Rhindon Cyber logo
    Support & Documentation
    Contact Support

    Core Concepts & Glossary

    RAIC models AI governance with a small set of objects that link to each other. Understanding those objects — and how they differ — makes every other page in this documentation easier to follow.

    Organizations and tenancy

    Every record in RAIC belongs to exactly one organization. An organization is your tenant: its users, AI systems, use cases, controls, risks, evidence, and audit history are isolated from every other tenant at the database layer, not just in the interface. Super Admins can impersonate an organization for support purposes; while impersonating, they see exactly what that tenant sees, and the impersonation itself is recorded in the platform audit log.

    The four core objects

    AI System
    A deployed or planned piece of AI technology — a vendor product, an internal model, or an API you consume. Systems carry a lifecycle stage, an owner, a risk tier, and links to datasets, suppliers, and controls. If you can point at software, it is a system.
    Use Case
    A business purpose that uses AI. Use cases arrive through intake (public portal or internal submission), get an RC-{DEPT}-{###} identifier, and move through the governance workflow to approval. One system can serve many use cases, and one use case can rely on several systems.
    Control
    A safeguard you have committed to operating — technical, procedural, or contractual. Controls carry an owner, a test method, effectiveness evidence, and mappings to framework requirements. They are the thing auditors actually examine.
    Risk
    A scored statement of something that could go wrong. Risks link to the systems and use cases they threaten and to the controls that reduce them.

    Inherent versus residual risk

    RAIC scores every risk twice. Inherent risk is the exposure before any control operates — the raw likelihood and impact if nothing were in place. Residual risk is the exposure that remains once your controls are working as designed. The gap between the two is the measurable value your control program delivers, which is why the heatmap lets you toggle between the two views. Both use the same 5x5 likelihood-by-impact grid so the numbers are directly comparable.

    Evidence and the approval lifecycle

    Governance claims in RAIC are only as good as their evidence. Most objects follow the same arc: draft, submitted for review, reviewed, approved, and then periodically re-reviewed on a cadence you set. Approvals capture who signed off and when; delegation lets an approver nominate a substitute without breaking the chain. Evidence attaches to the object it supports, and the uploader is recorded server-side rather than trusted from the browser.

    Framework mappings and crosswalks

    Rather than maintaining a separate control set per framework, RAIC keeps one canonical control register and maps it into each framework you care about. A single control can satisfy an ISO 42001 Annex A control, a NIST CSF 2.0 subcategory, a CIS safeguard, a SOC 2 Trust Services criterion, and an EU AI Act obligation at the same time. Crosswalk tables ship with the platform and drive the coverage and gap reports.

    Glossary

    AIMS
    AI Management System — the ISO/IEC 42001 term for the governance system RAIC helps you operate.
    Annex A
    The list of reference controls in ISO/IEC 42001 that your Statement of Applicability responds to.
    CGMI
    Cyber Governance Maturity Index — the cybersecurity half of the RAIC maturity score.
    GMI
    Governance Maturity Index — the AI governance half of the RAIC maturity score.
    KCI
    Key Control Indicator — a measurable signal that a control is operating effectively.
    NHI
    Non-Human Identity — a service principal, app registration, bot, or agent credential discovered during scanning.
    POA&M
    Plan of Action and Milestones — the remediation plan attached to an identified gap.
    PowerGRYD
    Rhindon's 5-layer maturity pyramid and the report family (R-PG-0 through R-PG-4) built on it.
    Shadow AI
    AI tools in use inside your organization that governance does not yet know about.
    SoA
    Statement of Applicability — the document declaring which framework controls apply to you and why.
    TGP
    Total Governance Posture — the combined score across AI and cyber governance.
    Unknown Signal
    A detected AI endpoint not yet present in the curated AI catalog, awaiting triage or auto-promotion.