Routing & applicability
Routing answers a narrower question than assessment:
Given the approved facts about this AI system, which assessment frameworks require work, which require a scope review, and which can presently be treated as outside the route?
It does not decide that a control is satisfied, that a legal obligation has been met, or that a system is safe. It creates the defensible starting scope for those decisions.
The two records used
Section titled “The two records used”Gamut combines:
- The System Record, which is the standing description of the system, its ownership, technology, lifecycle, deployment, data and operating context.
- The Use Case Intake, which records why and how the system is being used, the people and decisions it affects, its action capability, jurisdictions and assessment-specific risk facts.
The records are linked by the system reference. Similar names are not treated as proof that two records describe the same system.
Where the same standing fact appears in both records, the System Record is treated as the primary record and a disagreement is surfaced for review. A conflict is not silently resolved in favour of the more convenient route.
Authoritative cross-framework routing facts
Section titled “Authoritative cross-framework routing facts”The structured routing section in Intake captures facts that materially change applicability:
| Fact group | What to record | Why it matters |
|---|---|---|
| Decision impact | Advisory, operational, consequential, or legally significant | Helps identify impact-assessment, legal and assurance depth |
| Action capability | Read-only, recommend, write, execute, or administer | Identifies agentic and privileged-action exposure |
| Model origin | Internal, third-party, open-source/open-weight, or hybrid | Informs supplier, provider and lifecycle responsibilities |
| Organisation roles | For example provider, deployer, importer or downstream provider | Legal and value-chain duties depend on role |
| Capability flags | Privileged access, training activity and supplier dependency | Routes controls for access, change, data and third parties |
| Human-impact flags | Vulnerable populations, biometrics and emotion recognition | Triggers enhanced legal, rights and impact screening |
| Service and content flags | Critical service, synthetic content and deepfakes | Routes resilience, transparency and content obligations |
| Jurisdictions | Markets, users, affected people and output destinations | Establishes territorial and regulatory nexus |
Use Unknown when the answer has not been established. Do not select “No” merely because evidence has not yet been obtained.
Information needed for a reliable route
Section titled “Information needed for a reliable route”A reliable route normally requires:
- A stable link to the System Record.
- System name, purpose and use-case boundary.
- Model type or AI technique.
- Autonomy and human oversight.
- Deployment context.
- Users and affected people.
- Data sources and classification.
- Relevant geographies.
- Decision impact and action capability.
Missing information remains visible as a routing-quality gap.
Routing states
Section titled “Routing states”Each framework receives one of four states:
| State | Meaning | Assessor action |
|---|---|---|
| Applicable | Current facts positively trigger the framework or it is a universal baseline | Include it in the assessment plan |
| Screening required | Applicability cannot safely be ruled out because a material fact is unknown or needs specialist review | Complete the missing facts or scope review; do not treat it as excluded |
| Not applicable | Current facts provide a documented basis for leaving the framework outside the system route | Retain the basis and review it after change |
| Organisational review | Applicability is decided at organisation or management-system scope, not solely for one system | Resolve it through the appropriate organisational governance process |
This is fail-closed scoping: uncertainty creates work; it does not create an exemption.
Overall routing status
Section titled “Overall routing status”The route itself carries a status:
| Status | Meaning |
|---|---|
| Incomplete | Routing-critical information is missing |
| Conflict review | The linked records disagree on one or more material facts |
| Provisional | A route has been calculated but not confirmed by an accountable reviewer |
| Confirmed | The current basis has been reviewed and accepted |
| Reassessment required | Material facts changed after the previous confirmation |
Confirmation applies only to the facts and route visible at that time.
What to do when reassessment is required
Section titled “What to do when reassessment is required”A route panel may remain green because the current facts are complete and conflict-free while also showing an amber reassessment warning. These messages answer different questions:
- Green route panel: the current route is calculable and has no missing-fact or conflict blocker.
- Reassessment required: the basis changed after the previous confirmation, so accountable review is required.
Review the changed System Record and Intake facts, reconsider the ACRS dimensions, inspect any changed framework routes and control scope, then approve the current ACRS position or adjust it where the evidence requires. Revisit affected assessments and reconfirm only when the current basis is understood.
How each framework is treated
Section titled “How each framework is treated”| Framework | Routing approach |
|---|---|
| GTSAF | Universal framework baseline; complete system facts determine per-control applicability, while ACRS and governance weighting adjust assurance depth |
| ACRS | Universal capability-risk baseline for the system; informs proportionate assurance depth |
| NIST AI RMF | Available as a universal risk-management baseline; context determines prioritisation |
| ISO/IEC 42001 | Organisation-level AIMS scope decision informed by the AI portfolio |
| ISO/IEC 42005 | Triggered by actual or foreseeable impacts, affected parties and sensitive uses; incomplete impact facts require screening |
| EU AI Act | Routed from territorial nexus, role, use and regulated characteristics; the module then performs authoritative legal classification |
| ATF | Routed when the system can act, use tools or resources, orchestrate work, or exercise delegated authority |
| NAGF | Routed when markets, users, affected people, outputs, operations or regulated roles establish a Nigerian nexus |
| MAESTRO | Routed when architecture, model, data, tools, orchestration, ecosystem or human interaction creates layer-specific exposure |
Framework-level routing is deliberately separate from item-level applicability. Being routed to a framework does not mean every item within it applies.
Confirmation and change
Section titled “Confirmation and change”Review the route before confirming it. Confirm that:
- The linked System Record is correct.
- Unknowns have been investigated or deliberately left for screening.
- Conflicts are resolved.
- The stated organisation roles are accurate.
- Jurisdictions cover deployment, users, affected people and outputs.
- Decision impact and action capability reflect real operation.
- The required assessment plan is proportionate.
When a routing-critical fact changes, Gamut marks the previous route for reassessment. Examples include:
- A system moves from recommendation to execution.
- A new market or affected population is introduced.
- A new supplier, model or training activity is added.
- Biometric, emotion-recognition or synthetic-content functionality is enabled.
- The system enters a critical service or consequential decision process.
- The organisation’s legal role changes.
Reconfirm the route only after the changed basis and its assessment consequences have been reviewed.
Effect on assessment and scoring
Section titled “Effect on assessment and scoring”Routing determines what work is presented and how it is prioritised. It does not award a favourable score.
- Unknown applicability is not counted as a pass.
- A route does not satisfy a requirement.
- A mapped control does not automatically satisfy another framework.
- GTSAF conditional controls are included or excluded from complete, conflict-free system facts; incomplete facts remain pending.
- ACRS and governance weighting may increase required assurance depth but cannot invent or remove factual control applicability.
- Legal modules perform their own detailed scope, role and requirement decisions after routing.
Understanding the GTSAF route
Section titled “Understanding the GTSAF route”GTSAF distinguishes:
- Applicability breadth: the controls factually relevant to the selected system.
- Assurance depth: Baseline, Triggered or Enhanced rigour for each applicable control.
- Assessment result: what the answers, evidence and tests demonstrate.
The applicable count is not a risk ranking. A system using an external component may have more supplier controls than a higher-impact internal system, while the higher-impact system still requires much deeper assurance. GTSAF therefore also shows depth-weighted workload and normalised assurance intensity. See GTSAF system scope, applicability and assurance depth.
AI Assist and routing facts
Section titled “AI Assist and routing facts”In full-context mode, AI Assist may consider the selected system’s current route, routing facts, quality gaps and conflicts together with the authorised assessment record.
In Privacy Mode, direct identifiers and free-text routing facts are excluded. The model receives only the minimum structured route, applicability signals, completeness state and assessment values needed for bounded assistance. Privacy Mode reduces disclosure; it does not change the route.
AI Assist cannot confirm a route, approve an exclusion, alter applicability or accept risk.
Reviewer checklist
Section titled “Reviewer checklist”- System Record and Intake are linked to the same system.
- Purpose and boundary are specific.
- Decision impact and action capability describe production reality.
- Organisation roles are complete.
- All four jurisdiction perspectives have been considered.
- Unknowns are not disguised as negative answers.
- Conflicts have been resolved.
- Screening-required frameworks have an owner and next action.
- Organisational decisions are not misrepresented as system-level exclusions.
- Route confirmation reflects the current basis.
- Material changes trigger reassessment.