Method, scoring and terminology
ACRS classifies capability exposure, not control maturity. A higher result means the selected AI system requires deeper assurance, stronger evidence, tighter testing and more accountable oversight.
Inherent exposure versus control effectiveness
Section titled “Inherent exposure versus control effectiveness”The assessor should score the capability as it actually operates in the assessed context:
- The business dependency that exists.
- The actions that can occur.
- The effective access available.
- The credible harm that can result.
Do not lower a dimension merely because a control is planned. A control may reduce the probability, blast radius or residual risk, but the ACRS dimension still needs to describe the deployed capability accurately.
Examples:
- An agent with production write permission remains High Access even if logs are enabled.
- A payment agent remains High Action Autonomy if it can release payments before approval, even if a human reviews a daily report.
- A clinical workflow can remain High Harm even when the model is accurate, because Harm describes consequence severity rather than model-error probability.
- A tested manual process can reduce Dependency where it genuinely sustains safe operation at realistic demand.
The four-level vector
Section titled “The four-level vector”Each of the four dimensions receives an integer level:
| Level | Label | Meaning |
|---|---|---|
| 1 | Low | Narrow, contained, readily reversible or genuinely optional exposure. |
| 2 | Medium | Material but bounded exposure with practical limits, intervention or recovery. |
| 3 | High | Critical, privileged, consequential, severe, broad or hard-to-reverse exposure. |
The displayed vector uses stable dimension IDs:
dep:<1-3>, act:<1-3>, access:<1-3>, harm:<1-3>Example:
dep:2, act:3, access:2, harm:3Product formula
Section titled “Product formula”The raw product is:
Operational Dependency × Action Autonomy × Access Scope × Harm PotentialThe minimum is 1 × 1 × 1 × 1 = 1. The maximum is 3 × 3 × 3 × 3 = 81.
| Raw product | Product tier | Normal assurance direction |
|---|---|---|
| 1–8 | Low | Baseline GTSAF controls and proportionate review. |
| 9–36 | Medium | Enhanced controls, validation, monitoring and oversight. |
| 37–81 | High | Comprehensive relevant controls, independent challenge and continuous monitoring. |
Because every input is an integer, only discrete products occur. The product should therefore be reported as a whole number, not as a percentage, maturity score or compliance score.
Product tier versus routed tier
Section titled “Product tier versus routed tier”The product tier is the band produced by the multiplication alone.
The routed tier is the authoritative assurance route after severity floors are applied.
The routed tier can equal the product tier or be higher. It cannot be lowered below the product tier. This distinction matters in reports and explanations:
Raw product 36, product tier Medium, routed tier High because severe harm is combined with consequential autonomy and material access.
Severity-floor rules
Section titled “Severity-floor rules”Gamut applies the following conservative floors:
| Condition | Minimum routed tier | Why |
|---|---|---|
| Harm = 3 | Medium | Severe or potentially irreversible harm cannot route Low. |
| Action = 3 and Access = 3 | High | High autonomy with broad or privileged reach needs comprehensive assurance. |
| Harm = 3 and Action ≥ 2 | High | Severe harm plus material or high autonomy cannot remain Medium. |
| Harm = 3 and Access ≥ 2 | High | Severe harm plus material or broad access cannot remain Medium. |
| Action = 3 and Access ≥ 2 | High | Consequential pre-approval action with material access needs a High route. |
| Intake explicitly identifies high risk | High | An accepted structured high-risk fact cannot be averaged down. |
| Automated consequential decisions plus special-category data or a high-impact domain | High | Rights-affecting or similarly consequential automated decisions need comprehensive assurance. |
High-impact domains include contexts such as employment, recruitment, credit, insurance, health, medical care, education, benefits, legal services, surveillance, children and public administration. The exact result is determined by Gamut from the recorded intake.
Multiple floor reasons may be recorded. They explain the route; they are not additional points.
Why multiplication is used
Section titled “Why multiplication is used”Multiplication makes combinations matter. Four Low values remain Low, while several Medium or High values increase the score rapidly.
However, multiplication alone can still hide a severe asymmetric condition. For example:
1 × 1 × 1 × 3 = 3The product is Low, but Harm is High. The harm floor raises the route to at least Medium. This is why the severity-floor layer is necessary.
Automatic system-generated scoring
Section titled “Automatic system-generated scoring”When a system intake is selected, Gamut derives a suggested level for every dimension. Structured fields are the primary basis; bounded contextual text is used as a secondary signal.
Typical inputs include:
| Dimension | Important inference signals |
|---|---|
| Dependency | Critical or production workflow, customer service, payments, claims, clinical or security operations, public exposure and operational lifecycle. |
| Action | Recorded autonomy level, human-oversight type, automated-decision flag and descriptions of execution, writing, approval, transactions, tools or workflow automation. |
| Access | Personal or special-category data, external retrieval, APIs, databases, privileged or production access, financial, identity, biometric, health or customer data. |
| Harm | High-risk and automated-decision flags, public or community impact and high-impact domains affecting safety, rights, livelihood or essential services. |
Automatic scoring remains active if the assessor resets their overrides. It is not deleted merely because an assessment has not been confirmed.
Assessor overrides
Section titled “Assessor overrides”For each dimension, the assessor may:
- Accept the inferred level by leaving the explicit level unset.
- Select an explicit Low, Medium or High level.
- Record a rationale explaining the system facts, evidence and judgement.
An explicit level takes precedence in the vector. The saved record preserves whether the active value came from inference or the assessor.
Lower-than-inferred scores
Section titled “Lower-than-inferred scores”An explicit score below the inferred suggestion requires a rationale before confirmation. The rationale should explain:
- Which inference input overstates the effective exposure.
- Which boundary is technically enforced.
- Which evidence and test demonstrate that boundary.
- Why the lower anchor is met in the deployed environment.
- Which change would invalidate that judgement.
“The team considers it low risk” is not sufficient.
Higher-than-inferred scores
Section titled “Higher-than-inferred scores”The assessor may raise a score when the intake understates the deployment or when evidence reveals a broader capability. A rationale is still good practice because it improves traceability and helps future reassessment.
Contradiction checks
Section titled “Contradiction checks”Gamut identifies inconsistent facts that must be reviewed. Examples include:
- Special-category data marked Yes while personal data is No.
- External retrieval recorded in one field and denied in another.
- Assistive autonomy combined with automated consequential decisions.
- High Action Autonomy combined with approval before every consequential action.
- Low Access despite sensitive or external access.
- Low Harm while the intake explicitly identifies high risk.
A contradiction does not automatically decide which field is wrong. It prevents confident confirmation until the assessor resolves the record.
Provenance
Section titled “Provenance”Each dimension has one of two active provenance states:
| Provenance | Meaning |
|---|---|
| Inferred | The automatically generated level is active because no explicit assessor level is saved. |
| Assessor | An explicit assessor level is active and takes precedence. |
Provenance is not evidence strength. An assessor-entered score can still be weakly supported, and an inferred score can still be directionally correct.
Assessment status
Section titled “Assessment status”The user-facing state is derived from the validated assessment:
| Status | Meaning |
|---|---|
| Pending confirmation | The vector is usable for routing, but an authorised assessor has not signed it off. |
| Contradiction review required | Conflicting facts or an unjustified lower-than-inferred level prevent confirmation. |
| Confirmed by assessor | An authorised human confirmed the current assessment basis. |
The score is always computable because inference supplies any unset dimension. Confirmation is an optional sign-off, not a prerequisite for seeing the vector.
Assessment-basis change and stale confirmation
Section titled “Assessment-basis change and stale confirmation”Gamut binds confirmation to the material fields that drive the ACRS result, including dimension overrides and rationales, autonomy, oversight, data, retrieval, impact and deployment.
If a material basis field changes:
- The assessment basis changes.
- Prior confirmation is invalidated.
- The route returns to a pending state.
- Previously generated AI analysis is no longer current for the new basis.
- The assessor must review the changed facts and reconfirm where appropriate.
This prevents a signed Low or Medium result from surviving a later increase in autonomy, access or harm.
Confirmation
Section titled “Confirmation”Confirmation records an audited human sign-off for the current basis. It is allowed only when:
- Contradictions are resolved.
- Every lower-than-inferred override has a rationale.
- The selected system scope is valid.
- The user has the required role and entitlement.
Confirmation does not:
- Accept evidence automatically.
- Approve deployment.
- Accept residual risk.
- Prove GTSAF conformance.
- Prevent future reassessment.
Agent-level ACRS
Section titled “Agent-level ACRS”Agentic CISO can also record ACRS for an individual agent. Gamut infers agent levels from capabilities such as tool calling, memory, delegation, external action, code modification, spending authority and access to customer or confidential data.
Gamut recomputes the agent product and route. If a manually submitted agent level differs from the system suggestion, an override rationale is required. Agent-level scoring and system-intake ACRS use the same four dimensions and route logic, but they remain separate records with different scope.
Common scoring errors
Section titled “Common scoring errors”- Treating ACRS as a maturity score where higher is better.
- Averaging the four dimensions.
- Reporting the product as a percentage.
- Ignoring severity floors.
- Lowering Harm because probability is low.
- Lowering Access because the intended workflow is narrow while permissions are broad.
- Calling post-action notification “human approval”.
- Treating a supplier SLA as proof of a tested fallback.
- Copying one system’s vector to another.
- Treating an assessor rationale or AI recommendation as accepted evidence.