AI COMPLIANCE COMPARE

Lexicon · 34 terms

AI compliance lexicon: 34 terms

Short answer

Short definitions of the terms used across this site, with links to the standards bodies where a term comes from a standard and to the lesson that goes deeper.

A

Agentic compliance
Vendor term for compliance work carried out by AI agents with some autonomy, rather than by software that waits for a person to act.
AI agent
Software that carries out a defined task on its own, such as collecting evidence or drafting an answer, usually with a person approving the result.
AI GRC platform
Governance, risk and compliance software that uses AI agents for tasks such as evidence review, questionnaire answers, policy drafts and remediation suggestions. Read the lesson.
Auditor independence
The requirement that an auditor's judgment is not influenced by relationships with the audited company or others with an interest, such as a tool vendor. Read the lesson.

B

Bring your own auditor (BYOA)
Using an auditor you select yourself rather than one from the platform's network. Sprinto names BYOA on its Foundation plan.

C

Certification body
An organization that audits a management system against an ISO standard and issues a certificate if it conforms.
CMMC
Cybersecurity Maturity Model Certification: the US Department of Defense's cybersecurity requirements for its contractors.
Common control framework
A single set of internal controls that is mapped to many external frameworks. Sprinto uses this term.
Compliance automation
Software that connects to your systems, collects evidence against framework controls and tracks which controls pass or fail.
Continuous control monitoring
Automated, repeated checks that a control is still working, instead of a one-off check before an audit.
Control
A safeguard or process an organization operates to meet a requirement, such as quarterly access reviews or encryption at rest.
Control cross-mapping
Linking one control to the matching requirements in several frameworks so that evidence collected once counts for each. Read the lesson.
CPA firm
A licensed accounting firm. Only CPA firms can issue SOC reports.

E

EU AI Act
European Union regulation that places obligations on providers and deployers of AI systems according to the risk level of the system.
Evidence
Records that show a control operated: configuration exports, tickets, screenshots, logs or signed policies.

F

FedRAMP
The US government program that authorizes cloud services for use by federal agencies.
Framework
A published set of requirements an organization is assessed against, such as SOC 2, ISO 27001 or HIPAA.

G

GDPR
The European Union's General Data Protection Regulation, covering the processing of personal data.

H

HIPAA
US law that sets requirements for protecting health information handled by covered entities and their business associates.

I

ISMS
Information security management system: the policies, risk process, controls and reviews an organization runs to manage information security, as defined by ISO/IEC 27001.
ISO/IEC 27001
The international standard for information security management systems. Current version: ISO/IEC 27001:2022, Edition 3, published October 2022. Source: ISO/IEC 27001:2022 (iso.org).
ISO/IEC 42001
The international management system standard for artificial intelligence, covering how an organization governs the AI systems it builds or uses. Read the lesson.

N

NIST AI RMF
The NIST AI Risk Management Framework: voluntary guidance for identifying, measuring and managing risks from AI systems.

O

Observation period
The span of time a SOC 2 Type II report covers, during which controls must operate and evidence is collected.

P

PCI DSS
The Payment Card Industry Data Security Standard for organizations that store, process or transmit cardholder data.
Peer review
The AICPA program in which a CPA firm's accounting and auditing practice is reviewed by another firm. Buyers can ask whether an auditor is enrolled.

S

Security questionnaire
A list of security questions a customer sends a vendor during procurement. Several platforms here use AI to draft answers.
SOC 1
An AICPA report on controls at a service organization relevant to its customers' financial reporting.
SOC 2
An AICPA attestation report on a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy, issued by a CPA firm. Source: AICPA: SOC suite of services.
Statement of Applicability
An ISO 27001 document listing which controls apply to the organization, whether they are implemented, and why any are excluded.

T

TPRM
Third-party risk management: assessing and monitoring the security risk of your own vendors and suppliers.
Trust Center
A public or gated web page where a company shares its security posture, certifications and documents with customers.
Type I report
A SOC report on whether controls are suitably designed at a point in time.
Type II report
A SOC report on whether controls operated effectively over a period, known as the observation period.