What auditors actually check about your terminology management — and how Compliance Glossary helps you pass. Mapped to real regulatory standards.
We fact-checked every claim against actual regulatory standards. Each control weakness below is marked with its evidence level: Verified means an explicit regulatory requirement exists with a citable standard. Well-Supported means real compliance principles apply but the extension to glossary terms is inferred. Planned means the feature is on our roadmap.
21 CFR 211.100(b) SOX SOC 2 CC8
21 CFR 211.100(b) states: "Any deviation from the written procedures shall be recorded and justified" (see 21 CFR 211.100). SOC 2 Trust Services Criterion CC8.1 covers change management — it requires the entity to authorize, design, develop or acquire, configure, document, test, approve, and implement changes to infrastructure, data, software, and procedures (see AICPA 2017 Trust Services Criteria, revised 2022). In practice, audit evidence requires the reason for change, the authorizing person, and who implemented it. See how this applies to FDA terminology management and SOC 2 term governance.
This is one of the most consistently mandated requirements across all compliance frameworks. Auditors don't just want to see what changed — they need to know why.
ISO 9001:2015 §7.5.3 21 CFR 211.100(a) ISO 13485:2016 §4.2.4
ISO 9001:2015 Clause 7.5.3 requires documented information to be controlled so that it is available and suitable for use where and when needed, and that changes are controlled (see ISO 9001:2015, paywalled). ISO 13485:2016 Clause 4.2.4 requires a documented procedure for controlling documents, including periodic review, update, and re-approval (see ISO 13485:2016, paywalled). 21 CFR 211.100(a) requires written procedures to be drafted, reviewed, and approved by the appropriate organizational units and reviewed and approved by the quality control unit (see 21 CFR 211.100).
While no standard mandates a specific review frequency, auditors universally check that approved documents remain current. An approved term from 18 months ago with no review record is a red flag.
reviewedAt timestamp, set when approved. The Dashboard shows an amber warning listing all approved terms not reviewed in 6+ months. Auditors can see at a glance which terms are current and which need attention.
Controlled Terminology (general principle) ICH E2D
For pharmacovigilance (MedDRA) and clinical data submission (CDISC), controlled terminology is an explicit regulatory obligation. For other industries, the principle applies by analogy — enforcing a controlled vocabulary across documents applies wherever terminology drift creates risk. The app includes pre-loaded packs for EU AI Act, DORA, NIS2, SOC 2, FDA / GxP, ISO/IEC 27001, ISO 13485, and ALCOA+ / GxP data integrity. Non-verbatim packs install as drafts for review before audit use.
ICH pharmacovigilance guidelines expect staff handling regulated data to be trained in the applicable controlled terminologies (such as MedDRA) and for that proficiency to be confirmed — see ICH E2D Guideline and MedDRA training guidance from the MedDRA MSSO.
ALCOA+ (Attributable, Contemporaneous)
ALCOA+ requires data to be Attributable (who did it), Contemporaneous (timestamped when it happened), and Enduring (preserved for the record lifecycle). 21 CFR Part 11 requires audit trails for electronic records — though its full scope (electronic signatures, system validation) goes beyond what a glossary tool addresses. For a transparent view of our compliance scope and platform boundaries, see App Limitations.
ALCOA+ (Complete) ISO 27001 §7.5
ALCOA+ adds Complete as an attribute — nothing relevant should be missing from the record. While this principle was designed for clinical data records, auditors apply the same thinking to governance documentation. Empty fields suggest incomplete governance.
ALCOA+ (Consistent)
ALCOA+ adds Consistent as a data integrity attribute — data should be consistent across the organization (see ALCOA+ overview). The FDA's legacy CDRH event coding system was described in a 2010 AAMI Biomedical Instrumentation & Technology article as having — in the authors' words — concepts that were inconsistent, ambiguous, and duplicative (see AAMI paper). MedDRA exists specifically to prevent cross-team terminology divergence.
Single Source of Truth ISO 9001 §7.5.3
ISO 9001:2015 §7.5.3 requires documented information to be controlled so that only current, approved versions are available where they are used — and that obsolete versions are prevented from unintended use. Duplicate definitions create ambiguity about which version is authoritative — a direct control weakness.
ICH Q10 ISO 13485 §4.2.1
ICH Q10 (Pharmaceutical Quality System) identifies the source of each defined term (ICH, ISO, or newly developed) in its glossary — see ICH Q10 Guideline. ISO 13485:2016 Clause 4.2.1 requires the quality management system documentation to address the regulatory requirements applicable to the organization (see ISO 13485:2016, paywalled). Linking terms to their regulatory source demonstrates governance rigor.
regulatorySource field will link each term to its authoritative text (e.g., "FDA 21 CFR 11 §11.10(e)", "MiFID II Art. 4"). The audit export will include a traceability matrix.
No specific standard mandates this, but orphaned terms signal a neglected glossary. Planned: cross-reference scan results with the term list to flag terms defined but never found in any scanned content.
Controlled vocabulary is a real requirement in pharma (CDISC, MedDRA) and a common gap across industries. Planned: a reverse scanner that finds regulated-looking terms in documents that aren't yet managed in the glossary.
| Standard | What It Requires | Our Feature | Status |
|---|---|---|---|
| 21 CFR 211.100(b) | Deviations recorded and justified | Mandatory change reason on all changes (edits + status transitions) | Live |
| SOC 2 CC8 | Change reason + authorizing entity documented | Mandatory change reason + user ID on every version entry | Live |
| SOX | Changes authorized, documented, reviewed | Four-eyes approval + audit trail | Live |
| ISO 9001 7.5.3 | Documents reviewed and kept current | Stale approval detection (6-month flag) | Live |
| ISO 13485 4.2.4 | Document review and update procedures | reviewedAt tracking + dashboard | Live |
| 21 CFR Part 11 | Audit trails for electronic records | Append-only version history with user/timestamp (audit trail scope; e-signatures and system validation require org-level processes) | Live |
| ALCOA+ | Attributable, Complete, Consistent, Enduring | User tracking, mandatory change reasons, cross-space scan, CSV export | Live |
| Controlled Terminology | Terminology consistency across documents | Custom glossary synonym scanner across Confluence pages | Live |
| ICH Q10 | Source traceability for definitions | regulatorySource field + traceability matrix | Planned |