GYRO First Interview Study Guide Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/21

flashcard set

Earn XP

Description and Tags

Vocabulary-style flashcards covering GRC fundamentals, EU regulatory frameworks, company background, and key terminology from the GYRO First Interview Study Guide.

Last updated 8:36 AM on 8/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

22 Terms

1
New cards

GYRO

A Copenhagen boutique consultancy founded in 2014 that helps regulated organisations make and demonstrate risk-based decisions across GRC, cybersecurity, legal compliance, and AI.

2
New cards

Governance

The GRC domain defining who decides, who owns the work, which policies apply, how responsibilities are assigned, and how management receives assurance.

3
New cards

Risk

What could prevent an organisation from reaching its objectives, how likely and severe it is, which controls reduce it, and whether it should be treated, accepted, transferred, or avoided.

4
New cards

Compliance

Which laws, regulations, contracts, and standards apply, how requirements are implemented, and what evidence demonstrates that obligations are being met.

5
New cards

Control

A technical, organisational, or procedural measure that reduces risk or satisfies a requirement.

6
New cards

Evidence

Proof that a control exists and operates, such as logs, approvals, training records, configurations, test results, or tickets.

7
New cards

Risk Register

A living record of risks, likelihood, impact, controls, owners, treatment actions, deadlines, and status.

8
New cards

Control Owner

The person accountable for implementing, operating, and evidencing a control.

9
New cards

Gap Assessment

A comparison between required or desired practice and the organisation's current state.

10
New cards

Residual Risk

Risk that remains after controls and mitigation measures are applied.

11
New cards

Audit Trail

A traceable record of sources, actions, approvals, decisions, evidence, and changes.

12
New cards

Continuous Compliance

Keeping controls and evidence current throughout the year instead of assembling them only before an audit.

13
New cards

Core GRC Chain

The sequence: Requirement -> control -> owner -> evidence -> test -> gap or risk -> remediation -> management report.

14
New cards

NIS2

The EU cybersecurity directive for essential and important entities across critical sectors, implemented via Denmark's NIS2 Act which entered into force on 1 July 2025.

15
New cards

NIS2 Incident Reporting Framework

A staged incident reporting requirement for significant incidents: early warning within 24 hours, incident notification within 72 hours, and a final report generally within one month.

16
New cards

DORA

The EU Digital Operational Resilience Act, an EU regulation that has applied since 17 January 2025 establishing a uniform framework for ICT risk management in the financial sector.

17
New cards

ISO/IEC 27001:2022

A certifiable management-system standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

18
New cards

GDPR

EU regulation governing the processing of personal data and protecting individuals' rights, requiring personal-data breach notification to supervisory authorities within 72 hours.

19
New cards

Mads Hermann

Partner at GYRO with 15 years of experience and over 30 consulting projects, specializing in strategic IT transformation, agile risk management, and corporate governance.

20
New cards

Louise Bredgaard

Senior legal consultant at GYRO with ten years of legal experience across law firms, the public sector, and consulting, specializing in GDPR and regulatory governance.

21
New cards

ZTL

A regulated fintech and payments business that publicly describes an AI-powered governance platform developed with GYRO.

22
New cards

gyrotech.ai

The newer product platform for GYRO, presenting an autonomous GRC workforce powered by specialised AI agents.