Reporting and governance
ACRS reporting should answer:
How much capability exposure does this system carry, why is it routed at this assurance depth, what uncertainty or weakness remains, and what governance action follows?
Higher is worse
Section titled “Higher is worse”ACRS is a risk-exposure method:
- Low exposure is lower.
- High exposure is higher.
- A higher number is not a better maturity result.
Do not describe ACRS as:
- Conformance percentage.
- Control-effectiveness percentage.
- Readiness score.
- Maturity level.
- Certification result.
System report
Section titled “System report”The system report derives ACRS from the selected intake and should include:
- System name and identifier.
- Four dimension levels.
- Dimension provenance and rationales.
- Vector.
- Raw product.
- Product tier.
- Severity-floor reasons.
- Authoritative routed tier.
- Confirmation state.
- System-scoped evidence, tests and findings.
- Assessment owner.
- Confidence.
- Residual risk.
- Review date.
- Assessor conclusion.
- Reassessment triggers.
- Current-basis AI analysis where available.
The report must not substitute generic workspace ACRS values for the selected system’s intake.
Exposure presentation
Section titled “Exposure presentation”ACRS reports use the three-level exposure scale:
| Exposure | Meaning |
|---|---|
| Low / 1 of 3 | Narrow or contained capability exposure; baseline assurance still applies. |
| Medium / 2 of 3 | Material capability exposure requiring enhanced treatment and review. |
| High / 3 of 3 | Comprehensive assurance, stronger evidence, testing and accountable governance required. |
There is no ACRS Critical band. If the organisation uses Critical elsewhere, label it as a separate governance classification.
Product and route explanation
Section titled “Product and route explanation”Where a floor changes the tier, show both values:
Raw product 36; product tier Medium; authoritative route High. The route is raised because Harm is High and Action Autonomy and Access Scope are both at least Medium.
Do not report only “36 Medium” if the authoritative route is High.
Dimension-level reporting
Section titled “Dimension-level reporting”For each dimension, report:
- Selected level.
- Inferred or assessor provenance.
- Rationale.
- Evidence position.
- Test position.
- Open findings.
- Decision relevance.
High exposure or open findings should receive priority attention. A Low dimension with weak evidence may also require action because the claimed boundary is not demonstrated.
Structured assessor conclusion
Section titled “Structured assessor conclusion”The conclusion should integrate capability and assurance without confusing them.
Assessment owner
Section titled “Assessment owner”Name the accountable AI system owner or risk owner responsible for the conclusion. “Security team” or “to be assigned” is not sufficient for final sign-off.
Confidence
Section titled “Confidence”| Confidence | Typical basis |
|---|---|
| Low | Material facts, evidence or tests are missing; architecture is changing; significant uncertainty remains. |
| Medium | The main paths are understood and evidenced, but some boundaries or operating periods remain untested. |
| High | Current system facts, effective permissions, action paths, fallback and harm scenarios are well evidenced and independently challenged where appropriate. |
Confidence does not lower the routed tier. Low confidence usually requires more conservative governance.
Residual risk
Section titled “Residual risk”Residual risk should explain:
- Which controls reduce probability or impact.
- Which limitations remain.
- Which findings are open.
- Which assumptions the decision depends on.
- Whether exposure is within risk appetite.
- Which conditions restrict deployment or expansion.
Review due
Section titled “Review due”Set the date according to:
- Routed tier.
- Change frequency.
- Evidence volatility.
- Incident history.
- Supplier change.
- Regulatory or rights impact.
- Open remediation.
High and rapidly changing systems generally need shorter review intervals.
Reassessment triggers
Section titled “Reassessment triggers”Record observable triggers, for example:
- “Any addition of a production-write tool.”
- “Change from human-in-the-loop to human-on-the-loop.”
- “Processing of special-category personal data.”
- “Deployment to a new country or customer population.”
- “Fallback capacity falls below 80% of peak demand.”
- “Any approval-bypass, cross-tenant or harmful-output incident.”
Governance decisions informed by ACRS
Section titled “Governance decisions informed by ACRS”ACRS can inform:
- GTSAF depth and control priority.
- MAESTRO threat-modelling depth.
- Independent review requirements.
- Evidence and test rigour.
- Approval authority.
- Gateway policy, ceilings and runtime enforcement.
- ATF autonomy limits.
- Monitoring cadence.
- Deployment restrictions.
- Remediation priority.
- Executive or board visibility.
It should not be the only input to deployment or risk acceptance. Legal classification, control effectiveness, incidents, supplier risk, threat modelling and organisational risk appetite also matter.
System versus workspace reporting
Section titled “System versus workspace reporting”System report
Section titled “System report”Answers:
What is the capability exposure of this named system, and what assurance depth and action does it require?
It uses the selected system’s record only.
Workspace roll-up
Section titled “Workspace roll-up”Answers:
What is the distribution and worst-case capability exposure across the AI estate?
It can summarise:
- Systems assessed.
- Low, Medium and High distribution.
- Worst routed tier.
- Systems awaiting confirmation.
- High-risk agents.
- Missing owners.
- Evidence or review gaps.
The roll-up does not prove that every system has the same route or controls.
Reconciliation with other labels
Section titled “Reconciliation with other labels”| Label | What it describes |
|---|---|
| ACRS Low / Medium / High | Capability exposure and required assurance depth. |
| Intake governance tier | Organisational classification based on broader governance factors. |
| GTSAF Critical / High / Medium / Low | Consequence of failure of an individual control. |
| GTSAF Assured / Supported / Partial / Gap | Current control-assurance result. |
| MAESTRO Low to Critical | Threat severity from likelihood × impact. |
| ATF level | Permitted or target agent autonomy and trust state. |
Where two labels differ, explain the reason rather than forcing them to match. A system can have High ACRS exposure and a strong GTSAF assurance result: the first says the capability is consequential; the second says controls are well evidenced.
Board-safe explanation
Section titled “Board-safe explanation”ACRS measures how consequential an AI system’s capability is, not how compliant it is. The four dimensions show operational dependency, action autonomy, effective access and credible harm. The raw product shows combined exposure, while conservative floors prevent severe or dangerous combinations from being routed too low. The result determines assurance depth and governance attention; control effectiveness and residual-risk acceptance are assessed separately.
Report review checklist
Section titled “Report review checklist”- Correct selected system.
- Four dimensions use the 1–3 exposure scale.
- Product is not presented as a maturity percentage.
- Product tier and routed tier are both visible where they differ.
- Every severity-floor reason is explained.
- High means higher risk, not better performance.
- Evidence, tests and findings belong to the selected system.
- Current-basis AI analysis only.
- Owner, confidence, residual risk, review date and triggers present.
- No claim of certification or automatic compliance.