System scope, applicability and assurance depth
GTSAF is assessed per AI system. The AI System Scope selector determines which system’s applicability, answers, ownership, implementation narrative, evidence, tests, findings, assessor conclusions and AI analysis are active.
System scoping prevents a control record for one system from being mistaken for assurance over another system.
The governing principle
Section titled “The governing principle”GTSAF separates three questions:
- Applicability: Which controls are relevant to the system’s actual characteristics?
- Assurance depth: How rigorously must each applicable control be assessed?
- Effectiveness: What do the answers, evidence and tests demonstrate?
These questions must not be collapsed into one score.
- The linked System Record and Use Case Intake determine factual applicability.
- ACRS and the Governance Weighting Profile may increase assurance depth, review cadence and escalation.
- Assessment answers, evidence and tests determine the demonstrated control position.
ACRS and governance weighting do not invent a factual system feature and cannot add or remove a control merely because a system has a higher or lower risk score.
Before a system can be selected
Section titled “Before a system can be selected”A system becomes selectable when its authoritative route is complete and conflict-free. This means the linked System Record and Intake provide enough information to make control applicability decidable.
ACRS confirmation is not an applicability gate. If ACRS has not been confirmed, GTSAF can still show the system’s intake-derived control scope. The screen states that ACRS depth is unavailable so the assessor understands that no confirmed ACRS depth overlay is being used.
Systems with missing or conflicting routing facts remain visible but unavailable for system-specific exclusions. Complete or reconcile those facts in Routing and applicability.
The two assessment views
Section titled “The two assessment views”All GTSAF controls
Section titled “All GTSAF controls”This is the unscoped workspace view of the full canonical population of 358 controls.
Use it when:
- Establishing a complete framework baseline.
- Inspecting the whole library.
- Routing facts are not yet complete.
- Professional judgement requires review beyond a system’s calculated scope.
This view does not claim that all 358 controls apply to one system.
Selected AI system
Section titled “Selected AI system”This is the preferred view for a formal system assessment.
It combines:
- The linked System Record.
- The complete Use Case Intake route.
- Explicit per-control applicability conditions.
- The current governance tier.
- The selected system’s ACRS position, where available.
The selected system has its own assessment bucket. Changing the selection changes the active answers, ownership, narrative, governed N/A decisions, conclusions and AI outputs. Data from the previously selected system is not reused as evidence for the new one.
Factual scope drivers
Section titled “Factual scope drivers”Controls are activated by facts such as:
| Driver | Typical GTSAF effect |
|---|---|
| Governed data dependency | Data governance, quality, provenance, security and lifecycle controls |
| Personal or sensitive data | Privacy, rights, access, impact and records controls |
| Training or tuning | Data acquisition, annotation, model-development and validation controls |
| Retrieval or RAG | Retrieval, grounding, ingestion, context and prompt-injection controls |
| Public-facing interaction | Transparency, abuse protection, monitoring and human-impact controls |
| API or serving surface | Authentication, sessions, inference and runtime-security controls |
| Agentic execution | Identity, permissions, approvals, action monitoring and recovery controls |
| Automated decisioning | Oversight, contestability, explainability and impact controls |
| Consequential human or service impact | Stronger impact, governance and operational controls |
| External supplier or component | Supplier assurance, contracts, software supply chain and shared responsibility |
| Multi-tenant operation | Isolation, access, infrastructure and privacy controls |
| Regulated context | Legal accountability, records, oversight and assurance controls |
| Cultural or community impact | Context, participation, harm and representation controls |
The screen shows each active driver with the number of conditional controls for which it is a valid trigger. Driver counts can overlap. A control may be triggered by both supplier dependency and RAG, for example, so driver counts must not be added together.
Reading the scope calculation
Section titled “Reading the scope calculation”The scope cards reconcile the complete control population:
Applicable controls + Applicability pending + Out of scope = 358
Applicable controls are divided into three mutually exclusive assurance depths:
Baseline + Triggered + Enhanced = Applicable controls
Applicable controls
Section titled “Applicable controls”The number of controls factually relevant to the selected system. This measures scope breadth, not risk or compliance.
A lower-risk system can have a broader applicable population than a higher-risk system. For example, an externally hosted content tool may activate many supplier controls that do not apply to an internally developed fraud model.
Baseline depth
Section titled “Baseline depth”Applicable controls requiring the ordinary level of assessment evidence and review.
Triggered depth
Section titled “Triggered depth”Applicable controls activated by a relevant system feature or exposure and requiring additional attention beyond the baseline.
Enhanced depth
Section titled “Enhanced depth”Applicable controls requiring the strongest evidence, testing, challenge, monitoring or review because their factual conditions, governance tier or ACRS depth justify heightened assurance.
Enhanced does not mean the control has failed. It describes required assessment rigour.
Applicability pending
Section titled “Applicability pending”Controls for which the available route cannot yet support inclusion or exclusion. Pending controls remain visible and are excluded from scope-based scores and workload calculations until the facts are resolved.
Out of scope
Section titled “Out of scope”Controls for which the complete route provides a factual basis for exclusion. Out of scope is a routing conclusion, not an assessor claim that the control is satisfied.
Depth-weighted workload
Section titled “Depth-weighted workload”Applicable-control count alone cannot show assessment stringency. GTSAF therefore presents a depth-weighted workload:
Workload = (Baseline × 1) + (Triggered × 2) + (Enhanced × 3)
This is a transparent planning measure. It expresses the relative assurance work implied by the active scope; it is not a compliance score, cost estimate or certification grade.
Worked calculation
Section titled “Worked calculation”If the screen shows:
- Baseline: 21
- Triggered: 251
- Enhanced: 15
Then:
(21 × 1) + (251 × 2) + (15 × 3) = 568 workload points
Assurance intensity
Section titled “Assurance intensity”Assurance intensity normalises the weighted workload against the maximum possible depth for the applicable population:
Assurance intensity = Workload ÷ (Applicable controls × 3) × 100
For 287 applicable controls and 568 workload points:
568 ÷ (287 × 3) × 100 = 65.97%, displayed as 66%
Assurance intensity makes systems with differently sized scopes easier to compare. It indicates how deeply the applicable population must be assessed, not whether the controls are effective.
Breadth is not stringency
Section titled “Breadth is not stringency”Consider two systems:
| System | Applicable | Baseline | Triggered | Enhanced | Workload | Intensity |
|---|---|---|---|---|---|---|
| External content generator | 263 | 21 | 227 | 15 | 520 | 66% |
| Consequential fraud monitor | 259 | 21 | 3 | 235 | 732 | 94% |
The content generator has four more applicable controls because its external component activates supplier-specific requirements. The fraud monitor is nevertheless substantially more stringent: most of its applicable controls require Enhanced assurance, producing much greater workload and intensity.
Use applicable controls to explain breadth. Use workload and assurance intensity to explain required rigour.
How ACRS affects GTSAF
Section titled “How ACRS affects GTSAF”ACRS assesses:
| Dimension | Question |
|---|---|
| Operational dependency | How dependent are people or operations on the system? |
| Action autonomy | How independently can it recommend, decide or act? |
| Access scope | What data, systems, tools, credentials or privileges can it reach? |
| Harm potential | How serious could failure, misuse or compromise be? |
ACRS may deepen an already applicable control from Baseline to Triggered or Enhanced. It may also inform review cadence and escalation. It cannot make a supplier control applicable where no supplier exists, or remove a human-impact control where consequential impact is evidenced.
How governance weighting affects GTSAF
Section titled “How governance weighting affects GTSAF”The Governance Weighting Profile expresses the organisation’s approved risk policy. A higher governance tier may require stronger evidence, independent review, testing, monitoring or escalation for applicable controls.
Governance weighting changes depth, not factual applicability. This prevents a policy score from overriding the recorded architecture, data, suppliers, users and impacts of the system.
What happens when the route changes
Section titled “What happens when the route changes”If a material System Record or Intake fact changes after confirmation, the route becomes Reassessment required.
The assessor should:
- Review the changed System Record and Intake facts.
- Resolve any missing information or conflicts.
- Review the four ACRS dimensions.
- Adjust ACRS where the evidence requires it, or approve the current ACRS position.
- Review changed framework routes, factual scope drivers and GTSAF control scope.
- Revisit affected assessments, evidence, tests, findings and conclusions.
The green route panel means the route is complete and calculable. It does not mean that no action is required. An accompanying reassessment warning means the previous confirmation no longer represents the current facts.
Evidence and operational records
Section titled “Evidence and operational records”System-scoped operational records should be linked to the selected system or Intake. This applies to:
- Evidence.
- Evidence requests.
- Control tests.
- Findings.
An unlinked record is not automatically treated as system evidence. Where an organisation-wide artefact supports several systems, document and maintain the relationship to each relevant scope.
System assessment versus workspace roll-up
Section titled “System assessment versus workspace roll-up”The selected-system assessment answers:
How well is this named AI system controlled and assured?
The workspace roll-up answers:
What is the aggregate assurance posture across the assessed AI estate?
The roll-up summarises system-level records. It does not transfer answers, evidence, tests, findings, conclusions or AI output between systems and must not be used to claim that every system has the same control effectiveness.
When returning to a workspace, confirm the AI System Scope selector before entering answers or running AI Assist. The assessment screen identifies the active system so the assessor can verify the boundary.
When professional judgement expands review
Section titled “When professional judgement expands review”The route is a disciplined starting point. The assessor should review or add controls when:
- Architecture or system boundaries change.
- A model, hosting arrangement or supplier changes.
- Retrieval, tools, plugins, memory or delegated action are introduced.
- Autonomy, access or privileges increase.
- New data or affected populations enter scope.
- The system becomes public-facing.
- Jurisdiction or regulatory role changes.
- An incident, complaint or control failure reveals an unrecorded exposure.
Do not manipulate Intake facts to obtain a preferred control count. Record the system accurately, then document any additional professional-judgement review.
Explaining the result to an auditor
Section titled “Explaining the result to an auditor”Use this statement:
GTSAF is assessed per AI system. Complete System Record and Use Case Intake facts determine control applicability. ACRS and the approved governance weighting profile determine proportionate assurance depth but cannot invent or remove factual applicability. Baseline, Triggered and Enhanced controls reconcile to the applicable population. Depth-weighted workload and assurance intensity explain required rigour, while assessment answers, evidence and tests establish the demonstrated control position.