7 Compliance Terms SMBs Should Know
Compliance gets easier when the key terms are less confusing.
Here are seven terms every small business should understand before building policies, checklists, registers, evidence records, or audit-readiness documentation.
1. Policy A policy explains what should happen. It sets expectations, rules, and responsibilities.
2. Control A control is a safeguard, process, or activity used to reduce risk. Examples include approvals, access reviews, backups, training, monitoring, and vendor checks.
3. Evidence Evidence is proof that work happened. This could include logs, screenshots, signed acknowledgements, completed reviews, training records, or approval notes.
4. Risk Risk is the possibility that something could go wrong and affect your business, customers, systems, data, operations, or compliance obligations.
5. Register A register is a central list used to track important items. Common examples include a risk register, vendor register, asset register, document register, and evidence register.
6. Owner An owner is the person responsible for keeping a document, control, process, risk, vendor, or evidence item current.
7. Review Cycle A review cycle defines how often something should be checked, updated, approved, or refreshed.
A simple way to think about it:
Policy = what should happen Control = what reduces risk Evidence = how you prove it Risk = what could go wrong Register = how you track it Owner = who is responsible Review Cycle = when it gets checked again
Repost this list if it is helpful.
Browse the free glossaries for more plain-English compliance terms.














