Plain-language definitions
Compliance Glossary
Core terms used across obligations, governance, controls, evidence, monitoring and remediation.
- Accountability
- Responsibility for an outcome and for explaining decisions or performance.
- Assurance
- Independent or objective work that increases confidence in governance, risk management or controls.
- Attestation
- A recorded statement that a person confirms a fact, action, understanding or status.
- Audit trail
- Records that show actions, approvals, changes, dates and users in a process or system.
- Compliance obligation
- A requirement arising from law, regulation, license, permit, contract, standard or internal commitment.
- Control
- An activity designed to prevent, detect or correct a defined failure or risk event.
- Control design
- The documented way a control is expected to address a risk.
- Corrective action
- Work intended to resolve a finding or root cause and prevent recurrence.
- Due diligence
- Proportionate investigation before or during a decision or relationship.
- Evidence
- A record that supports whether an activity, decision or control occurred.
- Exception
- A departure from an expected rule, threshold, process or result.
- Finding
- A documented condition identified through monitoring, review, testing or audit.
- Governance
- Structures and decisions through which direction, accountability and oversight are established.
- Inherent risk
- Exposure considered before the effect of controls.
- Issue owner
- The person accountable for correcting and reporting an identified problem.
- Key risk indicator
- A measure intended to signal changing exposure or emerging problems.
- Monitoring
- Ongoing or recurring observation of activity, indicators, exceptions or deadlines.
- Obligations register
- A controlled record of requirements, applicability, owners, timing, controls and evidence.
- Operating effectiveness
- Whether a control actually operated as designed over a period.
- Policy
- A statement of organizational expectation, rule or principle.
- Procedure
- Instructions describing how work is performed.
- Regulatory change
- A new or modified external requirement that may affect the organization.
- Residual risk
- Exposure remaining after controls and other treatment are considered.
- Risk assessment
- A structured evaluation of possible events, causes, impacts, likelihood and controls.
- Root cause
- An underlying condition that contributed to an issue and should be addressed to reduce recurrence.
- Segregation of duties
- Dividing incompatible tasks so one person cannot complete and conceal a sensitive transaction alone.
- Testing
- Using defined procedures and evidence to evaluate control design or operation.
- Third party
- An external vendor, agent, contractor, partner or service provider relied upon by the organization.
- Three lines model
- A governance concept distinguishing operational ownership, risk/compliance challenge and independent assurance.
- Trigger event
- An event that starts a deadline, review, retention period or control activity.
- Whistleblowing channel
- A route for reporting suspected misconduct or concerns.
- Workpaper
- A record of review or testing procedures, evidence, analysis and conclusions.