Getting started
A practical path for understanding and adopting the framework suite.
Read in this order
- Review the suite architecture and framework boundaries.
- Identify the framework relevant to your immediate objective.
- Review domain summaries before individual controls or fields.
- Determine applicability and evidence requirements.
- Run a scoped pilot before asserting conformance or readiness.
Audience paths
Control and response design
Start with GAISSF domains, then AI-IRF response controls and UAIF incident fields.
Scope and assurance
Start with GAISSF, assessment methodology, evidence and crosswalk limitations.
Incident operations
Start with UAIF classification and AI-IRF operational domains.
Machine implementation
Start with schemas, profiles, validation rules and examples.
Scoping your first assessment
Scope is determined by the system's profile, not by the certificate an organization would prefer to hold. Three factors drive which GAISSF controls apply and which certification tier is realistic:
System capability and exposure
Internally facing versus externally facing deployment, autonomy level, tool-call and data access, and modality (text, voice, image, video, code).
Architecture and data flow
Deployment model, model and infrastructure providers, data ingress/egress, persistence points and third-party AI dependencies.
Assurance ambition
Whether the organization is scoping to Foundational Attestation, Operational Certification or Optimized Certification, and which optional controls it elects beyond the mandatory baseline.
Before commissioning an assessor, document: the systems in scope and out of scope with justification; the applicable GAISSF conformance profile (Appendix P.1 SMB Quick-Start or the full domain set); existing compliance certifications the system already holds (e.g. ISO/IEC 42001, SOC 2); and who holds decision authority for exceptions. This scoping record becomes the first item in the evidence file — see Evidence for evidence-tier and provenance requirements, and Assessment methodology for how scope moves into testing and findings.
Adoption gates
Do not publish conformance, certification or regulatory claims until scope, licensing, marks, assessment rules and evidence have been reviewed under the applicable programme instruments.
Common questions
Adoption, scoping, evidence and certification questions that recur across audiences are answered in full in the Frequently Asked Questions, including document hierarchy, profile selection, agentic and physical-AI applicability, and claims discipline.
Day-one adoption path
Begin with one bounded AI system, one accountable owner and one documented operating boundary—not an organization-wide compliance claim. This creates a repeatable pattern that can scale across business units, sectors and jurisdictions.
Name the system and owner
Record purpose, users, consequential outcomes and accountable technical, business and incident owners.
Map capability and exposure
Document models, agents, tools, data, providers, regions, autonomy, interfaces and explicit exclusions.
Select applicable controls
Start with the baseline, add capability and sector triggers, and record each non-applicability decision.
Build the evidence register
Assign owner, source, collection method, retention and freshness to every required evidence item.
Test control behaviour
Use design review, inspection, observation and adversarial testing; record failures and uncertainty.
Exercise response
Classify a scenario with UAIF, run AI-IRF, preserve evidence and verify decision authority.
Close and retest
Prioritize findings, capture remediation evidence, retest and log accepted residual risk.
Reuse the pattern
Scale only after the pilot assumptions, limitations and notably absent outcomes are documented.
A practical first 30 days
Scope
Approve the charter, boundary, responsibility matrix and GEL use-path review.
Profile
Determine baseline, conditional and sector controls; map safeguards and gaps.
Test
Collect provenance-bearing evidence, validate controls and conduct an incident exercise.
Decide
Issue internal findings, remediation and a scale/no-scale decision without implying certification.
Maintain one canonical control and evidence model, then add jurisdiction and sector overlays. Crosswalks inform applicability; they do not prove legal compliance.
Minimum pilot deliverables
GEL v1.0 claims and access gate
“Uses,” “implements,” or “maps to” may be used only when factually supportable and consistent with GEL v1.0.
Certification, conformity marks, badges, assessor status, endorsement and approval require the applicable instrument.
Self-assessment, crosswalk or evidence collection is not certification and does not establish regulatory compliance.
Review GEL v1.0 before external publication, embedding, commercial representation or mark use.
Notably Absent
This guide does not assert that an ODA3 certification scheme, accredited assessor network, certification mark, regulatory approval or equivalence with another standard or law is presently available through this public portal.