Back to blog
GRC Fundamentals

GRC glossary: 50 compliance and security terms defined

Inherent versus residual risk, nonconformity versus observation, anonymised versus pseudonymised - the distinctions that change what you have to do. A reference glossary across governance, controls, audit, privacy and resilience.
GRC Copilot Team
GRC glossary: 50 compliance and security terms defined

Compliance vocabulary is unusually precise, and the precision matters. Inherent and residual risk drive different decisions; a nonconformity and an observation carry different obligations; anonymised and pseudonymised data sit on opposite sides of a legal boundary. This glossary defines the terms that appear across governance, controls, audit, privacy and operations.

Governance and risk

Governance

The structures and decision rights that set direction and hold people accountable — who decides, within what limits, and to whom they answer.

Risk appetite

The amount of risk an organisation is willing to accept in pursuit of its objectives, set by leadership.

Risk tolerance

The practical boundary on a specific risk, tighter and more concrete than appetite.

Inherent risk

The exposure before the relevant controls are considered.

Residual risk

The exposure remaining after existing controls operate as designed. Compared against appetite to decide accept or treat.

Risk owner

The business leader with authority over the activity, who accepts residual risk. Not the security team.

Three lines of defence

A model separating operational ownership (first), oversight functions such as risk and compliance (second), and independent internal audit (third).

Statement of Applicability

The ISO 27001 document recording which Annex A controls apply, why, their status, and a justification for every exclusion.

Control owner

The named person accountable for a control operating. Should sit in the business, not in compliance.

Compensating control

An alternative measure used where a required control cannot be implemented, documented with the constraint and its acceptance.

Controls

Preventive control

Stops an unwanted event occurring — access restrictions, input validation, segregation of duties.

Detective control

Identifies that something has happened — logging, monitoring, reconciliation, access reviews.

Corrective control

Restores after an event — backups, incident response, patching.

Design effectiveness

Whether a control is capable of achieving its objective if it operates as described.

Operating effectiveness

Whether the control actually ran, consistently, throughout the period.

Segregation of duties

Ensuring no single person can complete a sensitive process end to end unchecked.

Least privilege

Granting only the access needed to perform a role, and no more.

Toxic combination

A pairing of privileges that is dangerous when held by one person, such as creating a vendor and approving payments to it.

Break-glass access

Emergency elevated access that bypasses normal controls, requiring alerting, time limits and post-use review.

Crypto-agility

The ability to change cryptographic algorithms without re-engineering the systems that use them.

Put the vocabulary to work

GRC Copilot assesses you against any framework, tracks controls and evidence, and produces the artefacts these terms describe.

Audit and assurance

Nonconformity

A failure to meet a requirement. Major indicates a systemic failure and blocks certification; minor is an isolated lapse.

Observation

An audit comment that is not a nonconformity — typically something conforming today but trending toward a problem.

Exception

In a SOC 2 report, an instance where a control did not operate as described. Visible to everyone who reads the report.

Qualified opinion

An auditor's conclusion that controls were not effective in some respect. Commercially significant.

Population completeness

Establishing that a list provided for sampling is genuinely complete. Tested before sampling, because a sample from a filtered population proves nothing.

Reperformance

An auditor independently re-executing a control and comparing results — the strongest form of test evidence.

Walkthrough

Tracing a transaction or process end to end to understand and confirm how a control is designed.

Complementary user entity control

A control the reader of an assurance report must operate for the provider's controls to be effective. An obligation transferred to you.

Carve-out method

Excluding a subservice organisation's controls from your report, so you must obtain their assurance separately. The normal approach.

Bridge letter

Management's unaudited assertion covering the gap between a report period end and today. Not assurance.

Privacy and data protection

Controller

The party that determines the purposes and means of processing personal data.

Processor

A party that processes personal data on a controller's behalf, under instruction.

Lawful basis

The legal ground relied on for a processing purpose. Consent is one option and often the weakest, because it is withdrawable.

DPIA

A data protection impact assessment — required before high-risk processing begins, assessing risk to individuals rather than to the organisation.

ROPA

Records of processing activities: what personal data you hold, why, where, who receives it and for how long. The foundation of a privacy programme.

Data subject request

An individual exercising a right — access, correction, erasure, portability or objection — usually within one month.

Pseudonymisation

Replacing identifiers so data cannot be attributed without additional information. Still personal data.

Anonymisation

Irreversibly preventing identification. Genuinely anonymised data falls outside privacy law; re-identifiable data does not.

Storage limitation

The principle that personal data is kept no longer than necessary. Indefinite retention is a violation, not a neutral default.

Standard contractual clauses

Pre-approved contract terms used to legitimise international transfers. Jurisdiction-specific — EU clauses need a UK addendum for UK exports.

Resilience, security and AI

RTO

Recovery time objective — the target time to restore an activity after disruption.

RPO

Recovery point objective — how much data loss is acceptable, expressed as time. Independent of RTO.

MTPD

Maximum tolerable period of disruption — how long an activity can be down before damage becomes unacceptable.

Business impact analysis

The exercise establishing which activities matter, how quickly consequences escalate, and what they depend on.

Immutable backup

A copy that cannot be modified or deleted before its retention expires, including by an administrator.

Harvest now, decrypt later

Capturing encrypted data today to decrypt once cryptographic capability improves — why long-lived confidential data is a present-day concern.

Prompt injection

Instructions hidden in content an AI system processes, exploiting the fact that instructions and data share one channel.

Shadow IT

Systems adopted without going through procurement or security review. Shadow AI is the current dominant form.

Concentration risk

Multiple suppliers resolving to one underlying dependency, so tiering by vendor hides the real exposure.

Attack surface

The set of points where an unauthorised party could attempt entry — expands with every service, integration and account.

Frequently asked questions

What is the difference between compliance and security?

Compliance proves you meet defined rules; security reduces the chance and impact of an attack. A fully compliant organisation can still carry serious unaddressed risk, because the rules were never the whole risk picture.

Is a framework the same as a regulation?

No. A framework is a structured control set you may adopt voluntarily; a regulation is imposed by law. A voluntary certificate does not discharge a regulatory obligation.

What is the difference between a policy and a standard?

A policy states intent and is approved at a senior level; a standard specifies mandatory technical detail; a procedure describes how to perform a task. Confusing them produces documents nobody can follow.

What does "evidence" mean in an audit?

A dated, attributable artefact produced by a system the performer cannot silently alter — a ticket, an export, minutes. Not an assertion that something happened.

Key takeaways

  • Inherent and residual risk answer different questions — record both.
  • Major and minor findings carry very different consequences.
  • Anonymised data leaves privacy scope; pseudonymised data does not.
  • RTO and RPO are independent objectives and should not be collapsed.
#glossary #definitions #terminology #grc #reference