Compliance Glossary

Compliance Glossary

17a-4:  Definition: A regulation by the U.S. Securities and Exchange Commission (SEC) that specifies record-keeping requirements for broker-dealers.

ABAC:  Acronym: Anti-Bribery and Anti-Corruption. Definition: A comprehensive approach that includes policies and procedures to prevent bribery and corruption within an organization.

ADEA:  Acronym: Age Discrimination in Employment Act. Definition: U.S. law prohibiting age discrimination against employees who are 40 years or older.

AFA:  Acronym: Anti-Fraud Awareness. Definition: Programs and initiatives aimed at educating employees about recognizing and preventing fraud.

AML/CFT:  Acronym: Anti-Money Laundering/Countering the Financing of Terrorism. Definition: Measures and regulations designed to prevent money laundering and terrorist financing.

Anti-Bribery and Corruption (ABC):  Definition: A set of laws, regulations, and practices aimed at preventing bribery and corruption in business transactions.

Anti-Kickback Statute:  Definition: A U.S. law that prohibits offering, paying, soliciting, or receiving kickbacks for referrals in federal healthcare programs.

Anti-Money Laundering (AML):  Definition: Measures and regulations designed to prevent money laundering and terrorist financing.

Anti-Trust Laws:  Definition: Laws aimed at promoting fair competition and preventing monopolistic behavior and anticompetitive practices.

Asset Forfeiture:  Definition: The confiscation of assets acquired through illegal activities as a penalty for wrongdoing.

Audit Committee:  Definition: A committee of a company’s board of directors responsible for oversight of financial reporting and internal controls.

Audit Trail:  Definition: A chronological record of system activities and transactions used to monitor and review actions for compliance and security purposes.

Bank Secrecy Act (BSA):  Definition: U.S. legislation requiring financial institutions to assist in detecting and preventing money laundering.

Basel III:  Definition: A global regulatory framework for banking institutions that establishes minimum capital and liquidity requirements.

Beneficial Ownership:  Definition: Identifying and reporting the individuals who ultimately own or control a legal entity.

Best Practices:  Definition: Industry-accepted standards and practices that represent the most effective way of achieving compliance and ethical conduct.

Blockchain Technology:  Definition: A distributed ledger technology that can be used for secure and transparent record-keeping, including compliance records.

Board of Directors:  Definition: A group of individuals elected by shareholders to oversee the management and strategic direction of a corporation.

Board Oversight:  Definition: The responsibility of a company’s board of directors in overseeing compliance efforts and ensuring ethical behavior.

Bribery Act 2010:  Definition: UK legislation that criminalizes bribery and imposes strict anti-bribery measures on businesses.

Business Continuity Plan (BCP):  Definition: A plan that outlines procedures and resources to maintain critical business operations during disruptions, including compliance with regulations.

Business Ethics:  Definition: Principles and values that guide ethical decision-making and behavior in the business environment.

CAMELS Rating:  Definition: A rating system used by bank regulators to assess the safety and soundness of financial institutions.

Certification of Compliance:  Definition: A formal declaration that an organization is in compliance with specific laws, regulations, or industry standards.

CFT:  Acronym: Countering the Financing of Terrorism. Definition: Efforts to prevent the funding of terrorist activities through financial transactions.

CFTC:  Acronym: Commodity Futures Trading Commission. Definition: A U.S. regulatory agency overseeing commodity and futures markets.

Chief Compliance Officer (CCO):  Definition: The senior executive responsible for overseeing an organization’s compliance program.

Code of Conduct:  Definition: A set of guidelines and principles that outline acceptable behavior and ethical standards for employees within an organization.

Code of Ethics:  Definition: A document that outlines an organization’s core values, principles, and ethical standards.

COI:  Acronym: Conflict of Interest. Definition: A situation where an individual’s personal interests may interfere with their ability to make impartial decisions in their professional role.

Compliance Framework:  Definition: A structured approach and set of processes used to ensure an organization’s compliance with laws and regulations.

Compliance Officer:  Definition: An individual responsible for ensuring that an organization adheres to relevant laws, regulations, and internal policies.

Conflict Minerals:  Definition: Minerals (e.g., gold, tin, tungsten, and tantalum) sourced from conflict zones, subject to disclosure and due diligence requirements.

Conflict of Interest Policy:  Definition: A formal policy that outlines procedures for identifying and addressing conflicts of interest within an organization.

Conflict of Interest:  Definition: A situation in which an individual’s personal interests or relationships may interfere with their ability to make impartial decisions in their professional role.

Consumer Financial Protection Bureau (CFPB):  Definition: A U.S. government agency responsible for consumer protection in the financial sector.

Corporate Culture:  Definition: The shared values, norms, and behaviors that shape an organization’s character and influence compliance practices.

Corporate Governance:  Definition: The system of rules, practices, and processes by which a company is directed and controlled to enhance accountability and transparency.

Corporate Social Responsibility (CSR):  Definition: An organization’s commitment to ethical and socially responsible business practices.

Crisis Communication Plan:  Definition: A strategy and set of procedures for communicating with stakeholders during a crisis or compliance incident.

Crisis Management:  Definition: The process of planning for, responding to, and recovering from critical events that may impact an organization’s compliance and reputation.

Customer Due Diligence (CDD):  Definition: The process of verifying and understanding the identity of customers, often required for anti-money laundering compliance.

Dark Web:  Definition: A hidden part of the internet used for illegal activities, including the sale of stolen data and hacking tools, posing compliance risks.

Data Breach Response:  Definition: The coordinated actions taken by an organization to address and mitigate the impact of a data breach.

Data Breach:  Definition: The unauthorized access, disclosure, or acquisition of sensitive data, often resulting in a security incident.

Data Classification:  Definition: Categorizing data based on its sensitivity and importance to determine appropriate security and handling measures.

Data Encryption:  Definition: The process of converting data into a code to prevent unauthorized access, essential for data security compliance.

Data Governance:  Definition: The framework and practices for managing data assets, ensuring data quality, and compliance with data regulations.

Data Privacy:  Definition: The protection of sensitive information and personal data in accordance with data protection laws and regulations.

Data Protection Officer (DPO):  Definition: An individual appointed to oversee data protection and compliance with data privacy regulations.

Debarment:  Definition: The exclusion of individuals or entities from participating in government contracts due to compliance violations.

Deferred Prosecution Agreement (DPA):  Definition: An agreement between a prosecutor and an organization to suspend criminal charges in exchange for certain actions, such as compliance improvements.

Digital Rights Management (DRM):  Definition: Technologies and strategies to protect digital content from unauthorized copying and distribution.

Directors and Officers (D&O) Insurance:  Definition: Insurance coverage that protects directors and officers from personal liability related to their management decisions.

Disaster Recovery Plan (DRP):  Definition: A plan that outlines procedures and resources for recovering IT systems and data in the event of a disaster.

Diversity and Inclusion:  Definition: Efforts to promote a diverse workforce and inclusive workplace, often associated with compliance with equal employment opportunity laws.

Document Management System:  Definition: Software and tools for organizing, storing, and managing documents and records, important for compliance records.

Document Retention Policy:  Definition: Guidelines for the retention and disposal of organizational documents, taking into account legal and regulatory requirements.

Dodd-Frank Wall Street Reform and Consumer Protection Act:  Definition: U.S. legislation aimed at reforming financial regulations to prevent another financial crisis.

Due Diligence:  Definition: A comprehensive review and investigation process to assess the risks associated with a business transaction or relationship.

E-Discovery:  Definition: The process of electronically identifying, collecting, and preserving information for legal proceedings, including compliance with e-discovery rules.

EEOC:  Acronym: Equal Employment Opportunity Commission. Definition: A U.S. agency responsible for enforcing laws against workplace discrimination.

Electronic Health Records (EHR):  Definition: Digital patient health records that must be managed in compliance with healthcare data privacy regulations.

Employee Handbook:  Definition: A document that outlines an organization’s policies, procedures, and expectations for employees.

Employee Monitoring:  Definition: The practice of tracking employee activities to ensure compliance with company policies and legal requirements.

Employee Training and Development:  Definition: Programs designed to educate and develop employees’ skills and knowledge, including compliance training.

Environmental Compliance:  Definition: Adherence to environmental laws and regulations to minimize an organization’s impact on the environment.

Environmental Impact Assessment (EIA):  Definition: A study that assesses the environmental consequences of a project, often required for compliance with environmental regulations.

Environmental Management System (EMS):  Definition: A framework for managing an organization’s environmental responsibilities and compliance with environmental laws.

Equal Employment Opportunity (EEO):  Definition: The principle of providing equal employment opportunities without discrimination, subject to compliance laws.

ESG:  Acronym: Environmental, Social, and Governance. Definition: A framework that evaluates a company’s performance in terms of sustainability, social responsibility, and corporate governance.

Ethics Hotline:  Definition: A confidential reporting mechanism for employees to report ethical concerns or compliance violations within an organization.

Ethics Training:  Definition: Educational programs and initiatives that promote ethical behavior and decision-making within an organization.

Export Control:  Definition: Compliance with laws and regulations governing the export of goods, services, and technology.

Fair Credit Reporting Act (FCRA):  Definition: U.S. law regulating the collection and use of consumer credit information.

Fair Labor Standards Act (FLSA):  Definition: U.S. labor law establishing standards for minimum wage, overtime pay, and child labor.

Fair Lending:  Definition: Compliance with laws that prohibit discriminatory lending practices based on factors such as race, gender, or age.

Fair Packaging and Labeling Act (FPLA):  Definition: U.S. law requiring honest and informative labeling of consumer products.

Fair Trade:  Definition: A movement that promotes ethical trading practices and fair compensation for producers in developing countries.

False Claims Act (FCA):  Definition: U.S. federal law imposing liability for submitting false claims to the government, often related to healthcare fraud.

FATCA:  Acronym: Foreign Account Tax Compliance Act. Definition: U.S. legislation aimed at preventing tax evasion by U.S. persons with foreign accounts.

FCPA:  Acronym: Foreign Corrupt Practices Act. Definition: A U.S. law that prohibits bribery and corrupt practices by U.S. companies and individuals abroad.

FDA Compliance:  Definition: Adherence to regulations set by the U.S. Food and Drug Administration, particularly in the pharmaceutical and food industries.

Financial Crimes Enforcement Network (FinCEN):  Definition: A bureau of the U.S. Department of the Treasury focused on combating financial crimes, including money laundering and terrorist financing.

Financial Industry Regulatory Authority (FINRA):  Definition: A self-regulatory organization that oversees securities firms and brokers in the United States.

Financial Statement Audit:  Definition: An independent examination of an organization’s financial statements for accuracy and compliance with accounting standards.

FINRA:  Acronym: Financial Industry Regulatory Authority. Definition: A self-regulatory organization that oversees securities firms and brokers in the United States.

Foreign Account Tax Compliance Act (FATCA):  Definition: U.S. legislation aimed at preventing tax evasion by U.S. persons with foreign accounts.

Foreign Corrupt Practices Act (FCPA):  Definition: U.S. law prohibiting bribery and corrupt practices by U.S. companies and individuals abroad.

Foreign Exchange Compliance:  Definition: Compliance with laws and regulations governing foreign exchange transactions and currency trading.

Form 10-K:  Definition: An annual report filed with the SEC by publicly traded companies, containing financial information and business operations details.

Form 10-Q:  Definition: A quarterly report filed with the SEC by publicly traded companies, providing financial updates and disclosures.

Form 8-K:  Definition: A report filed with the SEC to announce significant events, such as mergers, acquisitions, and changes in corporate governance.

Fraud Prevention:  Definition: Strategies and measures to detect, deter, and prevent fraudulent activities within an organization.

Fraud Triangle:  Definition: A model that describes the factors contributing to fraud: opportunity, motivation, and rationalization.

Free and Prior Informed Consent (FPIC):  Definition: A principle in corporate social responsibility that requires obtaining consent from indigenous communities before undertaking projects on their land.

Fringe Benefits:  Definition: Non-wage compensation provided to employees, often subject to tax and regulatory compliance.

Full Disclosure Principle:  Definition: An accounting principle that requires organizations to provide complete and accurate information in financial reporting.

Garnishment:  Definition: A legal process for collecting debt by deducting money from an employee’s wages, subject to compliance regulations.

GDPR:  Acronym: General Data Protection Regulation. Definition: European Union regulation governing data protection and privacy rights for individuals.

General Data Protection Regulation (GDPR):  Definition: European Union regulation governing data protection and privacy rights for individuals.

Gift Policy:  Definition: A policy that sets guidelines for giving and receiving gifts, often to prevent conflicts of interest and bribery.

Gifts and Hospitality Policy:  Definition: A policy that sets guidelines for giving and receiving gifts, entertainment, and hospitality to prevent potential conflicts of interest.

Gifts and Hospitality:  Definition: The giving or receiving of gifts, entertainment, or hospitality in a business context, often subject to compliance guidelines.

GLBA:  Acronym: Gramm-Leach-Bliley Act. Definition: A U.S. law that requires financial institutions to protect consumers’ personal financial information.

Global Compliance:  Definition: The practice of ensuring an organization’s adherence to laws, regulations, and standards across multiple countries.

Good Clinical Practice (GCP):  Definition: International standards for conducting clinical trials and research, crucial in the pharmaceutical and healthcare industries.

Good Manufacturing Practices (GMP):  Definition: A set of quality control guidelines and regulations for the pharmaceutical and manufacturing industries.

Governance, Risk Management, and Compliance (GRC):  Definition: A holistic approach to managing an organization’s governance, risk, and compliance functions.

Greenwashing:  Definition: Misleading marketing practices that falsely suggest a product or company is environmentally friendly or sustainable.

Health and Safety Compliance:  Definition: Adherence to laws and regulations aimed at ensuring the health and safety of employees and the public.

HIPAA:  Acronym: Health Insurance Portability and Accountability Act. Definition: U.S. law that governs the security and privacy of healthcare information.

Human Resources Compliance:  Definition: Compliance with laws and regulations governing employment, labor relations, and workforce management.

Incident Response Plan (IRP):  Definition: A structured approach and documented plan for responding to and mitigating data breaches and security incidents.

Incident Response Plan:  Definition: A structured approach and documented plan for responding to and mitigating data breaches and security incidents.

Independent Review:  Definition: An external assessment of an organization’s compliance practices and controls.

Information Governance:  Definition: The framework and processes for managing and protecting an organization’s information assets.

Information Security Officer (ISO):  Definition: An individual responsible for overseeing an organization’s information security program and compliance.

Information Security Policy:  Definition: A set of guidelines and procedures to protect an organization’s information assets from security threats and breaches.

Insider Threat:  Definition: The risk posed by individuals within an organization who misuse their access or knowledge for malicious purposes, affecting compliance.

Insider Trading:  Definition: Illegally buying or selling securities based on non-public, material information.

Intellectual Property Rights (IPR):  Definition: Legal protections for inventions, creative works, and proprietary information, requiring compliance with IP laws.

Interagency Working Group (IWG):  Definition: A collaborative effort between government agencies to address regulatory issues and promote compliance.

Internal Audit:  Definition: A systematic review and evaluation of an organization’s operations, processes, and controls to ensure compliance and identify areas for improvement.

Internal Controls:  Definition: Policies, procedures, and practices implemented to ensure compliance, prevent fraud, and safeguard assets within an organization.

International Traffic in Arms Regulations (ITAR):  Definition: U.S. regulations governing the export and import of defense-related articles, services, and technology.

ISO 14001:  Acronym: International Organization for Standardization (ISO) Standard 14001. Definition: A standard for environmental management systems that helps organizations minimize their environmental impact.

ISO 19600:  Acronym: International Organization for Standardization (ISO) Standard 19600. Definition: A standard that provides guidelines for establishing, implementing, maintaining, and improving a compliance management system.

ISO 22000:  Acronym: International Organization for Standardization (ISO) Standard 22000. Definition: A standard for food safety management systems, essential for compliance in the food industry.

ISO 27001:  Acronym: International Organization for Standardization (ISO) Standard 27001. Definition: A standard for information security management systems that helps organizations protect their data and information assets.

ISO 45001:  Acronym: International Organization for Standardization (ISO) Standard 45001. Definition: A standard for occupational health and safety management systems, critical for workplace safety compliance.

ISO 9001:  Acronym: International Organization for Standardization (ISO) Standard 9001. Definition: A standard for quality management systems that focuses on meeting customer requirements and improving processes.

Kickback:  Definition: A form of bribery where a party offers or receives something of value in exchange for favorable treatment.

Know Your Customer (KYC):  Definition: The process of verifying the identity of customers to prevent fraud and comply with anti-money laundering regulations.

KYC:  Acronym: Know Your Customer. Definition: The process of verifying the identity of customers to prevent fraud and comply with anti-money laundering regulations.

Labor Law Compliance:  Definition: Compliance with laws and regulations governing labor relations, wages, hours, and workplace conditions.

Labor Law Poster Compliance:  Definition: Compliance with laws requiring employers to display posters informing employees of their rights and protections.

Liability Insurance:  Definition: Insurance coverage that protects individuals or organizations from legal claims and financial losses.

Licensing and Permitting:  Definition: Compliance with regulations that require businesses to obtain licenses and permits to operate legally.

Lobbying:  Definition: Efforts by individuals or organizations to influence government decisions, often subject to specific regulations.

Market Abuse Directive (MAD):  Definition: European Union directive aimed at preventing market manipulation and insider trading.

Market Abuse Regulation (MAR):  Definition: European Union regulation aimed at preventing insider trading and market manipulation.

Materiality:  Definition: The significance or importance of information or events in the context of financial and compliance reporting.

Merger and Acquisition (M&A) Due Diligence:  Definition: The process of evaluating the legal, financial, and compliance aspects of a potential merger or acquisition.

Mergers and Acquisitions (M&A) Compliance:  Definition: Ensuring compliance with laws and regulations during the acquisition or merger of companies.

MiFID II:  Acronym: Markets in Financial Instruments Directive II. Definition: European Union regulation that enhances transparency and investor protection in financial markets.

Money Laundering:  Definition: The process of disguising the origins of illegally obtained money to make it appear legitimate.

Monitoring and Surveillance:  Definition: The practice of continuously observing and analyzing activities to detect compliance violations and security threats.

National Labor Relations Act (NLRA):  Definition: U.S. law protecting employees’ rights to organize and engage in collective bargaining.

Non-Compete Agreement:  Definition: A contract that restricts an employee from working for competitors after leaving the organization, subject to compliance laws.

Non-Disclosure Agreement (NDA):  Definition: A legal contract that binds parties to confidentiality, often used to protect sensitive information.

Occupational Safety and Health Administration (OSHA):  Definition: U.S. agency responsible for enforcing workplace safety and health regulations.

OFAC Sanctions List:  Definition: Lists of individuals, entities, and countries subject to economic and trade sanctions imposed by the U.S. Office of Foreign Assets Control (OFAC).

OFAC:  Acronym: Office of Foreign Assets Control. Definition: A U.S. government agency that administers and enforces economic and trade sanctions.

Office of Inspector General (OIG):  Definition: An independent office within a government agency responsible for investigating and preventing fraud, waste, and abuse.

Operational Risk:  Definition: The risk of financial loss or compliance failure resulting from internal processes, systems, or human errors.

Outsourcing Compliance:  Definition: Ensuring that outsourced services and functions comply with regulatory requirements and organizational standards.

Payroll Compliance:  Definition: Compliance with laws and regulations governing employee compensation, including wage and hour laws.

PCI DSS:  Acronym: Payment Card Industry Data Security Standard. Definition: A set of security standards for protecting payment card data.

Penetration Testing:  Definition: Simulated cyberattacks on an organization’s systems to assess vulnerabilities and security compliance.

Personal Protective Equipment (PPE):  Definition: Safety gear and equipment required in certain workplaces to protect employees, subject to compliance.

Phishing:  Definition: Deceptive attempts to trick individuals into revealing sensitive information, often for fraudulent purposes.

Policy Management:  Definition: The process of creating, maintaining, and enforcing organizational policies, including compliance policies.

Ponzi Scheme:  Definition: An investment fraud that promises high returns but pays earlier investors with the capital of new investors, often leading to compliance violations.

Privacy Impact Assessment (PIA):  Definition: An evaluation of the potential risks and impacts on individual privacy associated with a new project or system.

Product Liability:  Definition: Liability for injuries or damages caused by defective products, subject to product safety compliance.

Product Recall:  Definition: The process of withdrawing or recalling a product from the market due to safety or regulatory concerns.

Quality Assurance (QA):  Definition: Systems and processes that ensure products or services meet specified quality and compliance standards.

Ransomware:  Definition: Malicious software that encrypts an organization’s data and demands a ransom for its release, posing compliance and security risks.

Records Management:  Definition: The systematic control of an organization’s records, including storage, retrieval, and disposal, critical for compliance.

Red Flags Rule:  Definition: U.S. regulations requiring certain businesses to establish identity theft prevention programs.

Regulatory Affairs:  Definition: A function within organizations that focuses on ensuring compliance with regulatory requirements in their industry.

Regulatory Compliance:  Definition: Conforming to laws, regulations, and industry standards relevant to an organization’s operations.

Regulatory Reporting:  Definition: The process of preparing and submitting required reports to regulatory authorities to demonstrate compliance with relevant laws and regulations.

Regulatory Technology (RegTech):  Definition: Technology solutions and tools designed to help organizations streamline compliance processes and manage regulatory requirements.

Reputation Risk:  Definition: The risk of damage to an organization’s reputation due to compliance failures, unethical behavior, or other negative events.

Responsible Sourcing:  Definition: The practice of ensuring that products are sourced and produced in an ethical and sustainable manner.

Restitution:  Definition: The requirement to compensate victims or return ill-gotten gains as part of a legal settlement, often in compliance cases.

Risk Assessment:  Definition: The process of identifying, evaluating, and prioritizing potential risks to an organization’s compliance and operations.

Risk Management:  Definition: The process of identifying, assessing, and mitigating risks to an organization’s operations, finances, and reputation.

Risk-Based Approach:  Definition: A method of compliance management that prioritizes resources based on the level of risk posed by specific activities or areas.

Safeguarding:  Definition: Measures taken to protect individuals, assets, and information from harm or unauthorized access, essential for compliance.

Sanctions:  Definition: Penalties or restrictions imposed by governments or international bodies to enforce compliance with specific regulations, often related to international trade or national security.

Sarbanes-Oxley Act (SOX):  Definition: U.S. legislation that established accounting and reporting requirements for publicly traded companies to prevent corporate fraud.

SEC Whistleblower Program:  Definition: A program established by the U.S. SEC that provides financial incentives and protections to individuals who report securities law violations.

SEC:  Acronym: U.S. Securities and Exchange Commission. Definition: The regulatory agency responsible for overseeing securities markets and enforcing related regulations.

Securities Fraud:  Definition: Deceptive practices in the buying or selling of securities, subject to securities law compliance.

Security Clearance:  Definition: Authorization granted to individuals to access classified information, often subject to strict background checks and compliance.

Security Incident:  Definition: An event that compromises the confidentiality, integrity, or availability of an organization’s information or systems.

Security Policy:  Definition: A documented set of rules, procedures, and guidelines for ensuring information security and compliance.

Self-Regulatory Organization (SRO):  Definition: An organization that regulates its own industry members and members’ compliance with industry standards.

Sexual Harassment Policy:  Definition: A policy outlining measures to prevent and address sexual harassment in the workplace, subject to compliance requirements.

Single Point of Contact (SPOC):  Definition: A designated individual or team responsible for managing compliance-related communications and inquiries.

Social Engineering:  Definition: Manipulating individuals to disclose confidential information or perform actions that compromise security and compliance.

Social Media Compliance:  Definition: Compliance with regulations and guidelines when using social media for business purposes.

Social Responsibility:  Definition: An organization’s commitment to ethical, sustainable, and socially beneficial practices.

SOX 404 Compliance:  Definition: Compliance with Section 404 of the Sarbanes-Oxley Act, which requires the assessment and reporting of internal controls over financial reporting.

Stakeholder Engagement:  Definition: Involving stakeholders in decision-making and dialogue, including discussions on ethical and compliance matters.

Stress Testing:  Definition: Assessing an organization’s financial resilience under adverse economic conditions, often required for regulatory compliance.

Supervisory Control and Data Acquisition (SCADA):  Definition: A system for monitoring and controlling industrial processes, often critical for infrastructure compliance.

Supply Chain Management:  Definition: The oversight and control of the processes, materials, and information involved in the production and distribution of goods, subject to compliance.

System and Organization Controls (SOC):  Definition: Reports on controls at a service organization that may be relevant to user entities’ internal control over financial reporting.

Tax Compliance:  Definition: Adherence to tax laws and regulations, including accurate reporting and payment of taxes.

Third-Party Audit:  Definition: An independent examination of a third-party organization’s compliance with agreed-upon standards or requirements.

Third-Party Due Diligence:  Definition: The process of assessing and monitoring the compliance and integrity of third-party vendors, suppliers, or partners.

Third-Party Risk Assessment:  Definition: Evaluating and managing risks associated with third-party suppliers, vendors, and partners.

Trade Compliance:  Definition: Adherence to laws and regulations governing international trade, including import and export controls, sanctions, and customs regulations.

Trade Secret:  Definition: Confidential business information that provides a competitive advantage, subject to compliance with trade secret laws.

Travel and Expense (T&E) Compliance:  Definition: Ensuring compliance with policies and regulations when employees incur travel and business expenses.

UCC Filing:  Definition: The process of submitting a Uniform Commercial Code filing to establish security interests in personal property, subject to compliance with UCC regulations.

Unclaimed Property:  Definition: Property, such as abandoned bank accounts and unclaimed dividends, that must be reported and remitted to state authorities as required by unclaimed property laws.

United Nations Global Compact:  Definition: A voluntary initiative encouraging businesses to adopt sustainable and socially responsible policies.

Vendor Code of Conduct:  Definition: A set of ethical and compliance guidelines that vendors and suppliers must adhere to when conducting business with an organization.

Vendor Risk Management (VRM):  Definition: The process of assessing and mitigating risks associated with third-party vendors and suppliers.

Voluntary Disclosure:  Definition: The act of voluntarily reporting compliance violations or irregularities to relevant authorities or regulators.

Voluntary Self-Disclosure:  Definition: The act of an organization voluntarily reporting compliance violations to relevant authorities before they are discovered independently.

Water Compliance:  Definition: Compliance with laws and regulations governing water quality, usage, and disposal.

Whistleblower Protection:  Definition: Legal safeguards and mechanisms to protect employees who report wrongdoing within their organization from retaliation.

Whistleblower:  Definition: An individual who reports illegal or unethical activities within an organization to authorities or management.

Workplace Safety:  Definition: Compliance with laws and regulations that protect employees from hazards and ensure a safe working environment.

Zero Tolerance Policy:  Definition: A policy that mandates strict consequences for specific behaviors, often related to compliance violations or ethical misconduct.

Facebook®, Instagram®, LinkedIn®, Twitter®, YouTube®, Bloomberg®, Zoom®, RingCentral®, Microsoft®, Microsoft Teams®, Slack®, and Salesforce® are all registered trademarks of their respective entities.

MessageWatcher archiving complies with all the above companies' terms, conditions, and related policies.