Glossary

The risk & compliance lexicon.

Plain-English definitions for the 48 terms that run through enterprise risk, security and compliance — from Value at Risk to the EU AI Act, each cross-linked to the module that operationalises it.

This glossary defines the core vocabulary of enterprise risk management, security and regulatory compliance in clear, jargon-free language. Search for a term or jump to a letter — every entry links to related concepts and to the GeneSecure modules where it is put into practice.

A

AI Governance

AI Governance

AI governance is the framework of policies, controls and oversight that keeps AI systems safe, fair, explainable and compliant. For regulated enterprises it extends model risk management to cover AI-specific risks — drift, bias, hallucination, autonomy — guided by frameworks like the NIST AI RMF, ISO/IEC 42001 and the EU AI Act.

Attack Path

Cyber Defense

An attack path is the chain of steps — across assets, identities, permissions and network connections — by which an attacker could move from an initial entry point to a high-value target. Analysing attack paths lets defenders find and cut the few links that would block many routes to their crown-jewel systems, which is far more efficient than patching vulnerabilities in isolation.

B

Basel III

Banking Regulation

Basel III is the international regulatory framework from the Basel Committee on Banking Supervision that strengthens bank capital, leverage and liquidity requirements after the 2008 crisis. It raises the quantity and quality of capital banks must hold, introduces liquidity ratios (LCR and NSFR), and includes the 'Basel III endgame' reforms that refine credit, operational and market-risk capital.

Business Continuity

Operational Resilience

Business continuity is an organisation's capability to keep delivering critical operations during and after a disruption. A business continuity plan documents the people, processes, technology and recovery objectives needed to stay within acceptable downtime and data-loss tolerances through severe events.

C

Contractual Service Margin (CSM)

Insurance

The Contractual Service Margin is the unearned profit embedded in a group of insurance contracts under IFRS 17. It sits on the balance sheet at inception and is released to the income statement as the insurer provides coverage, ensuring profit is recognised over time rather than up front.

Control

Governance

A control is a process, policy or technical measure that reduces the likelihood or impact of a risk. Controls are classified as preventive, detective or corrective, and their design and operating effectiveness are tested during audits and compliance assessments such as SOC 2.

COSO ERM

Governance

The COSO Enterprise Risk Management framework is a widely used model that integrates risk management with strategy and performance across five components and twenty principles. It helps organisations embed risk thinking into governance, objective-setting and decision-making rather than treating it as a standalone compliance exercise.

Cyber Risk Quantification

Cybersecurity

Cyber risk quantification is the practice of expressing cyber exposure in financial terms — the probable monetary loss from threats — rather than qualitative red-amber-green ratings. Methods such as FAIR let security and finance leaders prioritise investment and compare cyber risk against other enterprise risks on a common dollar basis.

D

Detection Engineering

Cyber Defense

Detection engineering is the discipline of building, testing and tuning the rules and analytics that turn raw security telemetry into meaningful alerts. Modern practice treats detections as versioned content — often expressed in a portable format such as Sigma — with a test harness, measured MITRE ATT&CK coverage and a tuning lifecycle to keep false positives in check.

E

Effective Challenge

Model Risk

Effective challenge is the critical analysis of a model by objective, competent parties who are independent of its development and have the authority and incentive to push back. It is the principle in SR 11-7 that makes validation meaningful rather than a rubber stamp.

EPSS (Exploit Prediction Scoring System)

Cyber Defense

EPSS is an open, data-driven model that estimates the probability a given vulnerability will be exploited in the near term, expressed as a percentage. Used alongside CVSS severity and the KEV catalog, it helps teams focus remediation on the small fraction of vulnerabilities most likely to actually be attacked, rather than treating every 'critical' equally.

EU AI Act

AI Governance

The EU AI Act is the European Union's comprehensive, risk-tiered law governing artificial intelligence. It prohibits unacceptable-risk uses, imposes strict obligations on high-risk systems such as many in credit and insurance, sets duties for general-purpose AI models, and phases in over a multi-year timeline.

Expected Shortfall (ES)

Market Risk

Expected Shortfall, also called Conditional VaR, is the average loss in the worst-case tail beyond the Value at Risk threshold. Because it measures the depth of the tail rather than a single cut-off point, it captures extreme losses better than VaR and is the risk measure mandated under the FRTB market-risk framework.

Exposure Management (CTEM)

Cyber Defense

Continuous Threat Exposure Management (CTEM) is a programme for continuously discovering, prioritising and reducing an organisation's exploitable attack surface. Rather than a periodic scan, it correlates asset inventory, vulnerabilities, identities and exploitability signals to answer which exposures could actually be reached and used — and validates that remediation genuinely reduces risk.

F

FAIR (Factor Analysis of Information Risk)

Cyber Defense

FAIR is the leading open standard for quantifying cyber and operational risk in financial terms. It decomposes a risk into loss event frequency and loss magnitude, expresses the factors as calibrated ranges, and runs a Monte Carlo simulation to produce an annualised loss distribution — so cyber risk can be prioritised in dollars alongside every other enterprise risk.

FRTB

Market Risk

The Fundamental Review of the Trading Book is the Basel Committee's overhaul of market-risk capital. It replaces VaR with Expected Shortfall, hardens the boundary between the trading and banking books, and offers a sensitivities-based Standardised Approach alongside an approval-gated Internal Models Approach with non-modellable risk factor charges.

G

GRC

Governance

Governance, Risk and Compliance is an integrated approach to aligning an organisation's governance structures, risk management and regulatory compliance. A GRC platform unifies risk registers, controls, policies, audits and obligations so the three disciplines reinforce each other rather than operating in silos.

I

IFRS 17

Insurance

IFRS 17 is the global accounting standard for insurance contracts, effective from 2023, that measures insurance liabilities at current value and releases profit over the coverage period through the Contractual Service Margin. It replaced the inconsistent practices allowed under IFRS 4, making insurers' financial statements far more comparable.

IFRS 9

Credit Risk

IFRS 9 is the international accounting standard for financial instruments, whose impairment section introduces a forward-looking expected-credit-loss model staged by changes in credit risk. It is the international counterpart to the US CECL standard, though the two differ in mechanics such as IFRS 9's 12-month versus lifetime loss staging.

Internal Audit

Governance

Internal audit is the independent assurance function that evaluates the effectiveness of an organisation's governance, risk management and control processes. As the 'third line' in the three-lines model, it reports to the board and audit committee and provides objective challenge separate from the business and risk functions.

ISO 27001

Compliance

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) — a risk-based framework of policies and controls for protecting information. Organisations can be independently certified against it, and it is often mapped alongside SOC 2 and NIST CSF to satisfy multiple requirements with one control set.

ISO 31000

Governance

ISO 31000 is the international standard providing principles and guidelines for risk management applicable to any organisation. Rather than prescribing controls, it sets out a framework and process — establishing context, assessing, treating, monitoring and communicating risk — that can be tailored to any sector.

K

Key Risk Indicator (KRI)

Risk Management

A Key Risk Indicator is a metric that provides early warning of rising risk exposure, such as a spike in failed transactions or a control nearing its threshold. KRIs are tracked against defined limits so teams can act before a risk materialises into a loss or breach.

Known Exploited Vulnerabilities (KEV)

Cyber Defense

The KEV catalog is a list, maintained by the US Cybersecurity and Infrastructure Security Agency (CISA), of vulnerabilities confirmed to be actively exploited in the wild. Because a vulnerability on the KEV list is being used by real attackers, it is a powerful prioritisation signal — patching KEV entries on exposed, critical assets typically matters far more than chasing a high CVSS score alone.

L

Loss Given Default (LGD)

Credit Risk

Loss Given Default is the share of an exposure an institution expects to lose if a borrower defaults, after accounting for collateral and recoveries. Expressed as a percentage, it combines with the Probability of Default and Exposure at Default to produce an expected-loss estimate.

M

MITRE ATT&CK

Cyber Defense

MITRE ATT&CK is a globally-adopted knowledge base of adversary tactics and techniques observed in real-world attacks, organised across the stages of an intrusion. Security teams use it to measure detection coverage, map where they can and cannot see an attacker, and prioritise new detection content against the techniques most relevant to their threat model.

Model Validation

Model Risk

Model validation is the set of independent activities that verify a model is sound and performing as intended. Under SR 11-7 it covers conceptual soundness, ongoing monitoring (benchmarking and process verification) and outcomes analysis (back-testing), carried out by parties independent of model development.

Monte Carlo Simulation

Quantitative Methods

Monte Carlo simulation estimates the range of possible outcomes by running a model thousands or millions of times with randomly sampled inputs. In risk it is used to build loss distributions for VaR, price complex derivatives, and project capital and reserves under uncertainty, producing a full distribution rather than a single point estimate.

N

NIST Cybersecurity Framework

Cybersecurity

The NIST Cybersecurity Framework is a voluntary set of standards and best practices for managing cyber risk, organised around the functions Govern, Identify, Protect, Detect, Respond and Recover. Widely adopted across industries, it provides a common language for assessing and improving cybersecurity posture.

O

OCSF (Open Cybersecurity Schema Framework)

Cyber Defense

OCSF is an open, vendor-neutral standard for representing security events and findings in a common structure. Normalising telemetry from different tools onto an OCSF-aligned model lets detections and queries be written once and run across every source, and means swapping an underlying tool does not break the analytics built on top.

Operational Risk

Risk Management

Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. It spans fraud, system outages, human error, legal and compliance failures and disruption, and is increasingly governed through operational-resilience regimes like CPS 230 and DORA.

P

Probability of Default (PD)

Credit Risk

Probability of Default is the estimated likelihood that a borrower or counterparty will fail to meet its obligations over a given horizon. Together with Loss Given Default and Exposure at Default, it is a building block of expected-loss credit models used for provisioning under CECL and IFRS 9 and for regulatory capital.

R

Risk Appetite

Risk Management

Risk appetite is the amount and type of risk an organisation is willing to take to pursue its objectives, set by the board and expressed through limits and tolerances. It translates strategy into boundaries that guide day-to-day decisions and signal when exposure needs escalation.

S

Scenario Analysis

Risk Management

Scenario analysis examines the impact of specific hypothetical situations — a pandemic, a cyberattack, a supplier failure — on an organisation's risk profile and operations. Unlike statistical risk measures it is narrative and forward-looking, making it a core tool for operational resilience, business continuity and emerging-risk assessment.

SOC 2

Compliance

SOC 2 is an AICPA auditing framework that reports on a service organisation's controls relevant to security, availability, processing integrity, confidentiality and privacy. A Type I report assesses control design at a point in time, while a Type II report tests operating effectiveness over a period, and it is widely required by enterprise buyers.

Solvency Capital Requirement (SCR)

Insurance

The Solvency Capital Requirement is the amount of capital a Solvency II insurer must hold to withstand a 1-in-200-year loss over one year. It can be computed with the regulator's standard formula or an insurer's own approved internal model, and falling below it triggers escalating supervisory intervention.

Solvency II

Insurance

Solvency II is the European Union's prudential regime for insurers, built on three pillars: risk-based capital requirements (Pillar 1), governance and the Own Risk and Solvency Assessment (Pillar 2), and disclosure and reporting (Pillar 3). It requires insurers to hold capital calibrated to a 99.5% one-year confidence level, calculated via a standard formula or an approved internal model.

SR 11-7

Model Risk

SR 11-7 is 2011 US supervisory guidance from the Federal Reserve and OCC that defines expectations for model risk management at banks. It rests on three pillars — robust development and use, effective independent validation, and sound governance including a model inventory — and has become the de facto global standard for model governance.

Stress Testing

Quantitative Methods

Stress testing evaluates how a portfolio, balance sheet or institution would perform under severe but plausible adverse scenarios — such as a market crash, recession or rate shock. Regulators use mandated stress tests (like CCAR) to assess capital adequacy, while firms run their own scenarios to understand vulnerabilities that normal risk measures may miss.

T

Third-Party Risk

Risk Management

Third-party risk is the exposure an organisation inherits from vendors, suppliers and service providers, including the fourth parties those providers depend on. Managing it involves due diligence, ongoing monitoring, contractual safeguards and concentration analysis — obligations now reinforced by regimes such as CPS 230 and DORA.

V

Value at Risk (VaR)

Market Risk

Value at Risk estimates the maximum loss a portfolio is expected to suffer over a set horizon at a given confidence level — for example, a one-day 99% VaR of $5M means losses should exceed $5M on only about 1 in 100 days. Its weakness is that it says nothing about how severe losses become once that threshold is breached, which is why regulators increasingly favour Expected Shortfall.

Want the full story behind a term?

Our guides go deeper on the frameworks behind these definitions — FRTB, DORA, CPS 230, SR 11-7, CECL and AI governance.

Read the guides

Turn the vocabulary into a working system.

Book a walkthrough and see how GeneSecure operationalises these concepts — on one governed data fabric with a fully auditable trail.

Risk Management Glossary — VaR, Basel III & More Explained | GeneSecure