---
title: "Glossary"
summary: "Plain-English definitions of the compliance and platform vocabulary used across Zovos."
updated: "2026-10-03"
section: "Get started"
url: "https://zovos.ai/docs-glossary.html"
---

# Glossary

Zovos uses the vocabulary of bank and credit union compliance, plus a few terms specific to how the product records decisions. These are the meanings inside the product. If a term in the app is not explained here, tell [support](support.html) and we will add it.

## A to C

- **Absence testing.** This means deterministically searching your own records for conduct that should not exist and stating which population was searched, rather than claiming nothing ever happened.
- **Access group.** An access group is a named bundle of roles, job families and a scope that an owner gives to a set of people, directly or from a directory group. Leaving the group removes what it granted. Like a job family, an access group never changes the price.
- **Agent run.** An agent run is one immutable record of one AI call. It holds the agent, target, model, prompt template version, hashed inputs, tokens and confidence.
- **AML/CFT Officer.** The AML/CFT Officer is the person designated to run the anti-money laundering and countering the financing of terrorism program. Regulations and citations that name the role the BSA officer keep that wording.
- **Append-only.** An append-only record has no edit or delete affordance. Corrections are new entries.
- **Attestation.** An attestation is a named person signing that a policy or control is in place, with a date and rationale. A certification, by contrast, is a management sub-certification round.
- **Auditee.** An auditee is anyone whose work internal audit examines. The Owner, Compliance Analyst and Risk Approver roles are auditees, so in-progress internal-audit work is hidden from them.
- **Authority Engine.** This is the check on whether the person deciding actually held delegated authority to decide. It runs off, in monitor (dry run), or in enforce mode.
- **CAE.** The chief audit executive leads internal audit and reports to the board or its audit committee. At a credit union that reporting line runs to the supervisory committee.
- **CAP.** A corrective action plan holds the remediation steps, owner and target date attached to a finding.
- **Challenge record.** This is the attributed, append-only capture of board questions, concerns, challenges and directions. A direction opens a finding.
- **Citation.** A citation is one regulatory clause, with its code, section, title, version and effective date.
- **Claim lineage.** This is the trace from a figure in a board pack back to the records behind it. On re-verification each claim reads unchanged, drifted, or unknown.
- **Corpus.** The corpus is the shipped, read-only regulatory library that citations are drawn from.
- **Coverage graph.** The coverage graph visualizes the linkage between obligations, policies, controls and evidence, and shows where it is thin.
- **Credit risk review.** Credit risk review, often called loan review, is the independent check of how the institution rates its loans. In Zovos it samples a locked loan universe, and a reviewer cannot review a credit they originated or approved.
- **CRO.** The chief risk officer leads the second-line risk function at a community bank or credit union and often holds the Risk Approver role in Zovos.
- **Crosswalk.** A crosswalk is the linkage between a citation and the controls and policies that answer it.
- **CSI.** Confidential supervisory information. One regulator's material never appears in another regulator's session.
- **CUEC.** A complementary user entity control is a control *you* must operate for a vendor's SOC opinion to hold for you.

## D to G

- **DDQ.** A due-diligence questionnaire can be outbound to a vendor or inbound from a customer.
- **Delegation of Authority matrix.** This owner-editable table maps object type and severity to the required approver roles and number of signers.
- **Design vs operating effectiveness.** Design asks whether the control is built right. Operating asks whether it actually works, and it is derived from testing.
- **Display ID.** The display ID is the human-facing business key on every record. It is stable enough to cite in a memo or an examiner response.
- **Effective challenge.** Effective challenge is documented second-line push-back. Open challenges block attestation of a self-assessment.
- **EUC.** End-user computing refers to a spreadsheet consequential enough to be governed as a model.
- **Examiner grant.** An examiner grant is the time-boxed, scope-limited session an owner issues to a regulator for one examination. It can be revoked at any time, and it is the only way the examiner role is ever held.
- **Finding.** A finding is the tracked issue, whatever its source. The source can be an examiner matter, an internal audit issue, a self-identified issue, or a board direction.
- **First-day letter.** This is the examiner's opening document request list, also called the PBC list. Zovos ingests it and maps it to your evidence.
- **Five pillars.** These are the statutory AML/CFT program elements under the Bank Secrecy Act. They are internal controls, independent testing, a designated officer, training, and risk-based customer due diligence.
- **Framework enrollment.** Enrollment marks which of the catalogued frameworks your institution is examined against, and it scopes everything downstream.
- **Fraud case log.** The fraud case log is the oversight record of fraud cases escalated for a SAR decision. One member recommends whether to file and a different member decides. It records the decision, its rationale and the dates, and never the SAR itself.
- **Gap.** A gap is an obligation with no adequate policy or control coverage. AI-generated gaps stay proposed until a person accepts them.

## H to O

- **Hide, never disable.** An action or navigation item you lack permission for is absent from the screen rather than greyed out.
- **Honest empty state.** A panel with nothing behind it renders nothing rather than a fabricated zero.
- **Independence wall.** The independence wall separates internal audit from the work it audits. Audit content is redacted at the source for anyone outside the internal audit side, and a role on that side cannot hold first-line or second-line operate or approve permissions.
- **Inherent vs residual risk.** Inherent risk is likelihood times impact before controls. Residual risk is what remains after control effectiveness. Both are computed and never typed.
- **ISO.** The information security officer runs the institution's information security program. In Zovos the ISO usually holds the Cybersecurity job family.
- **Job family.** A job family describes what a person does, such as compliance, AML/CFT or internal audit. A person can hold several. Families personalize the sidebar, the dashboard and the home page, and they never grant a permission or change the price.
- **KRI.** A key risk indicator is a measured value with thresholds and a direction. Its red, amber or green status is derived rather than declared.
- **LAR.** The HMDA loan and application register is validated for data integrity against the FFIEC layout. Zovos is not a filing tool.
- **Launch delta.** Launch delta is the computed obligation difference for a product you are considering. Each obligation shows as newly applicable, already covered, or needing amendment.
- **Lines of defense.** The first line is the business, meaning the executives and business-line owners who take and manage risk. The second line is the independent risk management and compliance functions that set standards and challenge the first line. The third line is internal audit, which tests both and reports to the board. Every job family in Zovos sits on one of the three lines except two. The Board family oversees all three, and Platform administration sits outside them.
- **Loan universe.** A loan universe is the loan population a credit review samples from, as of one date. It is imported or entered as a draft and then locked, after which it cannot change. It holds loan numbers and descriptions, and no borrower names.
- **Maker-checker.** This is the rule that the approver may not be the submitter. Critical items need two distinct signers.
- **Material vs editorial change.** A material policy change invalidates sign-off and forces re-attestation. An editorial one does not, and it needs a documented justification.
- **Monitoring activity, review, workpaper.** A monitoring activity is the recurring test. A review is one execution of it, and a workpaper is the documented evidence that execution produces.
- **MRA and MRIA.** These stand for matter requiring attention and matter requiring immediate attention. They are the examiner-issued findings that carry the most weight.
- **Over-relied control.** This is a control so many obligations depend on that it has become a single point of failure.

## P to R

- **Partner program.** A partner program is a fintech or banking-as-a-service program under sponsor-bank oversight. It is governed through gates that are earned rather than set.
- **Proof ledger.** The proof ledger is the per-tenant, append-only hash chain that seals governance events as they happen.
- **Proof pack.** A proof pack is an export a third party can verify offline with the bundled verifier, without trusting us or the export.
- **RCSA.** A risk and control self-assessment is run per business unit per cycle and closed by attestation.
- **Review exception.** A review exception is a deficiency found in a credit review, with a corrective action, a responsible person and a target date. It is resolved only by someone independent of the credit, or promoted into a finding.
- **Risk appetite.** Risk appetite is the maximum residual risk the board accepts, by category. A risk above the band is a breach requiring a decision.
- **Root cause.** A root cause is required before a High/Critical or examiner-source finding can close. Every finding also needs remediation evidence. Root cause is the basis of the repeat-finding analysis examiners look for.

## S to Z

- **Scope.** A scope limits an access group's roles to the person's own records or to chosen business units. Every screen that does not accept a scoped member is closed to them.
- **Sealed artifact.** A sealed artifact is a generated document whose content hash is recorded in the proof ledger. Board packs, minutes, workpapers and exam binders are all sealed artifacts.
- **Shadow AI.** Shadow AI is AI in use across the institution that never went through intake. The AI systems registry exists to surface it.
- **Shadow vendor.** A shadow vendor is a payee appearing in accounts-payable spend with no record in the vendor inventory.
- **Sole-operator override.** When nobody else in the workspace holds the required permission, a decision proceeds with a mandatory justification and is tagged as such in the audit trail.
- **Supervisory Committee.** At a credit union the supervisory committee oversees internal audit and the annual audit, much as an audit committee does at a community bank. When your institution profile records a credit union charter, Zovos labels the Board job family Supervisory Committee.
- **Systemic cluster.** A systemic cluster is a complaint pattern by category and regulation at or above a threshold. It is the signal a consumer regulator would act on.
- **Time machine.** The time machine reconstructs your program as it stood on a past date and labels which elements are exact and which are approximated.
- **UDAAP.** This stands for unfair, deceptive, or abusive acts or practices. It is the lens applied to marketing reviews and complaint analysis.
- **Vendor tier.** The vendor tier is the band derived from data sensitivity, system access and spend. It sets how much diligence a vendor needs.
