Compliance & AI Governance Glossary
Plain-language, vendor-neutral definitions of the terms that come up across security, privacy, and AI-governance programs. Browse the full list below, or jump straight to a definition.
16 terms · Last updated 2026-06-07
All glossary terms
AI Compliance
AI compliance is the practice of ensuring artificial-intelligence systems meet applicable legal, regulatory, and ethical requirements throughout their lifecycle.
Read definition →Audit Readiness
Audit readiness is the state of having controls implemented and evidence organized so that an organization can enter a compliance audit with confidence and minimal last-minute work.
Read definition →Continuous Compliance
Continuous compliance is the practice of monitoring controls and collecting evidence on an ongoing basis, so an organization remains audit-ready at all times rather than only before an audit.
Read definition →Control Mapping
Control mapping is the practice of linking a single control to the multiple framework requirements it satisfies, so that one piece of evidence can support several frameworks at once.
Read definition →DPIA
A Data Protection Impact Assessment (DPIA) is a structured process for identifying and minimizing the data-protection risks of a project or processing activity.
Read definition →EU AI Act
The EU AI Act is the European Union's regulation for artificial intelligence, applying tiered obligations to AI systems according to the level of risk they pose.
Read definition →Evidence Collection
Evidence collection is the process of gathering proof that compliance controls are designed and operating effectively, for use in audits and attestations.
Read definition →GDPR
The General Data Protection Regulation (GDPR) is the European Union law governing the processing of personal data, granting individuals rights over their data and imposing accountability obligations on organizations.
Read definition →GRC
GRC stands for Governance, Risk, and Compliance — an integrated approach to aligning an organization's strategy, risk management, and adherence to regulations and standards.
Read definition →HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a US law that sets standards for protecting sensitive patient health information held by covered entities and their business associates.
Read definition →ISO 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS), specifying requirements for establishing, operating, and continually improving information security.
Read definition →NIST AI RMF
The NIST AI Risk Management Framework is a voluntary US framework that helps organizations identify, assess, and manage risks associated with AI systems.
Read definition →Risk Register
A risk register is a centralized record of an organization's identified risks, capturing their likelihood, impact, ownership, and treatment status.
Read definition →RoPA
A Record of Processing Activities (RoPA) is an inventory of how an organization processes personal data, maintained to demonstrate GDPR accountability.
Read definition →SOC 2
SOC 2 is an auditing standard that evaluates how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
Read definition →Vendor Risk Management
Vendor risk management (VRM) is the process of identifying, assessing, and monitoring the security and compliance risks introduced by third-party suppliers and service providers.
Read definition →