Skip to content

OrviQ 1.1 Release Notes

Release Date: September 2026
Release Tag: integration/policy-governance-bank-ready
Commit Baseline: d32bcfa403739f2d6bcd8c3782cf6fbd3d4b6ff4

We are pleased to announce the release of OrviQ 1.1, delivering comprehensive Enterprise Policy Governance, the certified Content 2.0 regulatory corpus, operationalization and bi-directional traceability, the self-service Employee Policy Portal, native Security Tool Integrations, and automated Cloud & Identity Discovery.


1. Enterprise Policy Governance & Content 2.0

Authoritative Content 2.0 Corpus

OrviQ 1.1 introduces an institutional-grade governance library designed for regulated financial institutions and global enterprises:

  • 110 Unique Governance Instruments: Covering institutional governance charters, statutory policies, supervisory codes, and board terms of reference (DOC-2026-0001 through DOC-2026-0110).
  • 518 Structured Sections & 1,058 Atomic Statements: Decomposed into granular, single-obligation governance statements for precise mapping and tracking.
  • 25 Pending Substantiation Statements: Identified clauses requiring tenant-specific operational parameterization.
  • 5 Certified Domain Packs (190 total memberships):
    • ORV-PACK-CORE: OrviQ Core Governance Library (103 memberships)
    • ORV-PACK-BANKING: Commercial Banking & Risk Governance Pack (37 memberships)
    • ORV-PACK-SBP: Pakistan / State Bank of Pakistan Governance Pack (38 memberships)
    • ORV-PACK-ISLAMIC: Islamic Banking & Shariah Governance Pack (7 memberships)
    • ORV-PACK-PAYMENTS: Digital Payments & Financial Infrastructure Pack (5 memberships)

Content Library (/governance/packs)

  • Browse, inspect, and adopt certified governance packs into the internal Policy Register via policy_pack.adopt.
  • Decoupled Lifecycle: Adopted policies become tenant-owned records in status draft. Disabling the content_library entitlement prevents new catalog adoptions but preserves all previously adopted policies and operational mappings.
  • Semantic Doctrine: Adopting Content 2.0 governance packs creates internal draft text; Adoption != compliance.

2. Policy Assessments (Upload & Assess)

  • Route: /governance/assessments (permissions: policy_assessment.run, policy_assessment.review).
  • Deterministic Pipeline: Upload legacy policy documents (.pdf, .docx, .txt) or select existing internal versions, extract structured text segments, and compare against immutable target expectation snapshots.
  • Human-in-the-Loop Adjudication: Review candidate alignments by submitting decisions (accept, reject, modify, reopen) that transition stored mapping states (manual, ai_suggested, accepted, rejected).
  • Policy Assessment Lifecycle: Assessments move through canonical states draft $\rightarrow$ extracted $\rightarrow$ in_review $\rightarrow$ completed.
  • Policy Coverage Scoring: Deterministically computes stored results (unassessed, addressed, partially_addressed, missing, not_applicable) and aggregate Policy Coverage %. Coverage measures textual alignment; Coverage != compliance.
  • Immutable Freezing: Completed assessments freeze evaluated snapshots and route identified deficiencies directly to the Gap Workbench.

3. Policy Gap Workbench

  • Route: /governance/gaps (permissions: policy.read, policy.write).
  • Deficiency Lifecycle: Deterministic tracking across 8 lifecycle states (open $\rightarrow$ in_remediation $\rightarrow$ ready_for_validation $\rightarrow$ closed, with branch states deferred, accepted_risk, not_applicable, cancelled).
  • 12 Remediation Pathways: Direct actions including statement amendments, adding sections, drafting new policies, adopting Content 2.0 templates, dispatching engineering action plans (ACT-), linking operational risks (RSK-), or requesting governed exceptions (EXC-).
  • Independent Validation Before Closure: Completing a remediation action transitions a gap to ready_for_validation. Formal gap closure requires independent validation before gap closure; completing a task does not automatically close a deficiency, and Gap closure != compliance determination.

4. Policy Operationalization & Traceability

  • Routes: Global view at /governance/operationalization; scoped view at /governance/policy/:pid/operationalization (permission: policy.operationalize).
  • Atomic Statement Model: Decomposes policies into atomic units (PST-YYYY-NNNN), eliminating coarse document-level assertions.
  • 10 Operational Target Types: Maps statements to Controls (CTL-), Requirements (REQ-), Evidence Expectations, Risks (RSK-), Owners, Scopes/Assets (SCP-/AST-), Tasks (ACT-), Metrics (IND-), Findings (FND-), and Exceptions (EXC-).
  • Operationalization Vocabulary: Formal status derivation (NOT_MAPPED, PARTIALLY_OPERATIONALIZED, OPERATIONALIZED, GAP_IDENTIFIED).
  • Bi-directional Traceability: Full lineage traversing forward from regulations down to telemetry, and reverse from technical observations up to executive policy. Traceability != compliance/effectiveness.

5. Horizon Regulatory & Content Change Impact

  • Route: /governance/change-impact (permissions: change_impact.assess, change_impact.approve).
  • Change Event Intake (CHG-): Ingests regulatory circulars and Content 2.0 version updates.
  • Automated Candidate Discovery: Identifies potentially affected downstream policies, statements, controls, and risks.
  • Maker-Checker Segregation of Duties: Assessor formulates impact determinations (review_required, no_impact, impact_confirmed); independent reviewer approves (assessor_id != reviewer_id).
  • Non-Destructive Triage: Regulatory changes alert and queue reviews; they never silently alter published policy text or downgrade compliance determinations without human governance.

6. Governed Policy Exceptions

  • Route: /governance/exceptions (permissions: exception.create, exception.approve).
  • Time-Bound Deviations (EXC-): Governs temporary deviations with mandatory compensating control evaluations and renewal cadences.
  • Two-Tier Status Model: Distinguishes raw persisted database states (draft, requested, in_review, approved, active, rejected, cancelled, closed) from dynamic derived UI badges (DRAFT, SUBMITTED, UNDER_REVIEW, APPROVED, ACTIVE, DUE_FOR_REVIEW, EXPIRING, EXPIRED, CLOSED, REJECTED, CANCELLED).
  • Non-Satisfaction Invariant: An active policy exception acknowledges an accepted temporary deviation; it never modifies source policy text, never closes policy gaps, and never marks controls effective.

7. Employee Policy Portal ("My Policies")

  • Route: /my-policies (permission: policy.attest).
  • Self-Service Experience: Purpose-built reading surface for staff members to review assigned corporate policies.
  • Version-Pinned Attestation: Employees read and acknowledge the exact published version pinned to their campaign.
  • Reading Verification: Opening a policy logs an immutable opened_at timestamp; opened != acknowledged.
  • First-Class Declinations: Employees may submit Acknowledge or Decline with a mandatory reason note, providing valuable operational feedback to compliance teams.
  • Attestation Doctrine: Attestations provide legal evidence of awareness; Attestation != control effectiveness/compliance.

8. Integration Architecture & Security Tool Telemetry

Integration Catalogue (/integrations/catalogue)

  • Read-only directory providing transparent disclosure of 22 catalogued integrations:
    • 20 Available Integrations: Operational integrations using declared methods in code (including native, push, csv):
      • Security Scanners: Tenable Security Center, Tenable Nessus, Titania Nipper, Qualys VMDR, Prowler
      • Cloud & Infrastructure: Microsoft Entra ID, Microsoft Azure, AWS
      • Collaboration & Notifications: Slack, Microsoft Teams, Email (SMTP), Webhook, In-App Notifications
      • ITSM & Issue Tracking: Jira Software, ServiceNow
      • Identity & Workforce: Okta, Google Workspace
      • Evidence & Document Storage: Google Drive, Microsoft OneDrive, Amazon S3
    • 2 Planned Integrations: Splunk and Microsoft Sentinel (catalogue-only entries in current release; method: push; not operational).
  • Entitlement: integrations_catalogue.

Security Tool Integrations (/integrations/security-tools)

  • Native API collectors and file report parsers (.nessus, Tenable CSV, Titania Nipper XML/CSV/JSON).
  • Maker-checker import confirmation (integration.import / integration.confirm).
  • Entitlement: integrations_security_tools (ships dark when disabled).

Cloud & Identity Discovery (/integrations/discovery)

  • Automated inventory and configuration check ingestion from Microsoft Entra ID, Microsoft Azure, AWS, and Prowler.
  • Entitlement: cloud_discovery (ships dark when disabled).

Scanner & Discovery Provenance into Assets and Findings

  • Discovered Assets (AST-): Discovered hosts and resources flow into the Asset Inventory with sensor ID and discovery timestamps, subject to human review (asset.discovery_review).
  • Scanner Findings (SFN-YYYY-NNNN): Ingested vulnerabilities and configuration deviations create technical scanner findings (SFN-) with immutable scanner metadata (source_scanner, scanner_rule_id, CVSS vectors). Through governed triage and promotion, an SFN is promoted to a formal compliance finding (FND-YYYY-NNNN) for action plan remediation or risk acceptance ($\text{SFN} \longrightarrow \text{governed triage/promotion} \longrightarrow \text{FND}$).

9. Platform Entitlements Summary

Entitlement KeyDescriptionShip-Dark Behavior
policy_governanceCore Policy Register, lifecycle, operationalization, assessments, and gapsStandard navigation gate
content_libraryAccess to Content 2.0 catalog and adoption engineAccess gate; adopted policies remain intact if disabled
content_pack_coreAccess to OrviQ Core Governance LibraryGranular pack gate
content_pack_bankingAccess to Commercial Banking & Risk Governance PackGranular pack gate
integrations_security_toolsNative scanner connections and report importsShips dark when disabled
cloud_discoveryAutomated cloud resource & identity discoveryShips dark when disabled
integrations_catalogueRead-only directory of 22 integrationsEntitlement gated
api_accessAdministrative API keys and inbound/outbound webhooksSettings gate

OrviQ Enterprise Governance, Risk & Compliance Platform