Scoring, assurance and conclusions
Gamut separates three questions:
- Applicability — does the legal requirement apply?
- Compliance answer — is it met?
- Assurance depth — how strongly is that answer demonstrated?
Combining these into one percentage would hide important differences.
Legal answers
Section titled “Legal answers”| Answer | Meaning |
|---|---|
| Compliant | The applicable obligation is implemented for the assessed system and role |
| Non-compliant | The obligation is absent, incomplete, ineffective or contradicted |
| N/A | The trigger does not apply and a governed non-applicability decision is complete |
| Unassessed | No conclusion has yet been made |
“Compliant” is not automatically “Assured.”
Assurance depth
Section titled “Assurance depth”| Depth | Label | Required interpretation |
|---|---|---|
| 3 | Assured | Implemented and current, accepted evidence, effective testing, no unresolved adverse finding |
| 2 | Supported/Partial | Relevant implementation evidence exists, but testing, coverage or closure is incomplete |
| 1 | Asserted | Claimed but weakly evidenced or untested |
| 0 | Gap | Absent, ineffective, contradicted or materially misleading |
Example
Section titled “Example”A deployer policy says human oversight is required, but no authority matrix, training record or operation test exists:
- Legal answer may be Compliant only if the assessor can support implementation.
- Assurance cannot exceed Asserted merely because a policy exists.
- If practice does not follow the policy, the answer is Non-compliant / Gap.
Category compliance
Section titled “Category compliance”Category compliance is coverage-inclusive:
compliant applicable atomic items───────────────────────────────── × 100all applicable atomic itemsUnassessed applicable items remain in the denominator. This prevents a high result from being created by answering only favourable items.
Approved N/A items are excluded from the applicable population. Unsupported N/A items are not.
Category assurance
Section titled “Category assurance”Assurance reflects the depth of the applicable atomic items. Always display it alongside:
- Assessment coverage.
- Evidence acceptance.
- Passing and failed tests.
- Open findings.
- Article 5 status.
- Current versus future legal status.
Do not interpret a category average as permission to ignore one failed statutory obligation.
N/A governance
Section titled “N/A governance”A valid N/A requires:
- Trigger-specific factual rationale of at least 80 characters.
- Exact legal basis.
- Evidence references.
- Decision owner.
- Independent approver.
- Approval date.
- Review or reassessment trigger.
Good:
Article 50(4) deepfake disclosure is not applicable because the deployed system only produces internal text summaries, cannot generate or manipulate image, audio or video content, and this is enforced by the approved model endpoint and content-type controls. Reassess if multimedia generation is enabled.
Weak:
Not relevant to our use case.
Hard stops and assurance gates
Section titled “Hard stops and assurance gates”Article 5
Section titled “Article 5”A confirmed prohibited practice, or unresolved potential prohibited practice, blocks confirmation. It cannot be averaged away.
Confirmation assurance
Section titled “Confirmation assurance”For confirmation, an applicable in-force atomic item must be:
- Compliant at depth 3; or
- Supported by an approved N/A decision.
Depth 3 additionally requires:
- Accepted/reviewed evidence linked to the item and system.
- Passing scoped testing.
- No failed test.
- No unresolved adverse finding.
If any condition is missing, Gamut returns an incomplete-assurance outcome rather than an optimistic confirmation.
Conclusion vocabulary
Section titled “Conclusion vocabulary”AI Assist and human reporting may use these evidence-aware positions:
| Position | Meaning |
|---|---|
assured_compliant | Applicable obligation is demonstrated at the full assurance gate |
supported_partial | Material support exists but assurance is incomplete |
asserted_unverified | Claim exists without sufficient verification |
gap | Requirement is absent, ineffective or contradicted |
not_applicable_pending_approval | N/A appears plausible but governance approval is incomplete |
future_readiness | Work relates to a provision not yet used as current binding law |
insufficient_information | Facts do not support a responsible determination |
potential_prohibited_practice | Article 5 concern requires immediate human/legal resolution |
These are not certification labels.
Current-law versus future-readiness conclusion
Section titled “Current-law versus future-readiness conclusion”The conclusion should have two explicit parts:
Current-law conclusion
Section titled “Current-law conclusion”Uses provisions in force as of the snapshot and states:
- Scope and roles.
- Applicable routes.
- Assured compliant items.
- Current gaps.
- Limitations and residual risk.
- Article 5 status.
Future-readiness conclusion
Section titled “Future-readiness conclusion”States:
- Applicable future obligations.
- Expected application dates.
- Implementation and evidence gaps.
- Planned completion.
- Any dependence on proposed but unadopted changes.
Never call a future item a current breach, or a proposed date binding.
Confidence
Section titled “Confidence”| Confidence | Typical basis |
|---|---|
| Low | Material scope, role, classification, evidence or legal uncertainty remains |
| Medium | Main routes and implementation are supported, but some operating periods or edge cases remain incomplete |
| High | Current facts, roles, evidence, testing and adverse signals have been independently challenged |
Confidence does not change the legal route. Low confidence normally calls for more conservative governance.
Residual risk
Section titled “Residual risk”Record:
- Open non-compliance.
- Limitations in evidence or testing.
- Reliance on suppliers or representatives.
- Affected persons and consequence.
- Interim safeguards.
- Deployment restrictions.
- Risk owner and acceptance authority.
- Expiry conditions.
Risk acceptance does not turn a legal gap into compliance.
Safe explanations
Section titled “Safe explanations”Prefer:
“As of 16 July 2026, the named system has no identified Article 5 hard stop. The applicable in-force items listed in the report meet Gamut’s depth-3 assurance gate, subject to the stated scope, legal assumptions, evidence period and reassessment triggers.”
Avoid:
- “EU certified.”
- “100% legally compliant forever.”
- “Low risk, so the Act does not apply.”
- “The vendor is compliant, therefore we are compliant.”
- “All future obligations are already legally in force.”
Why a percentage is not the conclusion
Section titled “Why a percentage is not the conclusion”A percentage cannot by itself reveal:
- A prohibited practice.
- One failed high-risk obligation.
- A false N/A.
- A failed test.
- An unresolved serious incident.
- A future obligation included as current.
- A provider duty reported against the wrong entity.
Use scores for navigation and progress; use the complete record for the conclusion.