Run your first assessment
An assessment scores a registered AI system against the controls of a framework and records why. This is where governance becomes defensible: not just a decision, but a decision with a documented rationale and evidence behind it. In Gamut, a good assessment is the end of a short chain that grounds the system first.
Ground the system before you score it
Section titled “Ground the system before you score it”A framework score is only as good as the context behind it. Before assessing, work through the chain that feeds it:
- AI System Records establishes what the system is.
- AI Use Case Intake & Approval explains what it does, who it affects, what data and decisions are involved, and records an accountable approval. See Intake & risk tiering.
- Risk Tiering Engine and ACRS Risk Assessment set the depth of governance expected, confirming the risk tier and capability band.
- Assessment Plan & Assurance Routing routes the system to the frameworks it actually needs.
By the time you open a framework, the system is grounded and routed, so you are scoring against the right controls rather than guessing which apply.
Choosing a framework
Section titled “Choosing a framework”Routing will suggest the frameworks that fit. Common starting points:
- EU AI Act readiness: to demonstrate readiness for the EU AI Act.
- GTSAF: for depth, 358 controls across 17 domains.
- NIST AI RMF or ISO/IEC 42001: if you align to those standards.
- ATF: for systems that take action as agents.
You can assess the same system against more than one framework; Gamut keeps each distinct while sharing the underlying system, evidence and findings. See Frameworks overview.
Scoring controls
Section titled “Scoring controls”Open the framework and work through its controls, domain by domain. Each framework uses the answer scale that fits it:
| Framework | How controls are scored |
|---|---|
| GTSAF, ATF | Each control is answered Yes / No / N/A. ATF adds a depth rating: how embedded a Yes is, or how far a No has progressed. |
| EU AI Act, NAGF | Each requirement is Compliant / Non-compliant / N/A, with a depth rating. |
| ISO/IEC 42005 | Each requirement is scored on a maturity scale. |
| MAESTRO | Each threat is scored for likelihood and impact, which combine into a risk band. |
For each control, whatever the scale:
- Record the answer or score.
- Capture the rationale, why you reached that conclusion.
- Attach or request evidence where relevant.
- If a control genuinely does not apply, mark it N/A with a documented justification. An unjustified N/A stays in scope and counts as not met.
- Raise a finding for any gap, deficiency or exception.
Scoring is coverage-inclusive: controls you have not assessed count as not-yet-met, so the score reflects real progress rather than only the parts you have looked at. See how scoring works for the model that applies across every framework.
Capture evidence, tests and findings
Section titled “Capture evidence, tests and findings”As you score, the supporting registers are one click away:
- Evidence Tracker: raise evidence requests and attach artefacts against controls.
- Testing Centre: record control tests with design and operating effectiveness.
- Findings Register: track gaps through root cause, remediation and validated closure.
After the assessment
Section titled “After the assessment”- Track any findings through to remediation.
- Produce a report from the Board Dashboard or a workpaper pack for leadership or audit.
- For agentic systems, continue with an ATF assessment and the agentic stack.