Skip to main content
Version: 1.0.0-beta

Glossary

Audit Terms

TermDefinition
Audit UniverseThe complete inventory of auditable entities across the organization (processes, departments, systems, locations)
EngagementA single audit assignment progressing through planning, fieldwork, reporting, and follow-up
WorkpaperDocumentation supporting audit procedures, findings, and conclusions
FindingA documented gap between the expected state (criteria) and the actual state (condition)
CCCERFinding documentation format: Condition, Criteria, Cause, Effect, Recommendation
PBCPrepared by Client — evidence requests sent to auditees for fulfilling
Action PlanDocumented remediation steps agreed by management to address audit findings
KRIKey Risk Indicator — a metric monitored against thresholds to detect emerging risks
CAEChief Audit Executive — the head of the internal audit function
IPPFInternational Professional Practices Framework — the IIA's authoritative guidance
IIAInstitute of Internal Auditors — the global professional association
SoDSegregation of Duties — prevents one person from performing conflicting roles (e.g., preparer and reviewer)
Gate CheckA quality control point requiring approval before an engagement can advance to the next phase
Board PackAn executive summary report compiled for board of directors consumption
Signoff ChainThe ordered sequence of reviewers who must approve a governed record

Technology Terms

TermDefinition
RBACRole-Based Access Control — permissions assigned to roles, roles assigned to users
RLSRow-Level Security — PostgreSQL feature enforcing data isolation at the database level
RAGRetrieval-Augmented Generation — AI technique grounding responses in actual data
LLMLarge Language Model — the AI model providing natural language capabilities
OIDCOpenID Connect — authentication protocol used with Keycloak
JWTJSON Web Token — the token format used for authentication and licensing
OCIOracle Cloud Infrastructure — the cloud platform hosting AIIA SaaS
pgvectorPostgreSQL extension for vector similarity search (used in RAG)
MinIOS3-compatible object storage for evidence files
KeycloakOpen-source identity and access management solution

Compliance Terms

TermDefinition
NCA ECCNational Cybersecurity Authority Essential Cybersecurity Controls (Saudi Arabia)
PDPLPersonal Data Protection Law (Saudi Arabia's data privacy regulation)
CSCCCloud Security Cybersecurity Controls
Vision 2030Saudi Arabia's strategic framework for economic and social transformation

AIIA Platform Terms

TermDefinition
AI CompanionContextual AI chat assistant available within engagements
AI Diff ReviewSide-by-side comparison of current vs. AI-suggested content
Data AgentAI capability that generates SQL queries from natural language questions
KRI PlaygroundVisual drag-and-drop builder for creating and testing KRI definitions
AI WizardGuided, step-by-step AI-assisted creation workflow
Commercial ModuleThe billing, licensing, and tenant management subsystem
Subscription TierThe level of service: Essentials, Professional, Enterprise, or Sovereign
Shared SaaSMulti-tenant deployment on shared OCI infrastructure
Private TenantDedicated infrastructure (namespace or cluster) on OCI
License KeyRS256-signed JWT encoding the organization's tier, modules, and expiry