Plain-English glossary
What every abbreviation means.
We don't assume you live inside compliance jargon. Every abbreviation on this site is spelled out the first time it appears on a page. This page is the durable reference — one short sentence per term, no assumed knowledge.
Missing a term? Tell us and we'll add it.
- AI assistant
- An AI helper that drafts the work — a human reviewer still has to approve it before anything counts.
- AI suggestions
- Draft suggestions produced by the AI, surfaced for a human to accept, edit, or reject.
- Appetite
- The level of risk the board has said it's willing to accept.
- Applicability
- Whether this rule applies to your firm, given what you do and who you serve.
- Attestation
- A formal sign-off by an owner that the work is done and accurate.
- Audit chain
- A tamper-evident record of every change, sealed so it can't be quietly altered.
- BRA
- Business Risk Assessment — the firm's standing assessment of money-laundering, terrorist-financing and proliferation-financing risk.
- CCO
- Chief Compliance Officer.
- CDD
- Customer Due Diligence — the standard checks a regulated firm runs on every customer.
- Compass confidence
- How sure Compass is about its suggestion. It's a guide — a human still decides.
- Compliance Officer
- The named compliance lead in firms that don't use the CCO title.
- Compliance position
- The overall picture of how the firm stands against the rules it has to follow.
- Compliance position
- The overall picture of how the firm stands against the rules it has to follow.
- Consequence
- How bad it would be if the risk happened — usually broken into legal, financial and reputational harm.
- Control
- A check, process, or system the firm uses to make sure a rule is being followed.
- Control effectiveness
- How well the control is actually working in practice — not just whether it exists.
- COO
- Chief Operating Officer — owns the operating budget and how the business runs day-to-day.
- Coordination
- How RegAlign brings the firm's existing systems together so nothing falls between the cracks.
- CRA
- Compliance Risk Assessment — the firm's view of how well its regulatory obligations are being met.
- CRO
- Chief Risk Officer — accountable for the firm's overall risk position to the board.
- Decision
- A formal call recorded in the system — what was decided, why, and who can see it.
- DPM
- Data Protection Manager — operational data-protection lead; not a statutory role.
- DPO
- Data Protection Officer — the statutory role under data-protection law that oversees how the firm handles personal data.
- DSAR
- Data Subject Access Request — a person asking what personal data the firm holds on them, and what's been done with it.
- EDD
- Enhanced Due Diligence — deeper checks applied to higher-risk customers, such as PEPs.
- ERM
- Enterprise Risk Management — the framework the firm uses to identify, assess and treat all material risks, not only compliance ones.
- Evidence
- Documents or records that prove a control is actually working.
- Evidence and audit trail
- The proof and sealed record that lets the firm show, after the fact, why each decision was made.
- Evidence confidence
- How sure we are this evidence is current, complete, and trustworthy.
- Evidence sufficiency
- Whether the proof behind a decision is present, recent, and complete enough to approve it cleanly.
- EWRA
- Enterprise-Wide Risk Assessment — older term for the BRA; same artefact, different jurisdictions use different names.
- Finding
- Something a test or review spotted that may not be working as intended.
- First line
- First line of the Three Lines Model — the business team that owns and manages the risk day-to-day.
- FIU
- Financial Intelligence Unit — the national authority that receives Suspicious Activity Reports.
- FIU consideration
- Initial assessment of whether a SAR needs to be reported to the Financial Intelligence Unit.
- GFSC
- Guernsey Financial Services Commission — Guernsey's financial-services regulator.
- goAML
- UNODC's standard SAR-filing system used by many FIUs worldwide; produces a defined XML format.
- Governance reporting status
- Whether this has been reported to the board or committee that needs to see it.
- Hash chain
- Each entry seals the one before it; if anything changes, the seal breaks and the tamper shows.
- Issue
- A finding that's been accepted as needing a fix, with an owner and deadline.
- JFIU
- Jersey Financial Intelligence Unit — Jersey's FIU; the destination for SARs filed in the island.
- JFSC
- Jersey Financial Services Commission — Jersey's financial-services regulator.
- KRI
- Key Risk Indicator — a metric tracked over time to warn that a risk is moving in the wrong direction.
- Maker-checker
- Two people: one prepares the work, a different one approves it. Both are logged.
- MLCO
- Money Laundering Compliance Officer. Some firms appoint an MLCO distinct from the MLRO.
- MLRO
- Money Laundering Reporting Officer.
- Monitoring frequency
- How often we check this control is still working — daily, monthly, quarterly, etc.
- Obligation
- A specific rule the firm has to follow, drawn from law, regulation, or policy.
- PEP
- Politically Exposed Person — someone in a prominent public role (or close to one), warranting extra scrutiny.
- POLSAR
- The structured form used to file a Suspicious Activity Report with the JFIU.
- RAG
- Red / Amber / Green — the standard traffic-light scheme used to summarise risk and status.
- Ratification
- The act of formally approving a decision at the board or committee.
- Ratify
- Formally approve a decision at the board or committee — the polite legal word for 'sign it off'.
- Recommendation status
- Where a recommendation has got to: open, in progress, done, or accepted with no further action.
- Residual risk
- The risk left over once the firm's controls are taken into account.
- Risk rating
- How serious this risk is before any controls are taken into account.
- Risk steward
- The person accountable for a specific risk domain — typically the Compliance Officer, MLCO or MLRO, depending on the risk.
- Risk treatment
- The board's chosen response to a risk: accept it, mitigate it (change controls), transfer it (insurance/outsourcing) or avoid it (stop the activity).
- SAR
- Suspicious Activity Report — the formal notification sent to the FIU once internal review is complete.
- Second line
- Second line of the Three Lines Model — Compliance and Risk, who provide expertise, support and challenge to the first line.
- Second-line concurrence
- Whether second-line agrees with first-line's conclusion: full, partial, or disagrees.
- Self-identified
- An issue the business team flagged themselves, before any independent check spotted it.
- SLA
- Service-level agreement — the deadline by which something must be done.
- Source of funds
- Where the specific money used in a transaction came from.
- Source of wealth
- How the customer built their overall wealth, not just the funds in this transaction.
- TCB
- Trust Company Business — Jersey-regulated firms that provide trustee, company-secretary or director services.
- Third line
- Third line of the Three Lines Model — Internal Audit, who independently check the first two.
- Three Lines Model
- IIA's 2020 refresh of the old 'three lines of defence' — names who owns risk (first line), who oversees it (second line) and who independently checks both (third line).
- Validation status
- Whether second-line (Compliance / Risk) has signed off on first-line's testing.
- Why trail
- The reasoning behind an action — sources, options considered, and confidence.
- Workflow
- The connected steps the firm runs through to stay on top of its rules.