Quick answer
A Confluence controlled vocabulary is a governed set of approved terms and definitions used across Confluence pages.
It helps compliance, QA, GRC, legal, security, and regulatory teams prevent inconsistent wording in policies, SOPs, controls, requirements, vendor answers, risk records, and audit narratives.
What a controlled vocabulary needs in Confluence
| Need | Risk without control | Governed vocabulary control |
|---|---|---|
| Approved definition | Teams copy definitions from old pages or policy drafts. | One approved glossary record with status and owner. |
| Synonym handling | Different teams use different words for the same regulated concept. | Approved synonyms and deprecated terms stored with the term. |
| Independent review | The author self-approves wording that affects compliance evidence. | Four-eyes review before approved state. |
| Cross-space reuse | Copied glossaries drift across legal, QA, security, and product spaces. | Shared glossaries distribute approved source terms to consumer spaces. |
| Page enforcement | Approved definitions exist, but writers do not know where pages drift. | Page scanner reports unapproved, deprecated, or undefined terminology. |
| Evidence export | Reviewers need manual screenshots and page-by-page history checks. | CSV export for controlled terminology evidence. |
Common controlled vocabulary sets
Security and SOC 2
Terms such as incident, control, risk owner, vendor, asset, change, evidence, and exception.
FDA, GxP, and QMS
Terms such as CAPA, deviation, validation, verification, complaint, SOP, training, and batch record.
EU AI Act
Terms such as provider, deployer, intended purpose, high-risk AI system, AI system, output, and model.
DORA and NIS2
Terms such as ICT risk, incident, essential entity, important entity, management body, third-party risk, and resilience.
Legal operations
Terms such as legal basis, personal data, processor, controller, indemnity, approval owner, and disclosure.
Vendor review
Terms such as subprocessors, data location, encryption, retention, audit rights, access control, and evidence owner.
Implementation sequence
- Pick the source space. Choose where approved definitions live.
- Create draft terms. Include definitions, synonyms, owners, categories, source notes, and requirement mappings.
- Route four-eyes review. Require independent review before terms become approved.
- Share approved terms. Publish the source glossary to Confluence spaces that consume the vocabulary.
- Scan pages. Detect deprecated, undefined, and unapproved terminology in Confluence pages.
- Export evidence. Use CSV export for review packets and audit preparation.
Related Confluence pages
Compliance for Confluence
Canonical overview for Confluence compliance glossary, controlled terminology, and audit evidence.
Confluence audit evidence
How controlled terms become reviewer-ready evidence.
Confluence compliance documentation
Where controlled vocabulary fits into regulated documentation.
Govern approved vocabulary inside Confluence.
Use Compliance Glossary when regulated pages need approved terms, shared glossary distribution, page scanning, and CSV evidence export.
FAQ
Is a controlled vocabulary the same as a glossary?
No. A glossary lists definitions. A controlled vocabulary governs which definitions are approved, which terms are deprecated, who reviewed changes, and where pages drift from approved wording.
Can one vocabulary serve multiple Confluence spaces?
Yes. Shared glossaries let a source space publish approved terms to consumer spaces.
Does the scanner change Confluence pages?
No. The scanner reads pages and reports terminology findings. It does not modify page content.