Education

The AI governance glossary behind every OwlScor report.

Not an AI primer — you already know what AI is. This is the compliance vocabulary: the frameworks, the acronyms, and the terms an auditor, regulator, or opposing counsel will actually use.

Start Here

NIST AI RMF, in four functions

The framework nearly every other standard — TRAIGA, CMMC, DFARS AI language — either references or builds on.

01

Govern

Culture, policy, and accountability structures — who owns AI risk, and is there a documented policy at all.

02

Map

Context and inventory — what AI systems exist, what they do, and how they're classified by risk.

03

Measure

Assessment — testing systems for performance, bias, and risk against defined metrics.

04

Manage

Response — prioritizing and acting on identified risks, with monitoring for what changes over time.

Reference

Governance Glossary

The specific terms you'll see in an OwlScor report, a board conversation, or a regulator's request.

NIST AI RMF

A voluntary federal framework (Govern, Map, Measure, Manage) for identifying and managing AI risk. Increasingly cited in procurement and legal language as the baseline for "reasonable" AI governance.

TRAIGA

The Texas Responsible AI Governance Act. Establishes prohibited AI uses and disclosure obligations for organizations operating in Texas — enforcement provisions are active.

CMMC

Cybersecurity Maturity Model Certification. DoD's framework for verifying contractors protect controlled unclassified information — increasingly referenced alongside AI governance requirements for defense primes and subs.

DFARS

Defense Federal Acquisition Regulation Supplement. Contract clauses DoD primes and subs must meet, including cybersecurity and, increasingly, AI system safeguards.

Evidence Tier

A confidence rating attached to each finding in an OwlScor report, from Tier 1 (self-attested questionnaire response) up through higher tiers backed by technical corroboration.

Pulse Update

A lightweight, on-demand re-score triggered by a specific event — a new AI tool, a new mandate, a legal matter — instead of a full re-run. Produces a new dated snapshot without redoing the whole intake.

AI System Inventory & Classification

The baseline question every framework starts with: do you know every AI system in production, and how each one is risk-tiered? Most organizations can't answer this without an assessment.

Data Provenance

Whether training and grounding data is documented, sourced, and rights-cleared. A growing legal exposure point as AI vendors face their own IP litigation.

Bias & Explainability

Whether a system's outputs can be explained in plain terms, and whether there's human review before a material decision. A legal requirement under several frameworks, not just a technical nicety.

Vendor / Third-Party Dependency

How exposed an organization is to a single AI vendor's terms, uptime, or compliance posture — a category regulators increasingly ask about directly since most organizations don't build their own models.

Shadow AI

AI tools adopted by employees or teams without formal review, procurement, or governance sign-off. Often the single largest gap an AI System Inventory uncovers.

Human-in-the-Loop

A control requiring a person to review or approve an AI system's output before it takes effect — the most common mitigation cited across every major AI governance framework.