Skip to content

Routing & applicability

Routing answers a narrower question than assessment:

Given the approved facts about this AI system, which assessment frameworks require work, which require a scope review, and which can presently be treated as outside the route?

It does not decide that a control is satisfied, that a legal obligation has been met, or that a system is safe. It creates the defensible starting scope for those decisions.

Gamut combines:

  • The System Record, which is the standing description of the system, its ownership, technology, lifecycle, deployment, data and operating context.
  • The Use Case Intake, which records why and how the system is being used, the people and decisions it affects, its action capability, jurisdictions and assessment-specific risk facts.

The records are linked by the system reference. Similar names are not treated as proof that two records describe the same system.

Where the same standing fact appears in both records, the System Record is treated as the primary record and a disagreement is surfaced for review. A conflict is not silently resolved in favour of the more convenient route.

Authoritative cross-framework routing facts

Section titled “Authoritative cross-framework routing facts”

The structured routing section in Intake captures facts that materially change applicability:

Fact groupWhat to recordWhy it matters
Decision impactAdvisory, operational, consequential, or legally significantHelps identify impact-assessment, legal and assurance depth
Action capabilityRead-only, recommend, write, execute, or administerIdentifies agentic and privileged-action exposure
Model originInternal, third-party, open-source/open-weight, or hybridInforms supplier, provider and lifecycle responsibilities
Organisation rolesFor example provider, deployer, importer or downstream providerLegal and value-chain duties depend on role
Capability flagsPrivileged access, training activity and supplier dependencyRoutes controls for access, change, data and third parties
Human-impact flagsVulnerable populations, biometrics and emotion recognitionTriggers enhanced legal, rights and impact screening
Service and content flagsCritical service, synthetic content and deepfakesRoutes resilience, transparency and content obligations
JurisdictionsMarkets, users, affected people and output destinationsEstablishes territorial and regulatory nexus

Use Unknown when the answer has not been established. Do not select “No” merely because evidence has not yet been obtained.

A reliable route normally requires:

  • A stable link to the System Record.
  • System name, purpose and use-case boundary.
  • Model type or AI technique.
  • Autonomy and human oversight.
  • Deployment context.
  • Users and affected people.
  • Data sources and classification.
  • Relevant geographies.
  • Decision impact and action capability.

Missing information remains visible as a routing-quality gap.

Each framework receives one of four states:

StateMeaningAssessor action
ApplicableCurrent facts positively trigger the framework or it is a universal baselineInclude it in the assessment plan
Screening requiredApplicability cannot safely be ruled out because a material fact is unknown or needs specialist reviewComplete the missing facts or scope review; do not treat it as excluded
Not applicableCurrent facts provide a documented basis for leaving the framework outside the system routeRetain the basis and review it after change
Organisational reviewApplicability is decided at organisation or management-system scope, not solely for one systemResolve it through the appropriate organisational governance process

This is fail-closed scoping: uncertainty creates work; it does not create an exemption.

The route itself carries a status:

StatusMeaning
IncompleteRouting-critical information is missing
Conflict reviewThe linked records disagree on one or more material facts
ProvisionalA route has been calculated but not confirmed by an accountable reviewer
ConfirmedThe current basis has been reviewed and accepted
Reassessment requiredMaterial facts changed after the previous confirmation

Confirmation applies only to the facts and route visible at that time.

A route panel may remain green because the current facts are complete and conflict-free while also showing an amber reassessment warning. These messages answer different questions:

  • Green route panel: the current route is calculable and has no missing-fact or conflict blocker.
  • Reassessment required: the basis changed after the previous confirmation, so accountable review is required.

Review the changed System Record and Intake facts, reconsider the ACRS dimensions, inspect any changed framework routes and control scope, then approve the current ACRS position or adjust it where the evidence requires. Revisit affected assessments and reconfirm only when the current basis is understood.

FrameworkRouting approach
GTSAFUniversal framework baseline; complete system facts determine per-control applicability, while ACRS and governance weighting adjust assurance depth
ACRSUniversal capability-risk baseline for the system; informs proportionate assurance depth
NIST AI RMFAvailable as a universal risk-management baseline; context determines prioritisation
ISO/IEC 42001Organisation-level AIMS scope decision informed by the AI portfolio
ISO/IEC 42005Triggered by actual or foreseeable impacts, affected parties and sensitive uses; incomplete impact facts require screening
EU AI ActRouted from territorial nexus, role, use and regulated characteristics; the module then performs authoritative legal classification
ATFRouted when the system can act, use tools or resources, orchestrate work, or exercise delegated authority
NAGFRouted when markets, users, affected people, outputs, operations or regulated roles establish a Nigerian nexus
MAESTRORouted when architecture, model, data, tools, orchestration, ecosystem or human interaction creates layer-specific exposure

Framework-level routing is deliberately separate from item-level applicability. Being routed to a framework does not mean every item within it applies.

Review the route before confirming it. Confirm that:

  • The linked System Record is correct.
  • Unknowns have been investigated or deliberately left for screening.
  • Conflicts are resolved.
  • The stated organisation roles are accurate.
  • Jurisdictions cover deployment, users, affected people and outputs.
  • Decision impact and action capability reflect real operation.
  • The required assessment plan is proportionate.

When a routing-critical fact changes, Gamut marks the previous route for reassessment. Examples include:

  • A system moves from recommendation to execution.
  • A new market or affected population is introduced.
  • A new supplier, model or training activity is added.
  • Biometric, emotion-recognition or synthetic-content functionality is enabled.
  • The system enters a critical service or consequential decision process.
  • The organisation’s legal role changes.

Reconfirm the route only after the changed basis and its assessment consequences have been reviewed.

Routing determines what work is presented and how it is prioritised. It does not award a favourable score.

  • Unknown applicability is not counted as a pass.
  • A route does not satisfy a requirement.
  • A mapped control does not automatically satisfy another framework.
  • GTSAF conditional controls are included or excluded from complete, conflict-free system facts; incomplete facts remain pending.
  • ACRS and governance weighting may increase required assurance depth but cannot invent or remove factual control applicability.
  • Legal modules perform their own detailed scope, role and requirement decisions after routing.

GTSAF distinguishes:

  • Applicability breadth: the controls factually relevant to the selected system.
  • Assurance depth: Baseline, Triggered or Enhanced rigour for each applicable control.
  • Assessment result: what the answers, evidence and tests demonstrate.

The applicable count is not a risk ranking. A system using an external component may have more supplier controls than a higher-impact internal system, while the higher-impact system still requires much deeper assurance. GTSAF therefore also shows depth-weighted workload and normalised assurance intensity. See GTSAF system scope, applicability and assurance depth.

In full-context mode, AI Assist may consider the selected system’s current route, routing facts, quality gaps and conflicts together with the authorised assessment record.

In Privacy Mode, direct identifiers and free-text routing facts are excluded. The model receives only the minimum structured route, applicability signals, completeness state and assessment values needed for bounded assistance. Privacy Mode reduces disclosure; it does not change the route.

AI Assist cannot confirm a route, approve an exclusion, alter applicability or accept risk.

  • System Record and Intake are linked to the same system.
  • Purpose and boundary are specific.
  • Decision impact and action capability describe production reality.
  • Organisation roles are complete.
  • All four jurisdiction perspectives have been considered.
  • Unknowns are not disguised as negative answers.
  • Conflicts have been resolved.
  • Screening-required frameworks have an owner and next action.
  • Organisational decisions are not misrepresented as system-level exclusions.
  • Route confirmation reflects the current basis.
  • Material changes trigger reassessment.