Skip to content

GTSAF

GTSAF, the Gamut Trust, Security and Assurance Framework, is Gamut’s flagship AI assurance framework. It turns AI governance principles into an assessable, evidence-led control system covering the entire AI lifecycle: governance, data, models, prompts, runtime, identity, agents, suppliers, monitoring, human oversight, resilience, auditability and infrastructure.

GTSAF contains 358 individually authored controls across 17 domains, supported by:

  • A unique objective and risk statement for every control.
  • Detailed implementation guidance.
  • Control-specific evidence expectations.
  • Control-specific test procedures.
  • Criticality and gate metadata.
  • System-specific applicability rules.
  • Shared-responsibility ownership.
  • Structured assessor conclusions and residual-risk records.
  • Audited traceability mappings to the EU AI Act, ISO/IEC 42001, ISO/IEC 42005 and NIST AI RMF.
  • Validated, system-scoped AI Assist.

Use this documentation suite according to what you need to explain or do:

If you need to…Read
Explain badges such as High, Gate, Enhanced, Triggered, Gap and AssuredConcepts, labels and terminology
Understand what each of the 17 domains covers and how to assess itDomains and control library
Explain why different systems receive different controls and assurance depthSystem scope, applicability and assurance depth
Complete a GTSAF assessment from beginning to sign-offAssessment workflow
Defend how the assurance figures are calculatedScoring and assurance model
Know what evidence to collect and how to test a controlEvidence, testing and findings
Explain what AI Assist reads, produces and is prohibited from doingAI Assist explainability
Produce or explain system and workspace reportsReporting and governance decisions
Walk through a realistic assessment exampleWorked example
Look up abbreviations, statuses and formulas quicklyReference and glossary
PropertyCurrent GTSAF library
VersionGTSAF v1.3
Controls358
Domains17, lettered A to Q
Gate controls71
Critical controls70
Criticality distribution70 Critical, 241 High, 43 Medium, 4 Low
Assessment levelPer AI system, with workspace roll-up
Control identifierGTSAF-<domain>-<nn>, for example GTSAF-A-01
Assessment answersYes, No or governed N/A
Shared-responsibility rolesMP, OSP, AP, AIC, CSP, Shared or ND
CrosswalksEU AI Act, ISO/IEC 42001, ISO/IEC 42005, NIST AI RMF

GTSAF works as a connected assurance process rather than a static checklist:

  1. Register the AI system. Record what it does, who owns it, where it operates, what data it handles, which suppliers it uses and how much autonomy or impact it has.
  2. Complete intake and risk classification. The intake establishes the system context. ACRS captures capability exposure through dependency, action autonomy, access scope and harm potential.
  3. Determine applicability and depth. Complete system facts determine which conditional controls apply. ACRS and the governance weighting profile set proportionate Baseline, Triggered or Enhanced assurance depth without rewriting factual applicability.
  4. Assess the controls. The assessor records Yes, No or N/A; assigns shared-responsibility ownership; documents implementation; and captures customer responsibilities.
  5. Collect and review evidence. Narrative statements explain the control but do not count as verified evidence. Evidence must be linked, reviewed and quality-rated.
  6. Test operating effectiveness. A test determines whether the control actually works under defined conditions. Failed tests and exceptions constrain assurance.
  7. Raise findings and remediation. Gaps, gate failures, rejected evidence and failed tests become actionable findings, risk decisions or remediation work.
  8. Record the human conclusion. The assessor documents design, implementation and operating effectiveness, residual risk, monitoring cadence and reassessment triggers.
  9. Generate system and workspace reporting. System reports use the selected system’s own assessment bucket. Workspace reports provide portfolio-level roll-up without replacing the individual system record.

Several badges can appear beside one control because they answer different questions.

DimensionExample labelsThe question it answers
CriticalityCritical, High, Medium, LowHow consequential would failure of this control be?
Control typeGateCan failure of this control prevent a positive assurance conclusion?
ApplicabilityMandatory, Triggered, Enhanced, Not applicableWhy and to what depth does this control apply to this system?
Assessment resultUnassessed, Partial, Supported, Assured, Gap, Gate fail, N/AWhat does the current assessment record demonstrate?

For example:

High · Gate · Enhanced · Gap

means:

  • The control has High criticality.
  • It is a Gate control.
  • The selected system requires Enhanced assessment depth.
  • At least one applicable requirement is answered No, producing a Gap.

It does not mean “High Gate Enhanced Gap” is one combined severity rating.

See Concepts, labels and terminology for every label and its decision consequence.

DomainNameControlsPrimary assurance focus
AGovernance, Strategy and Accountability11Board authority, policy, ownership, decision rights and governance operation
BLegal, Regulatory and Contractual Compliance11Applicable obligations, prohibited uses, contracts and jurisdiction
CAI Use Case Intake, Approval and Risk Tiering11Registration, classification, approval, exceptions and change triggers
DData Governance, Lineage and Provenance11Data origin, lineage, quality, rights, retention and traceability
EData Security and Privacy Engineering24Sensitive data, privacy controls, segregation, minimisation and protection
FSecure Data Acquisition and Annotation11Data collection, labelling, annotation, poisoning resistance and quality
GModel Development, Validation and Robustness11Model engineering, validation, robustness, benchmarks and release controls
HPrompt, Context and Retrieval Security25Prompt injection, RAG, context boundaries, grounding and retrieval integrity
IInference, API and Runtime Security25Serving security, APIs, sessions, output controls and runtime enforcement
JIdentity, Access and NHI Security26Human and non-human identity, secrets, privilege and access lifecycle
KAgentic AI and Autonomous Action Governance29Tools, memory, delegation, approvals, autonomy and kill switches
LThird-Party, Model and Software Supply Chain Assurance25Vendors, hosted models, dependencies, SBOMs and shared responsibility
MMonitoring, Detection and AI Security Operations35Logging, detection, behavioural monitoring, incidents and security operations
NHuman Oversight, Transparency and Impact Management15Human review, notices, explainability, fairness, appeal and social impact
OResilience, Continuity and Recovery36Failover, rollback, crisis response, recovery and provider substitution
PAuditability, Evidence and Assurance11Evidence governance, testing, audit records and assurance independence
QInfrastructure, Platform and Environment Security41Cloud, compute, network, platform, environment and isolation safeguards

The larger domains reflect modern AI concentration points: infrastructure, monitoring, agentic action, identity, prompt/retrieval security and third-party dependencies.

Every control contains enough information for an assessor to work primarily from the control screen:

  • Control statement: the required outcome.
  • Objective: why the control exists.
  • Risk addressed: what can go wrong if it is absent or ineffective.
  • Applicability: when the control applies and why.
  • Criticality and gate status.
  • Implementation guidance: practical actions expected to establish the control.
  • Required evidence: the artefacts and operating records to obtain.
  • Test procedure: how to determine whether the control works.
  • Control owner and evidence owner.
  • Cross-framework mappings.
  • Shared-responsibility role guidance.
  • Assessment answers and implementation narrative.
  • Linked evidence, evidence requests, tests and findings.
  • Structured assessor conclusion and residual risk.
  • System-scoped AI Assist.

GTSAF recognises that AI controls are commonly split across several parties:

CodeParty
MPModel Provider
OSPOrchestrated Service Provider
APApplication Provider
AICAI Customer
CSPCloud Service Provider
SharedResponsibility is divided between named parties
NDNot determined; an ownership gap requiring resolution

The selected guidance role changes the practical implementation guidance shown to the assessor. It does not transfer accountability automatically. Contracts, architecture and actual operating responsibility must support the selected ownership.

GTSAF follows several rules that prevent an assessment from overstating assurance:

  • Unanswered controls are not treated as safe. Coverage is included in conformance and assurance.
  • Narrative is not evidence. A detailed explanation improves narrative sufficiency but does not become verified evidence merely because it sounds credible.
  • A Yes answer is not proof. Evidence and testing are separate.
  • Operating effectiveness requires testing or operating records.
  • Failed tests, rejected evidence and gate failures constrain the result.
  • Critical and High controls receive greater weighting and assurance caps when evidence is weak.
  • N/A is governed. Unsupported N/A responses remain in scope and count as not met.
  • AI Assist cannot approve the assessment. Human review and sign-off remain mandatory.
  • System boundaries are enforced. A selected system does not inherit another system’s AI analysis or operational evidence.

Every GTSAF control includes audited traceability references to:

  • EU AI Act
  • ISO/IEC 42001
  • ISO/IEC 42005
  • NIST AI RMF

The crosswalk helps an assessor reuse evidence and identify related obligations. It does not prove that satisfying one GTSAF control automatically satisfies an external legal or standards requirement.

For a complete understanding, continue in this order:

  1. Concepts, labels and terminology
  2. Domains and control library
  3. System scope, applicability and assurance depth
  4. Assessment workflow
  5. Scoring and assurance model
  6. Evidence, testing and findings
  7. AI Assist explainability
  8. Reporting and governance decisions
  9. Worked example
  10. Reference and glossary