1/21
Vocabulary-style flashcards covering GRC fundamentals, EU regulatory frameworks, company background, and key terminology from the GYRO First Interview Study Guide.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
GYRO
A Copenhagen boutique consultancy founded in 2014 that helps regulated organisations make and demonstrate risk-based decisions across GRC, cybersecurity, legal compliance, and AI.
Governance
The GRC domain defining who decides, who owns the work, which policies apply, how responsibilities are assigned, and how management receives assurance.
Risk
What could prevent an organisation from reaching its objectives, how likely and severe it is, which controls reduce it, and whether it should be treated, accepted, transferred, or avoided.
Compliance
Which laws, regulations, contracts, and standards apply, how requirements are implemented, and what evidence demonstrates that obligations are being met.
Control
A technical, organisational, or procedural measure that reduces risk or satisfies a requirement.
Evidence
Proof that a control exists and operates, such as logs, approvals, training records, configurations, test results, or tickets.
Risk Register
A living record of risks, likelihood, impact, controls, owners, treatment actions, deadlines, and status.
Control Owner
The person accountable for implementing, operating, and evidencing a control.
Gap Assessment
A comparison between required or desired practice and the organisation's current state.
Residual Risk
Risk that remains after controls and mitigation measures are applied.
Audit Trail
A traceable record of sources, actions, approvals, decisions, evidence, and changes.
Continuous Compliance
Keeping controls and evidence current throughout the year instead of assembling them only before an audit.
Core GRC Chain
The sequence: Requirement -> control -> owner -> evidence -> test -> gap or risk -> remediation -> management report.
NIS2
The EU cybersecurity directive for essential and important entities across critical sectors, implemented via Denmark's NIS2 Act which entered into force on 1 July 2025.
NIS2 Incident Reporting Framework
A staged incident reporting requirement for significant incidents: early warning within 24 hours, incident notification within 72 hours, and a final report generally within one month.
DORA
The EU Digital Operational Resilience Act, an EU regulation that has applied since 17 January 2025 establishing a uniform framework for ICT risk management in the financial sector.
ISO/IEC 27001:2022
A certifiable management-system standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
GDPR
EU regulation governing the processing of personal data and protecting individuals' rights, requiring personal-data breach notification to supervisory authorities within 72 hours.
Mads Hermann
Partner at GYRO with 15 years of experience and over 30 consulting projects, specializing in strategic IT transformation, agile risk management, and corporate governance.
Louise Bredgaard
Senior legal consultant at GYRO with ten years of legal experience across law firms, the public sector, and consulting, specializing in GDPR and regulatory governance.
ZTL
A regulated fintech and payments business that publicly describes an AI-powered governance platform developed with GYRO.
gyrotech.ai
The newer product platform for GYRO, presenting an autonomous GRC workforce powered by specialised AI agents.