GAISSF Ecosystem
A three-layer AI security framework suite connecting governance and assurance, standardized incident classification, and operational response.
Three critical connections. One operational assurance architecture.
AI governance, incident management, and assurance are often addressed through separate programmes, terminology, and evidence. The ODA3 ecosystem is designed to connect them through shared requirements, structured information, and assessment-ready implementation.
Governance to Controls
GAISSF™ translates organizational AI security and safety expectations into structured control requirements, implementation guidance, and evidence considerations.
Intended value
- Clearer ownership and implementation expectations
- Traceability from governance requirements to operational controls
- A structured basis for assessment-ready implementation
Launch announcement
Read the GAISSF Ecosystem launch announcement and Founder Note.
Incidents to Response
UAIF™ provides a common incident-classification and taxonomy foundation, while AI-IRF™ structures the corresponding preparation, response, recovery, and improvement activities.
Intended value
- Consistent incident identification and classification
- Structured response and recovery workflows
- Better continuity between incident records, decisions, and evidence
Implementation to Assurance
ODA3 Institute’s developing assessment methods and certification infrastructure are designed to evaluate implementation against documented criteria and evidence requirements.
Intended value
- Evidence linked to defined implementation expectations
- Traceable identification of gaps and limitations
- Attestation and certification pathways as capabilities become operational
One ecosystem, defined scope
GAISSF™, UAIF™, and AI-IRF™ are designed to operate as connected components without implying regulatory approval, guaranteed compliance, or certification beyond documented operational scope.
Three-layer model
GAISSF is the umbrella governance and assurance framework. It applies across the full lifecycle rather than ending when an incident is classified or response begins. UAIF provides the standardized incident information consumed by AI-IRF, while both operate within the governance, control, evidence, and accountability requirements established by GAISSF.
GAISSF
Defines governance requirements, security controls, evidence expectations and assurance outcomes.
UAIF
Provides a standardized model for identifying, classifying and exchanging AI security incident information.
AI-IRF
Guides containment, investigation, recovery, communication and continuous improvement following AI security incidents.
Architecture relationship: GAISSF governs the full lifecycle; UAIF standardizes incident information; and AI-IRF uses that information to drive containment, investigation, recovery, communication and learning.
How the frameworks depend on one another
| Layer | Framework | Primary purpose | Relationship |
|---|---|---|---|
| 01 / GOVERN | GAISSF | Governance, controls, assurance and evidence requirements | Governs UAIF and AI-IRF and receives improvement evidence from both. |
| 02 / CLASSIFY | UAIF | Incident identification, classification and exchange | Creates consistent incident context and evidence for AI-IRF. |
| 03 / RESPOND | AI-IRF | Incident response, recovery and operational learning | Consumes UAIF classifications and feeds lessons back into GAISSF controls. |
Operational information flow
- GAISSF establishes governance requirements, control objectives, evidence expectations and accountability.
- UAIF identifies and structures an AI security incident using a common taxonomy, severity model, causality and evidence model.
- AI-IRF uses the UAIF incident record to guide containment, investigation, recovery, communication and operational learning.
- Post-incident findings return to GAISSF as evidence for control validation, remediation and assurance improvement.
Framework boundaries
The frameworks are deliberately separated by function. GAISSF is not an incident taxonomy, UAIF is not a response playbook, and AI-IRF is not an enterprise governance framework. Their integration creates the complete operating model without stretching any one framework beyond its intended architecture.