CompliverseAI
Compliance glossary

The vocabulary of GRC, plainly defined.

The terms that run through frameworks, controls, evidence, risk and audit, without the jargon.

Frameworks & compliance

Framework
A structured set of requirements and controls, such as ISO 27001 or SOC 2, that an organisation aligns its programme to.
Control
A safeguard or measure that reduces risk and satisfies a requirement, from access reviews to encryption.
Unified control library
One harmonised set of controls mapped across every framework that needs them, so you implement a control once and inherit it everywhere.
Gap analysis
A comparison of your current controls against a framework to surface exactly what is missing.
Statement of Applicability
The ISO 27001 document that records which Annex A controls apply, and the justification for any excluded.
Cross-framework reuse
Using a single piece of evidence to satisfy requirements in several frameworks at once, collected only once.

Evidence & audit

Evidence
An artifact, a log, policy, configuration or report, that proves a control is designed and operating.
Audit package
The assembled set of controls and evidence handed to an assessor, built from links that already exist.
Type I / Type II
SOC 2 report kinds: a point-in-time test of control design (I) versus operating effectiveness over a period (II).
Attestation
A formal, recorded acknowledgement that a policy or control has been read, reviewed or accepted.
Continuous control monitoring
Automated, ongoing checks that a control keeps working between formal audits, not just at assessment time.

Risk

Risk register
The catalogue of identified risks, each with an owner, a score and a treatment decision.
Inherent vs residual risk
The level of risk before controls are applied (inherent) versus what remains after them (residual).
Risk appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives.
Key Risk Indicator (KRI)
A metric that signals a rising level of risk as it approaches or breaches a defined threshold.
RCSA
Risk and Control Self-Assessment: a structured review in which the business rates its own risks and control effectiveness.
Treatment
The decision on how to handle a risk: accept, mitigate, transfer or avoid it.

Governance & policy

Policy lifecycle
The path a document travels: draft, review, approve, publish and attest, with version history at every step.
Exception
A documented, approved deviation from a policy or control, mapped back to what it departs from.
Committee
A governance body, such as a security steering committee, that owns decisions, charters and action items.
Regulatory change
A tracked update to a law or standard that triggers a review of the affected controls and policies.

Security & third parties

Vulnerability
A weakness in a system, application or process that could be exploited by a threat.
EPSS / KEV
The Exploit Prediction Scoring System and CISA's Known Exploited Vulnerabilities catalogue, used to prioritise fixes by real exploitability.
Remediation SLA
The agreed time allowed to fix a finding, tracked from the day it is raised.
TPRM
Third-Party Risk Management: assessing and continuously monitoring vendors across their whole lifecycle.
CIA triad
Confidentiality, Integrity and Availability, the three properties that information security controls protect.

The Compliverse model

The linkage graph
The connected data model that ties frameworks, policies, controls, evidence, risks and audits together as one graph.
Tenant isolation
Keeping each customer's data separated in its own scope, so answers and evidence never cross tenants.

Want to see these turned into a running programme on your own frameworks?

Book a live demo