Skip to content

Concepts, labels and terminology

GTSAF deliberately shows several labels on one control because each label describes a different assurance dimension. Reading the badges from left to right gives a compact explanation of the control:

  1. How important is it? Criticality.
  2. Can it block assurance? Gate status.
  3. Why does it apply? Applicability.
  4. What does the assessment demonstrate? Assessment result.

Suppose a control displays:

High · Gate · Enhanced · Gap

This should be read as:

  • High: failure of the control could have a serious consequence.
  • Gate: failure can block a positive assurance conclusion.
  • Enhanced: the selected system requires deeper evidence and stronger testing for this control.
  • Gap: at least one applicable assurance question is currently answered No.

The words are not one combined rating. They are independent labels.

Criticality expresses the potential consequence of control failure. It influences prioritisation and the weighting of domain and overall assurance.

LabelWeightMeaningAssessment consequence
Critical2.0Failure could create severe safety, legal, security, rights, operational or systemic consequences.Weak verified evidence caps assurance below a defensible level. A passing operating-effectiveness test is required before the control can reach Assured.
High1.5Failure could create a serious material consequence.Weak evidence constrains the control’s assurance result.
Medium1.0Material control expected in ordinary AI governance and security operation.Normal weighting.
Low0.75Lower relative consequence within the GTSAF control population.Lower roll-up weight, but still requires assessment when in scope.

The current library contains 70 Critical, 241 High, 43 Medium and 4 Low controls.

Criticality is not the same as the current assessment result. A Critical control can be Assured, and a Low control can still contain a Gap.

Gate is permanent control metadata. It means the control is important enough that a negative answer can prevent the system from receiving an unconstrained assurance conclusion.

Examples include controls governing approval authority, prohibited deployment conditions, identity boundaries, human intervention, evidence integrity or recovery capability.

Gate fail is an assessment result. It occurs when:

  • The control is marked as a Gate control; and
  • At least one applicable question is answered No.

A Gate fail:

  • Overrides the ordinary status label.
  • Caps calculated assurance at 25%.
  • Produces a proxy assurance score of 1.
  • Requires remediation, compensating controls, or an explicit decision not to proceed.
  • Must not be hidden by strong performance elsewhere in the domain.

There are 71 Gate controls in the current GTSAF library.

Applicability answers: how and why does this control apply to this AI system?

The control sits inside the baseline expected for the selected system.

Baseline, Triggered and Enhanced are mutually exclusive assurance-depth labels. Together they make up the applicable-control population.

Mandatory does not mean every organisation implements the control identically. The architecture, shared-responsibility model and operating context determine how the required outcome is achieved.

The system profile activates the control because a relevant feature or exposure is present.

Common triggers include:

  • Personal or sensitive data.
  • Training or fine-tuning.
  • Retrieval-augmented generation.
  • Public-facing interfaces.
  • API serving.
  • Agentic behaviour, tools or memory.
  • Automated decisions.
  • Material human impact.
  • Third-party models or hosted services.
  • Multi-tenant operation.
  • Regulatory or jurisdictional exposure.
  • Cultural, heritage, local-language or community-sensitive content.

Triggered means the system’s characteristics activate the control and require more than baseline attention. It does not mean the control has failed.

Enhanced means the control is in scope and needs deeper assurance because the system’s risk tier or exposure is elevated.

Enhanced assessment normally expects:

  • More complete and current evidence.
  • Stronger sampling.
  • Independent or second-line challenge.
  • A passing operating-effectiveness test.
  • Tighter monitoring.
  • Clearer exception governance.
  • More frequent reassessment.
  • Stronger evidence of supplier or shared-responsibility operation.

Enhanced is not an additional control duplicated on top of another count. It is the deepest of the three mutually exclusive assurance-depth states for an applicable control.

The complete system route does not contain a factual trigger for the conditional control.

The screen may use:

  • Not applicable
  • Out of scope

These describe routing, not an assessor-entered N/A answer. An assessor can still inspect an out-of-scope control and may choose to assess it where professional judgement requires.

The routing facts are not complete or conflict-free enough to support inclusion or exclusion. Pending is not a pass or an exemption. The assessor must resolve the missing or conflicting facts.

Applicable controls, workload and intensity

Section titled “Applicable controls, workload and intensity”
  • Applicable controls measure factual scope breadth.
  • Depth-weighted workload applies transparent weights of 1 to Baseline, 2 to Triggered and 3 to Enhanced controls.
  • Assurance intensity divides workload by the maximum possible depth for the applicable population.

These are scope-planning measures. They are separate from control effectiveness, conformance and the derived assurance score.

Assessment result answers: what does the current assessment record demonstrate?

The labels follow this precedence:

  1. N/A
  2. Unassessed
  3. Gate fail
  4. Gap
  5. Assured
  6. Supported
  7. Partial

There is no usable assessment response for the control.

Unassessed does not mean low risk, compliant or safe. Unassessed in-scope controls reduce coverage and therefore reduce conformance and roll-up assurance.

At least one applicable question is answered No.

A Gap indicates that the required outcome is not fully met. The assessor should:

  • Identify which requirement is not met.
  • Determine whether the weakness concerns design, implementation or operation.
  • Link a finding where appropriate.
  • Record the affected system and control.
  • Set a remediation owner and target date.
  • Decide whether interim compensating controls exist.
  • Record residual risk and any deployment restriction.

If a control shows Gap · Triggered, the words describe two dimensions:

The system profile triggered the control, and the current assessment says at least one requirement is not met.

The control has:

  • No applicable No answers; and
  • Calculated assurance of at least 75%.

Assured indicates a strong assessment position supported by the current record. It does not mean certified, permanently effective or free of residual risk.

For Critical controls, Assured also requires sufficient evidence and at least one passing operating-effectiveness test because Critical controls are subject to additional caps.

At least one applicable question is answered Yes, there are no No answers, but assurance remains below 75%.

Typical reasons include:

  • Incomplete coverage.
  • Evidence that is uploaded but not reviewed or accepted.
  • No passing control test.
  • Weak or missing ownership.
  • Insufficient implementation detail.
  • Evidence that is stale, generic or not system-linked.

Supported is a positive direction of travel, but it is not yet strong enough for Assured.

Assessment activity exists, but the record contains neither affirmative Yes support nor a No that would make it a Gap, and it has not reached Assured.

This is commonly a provisional or incomplete state, for example:

  • An N/A response has not completed the governed approval requirements.
  • Information has been entered but the assessor has not made an affirmative determination.
  • The available record is insufficient to classify the control as Supported.

Partial should normally prompt the assessor to complete the decision rather than leave it as the final conclusion.

The control’s assessment rows are entirely excluded through approved N/A decisions.

N/A is only honoured when the governed N/A record is complete. Otherwise, the requirement remains in scope and is treated as not met.

AnswerMeaning
YESThe assessor states that the requirement is met for the selected scope. Evidence and testing are still required to support the claim.
NOThe requirement is not met. This creates a Gap and creates a Gate fail if the control is a Gate.
NAThe assessor proposes that the requirement does not apply. The exclusion is only honoured after the N/A governance fields are complete.

A valid assessor-entered N/A requires:

  • A specific rationale of meaningful length.
  • A decision category.
  • A named decision owner.
  • A separate independent approver.
  • An approval date.
  • A review date or reassessment trigger.
  • Supporting evidence references where available.
  • Compensating controls or boundary safeguards where relevant.

The decision owner and independent approver must not be the same person.

CodeMeaning
MPModel Provider
OSPOrchestrated Service Provider
APApplication Provider
AICAI Customer
CSPCloud Service Provider
SharedTwo or more named parties divide responsibility
NDNot determined

ND is not a neutral long-term answer. It identifies an ownership gap.

Per-control AI Assist may use additional structured labels:

  • Applicable
  • Potentially applicable
  • Not applicable
  • Insufficient information
  • None
  • Weak
  • Partial
  • Adequate
  • Strong
  • Effective
  • Partially effective
  • Ineffective
  • Not tested
  • Insufficient evidence
  • Low
  • Moderate
  • Elevated
  • High
  • Critical
  • Unknown

These are AI recommendations for human review. They do not automatically modify routing, evidence, scores or the assessor conclusion.

When explaining a control badge to a stakeholder, use:

Criticality tells us how important the control is; Gate tells us whether failure can block assurance; Mandatory, Triggered or Enhanced tells us why and how deeply it applies; and the final status tells us what the current evidence-led assessment demonstrates.