Compliance vocabulary is unusually precise, and the precision matters. Inherent and residual risk drive different decisions; a nonconformity and an observation carry different obligations; anonymised and pseudonymised data sit on opposite sides of a legal boundary. This glossary defines the terms that appear across governance, controls, audit, privacy and operations.
Governance and risk
Governance
The structures and decision rights that set direction and hold people accountable — who decides, within what limits, and to whom they answer.
Risk appetite
The amount of risk an organisation is willing to accept in pursuit of its objectives, set by leadership.
Risk tolerance
The practical boundary on a specific risk, tighter and more concrete than appetite.
Inherent risk
The exposure before the relevant controls are considered.
Residual risk
The exposure remaining after existing controls operate as designed. Compared against appetite to decide accept or treat.
Risk owner
The business leader with authority over the activity, who accepts residual risk. Not the security team.
Three lines of defence
A model separating operational ownership (first), oversight functions such as risk and compliance (second), and independent internal audit (third).
Statement of Applicability
The ISO 27001 document recording which Annex A controls apply, why, their status, and a justification for every exclusion.
Control owner
The named person accountable for a control operating. Should sit in the business, not in compliance.
Compensating control
An alternative measure used where a required control cannot be implemented, documented with the constraint and its acceptance.
Controls
Preventive control
Stops an unwanted event occurring — access restrictions, input validation, segregation of duties.
Detective control
Identifies that something has happened — logging, monitoring, reconciliation, access reviews.
Corrective control
Restores after an event — backups, incident response, patching.
Design effectiveness
Whether a control is capable of achieving its objective if it operates as described.
Operating effectiveness
Whether the control actually ran, consistently, throughout the period.
Segregation of duties
Ensuring no single person can complete a sensitive process end to end unchecked.
Least privilege
Granting only the access needed to perform a role, and no more.
Toxic combination
A pairing of privileges that is dangerous when held by one person, such as creating a vendor and approving payments to it.
Break-glass access
Emergency elevated access that bypasses normal controls, requiring alerting, time limits and post-use review.
Crypto-agility
The ability to change cryptographic algorithms without re-engineering the systems that use them.
Put the vocabulary to work
GRC Copilot assesses you against any framework, tracks controls and evidence, and produces the artefacts these terms describe.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Audit and assurance
Nonconformity
A failure to meet a requirement. Major indicates a systemic failure and blocks certification; minor is an isolated lapse.
Observation
An audit comment that is not a nonconformity — typically something conforming today but trending toward a problem.
Exception
In a SOC 2 report, an instance where a control did not operate as described. Visible to everyone who reads the report.
Qualified opinion
An auditor's conclusion that controls were not effective in some respect. Commercially significant.
Population completeness
Establishing that a list provided for sampling is genuinely complete. Tested before sampling, because a sample from a filtered population proves nothing.
Reperformance
An auditor independently re-executing a control and comparing results — the strongest form of test evidence.
Walkthrough
Tracing a transaction or process end to end to understand and confirm how a control is designed.
Complementary user entity control
A control the reader of an assurance report must operate for the provider's controls to be effective. An obligation transferred to you.
Carve-out method
Excluding a subservice organisation's controls from your report, so you must obtain their assurance separately. The normal approach.
Bridge letter
Management's unaudited assertion covering the gap between a report period end and today. Not assurance.
Privacy and data protection
Controller
The party that determines the purposes and means of processing personal data.
Processor
A party that processes personal data on a controller's behalf, under instruction.
Lawful basis
The legal ground relied on for a processing purpose. Consent is one option and often the weakest, because it is withdrawable.
DPIA
A data protection impact assessment — required before high-risk processing begins, assessing risk to individuals rather than to the organisation.
ROPA
Records of processing activities: what personal data you hold, why, where, who receives it and for how long. The foundation of a privacy programme.
Data subject request
An individual exercising a right — access, correction, erasure, portability or objection — usually within one month.
Pseudonymisation
Replacing identifiers so data cannot be attributed without additional information. Still personal data.
Anonymisation
Irreversibly preventing identification. Genuinely anonymised data falls outside privacy law; re-identifiable data does not.
Storage limitation
The principle that personal data is kept no longer than necessary. Indefinite retention is a violation, not a neutral default.
Standard contractual clauses
Pre-approved contract terms used to legitimise international transfers. Jurisdiction-specific — EU clauses need a UK addendum for UK exports.
Resilience, security and AI
RTO
Recovery time objective — the target time to restore an activity after disruption.
RPO
Recovery point objective — how much data loss is acceptable, expressed as time. Independent of RTO.
MTPD
Maximum tolerable period of disruption — how long an activity can be down before damage becomes unacceptable.
Business impact analysis
The exercise establishing which activities matter, how quickly consequences escalate, and what they depend on.
Immutable backup
A copy that cannot be modified or deleted before its retention expires, including by an administrator.
Harvest now, decrypt later
Capturing encrypted data today to decrypt once cryptographic capability improves — why long-lived confidential data is a present-day concern.
Prompt injection
Instructions hidden in content an AI system processes, exploiting the fact that instructions and data share one channel.
Shadow IT
Systems adopted without going through procurement or security review. Shadow AI is the current dominant form.
Concentration risk
Multiple suppliers resolving to one underlying dependency, so tiering by vendor hides the real exposure.
Attack surface
The set of points where an unauthorised party could attempt entry — expands with every service, integration and account.
Frequently asked questions
What is the difference between compliance and security?
Compliance proves you meet defined rules; security reduces the chance and impact of an attack. A fully compliant organisation can still carry serious unaddressed risk, because the rules were never the whole risk picture.
Is a framework the same as a regulation?
No. A framework is a structured control set you may adopt voluntarily; a regulation is imposed by law. A voluntary certificate does not discharge a regulatory obligation.
What is the difference between a policy and a standard?
A policy states intent and is approved at a senior level; a standard specifies mandatory technical detail; a procedure describes how to perform a task. Confusing them produces documents nobody can follow.
What does "evidence" mean in an audit?
A dated, attributable artefact produced by a system the performer cannot silently alter — a ticket, an export, minutes. Not an assertion that something happened.
Key takeaways
- Inherent and residual risk answer different questions — record both.
- Major and minor findings carry very different consequences.
- Anonymised data leaves privacy scope; pseudonymised data does not.
- RTO and RPO are independent objectives and should not be collapsed.