Glossary
AI Compliance Glossary
Plain-English definitions of the terms that recur across AI governance, ISO 42001 certification and post-quantum evidence.
AI compliance has accumulated a vocabulary faster than it has accumulated shared meaning. The same term often means something slightly different to a security team, an auditor and a regulator. This glossary defines the terms as SecureGRC uses them, with each entry linking to the page that treats it in depth. Start here if you have hit a term in a comparison or guide and want the short version before the long one.
Terms in brief
- ML-BOM (machine learning bill of materials)
- A structured inventory of the components that make up an AI system — models, datasets, frameworks and their provenance — expressed in CycloneDX or SPDX. It is to an AI system what an SBOM is to a software build. Full guide →
- ISO/IEC 42001
- The first certifiable AI management system standard, published in 2023. It defines an auditable management system for AI, with Annex A controls covering the AI lifecycle. Full guide →
- MITRE ATLAS
- A knowledge base of adversarial tactics and techniques against machine learning systems, structured like ATT&CK. Mapping ATLAS tactics onto ISO 42001 control themes turns a threat model into a control obligation. See the crosswalk →
- CRYSTALS-Dilithium (FIPS 204 / ML-DSA)
- The NIST-standardised post-quantum digital signature algorithm. Signing compliance evidence with it means the signature remains verifiable even once a cryptographically relevant quantum computer exists. Why it matters →
- Harvest-now-decrypt-later
- The practice of capturing encrypted or signed data today in order to break it once quantum capability arrives. It is the reason long-lived audit evidence needs post-quantum signatures now rather than later. Full explanation →
- Metadata-only architecture
- An approach in which compliance is assessed from system metadata and declared configuration rather than by ingesting model weights or training data. It narrows what a vendor can see, and therefore what it can leak. Read the argument →
See it against your own AI systems
Request a demo and we will walk through an ML-BOM, a TCCE run and a signed evidence bundle for a system you actually operate.
Request a demo