GETTING STARTED

Getting started

A practical path for understanding and adopting the framework suite.

Read in this order

  1. Review the suite architecture and framework boundaries.
  2. Identify the framework relevant to your immediate objective.
  3. Review domain summaries before individual controls or fields.
  4. Determine applicability and evidence requirements.
  5. Run a scoped pilot before asserting conformance or readiness.

Audience paths

CISO / ARCHITECT

Control and response design

Start with GAISSF domains, then AI-IRF response controls and UAIF incident fields.

GOVERNANCE / COMPLIANCE

Scope and assurance

Start with GAISSF, assessment methodology, evidence and crosswalk limitations.

SOC / IR

Incident operations

Start with UAIF classification and AI-IRF operational domains.

DEVELOPER / TOOL VENDOR

Machine implementation

Start with schemas, profiles, validation rules and examples.

Scoping your first assessment

Scope is determined by the system's profile, not by the certificate an organization would prefer to hold. Three factors drive which GAISSF controls apply and which certification tier is realistic:

01

System capability and exposure

Internally facing versus externally facing deployment, autonomy level, tool-call and data access, and modality (text, voice, image, video, code).

02

Architecture and data flow

Deployment model, model and infrastructure providers, data ingress/egress, persistence points and third-party AI dependencies.

03

Assurance ambition

Whether the organization is scoping to Foundational Attestation, Operational Certification or Optimized Certification, and which optional controls it elects beyond the mandatory baseline.

Before commissioning an assessor, document: the systems in scope and out of scope with justification; the applicable GAISSF conformance profile (Appendix P.1 SMB Quick-Start or the full domain set); existing compliance certifications the system already holds (e.g. ISO/IEC 42001, SOC 2); and who holds decision authority for exceptions. This scoping record becomes the first item in the evidence file — see Evidence for evidence-tier and provenance requirements, and Assessment methodology for how scope moves into testing and findings.

Adoption gates

Do not publish conformance, certification or regulatory claims until scope, licensing, marks, assessment rules and evidence have been reviewed under the applicable programme instruments.

Common questions

Adoption, scoping, evidence and certification questions that recur across audiences are answered in full in the Frequently Asked Questions, including document hierarchy, profile selection, agentic and physical-AI applicability, and claims discipline.

Day-one adoption path

Begin with one bounded AI system, one accountable owner and one documented operating boundary—not an organization-wide compliance claim. This creates a repeatable pattern that can scale across business units, sectors and jurisdictions.

01 · CHARTER

Name the system and owner

Record purpose, users, consequential outcomes and accountable technical, business and incident owners.

02 · BOUND

Map capability and exposure

Document models, agents, tools, data, providers, regions, autonomy, interfaces and explicit exclusions.

03 · PROFILE

Select applicable controls

Start with the baseline, add capability and sector triggers, and record each non-applicability decision.

04 · EVIDENCE

Build the evidence register

Assign owner, source, collection method, retention and freshness to every required evidence item.

05 · VALIDATE

Test control behaviour

Use design review, inspection, observation and adversarial testing; record failures and uncertainty.

06 · OPERATE

Exercise response

Classify a scenario with UAIF, run AI-IRF, preserve evidence and verify decision authority.

07 · IMPROVE

Close and retest

Prioritize findings, capture remediation evidence, retest and log accepted residual risk.

08 · SCALE

Reuse the pattern

Scale only after the pilot assumptions, limitations and notably absent outcomes are documented.

A practical first 30 days

Days 1–5

Scope

Approve the charter, boundary, responsibility matrix and GEL use-path review.

Days 6–12

Profile

Determine baseline, conditional and sector controls; map safeguards and gaps.

Days 13–21

Test

Collect provenance-bearing evidence, validate controls and conduct an incident exercise.

Days 22–30

Decide

Issue internal findings, remediation and a scale/no-scale decision without implying certification.

Global adoption discipline

Maintain one canonical control and evidence model, then add jurisdiction and sector overlays. Crosswalks inform applicability; they do not prove legal compliance.

Minimum pilot deliverables

□ System and data-flow boundary
□ AI asset and dependency inventory
□ Applicable-control profile
□ Roles and decision rights
□ Evidence register with provenance
□ Test plan and results
□ UAIF-classified scenario
AI-IRF exercise record
□ Findings and remediation register
□ Notably Absent statement

GEL v1.0 claims and access gate

Factual use language

“Uses,” “implements,” or “maps to” may be used only when factually supportable and consistent with GEL v1.0.

Separate authorization

Certification, conformity marks, badges, assessor status, endorsement and approval require the applicable instrument.

Never infer

Self-assessment, crosswalk or evidence collection is not certification and does not establish regulatory compliance.

Review GEL v1.0 before external publication, embedding, commercial representation or mark use.

Notably Absent

This guide does not assert that an ODA3 certification scheme, accredited assessor network, certification mark, regulatory approval or equivalence with another standard or law is presently available through this public portal.