GAISSF PUBLICATION

Adoption Guide

Program Establishment, Governance and Implementation Planning

Document Control

AttributeControlled value
TitleGAISSF™ v1.0 Adoption Guide
Document IDGAISSF-IMP-009
Version1.0
PurposeGuide organizations in establishing a GAISSF adoption program
Primary audienceBoards, executives, CISOs, AI governance leads, security architects, compliance, risk, legal, internal audit and program managers
ClassificationInformative implementation guidance
DependenciesGAISSF-NOR-001 through GAISSF-NOR-008
PrecedenceGAISSF-NOR-001 and controlled profile records prevail
DistributionPublic — Website and GitHub

Foreword

GAISSF adoption is a program of governance, engineering, evidence and assurance—not a document-acquisition exercise. Organizations obtain value when control ownership, operating processes, technical validation and executive risk decisions are integrated into normal business and system lifecycle practices.

1. Purpose and Scope

This guide provides a structured method for planning and establishing a GAISSF adoption program. It covers sponsorship, scope, governance, resourcing, control ownership, gap assessment, evidence architecture, remediation, internal assurance, certification readiness and continuing operation.

The guide applies to enterprise-wide, business-unit, service, platform, product and AI-system adoption. Organizations should tailor the sequence to their size, sector, jurisdiction, deployment model and risk exposure.

2. Adoption Principles

PrincipleAdoption meaning
Authoritative-source disciplineUse NOR-001 and the controlled 59-control catalogue as the source of requirements. Do not re-author controls in local language without traceability.
Scope before scoringDefine organizational, system, geographic, lifecycle and supplier boundaries before assessing conformance.
Risk-based but not optional-by-preferenceApply the controlled conformance profile and document justified exceptions; do not select only convenient controls.
Evidence over assertionRequire operating evidence showing that controls function in the assessed scope.
Cross-functional ownershipDistribute accountability across governance, security, engineering, data, privacy, safety, legal, procurement and audit.
Integration over parallel bureaucracyEmbed GAISSF into existing management systems, development workflows, risk processes and assurance mechanisms.
Continuous operationTreat adoption as an operating system with monitoring, review and improvement—not a one-time project.

3. Adoption Outcomes

OutcomeWhat good looks likeEvidence
Governance establishedExecutive sponsor, steering body, decision rights and escalation routes are activeCharter, minutes, risk decisions
Scope controlledIn-scope systems, business units, suppliers and locations are enumeratedScope statement, inventory, architecture diagrams
Controls ownedEach applicable control has accountable and operating ownersRACI, control register
Gaps understoodDesign and operating gaps are recorded and prioritizedGap assessment, risk ratings
Evidence managedEvidence is indexed, current, traceable and reviewableEvidence repository and index
Remediation fundedCorrective actions have owners, dates and resourcesApproved roadmap, budget, action log
Assurance operatingInternal testing and management review are recurringTest results, audit reports, review records
Certification decision informedScope, readiness, cost and residual risks are understoodReadiness report and executive approval

4. Adoption Lifecycle

PhasePrimary purpose
Phase 0 — MobilizeConfirm sponsor, mandate, strategic objective and program lead.
Phase 1 — DiscoverInventory AI systems, services, models, data, suppliers and jurisdictions.
Phase 2 — ScopeDefine assessment boundary, conformance target and applicable profiles.
Phase 3 — GovernEstablish decision rights, control ownership and reporting.
Phase 4 — AssessPerform control-by-control design and operating-effectiveness assessment.
Phase 5 — RemediatePrioritize and implement corrective actions.
Phase 6 — EvidenceBuild certification-grade evidence packages and traceability.
Phase 7 — AssureConduct internal validation, independent review and readiness assessment.
Phase 8 — Certify or AttestPursue external assessment where appropriate.
Phase 9 — SustainMonitor change, threats, performance, exceptions and continued conformance.

5. Phase 0 — Mobilize the Program

5.1 Establish the mandate

  • Define the business reason for adoption: assurance, customer requirement, regulatory readiness, risk reduction, market access or internal standardization.
  • Name an executive sponsor with authority over scope, funding and cross-functional participation.
  • Appoint a program lead responsible for coordination, traceability and reporting.
  • Approve a program charter stating objectives, boundaries, assumptions, exclusions and intended certification outcome.

5.2 Program charter minimum content

Charter fieldMinimum content
PurposeWhy GAISSF is being adopted
Target outcomeInternal conformance, customer assurance, certification or staged adoption
Initial scopeBusiness units, systems, regions and lifecycle stages
AuthoritySponsor and decision rights
GovernanceSteering body and reporting cadence
ResourcesCore team, subject-matter support and budget
MilestonesAssessment, remediation, evidence and assurance checkpoints
DependenciesLegal, procurement, engineering, tooling and supplier constraints
Success criteriaMeasurable adoption and readiness outcomes

6. Phase 1 — Discover the Environment

Discovery shall produce an evidence-backed view of the AI estate. The inventory should include internally developed systems, embedded AI functions, third-party services, foundation-model dependencies, agentic components and physical-AI deployments.

Inventory fieldExample content
System identifierUnique name and owner
Purpose and usersBusiness objective, users and affected persons
Model dependencyModel name, provider, version and deployment type
DataTraining, tuning, retrieval and operational data categories
InterfacesAPIs, tools, agents, plugins, external actions and downstream systems
DeploymentCloud, on-premises, edge, mobile, embedded or cyber-physical
CriticalitySafety, financial, legal, operational and reputational impact
JurisdictionsCountries, regions and sector regimes
SuppliersModel, data, hosting, evaluation and integration providers
Lifecycle statusDesign, test, pilot, production, suspended or retired

7. Phase 2 — Define Scope and Conformance Target

7.1 Scope dimensions

  • Organizational boundary: legal entities, functions, sites and shared services.
  • System boundary: AI components, applications, infrastructure, interfaces and data flows.
  • Lifecycle boundary: acquisition, design, training, testing, deployment, monitoring and retirement.
  • Geographic boundary: jurisdictions and data-transfer locations.
  • Supplier boundary: outsourced services and inherited controls.
  • Certification boundary: what will and will not appear on a certificate or assurance statement.

7.2 Conformance target

TargetUseAdoption implication
FoundationalInitial controlled baselineAssess the canonical 52-control profile exactly as enumerated in the controlled profile register.
OperationalFull operating frameworkAssess all 59 controls and demonstrate consistent operation.
OptimizedAdvanced assurance and continuous monitoringAssess all 59 controls plus continuous-monitoring and improvement expectations.
Sector profileAdditional sector or jurisdiction obligationsApply additively; it does not replace the base profile.
Important: the Foundational profile is not equivalent to excluding the D9 domain. The controlled profile register shall be used to identify the seven exclusions and the 52 included controls.

7.3 Scope statement template

FieldIllustrative entry
OrganizationExample enterprise and named business unit
SystemsNamed AI services and supporting platforms
LocationsSpecified regions and hosting environments
LifecycleDevelopment through production operation
SuppliersNamed critical providers and inherited-control boundaries
ProfileFoundational / Operational / Optimized plus sector profiles
ExclusionsExplicitly justified and approved
Assessment periodEvidence period and cut-off date

8. Phase 3 — Establish Governance

RolePrimary accountability
Board or risk committeeOversight of material AI risk and assurance
Executive sponsorMandate, resources, escalation and residual-risk acceptance
GAISSF steering committeeCross-functional decisions and progress control
Program leadPlan, dependencies, traceability and reporting
Control ownerDesign and accountability for control effectiveness
Control operatorDay-to-day execution and evidence generation
System ownerSystem risk, lifecycle and supplier decisions
Legal and complianceApplicable obligations and legal interpretation
Internal audit / assuranceIndependent challenge and testing
Certification liaisonAssessment coordination and controlled representations

9. Phase 4 — Conduct the Baseline Assessment

Assessment should distinguish control design, implementation, operation and effectiveness. A policy alone does not demonstrate operation.

RatingMeaningTypical evidence
Not applicableExcluded only through controlled applicability rules or approved scope rationaleApplicability decision and approval
Not implementedNo adequate control design or operationGap record
DesignedControl is documented but not fully operatingPolicy, procedure, design record
ImplementedMechanism exists but evidence period is insufficient or inconsistentConfiguration, deployment record
OperatingControl operates consistently in the assessed scopeLogs, tickets, reviews, test outputs
EffectiveControl demonstrably reduces the intended risk and passes assurance testingOutcome metrics, independent validation

9.1 Assessment method

  1. Review the exact control statement and objective.
  2. Confirm applicability to the defined scope.
  3. Identify required control owners and operators.
  4. Inspect design documentation and implementation records.
  5. Sample operating evidence across the assessment period.
  6. Test technical and procedural operation where applicable.
  7. Record gaps, risks, dependencies and conflicting evidence.
  8. Assign corrective action and target date.

10. Phase 5 — Build the Remediation Roadmap

PriorityCriteriaExpected treatment
P0 — ImmediateMaterial safety, legal, security or uncontrolled production exposureContain, suspend or restrict operation; executive escalation
P1 — CriticalMajor control absence affecting certification or material riskFunded remediation with executive tracking
P2 — HighSignificant design or operating weaknessTime-bound corrective action
P3 — ModeratePartial implementation or evidence weaknessPlanned improvement
P4 — LowDocumentation, efficiency or optimization issueNormal improvement backlog

10.1 Roadmap fields

  • Control ID and finding ID
  • Risk statement and affected scope
  • Root cause
  • Interim containment
  • Corrective action
  • Accountable owner
  • Resources and dependencies
  • Target date
  • Validation method
  • Closure evidence

11. Phase 6 — Establish the Evidence Architecture

Evidence classExamplesQuality expectation
GovernanceCharters, approvals, meeting minutes, risk decisionsSigned, dated and scope-linked
DesignPolicies, procedures, architectures, threat modelsControlled version and owner
TechnicalConfigurations, test outputs, scans, model evaluationsReproducible and attributable
OperationalLogs, tickets, review records, monitoring outputsRepresentative across the evidence period
SupplierContracts, attestations, due diligence, service reportsCurrent and linked to inherited controls
Corrective actionFinding records, fixes, validation and closure approvalTraceable from issue to verified closure

11.1 Evidence index minimum fields

FieldDescription
Evidence IDUnique identifier
Control IDMapped GAISSF control
Scope elementSystem, business unit, supplier or location
OwnerEvidence custodian
PeriodDate range represented
SourceSystem or process of origin
IntegrityHash, signature or repository control where appropriate
StatusDraft, approved, expired or superseded
LocationControlled repository path
LimitationsKnown gaps, sampling limits or assumptions

12. Phase 7 — Internal Assurance and Readiness

  1. Perform a document and traceability review.
  2. Re-test high-risk technical controls.
  3. Verify the complete Statement of Applicability.
  4. Confirm evidence-period sufficiency.
  5. Review open exceptions and residual-risk acceptance.
  6. Validate that public claims match the assessed scope.
  7. Conduct management review and readiness decision.

12.1 Readiness decision criteria

DecisionCriteria
ProceedNo unresolved major nonconformities; evidence is sufficient; scope is stable
Proceed conditionallyLimited minor issues with approved closure plan and no material misstatement risk
DeferEvidence period, scope stability or remediation is insufficient
Stop and containMaterial uncontrolled risk or invalid certification representation

13. Phase 8 — External Assessment and Certification

Organizations seeking certification should establish a single controlled interface for assessor requests, evidence transfer, finding management and public claims.

Preparation areaRequired action
ScopeFreeze and approve the certification boundary
EvidenceProvide indexed, current and authenticated evidence
SamplingIdentify populations and support reproducible sampling
PersonnelMake control owners and operators available
FindingsUse controlled correction and corrective-action workflow
AppealsUse the certification program’s controlled appeals route
ClaimsApprove certificate wording, marks and public statements

14. Phase 9 — Sustain Adoption

Operating mechanismMinimum activity
Change monitoringAssess system, supplier, legal and threat changes
Control monitoringTrack failures, exceptions and performance indicators
Management reviewReview status, risks, resources and improvement
Internal assuranceRetest controls based on risk and change
Evidence maintenanceRefresh expired and superseded evidence
TrainingMaintain role-based competence
Incident learningFeed incidents and near misses into controls
Release managementAssess new GAISSF versions and migration impact

15. Adoption Roadmap

Time horizonPrimary activitiesDeliverables
Days 0-30Mobilize, inventory, initial scope, sponsor and charterProgram charter, inventory, draft scope
Days 31-60Governance, profile selection, baseline assessmentRACI, SoA, gap register
Days 61-90Prioritized remediation and evidence architectureRoadmap, evidence index, dashboards
Months 4-6Implement critical controls and internal assuranceOperating evidence, test results, review records
Months 7-9Close high-priority gaps and stabilize operationCorrective-action closure, readiness report
Months 10-12External assessment or sustained internal conformanceAssessment package, certification decision
Time horizons are illustrative. Actual duration depends on scope, maturity, evidence availability, supplier dependencies and remediation complexity.

16. Program Metrics

MetricInterpretationCaution
Applicable controls with assigned ownerOwnership completenessDoes not prove operation
Controls with current operating evidenceEvidence coverageQuality matters more than count
Open major findingsMaterial readiness riskTrack age and exposure
Corrective actions overdueExecution weaknessConsider dependency causes
Exceptions nearing expiryResidual-risk exposureRequire review before extension
Systems inventoriedDiscovery completenessShadow AI may remain
Supplier evidence coverageThird-party assuranceAttestations may be insufficient
Control retest pass rateOperational stabilityAvoid masking high-impact failures

17. Common Adoption Failure Modes

Failure modeWhy it failsCorrective response
Treating GAISSF as a checklistIgnores scope, operation and evidenceEstablish control ownership and testing
Starting with certificationCreates evidence scramble and unstable scopeBuild operating capability first
Copying control text into policyProduces paper conformanceConnect requirements to systems and workflows
Using maturity to offset failuresMasks unmet mandatory controlsSeparate maturity from conformance
Ignoring suppliersLeaves inherited risks unassessedDefine supplier boundaries and evidence
Over-scoping the first releaseCreates unmanageable remediationUse a defensible staged scope
Under-scoping interfacesExcludes material dependenciesInclude data flows, tools, agents and external actions
Relying on self-attestation onlyReduces assurance credibilityUse independent challenge based on risk

18. Sector and Jurisdiction Tailoring

Sector and jurisdiction requirements should be treated as additive overlays. The organization should maintain a legal and regulatory obligations register linked to GAISSF controls without claiming automatic equivalence.

  • Identify applicable laws, regulators, standards and contractual obligations.
  • Record which requirements are fully addressed, partially addressed or outside GAISSF scope.
  • Apply sector profiles and specialist safety or quality standards where required.
  • Escalate conflicts between framework guidance and applicable law.
  • Retain legal interpretation outside the control-assessment function.

19. Limitations

  • This guide does not enumerate every control requirement.
  • It does not replace the authoritative conformance profile or Statement of Applicability.
  • It does not establish universal cost, staffing or schedule benchmarks.
  • It does not determine legal applicability or certify a system.
  • It cannot eliminate sampling, evidence or assessor-judgement limitations.

20. Notably Absent

  • No promise of certification within a fixed period.
  • No claim that adoption guarantees security, safety, compliance or market approval.
  • No universal requirement to adopt the highest tier.
  • No permission to exclude controls for convenience.
  • No replacement for sector safety engineering, privacy, quality or cybersecurity obligations.
  • No assumption that all D9 controls are outside the Foundational profile.

Annex A — Adoption Readiness Checklist

☐ Executive sponsor appointed

☐ Program charter approved

☐ AI inventory substantially complete

☐ Scope statement approved

☐ Conformance profile selected

☐ Statement of Applicability established

☐ Control owners assigned

☐ Baseline assessment completed

☐ Critical risks contained

☐ Remediation roadmap funded

☐ Evidence repository operational

☐ Internal assurance completed

☐ Exceptions and residual risks approved

☐ Certification decision documented

☐ Continuing-conformance process active

Annex B — Program Workplan Template

WorkstreamOwnerKey outputsTarget dateStatus
GovernanceCharter, steering committee, reporting
Scope and inventoryInventory, boundary, SoA
Control implementationControl designs and procedures
Technical validationTests, evaluations and monitoring
Evidence managementEvidence index and repository
Supplier assuranceDue diligence and inherited-control records
RemediationCorrective-action plan and closure
Internal assuranceReadiness review and management approval
CertificationAssessment coordination and claims control

Annex C — Executive Decision Log Template

Decision IDDecisionOptions consideredRationaleOwnerDateEvidence

Annex D — Source Traceability

Guide sectionPrimary controlled source
Framework requirementsGAISSF-NOR-001
Executive interpretationGAISSF-NOR-002
Initial implementation sequenceGAISSF-NOR-003
Control records and evidence fieldsGAISSF-NOR-004
TerminologyGAISSF-NOR-005
External referencesGAISSF-NOR-006
Release and supersession statusGAISSF-NOR-007
Historical decisions and correctionsGAISSF-NOR-008

Annex E — Publication Record

VersionDateChangeStatus
1.029 June 2026Initial adoption guide for GAISSF v1.0Final Publication v1.0

Controlled Profile Reconciliation Notice

The Foundational profile comprises 52 controls across all nine domains, as enumerated in the controlled conformance profile. Seven controls are excluded from that profile; the exclusions are not equivalent to excluding the D9 domain.

Any earlier wording that described the Foundational profile as D1-D8 only or treated the entire D9 domain as excluded is superseded by this statement and the controlled conformance profile.

Detailed Program Establishment Model

WorkstreamActivitiesDeliverablesGate
GovernanceMandate, charter, sponsor, steering body, decision rightsCharter, RACI, reporting calendarSponsor approval
Scope and inventoryDiscover systems, data, models, agents, suppliers and jurisdictionsInventory, boundary, profile, SoAScope approval
AssessmentAssess design, implementation, operation and effectivenessGap register, risk ratings, evidence indexBaseline accepted
RemediationPrioritize, fund, implement and validate actionsRoadmap, budget, closure evidenceCritical gaps closed
AssuranceTest, sample, challenge and management-review controlsReadiness report, findings, risk decisionsProceed/defer decision
SustainmentOperate metrics, incidents, suppliers, evidence and improvementOperating dashboard and review recordsBAU acceptance

Resource and Competence Planning

The adoption plan should estimate effort by system count, control applicability, supplier dependence, evidence maturity and remediation complexity. Competence plans should cover AI engineering, cybersecurity, privacy, risk, safety, assurance and relevant sector obligations.

Role familyMinimum competence
Executive and riskAI risk, accountability, claims and residual-risk decisions
Architecture and engineeringModel, data, agent, platform and secure lifecycle controls
OperationsMonitoring, incident, change and evidence procedures
AssuranceSampling, technical testing, nonconformity and independence
Legal/complianceJurisdiction, contractual and sector obligations

Adoption Business Case

  • Baseline risk and customer/regulatory drivers
  • Cost of current fragmented controls and duplicated assurance
  • Expected implementation and operating cost
  • Commercial, resilience and trust benefits
  • Dependencies, constraints and residual uncertainty
  • Decision points for staged funding

Stakeholder Engagement Plan

StakeholderEngagement need
Board/executivesMaterial risk, resources and assurance decisions
Product/system ownersScope, acceptable use and control ownership
Engineering/operationsMechanisms, evidence and monitoring
Legal/privacy/safetyApplicable obligations and constraints
Procurement/suppliersContract, inherited controls and notification
Users/affected personsDisclosure, feedback, recourse and human factors

Sample Adoption Scenario

A mid-size enterprise beginning with an internal generative-AI assistant should first scope the assistant, model provider, retrieval data, user population and supporting cloud services. It should choose the intended profile, assign owners, assess the full applicable catalogue, contain high-risk data and tool access, build operating evidence over a representative period, and only then decide whether to seek certification.

The Foundational profile comprises 52 controls across all nine domains, as enumerated in the controlled conformance profile. Seven controls are excluded from that profile; the exclusions are not equivalent to excluding the D9 domain.

Publication Completeness and Intended Use

This full publication edition of GAISSF-IMP-009 is designed to stand on its own for its stated role: comprehensive program establishment and adoption planning. It includes purpose, scope, governance, operating guidance, evidence expectations, limitations, decision criteria and reusable records appropriate to that role.

Completeness does not mean that the document replaces the normative control statements, applicable law, sector-specific engineering, organizational procedures or professional judgement. Cross-referenced GAISSF documents remain part of the controlled document system.

Completeness dimensionTreatment in this edition
Normative alignmentReconciled to the authoritative 59-control baseline and controlled profile structure.
Operational usabilityIncludes roles, workflows, gates, evidence, metrics, escalation and examples where relevant.
TraceabilityIdentifies dependencies and preserves the distinction between requirements, guidance and examples.
LimitationsStates what the document does not establish or guarantee.
MaintenanceIncludes review triggers, change control and publication status.

How to use this document

ReaderRecommended use
Executive or board readerReview purpose, decision rights, legal and regulatory integration, limitations and Notably Absent sections.
Program or control ownerUse workflows, templates, gates, evidence fields and escalation criteria as implementation aids.
Engineering or operations teamTranslate guidance into system-specific procedures, configurations, runbooks and testable acceptance criteria.
Legal, privacy or compliance teamValidate jurisdiction-specific obligations, deadlines, retention, disclosure, privilege and regulator-facing requirements.
Assessor or auditorUse the document as informative context only; test claims against the authoritative normative sources and applicable assessment criteria.

See Also

  • GAISSF-NOR-001 and the controlled conformance profile.
  • GAISSF-IMP-010 for operational implementation.
  • GAISSF-IMP-017 for evidence and preservation.

Adoption-specific regulatory enhancements

Legal and Regulatory Obligations Register

FieldRequired content
Obligation identifierUnique identifier and source citation.
Jurisdiction and authorityCountry, state, sector and competent authority.
Applicability rationaleWhy the obligation applies or does not apply.
Affected scopeSystems, business activities, locations, suppliers and populations.
Responsible ownerAuthorized legal, privacy, compliance or regulatory owner.
Deadline or clockReporting, response, review or remediation timing.
Retention and preservationApplicable schedule, legal hold and disposal constraints.
GAISSF relationshipRelevant controls, evidence and known non-equivalence.
Decision and uncertaintyInterpretation, unresolved issue, exception and approval.
Review triggerLegal change, material system change, incident or periodic review.

Board and delegated-committee oversight evidence

  • Record information supplied, material risks, unresolved obligations, remediation funding and decision rationale.
  • Preserve minutes, dissent, management attestations and escalation of overdue high-risk matters.
  • Obtain jurisdiction-specific advice on director, officer and senior-management duties; GAISSF does not define those duties or the legal standard of care.

Retention governance

Retention periods shall be derived from applicable law, contracts, limitation periods, regulator expectations, litigation holds and business requirements. Generic periods shall not be treated as universally applicable.

Adoption measures and engagement cadence

OutcomeIllustrative measure
Scope controlled100% of in-scope systems have approved boundary, owner and jurisdiction record.
Controls owned100% of applicable controls have accountable and operating owners.
Evidence managedTarget percentage of required evidence is current, attributable and indexed.
Remediation fundedHigh-risk actions have approved owners, dates and resources.
Oversight activeMaterial legal and control issues are reported at the approved cadence.

Illustrative engagement: monthly executive risk briefing; biweekly program steering; weekly system-owner implementation review; event-driven legal and regulatory escalation. Cadence shall be tailored to risk.

Notably Absent — legal and regulatory boundary

  • No assertion that weak AI governance automatically creates personal liability or permits corporate-veil piercing.
  • No universal retention period.
  • No permission to select a profile solely by convenience or desired certificate scope.
  • No claim that GAISSF establishes fiduciary duties or a legal standard of care.

Publication revision record

RevisionDisposition
R2 — Regulatory and practitioner refinementAdded legal and regulatory integration, preservation, reporting, decision-record, public-claim and usability guidance. No normative GAISSF control was added, removed, renamed or amended.
Authority boundaryGAISSF-NOR-001, GAISSF-NOR-004 and controlled profile records remain authoritative.