Scoring and assurance model
GTSAF is an evidence-led assurance assessment, not a self-declared maturity survey. Gamut derives several measures from assessment answers, ownership, implementation detail, evidence, tests and coverage.
Scope measures are not effectiveness scores
Section titled “Scope measures are not effectiveness scores”Before interpreting conformance or assurance, distinguish the scope measures shown above the assessment:
| Scope measure | Purpose |
|---|---|
| Applicable controls | Factual breadth of the selected system’s control population |
| Baseline depth | Applicable controls requiring ordinary assurance |
| Triggered depth | Applicable controls requiring additional attention because a condition is present |
| Enhanced depth | Applicable controls requiring the deepest evidence, testing and review |
| Depth-weighted workload | Baseline × 1, Triggered × 2 and Enhanced × 3 |
| Assurance intensity | Workload as a percentage of maximum depth for the applicable population |
| Applicability pending | Controls awaiting sufficient, conflict-free routing facts |
| Out of scope | Conditional controls not triggered by the complete route |
These measures describe what must be assessed and how deeply. They do not demonstrate that a control is designed, implemented or operating effectively.
The counts must reconcile:
Baseline + Triggered + Enhanced = Applicable controls
Applicable controls + Applicability pending + Out of scope = 358
See System scope, applicability and assurance depth for the full calculation and worked comparison.
The headline measures
Section titled “The headline measures”| Measure | What it means |
|---|---|
| Conformance | Whether applicable requirements are answered Yes, including unanswered requirements in the denominator |
| Narrative sufficiency | Whether implementation and customer-responsibility explanations are detailed enough to review |
| Verified evidence | Strength of linked evidence workflow and test signals |
| Ownership clarity | Whether applicable answers have a determined responsible party |
| Assurance | Weighted combination of design, implementation, operation, evidence, coverage and resilience |
| Audit readiness | Combined view of assurance, ownership and verified evidence |
| Assurance score | Derived 1-to-5 summary of assurance, subject to gates and caps |
Conformance
Section titled “Conformance”Conformance is calculated over every in-scope, non-approved-N/A assessment row:
Conformance = Yes answers / applicable question rows
The denominator includes unanswered applicable rows.
This prevents a user from answering one easy question Yes and reporting 100% conformance while the rest of the scope is blank.
Gamut also retains an answered-only percentage as a secondary quality indicator, but the headline conformance measure is coverage-inclusive.
Example
Section titled “Example”An in-scope control has four questions:
- 2 Yes
- 0 No
- 0 approved N/A
- 2 unanswered
Headline conformance is:
2 / 4 = 50%
It is not 100%.
Approved and unapproved N/A
Section titled “Approved and unapproved N/A”An approved N/A is removed from the conformance denominator.
An unapproved N/A remains in scope and counts as not met.
This prevents silent scope reduction.
Narrative sufficiency
Section titled “Narrative sufficiency”Narrative sufficiency measures the quality of:
- Implementation detail.
- Customer or shared-responsibility detail.
Longer text does not automatically receive full credit. Repetition and low-information content can reduce the quality result.
Narrative sufficiency is useful because an assessor needs enough explanation to understand the control. It is not verified evidence.
Verified evidence
Section titled “Verified evidence”The verified-evidence measure uses linked record signals such as:
- Evidence uploaded.
- Evidence received.
- Evidence reviewed.
- Evidence accepted.
- Evidence quality rated Fair, Good or Strong.
- A passing or effective control test.
- Rejected or expired evidence.
- Poor evidence quality.
- A failed, ineffective or exception test.
Positive evidence progression raises the signal. Adverse evidence and failed testing cap it.
Representative progression:
| Signal | Evidence position |
|---|---|
| Evidence uploaded | At least 25 |
| Evidence received | At least 35 |
| Evidence reviewed | At least 55 |
| Evidence accepted | At least 70 |
| Fair quality | At least 45 |
| Good quality | At least 75 |
| Strong quality | At least 90 |
| Passing/effective test | At least 90 |
| Poor or rejected evidence | Capped at 35 |
| Failed/ineffective/exception test | Capped at 30 |
These signals do not mean every uploaded file is useful. The assessor must still evaluate relevance, scope, currency, integrity and sufficiency.
Ownership clarity
Section titled “Ownership clarity”Ownership clarity is the percentage of applicable answered rows with a valid ownership selection.
For a Yes answer, ND is not valid ownership.
Shared ownership should be supported by an explanation of responsibility division.
Assurance components
Section titled “Assurance components”The control assurance percentage combines:
| Component | Weight |
|---|---|
| Design effectiveness | 15% |
| Implementation effectiveness | 20% |
| Operating effectiveness | 20% |
| Verified evidence | 25% |
| Coverage | 10% |
| Resilience | 10% |
Design effectiveness
Section titled “Design effectiveness”Does the control design address the stated risk?
Implementation effectiveness
Section titled “Implementation effectiveness”Is the designed control actually implemented across the selected scope?
Operating effectiveness
Section titled “Operating effectiveness”Does the control work in practice?
Operating effectiveness requires a passing test or credible operating records. Narrative alone does not establish it.
Coverage
Section titled “Coverage”How much of the applicable control has been affirmatively demonstrated?
Resilience
Section titled “Resilience”Does the control remain dependable through change, failure, escalation and operational pressure?
What happens when a No exists
Section titled “What happens when a No exists”If at least one question is No:
- Design is reduced.
- Implementation is constrained by the weaker of narrative and evidence.
- Operating effectiveness is zero.
- Coverage reflects the reduced conformance.
- Resilience is constrained.
- The status becomes Gap, or Gate fail for a Gate control.
This prevents strong evidence for one part of a control from hiding an explicit failed requirement.
Assurance caps
Section titled “Assurance caps”Caps express rules that a weighted average must not override.
Gate failure
Section titled “Gate failure”If a Gate control contains a No:
- Assurance is capped at 25%.
- The assurance score is 1.
Critical control with weak evidence
Section titled “Critical control with weak evidence”If a Critical control has verified evidence below 75:
- Assurance is capped at 54%.
It cannot reach Assured.
Critical control without a passing test
Section titled “Critical control without a passing test”If a Critical control has no passing operating-effectiveness test:
- Assurance is capped at 74%.
It remains below the 75% Assured threshold.
High control with weak evidence
Section titled “High control with weak evidence”If a High control has verified evidence below 50:
- Assurance is capped at 54%.
Failed test
Section titled “Failed test”If a linked test is Failed, Ineffective or Exception:
- Assurance is capped at 25%.
The failure must be resolved or explicitly reflected in the risk decision.
Audit readiness
Section titled “Audit readiness”Audit readiness combines:
| Component | Weight |
|---|---|
| Assurance | 50% |
| Ownership clarity | 15% |
| Verified evidence adjusted for coverage | 35% |
Audit readiness asks whether a reviewer could reproduce and defend the conclusion, not merely whether the control appears designed.
Derived assurance score
Section titled “Derived assurance score”Gamut converts the assurance position to a 1-to-5 score:
| Score | Rule | Practical interpretation |
|---|---|---|
| 1 | Gate fail, or assurance at or below 25 | Material weakness or failed assurance condition |
| 2 | Assurance above 25 but below 55 | Limited support; significant improvement required |
| 3 | Assurance at least 55 but below 75 | Developing assurance; partially defensible |
| 4 | Assurance at least 75 | Assured under the current record |
| 5 | Assurance at least 90 and audit readiness at least 85 | Strong, well-evidenced and audit-ready assurance position |
A score of 4 or 5 does not remove the need to review residual risk, findings, scope and evidence currency.
Assessment-result logic
Section titled “Assessment-result logic”| Result | Logic |
|---|---|
| N/A | No score and the entire control is covered by approved N/A decisions |
| Unassessed | No derived score |
| Gate fail | Gate control with at least one No |
| Gap | Non-gate control with at least one No |
| Assured | No No answers and assurance at least 75 |
| Supported | At least one Yes, no No, assurance below 75 |
| Partial | A scored/provisional record exists without affirmative Yes support or a No |
Criticality weighting in roll-ups
Section titled “Criticality weighting in roll-ups”Domain and overall figures are weighted:
| Criticality | Weight |
|---|---|
| Critical | 2.0 |
| High | 1.5 |
| Medium | 1.0 |
| Low | 0.75 |
This means a weak Critical control affects the domain and overall posture more than a weak Low control.
Weighting does not permit a strong domain average to erase a Gate failure. Gate failures remain visible separately.
How to interpret the numbers
Section titled “How to interpret the numbers”Always interpret the result in this order:
- Selected system and scope.
- Gate failures.
- Failed tests.
- Rejected evidence.
- Critical control gaps.
- Open findings.
- Coverage and unanswered controls.
- Residual risk.
- Headline assurance figures.
Do not begin and end with the average score.
Common misunderstandings
Section titled “Common misunderstandings”“We answered Yes, so why are we not Assured?”
Section titled ““We answered Yes, so why are we not Assured?””Because Yes is a claim. Assured also depends on coverage, ownership, verified evidence and operating effectiveness.
“We uploaded a policy, so why is evidence weak?”
Section titled ““We uploaded a policy, so why is evidence weak?””The policy may not prove implementation or operation. It may also be unreviewed, stale, generic or not linked to the selected system.
“The domain average is strong, so can we ignore one Gate fail?”
Section titled ““The domain average is strong, so can we ignore one Gate fail?””No. Gate failures are explicit blockers and are not averaged away.
“Can a Critical control be Assured without testing?”
Section titled ““Can a Critical control be Assured without testing?””No. The no-passing-test cap keeps Critical assurance below 75.
“Does a score of 5 mean certified?”
Section titled ““Does a score of 5 mean certified?””No. It means the current Gamut record shows assurance of at least 90% and audit readiness of at least 85%, subject to the documented scope and human conclusion.