Intake & risk tiering
Intake captures the context an AI system needs to be governed. Risk tiering turns that context into a structured classification that helps decide how much governance the system needs. Authoritative routing combines Intake with the linked System Record to determine which frameworks need assessment or screening. Together they form the front of the governance lifecycle.
What intake captures
Section titled “What intake captures”Intake is a structured record, not a free-text form. Alongside the descriptive context, purpose, users, owner, business unit, vendor, deployment type and environment, data sources and geographies, it captures a set of risk signals as explicit flags:
- Personal data and special-category data involvement.
- High-risk use and automated decision-making.
- Public-facing exposure.
- Retrieval characteristics: RAG, retrieval sources, vector store, long context and external retrieval.
- Context-specific signals such as cultural significance, heritage relevance, local language significance, creative-sector use and community impact.
- Cross-framework routing facts covering decision impact, action capability, model origin, organisation roles, material capabilities and jurisdictions.
These are routing inputs. The linked System Record supplies the standing system facts, while Intake supplies use-case and impact context. See Routing & applicability for the complete decision model.
From intake to risk tier
Section titled “From intake to risk tier”Intake produces a risk tier (a system carries undetermined until classified, then low
through critical) and an initial risk rating. The risk tier is the pivot of the whole
lifecycle: it prioritises attention and routes the system to the controls and frameworks that
matter for its level of risk.
- Higher-risk systems attract deeper assessment and more demanding control expectations.
- Lower-risk systems are governed proportionately, without unnecessary overhead.
How signals become a tier is deterministic: a governance weighting profile of weighted dimensions and configurable thresholds does the mapping, so the same inputs always yield the same tier.
The ACRS score and confirmation
Section titled “The ACRS score and confirmation”For systems with agentic or capability-driven risk, intake derives an ACRS score and a capability band from the signals captured. Each dimension is seeded by inference from the intake facts and can be refined with explicit assessor evidence, so an intake-anchored capability score exists straight away. Gamut reconciles the system’s assigned risk tier against the ACRS band, so a mismatch between “how risky we called it” and “how capable it actually is” is surfaced rather than hidden.
You can open ACRS, complete the dimension assessment, and move on to the assessment plan without a mandatory gate. Confirmation is an optional, audited sign-off: it records an assessor-signed ACRS for the system and strengthens the basis for assurance depth, cadence and escalation. It is not required for GTSAF factual applicability: a complete, conflict-free authoritative Intake route is what makes the system selectable for a scoped GTSAF assessment.
If routing-critical facts change after confirmation, the route becomes Reassessment required. Review the changed facts, reconsider ACRS where necessary, and reconfirm only after the resulting framework routes and assessment scope have been reviewed.
Framework routing
Section titled “Framework routing”Intake does not route in isolation. Gamut combines it with the linked System Record and produces:
- Applicable frameworks: frameworks positively triggered by current facts.
- Screening-required frameworks: frameworks that cannot safely be ruled out while facts remain unknown.
- Organisational review: a decision, such as ISO/IEC 42001 AIMS scope, that is not a simple system-level exclusion.
- Required reviews: the specific reviews it must undergo.
- A reviewable routing basis, quality gaps and any conflicts between the records.
This is what connects intake to the rest of the platform: a routed system arrives at assessment already pointed at the right frameworks.
Unknown material facts fail closed as screening required. They do not silently remove a framework. A confirmed route becomes reassessment required when its material basis changes.
Approval
Section titled “Approval”An intake record carries an approval status (draft through approved) with a named approver. Risk
classification is therefore an accountable decision, not an automatic one: a person signs off that
the system is classified and routed correctly before it moves into deeper governance work.
Field groups and decision ownership
Section titled “Field groups and decision ownership”| Group | Examples | Primary effect |
|---|---|---|
| Identity and purpose | System, use case, owner, business unit, intended and prohibited use | Establishes the assessed boundary and accountability. |
| People and decisions | Users, affected people, decision impact, appeal and human oversight | Risk, impact and legal routing. |
| Data and retrieval | Sources, classification, personal data, RAG, external retrieval and retention | Privacy, security, supplier and impact controls. |
| Technology and supply | Model origin, vendor, deployment, integrations and dependencies | Threat, supplier, model and resilience routes. |
| Action and access | Autonomy, tools, permissions, targets and reversibility | ACRS, agentic and assurance depth. |
| Geography and regulation | Deployment, affected-person and market geography, regulated roles and sector | Jurisdictional and legal screening. |
| Lifecycle | Status, dates, review triggers and approver | Approval, reassessment and reporting. |
The person completing intake should obtain facts from system owners, technical teams, data/privacy, security, legal and affected business functions as needed. “Unknown” is valid while investigating; it is not a convenient negative answer.
Saving and synchronising
Section titled “Saving and synchronising”The screen shows save or autosave status. Wait for a successful saved state before navigating away. If save fails, preserve the entered information, correct the displayed validation or service issue and retry. Sync system record updates the connected inventory record where supported; verify the result rather than assuming the two records now agree.
When authoritative facts are incomplete
Section titled “When authoritative facts are incomplete”Incomplete material facts produce a routing-incomplete or screening-required state. Gamut may show conservative starting values, but those are not a confirmed factual route. Complete the named facts, resolve contradictions, review ACRS and then confirm the route. Other descriptive intake fields remain valuable governance records even when they do not independently determine applicability.
Worked routing example
Section titled “Worked routing example”A marketing-content generator and a fraud-monitoring system are both registered AI systems, so both receive baseline governance. The marketing system may trigger supplier, retrieval and content controls while leaving many decision, privileged-access and severe-harm controls out of scope. The fraud monitor may process personal data, influence consequential decisions, depend on live systems and require stronger evidence, testing and review. ACRS and the Governance Weighting Profile can increase depth and escalation; they do not invent or remove the factual triggers.
Intake quality checklist
Section titled “Intake quality checklist”- System boundary and owner confirmed.
- Purpose, users, affected people and decision impact are specific.
- Data, retrieval, supplier, action and access facts reflect production reality.
- Geographic and regulated-role facts have an evidence basis.
- Unknowns and contradictions are resolved or explicitly escalated.
- Save and system-record synchronisation succeeded.
- ACRS, route, applicability and review streams were checked after changes.
- Approval and reassessment triggers are recorded.
Why consistency matters
Section titled “Why consistency matters”The value of risk tiering is consistency. When every system is classified against the same signals and the same routing logic, risk decisions become comparable across the organisation and defensible to reviewers, who can trace each classification back to the intake that produced it. This is also the foundation for EU AI Act readiness, which is itself a risk-tiered regime.
- Registry & Discovery: where classified systems live.
- Routing & applicability: how the records become a defensible cross-framework route.
- Assessments & control testing: assess the routed system.
- ACRS: the capability-risk model behind the score.