Risk Glossary

ISO standards, regulations, risk terms, and key institutions — explained in plain language

200 terms
✦ Special FeatureWinners Consulting × 2026 US-EU Regulatory Research2026-04-13 Published

2026 US–EU Regulatory Keyword Dictionary

What is EU AI Act? How does DORA affect enterprises? Winners Consulting curates 51 core US-EU regulatory terms in Q&A format.

🤖 AI Governance🔐 Privacy📊 ERM🛡️ BCM🚗 Automotive💡 IP

Coverage:EU AI Act · DORA · NIS2 · CSRD · ISSB S1/S2 · UN R155/R156 · APRA · DTSA · ISO 42001 · ISO 27701 · ISO 22301 · ISO 56001

View Dictionary →
51
Key Terms
6
Themes
2
US · EU
🔍

200 terms

Key Institutions

CISA (Cybersecurity and Infrastructure Security Agency)

US federal agency under DHS responsible for cybersecurity and critical infrastructure protection

AUTO
Learn more →
ISO Standards

ISO 56001

International standard for Innovation Management Systems, helping organizations systematically manage innovation activities.

Learn more →
Risk Terms

Bow-Tie Risk Analysis

A structured risk analysis method displaying cause-and-effect relationships in bow-tie diagram format

Learn more →
Regulations

Cross-Border Privacy Rules (CBPR)

APEC's cross-border privacy certification mechanism corresponding to EU GDPR for Asia-Pacific region, enabling legal data transfer to US, Japan etc.

Learn more →
Regulations

Taiwan Trade Secret Act

Taiwan's Trade Secret Act protects economically valuable confidential business and technical information with criminal penalties for violations.

Learn more →
Risk Terms

Disaster Recovery Plan

A plan for responding to IT system and infrastructure disruptions — a technical subset of BCP focused on system recovery.

BCM
Learn more →
pims

Independent Sample Test

A statistical method used to determine if there is a significant difference between the means of two independent groups. In Privacy Information Management Systems (PIMS), it helps objectively evaluate the effectiveness of different privacy controls or notices on separate user populations, supporting evidence-based decision-making.

PIMS
Learn more →
Risk Terms

AI-Driven Predictive Continuity

Leveraging AI to predict potential business disruptions and automatically activate continuity plans, enhancing organizational resilience and minimizing impact.

BCM
Learn more →
Risk Terms

Recovery Time Objective / Recovery Point Objective

RTO/RPO define maximum acceptable downtime and data loss targets for business continuity planning

BCM
Learn more →
Risk Terms

Return on Invested Capital (ROIC)

A key financial metric measuring a company's efficiency in generating profits from all its capital sources (equity and debt).

VALUE_MANAGEMENT
Learn more →
Risk Terms

Key Risk Indicator (KRI)

Quantitative metrics used to provide early warning signals of increasing risk exposure in key areas.

ERM
Learn more →
ISO Standards

ISO 31000

International standard providing principles and guidelines for risk management applicable to any organization.

ERM
Learn more →
Risk Terms

Total Shareholder Return (TSR)

Total Shareholder Return (TSR) is a measure of the total return to shareholders, including stock appreciation and dividends, over a specific period.

VALUE_MANAGEMENT
Learn more →
Regulations

EU Cyber Resilience Act

EU mandatory cybersecurity regulation for all connected products. From September 2027, all connected products sold in the EU must comply with CRA requirements and bear CE marking.

PIMSAUTO
Learn more →
Risk Terms

PII processor

A PII processor is an entity that processes PII on behalf of a PII controller, such as a cloud service provider or data analytics firm.

PIMS
Learn more →
ISO Standards

Resource Pooling

Resource pooling is a core cloud computing feature where a provider's resources are pooled to serve multiple customers using a multi-tenant model.

CLOUD_RISK_ASSESSMENT
Learn more →
ISO Standards

ISO/IEC 17788

ISO/IEC 17788 is the international standard for cloud computing overview and vocabulary, unifying key terms and concepts.

CLOUD_RISK
Learn more →
Risk Terms

Weighted Average Cost of Capital (WACC)

WACC measures a company's average after-tax cost of financing its assets, serving as a key discount rate for evaluating investment projects.

VALUE_MANAGEMENT
Learn more →
ISO Standards

Products with digital elements

Any tangible movable item containing software or firmware that can connect directly or indirectly to a network.

CRA_COMPLIANCE
Learn more →
ISO Standards

International Integrated Reporting Framework (IIRC)

A global framework for communicating corporate value by integrating financial and non-financial information to show how an organization creates value over time through its six capitals.

ERMESG
Learn more →
ISO Standards

General Explanation of the Amendments to the Regulations Governing Establishment of Internal Control Systems by Public Companies (2024-04-22)

An official explanation of Taiwan's latest regulatory amendment requiring public companies to integrate sustainability (ESG) information into their internal control and audit systems.

Learn more →
Risk Terms

Business Impact Analysis

A methodology for identifying and quantifying the impact of business disruptions on an organization — the foundational tool for BCM and BCP.

BCM
Learn more →
ISO Standards

ISO 56001 Innovation Management System

ISO 56001 is the world's first certifiable international standard for innovation management systems, designed to help organizations institutionalize innovation and systematically manage uncertainty to achieve sustained value creation.

IMS
Learn more →
ISO Standards

Regulations Governing the Handling of Financial Forecasts of Public Companies

A regulation that specifies the procedures, content, and responsibilities for public companies when disclosing financial forecasts to protect investors.

VALUE_MANAGEMENT
Learn more →
Risk Terms

Information Security vs Privacy Protection

Information security serves as infrastructure for privacy protection, with overlapping but distinct regulatory requirements

PIMS
Learn more →
Risk Terms

Enterprise Risk Management

An integrated approach to managing all risks that could affect an organization's objectives, embedding risk management into organizational culture and decision-making.

ERM
Learn more →
ISO Standards

ISO 27001 Information Security Management System

International standard for systematic information security management ensuring confidentiality, integrity, and availability

PIMS
Learn more →
Risk Terms

Business Continuity Plan (BCP)

Strategic plan for maintaining critical business operations during and after disruptive incidents

BCM
Learn more →
ISO Standards

Enterprise Risk Management (ERM)

Enterprise Risk Management (ERM) is a strategic process for identifying, assessing, and preparing for any uncertainties that may affect an organization's objectives.

ERMESG
Learn more →
ISO Standards

Accountability

Accountability is the obligation for an organization to be responsible for its data processing and to demonstrate compliance with regulations.

PIMS
Learn more →
ISO Standards

ISO 31000

ISO 31000 is the international standard for risk management, providing principles and generic guidelines for any organization to manage uncertainty.

ERM
Learn more →
Risk Terms

Privacy-Preserving Machine Learning

A set of techniques enabling machine learning model training and analysis while protecting individual data privacy, using methods like federated learning and differential privacy.

PIMS
Learn more →
Risk Terms

Return on Equity (ROE)

A key metric measuring a company's ability to generate profits for its shareholders, indicating how much net income is earned per dollar of equity.

VALUE_MANAGEMENT
Learn more →
Regulations

EU AI Act

The EU's comprehensive AI regulation — the world's first major AI law, classifying AI systems by risk level with binding obligations.

AI
Learn more →
Risk Terms

Mechanistic Interpretability

A field of AI safety research that aims to reverse engineer neural networks to understand their internal mechanisms.

AI
Learn more →
ISO Standards

Measured Service

A characteristic of cloud services that automatically controls and optimizes resource usage, which can be monitored, measured, and reported, forming the basis for pay-per-use models.

CLOUD_RISK_ASSESSMENT
Learn more →
ISO Standards

COSO ERM Framework (Enterprise Risk Management—Integrating with Strategy and Performance)

A globally recognized framework integrating risk management with strategy and performance to help organizations create, preserve, and realize value.

ERMESG
Learn more →
Risk Terms

Value of Trade Secret Protection for R&D Innovation

Trade secrets offer perpetual protection, no disclosure requirement, low cost, and protection of negative knowledge, superior to patents for core R&D confidential information

TS-IMS
Learn more →
Risk Terms

Price-to-Book Ratio (PBR)

The Price-to-Book Ratio is a market valuation indicator that measures a company's stock price relative to its book value per share, used to assess potential undervaluation or overvaluation.

VALUE_MANAGEMENT
Learn more →
ISO Standards

ISO 22301

International standard for Business Continuity Management Systems, helping organizations maintain operations during disruptive incidents.

BCM
Learn more →
ISO Standards

Internal Market

A single market established by the EU to ensure the free movement of goods, services, capital, and people, where cyber resilience is key to its digital functioning.

CYBER_RESILIENCE
Learn more →
ISO Standards

Risk Appetite

The amount and type of risk that an organization is willing to accept in pursuit of its objectives.

ERM
Learn more →
Risk Terms

Conformity Assessment Technologies

A set of technical methods to verify that an AI system meets specified requirements and standards, such as the EU AI Act.

AI
Learn more →
Risk Terms

PII controller

An entity that determines the purposes and means of processing Personally Identifiable Information (PII), acting as the key decision-maker in privacy protection.

PIMS
Learn more →
Risk Terms

Enterprise Value Plan

A plan outlining a company's operational strategies and specific measures to analyze its value and enhance long-term competitiveness for investors.

VALUE_MANAGEMENT
Learn more →
ISO Standards

Privacy Risk Management

A systematic process to identify, assess, and respond to privacy risks arising from an organization's operations to protect individual privacy.

PIMS
Learn more →
Risk Terms

ISMS (Information Security Management System)

A framework for systematically managing an organization's sensitive information to ensure its confidentiality, integrity, and availability.

ERMPIMS
Learn more →
ISO Standards

OECD Privacy Guidelines

The OECD Privacy Guidelines are a key international standard for protecting personal data and cross-border data flows, based on eight core principles that influence national privacy laws.

PIMS
Learn more →
ISO Standards

Action Plan for Sustainable Development of TWSE/TPEx Listed Companies (2023)

An FSC action plan to guide listed companies towards net-zero transition and sustainable development goals.

Learn more →
ISO Standards

Global Reporting Initiative (GRI) Standards

The Global Reporting Initiative (GRI) Standards are the world's most widely used framework for sustainability reporting, helping organizations disclose their impacts on the economy, environment, and people.

ERMESG
Learn more →
Regulations

GDPR

EU General Data Protection Regulation — the world's strictest privacy law, with fines up to €20 million or 4% of global annual revenue.

PIMS
Learn more →
Regulations

IFRS S1 / S2 Sustainability Disclosure Standards

Global sustainability disclosure standards established by IASB for consistent ESG reporting

ERM
Learn more →
ISO Standards

ISO/IEC 29134: Guidelines for privacy impact assessment

ISO/IEC 29134 is the international standard providing guidelines for Privacy Impact Assessments (PIAs) to help organizations assess and mitigate privacy risks.

PIMS
Learn more →
ISO Standards

ISO/SAE 21434

International standard for road vehicle cybersecurity engineering, specifying cybersecurity practices throughout the vehicle development lifecycle.

AUTO
Learn more →
ISO Standards

Shared Competence

Areas where both the EU and its member states may legislate, but member states can only act if the EU has not.

CYBER_RESILIENCE
Learn more →
ISO Standards

Broad network access

Broad network access is a key cloud computing characteristic, allowing services to be accessed from diverse devices like computers and phones via standard mechanisms.

CLOUD_RISK_ASSESSMENT
Learn more →
ISO Standards

IEC 62443 Industrial Cybersecurity Standard

International cybersecurity standard for Industrial Automation and Control Systems (IACS), covering manufacturing, energy, water treatment, and other critical infrastructure. Primary harmonized standard for EU CRA.

AUTOPIMS
Learn more →
Risk Terms

Why ERM Matters for Corporate Governance

ERM transforms boards from reactive firefighting to proactive oversight, boosting investor confidence and enterprise valuation

ERM
Learn more →
ISO Standards

Personal Information De-identification Process Management System (PIDIPMS)

A management system for the personal information de-identification process, ensuring data protection and regulatory compliance during value-added applications.

PIMS
Learn more →
ISO Standards

ISO 42001

International standard for AI management systems, helping organizations establish responsible AI governance frameworks.

AI
Learn more →
ISO Standards

ISO/IEC 29134

ISO/IEC 29134 is an international standard providing guidelines for conducting a Privacy Impact Assessment (PIA) to systematically evaluate and treat privacy risks of a project.

PIMS
Learn more →
ISO Standards

De-identification

De-identification is the process of removing or obscuring personal identifiers from data to enable analysis while protecting individual privacy.

PIMS
Learn more →
ISO Standards

Level Playing Field

A situation where all businesses are subject to the same minimum standards and rules, ensuring fair competition and preventing risks caused by the negligence of a few.

CYBER_RESILIENCE
Learn more →
Risk Terms

ESG (Environmental, Social, and Governance)

A framework evaluating corporate performance in Environmental, Social, and Governance aspects for sustainable business practices.

ERM
Learn more →
Regulations

GDPR (General Data Protection Regulation)

A strict EU regulation for personal data and privacy protection for all individuals within the EU, with global applicability.

PIMS
Learn more →
Risk Terms

Privacy UX UI

The practice of integrating privacy principles into user interface and experience design, ensuring user control and transparency.

PIMS
Learn more →
ISO Standards

Transborder Flows of Personal Data

The transmission of personal data from one country to another, requiring compliance with specific regulations to ensure equivalent protection abroad.

PIMS
Learn more →
ISO Standards

Regulations Governing the Handling of Financial Forecasts of Public Companies

These are regulations by the FSC governing the preparation and disclosure of corporate financial forecasts to ensure transparent information and protect investors.

CVA
Learn more →
Risk Terms

Shareholder Return

The financial policy by which a company returns profits to its shareholders, typically through cash dividends or share buybacks.

VALUE_MANAGEMENT
Learn more →
ISO Standards

ESG-Related Risks

ESG-related risks are potential threats arising from environmental, social, and governance factors that can impact a company's financial performance and operations.

ERMESG
Learn more →
Risk Terms

Personal Information Incident

A Personal Information Incident is an event where personal data is disclosed, altered, destroyed, or stolen without authorization, harming the individual's rights.

PIMS
Learn more →
Risk Terms

Enterprise Risk Management vs Enterprise Resilience

ERM is risk appetite decision system, resilience is shock absorption capability; ERM provides foundational framework for resilience

Learn more →
ISO Standards

IR Engagement Service Platform

A digital platform to help listed companies conduct ESG-focused communication and engagement with institutional investors.

Learn more →
ISO Standards

ISO 27701

International standard for Privacy Information Management Systems, extending ISO 27001 to help organizations comply with GDPR and other privacy regulations.

PIMS
Learn more →
Key Institutions

OECD

International policy forum of 38 democratic market economies whose recommendations shape global AI, risk management, tax, and corporate governance policies.

ERMAI
Learn more →
ISO Standards

Public cloud

A cloud computing model where services are owned and operated by a third-party provider and delivered over the internet to the public.

CLOUD_RISK_ASSESSMENT
Learn more →
ISO Standards

Pseudonymization

Pseudonymization is a data protection technique that replaces personal data with pseudonyms, preventing direct identification without additional information.

PIMS
Learn more →
ISO Standards

Corporate Value Enhancement Plan

A concrete plan formulated and disclosed by a company, analyzing its internal and external status to set operational strategies, financial goals, and governance policies to enhance long-term value.

CVA
Learn more →
ISO Standards

k-anonymity

k-anonymity is a data de-identification technique ensuring any record in a dataset cannot be distinguished from at least k-1 other records, thus protecting individual privacy.

PIMS
Learn more →
ISO Standards

Multi-tenancy

A software architecture where a single software instance serves multiple tenants (customers), with mechanisms to keep each tenant's data isolated and secure.

CLOUD_RISK_ASSESSMENT
Learn more →
Risk Terms

Stakeholder

A stakeholder is any person or organization that can affect, be affected by, or perceive themselves to be affected by an organization's decisions or activities.

PIMS
Learn more →
ISO Standards

Anonymization

Anonymization is a data processing technique that irreversibly alters personal data, preventing the re-identification of any specific individual.

PIMS
Learn more →
Risk Terms

Agentic ERM

An ERM framework using AI agents to automate risk monitoring, alerting, and response, enhancing proactive risk management.

ERM
Learn more →
ISO Standards

Personal Data

Information that can directly or indirectly identify a natural person, crucial for digital transformation and regulatory compliance.

PIMS
Learn more →
ISO Standards

Accountability

Accountability is an organization's obligation to not only comply with data protection regulations but also to demonstrate that compliance.

PIMS
Learn more →
Risk Terms

Adversarial Robustness

An AI model's ability to resist malicious inputs designed to cause errors, ensuring stable and accurate performance.

AI
Learn more →
Regulations

Taiwan AI Basic Act

Taiwan's AI Basic Act passed in 2024, establishing foundational principles for AI development and government policy direction.

AI
Learn more →
Risk Terms

Algorithmic Impact Assessments

A systematic process to assess the potential risks of automated decision-making systems on individuals and society.

AI
Learn more →
ISO Standards

Community Cloud

A cloud deployment model where infrastructure is shared exclusively by a community of organizations with common goals (e.g., mission, compliance).

CLOUD_RISK_ASSESSMENT
Learn more →
Risk Terms

SELF DRIVE Act 2026

A proposed U.S. federal framework to regulate autonomous vehicles, superseding state laws and establishing a new entity for unified oversight.

AUTO
Learn more →
ISO Standards

Products with Digital Elements

Any software or hardware product and its solution whose intended use includes a direct or indirect data connection to a device or network.

Learn more →
ISO Standards

ISO 26262

International standard for road vehicle functional safety, specifying safety development processes for automotive electrical/electronic systems including ASIL classification.

AUTO
Learn more →
Risk Terms

PII (Personally Identifiable Information)

PII is any information that can be used to identify a specific individual, directly or indirectly. It is a core subject of corporate compliance and information security.

PIMS
Learn more →
Risk Terms

Zero-Party Data

Data a customer intentionally and proactively shares with a company, such as preferences, purchase intentions, and personal context.

PIMS
Learn more →
ISO Standards

Anonymization

The process of irreversibly altering personal data so that an individual cannot be identified, thereby reducing privacy risks.

PIMS
Learn more →
Risk Terms

Geopolitical Risk Management Framework

Systematic framework for identifying, assessing and responding to geopolitical events' impact on business operations

ERM
Learn more →
ISO Standards

ISO/IEC 27701 (International Standard)

An international privacy information management standard that extends ISO 27001, helping organizations protect personal data and comply with global privacy regulations.

PIMSERM
Learn more →
Risk Terms

Supply Chain Resilience

The ability of a supply chain to maintain core functions and rapidly recover from disruptive events.

BCMERM
Learn more →
Key Institutions

Bank for International Settlements

The bank for central banks, publishing Basel Accords and other global financial regulatory standards with definitive influence on banking risk management worldwide.

ERM
Learn more →
Risk Terms

Consent Management Platform

A software tool that manages user consent for cookies and personal data processing, ensuring compliance with privacy regulations.

PIMS
Learn more →
Key Institutions

Financial Stability Board

G20-mandated body monitoring global financial system systemic risks and making recommendations, with significant influence on national financial regulatory policies.

ERM
Learn more →
ISO Standards

ISO/IEC 22123-2

An international standard that specifies core concepts for cloud computing, aiming to establish a common understanding for global cloud services.

CLOUD_RISK_ASSESSMENT
Learn more →
ISO Standards

k-anonymity

k-anonymity is a data de-identification technique ensuring any record in a dataset cannot be distinguished from at least k-1 other records.

PIMS
Learn more →
Risk Terms

Treasury Stock

Treasury stock refers to shares a company repurchases from the open market. It can be used to increase EPS, for employee compensation, or to stabilize the stock price, but holds no voting rights or dividends.

VALUE_MANAGEMENT
Learn more →
Risk Terms

AI Alignment

The practice of ensuring AI systems' goals and behaviors are consistent with human values and intentions, preventing unintended harmful outcomes.

AI
Learn more →
Risk Terms

PIMS (Privacy Information Management System)

PIMS is a framework for managing Personally Identifiable Information (PII) to protect individual privacy and comply with regulatory requirements.

PIMSERM
Learn more →
ISO Standards

Hybrid cloud

A hybrid cloud combines a private cloud with one or more public cloud services, allowing data and applications to be shared between them.

CLOUD_RISK_ASSESSMENT
Learn more →
Risk Terms

Security-by-Design Automotive

An approach integrating cybersecurity into every phase of the vehicle development lifecycle, from concept to decommissioning, as mandated by ISO/SAE 21434.

AUTO
Learn more →
Risk Terms

Data Protection Impact Assessment

A pre-implementation assessment required for high-risk personal data processing activities — mandatory under GDPR in certain circumstances.

PIMS
Learn more →
Risk Terms

Why is Trade Secret Protection Important?

Trade secrets offer perpetual protection without disclosure, unlike patents' 20-year limit and mandatory revelation, providing broadest scope

TS-IMS
Learn more →
Risk Terms

Green Claims Directive

An EU directive to combat greenwashing by requiring sustainability claims to be substantiated with scientific evidence and third-party verification.

ERM
Learn more →
Key Institutions

NIST

US federal agency publishing widely adopted technical standards including the Cybersecurity Framework (CSF) and AI Risk Management Framework (AI RMF).

AIERM
Learn more →
ISO Standards

Private cloud

A private cloud is a cloud computing environment dedicated to a single organization, offering the highest degree of control over resources, security, and service quality.

CLOUD_RISK_ASSESSMENT
Learn more →
ISO Standards

Cloud Service Partner

An external vendor providing cloud computing services, entrusted with processing or storing a company's data, forming a critical part of supply chain security.

CLOUD_RISK_ASSESSMENT
Learn more →
Risk Terms

OTA Security Automotive

Ensuring the security of over-the-air (OTA) vehicle software updates, encompassing integrity, authenticity, and confidentiality, as mandated by regulations like UN R156.

AUTO
Learn more →
Risk Terms

ISO/SAE 21434 Amendment

A revision to the international automotive cybersecurity standard, enhancing supply chain security, SBOM, and vulnerability disclosure.

AUTO
Learn more →
Risk Terms

Zero-Knowledge Proofs

A cryptographic method to prove a statement is true without revealing any information beyond its validity.

PIMS
Learn more →
Risk Terms

Supply Chain Dependency Mapping

A process of visually representing supply chain nodes to identify critical dependencies, single points of failure, and concentration risks.

BCM
Learn more →
ISO Standards

CNS 17788

CNS 17788 is Taiwan's national standard for cloud service information security and personal data protection, integrating ISO/IEC 27017 and 27018.

CLOUD_RISK
Learn more →
Risk Terms

Interconnected Risk Business Continuity Management

A BCM approach assessing cascading effects of multiple, interconnected crises to enhance organizational resilience.

BCM
Learn more →
Risk Terms

Human-in-the-loop

A model requiring human interaction and oversight to guide, improve, or intervene in an AI system's decision-making process.

AI
Learn more →
Risk Terms

Third-Party Risk Management BCM

An integrated strategy to manage operational disruption risks arising from reliance on third-party service providers.

BCM
Learn more →
Risk Terms

GDPR Data IP

Intellectual property rights and compliance issues concerning personal data under the GDPR framework.

TS-IMS
Learn more →
Risk Terms

V2X Anomaly Detection

A system that identifies and flags abnormal or malicious signals within Vehicle-to-Everything (V2X) communication networks to ensure road safety.

AUTO
Learn more →
Risk Terms

Sustainability Reporting IP

The obligation to disclose sustainability-related intangible assets, such as R&D and green patents, under reporting standards like CSRD and ISSB.

TS-IMS
Learn more →
Risk Terms

CSMS Cybersecurity Management System Auto

A management system required by UN R155, ensuring cybersecurity throughout the vehicle's entire lifecycle, from development to post-production.

AUTO
Learn more →
Risk Terms

Cyber Resilience BCM

An integrated approach combining cybersecurity and Business Continuity Management (BCM) to ensure an organization can withstand, respond to, and recover from cyber incidents.

BCM
Learn more →
Risk Terms

Digital Twins for Resilience

A dynamic virtual model of a physical system used to simulate, predict, and enhance its operational resilience against disruptions.

BCM
Learn more →
Risk Terms

Geopolitical Risk Inventory

A systematic list used to identify, assess, and manage an organization's exposure to geopolitical risks, such as conflicts and regulatory changes.

ERM
Learn more →
Risk Terms

Data Clean Rooms

A secure environment where multiple parties can collaborate on data analysis without sharing the raw data, ensuring privacy and compliance.

PIMS
Learn more →
Risk Terms

DORA NIS2 Compliance

The dual compliance requirement for EU's financial digital operational resilience (DORA) and network and information systems security (NIS2) directives.

ERM
Learn more →
Risk Terms

Adaptive Governance BCM

A resilience governance framework that dynamically adjusts BCPs to address emerging risks and regulatory demands.

BCM
Learn more →
Risk Terms

Supply Chain Traceability ERM

Integrating supply chain traceability data into Enterprise Risk Management (ERM) to ensure regulatory compliance, mitigate risks, and enhance operational resilience.

ERM
Learn more →
Risk Terms

Trademark Modernization Act

A U.S. federal law to streamline the trademark registration process and combat fraudulent filings by allowing easier removal of unused trademarks.

TS-IMS
Learn more →
Risk Terms

IP Monetization

The process of converting intellectual property rights into revenue streams or economic value.

TS-IMS
Learn more →
Risk Terms

Tabletop Exercise Automation

The use of technology to automate the creation, execution, and documentation of business continuity tabletop exercises, enhancing efficiency and compliance.

BCM
Learn more →
Risk Terms

Whistleblower Protections ERM

Integrating whistleblower protection systems into the enterprise risk management framework to identify, assess, and mitigate compliance, legal, and reputational risks.

ERM
Learn more →
Risk Terms

Authorised Self-Driving Entity

A legal entity certified by a regulatory body to commercially deploy self-driving vehicles, assuming full legal and operational responsibility.

AUTO
Learn more →
Risk Terms

CSRD Double Materiality

A principle assessing ESG issues' two-way impact: on the company's finances and the company's impact on society and the environment.

ERM
Learn more →
Risk Terms

Federal AV Framework

A U.S. federal policy framework providing guidance for the safe development and deployment of automated vehicles.

AUTO
Learn more →
Risk Terms

Operational Resilience

An organization's ability to continue delivering critical operations through severe but plausible disruptions.

BCM
Learn more →
Risk Terms

Non-Practicing Entities

Entities that hold patents but do not manufacture or sell products, primarily earning revenue through licensing or litigation.

TS-IMS
Learn more →
Risk Terms

Patent Portfolio Optimization

A strategic process of managing patent assets to align with business goals, maximize value, and minimize costs and risks.

TS-IMS
Learn more →
auto

UNECE Regulation No. 156 (Software Update and Software Update Management System)

A mandatory UNECE regulation governing vehicle software updates and their management systems (SUMS). It requires manufacturers to implement secure processes for over-the-air (OTA) updates throughout the vehicle lifecycle. Compliance is essential for type approval, ensuring the integrity and safety of software updates.

AUTO
Learn more →
Risk Terms

Predictive Risk Intelligence

Using AI/ML to analyze data, proactively identifying and managing potential future risks before they materialize.

ERM
Learn more →
Risk Terms

Scenario Planning Analytics

A method using data analytics and AI to simulate and evaluate potential future risk scenarios, aiding strategic decision-making and resilience planning.

BCM
Learn more →
ISO Standards

Treaty on the Functioning of the European Union (TFEU)

The Treaty on the Functioning of the European Union (TFEU) is a core EU treaty governing the internal market, competition, and personal data protection, impacting global businesses.

Learn more →
Risk Terms

AI Copyright

The legal framework governing ownership and protection of creative works generated by artificial intelligence systems.

TS-IMS
Learn more →
Risk Terms

Interconnected Threats ERM

A systematic approach to manage the compound impact of interconnected geopolitical, climate, technological, and regulatory risks within an ERM framework.

ERM
Learn more →
Risk Terms

Digital Operational Resilience Act

An EU regulation strengthening the ICT risk management capabilities of financial entities to ensure operational resilience.

BCM
Learn more →
Regulations

Taiwan Personal Data Protection Act

Taiwan's Personal Data Protection Act regulating the collection, processing, and use of personal data, with fines up to NT$15 million.

PIMS
Learn more →
ai

AI Lifecycle

The AI lifecycle encompasses all stages of an AI system, from design and data collection to model training, deployment, monitoring, and retirement. It provides a structured framework for managing risks and ensuring compliance with standards like the NIST AI RMF and ISO/IEC 42001.

AI
Learn more →
ISO Standards

Re-identification

The process of re-associating de-identified data with a specific individual by linking it with other information.

PIMS
Learn more →
Risk Terms

Automotive Safety Integrity Level

The automotive safety risk classification system defined by ISO 26262, ranging from ASIL A (lowest) to ASIL D (highest), determining safety development requirements for vehicle systems.

AUTO
Learn more →
pims

Data Processing Agreement

A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor, outlining their respective obligations when personal data is processed by a third party. Mandated by regulations like GDPR Article 28, it ensures data protection, compliance, and mitigates legal and financial risks for organizations.

PIMS
Learn more →
ISO Standards

Infrastructure as a Service (IaaS)

IaaS is a cloud computing service that provides users with virtualized computing, storage, and networking IT infrastructure resources.

CLOUD_RISK_ASSESSMENT
Learn more →
ISO Standards

Cyber Resilience Act (CRA)

A mandatory EU regulation for products with digital elements, ensuring their cybersecurity from design and development throughout their entire lifecycle.

Learn more →
Risk Terms

Drug Patent Term Restoration

A system to compensate for patent term lost during a drug's regulatory review process.

TS-IMS
Learn more →
ai

Technical Documentation

A set of documents systematically detailing an AI system's design, data, development, and performance, as required by regulations like the EU AI Act. It ensures transparency, traceability, and accountability throughout the AI lifecycle, serving as key evidence for compliance and risk management.

AI
Learn more →
ISO Standards

Software as a Service (SaaS)

Software as a Service (SaaS) is a cloud computing service that allows users to access a provider's applications over the internet, typically via a web browser, without managing the underlying infrastructure.

CLOUD_RISK_ASSESSMENT
Learn more →
ai

high-risk categories

A classification under the EU AI Act for AI systems posing significant risks to health, safety, or fundamental rights. These systems, listed in Annex III, face stringent requirements for data governance, documentation, and human oversight, mandating a robust risk management system aligned with standards like ISO/IEC 23894.

AI
Learn more →
ai

algorithmic transparency

Algorithmic transparency involves disclosing AI system logic, decision-making processes, and potential impacts to ensure explainability and auditability. Essential for AI development and deployment, it builds trust, mitigates compliance risks, and meets regulatory demands like GDPR and NIST AI RMF.

AI
Learn more →
ai

Pearson’s correlation coefficient

Pearson's correlation coefficient is a statistical measure of the linear relationship between two continuous variables. In AI governance, as referenced in NIST AI RMF testing protocols, it's used to assess feature importance or detect bias. For enterprises, it quantifies relationships between risk factors, supporting data-driven mitigation strategies.

AI
Learn more →
ai

AI Risk Management Framework (AI RMF)

The NIST AI Risk Management Framework (AI RMF) provides a structured approach for organizations to identify, assess, mitigate, and monitor risks associated with artificial intelligence systems. Applicable across industries, it aims to enhance AI trustworthiness, fairness, and transparency, crucial for enterprise compliance and building public trust.

AI
Learn more →
Risk Terms

Executive Personal Liability ERM

A risk management framework to manage executives' personal legal or financial liability arising from their professional duties and decisions.

ERM
Learn more →
ISO Standards

Sustainability Accounting Standards Board (SASB) Standards

The Sustainability Accounting Standards Board (SASB) Standards are global standards for disclosing financially material sustainability information for specific industries to investors.

ERMESG
Learn more →
ai

Statutory Interpretation

Statutory interpretation is the process of determining the intended meaning of legislative text. It is crucial for clarifying compliance obligations under complex regulations like the EU AI Act, enabling enterprises to manage legal risks associated with high-risk AI systems.

AI
Learn more →
Risk Terms

Data Processor

A natural or legal person that processes personal data on behalf of the data controller.

PIMS
Learn more →
ISO Standards

Privacy Risk Assessment

A Privacy Risk Assessment is a systematic process to evaluate activities involving personal data, aiming to identify and mitigate potential impacts on individual privacy.

PIMS
Learn more →
ISO Standards

TISAX

Trusted Information Security Assessment Exchange — the mandatory cybersecurity assessment for European automotive supply chains.

AUTO
Learn more →
ISO Standards

Specific Purpose

The principle that personal data must be collected for specified, explicit, and legitimate purposes and not be further processed in a manner incompatible with those purposes.

PIMS
Learn more →
ISO Standards

TWSE Guidelines for the Preparation of Material Topics in Sustainability Reports

Official TWSE guidelines, based on GRI Standards, for listed companies to identify and prioritize material sustainability topics for their reports.

Learn more →
ai

collective ethical decision frameworks

Collective ethical decision frameworks integrate ethical preferences from multiple AI agents or human stakeholders to reach unified, ethically sound decisions. Applicable to complex AI systems (e.g., autonomous vehicles), they help enterprises ensure AI behavior aligns with societal values and regulatory requirements, mitigating reputational and compliance risks, as outlined in standards like NIST AI RMF.

AI
Learn more →
bcm

Remaining useful life (RUL)

Remaining Useful Life (RUL) is the predicted duration an asset can operate before failure. Critical for predictive maintenance and asset health monitoring, RUL helps enterprises optimize maintenance schedules, reduce downtime risks, and enhance operational resilience, aligning with ISO 55000 asset management principles.

BCM
Learn more →
ISO Standards

Criteria for Requiring Publicly Listed Companies to Disclose Complete Financial Forecasts

These are regulatory standards defining specific situations where listed companies must disclose complete financial forecasts, such as when releasing specific profit projections to the media.

VALUE_MANAGEMENT
Learn more →
ISO Standards

Platform as a Service (PaaS)

Platform as a Service (PaaS) is a cloud service that provides a platform for developing and deploying applications, allowing businesses to focus on software development without managing the underlying infrastructure.

CLOUD_RISK_ASSESSMENT
Learn more →
pims

constant false-alarm rate (CFAR)

Constant False-Alarm Rate (CFAR) is a technique in signal detection systems that dynamically adjusts detection thresholds to maintain a constant probability of false alarms. It ensures stable target detection despite varying background noise, crucial for reliable anomaly detection, reducing false positive costs, and enhancing decision-making in monitoring, security, and quality control.

PIMS
Learn more →
ai

risk-based approach

The risk-based approach is a strategic methodology for prioritizing and managing risks by allocating resources to the most significant threats. Central to frameworks like ISO 31000 and the EU AI Act, it enables organizations to focus controls where they are most needed, ensuring efficient compliance and effective risk mitigation.

AI
Learn more →
ISO Standards

EU Cybersecurity Act

The first comprehensive EU-wide cybersecurity framework, designed to enhance the EU's overall cyber resilience and establish a unified certification scheme for ICT products, services, and processes.

Learn more →
ISO Standards

Network and Information Systems Security Directive 2 (NIS2 Directive)

A legal framework enacted by the EU to enhance the cybersecurity resilience of critical infrastructure, expanding its scope and strengthening penalties to establish a high common level of cybersecurity across the Union.

CYBERSECURITY_COMPLIANCE
Learn more →
Risk Terms

Data Controller

A data controller is the entity that determines the purposes and means of processing personal data, holding primary responsibility for data protection.

PIMS
Learn more →
ai

AI harms

AI harms refer to the negative impacts of AI systems on individuals, groups, society, or the environment. These include issues like bias, privacy violations, and safety risks. Enterprises must manage these harms by implementing frameworks like the NIST AI Risk Management Framework (AI RMF) to ensure responsible and compliant AI deployment.

AI
Learn more →
Risk Terms

COSO ERM

The COSO Committee's integrated framework for enterprise risk management, emphasizing integration with business strategy and performance, widely used in public company governance.

ERM
Learn more →
erm

COSO Framework

A leading framework for internal control and enterprise risk management published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). It provides principles-based guidance for designing, implementing, and assessing control systems to manage risks and achieve strategic objectives.

ERM
Learn more →
auto

UNECE R155 - Cyber Security and Cyber Security Management System

UNECE Regulation No. 155 (R155) is a mandatory regulation for vehicle cybersecurity. It requires manufacturers to implement a certified Cyber Security Management System (CSMS) to manage cyber risks throughout the vehicle lifecycle. Compliance is essential for type approval in signatory countries.

AUTO
Learn more →
ISO Standards

Service Level Agreement

A contract between a service provider and a client that defines measurable metrics for service quality, responsibilities, and expectations.

CLOUD_RISK
Learn more →
ai

data poisoning

Data poisoning is a malicious attack that alters AI model training data to influence the learning process, causing errors or biases. Occurring primarily during the machine learning training phase, it poses significant risks to enterprises, leading to incorrect AI decisions, service disruptions, reputational damage, and severe compliance issues, as addressed by NIST AI RMF and ISO/IEC 27001.

AI
Learn more →
ISO Standards

Regulation (EU) 2019/1020 on market surveillance and compliance of products

This regulation strengthens EU market surveillance to ensure products sold, especially those from outside the EU, comply with regulations, protecting consumer safety and public interests.

Learn more →
ai

AI Act

The EU's landmark regulation creating a comprehensive legal framework for Artificial Intelligence. It uses a risk-based approach, classifying AI systems into four tiers and imposing corresponding obligations. It impacts any entity placing AI systems on the EU market, mandating compliance with safety, transparency, and fundamental rights.

AI
Learn more →
ISO Standards

Harmonisation

The process of integrating multiple, diverse regulations, standards, or frameworks into a consistent approach to streamline compliance, reduce costs, and improve efficiency.

CYBER_RESILIENCE
Learn more →
Risk Terms

Price-to-Earnings Ratio (P/E Ratio)

The Price-to-Earnings (P/E) ratio measures a company's stock price relative to its per-share earnings, indicating market expectations and valuation.

VALUE_MANAGEMENT
Learn more →
Risk Terms

Capital Allocation

Capital allocation is the decision-making process of distributing a company's financial resources to various opportunities to maximize long-term value.

VALUE_MANAGEMENT
Learn more →
bcm

Supply Chain Risk Management

Supply Chain Risk Management (SCRM) is the systematic process of identifying, assessing, mitigating, and monitoring potential disruptions and threats within a supply chain. Crucial for globalized, complex supply chains across all industries, it enhances operational resilience, reduces costs, protects reputation, and ensures compliance, often referencing standards like ISO 28000.

BCM
Learn more →
ai

amortized Bayesian inference

Amortized Bayesian inference pre-trains an inference network to rapidly estimate posterior distributions for new observations, amortizing computational costs upfront. Crucial for dynamic AI/ML applications, it enhances enterprise decision-making speed and risk management responsiveness, ensuring timely and reliable AI system performance.

AI
Learn more →
ISO Standards

Article 114 TFEU

Article 114 of the Treaty on the Functioning of the European Union is the legal basis for harmonizing laws to establish and ensure the functioning of the EU's internal market.

Learn more →
ISO Standards

Aggregated Data

Aggregated data is statistical information compiled from multiple individuals' data, from which personal identifiers have been removed.

PIMS
Learn more →
ai

AI Literacy

The ability to understand, apply, and critically evaluate artificial intelligence systems. For enterprises, AI literacy is fundamental to responsible AI deployment, mitigating operational and compliance risks, and is a prerequisite for implementing frameworks like the NIST AI RMF and ISO/IEC 42001.

AI
Learn more →
ISO Standards

TWSE Sustainability Report Material Topics Disclosure Examples

An official TWSE guide based on GRI standards to help companies identify and disclose material sustainability topics.

Learn more →
ISO Standards

Data Usability

Data Usability, often termed "Availability" in information security, ensures that information is accessible and usable upon demand by an authorized entity, a cornerstone of the CIA triad.

PIMS
Learn more →
Risk Terms

Geopolitical Risk

Uncertainty and potential losses to business operations caused by geopolitical factors including international political relations, conflicts, sanctions, and trade barriers.

ERMBCM
Learn more →