Home / Resources / Glossary

Resource

Glossary

Type: GlossaryValue: Common language

Resources

Plain-language definitions for audit, risk, and compliance operations

Plain-language definitions for audit, governance, risk, and compliance terms used in delivery programs.

Terminology Alignment

Shared language that reduces handoff friction between security, audit, and engineering teams.

Find Resources

Glossary Library

30 results found

Audit Trail

A chronological record of activity showing who performed an action, what changed, and when the change occurred.

Open

CAPA

Corrective and preventive actions used to address findings and reduce recurrence risk.

Open

Control

A policy, process, or technical safeguard designed to reduce specific risk and meet framework expectations.

Open

Control Owner

The accountable person responsible for implementing, maintaining, and evidencing a control.

Open

Evidence

Artifacts proving that a control is designed and operating as expected within a defined period.

Open

Evidence Completeness

The degree to which required evidence is collected, valid, current, and linked to relevant controls.

Open

Finding

A documented gap, exception, or non-conformity identified during audit or review activities.

Open

Framework Mapping

The process of aligning controls and evidence across multiple standards to reduce duplicate effort.

Open

GRC

Governance, risk, and compliance activities coordinated to align business objectives and controls.

Open

Internal Audit

An audit performed by an internal team to evaluate control effectiveness and readiness before external assessment.

Open

External Audit

An audit performed by an independent assessor to evaluate conformance against defined standards.

Open

ISO 27001

An information security management system standard focused on risk-based control governance.

Open

ISO 27701

A privacy information management extension to ISO security controls and governance models.

Open

ISO 42001

A framework for AI management system governance and accountability practices.

Open

NIST CSF 2.0

A cybersecurity framework organized by outcomes such as identify, protect, detect, respond, and recover.

Open

SOC 2

A controls-based assurance model focused on trust principles and operational reliability.

Open

Risk Register

A structured list of risks, owners, treatment plans, status, and review cadence.

Open

Risk Heatmap

A visual matrix showing risk severity based on impact and likelihood dimensions.

Open

Remediation

Actions taken to correct identified gaps and restore expected control effectiveness.

Open

SLA

Service level agreement targets for response, review, closure, or approval timelines.

Open

Single Pane Oversight

A consolidated view of audits, findings, evidence health, and remediation progress.

Open

Statement of Applicability

A document explaining which controls are applicable, excluded, and how decisions are justified.

Open

Workflow State Transition

Movement from one audit stage to another with defined approvals and validation conditions.

Open

Reviewer

A role responsible for evaluating submitted artifacts and confirming quality and completeness.

Open

Approval Log

A record of approval decisions including approver identity, decision, and supporting notes.

Open

Program Governance

The operating model that defines ownership, review cadence, approvals, and escalation pathways.

Open

Readiness Score

A summarized indicator showing progress toward defined audit or framework milestones.

Open

Control Testing

Validation activities used to confirm whether a control is operating as intended.

Open

Escalation Path

A predefined sequence of contacts and actions when items exceed SLA or risk thresholds.

Open

Evidence Reuse

Using one validated artifact across multiple mapped requirements where control intent overlaps.

Open

Authority Snapshot

Shared language that improves audit execution clarity

Terminology alignment removes handoff friction between security, audit, engineering, and external assurance teams.

30+Audit and compliance terms defined
5Term categories mapped to delivery use cases
1Cross-linked path to solutions and modules
0Ambiguous term usage in stakeholder reporting

Map glossary terms to your operating model

Use role-aligned walkthroughs to connect terminology with evidence workflows, CAPA ownership, and reporting standards.

Schedule
Book a Demo