Skip to content

Risk & Remediation

This domain covers what happens when something is not as it should be: identifying it, deciding what to do about it, doing it, and verifying it was done.

In the application it spans the Risk Management navigation domain: Risk Register, KRI Register, RCSA, Findings, Action Plans and Exceptions.


How the pieces relate


Articles

Risk

ArticleWhat it covers
Enterprise Risk RegisterThe register, connected assurance signals, treatment and lifecycle
Risk MethodologyScoring, appetite, review cadence and the derivation sweep
Risk AssessmentsRCSA campaigns across controls and owners
KRI RegisterKey risk indicators, thresholds, measurements and breaches
Risk AcceptanceGoverned acceptance with maker-checker, expiry and reassessment

Remediation

ArticleWhat it covers
FindingsThe unified findings register across sources, statuses and closure
Action PlansGoverned remediation with approval and independent verification
ExceptionsFormal, time-bound, approved deviation from a requirement or control

Two principles that govern the whole domain

Risk stays human-governed

Assurance signals, indicator failures, KRI breaches and exception events inform risk decisions. They never silently overwrite an inherent or residual rating, a treatment decision, an acceptance state, ownership or a risk status.

When telemetry suggests a risk deserves attention, OrviQ raises a "risk review recommended" signal with a full explanation of why — and leaves the decision to a person.

Completion is not closure

Completing a remediation action does not close the finding it serves. Closure requires independent verification, and for audit findings, auditor retest.

The reason is straightforward: the person who fixed something is not the right person to confirm it is fixed.


Who works in this domain

RoleTypical work
Risk ManagerOwning the register, reviewing signals, assessing risk acceptance requests
Control owner (Line 1)Remediating findings, owning and completing action plans
Compliance ManagerReviewing findings, approving exceptions, escalating
Internal AuditorValidating finding closure, retesting remediation
Chief Risk OfficerApproving risk acceptance, reviewing appetite breaches

Entitlements

CapabilityEntitlement
Risk register, KRIs, methodologyrisk_management
RCSA campaignscontrol_assurance
Findings, action plans, exceptionscompliance_core

OrviQ Enterprise Governance, Risk & Compliance Platform