--- title: Glossary description: "Plain-language glossary of AI governance and AI risk-audit terms — AIMS, GPAI, FRIA, HITL, AI-SBOM, model cards, Three Lines of Defence, TLPT, risk thresholds and more." keywords: "AI governance glossary, AI risk auditing terms, AIMS, GPAI, FRIA, HITL, AI-SBOM, model card, Three Lines of Defence, TLPT, ISO 31000, NIST AI RMF terms" --- # Glossary Key terms used across the library, in plain language (our own words, not normative definitions). Each links back to the standard that uses it. - **Agentic AI** — AI that plans, calls tools, holds memory and takes autonomous, multi-step actions — not just text replies. See [CSA Agentic Profile](reference_csa_agentic_profile.md). - **AIMS (AI Management System)** — the organisation-wide framework that [ISO/IEC 42001](reference_iso_42001.md) certifies. - **AI-SBOM** — an "AI bill of materials": the inventory of models, datasets and components an AI system is built from. - **Annex III (EU AI Act)** — the list of use cases that make a system *high-risk*. See [EU AI Act](reference_eu_ai_act.md). - **CETS 225** — the Council of Europe Framework Convention on AI (2024), the first binding international AI treaty; binds states, not companies, and is not yet in force. See [Council of Europe AI Convention](reference_coe_ai_convention.md). - **Conformity assessment** — the check (internal or by a notified body) that a high-risk system meets the EU AI Act before it goes to market. - **Cyber uplift** — how much an AI model increases an attacker's capability. See [Berkeley CLTC](reference_berkeley_cltc.md). - **FRIA** — Fundamental Rights Impact Assessment, required of certain deployers of high-risk systems (EU AI Act, Art. 27). - **GOVERN · MAP · MEASURE · MANAGE** — the four functions of the [NIST AI RMF](reference_nist_ai_rmf.md). - **GPAI** — a general-purpose AI model, with its own EU AI Act duties (transparency, copyright, training-data summary). - **HITL (Human-in-the-Loop)** — keeping a human in (or on) the loop of an AI decision; only effective if it can actually change the outcome. - **ICT third-party risk** — risk from outside tech / AI / cloud providers a financial firm depends on. Central to [DORA](reference_dora.md). - **Intolerable risk** — a level of risk that should be prevented outright, not merely managed. See [Berkeley CLTC](reference_berkeley_cltc.md). - **ISO 31000** — the general (non-AI) risk-management standard that [ISO/IEC 23894](reference_iso_23894.md) builds on. - **Model card** — short structured documentation of a model's purpose, data, performance and limitations. - **Oversight theatre** — human oversight that exists on paper but cannot actually stop the system. See [CSA Agentic Profile](reference_csa_agentic_profile.md). - **Profile (NIST)** — a tailored selection of a framework for a specific context (e.g. the GenAI Profile). - **Residual risk** — the risk that remains after treatment, which someone must formally accept. - **Risk source** — the origin of a risk (e.g. training data, model opacity); [ISO/IEC 23894](reference_iso_23894.md) Annex B lists AI-specific ones. - **Risk threshold** — a defined trigger point that, once crossed, demands a specific response. - **SC 42 (ISO/IEC JTC 1/SC 42)** — the subcommittee that writes the international AI standards (42001, 23894, 42005, 42006 …). - **Statement of Applicability (SoA)** — the documented list of which controls an organisation applies, and why (ISO/IEC 42001). - **Three Lines of Defence** — a governance model: the business owns risk (1st line), risk & compliance oversee it (2nd), internal audit assures it (3rd). - **TLPT (Threat-Led Penetration Testing)** — advanced, intelligence-led resilience testing required of significant entities under [DORA](reference_dora.md). - **Trustworthy AI** — NIST's set of characteristics: valid & reliable, safe, secure & resilient, accountable & transparent, explainable & interpretable, privacy-enhanced, and fair (with harmful bias managed).