Regulatory terms, defined and sourced.
The vocabulary of regulatory change, from horizon scanning to the rules themselves. Each entry links to its official source. General information, not legal advice.
A
- Agentic AI in complianceAgentic AI in compliance means AI agents that carry out multi-step compliance tasks on a trigger, use tools, and leave a record a person can audit.
- AI hallucinationAn AI hallucination is output that a language model states fluently and confidently but that is false or not supported by its sources.
- AMLA (Anti-Money Laundering Authority)AMLA is the EU agency in Frankfurt that will directly supervise selected high-risk financial firms and coordinate national AML supervisors.
C
- Compliance monitoring planA risk-based, dated schedule of what the compliance function will monitor and test, how often, by what method and with whom responsible.
- Compliance obligationA requirement an organization must meet, or has chosen to meet, arising from law, regulation, a regulator's rule, a contract, a code or a voluntary commitment.
- Consultation paperA regulator's published draft of new rules or guidance, released for public comment before the final text is decided.
- CSRD (Corporate Sustainability Reporting Directive)The CSRD is the EU directive that requires large companies to report sustainability information under the European Sustainability Reporting Standards.
D
- Dear CEO letterA letter from a UK regulator to the chief executives of a group of firms, setting out supervisory concerns and what it expects them to do.
- DORA (Digital Operational Resilience Act)DORA is the EU regulation that sets ICT risk, incident reporting, resilience testing and ICT third-party rules for financial entities.
E
- Enforcement actionA formal step a regulator takes against a firm or person for breaking the rules, such as a fine, an order, a ban or a court case.
- Environmental scanningThe management practice of gathering information about events and trends outside an organization to inform its planning, formalized by Francis Aguilar in 1967.
- EU AI ActThe EU AI Act is the EU regulation that sets risk-based rules for AI systems and general-purpose AI models, phased in from 2025 to 2028.
- EU MDR (Medical Device Regulation)The EU MDR is the regulation that governs clinical evidence, conformity assessment and post-market surveillance for medical devices sold in the EU.
F
- FCA Consumer DutyThe Consumer Duty is the FCA's requirement that firms act to deliver good outcomes for retail customers, in force since 31 July 2023.
- FDA guidance documentsDocuments that set out the US Food and Drug Administration's current thinking on a regulatory issue; nonbinding, but they shape what reviewers expect.
- FINRA Regulatory NoticesFINRA's formal notices to member firms that request comment on proposed rules, announce approved rule changes and give guidance.
G
- GDPR (General Data Protection Regulation)The GDPR is the EU regulation that governs how organizations process personal data of people in the EU, with fines up to 4% of worldwide turnover.
- General-purpose AI (GPAI) modelA general-purpose AI model is an AI model that can competently perform a wide range of distinct tasks and be built into many downstream systems.
O
- Obligations registerA structured record of every legal and regulatory duty an organization must meet, one row per obligation, with source, owner, controls and status.
- Official gazetteA government's official publication of record, where new laws, regulations and legally required notices are published.
- Official Journal of the European UnionThe EU's official gazette, where adopted EU legal acts are published in the L series and notices and information in the C series.
- Operational resilienceOperational resilience is a firm's ability to keep delivering its most important services through a severe disruption and to recover them within set limits.
P
- Private VPC deploymentA private VPC deployment runs a vendor's software inside the customer's own cloud account and network instead of in the vendor's shared environment.
- PSD3 and the Payment Services Regulation (PSR)PSD3 and the PSR are the EU's proposed successors to PSD2, splitting payment licensing rules from directly applicable conduct and fraud rules.
R
- RegTechRegulatory technology: software that helps firms meet regulatory requirements, from monitoring rule changes to reporting and financial crime checks.
- Regulatory and implementing technical standards (RTS and ITS)EU Level 2 rules that set out the technical detail of financial services legislation, drafted by the ESAs and adopted by the European Commission.
- Regulatory change impact assessmentA regulated organization's own analysis of a specific new rule: whether it applies, what it changes, and which owned, deadlined actions follow.
- Regulatory change logA dated record of each regulatory change an organization identified, the decision it took on it and the actions that followed.
- Regulatory change managementThe end-to-end process that turns each relevant regulatory change into an assessed, owned, deadlined and evidenced action.
- Regulatory compliance monitoringThe ongoing checking of which published rules apply to an organization and whether its activities actually comply with them.
- Regulatory horizon scanningThe systematic search for proposed, consulted and adopted but not yet applicable rules, so a compliance team can plan before a deadline arrives.
- Regulatory impact assessment (RIA)A rule-maker's structured appraisal of a proposed regulation's problem, options, costs and benefits, prepared before the rule is adopted.
- Regulatory intelligenceGathering and analyzing public regulatory information and communicating what it means for the business, in the Drug Information Association's definition.
- Regulatory lifecycle stagesThe stages a regulatory development moves through, from first signal and proposal to adoption, application, amendment and repeal.
- Regulatory mappingLinking each regulatory obligation to the entities, processes, policies and controls that discharge it, so coverage and gaps become visible.
- Relevance scoringRelevance scoring ranks each regulatory development by how closely it matches an organization's business, so reviewers read the most pertinent items first.
- Retrieval-augmented generation (RAG)Retrieval-augmented generation is a technique in which a language model first retrieves relevant passages from a document collection and then answers from them.
- Role-based access control (RBAC)Role-based access control grants permissions to roles rather than to individuals, and gives each user only the roles their job requires.
S
- SEC rulemakingThe process by which the US Securities and Exchange Commission proposes, takes public comment on and adopts rules under the securities laws.
- Source provenanceSource provenance is the record of where a piece of regulatory information came from, when it was published and retrieved, and exactly what it said.
- Supervisory statementA regulator's published statement of the expectations it holds firms to and how it will judge compliance with its rules.
T
- Tamper-evident audit logA tamper-evident audit log records who did what and when in a way that makes any later change, deletion or reordering of its entries detectable.
- Third-party risk managementThird-party risk management is how a firm selects, contracts with, monitors and exits outside providers, and manages the risks it takes on by relying on them.