Change Log
Public GAISSF v1.0 publication reproduced as accessible HTML from the final source document.
GAISSF™ v1.0
Change Log
Historical Traceability, Version History and Decision Record
| Field | Value |
|---|---|
| Document ID | GAISSF-NOR-008 |
| Version | 1.0 |
| Status | Final Publication v1.0 |
| Classification | Normative change and decision register |
| Publisher | ODA3 Institute |
| Legal entity | ODA3 Pvt Ltd |
| Framework baseline | GAISSF™ v1.0 — 59 controls across nine domains |
| Publication date | 1 July 2026 |
| Historical cut-off | 1 July 2026 |
This register records approved changes, rejected options, corrective actions, supersession, downstream impacts and matters explicitly unchanged. It is not a substitute for the normative requirements in GAISSF-NOR-001.
Document Control
| Attribute | Controlled value |
|---|---|
| Title | GAISSF™ v1.0 Change Log |
| Document ID | GAISSF-NOR-008 |
| Purpose | Historical traceability of versions, decisions, corrections and downstream impacts |
| Normative authority | Normative for change identifiers, status, decision provenance, supersession and change classification |
| Primary source records | GAISSF v1.0 source; ODA3-2026-06-MTH-GOV-034; GAISSF-NOR-007 |
| Precedence | GAISSF-NOR-001 governs requirements; approved source decisions govern provenance |
| Retention | Permanent for the supported life of GAISSF v1.0 and successor releases |
| Distribution | Public release register, with sensitive evidence retained internally |
Copyright, Licensing and Reliance Notice
© 2026 ODA3 Pvt Ltd. Published market-facing by ODA3 Institute.
GAISSF™ is used as a framework mark. Third-party names and marks are used for identification only.
This document records change history and does not constitute legal, audit, certification or regulatory advice.
Where a change-log entry conflicts with the approved normative source, the approved normative source prevails and the discrepancy shall be corrected.
1. Purpose and Scope
This document maintains the controlled historical record for GAISSF v1.0. It records the origin of the release baseline, editorial and technical decisions, changes applied before publication, post-generation defects, corrective actions, superseded artifacts, and downstream reconciliation obligations.
The log shall be updated whenever a change affects requirements, control scope, control identifiers, evidence, certification, terminology, source references, implementation schemas, validation tests, public claims or publication status.
2. Change Governance Rules
- Every material change SHALL have a unique change identifier, decision owner, decision date, rationale, impact classification and verification status.
- Changes SHALL distinguish source corrections from downstream-document corrections.
- No control SHALL be added, removed, modified or renumbered without explicit approval and impact analysis.
- Rejected options and the reason for rejection SHALL be retained where material to later interpretation.
- Each entry SHALL state what did not change.
- Superseded artifacts SHALL remain identifiable for provenance but SHALL NOT remain in active publication channels.
- Open corrective actions SHALL NOT be described as completed until evidence of downstream reconciliation exists.
3. Change Classification
| Class | Definition | Typical version effect |
|---|---|---|
| Normative breaking | Changes an obligation, scope, control, evidence or certification outcome | Major release unless emergency correction |
| Normative compatible | Clarifies or adds controlled detail without invalidating conforming implementations | Minor or patch after impact review |
| Editorial | Corrects presentation, references or wording without semantic change | Patch or pre-publication correction |
| Corrective | Repairs an error that misrepresented the approved source | Patch, reissue or supersession |
| Administrative | Changes ownership, contact, status or publication metadata | Patch or no framework version change |
| Deprecation | Announces future removal or replacement | Minor or major release planning |
4. Authoritative Baseline Decisions
| Decision ID | Date | Decision | Rationale | Status |
|---|---|---|---|---|
| DEC-001 | 01 May 2026 | Confirm canonical D1-D8 Foundational scope and conditional D9 applicability | Replace unsupported “26-core” claim with the 52 canonical controls in D1-D8; retain a 9-control SMB Quick-Start onboarding pathway and apply D9 when physical AI is in scope | Approved and applied |
| DEC-002 | 01 May 2026 | Treat the edits as pre-publication v1.0 changes | The framework had not been externally published; no version bump was necessary | Approved |
| DEC-003 | 01 May 2026 | Assign ODA3-2026-06-MTH-GOV-034 to the editorial decision record | Preserve auditable decision provenance | Approved |
| DEC-004 | 01 May 2026 | Correct Appendix Q description | Actual content is six written sub-annexes plus a 13-sector matrix, not 14 complete annexes | Approved and applied |
| DEC-005 | 1 July 2026 | Preserve 59 controls unchanged | The control specifications were not changed by the Foundational-scope reconciliation | Confirmed |
5. Foundational Scope Provenance
The authoritative editorial decision record establishes the following v1.0 structure:
- 59 total testable controls across nine domains.
- 52 canonical controls in D1-D8 form the Foundational baseline.
- The seven D9 controls are additional to the canonical 52-control D1-D8 baseline and become mandatory whenever physical AI or cyber-physical actuation is within scope.
- All seven D9 Physical AI Safety controls remain applicable and mandatory where the assessed scope includes physical AI or cyber-physical actuation.
- 9-control SMB Quick-Start as an onboarding pathway, not the complete Foundational attestation scope.
- Operational scope of all 59 controls.
- Optimized scope of all 59 controls plus continuous monitoring.
Controlled interpretation: the 52-control Foundational profile is the canonical D1-D8 baseline. D9 is additional and conditionally mandatory; its applicability must be assessed and justified for every scope.
6. Detailed Historical Change Register
| ID | Date | Artifact/area | Change or event | Reason | Impact | Status |
|---|---|---|---|---|---|---|
| CHG-001 | Pre-publication | Executive summary | “26-core control pathway” introduced during drafting | Created an unsupported numeric claim | Superseded by DEC-001 | Closed |
| CHG-002 | 01 May 2026 | Executive briefing | Split Foundational into 9-control SMB Quick-Start and 52-control Full Attestation pathways | Align positioning with enumerable source content | No controls changed | Closed |
| CHG-003 | 01 May 2026 | Maturity model | Added canonical 52-control Foundational-scope clarification | Close certification-scope ambiguity | No new requirements authored | Closed |
| CHG-004 | 01 May 2026 | Appendix Q descriptions | Changed “14 sector annexes” to six written sub-annexes plus 13-sector matrix | Match delivered content | Sector content unchanged | Closed |
| CHG-005 | 01 May 2026 | Document control | Added editorial review entry | Record approval provenance | No normative change | Closed |
| CHG-006 | May-June 2026 | GISS profiles and schema | Installed 52-control canonical profile, seven exclusions and 9-control Quick-Start pathway | Machine-readable alignment | Control IDs preserved | Closed |
| CHG-007 | 1 July 2026 | NOR-001 to NOR-004 drafts | A reconstructed 45-control set was generated | Downstream authoring defect; not source-approved | Four documents invalidated | Superseded |
| CHG-008 | 1 July 2026 | NOR-001 to NOR-004 corrected editions | 59 controls restored | Repair omitted-control defect | Control count corrected | Partially closed |
| CHG-009 | 1 July 2026 | NOR-001, NOR-004 and NOR-007 tier wording | Foundational scope incorrectly described as D1-D8, with all D9 outside scope | Misinterpretation of editorial record | Requires corrected reissue and downstream review | Closed - corrected publication editions issued 1 July 2026 |
| CHG-010 | 1 July 2026 | NOR-005 and NOR-006 | Glossary and bibliography created | Terminology and source transparency | Must be checked against corrected scope language | Review required |
| CHG-011 | 1 July 2026 | NOR-008 | Change log created and scope discrepancy formally recorded | Prevent further propagation | No control changes | Current |
7. Corrective Action Register
| Action ID | Required action | Affected artifacts | Priority | Acceptance evidence | Status |
|---|---|---|---|---|---|
| CAR-001 | Replace D1-D8/D9-excluded Foundational wording with the approved 52-control D1-D8 baseline with conditional mandatory D9 applicability | NOR-001, NOR-004, NOR-007 | Critical | Corrected Word editions; text comparison; control-scope validation | Closed - corrected NOR-001, NOR-004 and NOR-007 publication editions; canonical wording reconciled |
| CAR-002 | Review NOR-002 and NOR-003 for any derived tier or D9 statements | NOR-002, NOR-003 | High | Signed review checklist and corrected editions if needed | Closed - NOR-002 and NOR-003 reviewed and corrected |
| CAR-003 | Review glossary definitions and abbreviation notes for tier consistency | NOR-005 | High | Terminology cross-check against MTH-GOV-034 and NOR-001 | Closed - NOR-005 terminology reconciled; no conflicting assessment-tier taxonomy introduced |
| CAR-004 | Review bibliography annotations that describe domain applicability | NOR-006 | Medium | Citation and domain-index review | Closed - NOR-006 annotations reviewed; source-tier distinction and national sources added |
| CAR-005 | Update release notes to disclose the Foundational-scope interpretation correction | NOR-007 | Critical | Reissued release notes with explicit migration notice | Closed - NOR-007 reissued with explicit scope and migration clarification |
| CAR-006 | Validate machine-readable profiles, schemas and VTS against the exact 52-control list | GISS, schemas, VTS | Critical | Automated enumeration and 59/52/7 reconciliation report | Transferred - technical-release gate; schemas and VTS require separate automated 59/52/7 validation before their publication |
| CAR-007 | Remove superseded 45-control and incorrect-scope documents from active channels | Website, GitHub, internal repositories | Critical | Publication inventory and link verification | Transferred - publication-operations gate; obsolete active-channel copies must be removed and link-verified before public posting |
8. Impact Analysis
| Stakeholder | Potential impact | Required response |
|---|---|---|
| Implementing organizations | Incorrect SoA or omission of applicable D9 controls | Reconcile SoA against the approved 52-control list and system scope |
| Assessors | Incorrect sampling universe or certification conclusion | Use approved control applicability and document any previous reliance |
| Certification scheme owner | Eligibility and scope statements may be inconsistent | Reissue controlled scheme materials |
| Tool and schema developers | Profiles may encode wrong exclusions | Run automated 59/52/7 control-set comparison |
| Training providers | Courseware may teach incorrect domain boundary | Correct materials, exams and instructor notes |
| Regulators and customers | Public claims may misstate coverage | Issue corrected statements where material |
| ODA3 Institute | Publication integrity and provenance risk | Maintain visible correction history and close CARs |
9. Supersession Register
| Artifact class | Superseded condition | Permitted use |
|---|---|---|
| Any 45-control GAISSF document | States or implements fewer than 59 source controls without explicit profile qualification | Historical evidence only |
| Any document stating Foundational = D1-D8 | Contradicts the approved editorial provenance | Historical evidence only pending correction |
| Any document stating all D9 controls are outside Foundational | Contradicts the approved editorial provenance | Historical evidence only pending correction |
| Any “26-core” Foundational claim | Unsupported by the v1.0 source | Historical provenance only |
| Corrected future editions | Explicitly reconcile to 59 total, 52 Foundational and seven listed exclusions | Active use after approval |
10. What Did Not Change
- The authoritative framework contains 59 controls.
- No control was added, removed, modified or renumbered by the 01 May 2026 editorial decision.
- Operational scope remains all 59 controls.
- Optimized scope remains all 59 controls plus continuous monitoring.
- The nine-control SMB Quick-Start remains an onboarding path rather than a certification-scope substitute.
- Trademark, licensing and GEL governance were not changed by the scope reconciliation.
- Sector annex content was not expanded by the editorial correction.
11. Notably Absent
- No evidence that a 45-control framework was ever approved as the GAISSF v1.0 source baseline.
- No approved decision permits D9 to be ignored where physical AI or cyber-physical actuation is in scope.
- The approved Foundational baseline is the 52 controls in D1-D8.
- No claim that correction of documentation defects changes the original 59 control specifications.
- No claim that certification guarantees security, safety, legality or absence of harm.
- No concealment of rejected options or downstream defects.
12. Verification and Closure Requirements
- Each open corrective action SHALL have an owner and target closure date in the internal tracker.
- Closure SHALL require source-to-output comparison, not only a keyword replacement.
- The exact seven Foundational exclusions SHALL be enumerated and validated against the source control records.
- All references to 52 controls SHALL be reviewed for semantic accuracy.
- Publication channels SHALL be checked for superseded copies and stale links.
- A final release-integrity report SHALL confirm 59 total controls, 52 Foundational controls, seven exclusions, and consistent scope statements across all artifacts.
Annex A — Change Request Record Template
| Field | Required content |
|---|---|
| Change ID | Unique identifier |
| Request date | Date raised |
| Requester | Role or function |
| Affected artifacts | Documents, schemas, tests, training or public claims |
| Change description | Exact current and proposed state |
| Classification | Breaking, compatible, editorial, corrective, administrative or deprecation |
| Rationale | Evidence and decision basis |
| Normative impact | Controls, scope, evidence, assessment or certification |
| Alternatives considered | Options and rejection reasons |
| Decision | Approved, rejected, deferred or withdrawn |
| Approver and date | Controlled approval record |
| Implementation evidence | Files, diffs, validation logs and publication checks |
| What did not change | Explicit non-change statement |
| Closure status | Open, implemented, verified or closed |
Annex B — Decision Record Summary
| Decision | Resolution | Evidence source |
|---|---|---|
| Foundational reconciliation | Option B adopted: 52-control Full Attestation plus 9-control SMB Quick-Start | ODA3-2026-06-MTH-GOV-034 |
| Version treatment | Pre-publication v1.0 edits; no version bump | ODA3-2026-06-MTH-GOV-034 |
| Total control baseline | 59 controls retained unchanged | GAISSF v1.0 source and editorial verification |
| Foundational distribution | 52 canonical controls in D1-D8; seven additional D9 controls where physical AI or cyber-physical actuation is in scope | Per-control implementation-by-tier records |
| D9 treatment | All seven D9 controls are additional mandatory requirements where physical AI or cyber-physical actuation is within the assessed scope | Editorial decision record |
| Downstream 45-control drafts | Invalid and superseded | Corrective review on 1 July 2026 |
| D1-D8/D9 split wording | Incorrect downstream interpretation; corrective action open | NOR-008 reconciliation review |
Annex C — Publication History
| Document version | Date | Change summary | Status |
|---|---|---|---|
| 1.0 | 1 July 2026 | Initial public change log; records pre-publication decisions, 45-control defect, restoration to 59 controls, and open correction of Foundational-scope wording | Final Publication v1.0 |
Controlled Profile Reconciliation Notice
The Foundational profile comprises the 52 canonical controls in D1-D8. The seven D9 controls are additional mandatory controls whenever physical AI or cyber-physical actuation is within the assessed scope.
Any earlier wording that described the Foundational profile as spanning all nine domains, or that treated D9 as universally mandatory or universally excluded, is superseded by this statement. D9 applicability shall be determined and justified for every assessed scope.
Decision Provenance Requirements
| Record element | Requirement |
|---|---|
| Issue | Describe the inconsistency, defect or change request. |
| Evidence | Identify source documents and affected requirements. |
| Options | Record viable alternatives and consequences. |
| Decision | State approved treatment and authority. |
| Impact | Identify affected documents, tools, assessments and claims. |
| Verification | Record completion and independent check. |
Historical Integrity Rules
- Do not delete material rejected decisions.
- Distinguish editorial correction from substantive change.
- Preserve superseded identifiers and dates.
- Record unresolved issues as open actions rather than implied completion.
The Foundational profile comprises the 52 canonical controls in D1-D8. The seven D9 controls are additional mandatory controls whenever physical AI or cyber-physical actuation is within the assessed scope.
Publication Completeness and Intended Use
This full publication edition of GAISSF-NOR-008 is designed to stand on its own for its stated role: historical traceability, decision provenance and corrective-action record. It includes purpose, scope, governance, operating guidance, evidence expectations, limitations, decision criteria and reusable records appropriate to that role.
Completeness does not mean that the document replaces the normative control statements, applicable law, sector-specific engineering, organizational procedures or professional judgement. Cross-referenced GAISSF documents remain part of the controlled document system.
| Completeness dimension | Treatment in this edition |
|---|---|
| Normative alignment | Reconciled to the authoritative 59-control baseline and controlled profile structure. |
| Operational usability | Includes roles, workflows, gates, evidence, metrics, escalation and examples where relevant. |
| Traceability | Identifies dependencies and preserves the distinction between requirements, guidance and examples. |
| Limitations | States what the document does not establish or guarantee. |
| Maintenance | Includes review triggers, change control and publication status. |
v1.0 Publication Closure Statement
The NOR-001 through NOR-008 controlled document set has been reconciled to 59 total controls, the 52-control D1-D8 canonical Foundational baseline, and seven additional D9 controls that become mandatory where physical AI or cyber-physical actuation is within scope.
Document-content corrective actions are closed in this edition. Machine-readable schemas, validation-test assets, repositories, websites, GitHub releases, and other distribution channels remain subject to their own technical and publication-operation release gates. This document does not claim those external gates have been completed.