AI Governance
The policies, roles, processes and controls an organization uses to ensure AI is developed and used responsibly, safely and in line with regulation.
API Gateway
A managed entry point that routes, secures, throttles and monitors requests to an organization’s APIs.
Business Continuity Plan
A documented plan describing how an organization keeps critical services running during and after a disruption.
Cloud Landing Zone
A pre-configured cloud environment with identity, networking, security and governance controls, ready for workloads to be deployed.
Data Catalog
An inventory of an organization’s data assets, with descriptions, owners and metadata that help people find and understand data.
Data Contract
An agreement between data producers and consumers that defines the structure, quality and service levels of a data set.
Data Governance
The framework of roles, policies, standards and processes that ensures data is managed as a trusted, valuable asset.
Data Lakehouse
A data architecture combining the low-cost, flexible storage of a data lake with the management and performance features of a data warehouse.
Data Lineage
A record of where data comes from, how it moves and how it is transformed across systems.
Data Mesh
An approach to data architecture in which business domains own and publish their data as products, supported by a shared self-service platform.
Data Monetization
Creating measurable economic value from data, through better decisions, improved products, cost savings or new data-based services.
Data Quality
The degree to which data is accurate, complete, consistent, timely and fit for its intended use.
Data Steward
A person responsible for the quality, definitions and correct use of a specific data domain.
Digital Twin
A digital model of a physical asset, process or system that is updated with real-world data to support analysis and decisions.
Enterprise Architecture
The discipline of describing and designing how an organization’s business processes, applications, data and technology fit together.
Event-Driven Architecture
A design approach in which systems communicate by publishing and reacting to events, enabling loosely coupled, real-time integration.
Golden Record
A single, trusted version of a key business entity, such as a customer or product, created by matching and merging data from several sources.
Identity & Access Management
The processes and technology that control who can access which systems and data, and under what conditions.
Incident Response Plan
A documented plan that sets out how an organization detects, contains, investigates and recovers from security incidents.
Large Language Model
An AI model trained on large volumes of text to understand and generate language, used in assistants, search and content tools.
Master Data Management
The processes and technology used to create and maintain consistent, accurate master data, such as customers, products and suppliers.
Microservices
An architecture style in which an application is built as a set of small, independently deployable services.
Open Finance
The secure sharing of financial data and services between institutions and third parties through APIs, with customer consent.
Operating Model
A description of how an organization delivers value: its processes, structure, people, technology, data and governance.
Penetration Testing
An authorized, simulated attack on systems or applications to find security weaknesses before attackers do.
Platform Engineering
Building and running internal platforms that give development teams self-service access to the tools and infrastructure they need.
Privacy by Design
Building privacy protections into systems and processes from the start, rather than adding them afterward.
Recovery Time Objective
The maximum acceptable time to restore a system or service after a disruption.
RegTech
Technology that helps organizations meet regulatory requirements more efficiently, for example in reporting, monitoring and identity checks.
Retrieval-Augmented Generation
An AI technique in which a language model retrieves relevant documents from a trusted source and uses them to ground its answers.
Risk Register
A structured record of identified risks, their likelihood and impact, owners and treatment plans.
Security Operations Center
A team, often supported by a service provider, that monitors, detects and responds to security threats around the clock.
SIEM
Security information and event management: technology that collects and analyzes security logs to detect threats and support investigations.
Software Bill of Materials
A list of the components and dependencies in a piece of software, used to manage vulnerabilities and licenses.
Target Architecture
A description of the future state of an organization’s business, data, application and technology architecture.
Technical Debt
The future cost created by shortcuts or outdated technology choices that make systems harder to change.
Third-Party Risk
The risk an organization faces from suppliers, service providers and partners, including security, resilience and compliance risks.
Tokenization
Replacing sensitive data, such as card numbers, with non-sensitive tokens that have no exploitable value.
Vendor Lock-in
Dependence on a single supplier’s technology that makes switching costly or difficult.
Zero Trust
A security model that never assumes trust based on network location and verifies every user, device and request.