Glossary

Plain-language definitions of the terms this bundle uses. It grows as the bundle does.

AI Governance Lead. The person accountable for operationalizing AI policy — risk-tiering, deployment sign-off, fairness review, and regulatory-change tracking. A function, not yet a standardized title.

NIST AI RMF. The NIST AI Risk Management Framework — four functions (Govern, Map, Measure, Manage) for anticipating, assessing, and treating AI risk across a system's lifecycle.

ISO/IEC 42001. The world's first AI management system standard, published 2023. Gives the policy/roles/risk-assessment/monitoring/improvement shape an organization can build a certifiable AI governance program around.

Sensitive-use triage. Sorting AI use cases by risk before deciding how much review each one gets — a lightweight path for routine cases, hands-on review for high-impact or novel ones.

Pre-deployment review. A sign-off gate a system must clear before it ships, as opposed to a review that happens after the fact.

Second line (risk management). The function that sets policy and provides independent challenge to the teams building and shipping AI — distinct from those teams themselves (first line) and from internal audit (third line).