Reference
GRC glossary
The vocabulary that shows up in audit requests, security questionnaires and board packs — defined in plain English, with what actually matters about each one in practice rather than a restatement of the acronym.
Programme
- Continuous compliance
- Operating and evidencing controls continuously rather than assembling proof in the weeks before an audit. The practical difference is where the effort sits: continuous programmes spend it on automated collection and exception handling, periodic ones spend it on reconstruction, and only the first can answer a customer's question on the day it is asked. See also: Continuous compliance monitoring
- Control
- A measure put in place to reduce the likelihood or impact of something going wrong — an approval step, an automated check, a review performed on a schedule. Controls are described as preventive, detective or corrective by what they do, and as manual or automated by how they run. A control that exists on paper but produces no record is indistinguishable, to an auditor, from one that does not exist. See also: Compliance
- Control testing
- Checking that a control actually operated as designed over a period, rather than that it was designed sensibly. Testing usually involves selecting a sample of occurrences and inspecting the evidence for each. A control can fail testing for reasons that have nothing to do with security — most commonly because the evidence was never retained. See also: Audit evidence management
- Crosswalk (Framework mapping)
- A mapping between the requirements of different frameworks, showing where one control satisfies several. Crosswalks are what make running multiple frameworks tractable: an access review evidenced once can serve SOC 2, ISO 27001 and HIPAA rather than being performed and evidenced three times. See also: All frameworks Framework crosswalk projection
- Gap analysis
- A structured comparison of where a programme stands against a framework's requirements, producing the list of what is missing or insufficient. It is only worth doing if its output becomes tracked remediation with owners and dates — a gap analysis whose findings are not scheduled is a document that ages. See also: Gap analysis to remediation
- GRC (Governance, Risk and Compliance)
- The combined disciplines of directing an organisation (governance), understanding what could go wrong and deciding what to do about it (risk), and meeting external obligations (compliance). They are grouped because they share evidence: the same access review satisfies a compliance control, informs a risk assessment, and gives the board something to oversee. Treating them as separate programmes is what produces three teams collecting the same artifact three times. See also: The platform Grc maturity assessment
- Remediation
- The work of closing an identified gap, finding or vulnerability. What distinguishes real remediation from a closed ticket is verification: confirming the fix is in place and effective before the item is closed, rather than recording completion on the word of whoever did the work. See also: Risk to verified remediation
Risk
- FAIR (Factor Analysis of Information Risk)
- A quantitative model that expresses risk in financial terms by decomposing it into loss event frequency and loss magnitude, then simulating the range of outcomes rather than producing a single number. Its practical appeal is that a distribution of possible losses can be compared against the cost of a control, which a red-amber-green rating cannot. See also: Risk management Fair vs stoplights
- Inherent risk
- The level of risk before any controls are considered — the exposure that exists simply because of the activity being performed. It is a useful baseline because it shows how much of your current position depends on controls continuing to work. See also: Risk management
- KRI (Key Risk Indicator)
- A metric chosen because it moves before a risk materialises, giving warning while there is still time to act — as distinct from a KPI, which reports performance after the fact. A KRI needs a defined threshold and a named owner, because an indicator that breaches and triggers nothing is only a chart. See also: Define and measure kris Kri breach response
- Monte Carlo simulation
- A technique that runs a model many thousands of times using values drawn from probability distributions, producing a range of outcomes and their likelihoods instead of one point estimate. In risk quantification it is what turns uncertain inputs into a defensible statement such as the likely annual loss falling within a stated range. See also: Risk management
- Residual risk
- The risk that remains after controls are applied. It is the number that should drive decisions, because it reflects the exposure actually being carried. Residual risk is only credible where the controls it assumes are tested — otherwise it is inherent risk with optimism subtracted. See also: Risk management
- Risk appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, set by the board or executive. Appetite is only meaningful when expressed in terms that can be compared against measured exposure; stated as an adjective it cannot be breached, and therefore cannot be governed. See also: Risk management
- Risk register
- The catalogue of identified risks with their assessment, owner, treatment decision and current status. Its usefulness depends entirely on being maintained: a register reviewed annually describes the organisation as it was, and is routinely mistaken for a description of the organisation as it is. See also: Risk management
Audit
- Audit trail
- The chronological record of actions taken in a system — who did what, to which object, and when. Its value depends on being append-only: a log that participants can edit proves nothing about the events it describes. See also: Trust centre
- Chain of custody
- The unbroken record of where a piece of evidence came from, when it was captured and who has handled it since. It matters because evidence a third party can reach into and alter is weaker than evidence collected automatically and sealed. Auditors weigh how evidence was produced, not only what it shows. See also: Audit evidence management
- Evidence (Artifact)
- The record that proves a control operated: a log export, a signed approval, a configuration snapshot, a completed review. Evidence carries a date and a provenance, and both matter — an accurate screenshot taken months after the fact does not demonstrate that the control ran when it was supposed to. See also: Audit evidence management
- Materiality
- The threshold at which information would matter to a reasonable decision-maker. In securities disclosure it determines whether an incident must be reported, and it is assessed qualitatively as well as quantitatively — reputational, legal and customer impact count alongside financial loss, so a purely monetary threshold is not a sufficient test. See also: Sec cyber
- Type I vs Type II
- In a SOC 2 engagement, a Type I report assesses whether controls are suitably designed at a point in time, while a Type II additionally tests whether they operated effectively across an observation window of typically three to twelve months. Type I proves the design; Type II proves it held. Enterprise buyers generally ask for Type II. See also: Soc2
Access
- Access review (Access certification, User access review)
- A periodic check in which a reviewer confirms, for each person, that the access they hold is still warranted, and revokes what is not. It exists because entitlements outlive their reason for existing — people change roles, projects end, contractors leave — and the accumulation is silent. The output is a signed record of the decisions, which is what an auditor tests. See also: Workforce access reviews Access reviews
- Joiner-mover-leaver (JML)
- The lifecycle of workforce access: provisioning on joining, adjusting on role change, and removing on departure. The mover step is the one most often missed — people accumulate the access of every role they have held, because new access is granted without the old being withdrawn. See also: Workforce
- Least privilege
- The principle that a person or process should hold only the access required to perform its function, and no more. It limits the blast radius of a compromised account or a mistake. It is easy to state and hard to sustain, because access is granted under time pressure and removed, if at all, only when someone reviews it. See also: Workforce access reviews
- Segregation of duties (SoD)
- Splitting a sensitive process so that no single person can both initiate and approve it — the classic pairing being the ability to create a supplier and to pay one. Violations are usually combinations rather than individual permissions, which is why they survive permission-by-permission review and only surface when access is analysed as a set. See also: Segregation of duties
Vendor
- Fourth-party risk
- The risk carried by your suppliers' own suppliers — the subprocessors behind the vendor you contracted with. It matters because concentration often hides one layer down: several independent-looking vendors may share a single hosting provider, so an outage correlates across suppliers you believed were unrelated. See also: Vendor management
- Third-party risk management (TPRM)
- The discipline of assessing and monitoring the risk introduced by suppliers, processors and partners. It spans due diligence before contracting, contractual protections, ongoing monitoring proportionate to criticality, and an exit plan. It depends on a complete inventory — the vendor nobody recorded is the one with no assessment. See also: Vendor management Vendor risk management
- Vendor tiering
- Classifying suppliers by the risk they present — typically from the data they access, the criticality of the service, and the difficulty of replacing them — so that assessment depth follows exposure. Tiering exists so that a payroll processor and a stock photo subscription are not sent the same questionnaire. See also: Vendor management
Governance
- Policy attestation
- The record that a named person read and accepted a specific version of a policy on a specific date. Version matters: an attestation against a superseded document does not evidence that the person saw the rule now in force, which is why re-attestation follows material revisions. See also: Governance Policy attestation annual
- RACI
- A matrix assigning who is Responsible for doing work, Accountable for the outcome, Consulted before decisions, and Informed after them. Its value in a GRC programme is narrow but real: it removes the ambiguity about who owns a control, which is the most common reason a control quietly stops being performed. See also: Raci responsibility matrix
Resilience
- Business impact analysis (BIA)
- The exercise of determining which business processes matter most, what they depend on, and how quickly each must be restored. It produces the priorities that recovery planning is built on. Done once and shelved it decays quickly, because dependencies change faster than the document describing them. See also: Bia at scale
- RTO and RPO (Recovery Time Objective, Recovery Point Objective)
- RTO is how quickly a service must be restored after disruption; RPO is how much data loss is tolerable, expressed as time. They are commitments rather than measurements, and they are only credible once a recovery has been tested against them — an untested RTO is an aspiration. See also: Business continuity end to end
See these ideas working on your own data.
Start a 7-day readiness trial — no credit card, no sales call required.