Governance Glossary
Browse 119 governance terms defined in plain English, from the cultural dictionary of computing.
119 Governance Terms
- Advisory Board
- A group of advisors who provide strategic guidance, introductions, or expertise to a company without having the formal authority of a board of directors. In...
- AI Act
- The European Union's legal framework for regulating AI systems based on risk and use case. It influences how models are trained, evaluated, or served, and it...
- AI Alignment Problem
- The challenge of ensuring advanced AI systems reliably pursue human goals, values, and constraints. It influences how models are trained, evaluated, or served,...
- AI Audit
- A structured review of an AI system's behavior, data use, controls, and outcomes to assess risk, compliance, quality, or accountability. AI audits may examine...
- AI Compliance
- The practice of ensuring AI systems meet applicable legal, policy, contractual, and internal governance requirements. AI compliance work often covers data...
- AI Ethics Board
- A formal internal or external group tasked with reviewing AI-related risks, policies, and ethical concerns around deployment.
- AI Model Card
- A documentation artifact describing a model's purpose, data, metrics, limitations, and intended use. It influences how models are trained, evaluated, or...
- AI Privacy
- The protection of personal, sensitive, or confidential information when AI systems collect, process, store, or generate data. AI privacy concerns include...
- Apache Foundation
- A common shorthand for the Apache Software Foundation, the nonprofit that hosts and governs many major open source projects through a community-driven model...
- BDFL
- Benevolent Dictator For Life — a title given to the founder/leader of an open-source project who retains final decision-making authority. Guido van Rossum held...
- Benevolent Dictator
- A project leader with final authority over all decisions, trusted by the community to exercise that power wisely. The non-'for-life' variant of BDFL. Works...
- Benevolent Dictator For Life
- A governance model where one founder or central leader retains final decision authority over a project while generally acting in the project’s long-term...
- Board Meeting
- A formal meeting where the board reviews company performance, strategy, major decisions, and risks with management. In startups, board meetings often shape...
- Board Observer
- Someone allowed to attend board meetings and receive materials without holding a formal board seat or voting authority. Observer rights are common in venture...
- Board of Directors
- The formal governing body responsible for overseeing company leadership, major decisions, and fiduciary obligations to shareholders. Startups often move from...
- Board Seat
- A formal position on a company's board of directors, usually carrying governance rights, meeting participation, and influence over major decisions. Board seats...
- Code Nanny
- A joking term for a tool, reviewer, or policy that constantly tells developers what they should and should not do in the code. In engineering slang, code nanny...
- Code of Conduct
- A document establishing expected behavior standards for participants in an open-source project or community. The Contributor Covenant (2014) became the most...
- Code of Conduct Standard
- A standard or widely accepted template for defining expected behavior and enforcement norms in open-source or technical communities. In project culture, a code...
- Code Patrol
- A joking term for people or automation that watch for policy violations, risky changes, or quality problems in code. In engineering slang, code patrol can...
- Code Tribunal
- A formal or semi-formal group that judges important technical changes, standards, or disputes. In engineering slang, code tribunal can sound reassuringly...
- Committer
- A contributor with direct rights to commit code or merge changes into a project repository, often reflecting a trusted role in open source governance. In some...
- Community Standards
- The shared expectations for behavior, contribution, communication, and moderation within a project or ecosystem, often documented through codes of conduct and...
- Compliance
- Adherence to laws, regulations, standards, and internal policies governing data handling, security, and operations. Common frameworks include SOC 2, GDPR,...
- Compliance Automation
- Compliance Automation is the use of code, policy engines, and evidence collection workflows to automate compliance checks and reporting. Security teams use it...
- Compliance Framework
- A structured set of controls, requirements, and guidance used to assess or demonstrate compliance with regulatory, industry, or contractual security...
- Consensus Decision
- A decision reached through broad agreement rather than unilateral authority or simple majority vote. Consensus decisions can build trust and buy-in, though...
- Contributor Covenant
- A widely adopted open source code-of-conduct template that projects use to set expectations for respectful behavior and define reporting or enforcement paths....
- Contributor License Agreement
- A legal agreement contributors sign to grant a project rights to use, relicense, or defend their code contributions.
- Core Contributor
- A contributor who plays a central sustained role in maintaining or advancing a project, often with elevated trust, review authority, or release...
- Core Team
- The small group of maintainers or leaders who guide a project’s strategy, make major decisions, and often hold elevated review or release authority. In open...
- Cyber Insurance
- Cyber Insurance is insurance coverage and underwriting practices related to cyber incidents, recovery costs, and organizational controls. Security teams use it...
- Cyber Resilience
- Cyber Resilience is the ability of an organization to prepare for, withstand, recover from, and adapt after cyber incidents. Security teams use it to enforce...
- DAO
- Decentralized autonomous organization — an entity governed by smart contracts and token-holder votes rather than a traditional management structure. Members...
- Dark Data
- Data that an organization collects, stores, or generates but does not actively use, understand, or manage well. In data culture dark data is often seen as both...
- Data Classification
- Data Classification is the labeling of information by sensitivity and handling requirements so controls can be applied consistently. Security teams use it to...
- Data Contract
- A formal agreement between data producers and consumers that defines the schema, semantics, quality expectations, SLAs, and ownership of a data asset. Like API...
- Data Governance
- The policies, roles, processes, and controls used to manage data quality, access, lineage, retention, and compliance. In data-heavy organizations governance is...
- Data Governance Security
- The security controls embedded in data governance, including classification, access policy, retention, lineage, and accountability for sensitive data handling....
- Data Lineage
- The tracking of data's journey from source through transformations to final consumption — which systems produced it, what transformations were applied, and who...
- Data Retention Policy
- Data Retention Policy is a rule set that defines how long data is kept, when it is archived, and when it must be deleted. Security teams use it to enforce...
- Digital Sovereignty
- The idea that a country, region, or organization should retain meaningful control over its digital infrastructure, data, platforms, and strategic technology...
- Dual-Class Shares
- A share structure where different classes carry different voting rights, often letting founders retain outsized control relative to economic ownership. It is...
- Eclipse Foundation
- A nonprofit foundation that hosts and governs many open source projects, originally centered on the Eclipse IDE ecosystem but now spanning cloud, IoT, tooling,...
- Enterprise Architecture
- The high-level structure and governance of systems, processes, and technology across a large organization. In workplace culture enterprise architecture can be...
- Forking Etiquette
- The social norms around when and how to fork a project, including communication with maintainers, naming, attribution, and whether a fork is a hostile split or...
- Founder Vesting
- A vesting arrangement applied to founders' equity so ownership is earned over time rather than fully guaranteed from day one. It protects the company if a...
- Governance Model
- The structure by which a project decides who has authority, how decisions are made, how roles are granted, and how disputes are resolved. In open source,...
- Governance Risk Compliance
- The discipline of aligning security governance, risk assessment, control ownership, and compliance obligations into a coordinated management program....
- GRC
- Short for governance, risk, and compliance, the organizational framework used to manage policies, control requirements, audits, and risk decisions in a...
- hard fork (blockchain)
- A backward-incompatible change to a blockchain's protocol that permanently splits the network into two separate chains. Nodes that don't upgrade follow the old...
- Identity and Access Management
- Identity and Access Management is the set of processes and systems used to govern identities, roles, authentication, and authorization. Security teams use it...
- Identity Governance
- The policies, processes, and controls used to manage who should have access to what, who approves it, how it is reviewed, and how it is removed. Identity...
- Independent Board Member
- A board member who is not part of management and is not primarily there to represent a major investor, intended to provide independent judgment and oversight....
- Information Assurance
- A broad discipline focused on ensuring information remains trustworthy, available, protected, and properly managed throughout its lifecycle. It is often...
- Information Rights
- Contractual rights allowing investors or certain shareholders to receive financial statements, reports, and other company information on an ongoing basis....
- Information Security
- Information Security is the discipline of protecting confidentiality, integrity, and availability across information systems and data. Security teams use it to...
- Internal Audit
- An audit conducted by an organization's own internal audit function to evaluate whether controls, processes, and risk management practices are designed and...
- Investment Committee
- The group within an investment firm that reviews and approves potential deals before capital is committed. Getting through the investment committee is often...
- IT Asset Management
- The process of tracking and managing hardware, software, cloud resources, and related ownership or lifecycle data across an organization. In security, IT asset...
- IT Governance
- The structures and decision processes used to ensure technology investments, risks, policies, and operations are aligned with organizational goals and...
- Java Community Process
- The formal process used to propose and standardize changes in the Java ecosystem through Java Specification Requests and related governance mechanisms. In...
- Just-in-Time Access
- Just-in-Time Access is privileged access granted only when needed and usually for a limited duration with approval or audit controls. Security teams use it to...
- Key Ceremony
- Key Ceremony is a formal process for generating and handling high-value cryptographic keys under strict procedural controls. Security teams use it to enforce...
- Key Custodian
- A person or role formally responsible for safeguarding cryptographic keys or key material and enforcing the procedures around their handling. Key custodians...
- Key Escrow
- Key Escrow is an arrangement in which decryption keys are held by a trusted third party under defined recovery conditions. Security teams use it to enforce...
- Linux Foundation
- A nonprofit consortium that supports Linux and many related open source projects through governance, events, legal infrastructure, and ecosystem coordination....
- Multi-Cloud Security
- The protection of workloads, identities, networks, and data spread across more than one cloud provider. Multi-cloud security is difficult because each platform...
- Open Container Initiative
- The standards body that maintains widely used specifications for container images and runtimes.
- Open Governance
- A governance approach where decisions, roles, roadmaps, and processes are visible and participatory rather than concentrated behind closed doors. In open...
- Open Source Community
- The people and social structures around an open source project or ecosystem, including maintainers, contributors, users, sponsors, and moderators. It is often...
- Open Source Governance
- The rules and decision-making structures that determine how an open source project sets direction, grants authority, resolves disputes, and manages...
- Open Source Initiative
- The nonprofit organization that stewards the Open Source Definition and approves licenses as open source under that framework. The OSI plays a central role in...
- Open Source Maintainer
- A person responsible for reviewing contributions, making release decisions, handling issues, and guiding the direction of an open source project. Maintainers...
- Operational Security
- Operational Security is the practice of protecting sensitive activities, plans, and capabilities from observation or inference. Security teams use it to...
- OSPO
- Short for Open Source Program Office, an internal team or function that coordinates a company’s open source strategy, compliance, contributions, policies, and...
- Owner
- The person, team, or role formally accountable for a system, dataset, control, or risk decision. In security governance, assigning a clear owner is essential...
- PII Detection
- PII Detection is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
- Policy Compliance
- The state of systems, users, or processes adhering to an organization's defined security policies and standards. Policy compliance is broader than passing an...
- Policy Enforcement
- The technical and procedural actions used to ensure defined security policies are actually applied rather than merely documented. Policy enforcement can...
- Policy Violation
- An action or condition that conflicts with an organization's defined rules, standards, or security requirements. Policy violations may be accidental,...
- Privacy
- The discipline of controlling how personal or sensitive information is collected, used, shared, stored, and deleted in accordance with expectations, rights,...
- Program Security
- The overall security of a defined program, initiative, or managed set of activities, including its governance, staffing, controls, objectives, and measurement....
- Project Charter
- A document describing a project's purpose, scope, principles, or governance expectations. In open-source and organizational culture, a project charter helps...
- Project Governance
- The framework that defines how a project is run, including roles, voting or decision methods, release authority, conflict resolution, and succession. In open...
- Public Benefit Corporation
- A legal corporate form that allows a company to pursue specified public benefits alongside shareholder value rather than treating profit maximization as the...
- Public Company
- A company whose shares are publicly traded and therefore subject to exchange rules, market scrutiny, and extensive disclosure obligations. Becoming a public...
- Regulation
- A binding rule or set of rules issued by a government or regulator that organizations must follow in specific contexts such as privacy, critical...
- Repository Insights
- Metrics or dashboards that show repository activity, contribution patterns, issues, pull requests, and other operational signals. In team settings, repository...
- Responsible AI
- Responsible AI is an AI or ML concept used to represent, train, evaluate, or deploy learned systems. It is commonly used for building production models and...
- Review
- A structured examination of a system, process, design, or incident to evaluate quality, correctness, compliance, or risk. In security work, reviews range from...
- RFC Process
- A structured process for proposing and discussing significant changes to a project. Authors write a detailed proposal (motivation, detailed design,...
- Risk Acceptance
- A formal decision to tolerate a known security risk without fully remediating it, usually because the cost, feasibility, or business tradeoff makes immediate...
- Risk Appetite
- The amount and type of risk an organization is willing to tolerate in pursuit of its objectives. In security governance, risk appetite shapes how aggressive...
- Risk Category
- A grouping used to classify risks by type, such as operational, privacy, compliance, third-party, insider, or availability risk. Risk categories help...
- Risk Communication
- The practice of explaining security risk clearly to the people who need to understand, own, or act on it, such as engineers, leaders, auditors, or customers....
- Risk Framework
- A structured model for identifying, evaluating, treating, and tracking risk across an organization. Risk frameworks provide common terminology, roles, scoring...
- Risk Management
- The ongoing process of identifying, analyzing, prioritizing, treating, and monitoring risks so security decisions align with business realities and threat...
- Risk Monitoring
- The ongoing tracking of risk conditions, control effectiveness, threat changes, and remediation progress over time. Risk monitoring matters because a decision...
- Risk Owner
- The person or role accountable for deciding how a specific risk will be handled and for accepting the consequences of that decision. A risk owner is not always...
- Risk Statement
- A concise written description of a risk that explains the condition, the potential event, and the likely impact if it occurs. Strong risk statements are...
- Risk Strategy
- An organization's overall approach to identifying, prioritizing, and handling risk in line with its objectives, constraints, and tolerance levels. A risk...
- Risk Threshold
- A defined level of risk above which action, escalation, or executive approval is required and below which a risk may be tolerated or handled routinely. Risk...
- Role Separation
- The deliberate division of responsibilities and permissions across different roles so no single person or system can complete a sensitive workflow alone. Role...
- Safety Classifier
- Safety Classifier is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI...
- Safety Filter
- Safety Filter is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
- Shadow Board
- An informal or parallel advisory group that provides perspective and challenge to leadership without replacing the formal board of directors. Companies...
- soft fork (blockchain)
- A backward-compatible change to a blockchain's protocol where old nodes can still validate new blocks, even if they don't understand the new rules. Unlike a...
- SOX Compliance
- Conformance with Sarbanes-Oxley control and reporting requirements for public companies and their financial systems. It shows up in application security,...
- Stage Gate
- A decision checkpoint that work must pass before moving from one phase to the next, often used in product development, procurement, or governance-heavy...
- Sunlight Test
- An informal check of whether a decision, design, or behavior would still seem acceptable if exposed to public or wider internal scrutiny. The metaphor comes...
- Super Alignment
- Super Alignment is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
- System Card
- A document that describes an AI system's purpose, capabilities, limitations, risks, and evaluation results so stakeholders can understand how it should be...
- Technical Steering Committee
- A formal governing body in a project or foundation that makes or approves technical direction decisions, often abbreviated TSC. It is commonly used in larger...
- The Apache Way
- The community and governance philosophy associated with the Apache Software Foundation, emphasizing consensus, community over code, meritocratic contribution,...
- Training Data Licensing
- The legal and contractual framework governing whether data can be used to train or fine-tune AI models.
- Value Alignment
- Value Alignment is a safety or governance control for limiting harmful, noncompliant, or insecure model behavior. It is commonly used for production AI systems...
- WG
- Short for working group, a temporary or standing team focused on a specific technical area, proposal, or governance problem. The abbreviation is common in...
- Working Group
- A group formed to work on a specific technical, organizational, or policy area within a larger project, foundation, or standards process. Working groups allow...
Related Topics
- Open Source (15 terms in common)
- Compliance (13 terms in common)
- Risk Management (10 terms in common)
- Leadership (8 terms in common)
- Ai Safety (6 terms in common)
- Llm (6 terms in common)
- Boards (5 terms in common)
- Risk (5 terms in common)
- Data (5 terms in common)
- Standards (4 terms in common)
- Decision Making (4 terms in common)
- Investors (4 terms in common)
- Ai (4 terms in common)
- Controls (4 terms in common)
- Foundations (3 terms in common)
- Policies (3 terms in common)
- Documentation (3 terms in common)
- Cryptography (3 terms in common)
- Blockchain (3 terms in common)
- Key Management (3 terms in common)