GRC & AI Governance Glossary

Plain-language answers to the terms that come up most when teams start evaluating GRC and AI governance software.

What is GRC (governance, risk, and compliance)?

GRC is the set of practices an organization uses to align its activities with business goals (governance), identify and manage uncertainty (risk), and meet legal, regulatory, and contractual obligations (compliance). Most organizations start doing all three in spreadsheets and email, then move to dedicated software once the number of frameworks, controls, and stakeholders makes that unmanageable.

A GRC platform centralizes this work: a risk register, a control library, evidence collection, and framework mapping in one place instead of scattered documents.

See how AssuranceGrid structures GRC →

What is a risk register?

A risk register is a structured record of the risks an organization has identified, along with each risk's likelihood, potential impact, owner, and mitigation status. It's the foundation most risk management programs are built on, since reporting, heat maps, and remediation tracking all depend on risks being documented in one consistent place.

AssuranceGrid's risk register tracks inherent vs. residual risk on a 5x5 heat map, so you can see which risks controls have actually brought down and which still need attention.

See the risk register →

What is a control library?

A control library is a catalog of the safeguards, policies, and processes an organization has in place to manage its risks and satisfy compliance requirements. Well-run control libraries map a single control to every framework it satisfies, so one access-review control can count toward SOC 2, ISO 27001, and HIPAA at once instead of being tracked three separate times.

This is where most of the manual duplication in compliance work comes from, and it's the first thing a control library should eliminate.

How AssuranceGrid maps controls across frameworks →

What is AI governance?

AI governance is the set of policies, oversight, and controls an organization uses to manage the risks introduced by AI systems, such as models making consequential decisions, agents taking autonomous actions, or vendor AI tools operating without visibility. It typically includes an inventory of AI systems in use, risk classification, human oversight requirements, and enforcement policies for how AI is allowed to behave.

AI governance is increasingly treated as an extension of GRC rather than a separate discipline, particularly as regulations like the EU AI Act apply directly to it.

Take the free EU AI Act readiness assessment →

What is ISO 42001?

ISO/IEC 42001 is the first international standard for an AI management system (AIMS), published in December 2023. It sets certifiable requirements for how an organization governs AI across its lifecycle: risk management, data and third-party AI dependencies, human oversight, and continuous monitoring, similar in structure to how ISO 27001 governs information security.

It's voluntary, but enterprise customers and procurement teams are increasingly asking vendors about it directly, the same way SOC 2 became a default ask a decade ago. AssuranceGrid's Operational Trust model, described in the Governance Debt whitepaper, is built to align with ISO 42001's requirements alongside the NIST AI RMF.

See how ISO 42001 maps to Operational Trust →

What is the EU AI Act?

The EU AI Act is the European Union's regulation governing the development and use of AI systems, based on a tiered risk classification: prohibited, high-risk, limited, and minimal. It applies to organizations that place AI systems on the EU market or whose AI outputs are used in the EU, regardless of where the organization is headquartered, with obligations phasing in from February 2025 through the high-risk deadlines of December 2027 and August 2028.

Most organizations start by inventorying their AI systems and classifying each one against these risk tiers, since every other obligation depends on that.

Check your EU AI Act readiness →

Who does the EU AI Act apply to?

The Act reaches four roles: providers who develop or place AI systems on the EU market, deployers who use AI systems professionally within the EU, and importers and distributors who bring AI systems into the EU market. It also applies to any provider or deployer outside the EU whose AI system's output is used by people in the EU, even with no EU entity, staff, or office — the same extraterritorial reach GDPR established for data.

Most companies underestimate their exposure by assuming physical presence is required. If your product, chatbot, or hiring tool touches an EU customer or candidate, the Act can apply to you regardless of where you're incorporated.

Check whether — and how — the Act applies to you →

When do the Act's obligations apply, and what do violations cost?

Where the timeline actually stands
Feb 2, 2025
Prohibited practices banned; Article 4 AI literacy required
Aug 2, 2025
Governance rules and general-purpose AI (GPAI) model obligations apply
Aug 2, 2026
Transparency rules (Article 50) and remaining general provisions apply — where we are now
Dec 2, 2027
High-risk Annex III systems (biometrics, employment, critical infrastructure) come into force
Aug 2, 2028
High-risk AI embedded in regulated products (Annex I) comes into force

High-risk dates reflect the 2026 Digital Omnibus deferral: the Council gave final approval on June 29, 2026, pushing Annex III obligations from Aug 2026 to Dec 2027. Article 50 transparency and Article 4 AI literacy duties were left untouched.

What non-compliance costs
Prohibited practices
Up to €35M or 7% of global turnover
High-risk breaches & other violations
Up to €15M or 3% of global turnover
Incorrect or misleading information to authorities
Up to €7.5M or 1% of global turnover

These ceilings exceed GDPR's, and apply regardless of whether your organization has any EU presence.

Check your own readiness against these deadlines →

What is continuous compliance?

Continuous compliance is the practice of maintaining evidence of compliance on an ongoing basis, rather than reconstructing it in the weeks before an audit. It relies on automated evidence collection from the systems where the work actually happens, such as identity providers, cloud infrastructure, and code repositories, instead of manual screenshots and spreadsheet updates.

AssuranceGrid connects directly to tools like GitHub, Okta, BambooHR, and AWS to collect this evidence automatically as controls run.

See how evidence connectors work →