GRC & AI Governance Glossary

44 terms, defined in plain English by people who work with them daily — no circular definitions, no filler.

AI Governance

The system of policies, processes, and accountability an organization uses to manage the AI it builds and buys — covering inventory, risk assessment, approval, oversight, and monitoring across the AI lifecycle. Standards like ISO 42001 and laws like the EU AI Act are turning it from good practice into a formal requirement.

AI Impact Assessment

A structured evaluation of how an AI system affects individuals and society — rights, safety, fairness, livelihood — performed before deployment and revisited as the system changes. ISO 42001 requires it for relevant systems; it's the AI-era sibling of the GDPR's DPIA.

AI Inventory

A central register of every AI system an organization builds, buys, or uses inside vendor tools — with each system's purpose, data inputs, owner, and risk tier. It is the foundational artifact of AI governance: both ISO 42001 and the EU AI Act effectively require one.

AI Management System (AIMS)

The documented management system ISO/IEC 42001 certifies: leadership commitment, an AI policy, risk and impact assessments, lifecycle controls, and continual improvement, all applied to an organization's AI systems. It mirrors the structure of an ISO 27001 ISMS, applied to AI.

Algorithmic Bias

Systematic unfairness in a model's outputs toward particular groups, usually inherited from training data or proxy variables. Bias assessment is mandatory territory for high-risk systems under the EU AI Act and a named risk category in ISO 42001-aligned assessments.

Business Associate Agreement (BAA)

The contract HIPAA requires between a covered entity and any vendor handling PHI on its behalf, flowing safeguard obligations downstream. SaaS vendors serving healthcare carry direct regulatory liability as business associates — the BAA is where that liability is defined.

CAIQ & SIG

The two most common standardized questionnaire formats: the Cloud Security Alliance's CAIQ and Shared Assessments' SIG. Supporting them well matters because they arrive constantly — and mapping them once means every future one starts mostly answered.

Cardholder Data Environment (CDE)

The systems that store, process, or transmit payment card data — the scope of PCI DSS compliance. Shrinking the CDE through tokenization and hosted payment fields is the single most effective way to cut PCI cost and risk.

CIS Controls

Eighteen prioritized security controls maintained by the Center for Internet Security, split into Implementation Groups (IG1–IG3) by organizational maturity. IG1's 56 safeguards define 'essential cyber hygiene' — the accepted minimum for any organization.

Complementary User Entity Controls (CUECs)

The section of a vendor's SOC 2 report listing the controls the vendor expects you to operate for their attestation to hold — the homework almost nobody reads. Reviewing CUECs is the difference between collecting SOC 2 reports and actually using them.

Continuous Control Monitoring

Verifying controls on an ongoing basis and alerting when one drifts out of compliance, instead of discovering failures at the annual audit. The defining capability of modern compliance platforms.

Control

A defined activity or mechanism that reduces a risk or satisfies a requirement — an access review, an encryption standard, an approval gate. In modern GRC, one control is mapped across every framework it satisfies, so the work is done once and counted everywhere.

Corrective Action (CAPA)

The tracked remediation that follows an audit finding, incident root cause, or failed control — with an owner, a deadline, and verification of effectiveness. Auditors judge programs less by whether findings occur than by whether corrective actions close.

CSF Profile

NIST CSF's mechanism for progress: score your current state against a target state across the framework's subcategories and let the gap drive the roadmap. Done honestly, it becomes a defensible board-level narrative of security investment.

DPIA (Data Protection Impact Assessment)

GDPR's structured risk assessment, required before processing likely to create high risk to individuals — large-scale profiling, sensitive data, systematic monitoring, and much AI processing. It documents the risk, the mitigations, and the decision to proceed.

EU AI Act

The European Union's comprehensive AI regulation, in force since 2024 and phasing in through 2027. It bans certain practices, imposes transparency duties on general-purpose models, and places heavy risk-management, documentation, and human-oversight obligations on 'high-risk' AI systems — reaching any provider or deployer serving the EU market.

Evidence Collection

Gathering the artifacts that prove controls operated: review records, tickets, configurations, logs. Continuous, automated collection is what separates programs that sail through audits from teams reconstructing a year of history in a panic.

Fourth-Party Risk

The risk introduced by your vendors' vendors — the subprocessors and dependencies one layer removed. For critical vendors, mature programs track key fourth parties, because outages and breaches propagate up the chain.

GRC (Governance, Risk & Compliance)

The umbrella discipline coordinating how an organization is directed (governance), how uncertainty is managed (risk), and how obligations are met (compliance). Modern GRC platforms unify these on one data model so controls, risks, vendors, and evidence connect instead of living in silos.

High-Risk AI System

An EU AI Act classification for AI used in domains like hiring, credit, insurance pricing, education, and essential services. High-risk systems must meet requirements for risk management, data governance, technical documentation, human oversight, and post-market monitoring before and after they reach the market.

HIPAA Security Rule

The HIPAA rule requiring safeguards for electronic PHI: risk analysis, access management, audit controls, integrity protections, and transmission security. Compliance is demonstrated through documentation and evidence — there is no official certification.

Human Oversight

The requirement that consequential AI decisions remain subject to meaningful human control — a person who understands the system, can interpret its output, and can override it. A pillar of the EU AI Act's high-risk requirements and of every credible AI policy.

Inherent vs. Residual Risk

Inherent risk is exposure before any controls; residual risk is what remains after mitigations. The gap between them is your control environment made visible — and residual risk is what gets compared against risk appetite.

Internal Audit

An organization's own periodic, independent review of whether its management system is operating as documented — required by ISO 27001 and ISO 42001 before certification audits, and the mechanism that catches decay between external audits.

ISMS (Information Security Management System)

The management system ISO 27001 certifies: risk assessment methodology, selected controls, leadership involvement, internal audit, and continual improvement. The auditor certifies that the system managing security works — not a snapshot of technical settings.

ISO/IEC 27001

The leading international standard for information security management, certifying an organization's ISMS on a three-year cycle with annual surveillance audits. Where SOC 2 dominates the US, ISO 27001 is the passport for European and global enterprise procurement.

ISO/IEC 42001

The first certifiable international standard for AI management systems, published in 2023. It requires organizations to inventory their AI, assess its risks and impacts, define accountability, and operate lifecycle controls — with certification by accredited audit, on the same model as ISO 27001.

Key Risk Indicator (KRI)

A measurable signal that a risk's likelihood or impact is shifting — overdue access reviews, rising complaint volume, vendor incidents. KRIs with thresholds turn a static risk register into an early-warning system.

Model Drift

The gradual degradation of a model's performance as the real world diverges from its training data. Drift monitoring — tracking output quality against thresholds — is a core post-deployment control in every AI governance framework.

Model Risk

The risk that a model's output is wrong, biased, misused, or misunderstood — and that decisions built on it cause harm or loss. Managing it means assessment before deployment, monitoring for drift after, and human fallback for consequential decisions.

NIST Cybersecurity Framework (CSF)

The voluntary framework organizing security programs into six functions — Govern, Identify, Protect, Detect, Respond, Recover. Not certifiable; its value is structuring programs and communicating posture, often alongside SOC 2 or ISO 27001 attestations.

Observation Window

The period a SOC 2 Type II report covers, during which controls must operate consistently and generate evidence. First-time companies usually choose three months — the shortest window that carries weight with buyers.

PCI DSS

The Payment Card Industry Data Security Standard: twelve requirements enforced contractually by the card brands on anyone touching cardholder data. Version 4.0 is current, with its future-dated requirements now mandatory.

PHI (Protected Health Information)

Individually identifiable health information held or transmitted by HIPAA-covered entities and their business associates. Its electronic form (ePHI) triggers the HIPAA Security Rule's administrative, physical, and technical safeguard requirements.

Prompt Injection

An attack that manipulates an LLM-based system by smuggling instructions into its input — directly by a user or indirectly through content the system reads. It sits atop modern AI security risk lists and is a standard item in AI-era security questionnaires.

Records of Processing Activities (RoPA)

The Article 30 GDPR register of what personal data you process, why, on what lawful basis, with whom it's shared, and how long it's kept. The first document a European regulator requests — and the backbone of an operating privacy program.

Risk Register

The central record of an organization's identified risks — each scored for likelihood and impact, assigned an owner, and tracked through treatment. A register nobody rereads is a prop; a living one is the operating core of enterprise risk management.

Security Questionnaire

The standardized question set (often hundreds of items) buyers send vendors during security review, covering controls, policies, and practices. Answering them from an approved, AI-searchable answer library is one of the fastest-payback automations in GRC.

SOC 2

An attestation report, governed by the AICPA, in which an independent auditor evaluates a service organization's controls against the Trust Services Criteria. The de facto trust credential for B2B SaaS in North America — requested in most enterprise security reviews.

SOC 2 Type II

A SOC 2 report attesting that controls not only were suitably designed but operated effectively over a period — typically three to twelve months. Buyers overwhelmingly prefer Type II; Type I (design at a point in time) is mainly a stopgap to unblock deals.

Statement of Applicability (SoA)

The ISO 27001 document declaring, for every Annex A control, whether it applies to your organization and why. Auditors read it first; a sloppy SoA signals a sloppy ISMS.

Trust Center

A public, self-serve page presenting your certifications, control summaries, subprocessors, and security documents — often behind a lightweight access gate. A good trust center preempts many questionnaires because buyers' security teams check it before sending the spreadsheet.

Trust Services Criteria

The five criteria a SOC 2 audit can cover: Security (mandatory), Availability, Confidentiality, Processing Integrity, and Privacy. Scope is chosen per audit — most companies start with Security and add criteria their customers ask about.

Vendor Risk Management (TPRM)

Assessing and monitoring the third parties in your stack, tiered by data access and operational criticality. Every major framework requires it, and your customers' questionnaires ask how you do it — third-party risk is your risk with worse visibility.

See Compriska in action

A 30-minute walkthrough of the platform, tailored to your frameworks and industry.

Book a demo