Plain-English glossary

What every abbreviation means.

We don't assume you live inside compliance jargon. Every abbreviation on this site is spelled out the first time it appears on a page. This page is the durable reference — one short sentence per term, no assumed knowledge.

Missing a term? Tell us and we'll add it.

Accountable reviewer
The named human responsible for reviewing an AI suggestion before anything is acted on.
AI assistant
An AI helper that drafts the work — a human reviewer still has to approve it before anything counts.
AI suggestions
Draft suggestions produced by the AI, surfaced for a human to accept, edit, or reject.
Appetite
The level of risk the board has said it's willing to accept.
Applicability
Whether this rule applies to your firm, given what you do and who you serve.
Attestation
A formal sign-off by an owner that the work is done and accurate.
Audit chain
A traceable record of changes and actions designed to make later alteration detectable.
BRA
Business Risk Assessment — the firm's standing assessment of money-laundering, terrorist-financing and proliferation-financing risk.
CCO
Chief Compliance Officer — a title used by some firms for their senior compliance lead.
CDD
Customer Due Diligence — the standard checks a regulated firm runs on every customer.
Compass confidence
How sure Compass is about its suggestion. It's a guide — a human still decides.
Compliance Officer
The compliance role responsible for oversight under the firm's applicable legal and regulatory framework; exact responsibilities vary by jurisdiction and firm.
Compliance position
The overall picture of how the firm stands against the rules it has to follow.
Consequence
How bad it would be if the risk happened — usually broken into legal, financial and reputational harm.
Control
A check, process, or system the firm uses to make sure a rule is being followed.
Control effectiveness
How well the control is actually working in practice — not just whether it exists.
COO
Chief Operating Officer — typically responsible for how the business operates day-to-day; remit varies by firm.
Coordination
How RegAlign coordinates supported information and workflows while keeping accountable decisions with people.
CRA
Compliance Risk Assessment — a structured assessment of compliance risk arising from applicable obligations, business activity and control context.
CRO
Chief Risk Officer — a senior role responsible for risk oversight; exact accountability varies by firm.
Decision
A formal call recorded in the system — what was decided, why, and who can see it.
DPM
Data Protection Manager — an operational data-protection title used by some organisations; responsibilities depend on the firm.
DPO
Data Protection Officer — a data-protection oversight role that may be required or appointed depending on the applicable law and the organisation's circumstances.
DSAR
Data Subject Access Request — a person asking what personal data the firm holds on them, and what's been done with it.
EDD
Enhanced Due Diligence — deeper checks applied to higher-risk customers, such as PEPs.
ERM
Enterprise Risk Management — the framework the firm uses to identify, assess and treat all material risks, not only compliance ones.
Evidence
Documents or records that support a conclusion about a control, action, decision, or outcome.
Evidence and audit trail
The proof and recorded reasoning that lets the firm show, after the fact, why each decision was made.
Evidence confidence
How sure we are this evidence is current, complete, and trustworthy.
Evidence sufficiency
Whether the proof behind a decision is present, recent, and complete enough to approve it cleanly.
EWRA
Enterprise-Wide Risk Assessment — a term used in some frameworks for an organisation-wide financial-crime risk assessment; terminology and scope vary by jurisdiction.
Finding
Something a test or review spotted that may not be working as intended.
First line
First line of the Three Lines Model — the business team that owns and manages the risk day-to-day.
FIU
Financial Intelligence Unit — the national authority that receives Suspicious Activity Reports.
FIU consideration
Initial assessment of whether a SAR needs to be reported to the Financial Intelligence Unit.
GFSC
Guernsey Financial Services Commission — Guernsey's financial-services regulator.
goAML
UNODC's standard SAR-filing system used by many FIUs worldwide; produces a defined XML format.
Governance reporting status
Whether this has been reported to the board or committee that needs to see it.
Hash chain
A linked integrity mechanism in which a change to an earlier entry can be detected through the later chain.
Issue
A finding that's been accepted as needing a fix, with an owner and deadline.
JFIU
Jersey Financial Intelligence Unit — Jersey's FIU; the destination for SARs filed in the island.
JFSC
Jersey Financial Services Commission — Jersey's financial-services regulator.
KRI
Key Risk Indicator — a metric tracked over time to warn that a risk is moving in the wrong direction.
Maker-checker
Two people: one prepares the work, a different one approves it. Both are logged.
MLCO
Money Laundering Compliance Officer. Some firms appoint an MLCO distinct from the MLRO.
MLRO
Money Laundering Reporting Officer.
Monitoring frequency
How often we check this control is still working — daily, monthly, quarterly, etc.
Obligation
A specific rule the firm has to follow, drawn from law, regulation, or policy.
PEP
Politically Exposed Person — someone in a prominent public role (or close to one), warranting extra scrutiny.
POLSAR
The structured form used to file a Suspicious Activity Report with the JFIU.
Posture (legacy wording)
Earlier RegAlign shorthand for compliance position; current product wording uses compliance position.
RAG
Red / Amber / Green — the standard traffic-light scheme used to summarise risk and status.
Ratification
The act of formally approving or confirming a decision through the relevant board or committee process.
Ratify
Formally approve or confirm a decision through the relevant board or committee process.
Recommendation status
Where a recommendation has got to: open, in progress, done, or accepted with no further action.
Residual risk
The risk left over once the firm's controls are taken into account.
Risk rating
A score or category showing the assessed seriousness of a risk at a stated stage; inherent and residual ratings should be distinguished.
Risk steward
The person accountable for a specific risk domain — typically the Compliance Officer, MLCO or MLRO, depending on the risk.
Risk treatment
The board's chosen response to a risk: accept it, mitigate it (change controls), transfer it (insurance/outsourcing) or avoid it (stop the activity).
SAR
Suspicious Activity Report — the formal notification sent to the FIU once internal review is complete.
Second line
Second line of the Three Lines Model — Compliance and Risk, who provide expertise, support and challenge to the first line.
Second-line concurrence
Whether second-line agrees with first-line's conclusion: full, partial, or disagrees.
Self-identified
An issue the business team flagged themselves, before any independent check spotted it.
SLA
Service-level agreement — the deadline by which something must be done.
Source of funds
Where the specific money used in a transaction came from.
Source of wealth
How the customer built their overall wealth, not just the funds in this transaction.
TCB
Trust Company Business — Jersey-regulated firms that provide trustee, company-secretary or director services.
Third line
Third line of the Three Lines Model — Internal Audit, who independently check the first two.
Three Lines Model
IIA's 2020 refresh of the old 'three lines of defence' — names who owns risk (first line), who oversees it (second line) and who independently checks both (third line).
Validation status
Whether second-line (Compliance / Risk) has signed off on first-line's testing.
Why trail
The reasoning behind an action — sources, options considered, and confidence.
Workflow
The connected steps the firm runs through to stay on top of its rules.