Reference and glossary
Framework statistics
Section titled “Framework statistics”| Item | Value |
|---|---|
| Version | 1.3 |
| Domains | 17 |
| Controls | 358 |
| Gate controls | 71 |
| Critical controls | 70 |
| High controls | 241 |
| Medium controls | 43 |
| Low controls | 4 |
Domain reference
Section titled “Domain reference”| ID | Domain | Controls |
|---|---|---|
| A | Governance, Strategy and Accountability | 11 |
| B | Legal, Regulatory and Contractual Compliance | 11 |
| C | AI Use Case Intake, Approval and Risk Tiering | 11 |
| D | Data Governance, Lineage and Provenance | 11 |
| E | Data Security and Privacy Engineering | 24 |
| F | Secure Data Acquisition and Annotation | 11 |
| G | Model Development, Validation and Robustness | 11 |
| H | Prompt, Context and Retrieval Security | 25 |
| I | Inference, API and Runtime Security | 25 |
| J | Identity, Access and NHI Security | 26 |
| K | Agentic AI and Autonomous Action Governance | 29 |
| L | Third-Party, Model and Software Supply Chain Assurance | 25 |
| M | Monitoring, Detection and AI Security Operations | 35 |
| N | Human Oversight, Transparency and Impact Management | 15 |
| O | Resilience, Continuity and Recovery | 36 |
| P | Auditability, Evidence and Assurance | 11 |
| Q | Infrastructure, Platform and Environment Security | 41 |
Badge dimensions
Section titled “Badge dimensions”| Dimension | Labels |
|---|---|
| Criticality | Critical, High, Medium, Low |
| Control type | Gate |
| Applicability | Mandatory, Triggered, Enhanced, Not applicable |
| Result | Unassessed, Partial, Supported, Assured, Gap, Gate fail, N/A |
Criticality weights
Section titled “Criticality weights”| Criticality | Weight |
|---|---|
| Critical | 2.0 |
| High | 1.5 |
| Medium | 1.0 |
| Low | 0.75 |
Question answers
Section titled “Question answers”| Answer | Meaning |
|---|---|
| Yes | Requirement is claimed as met |
| No | Requirement is not met |
| N/A | Proposed exclusion, subject to governance approval |
Shared-responsibility roles
Section titled “Shared-responsibility roles”| Code | Meaning |
|---|---|
| MP | Model Provider |
| OSP | Orchestrated Service Provider |
| AP | Application Provider |
| AIC | AI Customer |
| CSP | Cloud Service Provider |
| Shared | Responsibility divided between named parties |
| ND | Not determined |
Assurance components
Section titled “Assurance components”| Component | Weight |
|---|---|
| Design effectiveness | 15% |
| Implementation effectiveness | 20% |
| Operating effectiveness | 20% |
| Verified evidence | 25% |
| Coverage | 10% |
| Resilience | 10% |
Audit-readiness components
Section titled “Audit-readiness components”| Component | Weight |
|---|---|
| Assurance | 50% |
| Ownership clarity | 15% |
| Verified evidence adjusted for coverage | 35% |
Assurance score
Section titled “Assurance score”| Score | Threshold |
|---|---|
| 1 | Gate fail or assurance at/below 25 |
| 2 | Assurance above 25 and below 55 |
| 3 | Assurance at least 55 and below 75 |
| 4 | Assurance at least 75 |
| 5 | Assurance at least 90 and audit readiness at least 85 |
| Condition | Cap |
|---|---|
| Gate failure | 25% |
| Critical control with evidence below 75 | 54% |
| Critical control without passing test | 74% |
| High control with evidence below 50 | 54% |
| Failed, ineffective or exception test | 25% |
Result precedence
Section titled “Result precedence”- N/A
- Unassessed
- Gate fail
- Gap
- Assured
- Supported
- Partial
Evidence workflow
Section titled “Evidence workflow”- Requested
- Received
- Reviewed
- Accepted
- Rejected
- Expired
Evidence quality
Section titled “Evidence quality”- Poor
- Fair
- Good
- Strong
Test results
Section titled “Test results”Positive:
- Passed
- Pass
- Effective
Adverse:
- Failed
- Fail
- Ineffective
- Exception
Other:
- Pending
- Not tested
Effectiveness labels
Section titled “Effectiveness labels”- Effective
- Partially effective
- Ineffective
- Not tested
- Insufficient evidence
Residual-risk labels
Section titled “Residual-risk labels”- Low
- Moderate
- Elevated
- High
- Critical
- Unknown
N/A decision fields
Section titled “N/A decision fields”- Rationale.
- Category.
- Decision owner.
- Independent approver.
- Approval date.
- Review date or reassessment trigger.
- Compensating controls.
- Evidence references.
Scope modes
Section titled “Scope modes”| Scope | Meaning |
|---|---|
| All GTSAF controls | Full canonical control population |
| Selected AI system | Per-system scope derived from a complete, conflict-free authoritative route |
Scope calculations
Section titled “Scope calculations”Applicable controls
Section titled “Applicable controls”Controls factually relevant to the selected system. This is a breadth measure, not a risk, compliance or effectiveness score.
Applicability pending
Section titled “Applicability pending”Controls awaiting sufficient, conflict-free facts. Pending controls are not treated as passed or out of scope.
Out of scope
Section titled “Out of scope”Conditional controls for which the complete route contains no factual trigger.
Baseline depth
Section titled “Baseline depth”Applicable controls requiring the ordinary assurance depth.
Depth-weighted workload
Section titled “Depth-weighted workload”Planning measure calculated as Baseline × 1 + Triggered × 2 + Enhanced × 3.
Assurance intensity
Section titled “Assurance intensity”Depth-weighted workload divided by Applicable controls × 3, expressed as a percentage.
Factual scope driver
Section titled “Factual scope driver”A recorded system characteristic capable of activating one or more conditional controls. Driver counts may overlap.
AI Assist actions
Section titled “AI Assist actions”Per control
Section titled “Per control”- Applicability analysis.
- Evidence assessment.
- Bounded test plan.
- Effectiveness analysis.
- Residual-risk analysis.
- Recommendations.
- Monitoring.
- Cross-control dependencies.
Active scope
Section titled “Active scope”- Executive assurance summary.
- Material gaps.
- Evidence and testing gaps.
- Ownership issues.
- Residual-risk decisions.
- Monitoring needs.
- Prioritised remediation roadmap.
Glossary
Section titled “Glossary”Agentic Capability Risk Score. Product-based risk classification using dependency, action autonomy, access scope and harm potential.
Applicable
Section titled “Applicable”A control or requirement included in the selected assessment boundary.
Assurance
Section titled “Assurance”The degree of confidence supported by assessment answers, evidence, testing, ownership, coverage and resilience.
Assured
Section titled “Assured”GTSAF result for a control with no No answers and assurance of at least 75%.
Audit readiness
Section titled “Audit readiness”The degree to which another reviewer can reproduce and defend the conclusion from the record.
Compensating control
Section titled “Compensating control”An alternative safeguard reducing risk where the primary requirement is not fully met.
Conformance
Section titled “Conformance”Yes answers divided by all applicable question rows, including unanswered rows.
Control
Section titled “Control”A required governance, security or assurance outcome represented by a canonical GTSAF ID.
Control owner
Section titled “Control owner”The party accountable for implementing or operating the control.
Evidence owner
Section titled “Evidence owner”The party responsible for producing and maintaining evidence.
Enhanced
Section titled “Enhanced”An in-scope control requiring deeper evidence and stronger testing because of elevated risk or exposure.
Finding
Section titled “Finding”A governed record describing a control weakness or assurance exception.
A control whose failure can block a positive assurance conclusion.
A result produced by at least one applicable No answer.
Mandatory baseline
Section titled “Mandatory baseline”Applicable controls assigned the ordinary assurance depth. Baseline, Triggered and Enhanced are mutually exclusive and reconcile to the applicable-control population.
Narrative sufficiency
Section titled “Narrative sufficiency”Quality of implementation and customer-responsibility explanation; separate from evidence.
Operating effectiveness
Section titled “Operating effectiveness”Whether a control works in practice over the assessed period.
Residual risk
Section titled “Residual risk”Risk remaining after considering implemented controls and compensating measures.
The named system, components, environments, data, users, suppliers, period and exclusions covered by the assessment.
Supported
Section titled “Supported”A positive but below-Assured result: at least one Yes, no No, and assurance below 75%.
Triggered
Section titled “Triggered”An applicable control requiring additional assurance because a factual system feature or exposure is present. ACRS or governance weighting may also deepen the assurance requirement without changing factual applicability.
Verified evidence
Section titled “Verified evidence”Linked, reviewed and quality-evaluated artefacts or operating records supporting the assessment.
Crosswalk disclaimer
Section titled “Crosswalk disclaimer”GTSAF references to external frameworks provide traceability. They do not establish automatic compliance, exact equivalence or certification.