Not an AI primer — you already know what AI is. This is the compliance vocabulary: the frameworks, the acronyms, and the terms an auditor, regulator, or opposing counsel will actually use.
The framework nearly every other standard — TRAIGA, CMMC, DFARS AI language — either references or builds on.
Culture, policy, and accountability structures — who owns AI risk, and is there a documented policy at all.
Context and inventory — what AI systems exist, what they do, and how they're classified by risk.
Assessment — testing systems for performance, bias, and risk against defined metrics.
Response — prioritizing and acting on identified risks, with monitoring for what changes over time.
The specific terms you'll see in an OwlScor report, a board conversation, or a regulator's request.
A voluntary federal framework (Govern, Map, Measure, Manage) for identifying and managing AI risk. Increasingly cited in procurement and legal language as the baseline for "reasonable" AI governance.
The Texas Responsible AI Governance Act. Establishes prohibited AI uses and disclosure obligations for organizations operating in Texas — enforcement provisions are active.
Cybersecurity Maturity Model Certification. DoD's framework for verifying contractors protect controlled unclassified information — increasingly referenced alongside AI governance requirements for defense primes and subs.
Defense Federal Acquisition Regulation Supplement. Contract clauses DoD primes and subs must meet, including cybersecurity and, increasingly, AI system safeguards.
A confidence rating attached to each finding in an OwlScor report, from Tier 1 (self-attested questionnaire response) up through higher tiers backed by technical corroboration.
A lightweight, on-demand re-score triggered by a specific event — a new AI tool, a new mandate, a legal matter — instead of a full re-run. Produces a new dated snapshot without redoing the whole intake.
The baseline question every framework starts with: do you know every AI system in production, and how each one is risk-tiered? Most organizations can't answer this without an assessment.
Whether training and grounding data is documented, sourced, and rights-cleared. A growing legal exposure point as AI vendors face their own IP litigation.
Whether a system's outputs can be explained in plain terms, and whether there's human review before a material decision. A legal requirement under several frameworks, not just a technical nicety.
How exposed an organization is to a single AI vendor's terms, uptime, or compliance posture — a category regulators increasingly ask about directly since most organizations don't build their own models.
AI tools adopted by employees or teams without formal review, procurement, or governance sign-off. Often the single largest gap an AI System Inventory uncovers.
A control requiring a person to review or approve an AI system's output before it takes effect — the most common mitigation cited across every major AI governance framework.