AI Governance Library

AI Governance Glossary: A Practitioner Vocabulary for GRC and Infosec Teams

The system of decision rights, policies, controls, accountability, and oversight used to direct how AI is selected, built, bought, deployed, monitored, and retired. Good AI governance connects business value with risk management and stakeholder protection.
AI Governance Glossary: A Practitioner Vocabulary for GRC and Infosec Teams

⚡ Quick Summary

The AI Governance Glossary by Kunal Rk provides a practitioner-focused reference manual establishing clear, standardized terminology across artificial intelligence governance, security, compliance, and risk management. Designed specifically for Governance, Risk, and Compliance (GRC) and information security professionals, the document bridges technical machine learning concepts and enterprise assurance requirements. It organizes essential vocabulary into eight distinct operational sections, outlining actionable definitions that translate abstract ethical principles and emerging regulations into auditable controls, concrete management structures, and technical safeguards across the full artificial intelligence lifecycle.

🧩 What's Covered

The glossary spans 29 pages organized into eight core subject domains:

  • AI Governance Foundations: Core concepts including AI Governance, Accountability, AI Actors, AI Inventory, AI Policies and Principles, Socio-technical AI Systems, System Ownership, Algorithmic Accountability, and Governance Operating Models.
  • ISO 42001 and AIMS: Concepts structuring management systems, such as AI Management Systems (AIMS), ISO/IEC 42001 requirements, Context of the Organization, AIMS Scope, Top Management responsibilities, Measurable AI Objectives, Documented Information, Competence, Awareness, Internal Audits, Nonconformities, Corrective Actions, Continual Improvement, Annex SL integration, and Certification Audits.
  • AI Risk and Assurance: Operational risk terminology including Risk Assessments, Risk Appetite, Multi-dimensional Risk Criteria, Treatment Plans, Residual Risk, Risk Ownership, Impact Assessments, Algorithmic Impact Assessments, Harms, Misuse vs. Foreseeable Misuse, Material Change thresholds, Risk Registers, Control Effectiveness, KRIs, and the NIST AI RMF functions.
  • Compliance and Regulation: Regulatory vocabulary covering the EU AI Act lifecycle and enforcement timelines (2025–2027), Prohibited AI Practices, High-Risk AI Systems, supply chain roles (Provider, Deployer, Importer, Distributor), General-Purpose AI (GPAI) with Systemic Risk, Technical Documentation, Instructions for Use, Conformity Assessments, Post-Market Monitoring, Fundamental Rights Impacts, AI Office, Sandboxes, DPIAs, Regulatory Registers, AI Contract Controls, Serious Incidents, Substantial Modifications, Notified Bodies, CE Marking, and Market Surveillance Authorities.
  • GenAI and Agentic Security: Frontier security topics such as Threat Modeling, RAG architectures, AI Agents, Tool Use boundaries, Hallucination controls, Grounding, Guardrails, Safety Classifiers, Memory Poisoning, Prompt Injection (Direct and Indirect), Sensitive Information Disclosure, Training and Model Poisoning, Model Theft, Model DoS, Excessive Agency, Insecure Output Handling, System Prompt Leakage, Vector and Embedding Weaknesses, Supply Chain Risks, Adversarial Examples, Jailbreaks, Red Teaming, and Kill Switches.
  • Privacy, Data, and Model Governance: Data Lineage, Data Provenance, Data Quality, Training/Validation/Test data segregation, Synthetic Data governance, Personal Data tracking, Data Minimization, Purpose Limitation, ROPA updates, Data Retention and Residency, Model Cards, Dataset Cards, Bias, Fairness metrics, Explainability, Transparency, Traceability, Model Registries, Foundation Models, Fine-Tuning, Post-Training, RLHF, Inference governance, Context Windows, Embeddings, Benchmarks, Evaluation Harnesses, Evaluation Contamination, and Model Behavior Specifications.
  • Frontier AI and Systemic Risk: Advanced risk governance including Frontier Models, Advanced AI Systems, Systemic Risks, High-Impact and Dangerous Capabilities, Capability and Safety Evaluations, Safety Cases, Preparedness Frameworks, Model Release Policies, Deployment Thresholds, Compute Governance (Training and Effective Compute), Scaling Laws, CBRN Risks, Autonomy Risks, and Loss of Control scenarios.
  • Lifecycle, Audit, and Monitoring: End-to-end execution terms covering AI Lifecycle stages, Use Case Intake, Vendor Risk Management, Model Evaluation and Datasets, SLOs, Triage pathways, Human Oversight architectures (Human-in-the-Loop, Human-on-the-Loop), Validation, Verification, Performance Monitoring, Drift types (Model, Data, and Concept Drift), Change Management, Rollback procedures, Audit Criteria, Audit Evidence standards, Layered Assurance, KPIs, Exception Management, and Decommissioning.

💡 Why it matters?

As organizations operationalize compliance frameworks like ISO/IEC 42001 and face binding mandates under the EU AI Act, cross-functional misalignment between technical and oversight teams creates critical vulnerabilities. This glossary is valuable because it frames every technical concept—from vector embedding weaknesses to reinforcement learning—through the practical requirements of GRC: evidence collection, audit trails, role accountabilities, and decision-making thresholds. It bridges the divide between engineering workflows and defensible enterprise controls.

❓ What's Missing

The document is strictly a structured glossary and conceptual reference; it deliberately omits detailed control implementation templates, step-by-step audit programs, specific sample policy drafting language, code examples, or sector-specific regulatory deep dives (such as sector-specific healthcare or financial services regulations outside the overarching EU AI Act framework).

👥 Best For

GRC managers, Information Security Officers (CISOs/ISOs), AI compliance officers, internal and external auditors, privacy professionals, legal counsel, and technical product leads seeking a standardized enterprise vocabulary to align artificial intelligence risk and governance activities.

📄 Source Details

  • Source Document: AI Governance Glossary: A practitioner vocabulary for GRC and Infosec teams
  • Author: Kunal Rk (GRC)
  • Format: 29-page Reference Glossary

📝 Thanks to

Kunal Rk for compiling and structuring a comprehensive, audit-ready AI governance vocabulary tailored for risk, security, and assurance practitioners.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.