Glossary · Category
Governance & compliance
131 plain-English definitions.
- AI acceptable use policy
- An internal policy defining what employees are and are not allowed to do with AI tools
- AI accountability framework
- A structure that assigns clear responsibility for the outcomes of an organization's AI systems
- AI Act penalties
- The fines, up to tens of millions of euros or a percentage of global revenue, imposed for violating the EU AI Act
- AI audit readiness
- The state of having documentation and controls in place so an organization can pass an AI compliance audit
- AI audit trail
- A recorded, tamper-evident log of AI system inputs, outputs, and decisions used to demonstrate compliance
- AI bias audit
- A formal review checking whether an AI system produces unfair or discriminatory outcomes for particular groups
- AI compliance automation
- Software that helps automatically track and enforce regulatory requirements across AI systems
- AI compliance checklist
- A step-by-step list of requirements a company must satisfy before deploying an AI system in a regulated context
- AI compliance gap analysis
- Comparing current AI practices against regulatory requirements to identify where a company falls short
- AI compliance reporting automation
- Software that automatically generates the documentation regulators require for AI system oversight
- AI compliance risk score
- A quantitative measure of how exposed an organization is to regulatory risk from its AI systems
- AI compliance software
- Tools designed to help organizations track, document, and prove compliance with AI regulations
- AI compliance training for employees
- Educational programs ensuring staff understand their obligations when using AI tools
- AI content moderation policy
- Rules governing what an AI system is permitted to generate or must filter out
- AI data breach notification requirements
- Legal obligations to inform regulators and affected individuals when an AI system's data is compromised
- AI data governance framework
- The rules and processes an organization uses to control how data is collected, stored, and used in AI systems
- AI data leakage prevention
- Controls that stop sensitive company or customer data from being exposed through AI tool usage
- AI data privacy
- Protections and controls ensuring personal or sensitive data processed by AI systems is not exposed or misused
- AI ethics committee
- A cross-functional group tasked with evaluating the ethical implications of proposed AI projects
- AI ethics policy
- An internal document setting out the principles an organization follows when building or buying AI systems
- AI explainability
- The degree to which a model's decisions can be understood and justified in human terms
- AI export control compliance
- Ensuring AI models and technology are not shared with restricted countries or entities in violation of export law
- AI fairness testing
- Evaluating a model's outputs across demographic groups to check for disparate treatment or impact
- AI governance
- The policies, processes, and oversight structures an organization uses to ensure AI systems are used safely, ethically, and in compliance with regulation
- AI governance board
- An internal committee responsible for reviewing and approving AI initiatives for risk and compliance
- AI governance certification for employees
- Formal credentials verifying that staff understand AI governance principles and requirements
- AI governance consulting
- External advisory services that help organizations design and implement AI governance programs
- AI governance framework
- A structured set of principles and controls an organization adopts to manage AI risk across its lifecycle
- AI governance maturity assessment
- Evaluating how developed an organization's AI governance practices are compared to best practice
- AI governance policy checklist
- A practical list of policy elements an organization should have in place to govern AI use
- AI governance roles and responsibilities
- The defined ownership structure specifying who is accountable for each aspect of AI risk and compliance
- AI governance software
- Platforms designed to help organizations track, document, and enforce AI policy compliance at scale
- AI incident response plan
- A documented procedure for detecting, containing, and remediating harm caused by an AI system failure
- AI inventory management
- Maintaining a complete catalog of every AI system and model in use across an organization
- AI liability insurance
- Insurance coverage specifically addressing financial losses caused by AI system failures or errors
- AI model bias mitigation techniques
- Methods used to reduce unfair or discriminatory patterns in a model's outputs
- AI model bias testing tools
- Software used to systematically evaluate whether a model treats different demographic groups fairly
- AI model card template
- A standardized fill-in-the-blank format organizations use to document their models consistently
- AI model documentation template
- A standardized format for recording a model's purpose, training data, and known limitations
- AI model explainability regulation
- Legal requirements mandating that certain automated decisions be explainable to affected individuals
- AI model explainability requirements
- Regulatory mandates that certain AI decisions must be explainable to the people they affect
- AI model lifecycle governance
- Overseeing an AI model's compliance and risk posture from initial development through retirement
- AI model monitoring for compliance
- Continuous tracking of a deployed model's behavior to ensure it remains within regulatory and policy bounds
- AI model provenance
- Documentation tracing where a model came from, how it was trained, and what data it used
- AI model registry
- A centralized system that catalogs every AI model an organization has deployed, along with its metadata and status
- AI model risk assessment
- An evaluation of the potential failure modes and harms a specific AI model could cause before it is deployed
- AI model validation
- Testing a model to confirm it performs as intended before it is approved for production use
- AI output auditability
- The ability to trace and review exactly what an AI system produced and why, after the fact
- AI procurement compliance requirements
- The regulatory and internal policy conditions an AI purchase must satisfy before approval
- AI red teaming
- Deliberately probing an AI system for vulnerabilities, harmful outputs, or security weaknesses before deployment
- AI regulatory compliance tracker
- A tool or system used to monitor an organization's compliance status against multiple applicable AI regulations
- AI regulatory sandbox
- A controlled environment where companies can test AI systems under regulatory supervision before full market release
- AI risk register
- A tracked list of identified AI-related risks, their likelihood, impact, and mitigation status
- AI supply chain risk
- The risk introduced by third-party models, datasets, or components embedded in an AI system
- AI system of record
- The authoritative internal record documenting which AI systems are deployed where and by whom
- AI third-party audit
- An independent external review verifying an AI vendor's or system's compliance and security claims
- AI training data provenance
- Documentation of where the data used to train a model originated and whether it was legally obtained
- AI transparency requirements
- Regulatory or contractual obligations that AI systems disclose how they make decisions and what data they use
- AI vendor compliance certification
- Third-party certifications, such as SOC 2 or ISO 42001, that an AI vendor holds to demonstrate compliance
- AI vendor due diligence
- The investigative process of verifying an AI vendor's claims about security, compliance, and performance before signing a contract
- AI vendor GDPR compliance
- Verifying that an AI vendor's data handling practices satisfy EU data protection law
- AI vendor lock-in risk
- The compliance and business risk created by depending too heavily on a single AI provider's proprietary systems
- AI vendor risk assessment
- The process of evaluating the security, compliance, and reliability risk posed by an external AI provider
- AI vendor security questionnaire
- A standardized set of questions procurement and security teams send AI vendors to assess their risk before purchase
- AI vendor SOC 2 Type II report
- An in-depth independent audit report verifying a vendor's security controls operated effectively over time
- AI whistleblower channel
- A confidential reporting mechanism for employees to flag AI governance or ethics violations
- AI whistleblower protection
- Legal protections for employees who report unsafe or noncompliant AI practices within their organization
- AI whistleblowing hotline
- A confidential channel for employees to report concerns about AI misuse or noncompliance
- algorithmic accountability
- The principle that organizations must be answerable for the decisions their algorithms make
- algorithmic impact assessment
- A formal evaluation of the potential societal or individual harms an AI system could cause
- algorithmic transparency report
- A public or regulatory disclosure explaining how an organization's automated systems make decisions
- automated decision-making regulation
- Laws governing when and how organizations may use algorithms to make decisions that affect individuals
- California AI regulations
- State-level rules in California governing the development and deployment of AI systems
- CCPA AI compliance
- Ensuring AI systems handling California residents' personal data comply with the California Consumer Privacy Act
- Colorado AI Act
- A U.S. state law regulating high-risk AI systems and requiring impact assessments
- consent management AI
- Systems for tracking and honoring user consent regarding how their data is used in AI processing
- cross-border data transfer AI
- Rules governing whether and how data processed by AI systems may move between countries
- data localization requirements
- Legal mandates that certain categories of data must be stored and processed within a specific jurisdiction
- data minimization AI
- The principle of collecting and processing only the data strictly necessary for an AI system to function
- data processing agreement AI
- A legal contract specifying how an AI vendor is permitted to process a customer's data
- data protection impact assessment AI
- A formal evaluation required under privacy law to assess how an AI system affects individuals' data rights
- data residency AI
- The requirement that data processed by an AI system stays within a specific country or region's borders
- data residency compliant AI provider
- An AI vendor able to guarantee that customer data stays within a specified geographic region
- data sovereignty AI
- The principle that data is subject to the laws of the country in which it is collected or stored, a key concern for AI deployments
- data sovereignty vs data residency
- The distinction between where data is physically stored and which country's laws govern it
- data subject access request AI
- A request from an individual to know what personal data an AI system holds and how it was used
- enterprise AI compliance calendar
- A schedule tracking upcoming regulatory deadlines and required compliance actions for AI systems
- enterprise AI compliance dashboard
- A reporting interface showing an organization's real-time compliance status across its AI systems
- enterprise AI data handling policy
- Rules governing how employee and customer data may be used when interacting with AI tools
- enterprise AI ethics review board
- An internal group that evaluates proposed AI projects for ethical concerns before approval
- enterprise AI legal hold
- Preserving AI system logs and outputs as evidence when litigation or investigation is anticipated
- enterprise AI policy compliance monitoring
- Ongoing automated checks that AI usage across the organization stays within approved policy
- enterprise AI policy enforcement
- Technical controls that automatically apply an organization's AI usage rules across all approved tools
- enterprise AI policy template
- A reusable starting document companies adapt to create their own internal AI usage policy
- enterprise AI privacy by design
- Building privacy protections into an AI system's architecture from the outset rather than adding them later
- enterprise AI risk appetite
- The level of AI-related risk an organization's leadership is willing to accept in pursuit of its objectives
- enterprise AI risk taxonomy
- A structured classification system for the different categories of risk an AI system can introduce
- enterprise AI security questionnaire
- A due-diligence document used to evaluate whether an AI vendor's security practices meet a company's standards
- enterprise AI trust center
- A vendor-published page detailing security, compliance, and privacy practices to reassure enterprise buyers
- enterprise data classification AI
- Categorizing company data by sensitivity level to determine which data is safe to use with which AI systems
- EU AI Act compliance
- The set of obligations a company must meet to legally deploy AI systems that touch the EU market
- EU AI Act high-risk system
- An AI application, such as one used in hiring or credit decisions, subject to the strictest obligations under EU law
- GDPR AI compliance
- Ensuring an AI system's handling of personal data meets the EU's General Data Protection Regulation
- generative AI acceptable use policy
- A specific policy defining approved and prohibited uses of generative AI tools within an organization
- generative AI copyright risk
- The legal exposure companies face when AI-generated content potentially infringes existing copyrighted material
- generative AI IP indemnification
- A vendor's contractual promise to cover legal costs if their AI's output infringes someone else's intellectual property
- generative AI legal risk
- The range of legal exposures, from copyright to liability, that come with deploying generative AI
- HIPAA AI healthcare
- The application of HIPAA privacy and security rules to AI tools used in healthcare settings
- HIPAA compliant AI
- An AI system configured and contracted so that it can legally process protected health information
- human oversight requirement
- A regulatory or policy mandate that humans retain meaningful control over AI decision-making
- industry-specific AI regulations
- Sector-specific rules, such as those in finance or healthcare, that impose additional AI compliance requirements
- ISO 27001 AI systems
- Applying the international information security management standard to AI infrastructure and processes
- model deprecation policy
- A vendor's or company's plan for retiring older AI models and migrating users to replacements
- model documentation requirements
- The records a company must keep describing how a model was built, trained, and validated
- model drift monitoring
- Ongoing tracking of whether a deployed model's performance degrades or its behavior changes over time
- model explainability tools
- Software that helps interpret and visualize why a model produced a particular output
- model risk governance committee
- An internal body responsible for overseeing and approving the risk profile of deployed AI models
- model risk management
- The discipline of identifying, measuring, and mitigating the risks that a model behaves incorrectly or unfairly
- model risk management framework
- A structured methodology banks and regulated firms use to identify and control the risks of deploying models
- model risk tiering
- Classifying AI models by their potential impact and risk level to apply proportionate oversight
- PCI DSS AI
- Ensuring AI systems that touch payment card data comply with the Payment Card Industry Data Security Standard
- prompt injection risk
- The security risk that malicious input tricks an AI system into ignoring its instructions or leaking data
- right to explanation
- A legal or regulatory principle giving individuals the right to understand how an automated decision about them was made
- shadow AI detection
- Tools and techniques used to discover unauthorized AI tool usage across an organization's network
- shadow AI risk
- The security, compliance, and data leakage exposure created when employees use unapproved AI tools
- SOC 2 compliance AI vendor
- Verifying that an AI vendor has passed an independent audit of its security controls
- SOC 2 for AI
- Extending the SOC 2 security and compliance audit framework to cover AI systems and data handling
- sovereign AI
- AI infrastructure and models built, hosted, and operated entirely within a nation's own borders and legal control
- Standard Contractual Clauses AI
- Legal templates used to lawfully transfer personal data outside the EU when using AI vendors
- third-party AI risk management
- Managing the risks introduced when a company relies on external AI vendors or models
- whistleblower AI misuse reporting
- Channels and protections for employees reporting concerns about improper AI system use