Plain-language definitions

Compliance Glossary

Core terms used across obligations, governance, controls, evidence, monitoring and remediation.

Accountability
Responsibility for an outcome and for explaining decisions or performance.
Assurance
Independent or objective work that increases confidence in governance, risk management or controls.
Attestation
A recorded statement that a person confirms a fact, action, understanding or status.
Audit trail
Records that show actions, approvals, changes, dates and users in a process or system.
Compliance obligation
A requirement arising from law, regulation, license, permit, contract, standard or internal commitment.
Control
An activity designed to prevent, detect or correct a defined failure or risk event.
Control design
The documented way a control is expected to address a risk.
Corrective action
Work intended to resolve a finding or root cause and prevent recurrence.
Due diligence
Proportionate investigation before or during a decision or relationship.
Evidence
A record that supports whether an activity, decision or control occurred.
Exception
A departure from an expected rule, threshold, process or result.
Finding
A documented condition identified through monitoring, review, testing or audit.
Governance
Structures and decisions through which direction, accountability and oversight are established.
Inherent risk
Exposure considered before the effect of controls.
Issue owner
The person accountable for correcting and reporting an identified problem.
Key risk indicator
A measure intended to signal changing exposure or emerging problems.
Monitoring
Ongoing or recurring observation of activity, indicators, exceptions or deadlines.
Obligations register
A controlled record of requirements, applicability, owners, timing, controls and evidence.
Operating effectiveness
Whether a control actually operated as designed over a period.
Policy
A statement of organizational expectation, rule or principle.
Procedure
Instructions describing how work is performed.
Regulatory change
A new or modified external requirement that may affect the organization.
Residual risk
Exposure remaining after controls and other treatment are considered.
Risk assessment
A structured evaluation of possible events, causes, impacts, likelihood and controls.
Root cause
An underlying condition that contributed to an issue and should be addressed to reduce recurrence.
Segregation of duties
Dividing incompatible tasks so one person cannot complete and conceal a sensitive transaction alone.
Testing
Using defined procedures and evidence to evaluate control design or operation.
Third party
An external vendor, agent, contractor, partner or service provider relied upon by the organization.
Three lines model
A governance concept distinguishing operational ownership, risk/compliance challenge and independent assurance.
Trigger event
An event that starts a deadline, review, retention period or control activity.
Whistleblowing channel
A route for reporting suspected misconduct or concerns.
Workpaper
A record of review or testing procedures, evidence, analysis and conclusions.