GRC Migrate

Home › Glossary

Reference · reviewed July 2026

GRC and compliance terms, defined

How to use this

Every term a vendor will use at you on a first call, defined in one or two sentences without the category language. If something on a demo did not make sense, it is probably here.

Compliance automation
The category these products belong to. Software that connects to your systems and gathers the evidence an audit needs, instead of a person gathering it by hand. The name is newer than the practice.
Integration (connector)
A prebuilt link between the platform and one of your systems, such as AWS or Okta. The count a vendor quotes matters far less than whether the specific systems you run are on the list.
Drift
When something that was configured correctly stops being correct, such as a new admin added without multi factor authentication. Catching drift between audits is most of what continuous monitoring is for.
Agent
A small program installed on employee laptops so the platform can confirm things like disk encryption and screen lock. Some platforms use one; some read the same facts from your device management tool instead.
Policy templates
Prewritten security policies the platform gives you to adapt and approve. They save real time, and an auditor will still expect them to describe what your company genuinely does.
Access review
A periodic check that everyone with access to a system should still have it. One of the few tasks a platform reminds you to do rather than doing for you.
Vendor risk management
Tracking the security posture of the suppliers you use. Usually sold as a separate module, and priced separately.
Implementation partner
An outside firm that sets the platform up and often runs the programme afterwards. Distinct from the platform vendor and from your auditor.
GRC
Governance, risk and compliance. Broad in theory. In practice, when a software company says it, they mean compliance evidence automation.
SOC 2
An attestation performed by a CPA firm against AICPA criteria. Requested by US enterprise buyers during security review. Not a law and not a certification.
ISO 27001
An international certification for an information security management system. What EU and UK enterprise buyers most often expect.
HIPAA
A US legal obligation that applies when you handle protected health information. There is no certificate at the end of it.
Type 1 and Type 2
Type 1 says your controls were designed properly on one day. Type 2 says they operated properly across a period, commonly three to twelve months.
Control
One specific practice you run to meet part of a framework, such as requiring multi factor authentication on all accounts.
Framework
The published set of expectations you are measured against. One framework contains many controls.
Evidence
Proof that a control was operating, with a date on it. Screenshots, config exports, signed acknowledgements, system logs.
Continuous monitoring
The platform re-runs its checks hourly or daily instead of once before an audit, so evidence is current instead of assembled in a panic.
Cross mapping
Counting one piece of evidence toward controls in more than one framework. The reason running SOC 2 and ISO 27001 together costs less than twice as much.
Trust center
A public page showing your security posture, certifications and documents so buyers can self serve instead of sending a questionnaire.
Security questionnaire
The spreadsheet a prospective customer sends asking how you handle security. The thing a trust center is meant to reduce.
Readiness
Everything that happens before an audit can start: choosing controls, writing policies, fixing gaps, collecting first evidence.
Observation window
The period a Type 2 report covers. It cannot be compressed by spending more, and it usually sets your delivery date.
Auditor portal
Where your audit firm reviews evidence. Some platforms have a dedicated collaboration space, others hand over exports.
vCISO
A fractional or part time chief information security officer. The person who supplies judgement when you do not have a full time security leader.
Scope
Which systems, products and locations your report covers. Narrow scope is faster and cheaper, and a customer may reject it.
Exception
A place where a control did not operate as intended. Exceptions are normal. Unexplained exceptions are the problem.