Glossary
The language of AI compliance.
Plain-language definitions of the terms a compliance or security team in financial services, insurance, or HR meets when governing AI. Each is linked to the controls and frameworks that address it.
Examination packageThe bundle of evidence a firm hands to a regulator or examiner.FINRA Regulatory Notice 24-09FINRA's 2024 reminder that existing rules apply to generative AI.FS AI RMF (Financial Services AI Risk Management Framework)A voluntary AI risk management framework for financial institutions, released by the U.S. Treasury in February 2026.MNPI (Material Non-Public Information)Information that could move a security's price and hasn't been made public.Model riskThe risk of loss from decisions based on incorrect or misused models.NIST AI 600-1 (Generative AI Profile)NIST's companion profile to the AI Risk Management Framework, defining twelve risk categories specific to generative AI.NYDFS 23 NYCRR 500New York's cybersecurity regulation for financial-services entities.PII (Personally Identifiable Information)Data that can identify an individual, subject to privacy and security controls.SR 26-2The Federal Reserve, OCC, and FDIC's joint guidance on bank model risk management, issued April 2026 to replace SR 11-7.Tamper-evident audit chainA hash-linked sequence of records where any alteration breaks the chain.WORM (Write Once, Read Many)Storage that can be written once and never altered, the basis of tamper-evident records.
See it in practice
From definitions to evidence.
See how these controls produce an examination-ready audit trail on your own traffic.