Compliance glossary

Plain-English definitions of the compliance, audit and information-security terms behind ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF and AI governance — written so you (and your auditor) know exactly what each one means.

Looking for a framework overview instead? See our framework guides.

Why this vocabulary matters

Compliance has a language of its own. The same word can carry a precise, specific meaning in ISO 27001, SOC 2, HIPAA, or the GDPR. A risk assessment, a control, and an audit each mean something exact that auditors and enterprise buyers expect you to use correctly. This glossary defines those terms in plain English. The goal is simple: you can read a standard, answer a security questionnaire, or talk to an auditor without guessing what a word means.

Clear definitions also matter for AI search. When someone asks an assistant what a Statement of Applicability is, or what a BAA covers, the engine looks for a short, accurate, self-contained answer to cite. Each entry here is written to be exactly that. It leads with a direct definition, then adds the context that makes the term useful.

How the glossary is organized

The terms are grouped into categories, from core concepts that recur everywhere to vocabulary specific to a single framework. Each definition links to the related terms around it, so you can follow a thread — for example, from a risk assessment to a risk register to a risk treatment plan. Where a term maps to a framework we cover, the page also points to the relevant guide and the editable policy templates.

We keep the glossary focused on component concepts, such as an ISMS, a Statement of Applicability, a BAA, or a DPIA. For an overview of a whole framework, start with the framework guides instead.

How to use it

Use the glossary in three ways. Look up a term you have hit in a standard, a contract, or a questionnaire. Browse a category to learn the vocabulary of a framework before you start. Or follow the related-term links to see how the parts of a compliance program fit together. Every definition is free to read, with no sign-up.

When a term sends you toward building the actual document, the toolkits provide editable, framework-aligned templates you can tailor. The glossary explains the concept; the toolkit gives you the starting draft. Neither replaces operating the controls, which is what compliance ultimately requires.

Security operations

The day-to-day practices that keep data safe: access control, monitoring, incident response, and recovery.

Audit & certification

How independent assurance works — the audits, reports, and evidence that turn a program into a certificate or attestation.

ISO 27001 & 42001

Terms specific to the ISO management-system standards for information security (27001) and AI (42001).

SOC 2

The vocabulary of a SOC 2 examination — the Trust Services Criteria, report types, and the CPA attestation.

AI governance & NIST CSF

Terms for governing AI systems and managing cybersecurity risk under the NIST frameworks.

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.