Skip to content

Scoring and assurance model

GTSAF is an evidence-led assurance assessment, not a self-declared maturity survey. Gamut derives several measures from assessment answers, ownership, implementation detail, evidence, tests and coverage.

Scope measures are not effectiveness scores

Section titled “Scope measures are not effectiveness scores”

Before interpreting conformance or assurance, distinguish the scope measures shown above the assessment:

Scope measurePurpose
Applicable controlsFactual breadth of the selected system’s control population
Baseline depthApplicable controls requiring ordinary assurance
Triggered depthApplicable controls requiring additional attention because a condition is present
Enhanced depthApplicable controls requiring the deepest evidence, testing and review
Depth-weighted workloadBaseline × 1, Triggered × 2 and Enhanced × 3
Assurance intensityWorkload as a percentage of maximum depth for the applicable population
Applicability pendingControls awaiting sufficient, conflict-free routing facts
Out of scopeConditional controls not triggered by the complete route

These measures describe what must be assessed and how deeply. They do not demonstrate that a control is designed, implemented or operating effectively.

The counts must reconcile:

Baseline + Triggered + Enhanced = Applicable controls

Applicable controls + Applicability pending + Out of scope = 358

See System scope, applicability and assurance depth for the full calculation and worked comparison.

MeasureWhat it means
ConformanceWhether applicable requirements are answered Yes, including unanswered requirements in the denominator
Narrative sufficiencyWhether implementation and customer-responsibility explanations are detailed enough to review
Verified evidenceStrength of linked evidence workflow and test signals
Ownership clarityWhether applicable answers have a determined responsible party
AssuranceWeighted combination of design, implementation, operation, evidence, coverage and resilience
Audit readinessCombined view of assurance, ownership and verified evidence
Assurance scoreDerived 1-to-5 summary of assurance, subject to gates and caps

Conformance is calculated over every in-scope, non-approved-N/A assessment row:

Conformance = Yes answers / applicable question rows

The denominator includes unanswered applicable rows.

This prevents a user from answering one easy question Yes and reporting 100% conformance while the rest of the scope is blank.

Gamut also retains an answered-only percentage as a secondary quality indicator, but the headline conformance measure is coverage-inclusive.

An in-scope control has four questions:

  • 2 Yes
  • 0 No
  • 0 approved N/A
  • 2 unanswered

Headline conformance is:

2 / 4 = 50%

It is not 100%.

An approved N/A is removed from the conformance denominator.

An unapproved N/A remains in scope and counts as not met.

This prevents silent scope reduction.

Narrative sufficiency measures the quality of:

  • Implementation detail.
  • Customer or shared-responsibility detail.

Longer text does not automatically receive full credit. Repetition and low-information content can reduce the quality result.

Narrative sufficiency is useful because an assessor needs enough explanation to understand the control. It is not verified evidence.

The verified-evidence measure uses linked record signals such as:

  • Evidence uploaded.
  • Evidence received.
  • Evidence reviewed.
  • Evidence accepted.
  • Evidence quality rated Fair, Good or Strong.
  • A passing or effective control test.
  • Rejected or expired evidence.
  • Poor evidence quality.
  • A failed, ineffective or exception test.

Positive evidence progression raises the signal. Adverse evidence and failed testing cap it.

Representative progression:

SignalEvidence position
Evidence uploadedAt least 25
Evidence receivedAt least 35
Evidence reviewedAt least 55
Evidence acceptedAt least 70
Fair qualityAt least 45
Good qualityAt least 75
Strong qualityAt least 90
Passing/effective testAt least 90
Poor or rejected evidenceCapped at 35
Failed/ineffective/exception testCapped at 30

These signals do not mean every uploaded file is useful. The assessor must still evaluate relevance, scope, currency, integrity and sufficiency.

Ownership clarity is the percentage of applicable answered rows with a valid ownership selection.

For a Yes answer, ND is not valid ownership.

Shared ownership should be supported by an explanation of responsibility division.

The control assurance percentage combines:

ComponentWeight
Design effectiveness15%
Implementation effectiveness20%
Operating effectiveness20%
Verified evidence25%
Coverage10%
Resilience10%

Does the control design address the stated risk?

Is the designed control actually implemented across the selected scope?

Does the control work in practice?

Operating effectiveness requires a passing test or credible operating records. Narrative alone does not establish it.

How much of the applicable control has been affirmatively demonstrated?

Does the control remain dependable through change, failure, escalation and operational pressure?

If at least one question is No:

  • Design is reduced.
  • Implementation is constrained by the weaker of narrative and evidence.
  • Operating effectiveness is zero.
  • Coverage reflects the reduced conformance.
  • Resilience is constrained.
  • The status becomes Gap, or Gate fail for a Gate control.

This prevents strong evidence for one part of a control from hiding an explicit failed requirement.

Caps express rules that a weighted average must not override.

If a Gate control contains a No:

  • Assurance is capped at 25%.
  • The assurance score is 1.

If a Critical control has verified evidence below 75:

  • Assurance is capped at 54%.

It cannot reach Assured.

If a Critical control has no passing operating-effectiveness test:

  • Assurance is capped at 74%.

It remains below the 75% Assured threshold.

If a High control has verified evidence below 50:

  • Assurance is capped at 54%.

If a linked test is Failed, Ineffective or Exception:

  • Assurance is capped at 25%.

The failure must be resolved or explicitly reflected in the risk decision.

Audit readiness combines:

ComponentWeight
Assurance50%
Ownership clarity15%
Verified evidence adjusted for coverage35%

Audit readiness asks whether a reviewer could reproduce and defend the conclusion, not merely whether the control appears designed.

Gamut converts the assurance position to a 1-to-5 score:

ScoreRulePractical interpretation
1Gate fail, or assurance at or below 25Material weakness or failed assurance condition
2Assurance above 25 but below 55Limited support; significant improvement required
3Assurance at least 55 but below 75Developing assurance; partially defensible
4Assurance at least 75Assured under the current record
5Assurance at least 90 and audit readiness at least 85Strong, well-evidenced and audit-ready assurance position

A score of 4 or 5 does not remove the need to review residual risk, findings, scope and evidence currency.

ResultLogic
N/ANo score and the entire control is covered by approved N/A decisions
UnassessedNo derived score
Gate failGate control with at least one No
GapNon-gate control with at least one No
AssuredNo No answers and assurance at least 75
SupportedAt least one Yes, no No, assurance below 75
PartialA scored/provisional record exists without affirmative Yes support or a No

Domain and overall figures are weighted:

CriticalityWeight
Critical2.0
High1.5
Medium1.0
Low0.75

This means a weak Critical control affects the domain and overall posture more than a weak Low control.

Weighting does not permit a strong domain average to erase a Gate failure. Gate failures remain visible separately.

Always interpret the result in this order:

  1. Selected system and scope.
  2. Gate failures.
  3. Failed tests.
  4. Rejected evidence.
  5. Critical control gaps.
  6. Open findings.
  7. Coverage and unanswered controls.
  8. Residual risk.
  9. Headline assurance figures.

Do not begin and end with the average score.

“We answered Yes, so why are we not Assured?”

Section titled ““We answered Yes, so why are we not Assured?””

Because Yes is a claim. Assured also depends on coverage, ownership, verified evidence and operating effectiveness.

“We uploaded a policy, so why is evidence weak?”

Section titled ““We uploaded a policy, so why is evidence weak?””

The policy may not prove implementation or operation. It may also be unreviewed, stale, generic or not linked to the selected system.

“The domain average is strong, so can we ignore one Gate fail?”

Section titled ““The domain average is strong, so can we ignore one Gate fail?””

No. Gate failures are explicit blockers and are not averaged away.

“Can a Critical control be Assured without testing?”

Section titled ““Can a Critical control be Assured without testing?””

No. The no-passing-test cap keeps Critical assurance below 75.

No. It means the current Gamut record shows assurance of at least 90% and audit readiness of at least 85%, subject to the documented scope and human conclusion.