Term Kind Topic What it is
Adversarial Evaluation practice Model Evaluation & Red-Teaming Deliberately attempting to make a model behave badly, because a probabilistic system with no fixed expected output cannot be verified by conventional testing.
Assurance Map practice Assurance, Audit & Model Risk A single view of which risks are covered by which assurance activity, exposing both the gaps nobody is looking at and the duplication several parties are paying for.
Conformance Automation practice Architecture Compliance Checks Encoding architectural standards as automated checks, so review effort is spent on novel design decisions rather than on verifying known rules.
Control Test Automation practice Continuous Controls Monitoring Executing a control's test continuously against the whole population rather than sampling it annually, which changes both the detection latency and the strength of the evidence.
Design Review Trigger practice Security Design Review The stated conditions under which a change requires security review, so that review capacity goes to what warrants it and everything else proceeds.
Evidence Based Approval practice Change Advisory vs Automated Gates Replacing a human judgement about whether a change is safe with a machine-produced record of the checks it passed, assessed once for the class rather than per instance.
Evidence by Construction practice Audit Evidence Designing systems so that operating them produces the audit evidence automatically, rather than reconstructing it from screenshots when an assessment arrives.
Model Card practice Model Documentation A structured record of what a model is for, how it was built and where it should not be used — written for the people who will deploy or be affected by it.
Model Inventory practice Model Risk Management A complete register of models in use with their purpose, owner, risk tier and validation status — the artifact everything else in model governance depends on.
Quantified Risk Estimate practice Risk Assessment Methods Expressing a risk as a probability distribution over financial loss rather than as a colour, which makes risks comparable and mitigations arguable on cost.
Review Scope Discipline practice Design Authority Stating what an architecture board does not review, which is what determines whether it stays useful or becomes a queue.
Time-Boxed Waiver practice Exception & Waiver Management An approved deviation from a standard that carries an owner, a justification, a compensating control and an expiry date after which it is reconsidered.
Use Case Risk Classification practice AI Risk Tiering Assigning an AI application to a risk tier based on the consequence of it being wrong, which then determines the obligations that apply.