Knowledge base
Clear words for complex work.
Definitions are written for orientation. Where a formal standard defines a term, use the authoritative source for contractual or certification decisions.
A to Z
95 working definitions.
- Access control
- Rules and checks that determine who may use information or systems.
- Action owner
- The person accountable for carrying out an agreed action.
- Adverse event
- An occurrence that caused harm or could reasonably have caused harm.
- AI impact assessment
- A structured review of who may be affected by an AI system and how.
- AI inventory
- A record of AI systems, purposes, owners and status.
- Amendment
- A published change that applies to a standard without replacing its edition.
- Appeal
- A request to review a decision under a defined process.
- Aspect
- An element of activity that can interact with the environment.
- Asset
- Something of value that an organisation needs to protect or manage.
- Assurance
- Confidence supported by evidence that arrangements work as intended.
- Audit
- A systematic, objective review against stated criteria.
- Audit criteria
- The policies, requirements or other references used for an audit.
- Audit evidence
- Verifiable information relevant to audit criteria.
- Baseline
- A reference point against which later performance is compared.
- Benchmark
- A defined comparison point, with scope and method made clear.
- Bias
- A systematic tendency that can distort a decision or result.
- Bottleneck
- A point that limits the flow or capacity of a process.
- Business case
- A reasoned account of expected value, cost, risk and alternatives.
- Business continuity
- The ability to continue priority activities during disruption.
- Business impact analysis
- A structured study of disruption consequences and recovery priorities.
- Capability
- The combined people, process, information and resources needed to perform work.
- Capacity
- The amount of work a system can handle under stated conditions.
- Change control
- A way to assess, approve, implement and review changes.
- Climate action amendment
- A 2024 change asking management systems to consider climate relevance in context.
- Compliance obligation
- A requirement an organisation must or chooses to meet.
- Competence
- Demonstrated ability to apply knowledge and skills in a role.
- Conflict of interest
- A competing interest that could affect objective judgement.
- Continual improvement
- Recurring work to improve suitability, adequacy or effectiveness.
- Control
- An arrangement that changes risk or helps achieve an outcome.
- Corrective action
- Action that addresses a cause to prevent a problem recurring.
- Customer journey
- The sequence of interactions a customer experiences.
- Data lineage
- A record of where data came from and how it changed.
- Decision log
- A traceable record of decisions, reasons, owners and dates.
- Dependency
- A person, system, supplier or resource needed for an activity.
- Document control
- Arrangements that keep information suitable, available and protected.
- Due diligence
- Proportionate investigation before a relationship or decision.
- Effectiveness
- The extent to which intended results are achieved.
- Energy baseline
- A quantified reference for comparing energy performance.
- Energy performance indicator
- A measure used to track energy performance.
- Environmental impact
- A change to the environment resulting from an activity.
- Evidence level
- A label describing the strength and nature of support for a claim.
- Exception
- A departure from a rule or expected operating condition.
- Finding
- A conclusion drawn by comparing evidence against criteria.
- Gap analysis
- A comparison between current practice and a defined target.
- Governance
- The arrangements for direction, accountability and oversight.
- Hazard
- A source or situation with potential to cause harm.
- Hierarchy of controls
- A priority order for reducing exposure to hazards.
- Human oversight
- Meaningful human ability to understand and intervene in a system.
- Incident
- An event that disrupted, harmed or could have harmed an outcome.
- Information asset
- Information and its supporting resources that have value.
- Internal audit
- An audit conducted for the organisation’s own assurance and improvement.
- Interested party
- A person or organisation that can affect or be affected by a decision.
- Key performance indicator
- A defined measure used to inform an important decision.
- Knowledge graph
- Records and explicit relationships that connect concepts and evidence.
- Lead indicator
- A measure that may signal future performance.
- Lesson learned
- An insight from evidence that leads to a practical change.
- Management review
- Leadership review of system performance and needed decisions.
- Materiality
- The importance of an issue to a defined decision or audience.
- Maturity
- The extent to which an approach is established and effective.
- Metadata
- Structured information describing a record and its provenance.
- Mitigation
- Action taken to reduce the likelihood or effect of a risk.
- Nonconformity
- A failure to meet a stated requirement.
- Objective
- A result an organisation intends to achieve.
- Operating model
- How people, processes, technology and governance deliver value.
- Opportunity
- A possibility that could lead to a beneficial outcome.
- Outcome measure
- A measure of the result produced, beyond activity counts.
- Process
- Connected activities that transform inputs into outputs.
- Process owner
- The person responsible for a process and its performance.
- Provenance
- Information showing where a claim or item came from.
- Quality objective
- A defined result relating to product, service or process quality.
- Rate limit
- A control on how often an action or request may occur.
- Recovery time objective
- A target time for restoring an activity after disruption.
- Residual risk
- Risk remaining after treatment or controls.
- Research limitation
- A condition that narrows what findings can reasonably show.
- Risk
- The effect of uncertainty on an objective.
- Risk appetite
- The amount and type of risk an organisation is willing to take.
- Risk register
- A record of risks, owners, responses and review decisions.
- Root cause
- An underlying condition whose change can prevent recurrence.
- Scope
- The boundaries of a system, project, review or claim.
- Source brief
- Original analysis that links to and distinguishes its underlying source.
- Source record
- Metadata describing an originating publication or dataset.
- Stakeholder
- A person or group with an interest in an activity or outcome.
- Statement of applicability
- A recorded rationale for selecting or excluding security controls.
- Supplier evaluation
- A proportionate assessment of supplier fit and performance.
- Surveillance
- A periodic review after an initial assessment or decision.
- System boundary
- The limits of a system and its interfaces.
- Taxonomy
- A structured set of categories used to organise information.
- Traceability
- The ability to follow an item or decision through its history.
- Transition plan
- Actions and dates for moving from one standard edition or system state to another.
- Validation
- Evidence that something is suitable for its intended use.
- Verification
- Evidence that stated requirements or conditions have been met.
- Version history
- A record of material changes to an item over time.
- Waste
- Effort or resources that do not contribute to the intended outcome.
- Watchlist
- A selected set of topics or records to monitor for change.
- Worker consultation
- Involvement of workers in understanding and improving work conditions.