Skip to content

Reporting and governance

ACRS reporting should answer:

How much capability exposure does this system carry, why is it routed at this assurance depth, what uncertainty or weakness remains, and what governance action follows?

ACRS is a risk-exposure method:

  • Low exposure is lower.
  • High exposure is higher.
  • A higher number is not a better maturity result.

Do not describe ACRS as:

  • Conformance percentage.
  • Control-effectiveness percentage.
  • Readiness score.
  • Maturity level.
  • Certification result.

The system report derives ACRS from the selected intake and should include:

  • System name and identifier.
  • Four dimension levels.
  • Dimension provenance and rationales.
  • Vector.
  • Raw product.
  • Product tier.
  • Severity-floor reasons.
  • Authoritative routed tier.
  • Confirmation state.
  • System-scoped evidence, tests and findings.
  • Assessment owner.
  • Confidence.
  • Residual risk.
  • Review date.
  • Assessor conclusion.
  • Reassessment triggers.
  • Current-basis AI analysis where available.

The report must not substitute generic workspace ACRS values for the selected system’s intake.

ACRS reports use the three-level exposure scale:

ExposureMeaning
Low / 1 of 3Narrow or contained capability exposure; baseline assurance still applies.
Medium / 2 of 3Material capability exposure requiring enhanced treatment and review.
High / 3 of 3Comprehensive assurance, stronger evidence, testing and accountable governance required.

There is no ACRS Critical band. If the organisation uses Critical elsewhere, label it as a separate governance classification.

Where a floor changes the tier, show both values:

Raw product 36; product tier Medium; authoritative route High. The route is raised because Harm is High and Action Autonomy and Access Scope are both at least Medium.

Do not report only “36 Medium” if the authoritative route is High.

For each dimension, report:

  • Selected level.
  • Inferred or assessor provenance.
  • Rationale.
  • Evidence position.
  • Test position.
  • Open findings.
  • Decision relevance.

High exposure or open findings should receive priority attention. A Low dimension with weak evidence may also require action because the claimed boundary is not demonstrated.

The conclusion should integrate capability and assurance without confusing them.

Name the accountable AI system owner or risk owner responsible for the conclusion. “Security team” or “to be assigned” is not sufficient for final sign-off.

ConfidenceTypical basis
LowMaterial facts, evidence or tests are missing; architecture is changing; significant uncertainty remains.
MediumThe main paths are understood and evidenced, but some boundaries or operating periods remain untested.
HighCurrent system facts, effective permissions, action paths, fallback and harm scenarios are well evidenced and independently challenged where appropriate.

Confidence does not lower the routed tier. Low confidence usually requires more conservative governance.

Residual risk should explain:

  • Which controls reduce probability or impact.
  • Which limitations remain.
  • Which findings are open.
  • Which assumptions the decision depends on.
  • Whether exposure is within risk appetite.
  • Which conditions restrict deployment or expansion.

Set the date according to:

  • Routed tier.
  • Change frequency.
  • Evidence volatility.
  • Incident history.
  • Supplier change.
  • Regulatory or rights impact.
  • Open remediation.

High and rapidly changing systems generally need shorter review intervals.

Record observable triggers, for example:

  • “Any addition of a production-write tool.”
  • “Change from human-in-the-loop to human-on-the-loop.”
  • “Processing of special-category personal data.”
  • “Deployment to a new country or customer population.”
  • “Fallback capacity falls below 80% of peak demand.”
  • “Any approval-bypass, cross-tenant or harmful-output incident.”

ACRS can inform:

  • GTSAF depth and control priority.
  • MAESTRO threat-modelling depth.
  • Independent review requirements.
  • Evidence and test rigour.
  • Approval authority.
  • Gateway policy, ceilings and runtime enforcement.
  • ATF autonomy limits.
  • Monitoring cadence.
  • Deployment restrictions.
  • Remediation priority.
  • Executive or board visibility.

It should not be the only input to deployment or risk acceptance. Legal classification, control effectiveness, incidents, supplier risk, threat modelling and organisational risk appetite also matter.

Answers:

What is the capability exposure of this named system, and what assurance depth and action does it require?

It uses the selected system’s record only.

Answers:

What is the distribution and worst-case capability exposure across the AI estate?

It can summarise:

  • Systems assessed.
  • Low, Medium and High distribution.
  • Worst routed tier.
  • Systems awaiting confirmation.
  • High-risk agents.
  • Missing owners.
  • Evidence or review gaps.

The roll-up does not prove that every system has the same route or controls.

LabelWhat it describes
ACRS Low / Medium / HighCapability exposure and required assurance depth.
Intake governance tierOrganisational classification based on broader governance factors.
GTSAF Critical / High / Medium / LowConsequence of failure of an individual control.
GTSAF Assured / Supported / Partial / GapCurrent control-assurance result.
MAESTRO Low to CriticalThreat severity from likelihood × impact.
ATF levelPermitted or target agent autonomy and trust state.

Where two labels differ, explain the reason rather than forcing them to match. A system can have High ACRS exposure and a strong GTSAF assurance result: the first says the capability is consequential; the second says controls are well evidenced.

ACRS measures how consequential an AI system’s capability is, not how compliant it is. The four dimensions show operational dependency, action autonomy, effective access and credible harm. The raw product shows combined exposure, while conservative floors prevent severe or dangerous combinations from being routed too low. The result determines assurance depth and governance attention; control effectiveness and residual-risk acceptance are assessed separately.

  • Correct selected system.
  • Four dimensions use the 1–3 exposure scale.
  • Product is not presented as a maturity percentage.
  • Product tier and routed tier are both visible where they differ.
  • Every severity-floor reason is explained.
  • High means higher risk, not better performance.
  • Evidence, tests and findings belong to the selected system.
  • Current-basis AI analysis only.
  • Owner, confidence, residual risk, review date and triggers present.
  • No claim of certification or automatic compliance.