Sprinklenet
Reference

AI Governance Glossary

Definitions of the terms used in AI governance programs, written for agency and enterprise teams that are setting up oversight of their AI systems.

Terms

Terms and Definitions

Where a longer treatment exists, the definition links to it.

AI Control Layer
An AI control layer is software that sits between an organization's people, applications, and data and the AI models they call. It routes each request, retrieves only permitted sources, applies access rules and guardrails, and writes an audit record of the call.
Knowledge Spaces
AI Governance
AI governance is the way an organization decides which AI systems it will use, who may use them, and how each one is checked while it is in service. It assigns decision rights, sets policy, and produces records that auditors, oversight bodies, and boards can inspect.
AI Governance Is Not Optional: A Practical Framework
AI Governance Platform
An AI governance platform is software that supports an AI governance program. Products in this category fall into two groups: tools that hold policies, inventories, and risk assessments, and control layers that enforce access rules, guardrails, and audit logging on each request as it runs.
Knowledge Spaces White Paper
AI Inventory
An AI inventory is a maintained record of every AI system an organization uses or is developing, with its owner, purpose, data, and status. It is the reference for risk assessment, monitoring, and periodic recertification of each system.
Federal AI Governance: A Practical Agency Roadmap
AI Policy
An AI policy is a written rule for how an organization and its staff may use AI. A policy set typically covers staff use of generative AI, data handling, transparency notices, human review, third-party AI services, and AI output used in decisions or as evidence.
AI Governance and Policy Services
AI Risk Register
An AI risk register lists the risks attached to an organization's AI systems, each with a rating, a control, an owner, and a review date. Review depth follows a risk tier set by the system's potential impact, so higher-impact systems receive fuller assessment.
AI Governance Roadmap for Mid-Market Enterprises
AI Sandbox
An AI sandbox is a controlled environment for testing AI tools before production use. It needs an approved data policy, named users, budget limits, restricted tools, and a clear exit path, and testing starts with public or approved test material.
How to Build a Governed AI Sandbox
AI Use Case Intake
AI use case intake is the standard form and approval path that every proposed use of AI passes through before work begins. The form records the use case, data sources, owner, and intended users, and each approved use is entered in the AI inventory.
Audit Log
An audit log is a time-ordered record of actions taken in a system. For an AI system, each entry records the actor, the action, the resource, the status, and the time, so a reviewer can establish who did what and when.
Building Audit Trails for Agentic AI Workflows
Evaluation Run
An evaluation run tests an AI system against a set of questions with recorded correct answers and scores the results. Runs are repeated when a prompt, a model, or a source changes, so a team can compare results before and after the change.
Guardrail
A guardrail is a configurable rule applied to what goes into or comes out of an AI system. Guardrails limit an assistant to allowed topics, block disallowed outputs, add required disclaimers, and escalate a request to a person when a rule is triggered.
The Security Review Checklist for Enterprise AI Tools
Human Review
Human review is an approval step in which a person examines an AI system's proposed output or action before it takes effect. A review design defines who may request the action, what the reviewer sees, and what the system does after approval or rejection.
How to Design Human Review for Agentic Automation
Model Routing
Model routing sends each request to the AI model suited to it, based on task complexity, cost, and latency. Routing across providers lets an organization change or add models without rebuilding the applications that depend on them.
The Executive Guide to Multi-Model AI Operations
NIST AI Risk Management Framework
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework from the National Institute of Standards and Technology for managing the risks of AI systems. It is organized around four functions: Govern, Map, Measure, and Manage. The NIST Generative AI Profile (NIST AI 600-1) applies it to generative AI.
NIST AI Risk Management Framework at nist.gov
Performance and Drift Monitoring
Performance and drift monitoring is the scheduled measurement of an AI system in production against set thresholds for accuracy, fairness, and drift in inputs and outputs. When a threshold is crossed, the check opens a ticket with a named owner.
Prompt Injection
Prompt injection is an attack in which text placed in a user message or a retrieved document instructs an AI system to disregard its rules. Defenses include source trust rules, isolation, allowlists, testing, output filtering, and audit logs.
How Prompt Injection Enters Enterprise Retrieval Systems
Responsible AI Framework
A responsible AI framework is the set of policies, roles, and controls an organization uses to decide which AI systems it will run and to keep them safe, fair, and effective while they are in use. A complete framework covers ethics and integrity standards, use case intake, an inventory of AI systems, risk assessment, performance and drift monitoring, staff training, and a governance body with defined decision rights.
Retrieval Grounding
Retrieval grounding is the practice of answering from documents retrieved at the time of the question, in addition to what the model learned in training. A grounded answer cites the passages it used, so a reader can inspect the source that supports each claim.
Building AI Systems That Can Cite Their Sources
Role-Based Access Control
Role-based access control (RBAC) grants permissions according to a user's assigned role. In an AI system it determines which assistants, knowledge sources, and administrative functions a person can reach, so an assistant answers only from material that person is permitted to see.
Data Governance for AI Programs With Sensitive Information
Get Started

Start with a Governance Review

For organizations that need to know where they stand, we review existing AI policies, the system inventory, and oversight practices against the NIST AI Risk Management Framework and applicable guidance, then deliver a gap assessment and a sequenced plan.