Auditor's glossary

For reading and citing with clarity.

Terms for reading about auditing, ISO systems, AI, public evidence and integrity without getting lost in jargon. Each definition includes usage and a citable reference.

0–9 1 term

§5.2 ISO/IEC 17021-1 Auditing · professional practice Normative definition also · Clause 5.2 · §5.2 · Auditor–implementer separation

A clause of ISO/IEC 17021-1 relating to impartiality and conflicts of interest in management system certification bodies. The separation between consultancy, implementation and certification auditing must be strictly managed, including time restrictions where applicable.

A 7 terms

Corrective action Auditing · professional practice Operational definition

Action intended to eliminate the cause of a nonconformity and prevent its recurrence. Correcting the immediate effect is not enough when the cause remains within the system.

AI Management System · AIMS Artificial intelligence Operational definition also · AI management system · AIMS

A documented system of processes, resources and responsibilities for an organisation to manage the artificial intelligence it develops, provides or uses. Its structure is defined by ISO/IEC 42001:2023.

Declared scope Core concepts Author's definition

A clear boundary for a piece: what it covers and what it leaves out. Without that boundary, readers do not know how far they can use the text.

Every serious piece of work needs to state its scope. This is not a decorative legal disclaimer: it is an honest way of saying what was examined, what it is useful for and where another discussion begins.

Annex A Management systems · ISO Normative definition

The normative list of controls accompanying ISO/IEC 27001. The 2022 version contains 93 controls grouped into four categories. The organisation must justify the inclusion or exclusion of each control in its statement of applicability (SoA).

AI Auditor Artificial intelligence Operational definition

A professional competent to audit an AI management system within a defined scope. Experience in other management systems contributes method, but does not in itself demonstrate competence in AI, data or algorithmic impacts.

Audit Auditing · professional practice Operational definition

An independent, documented process for obtaining evidence and comparing it with defined criteria. Taken seriously: method, criteria and independence.

Continuous auditing Core concepts Author's definition

An audit that follows the pace of the system, not just the calendar. It does not mean auditing more out of habit: it means looking when the system changes.

An annual review may fall short for systems that change every few weeks. Continuous auditing does not replace everything: it adds signals, change-triggered reviews and evidence that enables timely examination.

C 5 terms

Root cause Auditing · professional practice Operational definition also · Root cause · RCA

A cause that explains why the system allowed a nonconformity, beyond its immediate manifestation. There may be several concurrent causes; the analysis must substantiate them with evidence.

The five whys can start the search, but they do not replace proof. The analysis ends when the organisation can link a verifiable cause to the observed failure and design an action capable of changing that condition.

Example Acting on the apparent cause (the operator) predicts recurrence; acting on the system cause prevents it.

Technical Trust Core concepts Author's definition

Trust that does not depend on reputation alone. It rests on evidence, clear limits and someone who takes responsibility for what they assert.

It serves to examine what lies behind an important statement. It does not replace a certification, an audit or a standard: it helps ask what proof exists, who signs and how far the statement extends.

Cooling-off period Auditing · professional practice Normative definition also · Cooling-off period

A restriction period between a consultancy or implementation service and a certification audit of the same system. It protects the impartiality of the process when there is a risk of reviewing one's own work or a prior interest.

Opportunity cost of corruption Government and public integrity Operational definition

Private productive investment that does not take place in jurisdictions perceived as corrupt. The magnitude varies by country and method; sourced estimates are compiled in the report on corruption and economic cost.

The Auditor's Judgement Core concepts Author's definition

A short text signed by Fernando Arrieta. It helps structure a difficult discussion about auditing, evidence, governance or institutions.

D 1 term

DPIA Artificial intelligence Regulatory definition also · Data Protection Impact Assessment · Privacy impact assessment

A prior assessment of the impact that a processing operation may have on the protection of personal data. Article 35 of the GDPR requires it where processing is likely to pose a high risk to individuals' rights and freedoms.

E 5 terms

The map is not the territory Core concepts Author's definition also · Korzybski · Map–territory distinction

A useful auditing principle: the document represents the operation, but does not capture it fully. Auditing means examining the gap between what is written and what happens.

The documentation of a management system is the map. Actual operations are the territory. The auditor's job is to examine that distance and say where the written system stopped resembling the system as experienced.

Example An IT security policy may state that access reviews take place quarterly. The actual technical record may show that reviews occur every nine months. The policy is the map. The technical record is the territory.

Compliance standard Government and public integrity Operational definition

An explicit, documented criterion against which an organisation's performance is measured. If it changes or emerges after the results have been observed, the comparison is no longer reproducible.

EU AI Act Artificial intelligence Regulatory definition also · European AI Regulation · Regulation EU 2024/1689

A European regulation establishing prohibitions, obligations for certain high-risk systems and transparency duties. Its application is phased; the specific scope depends on the system, its use and each organisation's role.

Objective evidence Auditing · professional practice Operational definition

Information whose truth can be demonstrated through observation, measurement, records or other means. The auditor assesses its relevance, sufficiency and relationship to the applicable criterion.

Operational evidence Core concepts Author's definition

Evidence arising from actual operations, not from paperwork prepared for an audit. A dated delivery can be evidence; an unused procedure cannot.

Operational evidence exists before the audit. It is the trace an organisation leaves as it works. A mature system produces it naturally; an off-the-shelf system manufactures it late and in bulk.

F 2 terms

Technical sign-off Core concepts Author's definition

The act of putting one's own name behind a technical claim. The signatory does not merely appear: they take responsibility for what they have said.

Example "Whoever signs stands behind it. Whoever stands behind it signs." Technical responsibility is not decorative.

Statement of judgement Core concepts Author's definition

A short, quotable idea that captures the core of a piece without making it impersonal.

Example "When a system exists only to sustain a certificate, it is not a system. It is decoration."

G 2 terms

Global ACI / MRA Management systems · ISO Institutional reference also · Global Accreditation Cooperation Incorporated · Global ACI · Global ACI MRA · Multilateral Recognition Arrangement · GLOBAC

An international accreditation organisation that, since 1 January 2026, integrates the functions previously performed by IAF and ILAC. Its official name is Global Accreditation Cooperation Incorporated and its official acronym is Global ACI; the working name GLOBAC, used during the transition, was replaced by the official brand in April 2026. Its MRA (Multilateral Recognition Arrangement) seeks to maintain international recognition of accredited conformity assessment results.

Algorithmic governance Artificial intelligence Operational definition

The set of practices, controls, responsibilities and verification mechanisms through which an organisation governs the algorithmic systems it develops, provides or uses. Its design must keep pace with the system's actual rate of change.

H 2 terms

Finding Auditing · professional practice Operational definition

The result of comparing evidence against a criterion. A finding states which requirement applies, what was found and what the gap is. It needs no adjectives.

Human-in-the-loop Artificial intelligence Operational definition also · HITL · Human in the loop · Human oversight

A design in which a person intervenes within an AI system's decision flow. Oversight is effective when there is real authority to act, sufficient information and traceability of the intervention.

The presence of a signature or an approval screen does not demonstrate oversight. It is necessary to examine whether the person can stop or modify the outcome, which cases they review, what information they use and what record they leave. The adequacy of the control depends on the risk and the use.

Example In a credit assessment system, human review is nominal if no one can modify the outcome or if the sample lacks a defined basis. It is effective when the role, the ability to intervene and the record can be demonstrated.

I 10 terms

IAF MLA Management systems · ISO Institutional reference also · International Accreditation Forum Multilateral Recognition Arrangement

The historical multilateral agreement of the International Accreditation Forum. Since 1 January 2026, it should be read as a transitional reference integrated into the Global ACI / MRA architecture, which unifies the functions previously performed by IAF and ILAC.

Impartiality Auditing · professional practice Normative definition

Transparency plus active management of conflicts of interest. Auditors declare their ties and manage them explicitly. ISO/IEC 17021-1 sets out this requirement for bodies that audit and certify management systems.

Institutional integrity Government and public integrity Operational definition

The ability of a public or private organisation to maintain consistency between what it states, what it decides and how it operates. It is reflected in the available evidence, traceability and accountability.

ISO 19011 Management systems · ISO Normative definition

An international standard providing guidelines for auditing management systems. The current edition is ISO 19011:2026 (4th edition, published in May 2026). It maintains and strengthens the risk-based approach already included among the principles of the 2018 edition, and updates the guidance for contexts such as remote audits and virtual locations. It is guidance; it does not in itself impose certification obligations.

ISO 37001 Management systems · ISO Normative definition also · ISO 37001:2025 · ISO 37001:2016 · Anti-bribery

An international standard for anti-bribery management systems. The current edition, ISO 37001:2025, applies to public, private and non-profit organisations. Its effectiveness depends on the quality of implementation, not on the existence of a certificate.

ISO 9001 Management systems · ISO Normative definition also · ISO 9001:2015 · Quality management

An international standard for quality management systems. It defines the requirements for an organisation to demonstrate its ability to provide products and services that meet customer and applicable requirements.

ISO/IEC 17021-1 Management systems · ISO Normative definition

A standard containing principles and requirements for the competence, consistency and impartiality of bodies that audit and certify management systems. It provides the basis for assessing how a body manages independence, conflicts of interest and certification rigour.

ISO/IEC 27001 Management systems · ISO Normative definition also · ISO 27001 · ISO/IEC 27001:2022 · ISMS

An international requirements standard for information security management systems (ISMS). The 2022 edition contains 93 reference controls in Annex A, grouped into organisational, people, physical and technological themes.

ISO/IEC 27701 Management systems · ISO Normative definition also · ISO 27701 · Privacy Information Management

A privacy information management system (PIMS) standard. In its ISO/IEC 27701:2025 edition, it is standalone and independently certifiable: it is no longer described as an extension of ISO/IEC 27001, although it integrates well with an existing ISMS. Certificates issued under the 2019 edition transition to the 2025 edition.

ISO/IEC 42001 Management systems · ISO Normative definition also · ISO 42001 · AIMS · AI Management System

The first international standard for artificial intelligence management systems (AI Management System, AIMS), published in December 2023. It enables certification of an AI management system within a defined scope; it does not certify overall AI maturity or the responsibility of each individual model.

L 3 terms

Technical analysis Core concepts Author's definition

A signed review of a technical topic. It states what was examined, which sources were used and what falls outside its scope. It is not a verdict: it helps people make better decisions.

Example A report examines a public claim and shows that the evidence cited is insufficient. That is a technical analysis: signed, bounded in scope and citable.

Declared limitations Core concepts Author's definition

The part where a piece states what it does not cover. It is not a legal formality: it is a way of not claiming more than can be substantiated.

Example "This report is a technical analysis of publicly available evidence at the time of writing. It does not constitute a regulatory audit or an official decision." That is a declared limitation.

What is claimed is demonstrated Core concepts Author's definition

A central principle of this site: a serious claim needs an actor, a date, a criterion, a scope and a validity period. When these elements are missing, the statement loses traceability.

It governs the entire body of work. In auditing, a technical claim needs those components. In management systems, a certificate states that a system was assessed at a particular time and against specific criteria. In AI, saying "our system is responsible" is not enough without explaining who is accountable, against what criteria and until when.

M 2 terms

ISO Maturity Model Management systems · ISO Author's definition

An interpretive framework covering documentary, declarative, partial, operational and systemic maturity. It measures the gap between what is certified and what is actually operational.

AI system mutability Artificial intelligence Operational definition also · Algorithmic mutability · Model mutability

The ability of an AI system to change its behaviour or its relevant evidence after an assessment. This may arise from model updates, configuration adjustments, new data or drift in the user population.

Mutability is not necessarily a defect. It requires recording versions, defining reassessment triggers and detecting when the system in operation no longer corresponds to the system that was examined.

N 3 terms

NIST AI RMF Artificial intelligence Operational definition also · NIST AI Risk Management Framework

A voluntary framework from the United States National Institute of Standards and Technology for managing AI risks. It organises the work into four functions: govern, map, measure and manage.

Major nonconformity Auditing · professional practice Operational definition also · Major NC

An operational classification for a nonconformity that compromises the system's ability to achieve its intended results. The precise criterion and its effect on certification depend on the applicable standard, scheme and rules.

Minor nonconformity Auditing · professional practice Operational definition also · Minor NC

An operational classification for a limited nonconformity that does not, on its own, compromise the system's overall capability. It also requires action; its time frames and effects depend on the applicable scheme.

R 4 terms

Operational accountability Government and public integrity Operational definition

The practice of explaining decisions, responsible parties, criteria and results through documented evidence. It enables review of what was decided and on what basis.

Identifiable responsible party Core concepts Author's definition

A specific person, with a name and role, who can explain a claim, a decision or a system. The opposite of hiding everything behind "the organisation".

Model risk Artificial intelligence Operational definition

The possibility that a model may produce inappropriate results and cause significant consequences. Its assessment considers data, performance, context of use, changes in production and the human capacity to intervene.

ROPA Artificial intelligence Regulatory definition also · Record of Processing Activities · Record of processing activities

A record of personal data processing activities under the responsibility of a controller or processor. Article 30 of the GDPR defines its content and provides for exceptions that must be assessed on a case-by-case basis.

S 5 terms

Decorative system Core concepts Author's definition also · Certificate theatre

A management system designed to maintain a certificate, not to help people work better. It may look orderly and fail when operations put it to the test.

The problem is not just the template. It is the intent. Management wants the certificate, but not the system. The same symptom tends to recur: complete documents, different operations and responsible parties who do not use the procedures.

Deterministic system Artificial intelligence Operational definition

A system whose output is determined by its input and configured rules: under the same conditions, it produces the same result. Many generative systems are stochastic and require a different assessment approach.

The distinction changes the audit. A deterministic rule can be tested with expected cases; a stochastic system requires samples, metrics and distribution analysis. In both cases, version, configuration and context must be controlled.

Example A calculator is deterministic under a fixed configuration. A generative model may respond differently to the same prompt; its evaluation cannot rely on a single output.

Off-the-shelf system Core concepts Author's definition also · Generic implementation template

A system built from templates or documents copied from another organisation. It may pass an initial audit, but it fails when a real problem arises.

It emerges because it seems faster and cheaper. The problem comes later: the procedure describes how another organisation works, not how the certified organisation works.

Example It can be recognised because the documentation describes how another organisation operates, not the organisation itself; the gap with actual operations becomes apparent at the first incident.

Overpricing in public procurement Government and public integrity Operational definition

An unjustified difference between the price paid in public procurement and a comparable market reference. To substantiate it, specifications, quantities, conditions, dates and associated costs must be compared.

Underprovision of public services Government and public integrity Operational definition

The gap between the level of public service promised and that actually delivered. It may have budgetary, operational or integrity-related causes; attributing it requires specific evidence, not perception alone.

T 5 terms

Auditable telemetry Auditing · professional practice Operational definition

Records that the system generates while operating and that an auditor can review without waiting for the annual visit.

Tailor-made system Core concepts Author's definition also · Tailored management system · Contextual implementation

A management system built around how an organisation actually works. Its documentation structures what already happens or should happen there, not in an imaginary company.

It usually takes more work at the outset, but is put to better use afterwards. The team can follow the procedures because they match their actual practices.

Fiscal transparency Government and public integrity Operational definition

Structured, traceable publication of budget execution data. Its quality depends on timeliness, granularity, integrity and the ability to link each data item to a decision or transaction.

Triangulation Auditing · professional practice Operational definition also · Evidence triangulation · Cross-verification

A professional practice that checks a claim against independent sources, such as records, observation and interviews. The number and combination required depend on the risk and the subject being audited.

When sources agree, the conclusion gains support. When they differ, the discrepancy is also evidence: it requires expanding the sample, reviewing the criteria or reformulating the question before closing a finding.

Example A finding is supported when the same claim is confirmed by mutually independent sources; when they differ, the discrepancy is itself information.

Trigger-based verification Auditing · professional practice Operational definition also · Event-based verification

Verification triggered when something important changes: a model, data, a supplier or a rule of use. It replaces a calendar-based approach with an event-based one.

V 2 terms

Effectiveness verification Auditing · professional practice Operational definition

Documented verification that a corrective action produced the expected result and reduced the likelihood of recurrence. Closing a task does not, on its own, demonstrate that the system has changed.

Human verifier Core concepts Author's definition

A person who remains responsible even when using a machine for assistance. The model assists; the human reviews, decides and signs.

WhatsApp G-CERTI