Glossary
용어집Glossary
분야 핵심 용어를 정의·중요성·실무 적용과 함께 정리했습니다.Key terms in the field, with definitions, importance, and practical application.
용어 퀴즈 풀어보기Take the term quiz- Ethic Code Engineering
- 윤리경영·컴플라이언스의 추상적 원칙을 탐지 규칙과 코드로 구현해 부정·비위 리스크를 상시 모니터링하는 접근.An approach that implements the abstract principles of business ethics and compliance as detection rules and code, continuously monitoring fraud and misconduct risk.
- 왜 중요한가Why it matters컴플라이언스를 규정집에만 두면 형식적 점검에 그친다. 코드로 구현하면 365일 24시간 자동 감시가 가능해지고, 담당자가 바뀌어도 규칙이 살아 있다.Keeping compliance only in a policy manual leads to checkbox auditing. Implementing it as code enables 24/7 automated monitoring — and the rules persist even when personnel change.
- 실무 적용In practice이해충돌·우회 승인·한도 초과 등 윤리 규정을 SQL/파이썬 탐지 규칙으로 변환해 ERP·데이터웨어하우스에 연동하고, 위반 건을 자동 경보·기록한다.Translating ethics rules — conflict of interest, unauthorized approvals, over-limit transactions — into SQL/Python detection rules connected to ERP/data-warehouse systems to auto-alert and log violations.
- Ethic Code Engineering 전문성Ethic Code Engineering Expertise →
- 연계보관성Chain of Custody
- 디지털 증거가 수집 시점부터 분석·보고까지 변조 없이 관리되었음을 입증하는 기록 체계. 증거능력의 전제 조건.A record system proving that digital evidence was managed without tampering from collection through analysis and reporting — a prerequisite for admissibility.
- 왜 중요한가Why it matters법원·징계위원회는 연계보관성이 끊기면 증거를 채택하지 않는다. 아무리 명확한 부정 증거도 보관 기록이 없으면 무효가 될 수 있다.Courts and disciplinary bodies reject evidence when chain of custody is broken. Even the clearest fraud evidence can be invalidated without proper custody records.
- 실무 적용In practice증거 수집 즉시 SHA-256 등 해시값을 기록하고, 이동·분석마다 서명·타임스탬프를 남겨 변조 가능성을 차단한다.Recording hash values (e.g., SHA-256) immediately on collection, then adding signatures and timestamps at every transfer and analysis step to preclude tampering.
- AI 디지털 포렌식 전문성AI Digital Forensics Expertise →
- LLMLarge Language Model
- 방대한 텍스트로 학습한 거대 언어모델. 문서·메신저 분석, 증거 선별·요약, 감사 자동화에 활용되어 사람이 일일이 읽기 어려운 대량 자료에서 위험 신호를 끌어낸다.A large language model trained on vast text. Used for document/chat analysis, evidence triage and summarization, and audit automation, it surfaces risk signals from large volumes of material that humans cannot read one by one.
- LLM·AI 기반 내부감사LLM & AI-Driven Internal Audit
- LLM·AI로 전수 데이터의 이상행위·부정 패턴을 자동 탐지하고 대량 문서를 분석해 표본 감사의 한계를 보완하는 감사 방식.An audit method that uses LLM·AI to automatically detect anomalies and fraud patterns across full-population data and analyze large document sets, overcoming the limits of sampling-based audit.
- 왜 중요한가Why it matters표본 감사는 전체 거래의 5% 미만만 검토한다. AI를 활용하면 100% 전수 데이터에서 숨겨진 부정 패턴을 찾아낼 수 있다.Sampling-based audit reviews less than 5% of all transactions. AI enables finding hidden fraud patterns across 100% of full-population data.
- 실무 적용In practice구매·지급·비용처리 전 거래를 LLM이 분류·요약하고, 이상행위 탐지 규칙이 선별한 건을 감사자가 우선순위 순으로 검토하는 Human-in-the-Loop 구조로 운영한다.LLM classifies and summarizes all purchasing, payment, and expense transactions; detection rules triage the results; auditors review flagged items in priority order — a Human-in-the-Loop workflow.
- AI 내부감사 전문성AI Internal Audit Expertise →
- 이상행위 탐지Anomaly Detection
- 정상 패턴에서 벗어난 거래·행동을 통계·머신러닝·LLM 등 AI로 식별하는 기법. 부정 탐지의 핵심 도구.A technique that uses AI — statistics, machine learning, LLMs — to identify transactions and behaviors that deviate from normal patterns. A core tool for fraud detection.
- 외부 제보채널Whistleblowing Channel
- 조직 구성원·이해관계자가 비위·부정·괴롭힘을 익명으로 안전하게 신고할 수 있도록 외부에 둔 신고 창구. 윤리경영의 출발점이자, 운영 기록이 ESG 거버넌스의 핵심 증거가 된다. ‘ListenTips’가 AI 기반 제보채널의 예.An externally hosted reporting channel that lets members and stakeholders report misconduct, fraud, and harassment safely and anonymously. It is the starting point of business ethics, and its operating records become key evidence for ESG governance. ‘ListenTips’ is an example of an AI-powered whistleblowing channel.
- 왜 중요한가Why it matters내부 채널만으로는 상급자 연루 부정이나 구조적 비위를 신고하기 어렵다. 외부 독립 채널이 있을 때 제보 건수와 적발률이 크게 높아진다.Internal channels alone make it hard to report fraud involving superiors or structural misconduct. An independent external channel significantly increases reporting rates and detection.
- 실무 적용In practiceAI 분류기로 접수 즉시 사안 유형(부정·괴롭힘·컴플라이언스 위반)을 자동 분류하고 담당 조직에 배정해 처리 지연을 방지하며, 전수 기록을 ESG 보고에 활용한다.An AI classifier instantly categorizes incoming reports (fraud, harassment, compliance breach) and routes them to the responsible team, preventing delays — and full records feed ESG reporting.
- Ethic Code Engineering 전문성Ethic Code Engineering Expertise →
- ESG 경영ESG Management
- 환경(E)·사회(S)·지배구조(G) 관점에서 기업의 지속가능성과 비재무 리스크를 관리하는 경영. 내부신고 제도·윤리경영·반부패 통제는 사회(S)·지배구조(G)의 핵심 평가 지표다.Managing a company's sustainability and non-financial risk across Environmental (E), Social (S), and Governance (G) dimensions. Internal-reporting systems, business ethics, and anti-corruption controls are core assessment metrics for the Social (S) and Governance (G) pillars.
- 설명가능한 AIExplainable AI (XAI)
- AI가 내린 판단의 근거와 과정을 사람이 이해·검증할 수 있게 하는 기술과 원칙. AI 기반 감사에서는 ‘왜 의심스러운가’를 설명할 수 있어야 결과가 징계·수사·소송에서 증거능력을 갖는다.Techniques and principles that let humans understand and verify the basis and process of an AI’s decisions. In AI-driven audit, being able to explain ‘why it is suspicious’ is what gives results admissibility in discipline, investigation, or litigation.
- 왜 중요한가Why it matters블랙박스 AI가 ‘의심스럽다’고만 하면 당사자는 반박할 수 없고 결과가 법적 효력을 갖기 어렵다. 설명이 있어야 방어권이 보장되고 증거 능력이 생긴다.If a black-box AI simply flags something as ‘suspicious’ with no explanation, the subject cannot mount a rebuttal and the finding struggles to hold legal weight. Explainability enables due-process rights and evidentiary standing.
- 실무 적용In practiceLLM이 이상 거래를 탐지하면 ‘판단 근거(관련 문서·규정·패턴)’를 자동 생성해 감사 보고서에 포함시키고, 감사자가 이를 검토·서명해 책임을 명확히 한다.When an LLM flags an anomalous transaction, it auto-generates a rationale (related documents, rules, patterns); auditors review and sign off, making accountability explicit.
- AI 내부감사 전문성AI Internal Audit Expertise →
- 검색증강생성Retrieval-Augmented Generation (RAG)
- LLM이 답변 전에 신뢰할 수 있는 원문·데이터를 검색해 근거로 삼게 하는 방식. 감사·포렌식에서 환각을 줄이고 인용 가능한 근거를 남기는 데 쓰인다.An approach where an LLM retrieves trusted source documents and data to ground its answer before responding. Used in audit and forensics to reduce hallucination and leave citable evidence.
- 환각Hallucination
- LLM이 사실이 아닌 내용을 그럴듯하게 만들어 내는 현상. 부정 탐지에서 가장 위험한 오류로, 모든 AI 경고는 원문 근거로 교차검증해야 한다.When an LLM fabricates plausible but false content. The most dangerous error in fraud detection — every AI alert must be cross-checked against original-source evidence.
- 상시감사Continuous Auditing
- 거래·로그·문서를 실시간 또는 주기적으로 자동 분석해 위험을 상시 감시하는 감사 방식. 표본·사후 감사를 넘어 예방적 통제로 이동한다.An audit approach that automatically analyzes transactions, logs, and documents in real time or periodically to monitor risk continuously — moving beyond sampling and after-the-fact review toward preventive control.
- AI 거버넌스AI Governance
- 조직이 AI의 위험·편향·책임을 관리하기 위한 정책과 통제 체계. ISO/IEC 42001, NIST AI RMF, EU AI Act 등이 기준으로 쓰이며, AI 감사의 점검 대상이다.An organization's policies and controls for managing AI risk, bias, and accountability. Standards such as ISO/IEC 42001, the NIST AI RMF, and the EU AI Act serve as benchmarks and are a subject of AI audits.
- 내부통제Internal Control
- 조직이 부정·위법을 예방하고 목표를 효과적으로 달성하기 위해 두는 규정·절차·체계. 내부감사가 그 설계와 운영의 적정성을 점검한다.The rules, procedures, and systems an organization establishes to prevent fraud and violations and to achieve its objectives effectively. Internal audit examines the adequacy of their design and operation.
- 컴플라이언스Compliance
- 법령·규제·내부 규정을 준수하도록 관리하는 활동과 체계. 부패방지·이해충돌·개인정보 등 영역별 프로그램으로 운영되며, 윤리경영의 실행 축이다.Activities and systems for ensuring adherence to laws, regulations, and internal rules. Operated through programs for anti-corruption, conflicts of interest, and data privacy — the executional axis of business ethics.
- 이해충돌Conflict of Interest
- 직무상 의무와 개인의 사적 이익이 충돌하는 상황. 부정·부패의 주요 신호로, 거래·관계 데이터에서 탐지 규칙으로 상시 감시한다.A situation where one's official duties conflict with private interests. A key signal of fraud and corruption, monitored continuously via detection rules over transaction and relationship data.
- 부정 트라이앵글Fraud Triangle
- 부정이 발생하는 세 가지 조건 — 기회·압력(동기)·합리화 — 을 설명하는 고전 이론. 부정 위험을 진단하고 통제를 설계하는 출발점이다.A classic theory explaining the three conditions under which fraud occurs — opportunity, pressure (motivation), and rationalization. A starting point for diagnosing fraud risk and designing controls.
- e-Discoverye-Discovery (전자증거개시)
- 소송·조사에서 이메일·문서·메신저 등 전자적으로 저장된 정보를 식별·수집·검토·제출하는 절차. 방대한 데이터를 다뤄 AI·LLM 선별이 점차 핵심이 된다.The process of identifying, collecting, reviewing, and producing electronically stored information — emails, documents, chats — in litigation or investigation. As data volumes grow, AI/LLM triage is increasingly central.
- 부정 탐지Fraud Detection
- 조직 내 부정행위를 예방·조기 발견하기 위한 기법의 총칭. 규칙 기반 탐지, 통계 분석, 머신러닝, LLM을 결합해 의심 거래·행위를 선별한다.A collective term for techniques that prevent and early-detect fraud within an organization. Combines rule-based detection, statistical analysis, machine learning, and LLMs to triage suspicious transactions and behaviors.
- 왜 중요한가Why it mattersACFE 2026 보고서에 따르면 조직 부정은 평균 12개월 후에야 발견된다. 자동화된 상시 탐지는 이 공백을 줄여 피해 규모를 크게 낮춘다.According to the ACFE 2026 Report to the Nations, occupational fraud goes undiscovered for an average of 12 months. Automated continuous detection closes this gap and significantly reduces losses.
- 실무 적용In practice지급·구매·비용 전체 데이터에 탐지 규칙을 적용하고, LLM이 이상 건을 요약하면 감사자가 우선순위 건부터 확인하는 Human-in-the-Loop 방식으로 운영한다.Applying detection rules across all payment, procurement, and expense data; LLM summarizes flagged items; auditors review in priority order — a Human-in-the-Loop workflow.
- AI 내부감사 전문성AI Internal Audit Expertise →
- 디지털 증거 무결성Digital Evidence Integrity
- 디지털 증거가 수집·이송·분석 전 과정에서 변조·삭제 없이 원본 그대로 유지되었음을 보증하는 원칙과 절차.The principles and procedures guaranteeing that digital evidence remains unaltered and undeleted — in its original state — throughout collection, transfer, and analysis.
- 왜 중요한가Why it matters법원·징계위원회는 무결성이 입증되지 않은 증거를 채택하지 않는다. 해시 불일치 하나로 수개월의 조사 결과가 무효가 될 수 있다.Courts and disciplinary bodies do not admit evidence whose integrity cannot be proven. A single hash mismatch can invalidate months of investigation.
- 실무 적용In practice포렌식 이미징 직후 SHA-256 해시를 기록하고, 분석 전후에 재검증해 원본과 동일함을 로그로 남긴다. 이 기록이 법정에서 증거능력의 근거가 된다.Recording SHA-256 hash values immediately after forensic imaging, re-verifying before and after analysis, and logging the match. These records are the foundation of admissibility in court.
- AI 디지털 포렌식 전문성AI Digital Forensics Expertise →
- Human-in-the-LoopHuman-in-the-Loop (HITL)
- AI가 자동으로 최종 결론을 내리지 않고 중요 판단 지점마다 사람의 검토·승인을 거치도록 설계하는 AI 운영 방식.An AI operating model designed so that the AI does not reach final conclusions automatically, but instead passes through human review and approval at every critical decision point.
- 왜 중요한가Why it mattersAI 탐지 결과를 징계나 법적 절차에 활용하려면 사람이 개입한 판단 기록이 필수다. HITL은 오탐을 줄이고 AI 결정의 책임 귀속을 명확히 한다.Using AI-detected findings in disciplinary or legal proceedings requires a record of human judgment. HITL reduces false positives and clarifies accountability for AI decisions.
- 실무 적용In practiceAI가 위험 신호를 선별하면 감사자가 원문 근거를 확인하고 '동의/기각/보류'를 기록하는 워크플로로 운영한다. AI는 보조 도구, 최종 판단은 사람이 한다.AI surfaces risk signals; auditors verify original evidence and record 'agree / dismiss / hold' decisions in a workflow. AI is the assistant — humans make the final call.
- AI 내부감사 전문성AI Internal Audit Expertise →