Skip to content

Run your first assessment

An assessment scores a registered AI system against the controls of a framework and records why. This is where governance becomes defensible: not just a decision, but a decision with a documented rationale and evidence behind it. In Gamut, a good assessment is the end of a short chain that grounds the system first.

A framework score is only as good as the context behind it. Before assessing, work through the chain that feeds it:

  1. AI System Records establishes what the system is.
  2. AI Use Case Intake & Approval explains what it does, who it affects, what data and decisions are involved, and records an accountable approval. See Intake & risk tiering.
  3. Risk Tiering Engine and ACRS Risk Assessment set the depth of governance expected, confirming the risk tier and capability band.
  4. Assessment Plan & Assurance Routing routes the system to the frameworks it actually needs.

By the time you open a framework, the system is grounded and routed, so you are scoring against the right controls rather than guessing which apply.

Routing will suggest the frameworks that fit. Common starting points:

You can assess the same system against more than one framework; Gamut keeps each distinct while sharing the underlying system, evidence and findings. See Frameworks overview.

Open the framework and work through its controls, domain by domain. Each framework uses the answer scale that fits it:

FrameworkHow controls are scored
GTSAF, ATFEach control is answered Yes / No / N/A. ATF adds a depth rating: how embedded a Yes is, or how far a No has progressed.
EU AI Act, NAGFEach requirement is Compliant / Non-compliant / N/A, with a depth rating.
ISO/IEC 42005Each requirement is scored on a maturity scale.
MAESTROEach threat is scored for likelihood and impact, which combine into a risk band.

For each control, whatever the scale:

  • Record the answer or score.
  • Capture the rationale, why you reached that conclusion.
  • Attach or request evidence where relevant.
  • If a control genuinely does not apply, mark it N/A with a documented justification. An unjustified N/A stays in scope and counts as not met.
  • Raise a finding for any gap, deficiency or exception.

Scoring is coverage-inclusive: controls you have not assessed count as not-yet-met, so the score reflects real progress rather than only the parts you have looked at. See how scoring works for the model that applies across every framework.

As you score, the supporting registers are one click away:

  • Evidence Tracker: raise evidence requests and attach artefacts against controls.
  • Testing Centre: record control tests with design and operating effectiveness.
  • Findings Register: track gaps through root cause, remediation and validated closure.