Appearance
Compliance Posture
"Are we compliant?" has no single-number answer that survives scrutiny. This page explains what OrviQ reports instead, and how to present it.
The four populations
Every compliance figure starts by dividing your obligations into four groups. Confusing them is where most compliance reporting goes wrong.
| Population | Meaning | Counts toward compliance? |
|---|---|---|
| Approved Not Applicable | Governed as out of scope, with an approved justification | Excluded from the denominator; never counted as compliant |
| Unresolved applicability | Draft, pending review, rejected or under review | Counted as unresolved; never silently excluded |
| Applicable, assessed | In scope with a determination | Yes — the meaningful population |
| Applicable, unassessed | In scope, no determination reached | Counted as unassessed; not counted as failing |
The first two rows are where dashboards usually lie
Excluding unapproved "Not Applicable" decisions from the denominator would make the fastest route to 100% compliance a bulk edit. Counting approved exclusions as successes would inflate the numerator with obligations nobody ever had to meet.
OrviQ does neither, which is why an OrviQ posture figure is usually lower than the one a spreadsheet produces from the same underlying facts.
Reading a determination figure
For the assessed population, each obligation carries two independent verdicts:
Requirement satisfaction — the objective answer: satisfied, partially_satisfied, not_satisfied, not_assessed.
Governance disposition — the organisation's position: compliant, accepted_deviation, remediation_required, unassessed.
A board pack should report both. Satisfaction alone hides your accepted deviations; disposition alone hides whether the underlying obligations are actually met.
Percentages, and how OrviQ presents them
Where a percentage appears, it is always accompanied by what produced it.
| Bad | What OrviQ shows |
|---|---|
| "87% compliant" | 87% evidence coverage: 104 of 120 in-scope subjects covered, 16 uncovered |
| "Control effective" | Effective: all mandatory indicators passing, 214 of 214 fresh, 100% coverage |
| "92% of controls tested" | 128 effective, 44 partially effective, 11 ineffective, 3 not assessed — no owner |
The last row is the pattern to insist on. "92% tested" and "11 ineffective" are the same dataset, and only one of them tells you what to do on Monday.
Unassessed is not a failure, and not a pass
not_assessed is a first-class answer, displayed distinctly from not_satisfied.
| State | Means | Remedy |
|---|---|---|
not_assessed | We do not know | Map a control, attach evidence, define an indicator |
not_satisfied | We know, and the answer is no | Raise a finding, open an action plan, request an exception |
Presenting these as one amber category loses the distinction between a measurement gap and a control gap, which are different problems with different owners.
The mandatory failure gate in reporting
A control with nine passing indicators and one failing mandatory indicator reports ineffective, not 90%.
This will occasionally produce a headline that feels disproportionate — "three accounts out of 3,318 make the control ineffective". The answer to that objection is to name the three: they are the privileged ones.
Presenting posture to a board
Lead with the population, not the percentage. "Of 264 obligations, 81 are applicable to this scope; 61 are satisfied, 12 partially, 3 not satisfied, 5 unassessed."
Report accepted deviations explicitly. An accepted deviation is a decision the board or its delegate made. It belongs in the report as a decision with an owner and an expiry, not buried in an amber count.
Separate measurement gaps from control gaps. Five unassessed obligations and three failing obligations are different asks.
Show the trend, not the snapshot. A posture figure alone provokes the question "is that good?". A three-quarter trend answers it.
Name what is overdue. Overdue remediation is the most actionable number in any compliance pack, and the one most often aggregated away.
Resist the single-number request
Someone will ask for one number. The useful counter-offer is a four-line summary: applicable, satisfied, accepted deviations, and unassessed. It fits on a slide, and every line is defensible.
Where posture is derived
| View | Shows |
|---|---|
| Compliance Dashboard | Compliance posture across frameworks |
| Requirement Assurance cockpit | The five dimensions per obligation |
| Statement of Applicability | Applicability position and implementation context |
| Portfolio aggregate | Compliance, determination, ownership, attestation, findings, action plans and evidence |
| Compliance Visualizer | Relationships between obligations, controls and evidence |
Permissions
| Action | Permission |
|---|---|
| View dashboards and reports | report.read |
| View compliance status | compliance.read |
| View assurance posture | assurance.read |
| Export | export.data |
Example
A quarterly board summary for one adopted framework.
| Line | Value |
|---|---|
| Obligations in framework | 93 |
| Approved Not Applicable | 12, each with an approved justification |
| Unresolved applicability | 0 |
| Applicable | 81 |
| Satisfied | 61 |
| Partially satisfied | 12 |
| Not satisfied | 3 |
| Not assessed | 5 |
| Accepted deviations in force | 2, expiring in 90 and 140 days |
| Overdue remediation | 1 action plan, 11 days overdue |
What a board can do with this: ask about the three not satisfied, the five not assessed, the two deviations approaching expiry and the one overdue action. Ten obligations out of 93 need attention, and the report says which.
What "87% compliant" would have given them: nothing to act on, and a follow-up question the presenter could not answer.
Troubleshooting
"Our posture figure fell after we cleaned up the register." Common and usually correct. Resolving unapproved exclusions moves obligations back into the applicable population.
"Two views show different numbers." Check the scope and the adoption each is filtered to. Posture is always relative to a declared boundary.
"An obligation with an approved exception shows as not satisfied." Correct. Check its disposition — it reads accepted_deviation. See Compliance Determination.