Frameworks & tools

From governance principles to operational structures.

ITS frameworks translate hard governance questions into structures organisations can operate: what an AI system may do, on what evidence, within what limits, who can intervene, and how authority is withdrawn or restored.

Flagship framework
CI-AIGAF
Critical Infrastructure AI Governance & Assurance Framework · v1.0

Capability does not confer authority.

CI-AIGAF diagram: the evidence-to-authority chain, from practice, task and implementation through control objective, assurance claim, evidence, counterevidence, residual risk, decision and authority degradation: each consequential permission traceable to a requirement and supportable evidence.

CI-AIGAF answers one operational question before the technical ones: what is this AI-enabled service permitted to do, on what evidence, within what conditions, and what happens when those conditions stop being true?

It treats an AI system's operational authority as a bounded organisational decision backed by evidence, monitored in use, and withdrawn or restored deliberately, rather than a property that arrives automatically with capability. The public specification is written to be read from one question outward, without learning eighteen practices first.

CI-AIGAF is an independent ITS framework. It complements applicable law, regulation and standards; it is not itself a regulatory standard or certification scheme.

Sector implementation · Telecom / EU
CI-AIGAF EU-TEL
European Telecommunications Implementation · Beta

Applying the CI-AIGAF authority and evidence architecture to European telecommunications.

CI-AIGAF diagram: the distinction between what a system might do (claimed capability), what has been shown (evidence in the real operating context), and what it may do (formal permission within enforceable limits).

CI-AIGAF EU-TEL applies the core CI-AIGAF architecture to telecommunications in the European regulatory environment. It connects operational authority, evidence, human intervention and accountability with the obligations that affect telecom AI systems.

CI-AIGAF EU-TEL is a sector implementation of CI-AIGAF v1.0, currently in beta and open for feedback.

How a framework earns its authority

Produced from research, revised from evidence

A CI-AIGAF is not a fixed poster. It is the visible output of the ITS operating loop, and it stays open to revision when practice reveals something the research missed.

  1. Research

    An unresolved operational-governance problem is investigated in depth.

  2. Practitioner challenge

    Draft thinking is tested by operators, assurance, risk, security and legal practitioners.

  3. Public framework

    The strongest findings are codified into an open, readable specification.

  4. Organisational application

    The framework is applied through readiness reviews, tabletops and workshops.

  5. Evidence

    What implementation reveals is recorded, including where the framework falls short.

  6. Revision

    Evidence returns to research, and the framework is revised rather than frozen.

Evidence → Revision → Research ↻

Also from ITS

Governance tools

Interactive tool

AI Governance Elements Map

An interactive map of the elements of AI governance and how they relate, so you can locate where CI-AIGAF operates.

Open the Governance Map →
Put a framework to work

Turn the framework into organisational capability

A CI-AIGAF Readiness Review, workshop or tabletop translates the framework into your operations and evidence.