Skip to content

Compliance Posture

"Are we compliant?" has no single-number answer that survives scrutiny. This page explains what OrviQ reports instead, and how to present it.


The four populations

Every compliance figure starts by dividing your obligations into four groups. Confusing them is where most compliance reporting goes wrong.

PopulationMeaningCounts toward compliance?
Approved Not ApplicableGoverned as out of scope, with an approved justificationExcluded from the denominator; never counted as compliant
Unresolved applicabilityDraft, pending review, rejected or under reviewCounted as unresolved; never silently excluded
Applicable, assessedIn scope with a determinationYes — the meaningful population
Applicable, unassessedIn scope, no determination reachedCounted as unassessed; not counted as failing

The first two rows are where dashboards usually lie

Excluding unapproved "Not Applicable" decisions from the denominator would make the fastest route to 100% compliance a bulk edit. Counting approved exclusions as successes would inflate the numerator with obligations nobody ever had to meet.

OrviQ does neither, which is why an OrviQ posture figure is usually lower than the one a spreadsheet produces from the same underlying facts.


Reading a determination figure

For the assessed population, each obligation carries two independent verdicts:

Requirement satisfaction — the objective answer: satisfied, partially_satisfied, not_satisfied, not_assessed.

Governance disposition — the organisation's position: compliant, accepted_deviation, remediation_required, unassessed.

A board pack should report both. Satisfaction alone hides your accepted deviations; disposition alone hides whether the underlying obligations are actually met.


Percentages, and how OrviQ presents them

Where a percentage appears, it is always accompanied by what produced it.

BadWhat OrviQ shows
"87% compliant"87% evidence coverage: 104 of 120 in-scope subjects covered, 16 uncovered
"Control effective"Effective: all mandatory indicators passing, 214 of 214 fresh, 100% coverage
"92% of controls tested"128 effective, 44 partially effective, 11 ineffective, 3 not assessed — no owner

The last row is the pattern to insist on. "92% tested" and "11 ineffective" are the same dataset, and only one of them tells you what to do on Monday.


Unassessed is not a failure, and not a pass

not_assessed is a first-class answer, displayed distinctly from not_satisfied.

StateMeansRemedy
not_assessedWe do not knowMap a control, attach evidence, define an indicator
not_satisfiedWe know, and the answer is noRaise a finding, open an action plan, request an exception

Presenting these as one amber category loses the distinction between a measurement gap and a control gap, which are different problems with different owners.


The mandatory failure gate in reporting

A control with nine passing indicators and one failing mandatory indicator reports ineffective, not 90%.

This will occasionally produce a headline that feels disproportionate — "three accounts out of 3,318 make the control ineffective". The answer to that objection is to name the three: they are the privileged ones.

See Control Effectiveness.


Presenting posture to a board

Lead with the population, not the percentage. "Of 264 obligations, 81 are applicable to this scope; 61 are satisfied, 12 partially, 3 not satisfied, 5 unassessed."

Report accepted deviations explicitly. An accepted deviation is a decision the board or its delegate made. It belongs in the report as a decision with an owner and an expiry, not buried in an amber count.

Separate measurement gaps from control gaps. Five unassessed obligations and three failing obligations are different asks.

Show the trend, not the snapshot. A posture figure alone provokes the question "is that good?". A three-quarter trend answers it.

Name what is overdue. Overdue remediation is the most actionable number in any compliance pack, and the one most often aggregated away.

Resist the single-number request

Someone will ask for one number. The useful counter-offer is a four-line summary: applicable, satisfied, accepted deviations, and unassessed. It fits on a slide, and every line is defensible.


Where posture is derived

ViewShows
Compliance DashboardCompliance posture across frameworks
Requirement Assurance cockpitThe five dimensions per obligation
Statement of ApplicabilityApplicability position and implementation context
Portfolio aggregateCompliance, determination, ownership, attestation, findings, action plans and evidence
Compliance VisualizerRelationships between obligations, controls and evidence

Permissions

ActionPermission
View dashboards and reportsreport.read
View compliance statuscompliance.read
View assurance postureassurance.read
Exportexport.data

Example

A quarterly board summary for one adopted framework.

LineValue
Obligations in framework93
Approved Not Applicable12, each with an approved justification
Unresolved applicability0
Applicable81
Satisfied61
Partially satisfied12
Not satisfied3
Not assessed5
Accepted deviations in force2, expiring in 90 and 140 days
Overdue remediation1 action plan, 11 days overdue

What a board can do with this: ask about the three not satisfied, the five not assessed, the two deviations approaching expiry and the one overdue action. Ten obligations out of 93 need attention, and the report says which.

What "87% compliant" would have given them: nothing to act on, and a follow-up question the presenter could not answer.


Troubleshooting

"Our posture figure fell after we cleaned up the register." Common and usually correct. Resolving unapproved exclusions moves obligations back into the applicable population.

"Two views show different numbers." Check the scope and the adoption each is filtered to. Posture is always relative to a declared boundary.

"An obligation with an approved exception shows as not satisfied." Correct. Check its disposition — it reads accepted_deviation. See Compliance Determination.


OrviQ Enterprise Governance, Risk & Compliance Platform