Skip to content

GTSAF

GTSAF, the Gamut Trust, Security and Assurance Framework, is Gamut’s native AI assurance baseline. It is the deepest framework in the platform: 358 controls across 17 domains, with a workbook-driven scoring workflow. Where the regulatory frameworks tell you what you must achieve, GTSAF gives you a comprehensive, assessable control set to demonstrate how.

PropertyValue
Controls358
Domains17 (lettered A to Q)
Gate controls71
Critical controls70
Crosswalk targetsEU AI Act, ISO/IEC 42001, ISO/IEC 42005, NIST AI RMF
Control identifierGTSAF-<domain>-<nn>, for example GTSAF-A-01

Gate controls are the controls that gate progression: weaknesses there hold back a system’s assurance posture until addressed. Critical controls carry the highest risk weighting. Every control has its own objective, risk statement, implementation guidance, evidence expectations and test procedures.

GTSAF organises its controls into 17 domains, A through Q. Each domain groups related controls so that assessment proceeds in a structured, reviewable way.

DomainNameControls
AGovernance, Strategy and Accountability11
BLegal, Regulatory and Contractual Compliance11
CAI Use Case Intake, Approval and Risk Tiering11
DData Governance, Lineage and Provenance11
EData Security and Privacy Engineering24
FSecure Data Acquisition and Annotation11
GModel Development, Validation and Robustness11
HPrompt, Context and Retrieval Security25
IInference, API and Runtime Security25
JIdentity, Access and NHI Security26
KAgentic AI and Autonomous Action Governance29
LThird-Party, Model and Software Supply Chain Assurance25
MMonitoring, Detection and AI Security Operations35
NHuman Oversight, Transparency and Impact Management15
OResilience, Continuity and Recovery36
PAuditability, Evidence and Assurance11
QInfrastructure, Platform and Environment Security41

The domains span the full surface of AI assurance: governance and legal at the top (A, B, C), data and model integrity through the middle (D to G), the AI-specific attack surface (H, I, J), agentic and supply-chain risk (K, L), security operations and oversight (M, N), and resilience and infrastructure at the base (O, P, Q). Notice the depth on agentic action (K, 29 controls), identity and non-human identity (J, 26 controls), and infrastructure (Q, 41 controls), reflecting where modern AI risk concentrates.

  1. Register and run intake on the AI system.
  2. Start a GTSAF assessment from the system record.
  3. Work through the 17 domains, scoring each control with rationale.
  4. Attach or request evidence and raise findings where there are gaps. Gate and critical controls are the ones to clear first.
  5. Use reporting to produce assurance and board outputs.

ACRS can route the right GTSAF control depth to a system based on its capability risk, so lower-risk systems are governed proportionately while higher-risk systems get the comprehensive set.

Every one of the 358 GTSAF controls carries an audited crosswalk to the EU AI Act, ISO/IEC 42001, ISO/IEC 42005 and NIST AI RMF. This means a single body of GTSAF evidence supports assessments against those regimes, and a reviewer can trace any GTSAF control to the external obligations it speaks to.

The table below shows representative anchors for each domain (illustrated by the domain’s lead control). Per-control mappings are more specific and are available on each control inside the product.

DomainEU AI ActISO/IEC 42001NIST AI RMF
A GovernanceArts 9, 14, 17, 265.1, 5.2, 5.3GOVERN, MAP, MEASURE, MANAGE
B Legal & complianceArts 2, 5, 6, 164.1, 4.2, 4.3GOVERN, MAP, MANAGE
C Intake & risk tieringArts 6, 9, 11, 144.1, 6.1.1, 6.1.2GOVERN, MAP, MEASURE, MANAGE
D Data governanceArts 10, 11, 12, 137.5, 8.1MAP, MEASURE
E Data security & privacyArts 9, 10, 15, 176.1.2, 6.1.3, 8.1GOVERN, MAP, MEASURE, MANAGE
F Data acquisitionArts 9, 10, 15, 176.1.2, 6.1.3, 6.1.4GOVERN, MAP, MEASURE
G Model developmentArts 9, 10, 11, 126.2, 7.2, 8.1GOVERN, MAP, MEASURE, MANAGE
H Prompt & retrievalArts 9, 12, 13, 155.2, 5.3, 8.1MAP, MEASURE, MANAGE
I Inference & runtimeArts 12, 14, 15, 178.1, 9.1, 10.2GOVERN, MAP, MEASURE, MANAGE
J Identity & NHIArts 13, 14, 15, 265.3, 7.2, 7.3GOVERN, MAP, MEASURE, MANAGE
K Agentic actionArts 9, 13, 14, 156.1.2, 6.1.3, 6.1.4GOVERN, MAP, MEASURE, MANAGE
L Supply chainArts 10, 12, 15, 165.3, 7.4, 7.5MAP, MEASURE, MANAGE
M Monitoring & SecOpsArts 12, 15, 177.5, 8.1, 9.1MEASURE, MANAGE
N Human oversightArts 9, 13, 14, 266.1.2, 6.1.4, 7.4GOVERN, MAP, MEASURE, MANAGE
O Resilience & recoveryArts 9, 12, 15, 178.1, 8.3, 9.1GOVERN, MAP, MEASURE, MANAGE
P Auditability & evidenceArts 11, 12, 13, 177.5, 8.1, 9.1GOVERN, MAP, MEASURE
Q InfrastructureArts 12, 13, 15, 175.3, 7.1, 8.1MAP, MEASURE, MANAGE