Appearance
Risk & Remediation
This domain covers what happens when something is not as it should be: identifying it, deciding what to do about it, doing it, and verifying it was done.
In the application it spans the Risk Management navigation domain: Risk Register, KRI Register, RCSA, Findings, Action Plans and Exceptions.
How the pieces relate
Articles
Risk
| Article | What it covers |
|---|---|
| Enterprise Risk Register | The register, connected assurance signals, treatment and lifecycle |
| Risk Methodology | Scoring, appetite, review cadence and the derivation sweep |
| Risk Assessments | RCSA campaigns across controls and owners |
| KRI Register | Key risk indicators, thresholds, measurements and breaches |
| Risk Acceptance | Governed acceptance with maker-checker, expiry and reassessment |
Remediation
| Article | What it covers |
|---|---|
| Findings | The unified findings register across sources, statuses and closure |
| Action Plans | Governed remediation with approval and independent verification |
| Exceptions | Formal, time-bound, approved deviation from a requirement or control |
Two principles that govern the whole domain
Risk stays human-governed
Assurance signals, indicator failures, KRI breaches and exception events inform risk decisions. They never silently overwrite an inherent or residual rating, a treatment decision, an acceptance state, ownership or a risk status.
When telemetry suggests a risk deserves attention, OrviQ raises a "risk review recommended" signal with a full explanation of why — and leaves the decision to a person.
Completion is not closure
Completing a remediation action does not close the finding it serves. Closure requires independent verification, and for audit findings, auditor retest.
The reason is straightforward: the person who fixed something is not the right person to confirm it is fixed.
Who works in this domain
| Role | Typical work |
|---|---|
| Risk Manager | Owning the register, reviewing signals, assessing risk acceptance requests |
| Control owner (Line 1) | Remediating findings, owning and completing action plans |
| Compliance Manager | Reviewing findings, approving exceptions, escalating |
| Internal Auditor | Validating finding closure, retesting remediation |
| Chief Risk Officer | Approving risk acceptance, reviewing appetite breaches |
Entitlements
| Capability | Entitlement |
|---|---|
| Risk register, KRIs, methodology | risk_management |
| RCSA campaigns | control_assurance |
| Findings, action plans, exceptions | compliance_core |
Related domains
- Controls & Assurance — where the signals come from
- Audit & Oversight — independent testing and finding validation
- Incidents & Loss — events that generate findings and risk
- Enterprise Workflow — how approvals route