Home › Glossary
Reference · reviewed July 2026GRC and compliance terms, defined
How to use this
Every term a vendor will use at you on a first call, defined in one or two sentences without the category language. If something on a demo did not make sense, it is probably here.
- Compliance automation
- The category these products belong to. Software that connects to your systems and gathers the evidence an audit needs, instead of a person gathering it by hand. The name is newer than the practice.
- Integration (connector)
- A prebuilt link between the platform and one of your systems, such as AWS or Okta. The count a vendor quotes matters far less than whether the specific systems you run are on the list.
- Drift
- When something that was configured correctly stops being correct, such as a new admin added without multi factor authentication. Catching drift between audits is most of what continuous monitoring is for.
- Agent
- A small program installed on employee laptops so the platform can confirm things like disk encryption and screen lock. Some platforms use one; some read the same facts from your device management tool instead.
- Policy templates
- Prewritten security policies the platform gives you to adapt and approve. They save real time, and an auditor will still expect them to describe what your company genuinely does.
- Access review
- A periodic check that everyone with access to a system should still have it. One of the few tasks a platform reminds you to do rather than doing for you.
- Vendor risk management
- Tracking the security posture of the suppliers you use. Usually sold as a separate module, and priced separately.
- Implementation partner
- An outside firm that sets the platform up and often runs the programme afterwards. Distinct from the platform vendor and from your auditor.
- GRC
- Governance, risk and compliance. Broad in theory. In practice, when a software company says it, they mean compliance evidence automation.
- SOC 2
- An attestation performed by a CPA firm against AICPA criteria. Requested by US enterprise buyers during security review. Not a law and not a certification.
- ISO 27001
- An international certification for an information security management system. What EU and UK enterprise buyers most often expect.
- HIPAA
- A US legal obligation that applies when you handle protected health information. There is no certificate at the end of it.
- Type 1 and Type 2
- Type 1 says your controls were designed properly on one day. Type 2 says they operated properly across a period, commonly three to twelve months.
- Control
- One specific practice you run to meet part of a framework, such as requiring multi factor authentication on all accounts.
- Framework
- The published set of expectations you are measured against. One framework contains many controls.
- Evidence
- Proof that a control was operating, with a date on it. Screenshots, config exports, signed acknowledgements, system logs.
- Continuous monitoring
- The platform re-runs its checks hourly or daily instead of once before an audit, so evidence is current instead of assembled in a panic.
- Cross mapping
- Counting one piece of evidence toward controls in more than one framework. The reason running SOC 2 and ISO 27001 together costs less than twice as much.
- Trust center
- A public page showing your security posture, certifications and documents so buyers can self serve instead of sending a questionnaire.
- Security questionnaire
- The spreadsheet a prospective customer sends asking how you handle security. The thing a trust center is meant to reduce.
- Readiness
- Everything that happens before an audit can start: choosing controls, writing policies, fixing gaps, collecting first evidence.
- Observation window
- The period a Type 2 report covers. It cannot be compressed by spending more, and it usually sets your delivery date.
- Auditor portal
- Where your audit firm reviews evidence. Some platforms have a dedicated collaboration space, others hand over exports.
- vCISO
- A fractional or part time chief information security officer. The person who supplies judgement when you do not have a full time security leader.
- Scope
- Which systems, products and locations your report covers. Narrow scope is faster and cheaper, and a customer may reject it.
- Exception
- A place where a control did not operate as intended. Exceptions are normal. Unexplained exceptions are the problem.