Lexicon · 34 terms
AI compliance lexicon: 34 terms
Short answer
Short definitions of the terms used across this site, with links to the standards bodies where a term comes from a standard and to the lesson that goes deeper.
A
- Agentic compliance
- Vendor term for compliance work carried out by AI agents with some autonomy, rather than by software that waits for a person to act.
- AI agent
- Software that carries out a defined task on its own, such as collecting evidence or drafting an answer, usually with a person approving the result.
- AI GRC platform
- Governance, risk and compliance software that uses AI agents for tasks such as evidence review, questionnaire answers, policy drafts and remediation suggestions. Read the lesson.
- Auditor independence
- The requirement that an auditor's judgment is not influenced by relationships with the audited company or others with an interest, such as a tool vendor. Read the lesson.
B
- Bring your own auditor (BYOA)
- Using an auditor you select yourself rather than one from the platform's network. Sprinto names BYOA on its Foundation plan.
C
- Certification body
- An organization that audits a management system against an ISO standard and issues a certificate if it conforms.
- CMMC
- Cybersecurity Maturity Model Certification: the US Department of Defense's cybersecurity requirements for its contractors.
- Common control framework
- A single set of internal controls that is mapped to many external frameworks. Sprinto uses this term.
- Compliance automation
- Software that connects to your systems, collects evidence against framework controls and tracks which controls pass or fail.
- Continuous control monitoring
- Automated, repeated checks that a control is still working, instead of a one-off check before an audit.
- Control
- A safeguard or process an organization operates to meet a requirement, such as quarterly access reviews or encryption at rest.
- Control cross-mapping
- Linking one control to the matching requirements in several frameworks so that evidence collected once counts for each. Read the lesson.
- CPA firm
- A licensed accounting firm. Only CPA firms can issue SOC reports.
E
- EU AI Act
- European Union regulation that places obligations on providers and deployers of AI systems according to the risk level of the system.
- Evidence
- Records that show a control operated: configuration exports, tickets, screenshots, logs or signed policies.
F
- FedRAMP
- The US government program that authorizes cloud services for use by federal agencies.
- Framework
- A published set of requirements an organization is assessed against, such as SOC 2, ISO 27001 or HIPAA.
G
- GDPR
- The European Union's General Data Protection Regulation, covering the processing of personal data.
H
- HIPAA
- US law that sets requirements for protecting health information handled by covered entities and their business associates.
I
- ISMS
- Information security management system: the policies, risk process, controls and reviews an organization runs to manage information security, as defined by ISO/IEC 27001.
- ISO/IEC 27001
- The international standard for information security management systems. Current version: ISO/IEC 27001:2022, Edition 3, published October 2022. Source: ISO/IEC 27001:2022 (iso.org).
- ISO/IEC 42001
- The international management system standard for artificial intelligence, covering how an organization governs the AI systems it builds or uses. Read the lesson.
N
- NIST AI RMF
- The NIST AI Risk Management Framework: voluntary guidance for identifying, measuring and managing risks from AI systems.
O
- Observation period
- The span of time a SOC 2 Type II report covers, during which controls must operate and evidence is collected.
P
- PCI DSS
- The Payment Card Industry Data Security Standard for organizations that store, process or transmit cardholder data.
- Peer review
- The AICPA program in which a CPA firm's accounting and auditing practice is reviewed by another firm. Buyers can ask whether an auditor is enrolled.
S
- Security questionnaire
- A list of security questions a customer sends a vendor during procurement. Several platforms here use AI to draft answers.
- SOC 1
- An AICPA report on controls at a service organization relevant to its customers' financial reporting.
- SOC 2
- An AICPA attestation report on a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy, issued by a CPA firm. Source: AICPA: SOC suite of services.
- Statement of Applicability
- An ISO 27001 document listing which controls apply to the organization, whether they are implemented, and why any are excluded.
T
- TPRM
- Third-party risk management: assessing and monitoring the security risk of your own vendors and suppliers.
- Trust Center
- A public or gated web page where a company shares its security posture, certifications and documents with customers.
- Type I report
- A SOC report on whether controls are suitably designed at a point in time.
- Type II report
- A SOC report on whether controls operated effectively over a period, known as the observation period.