---
title: "The common language between business, IT and risk: the real bottleneck"
url: https://zerofive.ai/en/blog/insights/common-language-business-it-risk
canonical: https://zerofive.ai/en/blog/insights/common-language-business-it-risk
language: en
published: 2026-06-04
updated: 2026-09-18
author: "ZeroFive.AI"
tags: business IT risk alignment, enterprise AI culture, AI glossary, AI project communication, AI Culture
abstract: "AI projects slow down where business, IT and risk use the same words with different meanings: the typical misunderstandings, their costs and how to build a glossary that works."
---

# The common language between business, IT and risk: the real bottleneck

Try listening to an AI steering meeting with a linguist's ear instead of a manager's, and you will hear three languages exchanging the same words. The business says "the model works" and means the process improves; IT says "the model works" and means the technical metrics hold; risk hears "works" and asks against which approved perimeter, receiving stares in return. Nobody lies, nobody is wrong, yet the meeting produces an apparent agreement that will dissolve at the first verification, because the three functions have signed three different sentences believing them to be one.

In our assessments this linguistic friction appears with such regularity that we have stopped treating it as a communication detail: it is an operational bottleneck, with measurable costs, and in the rating's Readiness dimension it weighs inside the culture item more than transformation plans give it credit for.

## The words that divide the most

The recurring misunderstandings deserve to be named, because recognising them is half the remedy. "Validated" is the champion: for IT it means the technical tests pass, for the business it means the process owner has seen acceptable results, for risk it means a formal evaluation with preserved evidence exists, and a system can be validated in two languages out of three while travelling towards a blockage. "Data ready" follows closely, with the business meaning available in a report, IT meaning accessible via pipeline, risk meaning usable for that purpose with a written legal basis.

"Risk" deserves its own chapter, because the business uses it for the probability the project fails, the risk function for the exposure the project creates even by succeeding, and the conversation between the two meanings is the one deciding whether compliance enters at design time or arrives as a final surprise. Even "pilot" divides: an experiment with stopping conditions for some, a first release to be defended for others, and we have watched the difference between the two readings consume entire quarters.

The cost of this Babel presents itself in familiar forms: meetings that repeat because the previous agreement was not an agreement, requirements rewritten mid-development, the classic scene of the project stopped by risk "at the last moment", where the last moment is simply the first one in which somebody translated.

## The glossary that works (and the one that does not)

The obvious remedy, the corporate glossary, exists in many organisations and almost never works, because it is born as a document and documents do not change speech. The glossary that works has three different properties. It is short, twenty entries chosen among those that have already produced misunderstandings in-house, not two hundred imported from a framework. It is operational, meaning each entry defines the word through the evidence that proves it: "validated" gets no philosophical definition, it gets a list of what must exist for the word to be usable. And above all it is embedded in the artefacts the three functions fill in together, because a language is learned by using it where it counts.

This is where the instruments we have written about show their second trade. The AI Canvas is, among other things, a translator: the six boxes force business, IT and risk to write on the same page with words everyone endorses, and the drafting session is the place where the three meanings of "validated" meet before they cost anything. The go/no-go criteria do the same work on thresholds, and the systems register on classifications. The common language, in other words, is built less through courses and more through shared forms.

## Where to start

The sequence we see working starts from an inventory of the misunderstandings already paid for: half a day with the three functions reconstructing the latest frictions, extracting the words that generated them, produces the raw glossary and, with it, the consensus that one is needed. Then come the twenty operational definitions, the grafting into the artefacts, and a light maintenance ritual, because new words will arrive with new technologies.

It is the heart of the work that in our chain is called AI Culture, the gear change separating organisations where functions watch each other from those where they understand each other: calendly.com/fabiolalli/zerofive, or hello@zerofive.ai. The experiment to run at your very next meeting, meanwhile, costs thirty seconds and a little face: when somebody says "validated", ask what would need to exist, concretely, for the word to be true. The three answers you receive are the photograph of your bottleneck.
