Skip to content

AI Assist explainability

GTSAF AI Assist helps an assessor interpret the selected assessment. It is available for one control at a time and for a whole-system summary. It does not approve an answer, evidence, test, finding, N/A decision or final conclusion.

The result is bound to the selected AI system and current assessment basis. The panel identifies the system being analysed. When another system is selected, the previous result is not presented as the new system’s current analysis.

Workspace or portfolio analysis is appropriate only when the screen explicitly shows that scope. It does not replace system-level conclusions.

In full-context mode, AI Assist may consider:

  • Canonical control ID, title, objective and advisory.
  • Domain, criticality and Gate status.
  • Applicability label and route rationale.
  • Current answer and depth.
  • Implementation and customer-responsibility narrative.
  • Assessor rationale and conclusion fields.
  • N/A basis and approval state.
  • Authorised evidence status and metadata.
  • Control tests and results.
  • Open findings.
  • Selected system facts relevant to the control.
  • ACRS and assurance-depth context.

Only records available within the user’s authorised assessment scope are considered.

Whole-system analysis may consider:

  • Coverage and answer distribution.
  • Baseline, Triggered and Enhanced populations.
  • Applicable, pending and out-of-scope counts.
  • Depth-weighted workload and assurance intensity.
  • Gate and High-criticality gaps.
  • Evidence and testing depth.
  • Open findings and unresolved N/A.
  • Ownership and review gaps.
  • Current assurance conclusion.

The summary should direct the reviewer back to individual controls for evidence and decision detail.

Per-control analysis can identify:

  • Whether information is sufficient.
  • Verified facts and assumptions.
  • Evidence-supported strengths.
  • Missing evidence.
  • Contradictions or adverse findings.
  • Suggested implementation actions.
  • A safe bounded test and pass criteria.
  • Suggested answer, depth and assurance position for human review.
  • Residual risk and reassessment triggers.

AI suggestions are not automatically applied.

The Privacy Mode checkbox beside AI Assist uses scores-only reduced context. It excludes direct identifiers and free text such as system names, implementation narrative, customer-responsibility notes, N/A rationale and assessor conclusions.

The model receives only the minimum structural state, which can include control identifiers, answer and depth, applicability, evidence/test/finding status, ACRS route and completeness signals.

Privacy Mode reduces disclosure but may produce less specific advice. It does not make the provider call anonymous or change assessment data, routing, scoring or access.

  • A successful result is saved for the selected system, analysis scope and privacy mode.
  • The action changes from Run AI Assist to Re-run AI Assist.
  • Minimise collapses the output without deleting or approving it.
  • Re-run after material scope, control, evidence, test, finding or system change.

AI Assist uses an authorised provider and the existing API-key configuration available to the user or organisation. If no permitted provider is configured, analysis cannot run.

An API key does not grant access. AI Assist remains subject to the user’s plan, workspace, role, framework, model and selected-system permissions.

AI Assist must not describe a control as verified merely because:

  • The answer is Yes.
  • A narrative claims implementation.
  • A generic policy exists.
  • A document is linked but not accepted.
  • The model recommends a control.

Verify every evidence statement against the authorised record. Failed tests and open adverse findings must remain visible.

System descriptions, retrieved content, evidence and findings may contain instruction-like or malicious text. The model should treat that material as data, not authority.

Assessors should not include credentials, unnecessary personal data or unrestricted confidential content. Independently verify surprising instructions, citations and claims.

AI Assist cannot:

  • Set the final answer or depth.
  • Decide or approve applicability.
  • Approve N/A.
  • Accept evidence.
  • Pass a test.
  • Close a finding.
  • Confirm the assessment.
  • Accept residual risk.
  • Authorise deployment or production testing.
  • Change access or entitlements.
  • Certify compliance.
  • Correct system and control are displayed.
  • Route and assessment basis are current.
  • Facts are traceable to authorised records.
  • Assumptions and unknowns are explicit.
  • Evidence belongs to the selected system.
  • Failed tests and findings are included.
  • Gate and High-criticality implications are understood.
  • Proposed tests are safe and authorised.
  • Privacy Mode was selected where needed.
  • A human owns the final decision.