Reference

Glossary

A sourced reference index for the language of AI governance, privacy, cybersecurity, risk, and independent assurance. AuditDIFF separates plain-language explanations from legal, regulatory, standards, and other authoritative terminology.

Find a Term

Topic
Authority

Reference index

Terms

17 terms

A

Industry UsageAI Governance

AI Governance

The structures, roles, decision processes, controls, and oversight an organization uses to govern AI systems across their lifecycle.

Why it matters: AI governance connects technical systems to accountability, risk decisions, evidence, and oversight.

View Full Entry
Standard TerminologyAI GovernanceStandards

Artificial Intelligence Management System (AIMS)

A management system for establishing policies, objectives, processes, responsibilities, and continual improvement related to the responsible development, provision, or use of AI systems.

Why it matters: An AIMS turns AI governance from a collection of separate policies into an organized management system with defined responsibilities, processes, monitoring, and improvement.

View Full Entry
Audit & AssuranceAudit & Assurance

Audit Evidence

Information an auditor uses to evaluate whether a requirement or control is actually satisfied.

Why it matters: Policies and statements may describe what should happen. Evidence helps an auditor determine what was implemented and whether it operated as expected.

View Full Entry
Regulatory DefinitionAutomated DecisionsPrivacyAI Governance

Automated Decisionmaking Technology (ADMT)

A California regulatory term for technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking.

Why it matters: California attaches specific transparency and consumer-right requirements to qualifying uses of ADMT.

View Full Entry

C

Regulatory DefinitionCybersecurityAudit & AssurancePrivacy

Cybersecurity Audit

Under California's CCPA regulations, a cybersecurity audit is the annual audit required for a business whose processing of consumers' personal information presents significant risk to consumers' security under the applicable regulation.

Why it matters: The California requirement introduces defined scope, independence, evidence, reporting, and certification expectations for businesses that meet the regulatory threshold.

View Full Entry

D

ForHumanity TermAI GovernanceRisk

Diverse Inputs and Multi-Stakeholder Feedback (DIMSF)

A ForHumanity governance concept for deliberately incorporating people with varied lived experiences, backgrounds, cultures, perspectives, skills, expertise, protected categories, and intersectionalities into risk input, evaluation, and assessment across the system lifecycle.

Why it matters: Governance decisions can miss material impacts when they rely on a narrow set of perspectives.

View Full Entry

I

Audit & AssuranceAudit & AssuranceAI Governance

Independent Assurance

Evaluation performed with sufficient independence from the activity being assessed to provide credible confidence in the result.

Why it matters: Independence helps separate an organization's own claims about its program from an external evaluation of evidence against defined criteria.

View Full Entry
International StandardAI GovernanceStandardsAudit & Assurance

ISO/IEC 42001

ISO/IEC 42001:2023 is an international management system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system.

Why it matters: It gives organizations a structured management-system approach for governing AI-related risks, responsibilities, objectives, controls, monitoring, and continual improvement.

View Full Entry

M

California CCPA RegulationPrivacyRiskGovernance

Material Change

A meaningful change to covered processing that creates new negative impacts, increases an existing impact, or makes a safeguard less effective.

Why it matters: A material change can trigger an update to a CCPA risk assessment as soon as feasible and no later than 45 calendar days after the change.

View Full Entry

N

California CCPA RegulationPrivacyRisk

Negative Impact

A harmful consequence that processing personal information may create for a consumer.

Why it matters: A CCPA risk assessment must identify relevant negative impacts and weigh privacy risks against the benefits of the processing.

View Full Entry

O

Intergovernmental PrinciplesAI GovernanceResponsible AIStandards

OECD AI Principles

A set of intergovernmental principles and policy recommendations intended to support innovative and trustworthy AI that respects human rights and democratic values.

Why it matters: The principles provide a widely recognized policy baseline for human-centered AI and have influenced AI governance approaches across jurisdictions and organizations.

View Full Entry

P

Legal DefinitionPrivacyData Governance

Personal Information (PI)

Under the CCPA, personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household.

Why it matters: Whether information falls within the CCPA definition can determine which privacy duties, rights, notices, contracts, and safeguards apply.

View Full Entry
Industry UsagePrivacyRisk

Privacy Impact Assessment (PIA)

A structured assessment used to understand how a project or system handles personal information, identify privacy risks, and document decisions or safeguards.

Why it matters: A PIA can surface privacy issues before deployment and create a record of how risks and design choices were considered.

View Full Entry

R

Industry UsageAI GovernanceResponsible AIRisk

Responsible AI

A broad governance concept for developing, deploying, and using AI in ways that address risks such as safety, security, accountability, transparency, privacy, fairness, reliability, and harmful bias.

Why it matters: Responsible AI gives organizations a way to connect technical performance with human, organizational, legal, and societal impacts.

View Full Entry
Industry UsageRiskAI GovernancePrivacy

Risk Assessment

A structured process for identifying relevant risks, evaluating their significance, and documenting decisions about treatment or acceptance.

Why it matters: Risk assessments turn broad governance concerns into explicit decisions that can be reviewed, monitored, and evidenced.

View Full Entry

S

California CCPA RegulationPrivacyAutomated DecisionsRisk

Significant Decision

A decision with important consequences for a person in areas the California regulations specify, such as financial services, housing, education, employment, or healthcare.

Why it matters: Using ADMT to make a significant decision is one of the activities that can trigger California risk-assessment and ADMT requirements.

View Full Entry

T

ForHumanity TermAudit & AssuranceAI Governance

Target of Evaluation (ToE)

ForHumanity terminology for the defined subject and boundary of an evaluation, including the data processing operation and relevant AAA System components that the certification plan will assess.

Why it matters: An audit needs a clear boundary. If the target is ambiguous, evidence, responsibility, and conclusions can become ambiguous too.

View Full Entry