Frameworks overview & routing
Gamut is multi-framework. A single AI system can be assessed against one framework or several. The linked System Record and Use Case Intake provide an authoritative routing basis; ACRS then helps set proportionate assurance depth for capability-driven risk.
This page explains how frameworks work in Gamut and how to choose between them. Each framework has its own page with detail.
Why framework references are used
Section titled “Why framework references are used”Gamut uses framework names, article numbers, clause labels and control IDs to help you organise governance work, for navigation, assessment workflow and crosswalk traceability.
For publication versions, legal snapshots and the reassessment treatment when a source changes, see Framework currency and versioning.
The frameworks at a glance
Section titled “The frameworks at a glance”Gamut frameworks
Section titled “Gamut frameworks”Developed by Gamut as part of the platform:
| Framework | Structure |
|---|---|
| GTSAF | 358 controls across 17 domains (A to Q); 71 gate, 70 critical. |
| ACRS | 4 capability dimensions, score to 81, 3 risk bands. |
Open agentic frameworks Gamut implements
Section titled “Open agentic frameworks Gamut implements”Created by others and implemented in Gamut, with attribution:
| Framework | Structure | Created by |
|---|---|---|
| ATF | 5 control elements, 4 autonomy levels, promotion gates. | Josh Woodruff (MassiveScale.AI), CC BY 4.0 |
| MAESTRO | 7 layers plus cross-layer threats, likelihood-times-impact risk scoring. | Cloud Security Alliance (Ken Huang) |
Public and third-party references
Section titled “Public and third-party references”Mapping Gamut’s workflow to widely used external regimes and standards, at a product-safe level:
| Reference | Structure |
|---|---|
| EU AI Act | 11 orthogonal legal routes and 72 atomic checks anchored to Regulation (EU) 2024/1689. |
| NIST AI RMF | System-specific Current and Target Profiles across 4 functions, 19 categories and 72 Core outcomes. |
| ISO/IEC 42001 | Organisation-level AIMS: 173 atomic clause checks plus 38 Annex A controls. |
| ISO/IEC 42005 | System-specific AI impact assessment: 119 atomic items across 5 sections. |
| NAGF | Nigerian AI governance: 108 items, 7 sections and 19 legal or sector routes. |
How crosswalks work
Section titled “How crosswalks work”GTSAF is the hub. Every one of its 358 controls carries audited crosswalk mappings to the EU AI Act, ISO/IEC 42001, ISO/IEC 42005 and NIST AI RMF. Because evidence attaches to GTSAF controls and those controls map outward, a single body of governance work supports several regimes at once, and a reviewer can trace any conclusion across frameworks.
See the GTSAF crosswalk table for the domain-by-domain mapping.
How routing works
Section titled “How routing works”- Register the AI system and link its intake.
- Complete the authoritative cross-framework routing facts for decision impact, action capability, roles, material capabilities and jurisdictions.
- Gamut combines the two records into applicable, screening-required, not-applicable and organisation-level review decisions. Unknown material facts fail closed as screening required.
- Review conflicts and missing information, then confirm the route. A material basis change makes the previous confirmation subject to reassessment.
- Use ACRS and framework-specific routing to set the right control and assurance depth.
- You assess the system against one or more frameworks, recording rationale and evidence.
- Shared evidence and findings mean work done for one framework supports the others through crosswalk traceability.
See Routing & applicability for the full method and state definitions.
How scoring works
Section titled “How scoring works”Gamut’s frameworks share a consistent scoring philosophy, so a score means the same thing wherever you look.
- Correct scope first. Most framework assessments are system-specific. ISO/IEC 42001 is organisation-level, and ATF is agent-specific. Portfolio views must preserve those boundaries.
- Coverage-inclusive. Controls, requirements or threats that have not been assessed count as not-yet-met, not as passes. A barely-started assessment cannot report a high score, so progress and completeness stay visible together.
- Justified N/A only. Where a framework lets you mark an item not-applicable, doing so for an applicable item requires a documented justification. A justified N/A is taken out of scope; an unjustified N/A stays in scope and counts as not met.
- Evidence quality is measured separately. Conformance or compliance measures how much is met; evidence and ownership quality measure how strong the assessed work is, so the two are not conflated.
Each framework then applies its own scale on top of this: GTSAF a derived assurance proxy, ATF a strict zero-trust gate, the EU AI Act and NAGF a compliance percentage, ISO/IEC 42005 a maturity scale, and MAESTRO a likelihood-times-impact risk band.
Choosing a framework
Section titled “Choosing a framework”- Need to demonstrate regulatory readiness in the EU? Start with EU AI Act readiness.
- Want maximum assurance depth? Use GTSAF.
- Aligning to a recognised standard? Use NIST AI RMF or ISO/IEC 42001.
- Running an impact assessment? Use ISO/IEC 42005.
- Operating in Nigeria? Use NAGF.
- Governing agents that take action? Add ATF, score risk with ACRS, and threat-model with MAESTRO.