Their notes explain why. See Audit Findings.
Why do finding statuses differ depending on where the finding came from?
Status vocabularies are per-source and deliberately distinct. RCSA remediating and governed in_remediation are different states in different engines. Use the source-aware filter.
Dates and calendar
An engagement has no review status. Why?
No review date has been set. Reassessment frequency is guidance and is never used to derive a date. A missing date reports none rather than a fabricated signal.
Why don't collector runs appear on the GRC Calendar?
The calendar holds governance obligations people must meet. Technical schedules — collector runs, indicator evaluations, freshness sweeps, report generation — are deliberately excluded.
I got a notification but there's no task.
It was informational. A notification is a nudge; a Workbench task is an obligation. See Notifications.
History and audit
A historical view looks worse than I remember.
Reconstruction shows the records as they stood, including gaps. It does not apply today's evidence to a past date.
A finalised audit report shows outdated control names.
That is the immutable snapshot working. The report shows the environment as it was at the time of the audit.
A mapping shows "Ended, date not recorded". Why not a date?
Its validity end date was never recorded, so it cannot honestly be placed on a timeline. Showing the gap is better than inventing a date.
Can I reconstruct a period before we adopted OrviQ?
No. Reconstruction covers the period from when records were kept in the platform.
Access and visibility
A colleague sees different numbers on the same dashboard.
Dashboard and export visibility follows permissions. Both figures are correct for their access.
A navigation item shows a lock.
The entitlement is off. It is visible for discovery rather than hidden.
A permission I granted has no effect.
Either its entitlement is off, or it is not in the canonical catalogue — grants naming a permission outside the catalogue are dropped.
A workflow stage routes to nobody.
Its role binding names a role no user holds, or the department-head resolver cannot find the owner's organisational unit.