Plain-English glossary

What every abbreviation means.

We don't assume you live inside compliance jargon. Every abbreviation on this site is spelled out the first time it appears on a page. This page is the durable reference — one short sentence per term, no assumed knowledge.

Missing a term? Tell us and we'll add it.

AI assistant
An AI helper that drafts the work — a human reviewer still has to approve it before anything counts.
AI suggestions
Draft suggestions produced by the AI, surfaced for a human to accept, edit, or reject.
Appetite
The level of risk the board has said it's willing to accept.
Applicability
Whether this rule applies to your firm, given what you do and who you serve.
Attestation
A formal sign-off by an owner that the work is done and accurate.
Audit chain
A tamper-evident record of every change, sealed so it can't be quietly altered.
BRA
Business Risk Assessment — the firm's standing assessment of money-laundering, terrorist-financing and proliferation-financing risk.
CCO
Chief Compliance Officer.
CDD
Customer Due Diligence — the standard checks a regulated firm runs on every customer.
Compass confidence
How sure Compass is about its suggestion. It's a guide — a human still decides.
Compliance Officer
The named compliance lead in firms that don't use the CCO title.
Compliance position
The overall picture of how the firm stands against the rules it has to follow.
Compliance position
The overall picture of how the firm stands against the rules it has to follow.
Consequence
How bad it would be if the risk happened — usually broken into legal, financial and reputational harm.
Control
A check, process, or system the firm uses to make sure a rule is being followed.
Control effectiveness
How well the control is actually working in practice — not just whether it exists.
COO
Chief Operating Officer — owns the operating budget and how the business runs day-to-day.
Coordination
How RegAlign brings the firm's existing systems together so nothing falls between the cracks.
CRA
Compliance Risk Assessment — the firm's view of how well its regulatory obligations are being met.
CRO
Chief Risk Officer — accountable for the firm's overall risk position to the board.
Decision
A formal call recorded in the system — what was decided, why, and who can see it.
DPM
Data Protection Manager — operational data-protection lead; not a statutory role.
DPO
Data Protection Officer — the statutory role under data-protection law that oversees how the firm handles personal data.
DSAR
Data Subject Access Request — a person asking what personal data the firm holds on them, and what's been done with it.
EDD
Enhanced Due Diligence — deeper checks applied to higher-risk customers, such as PEPs.
ERM
Enterprise Risk Management — the framework the firm uses to identify, assess and treat all material risks, not only compliance ones.
Evidence
Documents or records that prove a control is actually working.
Evidence and audit trail
The proof and sealed record that lets the firm show, after the fact, why each decision was made.
Evidence confidence
How sure we are this evidence is current, complete, and trustworthy.
Evidence sufficiency
Whether the proof behind a decision is present, recent, and complete enough to approve it cleanly.
EWRA
Enterprise-Wide Risk Assessment — older term for the BRA; same artefact, different jurisdictions use different names.
Finding
Something a test or review spotted that may not be working as intended.
First line
First line of the Three Lines Model — the business team that owns and manages the risk day-to-day.
FIU
Financial Intelligence Unit — the national authority that receives Suspicious Activity Reports.
FIU consideration
Initial assessment of whether a SAR needs to be reported to the Financial Intelligence Unit.
GFSC
Guernsey Financial Services Commission — Guernsey's financial-services regulator.
goAML
UNODC's standard SAR-filing system used by many FIUs worldwide; produces a defined XML format.
Governance reporting status
Whether this has been reported to the board or committee that needs to see it.
Hash chain
Each entry seals the one before it; if anything changes, the seal breaks and the tamper shows.
Issue
A finding that's been accepted as needing a fix, with an owner and deadline.
JFIU
Jersey Financial Intelligence Unit — Jersey's FIU; the destination for SARs filed in the island.
JFSC
Jersey Financial Services Commission — Jersey's financial-services regulator.
KRI
Key Risk Indicator — a metric tracked over time to warn that a risk is moving in the wrong direction.
Maker-checker
Two people: one prepares the work, a different one approves it. Both are logged.
MLCO
Money Laundering Compliance Officer. Some firms appoint an MLCO distinct from the MLRO.
MLRO
Money Laundering Reporting Officer.
Monitoring frequency
How often we check this control is still working — daily, monthly, quarterly, etc.
Obligation
A specific rule the firm has to follow, drawn from law, regulation, or policy.
PEP
Politically Exposed Person — someone in a prominent public role (or close to one), warranting extra scrutiny.
POLSAR
The structured form used to file a Suspicious Activity Report with the JFIU.
RAG
Red / Amber / Green — the standard traffic-light scheme used to summarise risk and status.
Ratification
The act of formally approving a decision at the board or committee.
Ratify
Formally approve a decision at the board or committee — the polite legal word for 'sign it off'.
Recommendation status
Where a recommendation has got to: open, in progress, done, or accepted with no further action.
Residual risk
The risk left over once the firm's controls are taken into account.
Risk rating
How serious this risk is before any controls are taken into account.
Risk steward
The person accountable for a specific risk domain — typically the Compliance Officer, MLCO or MLRO, depending on the risk.
Risk treatment
The board's chosen response to a risk: accept it, mitigate it (change controls), transfer it (insurance/outsourcing) or avoid it (stop the activity).
SAR
Suspicious Activity Report — the formal notification sent to the FIU once internal review is complete.
Second line
Second line of the Three Lines Model — Compliance and Risk, who provide expertise, support and challenge to the first line.
Second-line concurrence
Whether second-line agrees with first-line's conclusion: full, partial, or disagrees.
Self-identified
An issue the business team flagged themselves, before any independent check spotted it.
SLA
Service-level agreement — the deadline by which something must be done.
Source of funds
Where the specific money used in a transaction came from.
Source of wealth
How the customer built their overall wealth, not just the funds in this transaction.
TCB
Trust Company Business — Jersey-regulated firms that provide trustee, company-secretary or director services.
Third line
Third line of the Three Lines Model — Internal Audit, who independently check the first two.
Three Lines Model
IIA's 2020 refresh of the old 'three lines of defence' — names who owns risk (first line), who oversees it (second line) and who independently checks both (third line).
Validation status
Whether second-line (Compliance / Risk) has signed off on first-line's testing.
Why trail
The reasoning behind an action — sources, options considered, and confidence.
Workflow
The connected steps the firm runs through to stay on top of its rules.