Term Kind Topic What it is
Single-Credential Test Can One Credential Do Both, Segregation Reality Check practice Segregation of Duties Asking whether any single credential - including a database administrator, a root account or a deployment pipeline - can both initiate and approve a movement of value, which distinguishes a real segregation co…
Three Lines Model Three Lines of Defence concept Three Lines Model The organisational separation between those who own and manage risk, those who oversee and challenge, and those who provide independent assurance.
Time-Boxed Waiver practice Exception & Waiver Management An approved deviation from a standard that carries an owner, a justification, a compensating control and an expiry date after which it is reconsidered.
Toxic Combination concept Segregation of Duties A pair of permissions that is acceptable individually and dangerous together, which is what a segregation-of-duties model exists to identify.
Use Case Risk Classification practice AI Risk Tiering Assigning an AI application to a risk tier based on the consequence of it being wrong, which then determines the obligations that apply.
Validated Envelope Model Use Envelope, Validation Boundary concept Model Risk Management The explicit conditions a model's validation actually covers - input schema, population, feature sources, thresholds, upstream versions - outside which the sign-off does not hold and the serving path must refu…
Waiver as Code Machine-Readable Exception, Gate-Readable Waiver pattern Exception & Waiver Management Storing each approved deviation where the enforcement point reads it - rule id, scope, owner, justification, compensating control, expiry - so an exception stops a block automatically and its expiry becomes a …
Waiver Expiry Time-Bounded Exception, Expiring Risk Acceptance practice Exception & Waiver Management A mandatory end date on every exception to a standard, so that continuing the exception is an active decision rather than the default.
Warn-Mode Debt Advisory Gate Backlog, Non-Blocking Policy Debt concept Architecture Compliance Checks The accumulated violations of a policy that has only ever warned, which makes switching it to blocking politically impossible and hides how many of its rules are simply wrong.