Audit Trail
A chronological record of activity showing who performed an action, what changed, and when the change occurred.
OpenCAPA
Corrective and preventive actions used to address findings and reduce recurrence risk.
OpenControl
A policy, process, or technical safeguard designed to reduce specific risk and meet framework expectations.
OpenControl Owner
The accountable person responsible for implementing, maintaining, and evidencing a control.
OpenEvidence
Artifacts proving that a control is designed and operating as expected within a defined period.
OpenEvidence Completeness
The degree to which required evidence is collected, valid, current, and linked to relevant controls.
OpenFinding
A documented gap, exception, or non-conformity identified during audit or review activities.
OpenFramework Mapping
The process of aligning controls and evidence across multiple standards to reduce duplicate effort.
OpenGRC
Governance, risk, and compliance activities coordinated to align business objectives and controls.
OpenInternal Audit
An audit performed by an internal team to evaluate control effectiveness and readiness before external assessment.
OpenExternal Audit
An audit performed by an independent assessor to evaluate conformance against defined standards.
OpenISO 27001
An information security management system standard focused on risk-based control governance.
OpenISO 27701
A privacy information management extension to ISO security controls and governance models.
OpenISO 42001
A framework for AI management system governance and accountability practices.
OpenNIST CSF 2.0
A cybersecurity framework organized by outcomes such as identify, protect, detect, respond, and recover.
OpenSOC 2
A controls-based assurance model focused on trust principles and operational reliability.
OpenRisk Register
A structured list of risks, owners, treatment plans, status, and review cadence.
OpenRisk Heatmap
A visual matrix showing risk severity based on impact and likelihood dimensions.
OpenRemediation
Actions taken to correct identified gaps and restore expected control effectiveness.
OpenSLA
Service level agreement targets for response, review, closure, or approval timelines.
OpenSingle Pane Oversight
A consolidated view of audits, findings, evidence health, and remediation progress.
OpenStatement of Applicability
A document explaining which controls are applicable, excluded, and how decisions are justified.
OpenWorkflow State Transition
Movement from one audit stage to another with defined approvals and validation conditions.
OpenReviewer
A role responsible for evaluating submitted artifacts and confirming quality and completeness.
OpenApproval Log
A record of approval decisions including approver identity, decision, and supporting notes.
OpenProgram Governance
The operating model that defines ownership, review cadence, approvals, and escalation pathways.
OpenReadiness Score
A summarized indicator showing progress toward defined audit or framework milestones.
OpenControl Testing
Validation activities used to confirm whether a control is operating as intended.
OpenEscalation Path
A predefined sequence of contacts and actions when items exceed SLA or risk thresholds.
OpenEvidence Reuse
Using one validated artifact across multiple mapped requirements where control intent overlaps.
Open