GRC & AI Governance Glossary
44 terms, defined in plain English by people who work with them daily — no circular definitions, no filler.
The system of policies, processes, and accountability an organization uses to manage the AI it builds and buys — covering inventory, risk assessment, approval, oversight, and monitoring across the AI lifecycle. Standards like ISO 42001 and laws like the EU AI Act are turning it from good practice into a formal requirement.
A structured evaluation of how an AI system affects individuals and society — rights, safety, fairness, livelihood — performed before deployment and revisited as the system changes. ISO 42001 requires it for relevant systems; it's the AI-era sibling of the GDPR's DPIA.
A central register of every AI system an organization builds, buys, or uses inside vendor tools — with each system's purpose, data inputs, owner, and risk tier. It is the foundational artifact of AI governance: both ISO 42001 and the EU AI Act effectively require one.
The documented management system ISO/IEC 42001 certifies: leadership commitment, an AI policy, risk and impact assessments, lifecycle controls, and continual improvement, all applied to an organization's AI systems. It mirrors the structure of an ISO 27001 ISMS, applied to AI.
Systematic unfairness in a model's outputs toward particular groups, usually inherited from training data or proxy variables. Bias assessment is mandatory territory for high-risk systems under the EU AI Act and a named risk category in ISO 42001-aligned assessments.
The contract HIPAA requires between a covered entity and any vendor handling PHI on its behalf, flowing safeguard obligations downstream. SaaS vendors serving healthcare carry direct regulatory liability as business associates — the BAA is where that liability is defined.
The two most common standardized questionnaire formats: the Cloud Security Alliance's CAIQ and Shared Assessments' SIG. Supporting them well matters because they arrive constantly — and mapping them once means every future one starts mostly answered.
The systems that store, process, or transmit payment card data — the scope of PCI DSS compliance. Shrinking the CDE through tokenization and hosted payment fields is the single most effective way to cut PCI cost and risk.
Eighteen prioritized security controls maintained by the Center for Internet Security, split into Implementation Groups (IG1–IG3) by organizational maturity. IG1's 56 safeguards define 'essential cyber hygiene' — the accepted minimum for any organization.
The section of a vendor's SOC 2 report listing the controls the vendor expects you to operate for their attestation to hold — the homework almost nobody reads. Reviewing CUECs is the difference between collecting SOC 2 reports and actually using them.
Verifying controls on an ongoing basis and alerting when one drifts out of compliance, instead of discovering failures at the annual audit. The defining capability of modern compliance platforms.
A defined activity or mechanism that reduces a risk or satisfies a requirement — an access review, an encryption standard, an approval gate. In modern GRC, one control is mapped across every framework it satisfies, so the work is done once and counted everywhere.
The tracked remediation that follows an audit finding, incident root cause, or failed control — with an owner, a deadline, and verification of effectiveness. Auditors judge programs less by whether findings occur than by whether corrective actions close.
NIST CSF's mechanism for progress: score your current state against a target state across the framework's subcategories and let the gap drive the roadmap. Done honestly, it becomes a defensible board-level narrative of security investment.
GDPR's structured risk assessment, required before processing likely to create high risk to individuals — large-scale profiling, sensitive data, systematic monitoring, and much AI processing. It documents the risk, the mitigations, and the decision to proceed.
The European Union's comprehensive AI regulation, in force since 2024 and phasing in through 2027. It bans certain practices, imposes transparency duties on general-purpose models, and places heavy risk-management, documentation, and human-oversight obligations on 'high-risk' AI systems — reaching any provider or deployer serving the EU market.
Gathering the artifacts that prove controls operated: review records, tickets, configurations, logs. Continuous, automated collection is what separates programs that sail through audits from teams reconstructing a year of history in a panic.
The risk introduced by your vendors' vendors — the subprocessors and dependencies one layer removed. For critical vendors, mature programs track key fourth parties, because outages and breaches propagate up the chain.
The umbrella discipline coordinating how an organization is directed (governance), how uncertainty is managed (risk), and how obligations are met (compliance). Modern GRC platforms unify these on one data model so controls, risks, vendors, and evidence connect instead of living in silos.
An EU AI Act classification for AI used in domains like hiring, credit, insurance pricing, education, and essential services. High-risk systems must meet requirements for risk management, data governance, technical documentation, human oversight, and post-market monitoring before and after they reach the market.
The HIPAA rule requiring safeguards for electronic PHI: risk analysis, access management, audit controls, integrity protections, and transmission security. Compliance is demonstrated through documentation and evidence — there is no official certification.
The requirement that consequential AI decisions remain subject to meaningful human control — a person who understands the system, can interpret its output, and can override it. A pillar of the EU AI Act's high-risk requirements and of every credible AI policy.
Inherent risk is exposure before any controls; residual risk is what remains after mitigations. The gap between them is your control environment made visible — and residual risk is what gets compared against risk appetite.
An organization's own periodic, independent review of whether its management system is operating as documented — required by ISO 27001 and ISO 42001 before certification audits, and the mechanism that catches decay between external audits.
The management system ISO 27001 certifies: risk assessment methodology, selected controls, leadership involvement, internal audit, and continual improvement. The auditor certifies that the system managing security works — not a snapshot of technical settings.
The leading international standard for information security management, certifying an organization's ISMS on a three-year cycle with annual surveillance audits. Where SOC 2 dominates the US, ISO 27001 is the passport for European and global enterprise procurement.
The first certifiable international standard for AI management systems, published in 2023. It requires organizations to inventory their AI, assess its risks and impacts, define accountability, and operate lifecycle controls — with certification by accredited audit, on the same model as ISO 27001.
A measurable signal that a risk's likelihood or impact is shifting — overdue access reviews, rising complaint volume, vendor incidents. KRIs with thresholds turn a static risk register into an early-warning system.
The gradual degradation of a model's performance as the real world diverges from its training data. Drift monitoring — tracking output quality against thresholds — is a core post-deployment control in every AI governance framework.
The risk that a model's output is wrong, biased, misused, or misunderstood — and that decisions built on it cause harm or loss. Managing it means assessment before deployment, monitoring for drift after, and human fallback for consequential decisions.
The voluntary framework organizing security programs into six functions — Govern, Identify, Protect, Detect, Respond, Recover. Not certifiable; its value is structuring programs and communicating posture, often alongside SOC 2 or ISO 27001 attestations.
The period a SOC 2 Type II report covers, during which controls must operate consistently and generate evidence. First-time companies usually choose three months — the shortest window that carries weight with buyers.
The Payment Card Industry Data Security Standard: twelve requirements enforced contractually by the card brands on anyone touching cardholder data. Version 4.0 is current, with its future-dated requirements now mandatory.
Individually identifiable health information held or transmitted by HIPAA-covered entities and their business associates. Its electronic form (ePHI) triggers the HIPAA Security Rule's administrative, physical, and technical safeguard requirements.
An attack that manipulates an LLM-based system by smuggling instructions into its input — directly by a user or indirectly through content the system reads. It sits atop modern AI security risk lists and is a standard item in AI-era security questionnaires.
The Article 30 GDPR register of what personal data you process, why, on what lawful basis, with whom it's shared, and how long it's kept. The first document a European regulator requests — and the backbone of an operating privacy program.
The central record of an organization's identified risks — each scored for likelihood and impact, assigned an owner, and tracked through treatment. A register nobody rereads is a prop; a living one is the operating core of enterprise risk management.
The standardized question set (often hundreds of items) buyers send vendors during security review, covering controls, policies, and practices. Answering them from an approved, AI-searchable answer library is one of the fastest-payback automations in GRC.
An attestation report, governed by the AICPA, in which an independent auditor evaluates a service organization's controls against the Trust Services Criteria. The de facto trust credential for B2B SaaS in North America — requested in most enterprise security reviews.
A SOC 2 report attesting that controls not only were suitably designed but operated effectively over a period — typically three to twelve months. Buyers overwhelmingly prefer Type II; Type I (design at a point in time) is mainly a stopgap to unblock deals.
The ISO 27001 document declaring, for every Annex A control, whether it applies to your organization and why. Auditors read it first; a sloppy SoA signals a sloppy ISMS.
A public, self-serve page presenting your certifications, control summaries, subprocessors, and security documents — often behind a lightweight access gate. A good trust center preempts many questionnaires because buyers' security teams check it before sending the spreadsheet.
The five criteria a SOC 2 audit can cover: Security (mandatory), Availability, Confidentiality, Processing Integrity, and Privacy. Scope is chosen per audit — most companies start with Security and add criteria their customers ask about.
Assessing and monitoring the third parties in your stack, tiered by data access and operational criticality. Every major framework requires it, and your customers' questionnaires ask how you do it — third-party risk is your risk with worse visibility.
See Compriska in action
A 30-minute walkthrough of the platform, tailored to your frameworks and industry.
Book a demo