The vocabulary, without the jargon.
Every term this site uses, defined in a line or two. Written for someone who has been handed a regulation and a deadline, not for someone who already knows the answer. Each definition links to the guide that works it through properly.
Reviewed: 2 September 2026. Definitions describe the concept; figures and deadlines live in the dated guides.
This glossary defines the terms used across four regulatory regimes: the EU Digital Operational Resilience Act and its Register of Information, UK operational resilience under the FCA and PRA, HMRC Making Tax Digital for VAT and Income Tax, and the EU AI Act alongside UK AI governance. Each entry has its own anchor so it can be linked and cited directly, and each links on to the guide that explains it in full.
EU DORA.
The Digital Operational Resilience Act and its implementing standards.
Digital Operational Resilience Act (DORA)
Regulation (EU) 2022/2554, the EU law that sets ICT risk-management, incident-reporting and third-party oversight requirements for financial entities. It applies alongside, not instead of, existing prudential rules. Read more.
Register of Information (RoI)
The structured record every in-scope financial entity must maintain of its contractual arrangements for ICT services, and submit to its competent authority. Its shape is fixed by implementing technical standards, not left to the firm. Read more.
Implementing Technical Standards (ITS)
Commission Implementing Regulation (EU) 2024/2956, which defines the Register of Information as a set of linked templates with prescribed fields, formats and cross-references. It is the document that decides whether a register is well-formed. Read more.
ICT third-party service provider
An undertaking supplying ICT services to a financial entity. The register records the provider, the arrangement, and the function the service supports — three separate things that are frequently conflated. Read more.
Critical or important function
A function whose failure would materially impair a firm's financial performance, or the soundness or continuity of its regulated services. Whether a given function qualifies is the firm's judgement, and it drives much of what the register demands. Read more.
ICT subcontracting chain
The sequence of providers behind a direct supplier. DORA's interest does not stop at the counterparty you contracted with: where a subcontractor effectively supports a critical or important function, the chain has to be recorded. Read more.
Annex III ICT service type
The controlled vocabulary of ICT service types used to classify each arrangement in the register. Entries must carry the published code, not a free-text description of the service. Read more.
Legal Entity Identifier (LEI)
A 20-character code identifying a legal entity, defined by ISO 17442: 18 characters identifying the entity followed by two check digits. The checksum is MOD 97-10, so a mistyped LEI is detectable arithmetically without any lookup. Read more.
xBRL-CSV
The reporting format in which the Register of Information is submitted: CSV tables bound to a published taxonomy, so a supervisor's tooling can validate the submission mechanically rather than by reading it. Read more.
Referential integrity
The requirement that identifiers used in one register template resolve to a matching record in another. Most rejected registers fail here rather than on any single field: each table is individually plausible and they do not join up. Read more.
UK operational resilience.
What the PRA and FCA expect firms to hold on the record.
Important business service (IBS)
A service a firm provides to an external end user whose disruption could cause intolerable harm to consumers or risk to market integrity. Naming these is the first act of an operational-resilience framework, and everything else hangs off the list. Read more.
Impact tolerance
The maximum tolerable disruption to an important business service, expressed as a measurable limit — usually time, sometimes volume. It is a board-level statement of what the firm will not allow to happen, not an availability target. Read more.
Severe but plausible scenario
The class of disruption a firm must be able to remain within its impact tolerances for. Severe rules out comfortable scenarios; plausible rules out the unfalsifiable ones. Choosing them well is most of the work in scenario testing. Read more.
Mapping
The documented chain of people, processes, technology, facilities and third parties that an important business service depends on. Its purpose is to make a tolerance testable: without it, a tolerance is an assertion. Read more.
Self-assessment
The firm's own written account of its important business services, tolerances, mapping and testing, kept current and available to the supervisor on request. Read more.
Material third party
A supplier whose failure would threaten a firm's ability to stay within its impact tolerances. UK reporting rules require these to be identified and registered, in a register distinct from — though overlapping with — a DORA one. Read more.
SYSC 15A
The FCA Handbook chapter setting operational-resilience requirements for FCA-regulated firms. Its PRA counterpart for dual-regulated firms is supervisory statement SS1/21. Read more.
HMRC Making Tax Digital.
The digital record-keeping and filing regime for VAT and Income Tax.
Making Tax Digital (MTD)
HMRC's programme requiring businesses to keep digital records and file through software rather than by re-keying figures into a portal. VAT came first; Income Tax Self Assessment follows. Read more.
Digital link
An electronic transfer of data between pieces of software with no manual intervention in between. Copy-and-paste and re-typing both break it — which is the rule most often broken by accident, because the resulting figure is still correct. Read more.
Bridging software
Software that takes figures from a firm's existing records and submits them to HMRC over the API, preserving the digital link. The term covers everything from a spreadsheet macro to a validated pipeline, which is why the label alone tells a buyer very little. Read more.
Functional compatible software
HMRC's term for a software product, or set of products, that together keep the required digital records and exchange information with HMRC digitally. The obligation is on the whole chain, not on one application in it. Read more.
The nine boxes
The nine values that constitute a UK VAT return. Under MTD they must be produced by software from digitally linked records rather than assembled by hand. Read more.
Income Tax Self Assessment (ITSA)
The Income Tax regime being brought into Making Tax Digital, replacing one annual return with quarterly updates per income source plus a year-end process. For a practice it multiplies filing events across the whole client book. Read more.
Quarterly update
A cumulative summary of income and expenses for a business or property source, submitted to HMRC during the tax year under MTD for Income Tax. It is not a tax calculation and nothing is due on the strength of it. Read more.
Final declaration
The year-end step under MTD for Income Tax in which a taxpayer confirms their complete position and finalises their liability. It is the point at which a named person takes responsibility for the figures. Read more.
VAT registration number (VRN)
The identifier for a VAT-registered business. It carries a modulus check, so a mistyped VRN can be caught before a submission is attempted rather than after HMRC rejects it.
CIS300
The Construction Industry Scheme monthly contractor return, reporting payments to subcontractors and the tax deducted at 0%, 20% or 30% depending on the subcontractor's verification status.
EU AI Act and UK AI governance.
Two different regimes that are frequently confused.
EU Artificial Intelligence Act (EU AI Act)
Regulation (EU) 2024/1689, which regulates AI systems placed on the EU market according to the risk they present, with the heaviest obligations falling on high-risk systems and on general-purpose models. Read more.
High-risk AI system
An AI system whose use case places it in the Act's high-risk category, triggering obligations for risk management, data governance, technical documentation, logging, human oversight and conformity assessment. Classification follows from what the system is used for, not from how sophisticated it is. Read more.
Annex IV technical documentation
The documentation set a provider of a high-risk AI system must hold, covering the system's design, development, monitoring and performance. Completeness is the gate: a partially documented system is an undocumented one. Read more.
General-purpose AI model (GPAI)
A model displaying significant generality and capable of competently performing a wide range of tasks. The Act places transparency and, above a capability threshold, systemic-risk obligations on providers of these models. Read more.
Fundamental rights impact assessment (FRIA)
The assessment required under Article 27 from certain deployers of high-risk AI systems, covering the effect of the system's use on the rights of affected people. Read more.
Provider and deployer
The Act's two principal roles. A provider develops a system and places it on the market; a deployer uses one under its own authority. The obligations differ sharply, and a firm that fine-tunes or rebrands a system can become a provider without intending to. Read more.
SS1/23
The PRA supervisory statement setting model risk management principles for banks, in effect since 17 May 2024. It is a UK expectation about model governance, and it is not an AI Act — the UK has not enacted one. Read more.
Model inventory
The record of every model a firm relies on, with a risk tier derived from its materiality, complexity and the autonomy of the decisions it drives. The tier then sets how often the model must be validated. Read more.
Algorithmic Transparency Recording Standard (ATRS)
The UK government standard for publishing records of algorithmic tools used in public-sector decision-making, mandatory for central government departments. Read more.
How Qgentic works.
Terms used across this site to describe the product itself.
Deterministic validation
Checking a filing with fixed rules executed as code, so identical inputs always produce an identical result. It is what makes a filing reproducible and a rejection explainable, and it is why language models are used for extraction here but never for deciding whether a return is correct. Read more.
Named approver
The person who approves a filing before it leaves the firm. Every Qgentic run halts at an approval gate; there is no unattended self-approval mode, and the approval is recorded against a person rather than a service account. Read more.
Hash-chained audit log
An append-only record in which each entry carries a SHA-256 hash of the one before it, so any alteration of history breaks the chain and is detectable. It is what turns an assertion about what happened into evidence an auditor can verify. Read more.
Air-gapped
A deployment on a network with no route to the internet. For compliance software the claim is only meaningful if the product also has no phone-home licensing, no telemetry and no external dependency at run time — which is testable, and worth testing. Read more.
Meter event
A billable outcome recorded on the audit chain — an arrangement registered, a vendor validated, a submission prepared. Because billing counts these entries, an invoice line can be recomputed from the exported log. Read more.
Prepare-only
A pack that produces the complete, validated submission package but does not transmit it, because the regulator publishes no submission API. The firm files through the channel it already uses. Stated plainly wherever it applies, because describing prepare-only as filing misrepresents what a buyer gets. Read more.