For reading and citing with clarity.
Terms for reading about auditing, ISO systems, AI, public evidence and integrity without getting lost in jargon. Each definition includes usage and a citable reference.
0–9 1 term
- §5.2 ISO/IEC 17021-1 Auditing · professional practice Normative definition also · Clause 5.2 · §5.2 · Auditor–implementer separation
-
A clause of ISO/IEC 17021-1 relating to impartiality and conflicts of interest in management system certification bodies. The separation between consultancy, implementation and certification auditing must be strictly managed, including time restrictions where applicable.
A 7 terms
- Corrective action Auditing · professional practice Operational definition
-
Action intended to eliminate the cause of a nonconformity and prevent its recurrence. Correcting the immediate effect is not enough when the cause remains within the system.
- AI Management System · AIMS Artificial intelligence Operational definition also · AI management system · AIMS
-
A documented system of processes, resources and responsibilities for an organisation to manage the artificial intelligence it develops, provides or uses. Its structure is defined by ISO/IEC 42001:2023.
- Declared scope Core concepts Author's definition
-
A clear boundary for a piece: what it covers and what it leaves out. Without that boundary, readers do not know how far they can use the text.
Every serious piece of work needs to state its scope. This is not a decorative legal disclaimer: it is an honest way of saying what was examined, what it is useful for and where another discussion begins.
- Annex A Management systems · ISO Normative definition
-
The normative list of controls accompanying ISO/IEC 27001. The 2022 version contains 93 controls grouped into four categories. The organisation must justify the inclusion or exclusion of each control in its statement of applicability (SoA).
- AI Auditor Artificial intelligence Operational definition
-
A professional competent to audit an AI management system within a defined scope. Experience in other management systems contributes method, but does not in itself demonstrate competence in AI, data or algorithmic impacts.
- Audit Auditing · professional practice Operational definition
-
An independent, documented process for obtaining evidence and comparing it with defined criteria. Taken seriously: method, criteria and independence.
- Continuous auditing Core concepts Author's definition
-
An audit that follows the pace of the system, not just the calendar. It does not mean auditing more out of habit: it means looking when the system changes.
An annual review may fall short for systems that change every few weeks. Continuous auditing does not replace everything: it adds signals, change-triggered reviews and evidence that enables timely examination.
C 5 terms
- Root cause Auditing · professional practice Operational definition also · Root cause · RCA
-
A cause that explains why the system allowed a nonconformity, beyond its immediate manifestation. There may be several concurrent causes; the analysis must substantiate them with evidence.
The five whys can start the search, but they do not replace proof. The analysis ends when the organisation can link a verifiable cause to the observed failure and design an action capable of changing that condition.
Example Acting on the apparent cause (the operator) predicts recurrence; acting on the system cause prevents it.
- Technical Trust Core concepts Author's definition
-
Trust that does not depend on reputation alone. It rests on evidence, clear limits and someone who takes responsibility for what they assert.
It serves to examine what lies behind an important statement. It does not replace a certification, an audit or a standard: it helps ask what proof exists, who signs and how far the statement extends.
- Cooling-off period Auditing · professional practice Normative definition also · Cooling-off period
-
A restriction period between a consultancy or implementation service and a certification audit of the same system. It protects the impartiality of the process when there is a risk of reviewing one's own work or a prior interest.
- Opportunity cost of corruption Government and public integrity Operational definition
-
Private productive investment that does not take place in jurisdictions perceived as corrupt. The magnitude varies by country and method; sourced estimates are compiled in the report on corruption and economic cost.
- The Auditor's Judgement Core concepts Author's definition
-
A short text signed by Fernando Arrieta. It helps structure a difficult discussion about auditing, evidence, governance or institutions.
D 1 term
- DPIA Artificial intelligence Regulatory definition also · Data Protection Impact Assessment · Privacy impact assessment
-
A prior assessment of the impact that a processing operation may have on the protection of personal data. Article 35 of the GDPR requires it where processing is likely to pose a high risk to individuals' rights and freedoms.
E 5 terms
- The map is not the territory Core concepts Author's definition also · Korzybski · Map–territory distinction
-
A useful auditing principle: the document represents the operation, but does not capture it fully. Auditing means examining the gap between what is written and what happens.
The documentation of a management system is the map. Actual operations are the territory. The auditor's job is to examine that distance and say where the written system stopped resembling the system as experienced.
Example An IT security policy may state that access reviews take place quarterly. The actual technical record may show that reviews occur every nine months. The policy is the map. The technical record is the territory.
- Compliance standard Government and public integrity Operational definition
-
An explicit, documented criterion against which an organisation's performance is measured. If it changes or emerges after the results have been observed, the comparison is no longer reproducible.
- EU AI Act Artificial intelligence Regulatory definition also · European AI Regulation · Regulation EU 2024/1689
-
A European regulation establishing prohibitions, obligations for certain high-risk systems and transparency duties. Its application is phased; the specific scope depends on the system, its use and each organisation's role.
- Objective evidence Auditing · professional practice Operational definition
-
Information whose truth can be demonstrated through observation, measurement, records or other means. The auditor assesses its relevance, sufficiency and relationship to the applicable criterion.
- Operational evidence Core concepts Author's definition
-
Evidence arising from actual operations, not from paperwork prepared for an audit. A dated delivery can be evidence; an unused procedure cannot.
Operational evidence exists before the audit. It is the trace an organisation leaves as it works. A mature system produces it naturally; an off-the-shelf system manufactures it late and in bulk.
F 2 terms
- Technical sign-off Core concepts Author's definition
-
The act of putting one's own name behind a technical claim. The signatory does not merely appear: they take responsibility for what they have said.
Example "Whoever signs stands behind it. Whoever stands behind it signs." Technical responsibility is not decorative.
- Statement of judgement Core concepts Author's definition
-
A short, quotable idea that captures the core of a piece without making it impersonal.
Example "When a system exists only to sustain a certificate, it is not a system. It is decoration."
G 2 terms
- Global ACI / MRA Management systems · ISO Institutional reference also · Global Accreditation Cooperation Incorporated · Global ACI · Global ACI MRA · Multilateral Recognition Arrangement · GLOBAC
-
An international accreditation organisation that, since 1 January 2026, integrates the functions previously performed by IAF and ILAC. Its official name is Global Accreditation Cooperation Incorporated and its official acronym is Global ACI; the working name GLOBAC, used during the transition, was replaced by the official brand in April 2026. Its MRA (Multilateral Recognition Arrangement) seeks to maintain international recognition of accredited conformity assessment results.
- Algorithmic governance Artificial intelligence Operational definition
-
The set of practices, controls, responsibilities and verification mechanisms through which an organisation governs the algorithmic systems it develops, provides or uses. Its design must keep pace with the system's actual rate of change.
H 2 terms
- Finding Auditing · professional practice Operational definition
-
The result of comparing evidence against a criterion. A finding states which requirement applies, what was found and what the gap is. It needs no adjectives.
- Human-in-the-loop Artificial intelligence Operational definition also · HITL · Human in the loop · Human oversight
-
A design in which a person intervenes within an AI system's decision flow. Oversight is effective when there is real authority to act, sufficient information and traceability of the intervention.
The presence of a signature or an approval screen does not demonstrate oversight. It is necessary to examine whether the person can stop or modify the outcome, which cases they review, what information they use and what record they leave. The adequacy of the control depends on the risk and the use.
Example In a credit assessment system, human review is nominal if no one can modify the outcome or if the sample lacks a defined basis. It is effective when the role, the ability to intervene and the record can be demonstrated.
I 10 terms
- IAF MLA Management systems · ISO Institutional reference also · International Accreditation Forum Multilateral Recognition Arrangement
-
The historical multilateral agreement of the International Accreditation Forum. Since 1 January 2026, it should be read as a transitional reference integrated into the Global ACI / MRA architecture, which unifies the functions previously performed by IAF and ILAC.
- Impartiality Auditing · professional practice Normative definition
-
Transparency plus active management of conflicts of interest. Auditors declare their ties and manage them explicitly. ISO/IEC 17021-1 sets out this requirement for bodies that audit and certify management systems.
- Institutional integrity Government and public integrity Operational definition
-
The ability of a public or private organisation to maintain consistency between what it states, what it decides and how it operates. It is reflected in the available evidence, traceability and accountability.
- ISO 19011 Management systems · ISO Normative definition
-
An international standard providing guidelines for auditing management systems. The current edition is ISO 19011:2026 (4th edition, published in May 2026). It maintains and strengthens the risk-based approach already included among the principles of the 2018 edition, and updates the guidance for contexts such as remote audits and virtual locations. It is guidance; it does not in itself impose certification obligations.
- ISO 37001 Management systems · ISO Normative definition also · ISO 37001:2025 · ISO 37001:2016 · Anti-bribery
-
An international standard for anti-bribery management systems. The current edition, ISO 37001:2025, applies to public, private and non-profit organisations. Its effectiveness depends on the quality of implementation, not on the existence of a certificate.
- ISO 9001 Management systems · ISO Normative definition also · ISO 9001:2015 · Quality management
-
An international standard for quality management systems. It defines the requirements for an organisation to demonstrate its ability to provide products and services that meet customer and applicable requirements.
- ISO/IEC 17021-1 Management systems · ISO Normative definition
-
A standard containing principles and requirements for the competence, consistency and impartiality of bodies that audit and certify management systems. It provides the basis for assessing how a body manages independence, conflicts of interest and certification rigour.
- ISO/IEC 27001 Management systems · ISO Normative definition also · ISO 27001 · ISO/IEC 27001:2022 · ISMS
-
An international requirements standard for information security management systems (ISMS). The 2022 edition contains 93 reference controls in Annex A, grouped into organisational, people, physical and technological themes.
- ISO/IEC 27701 Management systems · ISO Normative definition also · ISO 27701 · Privacy Information Management
-
A privacy information management system (PIMS) standard. In its ISO/IEC 27701:2025 edition, it is standalone and independently certifiable: it is no longer described as an extension of ISO/IEC 27001, although it integrates well with an existing ISMS. Certificates issued under the 2019 edition transition to the 2025 edition.
- ISO/IEC 42001 Management systems · ISO Normative definition also · ISO 42001 · AIMS · AI Management System
-
The first international standard for artificial intelligence management systems (AI Management System, AIMS), published in December 2023. It enables certification of an AI management system within a defined scope; it does not certify overall AI maturity or the responsibility of each individual model.
L 3 terms
- Technical analysis Core concepts Author's definition
-
A signed review of a technical topic. It states what was examined, which sources were used and what falls outside its scope. It is not a verdict: it helps people make better decisions.
Example A report examines a public claim and shows that the evidence cited is insufficient. That is a technical analysis: signed, bounded in scope and citable.
- Declared limitations Core concepts Author's definition
-
The part where a piece states what it does not cover. It is not a legal formality: it is a way of not claiming more than can be substantiated.
Example "This report is a technical analysis of publicly available evidence at the time of writing. It does not constitute a regulatory audit or an official decision." That is a declared limitation.
- What is claimed is demonstrated Core concepts Author's definition
-
A central principle of this site: a serious claim needs an actor, a date, a criterion, a scope and a validity period. When these elements are missing, the statement loses traceability.
It governs the entire body of work. In auditing, a technical claim needs those components. In management systems, a certificate states that a system was assessed at a particular time and against specific criteria. In AI, saying "our system is responsible" is not enough without explaining who is accountable, against what criteria and until when.
M 2 terms
- ISO Maturity Model Management systems · ISO Author's definition
-
An interpretive framework covering documentary, declarative, partial, operational and systemic maturity. It measures the gap between what is certified and what is actually operational.
- AI system mutability Artificial intelligence Operational definition also · Algorithmic mutability · Model mutability
-
The ability of an AI system to change its behaviour or its relevant evidence after an assessment. This may arise from model updates, configuration adjustments, new data or drift in the user population.
Mutability is not necessarily a defect. It requires recording versions, defining reassessment triggers and detecting when the system in operation no longer corresponds to the system that was examined.
N 3 terms
- NIST AI RMF Artificial intelligence Operational definition also · NIST AI Risk Management Framework
-
A voluntary framework from the United States National Institute of Standards and Technology for managing AI risks. It organises the work into four functions: govern, map, measure and manage.
- Major nonconformity Auditing · professional practice Operational definition also · Major NC
-
An operational classification for a nonconformity that compromises the system's ability to achieve its intended results. The precise criterion and its effect on certification depend on the applicable standard, scheme and rules.
- Minor nonconformity Auditing · professional practice Operational definition also · Minor NC
-
An operational classification for a limited nonconformity that does not, on its own, compromise the system's overall capability. It also requires action; its time frames and effects depend on the applicable scheme.
R 4 terms
- Operational accountability Government and public integrity Operational definition
-
The practice of explaining decisions, responsible parties, criteria and results through documented evidence. It enables review of what was decided and on what basis.
- Identifiable responsible party Core concepts Author's definition
-
A specific person, with a name and role, who can explain a claim, a decision or a system. The opposite of hiding everything behind "the organisation".
- Model risk Artificial intelligence Operational definition
-
The possibility that a model may produce inappropriate results and cause significant consequences. Its assessment considers data, performance, context of use, changes in production and the human capacity to intervene.
- ROPA Artificial intelligence Regulatory definition also · Record of Processing Activities · Record of processing activities
-
A record of personal data processing activities under the responsibility of a controller or processor. Article 30 of the GDPR defines its content and provides for exceptions that must be assessed on a case-by-case basis.
S 5 terms
- Decorative system Core concepts Author's definition also · Certificate theatre
-
A management system designed to maintain a certificate, not to help people work better. It may look orderly and fail when operations put it to the test.
The problem is not just the template. It is the intent. Management wants the certificate, but not the system. The same symptom tends to recur: complete documents, different operations and responsible parties who do not use the procedures.
- Deterministic system Artificial intelligence Operational definition
-
A system whose output is determined by its input and configured rules: under the same conditions, it produces the same result. Many generative systems are stochastic and require a different assessment approach.
The distinction changes the audit. A deterministic rule can be tested with expected cases; a stochastic system requires samples, metrics and distribution analysis. In both cases, version, configuration and context must be controlled.
Example A calculator is deterministic under a fixed configuration. A generative model may respond differently to the same prompt; its evaluation cannot rely on a single output.
- Off-the-shelf system Core concepts Author's definition also · Generic implementation template
-
A system built from templates or documents copied from another organisation. It may pass an initial audit, but it fails when a real problem arises.
It emerges because it seems faster and cheaper. The problem comes later: the procedure describes how another organisation works, not how the certified organisation works.
Example It can be recognised because the documentation describes how another organisation operates, not the organisation itself; the gap with actual operations becomes apparent at the first incident.
- Overpricing in public procurement Government and public integrity Operational definition
-
An unjustified difference between the price paid in public procurement and a comparable market reference. To substantiate it, specifications, quantities, conditions, dates and associated costs must be compared.
- Underprovision of public services Government and public integrity Operational definition
-
The gap between the level of public service promised and that actually delivered. It may have budgetary, operational or integrity-related causes; attributing it requires specific evidence, not perception alone.
T 5 terms
- Auditable telemetry Auditing · professional practice Operational definition
-
Records that the system generates while operating and that an auditor can review without waiting for the annual visit.
- Tailor-made system Core concepts Author's definition also · Tailored management system · Contextual implementation
-
A management system built around how an organisation actually works. Its documentation structures what already happens or should happen there, not in an imaginary company.
It usually takes more work at the outset, but is put to better use afterwards. The team can follow the procedures because they match their actual practices.
- Fiscal transparency Government and public integrity Operational definition
-
Structured, traceable publication of budget execution data. Its quality depends on timeliness, granularity, integrity and the ability to link each data item to a decision or transaction.
- Triangulation Auditing · professional practice Operational definition also · Evidence triangulation · Cross-verification
-
A professional practice that checks a claim against independent sources, such as records, observation and interviews. The number and combination required depend on the risk and the subject being audited.
When sources agree, the conclusion gains support. When they differ, the discrepancy is also evidence: it requires expanding the sample, reviewing the criteria or reformulating the question before closing a finding.
Example A finding is supported when the same claim is confirmed by mutually independent sources; when they differ, the discrepancy is itself information.
- Trigger-based verification Auditing · professional practice Operational definition also · Event-based verification
-
Verification triggered when something important changes: a model, data, a supplier or a rule of use. It replaces a calendar-based approach with an event-based one.
V 2 terms
- Effectiveness verification Auditing · professional practice Operational definition
-
Documented verification that a corrective action produced the expected result and reduced the likelihood of recurrence. Closing a task does not, on its own, demonstrate that the system has changed.
- Human verifier Core concepts Author's definition
-
A person who remains responsible even when using a machine for assistance. The model assists; the human reviews, decides and signs.