A sourced reference index for the language of AI governance, privacy, cybersecurity, risk, and independent assurance. AuditDIFF separates plain-language explanations from legal, regulatory, standards, and other authoritative terminology.
A management system for establishing policies, objectives, processes, responsibilities, and continual improvement related to the responsible development, provision, or use of AI systems.
Why it matters: An AIMS turns AI governance from a collection of separate policies into an organized management system with defined responsibilities, processes, monitoring, and improvement.
Information an auditor uses to evaluate whether a requirement or control is actually satisfied.
Why it matters: Policies and statements may describe what should happen. Evidence helps an auditor determine what was implemented and whether it operated as expected.
A California regulatory term for technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking.
Why it matters: California attaches specific transparency and consumer-right requirements to qualifying uses of ADMT.
Under California's CCPA regulations, a cybersecurity audit is the annual audit required for a business whose processing of consumers' personal information presents significant risk to consumers' security under the applicable regulation.
Why it matters: The California requirement introduces defined scope, independence, evidence, reporting, and certification expectations for businesses that meet the regulatory threshold.
A ForHumanity governance concept for deliberately incorporating people with varied lived experiences, backgrounds, cultures, perspectives, skills, expertise, protected categories, and intersectionalities into risk input, evaluation, and assessment across the system lifecycle.
Why it matters: Governance decisions can miss material impacts when they rely on a narrow set of perspectives.
Evaluation performed with sufficient independence from the activity being assessed to provide credible confidence in the result.
Why it matters: Independence helps separate an organization's own claims about its program from an external evaluation of evidence against defined criteria.
ISO/IEC 42001:2023 is an international management system standard that specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system.
Why it matters: It gives organizations a structured management-system approach for governing AI-related risks, responsibilities, objectives, controls, monitoring, and continual improvement.
A meaningful change to covered processing that creates new negative impacts, increases an existing impact, or makes a safeguard less effective.
Why it matters: A material change can trigger an update to a CCPA risk assessment as soon as feasible and no later than 45 calendar days after the change.
A set of intergovernmental principles and policy recommendations intended to support innovative and trustworthy AI that respects human rights and democratic values.
Why it matters: The principles provide a widely recognized policy baseline for human-centered AI and have influenced AI governance approaches across jurisdictions and organizations.
Under the CCPA, personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household.
Why it matters: Whether information falls within the CCPA definition can determine which privacy duties, rights, notices, contracts, and safeguards apply.
A structured assessment used to understand how a project or system handles personal information, identify privacy risks, and document decisions or safeguards.
Why it matters: A PIA can surface privacy issues before deployment and create a record of how risks and design choices were considered.
A broad governance concept for developing, deploying, and using AI in ways that address risks such as safety, security, accountability, transparency, privacy, fairness, reliability, and harmful bias.
Why it matters: Responsible AI gives organizations a way to connect technical performance with human, organizational, legal, and societal impacts.
A decision with important consequences for a person in areas the California regulations specify, such as financial services, housing, education, employment, or healthcare.
Why it matters: Using ADMT to make a significant decision is one of the activities that can trigger California risk-assessment and ADMT requirements.
ForHumanity terminology for the defined subject and boundary of an evaluation, including the data processing operation and relevant AAA System components that the certification plan will assess.
Why it matters: An audit needs a clear boundary. If the target is ambiguous, evidence, responsibility, and conclusions can become ambiguous too.