Skip to content

Glossary

Key terms and definitions used throughout the Modulos platform and documentation.

Use the filters to narrow to platform terms, general AI governance language, or framework-specific terminology.

Categories
Frameworks

A

ADMT supplier

CCPA ADMT Regulations

In the CCPA ADMT Regulations framework, a business that makes ADMT trained using personal information available to another business, the recipient-business, to make a significant decision. Under Cal. Code Regs. tit. 11, section 7153, it must provide to the recipient-business all facts available to it that are necessary for the recipient-business to conduct its own risk assessment; the duty applies only to ADMT trained using personal information, is triggered by making the ADMT available rather than by any transfer of personal information, and runs one way, the recipient-business having no section 7153 duty to obtain the facts. An ADMT supplier is also a business using ADMT wherever it uses the technology for its own significant decisions. Supplier is the framework's label for this role; the regulation speaks of a business that makes ADMT available and of the recipient-business.

Also called
Recipient-business
In Modulos
The CCPA Role tag value ADMT supplier marks MRF-495 and MRF-496 (controls MCF-701 and MCF-702).

Adverse outcome

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(1)), a decision that denies, terminates, revokes, or materially reduces or restricts a consumer's access to, eligibility for, selection for, compensation for, or the provision of an opportunity or service, or one resulting in materially less favorable differentiated price, cost, compensation, or other material terms that are reasonably likely to materially limit, delay, or effectively deny, or otherwise fundamentally alter, that access, eligibility, selection, compensation, or provision of an opportunity or service compared to terms offered to similarly situated consumers. It triggers the deployer's 30-day post-adverse-outcome disclosures and, on request, the consumer's correction and meaningful-human-review rights.

In Modulos
Requirements MRF-486 (disclosures, control MCF-692) and MRF-487 (rights, control MCF-693).

AI governance

AI Governance

The people, processes, and controls used to ensure AI is developed and used responsibly, safely, and in line with laws, standards, and organizational goals.

AI management system

ISO 42001AI Governance

An organizational management system for governing AI across the lifecycle, including policies, roles, oversight, performance evaluation, and continuous improvement.

Also called
AIMS

AI model

AI Governance

A mathematical or machine learning component that transforms inputs into outputs. A model is typically one component within a broader AI system.

AI system

PlatformAI GovernanceEU AI Act

A machine-based system that, for a given set of objectives, produces outputs such as predictions, content, recommendations, or decisions.

In governance, an AI system is more than a model: it includes data, software components, infrastructure, people, and processes that shape real-world behavior.

Also called
AI application
In Modulos
Represented as a project, with lifecycle stage, frameworks, requirements, controls, evidence, assets, tests, and risk quantification.

Annex III

EU AI Act

A section of the EU AI Act that lists high-risk use cases by intended purpose. Systems in these categories typically trigger high-risk obligations.

API token

Platform

A personal credential used to authenticate API requests for automation and integrations. Treat API tokens like passwords.

In Modulos
Managed in User Settings under API Tokens.

Asset

Platform

A structured record for governance artifacts such as model cards, dataset cards, policies, and assessments. Assets support collaboration, review, and audit readiness.

In Modulos
Managed under Assets. Many assets support review before being marked completed.

Audit pack

PlatformAI Governance

An exportable package of requirements, controls, evidence, and supporting artifacts that you can share for internal review or external assurance.

In Modulos
Generated from the project via exports.

Audit trail

PlatformAI Governance

A chronological record of changes and actions. In practice this is often implemented as comments, logs, and immutable change history.

Authorized representative

EU AI Act

Under the EU AI Act, an EU-based entity appointed by a non-EU provider to carry out specific compliance tasks and act as a contact point for authorities.

Related

Automated decision-making technology

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(2), enrolled-act numbering), a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual. Excluded are a fixed technology list (anti-malware, calculators, databases, firewalls, spreadsheets that require human analysis and do not use machine learning, foundation models, or large language models, and others), tools used by an individual solely to summarize, organize, translate, draft, route, or present information for human review of administrative processing, and consumer-facing natural-language technology that is not contracted, advertised, marketed, configured, or intended for consequential decisions and is subject to an acceptable-use policy prohibiting such use.

Also called
ADMT

Automated decisionmaking technology (CCPA)

CCPA ADMT Regulations

Under the CCPA ADMT Regulations (Cal. Code Regs. tit. 11, section 7001(e)), any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking. A business substantially replaces human decisionmaking when it uses the technology's output to make a decision without human involvement. ADMT includes profiling that replaces or substantially replaces human decisionmaking, and it is not limited to artificial intelligence: rules-based technology qualifies on the same terms. Web hosting, domain registration, networking, caching, website-loading, data storage, firewalls, anti-virus, anti-malware, spam- and robocall-filtering, spellchecking, calculators, databases, and spreadsheets are not ADMT, provided that they do not replace human decisionmaking. Spelled without a hyphen in the regulations; Colorado SB 26-189 defines a different automated decision-making technology under the same initials.

Also called
ADMT (CCPA)
In Modulos
The coverage determination is requirement MRF-489, carried by control MCF-695.

Automated employment decision tool

NYC Local Law 144

Under NYC Local Law 144 (section 20-870), any computational process, derived from machine learning, statistical modeling, data analytics, or artificial intelligence, that issues simplified output, including a score, classification, or recommendation, that is used to substantially assist or replace discretionary decision making for making employment decisions that impact natural persons. The DCWP rules read 'substantially assist or replace' as relying solely on the output, weighting it more than any other criterion, or using it to overrule conclusions from other factors including human decision-making. The statute lists junk email filters, firewalls, antivirus software, calculators, spreadsheets, databases, data sets, and other data compilations as examples of excluded tools, but only where the tool does not automate, support, substantially assist, or replace discretionary decision-making and does not materially impact natural persons.

Also called
AEDT
In Modulos
The in-or-out determination is requirement MRF-476, recorded through the shared control MCF-16 (Risk Tiering).

B

Bias audit

NYC Local Law 144

Under NYC Local Law 144, an impartial evaluation by an independent auditor that tests an automated employment decision tool's disparate impact on the EEO-1 Component 1 categories. For a selection or classification function it calculates the selection rate for every category and the impact ratio for each category (except a category properly excluded under the less-than-2-percent rule, whose count and rate are still reported); for a scoring function it calculates the median score for the full sample, the scoring rate for every category, and the impact ratio subject to the same exception; both sets apply if the tool does both. The calculations run separately for sex, race/ethnicity, and intersectional categories, and the audit states how many assessed individuals were omitted because they fell within an unknown category. A tool may not be used if more than one year has passed since its most recent bias audit.

In Modulos
Requirements MRF-477 (the audit) and MRF-478 (its data), carried by control MCF-684 (Independent AEDT bias audit).

Business (CCPA)

CCPA ADMT Regulations

Under Civ. Code section 1798.140(d), a sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity organized or operated for the profit or financial benefit of its shareholders or other owners that collects consumers' personal information or has it collected on its behalf, alone or jointly with others determines the purposes and means of the processing, does business in California, and satisfies one or more of three thresholds: as of January 1 of the calendar year, annual gross revenues in the preceding calendar year in excess of the section 1798.140(d)(1)(A) figure of $25,000,000 as adjusted ($26,625,000 since January 1, 2025); alone or in combination, annually buying, selling, or sharing the personal information of 100,000 or more consumers or households; or deriving 50 percent or more of annual revenues from selling or sharing consumers' personal information. An entity under common control and common branding that shares consumers' personal information with such a business, a joint venture of businesses each holding at least a 40 percent interest, and a person doing business in California, not covered by the other routes, that voluntarily certifies to the Agency that it complies with and is bound by the CCPA also qualify. The CCPA ADMT Regulations apply to a business that uses ADMT to make a significant decision concerning a consumer or processes personal information it intends to use to train such ADMT. The monetary thresholds are adjusted in odd-numbered years to reflect any increase in the Consumer Price Index, next effective January 1, 2027.

Also called
Business using ADMT
In Modulos
The CCPA Role tag value Business using ADMT marks all 13 requirements of MFF-29 and OFF-29; business status is tested in MRF-489.

C

California Privacy Protection Agency

CCPA ADMT Regulations

The California regulator that implements and enforces the California Consumer Privacy Act, short name CalPrivacy. It adopted the CCPA regulations on automated decisionmaking technology and risk assessments on July 24, 2025; the Office of Administrative Law approved them on September 22, 2025 and they took effect on January 1, 2026. Businesses submit information about their risk assessments to the Agency under section 7157, and the Agency or the Attorney General may require the risk assessment reports themselves at any time. In its Final Statement of Reasons the Agency said it may revisit the ADMT definition, the significant-decision definition, and the Article 11 applicability provision in future rulemaking. The Agency adjusts the CCPA monetary thresholds in odd-numbered years for any increase in the Consumer Price Index.

Also called
CalPrivacyCPPAthe Agency (CCPA)

CCPA ADMT Regulations

CCPA ADMT Regulations

The California Privacy Protection Agency's (CalPrivacy) regulations on automated decisionmaking technology (ADMT) under the California Consumer Privacy Act, Civ. Code section 1798.100 et seq., codified in Cal. Code Regs. tit. 11. They implement the CCPA and are not a new statute. Adopted July 24, 2025, approved by the Office of Administrative Law September 22, 2025, effective January 1, 2026. A business that uses ADMT to make a significant decision concerning a consumer must provide a Pre-use Notice (section 7220), the ability to opt out of ADMT except on the conditions of three exceptions (section 7221), and responses to requests to access ADMT (section 7222), and must conduct a risk assessment before initiating the processing (sections 7150 through 7157); a business that processes consumers' personal information it intends to use to train such ADMT must also conduct a risk assessment. Consumers include California-resident employees, job applicants, independent contractors, and students. Article 11 compliance is due no later than January 1, 2027 for a business that used ADMT for a significant decision before that date, and at any time a business uses ADMT for a significant decision on or after it; risk assessments of processing that began before January 1, 2026 and continues are due by December 31, 2027; information about assessments conducted in 2026 and 2027 is submitted to the Agency by April 1, 2028, with later filings due by April 1 following any year in which assessments were conducted.

Also called
California ADMT regulationsCPPA ADMT regulationsCCPA automated decisionmaking technology regulations
In Modulos
Modeled as the paired templates MFF-29 (one project per ADMT, MRF-489 through MRF-496) and OFF-29 (organization, ORF-488 through ORF-492), with 13 new controls (MCF-695 through MCF-702, OCF-385 through OCF-389), none shared, and a CCPA Role tag (Business using ADMT; Service provider or contractor; Third party; ADMT supplier).

CE marking

EU AI Act

A marking that indicates a product meets applicable EU requirements. For some high-risk AI systems and regulated products, CE marking is part of the conformity route.

Colorado SB 26-189

Colorado SB 26-189

Colorado Senate Bill 26-189 (2026, Session Law chapter 131), signed May 14, 2026, is Colorado's current law on automated decision-making technology (ADMT) used to materially influence consequential decisions. It repealed and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes, replacing the 2024 Colorado AI Act (SB 24-205) before that act ever applied. Subject to sections 6-1-1702(3) and (5), developers owe deployers a five-element transparency package and update notices. Deployers owe consumers the applicable pre-use notice, post-adverse-outcome disclosures within 30 days, correction instructions, and a meaningful-human-review opportunity to the extent commercially reasonable. Developers retain the required records for at least three years after each record's creation and deployers for at least three years after each consequential decision, longer where other law requires. Liability under existing state anti-discrimination law is allocated by relative fault; section 6-1-1707(7) voids specified developer-deployer contract provisions indemnifying a party for its own Colorado anti-discrimination violations, subject to a developer carve-out, while other lawful commercial terms and insurance claims are unaffected. The Attorney General enforces part 17 through the Colorado Consumer Protection Act, with the sections 6-1-1702 through 6-1-1705 disclosure requirements and consumer rights enforceable exclusively by the Attorney General. The developer and deployer duties apply to consequential decisions made on or after January 1, 2027; the provisions listed in Section 5(2) of the act took effect on passage; the mandatory Attorney General rules are due on or before January 1, 2027. The act has no statutory short title: Colorado AI Act and CAIA commonly refer to the repealed SB 24-205 regime, and Colorado ADMT law is an informal and potentially ambiguous label; literature under those names published before May 2026 describes the repealed statute.

Also called
Colorado AI ActCAIAColorado ADMT law
In Modulos
Modeled as the paired templates MFF-28 (one project per covered ADMT, MRF-482 through MRF-488) and OFF-28 (organization, ORF-483 through ORF-487), with 12 new controls and the shared control MCF-171, and an ADMT Role tag (Developer, Deployer).

Comments and logs

Platform

A shared activity feed attached to governance objects, used to document decisions, changes, and review discussions over time.

Conformity assessment

AI GovernanceEU AI Act

A structured process to demonstrate that requirements have been met. Under the EU AI Act, the applicable conformity route depends on system type, role, and product context.

Connector

Platform

A user account connection to an external tool or service. Connectors are tied to a person and are used to bring user-scoped data into Modulos and Scout.

In Modulos
Configured in User Settings under Connectors.

Consequential decision

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(3)), a decision, determination, or action made about a consumer that relates to the provision of, or the consumer's access to, eligibility for, selection for, or compensation for, a covered domain, or one that relates to a differentiated price, cost sharing, compensation, or other material terms in a manner reasonably likely to materially limit, delay, effectively deny, or otherwise fundamentally alter the consumer's access, eligibility, or opportunity for a covered domain. Nine exclusions apply, each on its own conditions, including low-stakes or routine processes, advertising and marketing, human-analysis spreadsheets, summarize-for-human-review uses without a materially influencing inference, narrow procedural tasks, cybersecurity and anti-money-laundering controls, sanctions compliance, fraud prevention, and routine academic administration.

Control

PlatformAI Governance

A measure that reduces risk or supports compliance. Controls can be technical, organizational, or procedural.

In Modulos
Controls are executed and supported by evidence. Execution feeds requirement readiness and fulfillment.

Control readiness

Platform

A progress signal for a control based on what has been documented and linked. Readiness helps teams prioritize what to execute next.

Covered ADMT

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(5)), automated decision-making technology that is used to materially influence a consequential decision. The developer and deployer duties of the act attach to covered ADMT only.

In Modulos
The coverage and role determination is requirement MRF-482, carried by control MCF-688.

Covered domain

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(6)), one of seven areas in which a decision can be consequential: education; employment or an employment opportunity that creates or may create an employer-employee relationship; the lease or purchase of residential real estate in Colorado; a financial or lending service; insurance (underwriting, pricing, coverage, claims adjudication, or other determinations materially affecting access to benefits); health-care services; and essential government services and public benefits.

D

Data Protection Impact Assessment

GDPR

A risk assessment required by GDPR for certain processing activities. A DPIA documents necessity, proportionality, risks, and mitigations.

Also called
DPIA

Deployer

EU AI Act

Under the EU AI Act, the entity that uses an AI system under its authority, for example by integrating it into a product or business process.

Related

Deployer (Colorado SB 26-189)

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(7)), a person doing business in Colorado that deploys a covered ADMT. The role is not exclusive of the developer role; a deployer that intentionally and substantially modifies an ADMT into a covered ADMT becomes its developer.

In Modulos
The ADMT Role tag value Deployer marks MRF-482, MRF-485 through MRF-488, and ORF-483 through ORF-487.

Developer (Colorado SB 26-189)

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(8)), a person doing business in Colorado that develops, offers, sells, leases, licenses, or otherwise makes commercially available a covered ADMT; develops a component designed, marketed, intended, documented, advertised, configured, or contracted to be used as part of one; or intentionally and substantially modifies an ADMT such that it becomes a covered ADMT. Excluded are development and use solely for research purposes where the ADMT is not used in a consequential decision in the research; internal-only use not made available to others for consequential decisions; a preceding developer after an unaffiliated person's modification that changes the system's intended, documented, marketed, advertised, configured, or contracted use; and a component integrated into a covered ADMT without the person's actual knowledge. The role is not exclusive of the deployer role and can be acquired later, including through modification.

In Modulos
The ADMT Role tag value Developer marks MRF-482, MRF-483, MRF-484, ORF-486, and ORF-487.

Distribution date

NYC Local Law 144

Under the NYC Local Law 144 rules, the date the employer or employment agency began using a specific automated employment decision tool. It must be posted with the date of the most recent bias audit and the required summary before the tool is used, and remain posted for at least six months after the tool's last use for an employment decision. It is the deployer's first-use date, not the vendor's release date.

In Modulos
Part of the publication requirement MRF-479, carried by control MCF-685.

Distributor

EU AI Act

Under the EU AI Act, an entity that makes an AI system available on the EU market without being the provider or importer.

Related

E

Evidence

PlatformAI Governance

Information that supports a claim of compliance or execution. Evidence can be files, links, logs, metrics, or structured records.

In Modulos
Stored in the Evidence library and linked to controls, requirements, and risks.

F

Fermi estimate

PlatformAI Governance

An order-of-magnitude estimate created by decomposing a complex question into explicit assumptions that can be challenged and refined.

FINMA AI Governance

FINMA AI Governance

FINMA Guidance 08/2024 on governance and risk management when using AI, issued by the Swiss Financial Market Supervisory Authority. The existing technology-neutral, principle-based supervisory framework already covers AI, so the guidance creates no new obligations; it reports seven areas FINMA assessed: governance, inventory and risk classification, data quality, testing and ongoing monitoring, documentation, explainability, and independent review.

Foundation model

AI GovernanceEU AI Act

A large, general model trained on broad data that can be adapted to many tasks. Foundation models are often a component of a broader AI system.

Framework version

Platform

A versioned release of a framework. Versions enable controlled updates as regulations and standards evolve.

In Modulos
Projects can update to the latest version or freeze updates for stability during reviews and audits.

G

General-purpose AI model

AI GovernanceEU AI Act

A model designed for generality across tasks and domains, often provided as a reusable capability. In the EU AI Act this concept is referred to as GPAI.

Also called
GPAI model
Related

H

High-risk AI system

EU AI Act

An AI system that falls into a high-risk category under the EU AI Act, for example because of its intended purpose or because it is a safety component of a regulated product.

Human involvement (CCPA ADMT Regulations)

CCPA ADMT Regulations

Under Cal. Code Regs. tit. 11, section 7001(e)(1), the condition that keeps a technology from substantially replacing human decisionmaking. It requires the human reviewer to know how to interpret and use the technology's output to make the decision, to review and analyze the output and any other information that is relevant to make or change the decision, and to have the authority to make or change the decision based on that analysis. All three parts must hold, and the test is applied in the original decision flow: a reviewer who lacks any part leaves the technology in scope, and a reviewer available only on appeal after the decision never takes it out. Human involvement is distinct from the human-appeal exception to the opt-out in section 7221(b)(1).

In Modulos
The organization capability behind a human-involvement claim is ORF-489, carried by control OCF-386; the per-technology test is part of MRF-489.

Human oversight

AI GovernanceEU AI Act

Measures that enable people to understand, monitor, and intervene in AI system behavior so that risks can be detected and corrected in time.

In Modulos
Implemented through ownership, reviews, approvals, and clear accountability across controls, requirements, evidence, and assets.

I

Impact ratio

NYC Local Law 144

Under the NYC Local Law 144 rules, either the selection rate for a category divided by the selection rate of the most selected category, or the scoring rate for a category divided by the scoring rate of the highest scoring category. The reference category has an impact ratio of 1.00 whenever its rate is above zero. Local Law 144 sets no threshold for the ratio; the four-fifths (80 percent) benchmark of the EEOC Uniform Guidelines is a federal reference point, not a Local Law 144 requirement.

Independent auditor

NYC Local Law 144

Under the NYC Local Law 144 rules (6 RCNY section 5-300), a person or group capable of exercising objective and impartial judgment on all issues within the scope of a bias audit. An auditor is not independent if they are or were involved in using, developing, or distributing the tool; have, at any point during the audit, an employment relationship with the employer or employment agency that seeks to use the tool or with the vendor that developed or distributes it; or have a direct or material indirect financial interest in either. DCWP maintains no list of approved auditors.

Information security management system

ISO 27001

A management system for establishing, implementing, maintaining, and continually improving information security, typically aligned to ISO 27001.

Also called
ISMS

ISO 27001

ISO 27001

An international standard for information security management systems, used for organizational security governance, risk management, and certification.

ISO 42001

ISO 42001

An international standard for AI management systems. It focuses on organizational processes and governance for AI across the lifecycle.

Also called
AIMS standard

L

Logging and record keeping

AI GovernanceEU AI Act

The practice of keeping records that support traceability, monitoring, and investigation, including inputs, outputs, decisions, and key lifecycle events.

M

MAS FEAT

MAS FEAT

A set of principles and guidance from the Monetary Authority of Singapore focused on fairness, ethics, accountability, and transparency in AI and data analytics.

Material update

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(14)), an update, patch, release, revision, or new version of a covered ADMT, including associated software, model parameters, default settings, or documentation, that the developer knows or reasonably should know is likely to materially affect the tool's outputs or performance in a manner relevant to its intended use, or the developer's stated intended use. Routine maintenance, cosmetic changes, and bug fixes without such effects are excluded. When section 6-1-1702(5) applies, a developer must notify each deployer within a reasonable time of material updates and the other changes listed in section 6-1-1702(2), for the deployer uses section 6-1-1702(3) covers.

In Modulos
Requirement MRF-484, carried by control MCF-690.

Materially influence

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(13)), an ADMT output materially influences a consequential decision when it is a non-de minimis factor used in making the decision and affects its outcome, including by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made; incidental, trivial, or clerical uses are excluded. The Attorney General may adopt rules clarifying the definition, including through presumptions, illustrative examples, and objective indicators.

Meaningful human review

Colorado SB 26-189

Under Colorado SB 26-189 (C.R.S. section 6-1-1701(15)), review of a consequential decision by an individual designated by the deployer who has authority to approve, modify, or override the decision and who considers relevant, available primary evidence, is trained to conduct the review, does not default to the system output, and has access to sufficient information to understand the output's intended use, material limitations, and categories of inputs and the principal factors used to generate it, without requiring disclosure of proprietary source code, model weights, or other trade secrets. A consumer who experiences an adverse outcome may request an opportunity for meaningful human review and reconsideration to the extent commercially reasonable.

In Modulos
The per-tool exercise is MRF-487 (control MCF-693); the organization capability is ORF-484 (control OCF-381).

Model card

PlatformAI Governance

A structured document describing a model’s intended use, performance, limitations, and key risks, designed to support responsible deployment.

Modulos Client

Platform

A client library and tooling to integrate your systems with Modulos via API, typically used to automate governance data flows and evidence capture.

Monte Carlo simulation

PlatformAI Governance

A probabilistic method that uses random sampling to model uncertainty. In risk quantification, it produces a distribution of possible monetary losses.

N

NIST AI RMF

NIST AI RMF

A risk management framework from NIST that provides guidance and functions to govern, map, measure, and manage AI risks.

NIST AI RMF functions

NIST AI RMF

The core functions of the NIST AI RMF: Govern, Map, Measure, and Manage. Teams use them to structure risk management work across the AI lifecycle.

NYC Local Law 144

NYC Local Law 144

New York City's Local Law 144 of 2021 on automated employment decision tools (N.Y.C. Administrative Code sections 20-870 through 20-874, implemented by DCWP rules 6 RCNY sections 5-300 through 5-304). In the city, an employer or employment agency may not use such a tool to screen candidates for employment or employees for promotion unless the tool has had a bias audit by an independent auditor no more than one year before use; the audit date, the required summary, and the tool's distribution date are publicly posted before use and kept posted for at least six months after the latest use for an employment decision; and candidates and employees who reside in the city are notified at least 10 business days before the tool assesses them. The rules also require posting the tool's data type, data source, and data retention policy, with written-request instructions, clearly and conspicuously on the employment section of the website, answering such requests within 30 days, and withholding, with an explanation, information whose disclosure the law prohibits. Effective January 1, 2023; enforced by the Department of Consumer and Worker Protection since July 5, 2023.

Also called
Local Law 144LL144NYC AEDT law
In Modulos
Modeled as the application-level template MFF-27 (one project per tool), with 6 requirements MRF-476 through MRF-481 and 4 new controls MCF-684 through MCF-687.

O

Organization

Platform

The top-level entity in Modulos where global settings, users, and organization-level configuration are managed.

In Modulos
Organization admins can view and edit all organization configuration. Project access is managed separately.

Organization roles

Platform

Roles that apply across an organization, such as Organization Admin, Organization Member, Organization Risk Manager, and Organization Policy Manager. Roles shape what users can manage versus view.

In Modulos
Organization Admins can view and edit everything in the organization. Organization Risk Managers maintain organization-level risk quantification settings and budgets. Organization Policy Managers review, approve, and publish policy versions in Policy Center.

OWASP Top 10 for Agentic Applications

OWASP Top 10 for Agentic

A community list of common security risks in agentic AI applications, focusing on multi-step autonomy, tool orchestration, delegation, and inter-agent communication.

Also called
OWASP Agentic Top 10OWASP Top 10 for Agentic
Related

P

Personal identifiable information

ISO 27701GDPR

Information that can identify a person, directly or indirectly. ISO 27701 uses the term PII and defines additional privacy management practices.

Also called
PII

Policies and procedures

AI GovernanceISO 27001ISO 42001

Documented organizational rules and operating practices used to ensure consistent, auditable behavior across teams and systems.

Policy manager

PlatformAI Governance

A role responsible for reviewing and approving policy versions before they are published to the organization.

In Modulos
Represented as an Organization Policy Manager role. Policy Managers are notified when a version is submitted for approval and can approve, reject (with a reason), or publish versions in Policy Center.

Pre-use Notice

CCPA ADMT Regulations

Under the CCPA ADMT Regulations (Cal. Code Regs. tit. 11, section 7220), the notice a business must give consumers when it uses ADMT to make a significant decision concerning them. It must be presented prominently and conspicuously at or before the point when the business collects the personal information it plans to process using the ADMT (or, for information already collected for a different purpose, before that processing), in the manner in which the business primarily interacts with the consumer, and in compliance with section 7003(a) and (b). It must give a plain-language explanation of the specific purpose; the right to opt out of ADMT and how to submit the request, or, where the business relies on the human-appeal exception, the ability to appeal with instructions, or, where it relies on another section 7221(b) exception, the specific exception relied upon; the right to access ADMT and how to submit the request; the non-retaliation statement; and how the ADMT works, including the categories of personal information that affect the output, the type of output and how it is used, and the alternative process for consumers who opt out unless an exception applies. Only the how-it-works layer may omit trade secrets and information that would compromise the business's ability to prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information, to resist malicious, deceptive, fraudulent, or illegal actions directed at the business or at consumers or to prosecute those responsible, or to ensure the physical safety of natural persons. It may sit in the Notice at Collection.

In Modulos
Requirement MRF-490, carried by control MCF-696; the notice templates and wiring are ORF-491 (OCF-388).

Project

Platform

A scoped workspace for an AI system or organizational governance effort. Projects contain frameworks, requirements, controls, evidence, assets, testing, and risk quantification.

Project roles

Platform

Roles that control access within a project. Project roles are separate from organization roles so teams can limit access to sensitive workstreams.

Prompt injection

OWASP Top 10 for LLMAI Governance

An attack where an adversary manipulates a model’s instructions or context to produce unintended behavior, potentially bypassing safeguards.

R

Red teaming

AI GovernanceOWASP Top 10 for LLM

A structured practice for stress-testing an AI system by probing for failures, misuse, and adversarial behavior, often using realistic attacker mindsets.

Request to access ADMT

CCPA ADMT Regulations

Under the CCPA ADMT Regulations (Cal. Code Regs. tit. 11, section 7222), a verifiable consumer request for information about a business's use of ADMT to make a significant decision concerning the consumer. The business must provide plain-language explanations of the specific purpose for which it used the ADMT with respect to that consumer; the logic of the ADMT, enabling the consumer to understand how it processed their personal information to generate an output with respect to them; the outcome of the decisionmaking process, including how the business used the output to make the significant decision and, where the business plans an additional significant decision from that output, how it will be used; and the non-retaliation statement with instructions for exercising the consumer's other CCPA rights. Only the logic and outcome elements may omit trade secrets and information that would compromise the business's ability to prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information, to resist malicious, deceptive, fraudulent, or illegal actions directed at the business or at consumers or to prosecute those responsible, or to ensure the physical safety of natural persons. The request is verified under Article 5, confirmed within 10 business days, and answered within 45 calendar days, extendable once by up to 45 days where necessary; a business that used an ADMT with respect to a consumer more than four times within a 12-month period may provide an aggregate-level response for the logic information. A service provider or contractor must assist the business in responding.

Also called
Access to ADMT
In Modulos
Requirement MRF-494, carried by control MCF-700; the request machinery is ORF-488 (OCF-385).

Request to appeal ADMT

CCPA ADMT Regulations

Under the CCPA ADMT Regulations (Cal. Code Regs. tit. 11, sections 7001(kk) and 7221(b)(1)), a consumer request to appeal the business's use of ADMT for a significant decision, available where the business relies on the human-appeal exception instead of providing the ability to opt out. To qualify for the exception the business must designate a human reviewer who reviews and analyzes the output of the ADMT and any other information relevant to change the decision, considers the information the consumer provides in support of the appeal, knows how to interpret and use the output, and has the authority to change the decision; and it must clearly describe how to submit an appeal, enable the consumer to provide information to the reviewer, and offer a method that is easy to execute, requires minimal steps, and complies with section 7004, with section 7003(a) and (b) communications, the section 7021 timelines, and Article 5 verification. The appeal removes only the opt-out; the Pre-use Notice, the right to access ADMT, and the risk assessment continue to apply, and the notice must inform the consumer of the ability to appeal with instructions.

Also called
Human-appeal exceptionHuman appeal (CCPA ADMT)
In Modulos
Requirement MRF-492, carried by control MCF-698; the reviewer capability is ORF-489 (OCF-386).

Request to opt-out of ADMT

CCPA ADMT Regulations

Under the CCPA ADMT Regulations (Cal. Code Regs. tit. 11, section 7221), a consumer's request that a business stop using ADMT to make a significant decision concerning them. A business must provide the ability to opt out except where one of three exceptions applies on its conditions: a human-appeal route to a reviewer with the authority to overturn the decision (subsection (b)(1)); the admission, acceptance, or hiring exception (subsection (b)(2)); or the allocation or assignment of work and compensation exception (subsection (b)(3)), the latter two requiring that the ADMT be used solely for the permitted purpose and that it work for the business's purpose and not unlawfully discriminate based upon protected characteristics. The business must offer two or more designated methods, online including an interactive form reached through an opt-out link in the Pre-use Notice, must not require verification, an account, or burdensome information, and must provide a means to confirm the request was processed. A request received before the processing begins bars it; a request received after the processing began from a consumer who did not opt out at the Pre-use Notice requires the business to cease processing that consumer's personal information using that ADMT as soon as feasibly possible and no later than 15 business days, and to instruct the recipients of that consumer's information for that ADMT to comply in the same time frame.

Also called
Opt-out of ADMTADMT opt-out
In Modulos
Requirement MRF-491, carried by control MCF-697; the exceptions are MRF-492 (human appeal, MCF-698) and MRF-493 (hiring and work allocation, MCF-699); the request machinery is ORF-488 (OCF-385).

Requirement

PlatformAI Governance

A statement of what must be satisfied, usually sourced from a framework. Requirements provide audit-ready structure for governance work.

In Modulos
Requirements are fulfilled when related controls are executed with supporting evidence. The requirement view also supports comments and ownership.

Requirement readiness

Platform

A progress signal for a requirement based on the readiness and execution of mapped controls.

Review

PlatformAI Governance

The accountability step that finalizes governance work. Controls change status directly with a logged comment; a Requirement becomes ready for review once its linked Controls reach a final status, and the Requirement Owner reviews the completed work and marks the Requirement fulfilled. Assets keep a formal review request that assigned reviewers approve or reject.

Risk appetite

PlatformAI Governance

The amount of risk an organization is willing to accept, expressed as a monetary budget or limit that guides prioritization and delegation.

Risk assessment (CCPA)

CCPA ADMT Regulations

Under Cal. Code Regs. tit. 11, Article 10 (sections 7150 through 7157), the assessment a business must conduct and document before initiating processing that presents significant risk to consumers' privacy, which includes using ADMT for a significant decision concerning a consumer (section 7150(b)(3)) and processing consumers' personal information the business intends to use to train such ADMT (section 7150(b)(6)). The assessment identifies the specific purpose, the categories of personal information and the minimum necessary, the operational elements, and, for ADMT uses, the logic of the ADMT with its assumptions and limitations and the output and how it will be used; weighs the negative impacts to consumers' privacy against the benefits; records the safeguards and whether the business will initiate the processing; and is reviewed and approved by an individual with authority to participate in the initiation decision. It is reviewed, and updated as necessary, at least every three years, updated as soon as feasibly possible and no later than 45 calendar days after a material change, and retained while the processing continues or for five years after the completion of the assessment, whichever is later. Processing begun before January 1, 2026 that continues must be assessed by December 31, 2027. Information about the assessments (not the assessments or reports themselves; the reports are required on the Agency's or the Attorney General's request) is submitted to the Agency by April 1, 2028 for assessments conducted in 2026 and 2027 and by April 1 following any later year with assessments; the reports are produced on the Agency's or the Attorney General's request, within 30 calendar days.

Also called
CCPA risk assessmentRisk assessment report (CCPA)
In Modulos
Requirement MRF-495 (control MCF-701) for one ADMT; the program and the Agency submissions are ORF-490 (control OCF-387).

Risk category

Platform

A high-level grouping used to organize risks, for example technical, operational, legal and compliance, ethical and reputational, and governance risks.

Risk limit

PlatformAI Governance

A monetary ceiling allocated to a project or category to keep aggregate exposure within the organization’s risk appetite.

Risk management

AI GovernanceEU AI ActISO 27001NIST AI RMF

The ongoing process of identifying, analyzing, and treating risk. Effective risk management is continuous and tied to real operational decisions.

Risk manager

PlatformAI Governance

A role responsible for maintaining risk methods, assumptions, and budgets, and supporting teams who quantify and manage risk in projects.

In Modulos
Often represented as an Organization Risk Manager role, focused on risk quantification methods, taxonomy, and budget governance.

Risk matrix

AI Governance

A qualitative tool that maps likelihood and impact into buckets. Risk matrices are easy to produce but can be misleading for prioritization because they hide magnitude and uncertainty.

Risk taxonomy

Platform

A structured library of risk categories and risk types used to keep risk identification and quantification consistent across teams.

Runtime Inspection

PlatformAI Governance

Automated or manual checks that evaluate system behavior, such as fairness, privacy, robustness, or safety checks. Runtime Inspection produces governance signals over time.

S

Saudi AI Risk Management

Saudi AI Risk Management

SDAIA's National Artificial Intelligence Risk Management Framework (SDAIA-P145, April 2026), an advisory national methodology for government and private-sector entities in Saudi Arabia. It rests on four reference pillars (general principles and AI ethics, AI regulations, data regulations, and sector regulations) and a five-stage risk cycle — context and scope, identification, assessment, treatment, and monitoring and review — with per-risk scoring on a 4x4 likelihood-impact matrix.

Also called
SDAIA National AI Risk Management FrameworkSDAIA-P145

Scenario analysis

PlatformAI Governance

A method that decomposes risk into explicit scenarios and assumptions so teams can estimate frequency and monetary impact in a transparent way.

Scoring rate

NYC Local Law 144

Under the NYC Local Law 144 rules, the rate at which individuals in a category receive a score above the sample's median score, where the score has been calculated by an automated employment decision tool. Used with the full-sample median score and the impact ratio wherever the tool scores people; if the tool also selects or classifies people, the separate selection-rate calculation set applies as well.

Scout

Platform

Modulos’ AI assistant that can reference and reason across governance data in the platform and across connected sources and connectors.

Links

Selection rate

NYC Local Law 144

Under the NYC Local Law 144 rules, the rate at which individuals in a category are either selected to move forward in the hiring process or assigned a classification by an automated employment decision tool: the number in the category moving forward or assigned a classification divided by the total number in the category who applied for a position or were considered for promotion.

Service provider or contractor (CCPA)

CCPA ADMT Regulations

A service provider (Civ. Code section 1798.140(ag)) is a person that processes personal information on behalf of a business and receives it from or on behalf of the business for a business purpose under a written contract with the prescribed terms; a contractor (section 1798.140(j)) is a person to whom the business makes personal information available for a business purpose under such a contract. Both contracts must carry the section 7051(a) terms of the regulations. Personal information collected under the contract may be retained, used, or disclosed only for the purposes section 7050(a) permits and only where reasonably necessary and proportionate. Under the CCPA ADMT Regulations a service provider or contractor must cooperate in the business's risk assessment by making available all necessary facts in its possession, custody, or control (section 7050(h)(2)), must assist the business in responding to a verifiable consumer request to access ADMT (section 7222(i)), and must comply with the business's instruction to stop processing a consumer's personal information with an ADMT within the same time frame as the business after a post-initiation opt-out (section 7221(n)(2)). A person without a section 7051(a)-compliant contract is not a service provider or contractor. One that independently meets the business definition carries the business duties for ADMT it uses for its own significant decisions.

Also called
Service provider (CCPA)Contractor (CCPA)
In Modulos
The CCPA Role tag value Service provider or contractor marks MRF-496, carried by control MCF-702; the business's contract terms are ORF-491 (OCF-388).

Significant decision

CCPA ADMT Regulations

Under the CCPA ADMT Regulations (Cal. Code Regs. tit. 11, section 7001(ddd)), a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. The list is closed and each category has its own subdefinition: financial or lending services means the extension of credit or a loan, transmitting or exchanging funds, deposit or checking accounts, check cashing, or installment payment plans; housing means any building, structure, or portion of one that is used or occupied as, or designed, arranged, or intended to be used or occupied as, a home, residence, or sleeping place by one or more consumers, permanent or temporary, but an ADMT that provides or denies housing based solely on its availability or vacancy or on the successful receipt of payment for housing from the consumer is not making a significant decision; education enrollment or opportunities means admission or acceptance into academic or vocational programs, educational credentials, and suspension and expulsion; employment or independent contracting opportunities or compensation means hiring; allocation or assignment of work for employees, or salary, hourly or per-assignment compensation, incentive compensation such as a bonus, or another benefit; promotion; and demotion, suspension, and termination; healthcare services means services related to the diagnosis, prevention, or treatment of human disease or impairment, or the assessment or care of an individual's health. Advertising to a consumer is not a significant decision, and insurance is not on the list. The regulations contain no general test for decisions with legal or similarly significant effects.

Source

Platform

A service account connection attached to a project. Sources are project-scoped and are used to bring system data such as code, logs, and metrics into Modulos.

In Modulos
Configured per project under Settings and Sources.
Links

Statement of Applicability

ISO 27001ISO 27701ISO 42001

A documented record of which reference controls an organization has selected to treat its risks and the justification for including or excluding each — including implementation status where the standard requires it (ISO 27001 and ISO 27701). ISO 42001 records selected controls and justifications as its SoA-equivalent record. Central to certification audits under all three standards.

Also called
SoA

Supplier data protection requirements

Microsoft Supplier DPRAI Governance

A structured set of requirements that suppliers must meet for handling, protecting, and processing customer or partner data.

T

Technical documentation

AI GovernanceEU AI Act

Documentation that describes how an AI system is built, how it behaves, and how it is controlled, so that others can assess compliance and risk.

Third party (CCPA)

CCPA ADMT Regulations

Under Civ. Code section 1798.140(ai), a person who is not the business with whom the consumer intentionally interacts and that collects personal information from the consumer as part of the consumer's current interaction with the business, not a service provider to the business, and not a contractor. Under Cal. Code Regs. tit. 11, section 7052, a third party that does not have a contract complying with section 7053(a) shall not collect, use, process, retain, sell, or share the personal information that the business made available to it, and with such a contract must comply with its terms, including treating the information consistently with the business's obligations. Under the CCPA ADMT Regulations the role covers a third party receiving personal information the business made available for processing with an ADMT; one that independently meets the business definition carries the business duties for its own uses.

In Modulos
The CCPA Role tag value Third party marks MRF-496, carried by control MCF-702.

Threat vector

PlatformAI Governance

A distinct pathway by which an AI system can cause harm. Threat vectors are used to decompose risk into quantifiable parts.

Transparency

AI GovernanceEU AI Act

Clear communication about an AI system’s purpose, limitations, and appropriate use, so that affected users and operators can make informed decisions.

Trust Center

AI Governance

A central location where an organization publishes security, privacy, and compliance information and artifacts for customers and partners.

U

UAE AI Ethics

UAE AI Ethics

A set of ethical principles and guidance that promotes responsible AI, including fairness, accountability, transparency, safety, and human-centered outcomes.

UAE Consumer AI

UAE Consumer AI

CBUAE guidance on consumer protection and the responsible adoption and use of AI and ML by licensed financial institutions in the UAE, covering governance, fairness, transparency, oversight, data handling, monitoring, and redress.

UAE PDPL

UAE PDPL

Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, the UAE's federal data protection law, in force since 2 January 2022. It covers lawful processing and consent, data subject rights, the data protection officer, breach reporting, data protection impact assessments, and cross-border transfers, with its Executive Regulation not yet issued. The DIFC and ADGM financial free zones are excluded and run their own data protection regimes.

Also called
PDPLFederal Decree-Law No. 45 of 2021

INFO

This glossary is informational. It does not constitute legal advice.