PRACTITIONER ADOPTION GUIDES

ODA3 Practitioner Adoption Guides

Sixteen practitioner guides for understanding the ODA3 framework ecosystem, beginning a bounded GAISSF implementation, relating existing programmes to GAISSF, operationalizing AI incident management, securing physical AI, and preparing traceable assurance evidence.

Start with ODA3

COM-002

ODA3 Institute in 15 Minutes

ODA3 Institute builds the operational-assurance layer between AI governance requirements and real- world system behavior, while developing the assessment and certification infrastructure needed to evaluate that implementation against documented criteria and evidence. In practice, that means four frameworks — GAISSF™, UAIF™, AI-IRF™, and PAI-SF™ — that together address AI safety and security, incident classification, incident response, and physical-AI security assurance. This guide is deliberately short. It will

View guide →
COM-001

The 10-Minute Introduction to GAISSF™

GAISSF™ (the Global AI Safety and Security Framework) gives organizations an evidence-driven operational structure for AI safety and security. Many AI governance programs do not yet answer one operational question clearly: what controls are actually in place, what evidence supports them, and where the uncertainty remains. This guide is deliberately short. It will not make you a GAISSF™ practitioner. It will give you enough to decide whether the framework is relevant to your organization, and where to go next if it

View guide →
COM-007

Which GAISSF Ecosystem Framework Do I Need?

ODA3 Institute publishes four frameworks — GAISSF™, UAIF™, AI-IRF™, and PAI-SF™ — and readers arriving from the suite-level or framework-specific introductions often ask a practical next question: which one applies to me? This guide is a short decision aid, not a substitute for reading the frameworks themselves. It routes by immediate objective and system scope, not by a fixed sequence.

View guide →
COM-008

The AI Assurance Imperative — A Board Member’s Guide to GAISSF™

As organizations deploy AI systems, boards may need to determine whether AI-related risks are being governed and whether management can demonstrate that governance with evidence. This guide gives board members a small set of questions to ask about AI governance — grounded in what GAISSF™, ODA3 Institute's AI safety and security framework, is designed to help organizations demonstrate. It assumes no technical background and does not require reading any other GAISSF™ material first.

View guide →

Adopt GAISSF

COM-003

GAISSF™ Appendix P.1 SMB Quick-Start

Appendix P.1 SMB Quick-Start is one of two conformance-profile entry points GAISSF™ recognizes, alongside the full domain set. This guide orients you to what that profile is and how to approach it — it is not itself a control catalogue, an assessment methodology, or a substitute for reviewing the authoritative profile. This guide assumes you've already read the suite-level or GAISSF-specific introduction and have decided GAISSF™ is relevant to you. If not, start there first.

View guide →
COM-009

The First 30 Days with GAISSF™

This guide offers a suggested implementation spine for the first 30 days after an organization decides to begin applying GAISSF™: from establishing scope through a Day 30 management checkpoint. It is a planning structure, not a required timeline, and Day 30 is a checkpoint for management review — not an attestation, certification, conformance, safety, or regulatory conclusion.

View guide →
COM-010

Applying GAISSF™: Worked Scenarios

This guide illustrates how GAISSF™ Ecosystem scoping and evidence discipline can be applied across diverse, regulated operating environments. The scenarios are hypothetical. They are designed to teach a reasoning process, not to determine framework applicability, regulatory obligations, control sufficiency, conformance, certification, or system safety for another system. Framework applicability must be determined from the specific system and context. It must not be inferred from a sector label, a similar-sounding

View guide →

Map Existing Programmes

COM-004

Mapping GAISSF™ to NIST AI RMF

Organizations already working from the NIST AI Risk Management Framework (AI RMF) often ask the same question before adopting GAISSF™: does this mean starting over? This guide answers that directly. It is not a control-by-control crosswalk — it is a structural orientation showing where NIST AI RMF and GAISSF™ address related concerns differently, where GAISSF™ may add control or evidence granularity, and what should be examined through a formal crosswalk.

View guide →
COM-005

Mapping GAISSF™ to ISO/IEC 42001

Organizations already certified or working toward ISO/IEC 42001 artificial intelligence management system standard often ask the same question before adopting GAISSF™: does this mean starting over? This guide answers that directly. It is not a control- by-control crosswalk — it is a structural orientation showing where ISO/IEC 42001 and GAISSF™ address related concerns differently, where GAISSF™ may add control or evidence granularity, and

View guide →
COM-006

Mapping GAISSF™ to SOC 2

Organizations already reporting under System and Organization Controls (SOC) 2 often ask the same question before adopting GAISSF™: does this mean starting over? This guide answers that directly. It is not a control-by-control crosswalk — it is a structural orientation showing where SOC 2 and GAISSF™ address related concerns differently, where GAISSF™ may add control or evidence granularity, and what should be examined through a formal crosswalk.

View guide →

Prepare and Respond to AI Incidents

COM-011

When AI Breaks — The ODA3 Guide to AI Incident Response

AI incidents can be difficult to recognise because a detection signal is not automatically an incident, an incorrect output is not automatically malicious, and response may need to begin before causality, severity or classification is settled. This guide provides a short operational orientation for teams that need to recognise potentially material AI events, preserve evidence and uncertainty, determine what is known, and begin proportionate response. UAIF™ structures incident identity, causality, harm, severity,

View guide →
COM-012

Classifying AI Incidents — A Practical Guide to UAIF™

AI incident classification is not simply the act of attaching a label after something goes wrong. An organisation may observe anomalous or harmful system behaviour before it knows the cause, the full consequence, whether the condition is an incident or a vulnerability, or whether a regulatory reporting obligation exists. UAIF™ provides a machine-readable incident interchange, classification, severity-scoring, and conformance architecture for AI incidents. Its seven-layer architecture separates identity and

View guide →
COM-013

AI Incident Response Field Guide — Using UAIF™ and AI-IRF™ for Real-World AI Incidents

AI incidents rarely arrive as cleanly classified security tickets. A responder may first see an anomalous model output, an unexpected tool call, a retrieval result containing restricted information, a vendor model behaviour change, a physical-AI safety event, or an alert whose relationship to AI is not yet established. The operational problem is therefore twofold:

View guide →

Secure Physical AI

Build Assurance Evidence

Claims boundary

These guides support practitioner understanding, implementation planning, mapping, incident preparation and evidence preparation. Their publication or use does not establish implementation completeness, control effectiveness, conformity, certification, independent assurance, regulatory approval or legal compliance.

All external references to ODA3 frameworks remain subject to GEL v1.0.