The vocabulary, in plain words
Every term carries what it is and why a practitioner cares. The second line is the part that makes it usable. Free at every tier, because vocabulary is the first barrier into this work and the wrong thing to charge for.
B
- Bridge letter gap letter
-
A statement from a service organization covering the period between the end of its most recent assurance report and today.
It is management's representation, not an auditor's opinion: no controls were tested for that period. A bridge stretching past about six months usually means the next report is late.
Taught in TPR-210 · See also: Type I and Type II, Subservice organisation
C
- Complementary user entity control CUEC
-
A control the service organization assumes its customer operates, listed in the assurance report and relied on by the auditor's opinion.
It is an obligation that lands on you. A clean opinion means the service is secure if you do your part, and the report tells you what your part is.
Taught in TPR-215 · See also: Subservice organisation, Type I and Type II
- Concentration risk
-
Exposure created when many of your services depend on the same provider, region, firm or rail.
Some concentration is rational; the obligation is to know about it and plan for it. Nine independent vendors on one cloud region fail together.
Taught in TPR-250 · See also: Fourth party
F
- Fourth party
-
Your vendor's vendor: the providers behind the companies you contract with.
You did not choose them and cannot see them without looking. The same few names sit behind many vendors, so apparent diversification often is not.
Taught in TPR-250 · See also: Concentration risk, Subservice organisation
S
- Subservice organisation carve-out
-
A vendor of your vendor whose controls matter to the service you receive, either included in the report or carved out of it and named.
A carve-out is a boundary, not a finding. It tells you which control objectives depend on a company whose report you do not yet hold.
Taught in TPR-210 · See also: Complementary user entity control, Fourth party
T
- Type I and Type II
-
A Type I report opines on whether controls are suitably designed at a point in time; a Type II adds testing of whether they operated over a period.
A Type I can be achieved by a company that wrote its policies last month. Sophisticated buyers read the Type II exceptions before the opinion.
Taught in TPR-210 · See also: Bridge letter, Complementary user entity control
Maintained by the association. A term here is a summary; the course named beside it is where the practice is taught.