GAISSF Ecosystem
ODA3 Institute's GAISSF Ecosystem is a four-framework operational assurance architecture connecting AI governance, incident classification, incident response and physical AI security.
Four connected frameworks. One operational assurance architecture.
AI governance, incident management, physical-AI security, and assurance are often addressed through separate programmes, terminology, and evidence. The ODA3 ecosystem connects them through shared requirements, structured information, bounded evidence, and operational feedback.
Governance to Controls
GAISSF™ translates organizational AI security and safety expectations into structured control requirements, implementation guidance, and evidence considerations.
Intended value
- Clearer ownership and implementation expectations
- Traceability from governance requirements to operational controls
- A structured basis for evidence-ready implementation
Incidents to Response
UAIF™ provides a common incident-classification and taxonomy foundation, while AI-IRF™ structures the corresponding preparation, response, recovery, and improvement activities.
Intended value
- Consistent incident identification and classification
- Structured response and recovery workflows
- Better continuity between incident records, decisions, and evidence
Implementation to Assurance
ODA3 Institute’s assurance and evidence methods are designed to examine implementation against documented criteria and defined evidence requirements.
Intended value
- Evidence linked to defined implementation expectations
- Traceable identification of gaps and limitations
- Bounded assurance conclusions tied to documented scope and evidence
One ecosystem, defined scope
GAISSF™, UAIF™, AI-IRF™, and PAI-SF™ are designed to operate as connected components without implying regulatory approval, guaranteed compliance, or certification beyond documented operational scope.
For vendor-neutral movement of governance context and operational evidence across enterprise platforms, see the Platform Interoperability Guide.
Four-framework model
GAISSF is the umbrella governance and assurance framework. UAIF standardizes AI incident classification and evidence context, while AI-IRF structures response, recovery, and operational learning. PAI-SF extends the assurance architecture where AI-enabled sensing, autonomy, command, or actuation can produce physical effects. The four frameworks remain distinct by function but share governance, evidence, incident, and improvement interfaces.
GAISSF
Defines governance requirements, security controls, evidence expectations and assurance outcomes.
UAIF
Provides a standardized model for identifying, classifying and exchanging AI security incident information.
AI-IRF
Guides containment, investigation, recovery, communication and continuous improvement following AI security incidents.
PAI-SF
Extends the assurance architecture to physical-AI systems where sensing, autonomy, communications and actuation can produce real-world effects.
Architecture relationship: GAISSF governs the full lifecycle; UAIF standardizes incident information; AI-IRF uses that information to drive containment, investigation, recovery, communication and learning; and PAI-SF applies specialized physical-AI security controls where digital decisions can produce or influence real-world effects.
How the frameworks depend on one another
| Layer | Framework | Primary purpose | Relationship |
|---|---|---|---|
| 01 / GOVERN | GAISSF | Governance, controls, assurance and evidence requirements | Provides the governance and assurance baseline; governs the interfaces used by UAIF and AI-IRF and provides the continuity point for PAI-SF physical-AI requirements. |
| 02 / CLASSIFY | UAIF | Incident identification, classification and exchange | Creates consistent incident context and evidence for AI-IRF. |
| 03 / RESPOND | AI-IRF | Incident response, recovery and operational learning | Consumes UAIF classifications and feeds lessons back into GAISSF controls. |
| 04 / PHYSICAL AI | PAI-SF | Physical-AI security and safety assurance | Applies specialized physical-AI security controls where AI decisions can drive or influence physical actions, while relevant incidents continue through UAIF classification and AI-IRF response. |
Operational information flow
- GAISSF establishes governance requirements, control objectives, evidence expectations and accountability.
- PAI-SF extends the applicable security architecture where AI-enabled sensing, autonomy, command or actuation can create physical consequence.
- UAIF identifies and structures material AI incidents using a common classification, causality and evidence model.
- AI-IRF uses the UAIF incident record to guide containment, investigation, recovery, communication and operational learning.
- Implementation evidence, incident findings and lessons return to the applicable GAISSF/PAI-SF controls as inputs to validation, remediation and assurance improvement.
Framework boundaries
The frameworks are deliberately separated by function. GAISSF is not an incident taxonomy, UAIF is not a response playbook, AI-IRF is not an enterprise governance framework, and PAI-SF is not a replacement for functional safety or sector approval. Their integration creates a connected operating architecture without stretching any one framework beyond its intended scope.