Reference
Glossary
33 terms, defined the way a practitioner would explain them to a colleague — including the ones that mostly exist to be sold.
Where a term is contested or has been stretched by marketing, the entry says so. Where a term is genuinely useful, the entry says what it costs to actually do.
Practice
Continuous auditing
Assurance performed on a short, repeating cycle rather than annually — testing that re-runs as a definition instead of being rebuilt as a project each period.
Continuous controls monitoring (CCM)
Management's own automated, ongoing surveillance of whether its controls are operating — a first- and second-line activity, not an audit one.
IPE
Reports and data generated by the organisation being audited, which must be tested for completeness and accuracy before they can be relied on as evidence.
Key control
A control relied on to address a risk to the point that its failure would, on its own, mean the risk is not adequately mitigated.
Material weakness
The most severe classification of internal control deficiency — one where there is a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis.
PBC list
The list of documents an auditor asks the business to produce — an artifact that exists only because auditors historically could not reach the systems themselves.
Population testing
Testing every item in a population rather than a sample, which becomes the default once tests are executed by software against the system of record.
Sampling
Selecting a subset of a population to test, using the result to infer a conclusion about the whole — a workaround for human throughput that automation makes largely unnecessary.
Test of design (ToD)
An assessment of whether a control, if it operated as described, would actually prevent or detect the failure it is meant to address.
Test of operating effectiveness (ToE)
Evidence that a control actually operated as designed, at the required frequency, throughout the period — by whom, how consistently, and with what result.
Walkthrough
Tracing a single transaction end-to-end through a process to confirm the process works the way it is documented and the controls sit where they are said to sit.
Workpaper
The record of what was tested, how, and what was concluded — and, structurally, the single biggest determinant of whether audit work can be automated or re-run.
Technology
Agent-native GRC
Governance, risk and compliance software designed from the data model up so that software agents can do the work, with human approval built into the record rather than bolted on afterwards.
Agentic AI
AI systems that plan and carry out multi-step work using tools, rather than only producing text in response to a prompt.
Approval gate
A required, recorded human decision that stands between machine-performed work and the audit record.
Audit analytics
Applying queries, statistics and visualisation to full datasets to identify exceptions, patterns and risk — the bridge between sampling and genuinely continuous assurance.
Model Context Protocol (MCP)
An open protocol that lets an AI assistant discover and call the tools and data a system exposes — increasingly how audit systems make themselves usable by agents.
Supervised autonomy
An operating model where software agents execute audit work end-to-end but no conclusion becomes part of the record until a named human approves it.
Frameworks & standards
Control crosswalk
A mapping between the requirements of different frameworks, showing where one control satisfies obligations under several at once.
COSO Internal Control Framework
The internal control framework used by the overwhelming majority of SOX programmes, structured as five components and seventeen principles.
EU AI Act
The EU's risk-tiered regulation of AI systems, imposing obligations that scale from transparency duties to extensive conformity requirements for high-risk uses.
ISO/IEC 27001
The international standard for an information security management system, certified against by an accredited body, with 93 Annex A controls in the 2022 revision.
ISO/IEC 42001
The international standard for an artificial intelligence management system — the certifiable counterpart to ISO 27001 for organisations building or deploying AI.
ITGC
The controls over the IT environment that financial and operational controls depend on — access, change management, and operations — and the most commonly failed area in SOX programmes.
NIST Cybersecurity Framework 2.0
A voluntary framework organising cybersecurity outcomes into six functions — Govern, Identify, Protect, Detect, Respond, Recover — widely used as a common language between technical and board audiences.
SOC 2
An AICPA attestation report on a service organisation's controls against the Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy.
SOX 404
The Sarbanes-Oxley requirement that management assess, and (for accelerated filers) the external auditor attest to, the effectiveness of internal control over financial reporting.
Unified control
A single control definition satisfying requirements from several frameworks at once, so one test produces evidence for many obligations.
Governance
Audit universe
The full inventory of entities, processes, systems and risks that could be audited, from which the annual plan is selected.
QAIP
The IIA-required programme of internal and external assessments covering whether an internal audit function conforms to the Standards and operates effectively.
Risk appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives — and, when expressed properly, the input that sets audit cadence.
Three Lines Model
The IIA's model distinguishing management's ownership of risk (first line), its oversight functions (second line), and internal audit's independent assurance (third line).
Roles
Chief Audit Executive (CAE)
The person with overall responsibility for the internal audit function, reporting functionally to the board or audit committee and administratively to management.