Term Kind Topic What it is
Assurance and Governance concept Assurance, Audit & Model Risk Providing confidence that controls exist and operate — through automation and evidence rather than through review meetings.
Audit Evidence concept Audit Evidence Durable, tamper-resistant records demonstrating that a control operated as described, for every instance in the period under review.
Automation Bias Deference to Automation, Rubber-Stamp Oversight concept Human-in-the-Loop Design The well-documented tendency for people to defer to a system's output rather than assess it independently - which is why nominal human oversight provides no protection.
Certification and Architecture concept Certification Impact on Architecture How pursuing a certification shapes architecture — mainly through scope boundaries and the need for automatic evidence.
Certification Scope Boundary concept Certification Impact on Architecture The declared set of systems, locations and people a certification covers, which determines both its cost and what it actually tells a customer.
Champion-Challenger Contamination Closed-Loop Evaluation Bias, Logged-Feedback Contamination concept Model Risk Management The condition where a model's offline evaluation data was generated by the model it is being compared against, so the metric rewards imitation and improves while live outcomes stay flat.
Change Advisory versus Automated Gates concept Change Advisory vs Automated Gates Whether change is controlled by human review or by automated verification — where the evidence favours automation and the regulation increasingly permits it.
Common-Cause Risk Shared Dependency Risk, Correlated Risk Cluster concept Risk Assessment Methods Several separately scored risks that all fire on the same underlying event, so a register scoring them independently ranks one large loss as a set of medium ones and funds none of them.
Control Coverage Assurance Coverage, Estate Coverage concept Continuous Controls Monitoring The proportion of the actual estate a control operates on - the metric that determines whether monitoring provides assurance or false confidence.
Control Design vs Operating Effectiveness concept Control Design vs Operation The distinction between a control being correctly designed to address a risk and it actually having worked consistently over a period.
Coverage Drift Shrinking Scope, Control Reach Decay concept Continuous Controls Monitoring A control operating perfectly on a diminishing share of the estate - passing every assessment of the systems it covers while providing progressively less assurance overall.
Evidence Retention Window Evidence Window, Assurance Retention Horizon concept Audit Evidence The span for which control evidence has to stay reproducible - the assurance period plus report lag plus the next cycle - which is routinely far longer than the retention anyone set on the systems that hold it.
Fairness Definition Choice Incompatible Fairness Metrics, Which Fairness concept Bias & Fairness Controls The unavoidable selection between mathematically incompatible fairness definitions - a legal and business determination that a team makes implicitly if it does not make it explicitly.
Fairness Through Unawareness Blindness Approach, Attribute Removal concept Bias & Fairness Controls The mistaken belief that removing a protected attribute from a model's inputs prevents disparate outcomes, when correlated features still carry the attribute and the deletion usually destroys the ability to me…
Independent Assurance concept Three Lines Model Assessment by a function with no involvement in designing or operating the control, which is what makes the assessment worth anything.
Operating Effectiveness concept Control Design vs Operation Whether a control actually ran, consistently, over a period — as distinct from whether it was well designed, and the harder of the two to demonstrate.
Risk Appetite concept Risk Appetite The amount and type of risk an organisation is willing to accept in pursuit of its objectives, stated explicitly enough to guide a design decision.
Risk Tolerance Statement concept Risk Appetite The board-level declaration of how much of each risk type the organisation will accept, which is what tells an architect which risks may be accepted without escalation.
Runtime Compliance Drift Plan-Time Blind Spot, Post-Apply Divergence concept Architecture Compliance Checks The growing gap between what infrastructure code declares and what the running estate actually looks like, which a pipeline-based policy check cannot see and therefore reports as compliant.
Segregation of Duties SoD, Separation of Duties concept Segregation of Duties Ensuring no single individual can both initiate and approve a sensitive action, so that fraud or error requires collusion.
Silent Control Failure Dormant Control, Control Decay concept Control Design vs Operation A control that has stopped operating while still reporting success, so the organisation keeps making decisions on the assumption that it is protecting them.
Three Lines Model Three Lines of Defence concept Three Lines Model The organisational separation between those who own and manage risk, those who oversee and challenge, and those who provide independent assurance.
Toxic Combination concept Segregation of Duties A pair of permissions that is acceptable individually and dangerous together, which is what a segregation-of-duties model exists to identify.
Validated Envelope Model Use Envelope, Validation Boundary concept Model Risk Management The explicit conditions a model's validation actually covers - input schema, population, feature sources, thresholds, upstream versions - outside which the sign-off does not hold and the serving path must refu…
Warn-Mode Debt Advisory Gate Backlog, Non-Blocking Policy Debt concept Architecture Compliance Checks The accumulated violations of a policy that has only ever warned, which makes switching it to blocking politically impossible and hides how many of its rules are simply wrong.