AI Governance Glossary

About this glossary: Plain-language definitions of the AI governance, security, and audit terms used across Assessed Govern and Assessed Assurance.

AI governance

The policies, controls, accountability, and oversight an organization uses to manage AI risk and meet its obligations throughout the AI lifecycle.

AI governance platform

Software that determines which governance obligations apply to each AI system, proves whether the required controls exist with evidence, and keeps that record current.

AI system inventory

A current record of every AI system an organization operates, including what it does, the data it touches, its capabilities, and its owner.

Automated AI system discovery

Identifying AI systems and their capabilities by reading code, infrastructure, and identity configuration rather than relying on surveys.

Shadow AI

AI models, agents, or AI-enabled features in use without being registered in the approved inventory.

AI risk management

The process of identifying, measuring, prioritizing, and treating risks that arise from designing, deploying, or using AI systems.

ARISE Framework™

The governance model from Assessed Intelligence that unifies AI, cybersecurity, privacy, and ethics governance in one common operating picture, with 128 controls and 953 prioritized requirements mapped to more than 42 frameworks.

Crosswalk

A mapping between a common control set and the requirements of external frameworks, which lets one piece of evidence satisfy overlapping requirements.

EU AI Act

The European Union regulation that governs AI systems by risk category, with prohibited practices, obligations for high-risk systems, transparency duties, and requirements for general-purpose AI models.

NIST AI RMF

The NIST AI Risk Management Framework, a voluntary framework organized around four functions: Govern, Map, Measure, and Manage.

ISO/IEC 42001

The international, certifiable standard that specifies requirements for an AI management system.

OWASP Top 10 for LLM Applications

An industry list of the most critical security risks in applications built on large language models, such as prompt injection and excessive agency.

Prompt injection

An attack in which untrusted input alters a language model’s instructions or behavior, which becomes more dangerous when the model can call tools.

Excessive agency

A condition in which an AI system has more tools, permissions, or autonomy than its task requires.

AI CI/CD governance gate

An automated pipeline check that evaluates each change to an AI system and returns pass, warn, or block based on governance risk.

Governance fingerprint

An encoding of an AI system’s risk profile across dimensions such as autonomy, data sensitivity, exposure, impact, tool authority, and human oversight.

AI determination record

A tamper-evident document stating what an AI system is, which governance applies, what evidence proves each control, and where the gaps are.

Evidence freshness

How recently evidence for a control was collected or validated. Evidence past its time-to-live is treated as stale and reopens the related finding.

Continuous AI assurance

Re-proving AI governance controls whenever systems change or evidence expires, rather than relying on point-in-time audits.

Attestation

A signed statement by an accountable person or an independent assessor that a control or program operates as described.

AI audit tool

Software that supports audit engagements for AI and security frameworks by automating evidence analysis, control mapping, and reporting while the auditor keeps judgment and the opinion.

PBC request

A “provided by client” request in which the auditor asks the client for specific evidence during an engagement.

5Cs

A structure for documenting audit findings by criteria, condition, cause, consequence, and corrective action.

Human oversight

Measures that let people monitor, interpret, and, where necessary, override or stop an AI system’s outputs and actions.

See how these concepts work in practice in Assessed Govern and Assessed Assurance.

Join the beta

Tell us about your organization and which platform you want to run. We use these details only to contact you about the beta, as described in our Privacy Policy.

Interested in

By signing up, you agree that Assessed Solutions may contact you about the beta. You can ask us to delete your details at any time. See our Privacy Policy.

You're on the list.

Thank you for your interest. We will contact you at the email you provided with next steps for the beta.