Compliance Guide

What auditors actually check about your terminology management — and how Compliance Glossary helps you pass. Mapped to real regulatory standards.

We fact-checked every claim against actual regulatory standards. Each control weakness below is marked with its evidence level: Verified means an explicit regulatory requirement exists with a citable standard. Well-Supported means real compliance principles apply but the extension to glossary terms is inferred. Planned means the feature is on our roadmap.

Verified

Change Justification

21 CFR 211.100(b) SOX SOC 2 CC8

"Why did this definition change?"

The Requirement

21 CFR 211.100(b) states: "Any deviation from the written procedures shall be recorded and justified" (see 21 CFR 211.100). SOC 2 Trust Services Criterion CC8.1 covers change management — it requires the entity to authorize, design, develop or acquire, configure, document, test, approve, and implement changes to infrastructure, data, software, and procedures (see AICPA 2017 Trust Services Criteria, revised 2022). In practice, audit evidence requires the reason for change, the authorizing person, and who implemented it. See how this applies to FDA terminology management and SOC 2 term governance.

This is one of the most consistently mandated requirements across all compliance frameworks. Auditors don't just want to see what changed — they need to know why.

How we help: Every change — edits, status transitions (submit, approve, reject, deprecate, reactivate) — requires a "Reason for Change" field. The reason is stored in the version history alongside the diff, visible in the History view and included in the audit CSV export. The field is mandatory — changes without a reason are rejected.
Verified

Stale Approvals Detection

ISO 9001:2015 §7.5.3 21 CFR 211.100(a) ISO 13485:2016 §4.2.4

"When was this term last reviewed?"

The Requirement

ISO 9001:2015 Clause 7.5.3 requires documented information to be controlled so that it is available and suitable for use where and when needed, and that changes are controlled (see ISO 9001:2015, paywalled). ISO 13485:2016 Clause 4.2.4 requires a documented procedure for controlling documents, including periodic review, update, and re-approval (see ISO 13485:2016, paywalled). 21 CFR 211.100(a) requires written procedures to be drafted, reviewed, and approved by the appropriate organizational units and reviewed and approved by the quality control unit (see 21 CFR 211.100).

While no standard mandates a specific review frequency, auditors universally check that approved documents remain current. An approved term from 18 months ago with no review record is a red flag.

How we help: Every term tracks a reviewedAt timestamp, set when approved. The Dashboard shows an amber warning listing all approved terms not reviewed in 6+ months. Auditors can see at a glance which terms are current and which need attention.
Verified

Synonym Drift & Terminology Consistency

Controlled Terminology (general principle) ICH E2D

"Your glossary says 'Adverse Event' but your documents say 'AE', 'AEs', and 'adverse events'."

The Requirement

For pharmacovigilance (MedDRA) and clinical data submission (CDISC), controlled terminology is an explicit regulatory obligation. For other industries, the principle applies by analogy — enforcing a controlled vocabulary across documents applies wherever terminology drift creates risk. The app includes pre-loaded packs for EU AI Act, DORA, NIS2, SOC 2, FDA / GxP, ISO/IEC 27001, ISO 13485, and ALCOA+ / GxP data integrity. Non-verbatim packs install as drafts for review before audit use.

ICH pharmacovigilance guidelines expect staff handling regulated data to be trained in the applicable controlled terminologies (such as MedDRA) and for that proficiency to be confirmed — see ICH E2D Guideline and MedDRA training guidance from the MedDRA MSSO.

How we help: The Compliance Scanner detects synonym violations across your Confluence pages using your custom glossary. Define "Adverse Event" as the approved term with synonyms "AE, AEs, adverse events" — the scanner flags every page using the informal variants and recommends the approved form. Scope note: This is custom glossary enforcement, not a direct integration with MedDRA or CDISC databases. Teams requiring specific MedDRA/CDISC coding should import those terms into the glossary.
Well-Supported

Complete Audit Trail

ALCOA+ (Attributable, Contemporaneous)

"Show me who changed what, when, and why."

The Principle

ALCOA+ requires data to be Attributable (who did it), Contemporaneous (timestamped when it happened), and Enduring (preserved for the record lifecycle). 21 CFR Part 11 requires audit trails for electronic records — though its full scope (electronic signatures, system validation) goes beyond what a glossary tool addresses. For a transparent view of our compliance scope and platform boundaries, see App Limitations.

How we help: Every action — create, edit, status change, approval, deprecation — is recorded with user ID, timestamp, and mandatory change reason. Version history is append-only (no UI to edit or delete version records) and included in the audit CSV export. The four-eyes principle prevents self-approval. Scope note: We implement audit trail and change control aspects of Part 11. Full Part 11 compliance (electronic signatures, system validation, access controls) requires organizational processes beyond a single app.
Well-Supported

Incomplete Metadata

ALCOA+ (Complete) ISO 27001 §7.5

"Why is this term missing a category and synonyms?"

The Principle

ALCOA+ adds Complete as an attribute — nothing relevant should be missing from the record. While this principle was designed for clinical data records, auditors apply the same thinking to governance documentation. Empty fields suggest incomplete governance.

How we help: Terms have structured metadata fields: category, synonyms, notes, space scope. The audit export makes gaps visible. Dashboard compliance score incentivizes completeness.
Well-Supported

Cross-Space Inconsistency

ALCOA+ (Consistent)

"Does 'material adverse change' mean the same thing in your legal space as in your finance space?"

The Principle

ALCOA+ adds Consistent as a data integrity attribute — data should be consistent across the organization (see ALCOA+ overview). The FDA's legacy CDRH event coding system was described in a 2010 AAMI Biomedical Instrumentation & Technology article as having — in the authors' words — concepts that were inconsistent, ambiguous, and duplicative (see AAMI paper). MedDRA exists specifically to prevent cross-team terminology divergence.

How we help: The Compliance Scanner runs across Confluence spaces, detecting where the same term appears in different contexts. One glossary serves as the single source of truth for all spaces.
Well-Supported

Duplicate Definitions

Single Source of Truth ISO 9001 §7.5.3

"You have two entries for 'Data Controller' with different definitions. Which one is authoritative?"

The Principle

ISO 9001:2015 §7.5.3 requires documented information to be controlled so that only current, approved versions are available where they are used — and that obsolete versions are prevented from unintended use. Duplicate definitions create ambiguity about which version is authoritative — a direct control weakness.

How we help: CSV import automatically detects and skips duplicates (case-insensitive matching). Existing duplicates are reported to the user with their current status so they can be resolved.
Well-Supported

Regulatory Source Traceability

ICH Q10 ISO 13485 §4.2.1

"Where does this definition come from? What's the authoritative source?"

The Principle

ICH Q10 (Pharmaceutical Quality System) identifies the source of each defined term (ICH, ISO, or newly developed) in its glossary — see ICH Q10 Guideline. ISO 13485:2016 Clause 4.2.1 requires the quality management system documentation to address the regulatory requirements applicable to the organization (see ISO 13485:2016, paywalled). Linking terms to their regulatory source demonstrates governance rigor.

How we help (planned): A regulatorySource field will link each term to its authoritative text (e.g., "FDA 21 CFR 11 §11.10(e)", "MiFID II Art. 4"). The audit export will include a traceability matrix.
Planned

Orphaned Terms Detection

"You defined 200 terms but only 80 appear in your documents. Is the glossary maintained?"

No specific standard mandates this, but orphaned terms signal a neglected glossary. Planned: cross-reference scan results with the term list to flag terms defined but never found in any scanned content.

Planned

Missing Terms Detection

"This regulated term appears in your documentation but isn't in your glossary."

Controlled vocabulary is a real requirement in pharma (CDISC, MedDRA) and a common gap across industries. Planned: a reverse scanner that finds regulated-looking terms in documents that aren't yet managed in the glossary.

Standards Coverage Summary

StandardWhat It RequiresOur FeatureStatus
21 CFR 211.100(b)Deviations recorded and justifiedMandatory change reason on all changes (edits + status transitions)Live
SOC 2 CC8Change reason + authorizing entity documentedMandatory change reason + user ID on every version entryLive
SOXChanges authorized, documented, reviewedFour-eyes approval + audit trailLive
ISO 9001 7.5.3Documents reviewed and kept currentStale approval detection (6-month flag)Live
ISO 13485 4.2.4Document review and update proceduresreviewedAt tracking + dashboardLive
21 CFR Part 11Audit trails for electronic recordsAppend-only version history with user/timestamp (audit trail scope; e-signatures and system validation require org-level processes)Live
ALCOA+Attributable, Complete, Consistent, EnduringUser tracking, mandatory change reasons, cross-space scan, CSV exportLive
Controlled TerminologyTerminology consistency across documentsCustom glossary synonym scanner across Confluence pagesLive
ICH Q10Source traceability for definitionsregulatorySource field + traceability matrixPlanned

Sources