Skip to content

Reference and glossary

ItemValue
Version1.3
Domains17
Controls358
Gate controls71
Critical controls70
High controls241
Medium controls43
Low controls4
IDDomainControls
AGovernance, Strategy and Accountability11
BLegal, Regulatory and Contractual Compliance11
CAI Use Case Intake, Approval and Risk Tiering11
DData Governance, Lineage and Provenance11
EData Security and Privacy Engineering24
FSecure Data Acquisition and Annotation11
GModel Development, Validation and Robustness11
HPrompt, Context and Retrieval Security25
IInference, API and Runtime Security25
JIdentity, Access and NHI Security26
KAgentic AI and Autonomous Action Governance29
LThird-Party, Model and Software Supply Chain Assurance25
MMonitoring, Detection and AI Security Operations35
NHuman Oversight, Transparency and Impact Management15
OResilience, Continuity and Recovery36
PAuditability, Evidence and Assurance11
QInfrastructure, Platform and Environment Security41
DimensionLabels
CriticalityCritical, High, Medium, Low
Control typeGate
ApplicabilityMandatory, Triggered, Enhanced, Not applicable
ResultUnassessed, Partial, Supported, Assured, Gap, Gate fail, N/A
CriticalityWeight
Critical2.0
High1.5
Medium1.0
Low0.75
AnswerMeaning
YesRequirement is claimed as met
NoRequirement is not met
N/AProposed exclusion, subject to governance approval
CodeMeaning
MPModel Provider
OSPOrchestrated Service Provider
APApplication Provider
AICAI Customer
CSPCloud Service Provider
SharedResponsibility divided between named parties
NDNot determined
ComponentWeight
Design effectiveness15%
Implementation effectiveness20%
Operating effectiveness20%
Verified evidence25%
Coverage10%
Resilience10%
ComponentWeight
Assurance50%
Ownership clarity15%
Verified evidence adjusted for coverage35%
ScoreThreshold
1Gate fail or assurance at/below 25
2Assurance above 25 and below 55
3Assurance at least 55 and below 75
4Assurance at least 75
5Assurance at least 90 and audit readiness at least 85
ConditionCap
Gate failure25%
Critical control with evidence below 7554%
Critical control without passing test74%
High control with evidence below 5054%
Failed, ineffective or exception test25%
  1. N/A
  2. Unassessed
  3. Gate fail
  4. Gap
  5. Assured
  6. Supported
  7. Partial
  • Requested
  • Received
  • Reviewed
  • Accepted
  • Rejected
  • Expired
  • Poor
  • Fair
  • Good
  • Strong

Positive:

  • Passed
  • Pass
  • Effective

Adverse:

  • Failed
  • Fail
  • Ineffective
  • Exception

Other:

  • Pending
  • Not tested
  • Effective
  • Partially effective
  • Ineffective
  • Not tested
  • Insufficient evidence
  • Low
  • Moderate
  • Elevated
  • High
  • Critical
  • Unknown
  • Rationale.
  • Category.
  • Decision owner.
  • Independent approver.
  • Approval date.
  • Review date or reassessment trigger.
  • Compensating controls.
  • Evidence references.
ScopeMeaning
All GTSAF controlsFull canonical control population
Selected AI systemPer-system scope derived from a complete, conflict-free authoritative route

Controls factually relevant to the selected system. This is a breadth measure, not a risk, compliance or effectiveness score.

Controls awaiting sufficient, conflict-free facts. Pending controls are not treated as passed or out of scope.

Conditional controls for which the complete route contains no factual trigger.

Applicable controls requiring the ordinary assurance depth.

Planning measure calculated as Baseline × 1 + Triggered × 2 + Enhanced × 3.

Depth-weighted workload divided by Applicable controls × 3, expressed as a percentage.

A recorded system characteristic capable of activating one or more conditional controls. Driver counts may overlap.

  • Applicability analysis.
  • Evidence assessment.
  • Bounded test plan.
  • Effectiveness analysis.
  • Residual-risk analysis.
  • Recommendations.
  • Monitoring.
  • Cross-control dependencies.
  • Executive assurance summary.
  • Material gaps.
  • Evidence and testing gaps.
  • Ownership issues.
  • Residual-risk decisions.
  • Monitoring needs.
  • Prioritised remediation roadmap.

Agentic Capability Risk Score. Product-based risk classification using dependency, action autonomy, access scope and harm potential.

A control or requirement included in the selected assessment boundary.

The degree of confidence supported by assessment answers, evidence, testing, ownership, coverage and resilience.

GTSAF result for a control with no No answers and assurance of at least 75%.

The degree to which another reviewer can reproduce and defend the conclusion from the record.

An alternative safeguard reducing risk where the primary requirement is not fully met.

Yes answers divided by all applicable question rows, including unanswered rows.

A required governance, security or assurance outcome represented by a canonical GTSAF ID.

The party accountable for implementing or operating the control.

The party responsible for producing and maintaining evidence.

An in-scope control requiring deeper evidence and stronger testing because of elevated risk or exposure.

A governed record describing a control weakness or assurance exception.

A control whose failure can block a positive assurance conclusion.

A result produced by at least one applicable No answer.

Applicable controls assigned the ordinary assurance depth. Baseline, Triggered and Enhanced are mutually exclusive and reconcile to the applicable-control population.

Quality of implementation and customer-responsibility explanation; separate from evidence.

Whether a control works in practice over the assessed period.

Risk remaining after considering implemented controls and compensating measures.

The named system, components, environments, data, users, suppliers, period and exclusions covered by the assessment.

A positive but below-Assured result: at least one Yes, no No, and assurance below 75%.

An applicable control requiring additional assurance because a factual system feature or exposure is present. ACRS or governance weighting may also deepen the assurance requirement without changing factual applicability.

Linked, reviewed and quality-evaluated artefacts or operating records supporting the assessment.

GTSAF references to external frameworks provide traceability. They do not establish automatic compliance, exact equivalence or certification.