Glossary
A shared language for the work.
Explore the concepts behind enterprise AI, governance, security and delivery. Find a working definition, see an illustrative example and follow the idea into a practical resource.

From meaning to practice
Find the term you need
Use these explanations in a working discussion. They provide a starting point; your organisation’s definitions and responsibilities should be recorded in the context of its own processes.
Acceptance criteria
The agreed conditions used to decide whether a piece of work is ready for its intended use. Useful criteria describe observable behaviour and the evidence a reviewer needs to make the decision.
A policy assistant returns a relevant approved source, respects the user’s permissions and provides a clear next step when no answer is available.
Access control
The rules and mechanisms that determine which people or systems may view information or perform an action. A workflow needs those rules enforced across the application, its sources and connected tools.
An employee can search documents available to their team while a restricted case file remains unavailable to retrieval.
AI evaluation
A defined process for assessing an AI system against tasks, criteria and expected behaviour relevant to its intended use. It includes limitations and failure cases as well as successful responses.
Reviewers check routine questions, conflicting sources, unanswered questions and attempts to retrieve material outside a user’s permissions.
Audit trail
A record of relevant events and changes that helps an authorised reviewer understand what happened, when it happened and which person or system performed it. Its usefulness depends on the scope and detail recorded.
A reviewer can see the original submission, a request for clarification, the revised evidence and the final decision.
Control
An activity or mechanism intended to address a requirement or risk. The control description, accountable owner, evidence of operation and assessment of its effectiveness are related but distinct records.
A designated owner reviews application access for an agreed population and period, then tracks required changes.
Control owner
The role accountable for a control within an agreed scope. The owner needs clarity about performance, review, exceptions and escalation, even when other people carry out individual steps.
A system owner ensures the access review has assigned reviewers and resolves questions about an overdue submission.
Data lineage
Information about where data originated and how it moved or changed before reaching a result. Lineage helps people relate a value, passage or report to its underlying sources and transformations.
An analyst can trace a dashboard value through a transformation to the source record and relevant reporting period.
Data minimisation
A design approach that limits collected or retained data to what is needed for a defined purpose. Teams should decide which information supports the workflow and avoid unnecessary copies or operational records.
An error report records a request identifier and failure category when copying an entire sensitive document is unnecessary for investigation.
Evidence
Information used to support an assessment or conclusion. Its relevance depends on the claim being assessed, the scope and period covered, and the method used to review it.
A list of access decisions and verified changes may support a review more directly than a message saying the task is complete.
Finding
A recorded observation or issue arising from an assessment. A useful finding explains the condition, supporting evidence, relevant scope and the decision or action it requires.
An assessment identifies an account that remained active after the agreed access decision and assigns a follow-up action.
Grounding
Using identified information to support a generated response. A grounded workflow still needs evaluation: the presence of a citation alone does not establish that each statement is supported or that the source is current.
An assistant links a policy passage so the reader can check the instruction and its source version.
Human oversight
Defined responsibility for reviewing, correcting, approving or stopping AI-assisted work. It requires enough context, authority and opportunity for a person to exercise the decision in practice.
Before an email is sent, a reviewer sees the actual recipient, message and attachments and can reject or revise the action.
Knowledge base
A selected collection of information used to support a particular audience or task. In an enterprise workflow, useful knowledge has identifiable sources, owners, versions and access rules.
An approved policy library supports employee questions while drafts and superseded instructions follow a separate treatment.
Least privilege
Giving a person or system the access needed for its assigned work, with a scope that can be understood and enforced. Review both the permitted operation and the information or records it can affect.
An assistant may prepare a draft for one approved record without receiving permission to update unrelated records.
Model
The component of an AI system that produces an output from an input using patterns learned during training. Its behaviour in a particular application also depends on the instructions, context, tools and surrounding workflow.
The same model may produce different results when it receives a different source passage or an instruction to format an answer for review.
Obligation
A requirement the organisation has determined applies within a defined scope. Its source, applicability and interpretation need appropriate review before they become the basis for control design or assessment.
A team records a relevant requirement, the business scope it covers and the controls selected to respond to it.
Prompt injection
An attempt to influence an AI application through instructions embedded in user input or material the application processes. It is relevant when untrusted content could alter the intended task or affect connected actions.
A retrieved document contains a request to disregard the application’s task and send information elsewhere.
Retrieval-augmented generation (RAG)
An approach that supplies a model with selected material retrieved from a knowledge source to inform its response. Source quality, retrieval relevance, permissions and answer support still need to be evaluated.
An assistant retrieves a relevant passage from an approved procedure before drafting an answer to an employee’s question.
Risk
Uncertainty that can affect the objectives a team or organisation is trying to achieve. A useful risk discussion defines the context, possible consequences, existing responses and the decision required.
Unclear source ownership creates uncertainty about whether an employee receives current guidance from a knowledge assistant.
Risk appetite
The types and amount of risk an organisation is willing to take in pursuit of its objectives. Applying it to work requires relevant criteria, responsibilities and a route for making decisions.
An organisation uses its agreed criteria to decide which unresolved exceptions need escalation to an authorised decision-maker.
Source register
A working record of the information selected for a workflow. It can identify each source’s purpose, owner, approval status, location, intended audience and the rules for updates or withdrawal.
A policy source has a named owner, a current version and a documented process for removing superseded content from retrieval.
Version history
A record of how an item changes over time. It helps a reviewer distinguish the current state from the material or configuration used for an earlier decision or assessment.
The team preserves the evaluation configuration used for release so later results can be compared with the same baseline.
Workflow
A defined sequence of activities and decisions that moves work from an initial trigger to an intended outcome. It includes responsibilities, inputs, outputs and the handling of exceptions.
A control assessment moves from assignment to evidence submission, review, action tracking and an agreed closure decision.
Workflow owner
The role accountable for the purpose and operation of a defined process. This role helps set boundaries, accepts the business outcome and resolves questions about how the workflow should behave.
A policy owner decides which questions an assistant should answer and which need a person to interpret an individual case.
No terms match your search
Try a broader term or select All terms to search the complete collection.
Put the definitions in context
Use the glossary alongside a practical guide or explainer so the terminology connects to a decision your team needs to make.
Definitions and examples are written for this resource. Explore our editorial approach or suggest a clarification.
