Key ceremony
The scripted, witnessed procedure in which a CA creates or retires a root key inside an HSM, with split knowledge, dual control and an audited record.
The formal, scripted and witnessed procedure in which a certificate authority generates, backs up or retires its most important keys. Key generation itself is a command; the ceremony is everything around it that makes the result trustworthy afterwards.
A ceremony has a script written in advance, named role holders who are checked in, an HSM as the place where the key is created and never leaves, split knowledge and dual control over the backup shares, a witness who is independent of the operators, and a signed record of what happened - often with video. Auditors do not verify the key, they verify that record: the CP and CPS promise how the ceremony runs, and a conformity assessment body checks that the promise was kept.
The reason for the theatre is that a root key cannot be repaired. Everything a PKI issues hangs from it, so the moment of creation is the one moment where a single person with too much access could compromise every certificate that follows - quietly, and for years. A ceremony makes that impossible to do alone and impossible to do unnoticed.