Glossary
GRC language, defined for operators and AI engines.
Clear definitions help Google, customers, and language models cite OptimaGRC correctly.
GRC (Governance, Risk, and Compliance)
GRC is the coordinated set of capabilities that help an organization reliably achieve objectives, address uncertainty, and act with integrity. It is not limited to information security.
Integrated GRC
Integrated GRC means shared data, workflows, and evidence across domains instead of separate tools for Cyber, Quality, Safety, and Audit.
ISMS (Information Security Management System)
An ISMS is the ISO/IEC 27001 system of policies, controls, risks, and improvement that protects information.
Residual risk
Residual risk is the risk remaining after controls and treatments are applied, as opposed to inherent risk before those measures.
Cross-framework control mapping
Control mapping links one implemented control to many regulatory or standard requirements so testing is not duplicated.
TPRM (Third-Party Risk Management)
TPRM is the discipline of identifying, assessing, monitoring, and remediating risk introduced by vendors, suppliers, and other third parties.
BIA (Business Impact Analysis)
A BIA identifies critical activities and the impact of disruption over time, informing RTO, RPO, and continuity strategies.
CAPA (Corrective and Preventive Action)
CAPA is the structured process of fixing the cause of a problem and preventing recurrence — used in Quality, HSE, and security findings.
Continuous control monitoring (CCM)
CCM is the automated or frequent testing of controls using system evidence rather than annual sampling only.
Operational GRC
Operational GRC extends governance, risk, and compliance into Quality, Safety, Environment, Continuity, and People — not only IT controls.
Regulatory KPIs
Regulatory KPIs are quantitative measures of obligation coverage, control health, audit cycle time, quality and HSE performance, privacy clocks, and continuity attainment that a board can read without opening a spreadsheet.
DMS (Document Management System)
A DMS generates and controls policies, procedures, forms, and work instructions using organisation templates and unique document reference numbers — rather than unmanaged copies on a shared drive.
Legal document governance
Legal document governance is the controlled register of laws, licences, circulars, permits, and regulator correspondence — with owners, effective dates, and impact on the management system.
Custom KPI build
Custom KPI build is the ability to define a measure — formula, unit, target, owner, and evidence source — that is not in a pre-built pack, then reuse it on unlimited dashboards.
