Term Kind Topic What it is
Adversarial Evaluation practice Model Evaluation & Red-Teaming Deliberately attempting to make a model behave badly, because a probabilistic system with no fixed expected output cannot be verified by conventional testing.
AI Risk Tiering practice AI Risk Tiering Classifying AI systems by potential harm so that governance effort is proportionate, rather than applying the same controls to every use.
Architecture Compliance Check practice Architecture Compliance Checks Automated verification that a running system still conforms to the architectural decisions and standards it was approved against.
Assurance Map practice Assurance, Audit & Model Risk A single view of which risks are covered by which assurance activity, exposing both the gaps nobody is looking at and the duplication several parties are paying for.
Bias and Fairness Control practice Bias & Fairness Controls Measuring and constraining disparate outcomes across groups, where the definition of fairness must be chosen deliberately because the definitions are mutually incompatible.
Complementary User Entity Control CUEC, User Control Consideration practice Three Lines Model A control the service provider's auditor assumed the customer operates, so that a clean vendor opinion only holds for customers who are actually running it.
Conformance Automation practice Architecture Compliance Checks Encoding architectural standards as automated checks, so review effort is spent on novel design decisions rather than on verifying known rules.
Consequence-Based Tiering Proportionate Governance, Risk Tier by Impact practice AI Risk Tiering Assigning governance requirements according to the consequence of a system being wrong and who bears it, rather than by technology - so that the strictest controls apply where they matter and low-risk uses rem…
Continuous Controls Monitoring CCM practice Continuous Controls Monitoring Automatically testing control effectiveness continuously across the whole population, rather than through periodic manual sampling.
Control Test Automation practice Continuous Controls Monitoring Executing a control's test continuously against the whole population rather than sampling it annually, which changes both the detection latency and the strength of the evidence.
Design Authority practice Design Authority The body or role that approves significant designs — valuable when it improves decisions, harmful when it becomes a queue.
Design Review Trigger practice Security Design Review The stated conditions under which a change requires security review, so that review capacity goes to what warrants it and everything else proceeds.
Evidence Based Approval practice Change Advisory vs Automated Gates Replacing a human judgement about whether a change is safe with a machine-produced record of the checks it passed, assessed once for the class rather than per instance.
Evidence by Construction practice Audit Evidence Designing systems so that operating them produces the audit evidence automatically, rather than reconstructing it from screenshots when an assessment arrives.
Evidence By-Product Evidence Automation, Continuous Evidence practice Audit Evidence Audit evidence produced automatically by the control operating, rather than assembled by engineers before each audit.
Exception and Waiver Management practice Exception & Waiver Management The formal process for permitting a deviation from a standard, with a named risk owner, a stated expiry and a remediation plan.
Exception Register Waiver Management, Control Deviation Record, Risk Acceptance Log practice Exception & Waiver Management A recorded, owned, time-bounded set of approved deviations from a control - which is what makes a control survivable, and whose aggregate is the best available evidence about whether the control fits reality.
Fail-Closed Control Deny on Error, Safe-Failure Gate practice Control Design vs Operation A control that blocks when it cannot evaluate, rather than allowing the action through - so that a broken control is visible immediately instead of silently ceasing to protect anything.
Intended Use Statement Scope of Use, Out-of-Scope Use Declaration practice Model Documentation The part of model documentation that states what the model is validated for and what it must not be used for, so that a deployer can tell whether their use case is covered.
Launch-Blocking Finding Irreversibility Gate, Block-or-Advise Rule practice Security Design Review The rule that a design review holds a launch only for findings whose remediation cost explodes once real users exist, and turns everything else into a dated commitment with an owner.
Model Inventory AI Register, Model Registry, Deployed Model Catalogue practice Model Risk Management A complete record of every model deployed in the organisation with its owner, purpose, risk tier and review date - the precondition for any AI governance, and the thing most organisations do not have.
Model Inventory Model Register, AI System Register practice Model Risk Management A maintained register of every model making or informing decisions - the prerequisite without which no other model governance control can be applied.
Model Risk Management MRM, SR 11-7 practice Model Risk Management The discipline of governing the risk that a model is wrong, is used incorrectly, or is applied outside the conditions it was built for.
Partial Deployment Verification Artefact Completeness Check, Fleet Convergence Verification practice Segregation of Duties Machine confirmation that every target in a fleet is running the intended artefact, independently checked, so that an incomplete rollout cannot present itself as a finished one.
Policy as Code Compliance as Code, Automated Control, Executable Policy practice Architecture Compliance Checks Expressing controls as executable rules evaluated automatically against real system state, so that compliance is demonstrated continuously over the whole population rather than asserted in a document and sampl…
Quantified Risk Estimate practice Risk Assessment Methods Expressing a risk as a probability distribution over financial loss rather than as a colour, which makes risks comparable and mitigations arguable on cost.
Red Teaming a Model practice Model Evaluation & Red-Teaming Adversarial testing of a model or AI system to find inputs that produce harmful, incorrect or policy-violating outputs before users do.
Review Scope Discipline practice Design Authority Stating what an architecture board does not review, which is what determines whether it stays useful or becomes a queue.
Risk Assessment Methods practice Risk Assessment Methods Structured ways to identify and prioritise what could go wrong — where the value is the conversation and the ranking, not the number.
Security Design Review practice Security Design Review A structured examination of an architecture's security properties before it is built, focused on trust boundaries and threat paths rather than on a checklist.
Single-Credential Test Can One Credential Do Both, Segregation Reality Check practice Segregation of Duties Asking whether any single credential - including a database administrator, a root account or a deployment pipeline - can both initiate and approve a movement of value, which distinguishes a real segregation co…
Time-Boxed Waiver practice Exception & Waiver Management An approved deviation from a standard that carries an owner, a justification, a compensating control and an expiry date after which it is reconsidered.
Use Case Risk Classification practice AI Risk Tiering Assigning an AI application to a risk tier based on the consequence of it being wrong, which then determines the obligations that apply.
Waiver Expiry Time-Bounded Exception, Expiring Risk Acceptance practice Exception & Waiver Management A mandatory end date on every exception to a standard, so that continuing the exception is an active decision rather than the default.