AI Governance

The policies, roles, processes and controls an organization uses to ensure AI is developed and used responsibly, safely and in line with regulation.

API Gateway

A managed entry point that routes, secures, throttles and monitors requests to an organization’s APIs.

Business Continuity Plan

A documented plan describing how an organization keeps critical services running during and after a disruption.

Cloud Landing Zone

A pre-configured cloud environment with identity, networking, security and governance controls, ready for workloads to be deployed.

Data Catalog

An inventory of an organization’s data assets, with descriptions, owners and metadata that help people find and understand data.

Data Contract

An agreement between data producers and consumers that defines the structure, quality and service levels of a data set.

Data Governance

The framework of roles, policies, standards and processes that ensures data is managed as a trusted, valuable asset.

Data Lakehouse

A data architecture combining the low-cost, flexible storage of a data lake with the management and performance features of a data warehouse.

Data Lineage

A record of where data comes from, how it moves and how it is transformed across systems.

Data Mesh

An approach to data architecture in which business domains own and publish their data as products, supported by a shared self-service platform.

Data Monetization

Creating measurable economic value from data, through better decisions, improved products, cost savings or new data-based services.

Data Quality

The degree to which data is accurate, complete, consistent, timely and fit for its intended use.

Data Steward

A person responsible for the quality, definitions and correct use of a specific data domain.

Digital Twin

A digital model of a physical asset, process or system that is updated with real-world data to support analysis and decisions.

Enterprise Architecture

The discipline of describing and designing how an organization’s business processes, applications, data and technology fit together.

Event-Driven Architecture

A design approach in which systems communicate by publishing and reacting to events, enabling loosely coupled, real-time integration.

Golden Record

A single, trusted version of a key business entity, such as a customer or product, created by matching and merging data from several sources.

Incident Response Plan

A documented plan that sets out how an organization detects, contains, investigates and recovers from security incidents.

Large Language Model

An AI model trained on large volumes of text to understand and generate language, used in assistants, search and content tools.

Master Data Management

The processes and technology used to create and maintain consistent, accurate master data, such as customers, products and suppliers.

Microservices

An architecture style in which an application is built as a set of small, independently deployable services.

Open Finance

The secure sharing of financial data and services between institutions and third parties through APIs, with customer consent.

Operating Model

A description of how an organization delivers value: its processes, structure, people, technology, data and governance.

Penetration Testing

An authorized, simulated attack on systems or applications to find security weaknesses before attackers do.

Platform Engineering

Building and running internal platforms that give development teams self-service access to the tools and infrastructure they need.

Privacy by Design

Building privacy protections into systems and processes from the start, rather than adding them afterward.

RegTech

Technology that helps organizations meet regulatory requirements more efficiently, for example in reporting, monitoring and identity checks.

Retrieval-Augmented Generation

An AI technique in which a language model retrieves relevant documents from a trusted source and uses them to ground its answers.

Risk Register

A structured record of identified risks, their likelihood and impact, owners and treatment plans.

Security Operations Center

A team, often supported by a service provider, that monitors, detects and responds to security threats around the clock.

SIEM

Security information and event management: technology that collects and analyzes security logs to detect threats and support investigations.

Software Bill of Materials

A list of the components and dependencies in a piece of software, used to manage vulnerabilities and licenses.

Target Architecture

A description of the future state of an organization’s business, data, application and technology architecture.

Technical Debt

The future cost created by shortcuts or outdated technology choices that make systems harder to change.

Third-Party Risk

The risk an organization faces from suppliers, service providers and partners, including security, resilience and compliance risks.

Tokenization

Replacing sensitive data, such as card numbers, with non-sensitive tokens that have no exploitable value.

Vendor Lock-in

Dependence on a single supplier’s technology that makes switching costly or difficult.

Zero Trust

A security model that never assumes trust based on network location and verifies every user, device and request.