Glossary
The compliance glossary
58 terms from EU and Swedish regulation — CSRD, NIS2, DORA, GDPR, the AI Act, EUDR and more — defined in plain language, in English and Swedish.
Last reviewed
A
- Accessibility statement Supply chain & product
- Accreditation Governance & assurance
- AI literacy Data protection & AI
- Audit trail Governance & assurance
B
- Beneficial owner Governance & assurance
- Business continuity management Cybersecurity & resilience
C
- CBAM certificate Supply chain & product
- CE marking Supply chain & product
- Certification audit Governance & assurance
- Chain of custody (CoC) Supply chain & product
- Climate transition plan Sustainability reporting
- Conformity assessment Supply chain & product
- Controller (data controller) Data protection & AI
- Customer due diligence (KYC) Governance & assurance
- Cybersäkerhetslagen (Swedish Cybersecurity Act) Cybersecurity & resilience
D
- Data portability Data protection & AI
- Data processing agreement (DPA) Data protection & AI
- Deforestation-free Supply chain & product
- Double materiality Sustainability reporting
- DPIA (data protection impact assessment) Data protection & AI
- Due diligence statement (EUDR) Supply chain & product
E
- Early warning (24-hour incident notification) Cybersecurity & resilience
- Embedded emissions (CBAM) Supply chain & product
- ESRS (European Sustainability Reporting Standards) Sustainability reporting
- Essential and important entities Cybersecurity & resilience
- EU Taxonomy alignment Sustainability reporting
G
- Gap analysis Governance & assurance
- Gender pay gap reporting Governance & assurance
- General-purpose AI model (GPAI) Data protection & AI
- Geolocation (EUDR) Supply chain & product
- Greenwashing Sustainability reporting
H
- High-risk AI system Data protection & AI
- Human rights due diligence Sustainability reporting
I
- ICT third-party risk Cybersecurity & resilience
- Incident response plan Cybersecurity & resilience
- Internal control Governance & assurance
- ISMS (information security management system) Cybersecurity & resilience
L
- Legitimate interest Data protection & AI
- Limited assurance Sustainability reporting
M
- Management system Governance & assurance
N
- Nonconformity Governance & assurance
P
- Penetration testing Cybersecurity & resilience
- Personal data Data protection & AI
- Personal data breach Data protection & AI
- Principal adverse impact (PAI) indicators Sustainability reporting
- Processor (data processor) Data protection & AI
R
- Register of information (DORA) Cybersecurity & resilience
- Risk assessment Governance & assurance
S
- Sanctions screening Governance & assurance
- Scope 3 emissions Sustainability reporting
- Standard contractual clauses (SCCs) Data protection & AI
- Statement of Applicability (SoA) Cybersecurity & resilience
- Strong customer authentication (SCA) Governance & assurance
- Sustainability statement Sustainability reporting
T
- TLPT (threat-led penetration testing) Cybersecurity & resilience
- Transfer impact assessment (TIA) Data protection & AI
V
- Value chain Sustainability reporting
W
- Whistleblowing channel Governance & assurance