Glossary

AI Compliance Glossary

Plain-English definitions of the terms that recur across AI governance, ISO 42001 certification and post-quantum evidence.

AI compliance has accumulated a vocabulary faster than it has accumulated shared meaning. The same term often means something slightly different to a security team, an auditor and a regulator. This glossary defines the terms as SecureGRC uses them, with each entry linking to the page that treats it in depth. Start here if you have hit a term in a comparison or guide and want the short version before the long one.

Terms in brief

ML-BOM (machine learning bill of materials)
A structured inventory of the components that make up an AI system — models, datasets, frameworks and their provenance — expressed in CycloneDX or SPDX. It is to an AI system what an SBOM is to a software build. Full guide →
ISO/IEC 42001
The first certifiable AI management system standard, published in 2023. It defines an auditable management system for AI, with Annex A controls covering the AI lifecycle. Full guide →
MITRE ATLAS
A knowledge base of adversarial tactics and techniques against machine learning systems, structured like ATT&CK. Mapping ATLAS tactics onto ISO 42001 control themes turns a threat model into a control obligation. See the crosswalk →
CRYSTALS-Dilithium (FIPS 204 / ML-DSA)
The NIST-standardised post-quantum digital signature algorithm. Signing compliance evidence with it means the signature remains verifiable even once a cryptographically relevant quantum computer exists. Why it matters →
Harvest-now-decrypt-later
The practice of capturing encrypted or signed data today in order to break it once quantum capability arrives. It is the reason long-lived audit evidence needs post-quantum signatures now rather than later. Full explanation →
Metadata-only architecture
An approach in which compliance is assessed from system metadata and declared configuration rather than by ingesting model weights or training data. It narrows what a vendor can see, and therefore what it can leak. Read the argument →

See it against your own AI systems

Request a demo and we will walk through an ML-BOM, a TCCE run and a signed evidence bundle for a system you actually operate.

Request a demo