Term Kind Topic What it is
Communication Capture Obligation Off-Channel Risk, Supervised Communications practice Records Retention & Legal Hold A duty to preserve and produce business communications, which fails whenever the compliant channel is less convenient than an available alternative - making channel design, not policy, the control that determi…
Compliance Scope Boundary Scope Reduction, Cardholder Data Environment practice PCI-DSS Scoping The set of systems subject to a compliance regime - determined by where regulated data flows, and reducible by architecture rather than by adding controls.
Consent Propagation Consent Enforcement, Withdrawal Fanout practice Consent Architecture Carrying a consent decision - and especially a withdrawal - to every system and third party that processes on the basis of it, which is where most consent implementations fail.
Geo-Restriction and Sanctions practice Geo-Restriction & Sanctions Preventing prohibited access and transactions by location or party — where the control must be enforced, evidenced and current.
Legal Hold practice Records Retention & Legal Hold Suspending deletion for specific records because of anticipated litigation or investigation, which must override the retention schedule and be provable.
Material Outsourcing Notification practice Sector Cloud Rules The regulatory obligation to inform a supervisor before placing a critical function with a third party, which puts cloud adoption on a timeline architecture must respect.
Obligation Mapping practice Regulatory & Data Protection Architecture Translating each legal or regulatory requirement into the specific design constraints it imposes, so that compliance becomes a set of testable properties rather than a document.
PCI DSS Scope Reduction practice PCI-DSS Scoping Deliberately limiting which systems handle cardholder data so that the audited estate is small, since every in-scope system carries the full control burden.
Point-in-Time Reconstruction As-At Reporting, Reproducible Submission practice Regulatory Reporting Pipelines The ability to regenerate a past report from the data and rules as they stood then - without which a regenerated figure differs from the submitted one and the difference cannot be explained.
Privacy by Design practice Privacy by Design Building data protection into the architecture from the first design decision rather than adding controls to a system already built.
Privacy Loss Accounting Budget Composition Tracking, Epsilon Accounting practice Privacy-Enhancing Technologies Tracking cumulative privacy loss across every statistic released from a dataset, because differential privacy's guarantee holds over the whole publication rather than per query - and once the budget is spent, …
Provider Exit Plan practice Exit & Concentration Risk A documented and tested plan for moving a workload off a provider, whose credibility is measured by what has actually been rehearsed rather than described.
Pseudonymisation practice Pseudonymisation Replacing identifying fields with a reference so records cannot be attributed to a person without separately held additional information.
Purpose Binding Purpose Metadata, Use Limitation Tagging practice Lawful Basis & Purpose Limitation Recording with the data the purpose it was collected for, and carrying that constraint through derivation, so a later use can be checked against what was agreed at collection.
Records Retention and Legal Hold practice Records Retention & Legal Hold The obligation to keep specified records for a defined period, and to suspend all deletion for material relevant to anticipated litigation.
Register of Information ICT Third-Party Register, Contractual Arrangements Register practice Sector Cloud Rules A maintained record of every contractual arrangement with a technology provider, including its subcontractors and which critical functions it supports, which converts supplier dependency from a question requir…
Restatement Record Correction Record, Submission Versioning practice Regulatory Reporting Pipelines Preserving the original submission alongside its correction, with the reason and the difference explicable - so that a restated figure strengthens the audit trail instead of destroying it.
Scope Reduction practice PCI-DSS Scoping Shrinking the set of systems that store, process or transmit cardholder data, because the cost of the standard is proportional to the number of systems in scope.
Subject Access Fulfilment practice Data Subject Rights The operational path from a request to a complete, verified, delivered response within the statutory period, across systems that were never designed for it.
Third-Party Risk Assessment Vendor Risk, Supplier Assurance practice Third-Party Risk Evaluating the security, resilience and compliance posture of suppliers whose failure would become your incident.