Risk and Compliance terminology

  • Release version: Zurich
  • Updated July 21, 2026
  • 1 minute to read
  • Key terms used across Risk and Compliance views in AI Control Tower, including compliance score and regulatory risk classification.

    Regulatory risk classification

    Regulatory risk classification groups AI assets by acceptability or risk category, such as unacceptable, high, medium, and low. At the asset level, classification can remain undetermined until the relevant governance data is available.

    Compliance score and compliance posture

    Compliance score represents visible compliance posture for the selected scope. Framework-specific posture views show how governance information is presented for priority authority documents or policies and can surface issue indicators relevant to those frameworks.

    Inherent risk, residual risk, and control effectiveness

    Inherent risk describes the level of risk before control effectiveness is considered. Control effectiveness describes how well controls address the identified risk. Residual risk represents the level of risk that remains after control effectiveness is considered.

    Risk heat map

    Risk heat maps show how risk information is distributed across combinations of risk level and control effectiveness. These views help users understand where higher-risk conditions are associated with less effective controls.

    Governance records

    Asset-level Risk and Compliance views can surface related governance records for an AI system, including assessments, risks, controls, issues, policy exceptions, attestations, and similar governance artifacts that contribute to the system's current posture.

    Incomplete states

    Some Risk and Compliance views can display incomplete states such as To be determined, No data available, or zero-valued indicators. These states indicate that the relevant governance information is not yet available for display in the selected context.