Terminology
2240 terms, tools, patterns and metrics an architect is expected to use precisely. Each one gets a short explanation of what it is, and — where it matters — what it is commonly confused with. Search filters as you type; the column headers sort.
All areas2240
Architecture Fundamentals77
Distributed Systems107
Data Architecture110
Cloud Architecture94
Networking88
API & Integration Architecture82
Reliability & Resilience80
Observability75
Performance & Capacity Engineering72
Security Architecture86
Cost Architecture & FinOps71
Business Architecture67
Architecture Communication67
Enterprise Architecture66
Legacy Modernization71
AI-Era Architecture74
Software Architecture & Engineering71
Architecture Patterns71
Architecture Decision-Making63
The Architect's Meta-Skills61
Delivery & Release Engineering66
Platform Engineering & Developer Experience70
Testing & Quality Architecture71
Data Platform Architecture69
Streaming & Real-Time Data69
Data Governance & Semantics74
Frontend & Experience Architecture66
Edge, Mobile & IoT68
Regulatory & Data Protection Architecture65
Assurance, Audit & Model Risk69
69 terms shown.
| Term | Kind | Topic | What it is |
|---|---|---|---|
| Adversarial Evaluation | practice | Model Evaluation & Red-Teaming | Deliberately attempting to make a model behave badly, because a probabilistic system with no fixed expected output cannot be verified by conventional testing. |
| AI Risk Tiering | practice | AI Risk Tiering | Classifying AI systems by potential harm so that governance effort is proportionate, rather than applying the same controls to every use. |
| Architecture Compliance Check | practice | Architecture Compliance Checks | Automated verification that a running system still conforms to the architectural decisions and standards it was approved against. |
| Assurance and Governance | concept | Assurance, Audit & Model Risk | Providing confidence that controls exist and operate — through automation and evidence rather than through review meetings. |
| Assurance Map | practice | Assurance, Audit & Model Risk | A single view of which risks are covered by which assurance activity, exposing both the gaps nobody is looking at and the duplication several parties are paying for. |
| Audit Evidence | concept | Audit Evidence | Durable, tamper-resistant records demonstrating that a control operated as described, for every instance in the period under review. |
| Automation Bias Deference to Automation, Rubber-Stamp Oversight | concept | Human-in-the-Loop Design | The well-documented tendency for people to defer to a system's output rather than assess it independently - which is why nominal human oversight provides no protection. |
| Bias and Fairness Control | practice | Bias & Fairness Controls | Measuring and constraining disparate outcomes across groups, where the definition of fairness must be chosen deliberately because the definitions are mutually incompatible. |
| Break-Glass Change Ratio Emergency Change Rate, Bypass Ratio | metric | Change Advisory vs Automated Gates | The share of production changes that took the emergency path instead of the gated one, which measures how much of the change population a control actually covers. |
| Certification and Architecture | concept | Certification Impact on Architecture | How pursuing a certification shapes architecture — mainly through scope boundaries and the need for automatic evidence. |
| Certification Scope Boundary | concept | Certification Impact on Architecture | The declared set of systems, locations and people a certification covers, which determines both its cost and what it actually tells a customer. |
| Champion-Challenger Contamination Closed-Loop Evaluation Bias, Logged-Feedback Contamination | concept | Model Risk Management | The condition where a model's offline evaluation data was generated by the model it is being compared against, so the metric rewards imitation and improves while live outcomes stay flat. |
| Change Advisory versus Automated Gates | concept | Change Advisory vs Automated Gates | Whether change is controlled by human review or by automated verification — where the evidence favours automation and the regulation increasingly permits it. |
| Change Risk Budget Material Incident Budget, Change Risk Allowance | metric | Risk Appetite | A stated ceiling on material customer-visible incidents per period, converted into the change failure rate and escape rate engineering must design for - a conversion that usually shows blast radius and revert … |
| Common-Cause Risk Shared Dependency Risk, Correlated Risk Cluster | concept | Risk Assessment Methods | Several separately scored risks that all fire on the same underlying event, so a register scoring them independently ranks one large loss as a set of medium ones and funds none of them. |
| Complementary User Entity Control CUEC, User Control Consideration | practice | Three Lines Model | A control the service provider's auditor assumed the customer operates, so that a clean vendor opinion only holds for customers who are actually running it. |
| Compliance Scope Reduction Scope Minimisation, Descoping | pattern | Certification Impact on Architecture | Designing so that regulated data never touches most of the estate, which removes systems from assessment entirely rather than adding controls to them. |
| Conformance Automation | practice | Architecture Compliance Checks | Encoding architectural standards as automated checks, so review effort is spent on novel design decisions rather than on verifying known rules. |
| Consequence-Based Tiering Proportionate Governance, Risk Tier by Impact | practice | AI Risk Tiering | Assigning governance requirements according to the consequence of a system being wrong and who bears it, rather than by technology - so that the strictest controls apply where they matter and low-risk uses rem… |
| Continuous Controls Monitoring CCM | practice | Continuous Controls Monitoring | Automatically testing control effectiveness continuously across the whole population, rather than through periodic manual sampling. |
| Control Coverage Assurance Coverage, Estate Coverage | concept | Continuous Controls Monitoring | The proportion of the actual estate a control operates on - the metric that determines whether monitoring provides assurance or false confidence. |
| Control Design vs Operating Effectiveness | concept | Control Design vs Operation | The distinction between a control being correctly designed to address a risk and it actually having worked consistently over a period. |
| Control Test Automation | practice | Continuous Controls Monitoring | Executing a control's test continuously against the whole population rather than sampling it annually, which changes both the detection latency and the strength of the evidence. |
| Coverage Drift Shrinking Scope, Control Reach Decay | concept | Continuous Controls Monitoring | A control operating perfectly on a diminishing share of the estate - passing every assessment of the systems it covers while providing progressively less assurance overall. |
| Design Authority | practice | Design Authority | The body or role that approves significant designs — valuable when it improves decisions, harmful when it becomes a queue. |
| Design Review Trigger | practice | Security Design Review | The stated conditions under which a change requires security review, so that review capacity goes to what warrants it and everything else proceeds. |
| Evaluation Gate Coverage Gate Scope Ratio, Release Evaluation Coverage | metric | Model Evaluation & Red-Teaming | The share of a feature's real failure surface that its release evaluation actually exercises, which determines whether a passed gate is evidence of safety or evidence that the suite is stale. |
| Evidence Based Approval | practice | Change Advisory vs Automated Gates | Replacing a human judgement about whether a change is safe with a machine-produced record of the checks it passed, assessed once for the class rather than per instance. |
| Evidence by Construction | practice | Audit Evidence | Designing systems so that operating them produces the audit evidence automatically, rather than reconstructing it from screenshots when an assessment arrives. |
| Evidence By-Product Evidence Automation, Continuous Evidence | practice | Audit Evidence | Audit evidence produced automatically by the control operating, rather than assembled by engineers before each audit. |
| Evidence Retention Window Evidence Window, Assurance Retention Horizon | concept | Audit Evidence | The span for which control evidence has to stay reproducible - the assurance period plus report lag plus the next cycle - which is routinely far longer than the retention anyone set on the systems that hold it. |
| Exception and Waiver Management | practice | Exception & Waiver Management | The formal process for permitting a deviation from a standard, with a named risk owner, a stated expiry and a remediation plan. |
| Exception Register Waiver Management, Control Deviation Record, Risk Acceptance Log | practice | Exception & Waiver Management | A recorded, owned, time-bounded set of approved deviations from a control - which is what makes a control survivable, and whose aggregate is the best available evidence about whether the control fits reality. |
| Fail-Closed Control Deny on Error, Safe-Failure Gate | practice | Control Design vs Operation | A control that blocks when it cannot evaluate, rather than allowing the action through - so that a broken control is visible immediately instead of silently ceasing to protect anything. |
| Fairness Definition Choice Incompatible Fairness Metrics, Which Fairness | concept | Bias & Fairness Controls | The unavoidable selection between mathematically incompatible fairness definitions - a legal and business determination that a team makes implicitly if it does not make it explicitly. |
| Fairness Through Unawareness Blindness Approach, Attribute Removal | concept | Bias & Fairness Controls | The mistaken belief that removing a protected attribute from a model's inputs prevents disparate outcomes, when correlated features still carry the attribute and the deletion usually destroys the ability to me… |
| Human in the Loop Design | pattern | Human-in-the-Loop Design | Placing human judgement at the points where automation should not decide alone — with attention to whether the human can actually exercise judgement. |
| Independent Assurance | concept | Three Lines Model | Assessment by a function with no involvement in designing or operating the control, which is what makes the assessment worth anything. |
| Intended Use Statement Scope of Use, Out-of-Scope Use Declaration | practice | Model Documentation | The part of model documentation that states what the model is validated for and what it must not be used for, so that a deployer can tell whether their use case is covered. |
| Irreversible Operation Guard Soft Delete Window, Two-Person Destructive Control | pattern | Segregation of Duties | The set of design choices that make a destructive action recoverable by default - a delay before permanence, a type check on the target, and a second approver for bulk effects. |
| Launch-Blocking Finding Irreversibility Gate, Block-or-Advise Rule | practice | Security Design Review | The rule that a design review holds a launch only for findings whose remediation cost explodes once real users exist, and turns everything else into a dated commitment with an owner. |
| Model Card | tool | Model Documentation | A structured document describing a model's intended use, training data, evaluation results, limitations and ethical considerations. |
| Model Inventory AI Register, Model Registry, Deployed Model Catalogue | practice | Model Risk Management | A complete record of every model deployed in the organisation with its owner, purpose, risk tier and review date - the precondition for any AI governance, and the thing most organisations do not have. |
| Model Inventory Model Register, AI System Register | practice | Model Risk Management | A maintained register of every model making or informing decisions - the prerequisite without which no other model governance control can be applied. |
| Model Risk Management MRM, SR 11-7 | practice | Model Risk Management | The discipline of governing the risk that a model is wrong, is used incorrectly, or is applied outside the conditions it was built for. |
| Operating Effectiveness | concept | Control Design vs Operation | Whether a control actually ran, consistently, over a period — as distinct from whether it was well designed, and the harder of the two to demonstrate. |
| Partial Deployment Verification Artefact Completeness Check, Fleet Convergence Verification | practice | Segregation of Duties | Machine confirmation that every target in a fleet is running the intended artefact, independently checked, so that an incomplete rollout cannot present itself as a finished one. |
| Policy as Code Compliance as Code, Automated Control, Executable Policy | practice | Architecture Compliance Checks | Expressing controls as executable rules evaluated automatically against real system state, so that compliance is demonstrated continuously over the whole population rather than asserted in a document and sampl… |
| Quantified Risk Estimate | practice | Risk Assessment Methods | Expressing a risk as a probability distribution over financial loss rather than as a colour, which makes risks comparable and mitigations arguable on cost. |
| Red Teaming a Model | practice | Model Evaluation & Red-Teaming | Adversarial testing of a model or AI system to find inputs that produce harmful, incorrect or policy-violating outputs before users do. |
| Review Scope Discipline | practice | Design Authority | Stating what an architecture board does not review, which is what determines whether it stays useful or becomes a queue. |
| Reviewer Throughput Ceiling Oversight Capacity Limit, Review Time Budget | metric | Human-in-the-Loop Design | The number of items a human reviewer can genuinely assess per hour, which bounds what any human-in-the-loop control can actually deliver regardless of what the design document claims. |
| Risk Appetite | concept | Risk Appetite | The amount and type of risk an organisation is willing to accept in pursuit of its objectives, stated explicitly enough to guide a design decision. |
| Risk Assessment Methods | practice | Risk Assessment Methods | Structured ways to identify and prioritise what could go wrong — where the value is the conversation and the ranking, not the number. |
| Risk Tolerance Statement | concept | Risk Appetite | The board-level declaration of how much of each risk type the organisation will accept, which is what tells an architect which risks may be accepted without escalation. |
| Runtime Compliance Drift Plan-Time Blind Spot, Post-Apply Divergence | concept | Architecture Compliance Checks | The growing gap between what infrastructure code declares and what the running estate actually looks like, which a pipeline-based policy check cannot see and therefore reports as compliant. |
| Sampling Risk Detection Probability, Audit Sampling Power | metric | Continuous Controls Monitoring | The probability that a sample-based control test misses a violation that exists in the population - which for small samples and rare violations is most of the time. |
| Security Design Review | practice | Security Design Review | A structured examination of an architecture's security properties before it is built, focused on trust boundaries and threat paths rather than on a checklist. |
| Segregation of Duties SoD, Separation of Duties | concept | Segregation of Duties | Ensuring no single individual can both initiate and approve a sensitive action, so that fraud or error requires collusion. |
| Silent Control Failure Dormant Control, Control Decay | concept | Control Design vs Operation | A control that has stopped operating while still reporting success, so the organisation keeps making decisions on the assumption that it is protecting them. |
Nothing on this page matches. Search the whole glossary.