Skip to content

Frameworks overview & routing

Gamut is multi-framework. A single AI system can be assessed against one framework or several. The linked System Record and Use Case Intake provide an authoritative routing basis; ACRS then helps set proportionate assurance depth for capability-driven risk.

This page explains how frameworks work in Gamut and how to choose between them. Each framework has its own page with detail.

Gamut uses framework names, article numbers, clause labels and control IDs to help you organise governance work, for navigation, assessment workflow and crosswalk traceability.

For publication versions, legal snapshots and the reassessment treatment when a source changes, see Framework currency and versioning.

Developed by Gamut as part of the platform:

FrameworkStructure
GTSAF358 controls across 17 domains (A to Q); 71 gate, 70 critical.
ACRS4 capability dimensions, score to 81, 3 risk bands.

Created by others and implemented in Gamut, with attribution:

FrameworkStructureCreated by
ATF5 control elements, 4 autonomy levels, promotion gates.Josh Woodruff (MassiveScale.AI), CC BY 4.0
MAESTRO7 layers plus cross-layer threats, likelihood-times-impact risk scoring.Cloud Security Alliance (Ken Huang)

Mapping Gamut’s workflow to widely used external regimes and standards, at a product-safe level:

ReferenceStructure
EU AI Act11 orthogonal legal routes and 72 atomic checks anchored to Regulation (EU) 2024/1689.
NIST AI RMFSystem-specific Current and Target Profiles across 4 functions, 19 categories and 72 Core outcomes.
ISO/IEC 42001Organisation-level AIMS: 173 atomic clause checks plus 38 Annex A controls.
ISO/IEC 42005System-specific AI impact assessment: 119 atomic items across 5 sections.
NAGFNigerian AI governance: 108 items, 7 sections and 19 legal or sector routes.

GTSAF is the hub. Every one of its 358 controls carries audited crosswalk mappings to the EU AI Act, ISO/IEC 42001, ISO/IEC 42005 and NIST AI RMF. Because evidence attaches to GTSAF controls and those controls map outward, a single body of governance work supports several regimes at once, and a reviewer can trace any conclusion across frameworks.

See the GTSAF crosswalk table for the domain-by-domain mapping.

  1. Register the AI system and link its intake.
  2. Complete the authoritative cross-framework routing facts for decision impact, action capability, roles, material capabilities and jurisdictions.
  3. Gamut combines the two records into applicable, screening-required, not-applicable and organisation-level review decisions. Unknown material facts fail closed as screening required.
  4. Review conflicts and missing information, then confirm the route. A material basis change makes the previous confirmation subject to reassessment.
  5. Use ACRS and framework-specific routing to set the right control and assurance depth.
  6. You assess the system against one or more frameworks, recording rationale and evidence.
  7. Shared evidence and findings mean work done for one framework supports the others through crosswalk traceability.

See Routing & applicability for the full method and state definitions.

Gamut’s frameworks share a consistent scoring philosophy, so a score means the same thing wherever you look.

  • Correct scope first. Most framework assessments are system-specific. ISO/IEC 42001 is organisation-level, and ATF is agent-specific. Portfolio views must preserve those boundaries.
  • Coverage-inclusive. Controls, requirements or threats that have not been assessed count as not-yet-met, not as passes. A barely-started assessment cannot report a high score, so progress and completeness stay visible together.
  • Justified N/A only. Where a framework lets you mark an item not-applicable, doing so for an applicable item requires a documented justification. A justified N/A is taken out of scope; an unjustified N/A stays in scope and counts as not met.
  • Evidence quality is measured separately. Conformance or compliance measures how much is met; evidence and ownership quality measure how strong the assessed work is, so the two are not conflated.

Each framework then applies its own scale on top of this: GTSAF a derived assurance proxy, ATF a strict zero-trust gate, the EU AI Act and NAGF a compliance percentage, ISO/IEC 42005 a maturity scale, and MAESTRO a likelihood-times-impact risk band.