Skip to content

Intake & risk tiering

Intake captures the context an AI system needs to be governed. Risk tiering turns that context into a structured classification that helps decide how much governance the system needs. Authoritative routing combines Intake with the linked System Record to determine which frameworks need assessment or screening. Together they form the front of the governance lifecycle.

Intake is a structured record, not a free-text form. Alongside the descriptive context, purpose, users, owner, business unit, vendor, deployment type and environment, data sources and geographies, it captures a set of risk signals as explicit flags:

  • Personal data and special-category data involvement.
  • High-risk use and automated decision-making.
  • Public-facing exposure.
  • Retrieval characteristics: RAG, retrieval sources, vector store, long context and external retrieval.
  • Context-specific signals such as cultural significance, heritage relevance, local language significance, creative-sector use and community impact.
  • Cross-framework routing facts covering decision impact, action capability, model origin, organisation roles, material capabilities and jurisdictions.

These are routing inputs. The linked System Record supplies the standing system facts, while Intake supplies use-case and impact context. See Routing & applicability for the complete decision model.

Intake produces a risk tier (a system carries undetermined until classified, then low through critical) and an initial risk rating. The risk tier is the pivot of the whole lifecycle: it prioritises attention and routes the system to the controls and frameworks that matter for its level of risk.

  • Higher-risk systems attract deeper assessment and more demanding control expectations.
  • Lower-risk systems are governed proportionately, without unnecessary overhead.

How signals become a tier is deterministic: a governance weighting profile of weighted dimensions and configurable thresholds does the mapping, so the same inputs always yield the same tier.

For systems with agentic or capability-driven risk, intake derives an ACRS score and a capability band from the signals captured. Each dimension is seeded by inference from the intake facts and can be refined with explicit assessor evidence, so an intake-anchored capability score exists straight away. Gamut reconciles the system’s assigned risk tier against the ACRS band, so a mismatch between “how risky we called it” and “how capable it actually is” is surfaced rather than hidden.

You can open ACRS, complete the dimension assessment, and move on to the assessment plan without a mandatory gate. Confirmation is an optional, audited sign-off: it records an assessor-signed ACRS for the system and strengthens the basis for assurance depth, cadence and escalation. It is not required for GTSAF factual applicability: a complete, conflict-free authoritative Intake route is what makes the system selectable for a scoped GTSAF assessment.

If routing-critical facts change after confirmation, the route becomes Reassessment required. Review the changed facts, reconsider ACRS where necessary, and reconfirm only after the resulting framework routes and assessment scope have been reviewed.

Intake does not route in isolation. Gamut combines it with the linked System Record and produces:

  • Applicable frameworks: frameworks positively triggered by current facts.
  • Screening-required frameworks: frameworks that cannot safely be ruled out while facts remain unknown.
  • Organisational review: a decision, such as ISO/IEC 42001 AIMS scope, that is not a simple system-level exclusion.
  • Required reviews: the specific reviews it must undergo.
  • A reviewable routing basis, quality gaps and any conflicts between the records.

This is what connects intake to the rest of the platform: a routed system arrives at assessment already pointed at the right frameworks.

Unknown material facts fail closed as screening required. They do not silently remove a framework. A confirmed route becomes reassessment required when its material basis changes.

An intake record carries an approval status (draft through approved) with a named approver. Risk classification is therefore an accountable decision, not an automatic one: a person signs off that the system is classified and routed correctly before it moves into deeper governance work.

GroupExamplesPrimary effect
Identity and purposeSystem, use case, owner, business unit, intended and prohibited useEstablishes the assessed boundary and accountability.
People and decisionsUsers, affected people, decision impact, appeal and human oversightRisk, impact and legal routing.
Data and retrievalSources, classification, personal data, RAG, external retrieval and retentionPrivacy, security, supplier and impact controls.
Technology and supplyModel origin, vendor, deployment, integrations and dependenciesThreat, supplier, model and resilience routes.
Action and accessAutonomy, tools, permissions, targets and reversibilityACRS, agentic and assurance depth.
Geography and regulationDeployment, affected-person and market geography, regulated roles and sectorJurisdictional and legal screening.
LifecycleStatus, dates, review triggers and approverApproval, reassessment and reporting.

The person completing intake should obtain facts from system owners, technical teams, data/privacy, security, legal and affected business functions as needed. “Unknown” is valid while investigating; it is not a convenient negative answer.

The screen shows save or autosave status. Wait for a successful saved state before navigating away. If save fails, preserve the entered information, correct the displayed validation or service issue and retry. Sync system record updates the connected inventory record where supported; verify the result rather than assuming the two records now agree.

Incomplete material facts produce a routing-incomplete or screening-required state. Gamut may show conservative starting values, but those are not a confirmed factual route. Complete the named facts, resolve contradictions, review ACRS and then confirm the route. Other descriptive intake fields remain valuable governance records even when they do not independently determine applicability.

A marketing-content generator and a fraud-monitoring system are both registered AI systems, so both receive baseline governance. The marketing system may trigger supplier, retrieval and content controls while leaving many decision, privileged-access and severe-harm controls out of scope. The fraud monitor may process personal data, influence consequential decisions, depend on live systems and require stronger evidence, testing and review. ACRS and the Governance Weighting Profile can increase depth and escalation; they do not invent or remove the factual triggers.

  • System boundary and owner confirmed.
  • Purpose, users, affected people and decision impact are specific.
  • Data, retrieval, supplier, action and access facts reflect production reality.
  • Geographic and regulated-role facts have an evidence basis.
  • Unknowns and contradictions are resolved or explicitly escalated.
  • Save and system-record synchronisation succeeded.
  • ACRS, route, applicability and review streams were checked after changes.
  • Approval and reassessment triggers are recorded.

The value of risk tiering is consistency. When every system is classified against the same signals and the same routing logic, risk decisions become comparable across the organisation and defensible to reviewers, who can trace each classification back to the intake that produced it. This is also the foundation for EU AI Act readiness, which is itself a risk-tiered regime.