GRC Glossary — Risk, Compliance, and Governance Terms
A reference glossary of governance, risk, and compliance (GRC) terms used in Korinza and across the industry. Covers risk management, compliance frameworks, audit terminology, private equity concepts, and regulatory acronyms.
GRC
- GRC
- Governance, Risk, and Compliance. An integrated approach to managing an organisation's overall governance, enterprise risk management, and regulatory compliance with the goal of acting with integrity and in accordance with its risk appetite.
- Control
- A measure or safeguard that modifies risk. Controls can be preventive (stopping an event), detective (identifying an event after it occurs), or corrective (reducing the impact of an event).
Risk
- Risk Register
- A centralised log of identified risks, including their likelihood, impact, owner, treatment plan, and current status. The risk register is the primary tool for tracking and managing organisational risk.
- Risk Score
- A numerical representation of a risk's severity, typically calculated as Likelihood × Impact on a 1–25 scale. Higher scores indicate higher priority risks requiring more urgent treatment.
- Risk Treatment
- The process of selecting and implementing measures to modify risk. Common treatment options include: mitigate (reduce likelihood or impact), accept (acknowledge and monitor), transfer (insurance or contract), and avoid (stop the activity).
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives. Risk appetite is typically set by the board and expressed as qualitative statements or quantitative thresholds.
- Risk Tolerance
- The acceptable variation in outcomes related to specific performance measures linked to objectives the organisation is willing to accept. Risk tolerance is more specific and operational than risk appetite.
- Inherent Risk
- The level of risk that exists before any controls or mitigating actions are applied. Inherent risk represents the raw exposure to a threat.
- Residual Risk
- The level of risk that remains after controls and mitigating actions have been applied. Residual risk is compared against risk tolerance to determine whether additional treatment is required.
Framework
- Control Framework
- A structured set of controls organised to address specific risk domains or regulatory requirements. Examples include NIST CSF, ISO 27001, and SOC 2 Trust Services Criteria.
- Compliance Framework
- A structured set of guidelines, standards, and best practices that organisations follow to comply with laws, regulations, and industry standards. Examples include HIPAA, PCI DSS, and SOC 2.
- SOC 2
- Service Organisation Control 2. An auditing standard developed by the AICPA that evaluates a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. SOC 2 Type II reports cover a period of time (typically 6–12 months).
- ISO 27001
- An international standard for information security management systems (ISMS). ISO 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS.
- HIPAA
- Health Insurance Portability and Accountability Act. U.S. federal law that sets national standards for the protection of sensitive patient health information. HIPAA applies to covered entities (healthcare providers, health plans) and their business associates.
- NIST CSF
- National Institute of Standards and Technology Cybersecurity Framework. A voluntary framework of standards, guidelines, and best practices for managing cybersecurity risk. Organised around five functions: Identify, Protect, Detect, Respond, Recover.
- PCI DSS
- Payment Card Industry Data Security Standard. A set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
- ISO 9001
- International standard for quality management systems (QMS). ISO 9001 specifies requirements for a QMS that organisations can use to demonstrate their ability to consistently provide products and services that meet customer and regulatory requirements.
- ISO 45001
- International standard for occupational health and safety management systems. ISO 45001 specifies requirements for an OH&S management system to enable organisations to provide safe and healthy workplaces.
Compliance
- Gap Analysis
- An assessment that compares an organisation's current state against a desired state or standard to identify deficiencies. In compliance, gap analysis identifies controls or processes that are missing or insufficient.
- Corrective Action Plan (CAP)
- A documented plan that describes the steps an organisation will take to address identified deficiencies or findings. CAPs include responsible owners, target completion dates, and verification criteria.
- Attestation
- A formal declaration by a responsible party that a statement, process, or control is accurate and complete. Attestations are used in compliance programs to confirm that policies have been reviewed and controls are operating.
Audit
- Audit Trail
- A chronological record of system activities that provides documentary evidence of the sequence of activities that have affected a specific operation, procedure, or event. Audit trails are essential for regulatory compliance and forensic investigation.
- Evidence
- Documentation or records that demonstrate a control is operating effectively. Evidence is collected during audits and assessments to support findings and conclusions.
- Finding
- An identified deficiency, weakness, or area of non-compliance discovered during an audit or assessment. Findings are typically classified by severity and require a corrective action plan.
Regulatory
- OSHA
- Occupational Safety and Health Administration. U.S. federal agency that enforces workplace safety and health regulations. OSHA sets and enforces standards, and provides training, outreach, education, and assistance.
- 21 CFR Part 820
- FDA Quality System Regulation for medical device manufacturers. Establishes requirements for the methods, facilities, and controls used in the design, manufacture, packaging, labelling, storage, installation, and servicing of medical devices.
- OFAC SDN
- Office of Foreign Assets Control Specially Designated Nationals list. A list of individuals and entities with whom U.S. persons are generally prohibited from doing business. Korinza screens company entities and key personnel against the SDN list.
- OIG LEIE
- HHS Office of Inspector General List of Excluded Individuals and Entities. A database of individuals and entities excluded from participation in Medicare, Medicaid, and other federal health care programs. Healthcare companies are required to screen employees and vendors against LEIE.
- SAM.gov
- System for Award Management. The U.S. government's primary database of vendors doing business with the federal government. SAM.gov includes a debarment and suspension list of parties excluded from federal procurement.
- EDGAR
- Electronic Data Gathering, Analysis, and Retrieval system. The SEC's online system for companies and individuals to submit filings required by the Securities and Exchange Commission. Korinza monitors EDGAR for filing compliance.
- Form 5500
- Annual report filed with the Department of Labor for employee benefit plans (pension, 401k, health). Companies with 100 or more participants in a benefit plan are required to file Form 5500 annually.
Private Equity
- Portfolio Company (Portco)
- A company in which a private equity fund has made an investment. Portfolio companies are typically managed by the PE sponsor during the hold period to improve operations and financial performance before exit.
- Operating Partner
- A senior executive affiliated with a PE firm who works directly with portfolio companies to drive operational improvements. Operating partners often have deep industry expertise and serve on portfolio company boards.
- PE Sponsor
- The private equity firm that manages the fund and oversees portfolio company investments. The PE sponsor provides capital, strategic guidance, and operational support to portfolio companies.
- Hold Period
- The period of time a PE firm holds an investment in a portfolio company, typically 3–7 years. During the hold period, the PE sponsor works to improve the portfolio company's operations, financials, and compliance posture to maximise exit value.
- Due Diligence
- The investigation and analysis of a potential investment before a transaction is completed. Compliance due diligence evaluates the target company's regulatory exposure, compliance program maturity, and outstanding legal or regulatory issues.
- Add-on Acquisition
- An acquisition made by an existing portfolio company to expand its capabilities, customer base, or geographic reach. Add-on acquisitions increase the complexity of the portfolio company's compliance obligations and risk profile.
- EBITDA
- Earnings Before Interest, Taxes, Depreciation, and Amortisation. A common measure of operating performance used in PE to evaluate portfolio company profitability and calculate valuation multiples.
- Value Creation Plan (VCP)
- A strategic plan developed by the PE sponsor and portco management to improve the company's financial performance and operational capabilities during the hold period. Compliance program improvement is often a component of the VCP.
Insurance
- COI
- Certificate of Insurance. A document issued by an insurance company or broker that verifies the existence of an insurance policy and summarises the key aspects of the coverage. Korinza's AI can extract policy details from uploaded COI documents.
Technical
- JWT
- JSON Web Token. A compact, URL-safe means of representing claims to be transferred between two parties. Korinza uses signed JWTs for session management.
- FRED
- Federal Reserve Economic Data. A database maintained by the Federal Reserve Bank of St. Louis containing hundreds of thousands of economic time series. Korinza uses the FRED API for economic signal monitoring.
- Webhook
- An HTTP callback that sends real-time data to a specified URL when a specific event occurs. Korinza supports outbound webhooks for risk, control, audit, and policy events.
- DMARC
- Domain-based Message Authentication, Reporting, and Conformance. An email authentication protocol that builds on SPF and DKIM to protect email domains from spoofing and phishing. Korinza monitors DMARC configuration for portfolio company domains.