GAISSF DOCUMENTATION

Quick Start Guide

Public GAISSF v1.0 publication reproduced as accessible HTML from the final source document.

GAISSF™ v1.0

Quick Start Guide

Global AI Security & Safety Framework

Document IDGAISSF-NOR-003
Version1.0
StatusFinal Publication v1.0
ClassificationInformative
Publication date1 July 2026
PublisherODA3 Institute

Authoritative control baseline: 59 controls across nine domains. Canonical Foundational scope: 52 controls. Additional physical-AI controls: 7.

Document Control

Document titleGAISSF™ v1.0 Quick Start Guide
Document IDGAISSF-NOR-003
Version1.0
StatusFinal Publication v1.0
ClassificationInformative
PublisherODA3 Institute
Legal entityODA3 Pvt Ltd
Authoritative sourceGAISSF-NOR-001
Control baseline59 controls across D1-D9
Foundational scope52 controls (D1-D8)
Additional controls7 physical-AI controls (D9)
SupersedesEarlier 45-control generated draft; withdrawn
Publication date1 July 2026

Precedence Statement

This guide provides implementation guidance only. It does not create or modify GAISSF requirements. Use GAISSF-NOR-001 and GAISSF-NOR-004 for authoritative requirements and control records.

1. Rapid Onboarding Sequence

StepAction
1Appoint an executive sponsor and implementation lead.
2Define the organizational, system, data, supplier and deployment boundary.
3Create an inventory of AI systems and dependencies.
4Select the target conformance tier.
5Prepare a 59-control Statement of Applicability.
6Assess the 52 canonical Foundational controls first.
7Determine whether physical-world influence, cyber-physical actuation, or safety-relevant autonomous control is within scope. If so, assess all applicable D9 controls as mandatory additions to the selected baseline.
8Assign control owners and evidence custodians.
9Perform evidence-based gap assessment and remediation.
10Conduct internal readiness review before independent assessment.

2. Scope Decision

Document legal entities, business units, AI systems, models, datasets, agents, tools, APIs, third parties, interfaces, environments and excluded components. An exclusion should be supported by a risk-based justification and should not remove a dependency that materially affects the assessed system.

3. Select the Conformance Path

PathControlsUse
Foundational52 controls: D1-D8Canonical starting baseline
Operational59 controls: D1-D9Full framework coverage
Optimized59 controls plus continuous monitoringHigher-assurance sustained operation

The seven D9 controls are not part of the canonical Foundational scope, but they become applicable where physical AI, robotics, autonomous actuation, operational technology or cyber-physical effects are in scope.

4. Build the Statement of Applicability

Required fieldExample
Control IDD1-CTL-01
ApplicabilityApplicable
JustificationTraining data used within assessed boundary
Implementation statusImplemented / Partially implemented / Not implemented
Evidence referenceEVD-D1-01-001
OwnerModel Security Lead
Exception or risk acceptanceNone / reference
Last reviewYYYY-MM-DD

5. Evidence Starter Set

Create an evidence index that links each applicable control to policies, system records, configurations, logs, test results, approvals, supplier records, incident records and corrective actions. Preserve original timestamps, signatures, hashes and chain-of-custody information where relevant.

6. First 30/60/90 Days

PeriodPriority outcomes
Days 1-30Sponsor, scope, inventory, tier decision, SoA structure, owners
Days 31-60Gap assessment, evidence collection, priority remediation, exception governance
Days 61-90Operating evidence, internal testing, corrective actions, readiness review

7. Common Failure Modes

Common failures include counting policies as operating evidence, omitting supplier dependencies, treating the 52-control Foundational scope as optional sampling, ignoring D9 applicability, using maturity scores to conceal nonconformity, accepting indefinite exceptions, and making certification claims broader than the assessed boundary.

8. Foundational Control Checklist — 52 Controls

Control IDControl titleOwnerStatusEvidence reference
D1-CTL-01DATASET PROVENANCE & POISONING PREVENTION
D1-CTL-02MODEL EXTRACTION RESISTANCE
D1-CTL-03BEHAVIORAL DRIFT DETECTION
D1-CTL-04FEDERATED LEARNING POISONING PREVENTION
D1-CTL-05EMBEDDING SPACE ROBUSTNESS
D1-CTL-06POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING
D1-CTL-07LORA/ADAPTER INTEGRITY VERIFICATION
D1-CTL-08MODEL MERGE ATTACK DETECTION
D1-CTL-09QUANTIZATION BACKDOOR SCREENING
D2-CTL-01DIRECT PROMPT INJECTION PREVENTION
D2-CTL-02INDIRECT PROMPT INJECTION PREVENTION
D2-CTL-03JAILBREAK RESISTANCE TESTING
D2-CTL-04MULTI-MODAL INJECTION DEFENSE
D2-CTL-05FUNCTION CALL/TOOL CALL INJECTION PREVENTION
D2-CTL-06CROSS-CONTEXT HIJACKING MITIGATION
D3-CTL-01LEAST AGENCY ENFORCEMENT
D3-CTL-02INTER-AGENT COMMUNICATION SECURITY
D3-CTL-03AGENTIC PROMPT CHAINING DETECTION
D3-CTL-04EMBODIED AI SAFETY CONTROLS
D3-CTL-05MULTI-AGENT TRUST CHAIN ATTESTATION
D3-CTL-06PERSISTENT MEMORY EXFILTRATION PREVENTION
D3-CTL-07SECURE MEMORY LIFECYCLE MANAGEMENT
D4-CTL-01AI BILL OF MATERIALS (AI BOM) MAINTENANCE
D4-CTL-02MODEL FILE & ARTIFACT SCANNING
D4-CTL-03MODEL HUB & REGISTRY VETTING
D4-CTL-04MCP SERVER BEHAVIORAL MONITORING
D4-CTL-05THIRD-PARTY AI API SECURITY ASSESSMENT
D4-CTL-06SHADOW AI DISCOVERY & GOVERNANCE
D4-CTL-07AI SOFTWARE COMPOSITION ANALYSIS (SCA)
D5-CTL-01HARMFUL CONTENT BLOCKING
D5-CTL-02PII LEAKAGE PREVENTION
D5-CTL-03COPYRIGHT DETECTION
D5-CTL-04AI WATERMARKING ROBUSTNESS
D5-CTL-05PRIVACY-BY-DESIGN VERIFICATION
D5-CTL-06PRIVACY-PRESERVING ML VALIDATION
D6-CTL-01HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS
D6-CTL-02AUDIT TRAIL COMPLETENESS
D6-CTL-03AI MODEL CARD COMPLETENESS
D6-CTL-04AI INCIDENT RESPONSE READINESS
D6-CTL-05MODEL DEPRECATION & DECOMMISSIONING
D6-CTL-06THIRD-PARTY AI VENDOR GOVERNANCE
D6-CTL-07AI RESILIENCE & BUSINESS CONTINUITY
D7-CTL-H01AI-GENERATED PHISHING SIMULATION
D7-CTL-H02DEEPFAKE DETECTION TRAINING
D7-CTL-H03OUT-OF-BAND AUTHENTICATION
D7-CTL-H04AI SOCIAL ENGINEERING IR
D7-CTL-H05AI-ENHANCED EXTERNAL ATTACK DEFENSE
D8-CTL-01EU AI ACT RISK TIER MAPPING
D8-CTL-02ISO 42001 GAP ANALYSIS
D8-CTL-03GPAI TECHNICAL DOCUMENTATION VERIFICATION
D8-CTL-04DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)
D8-CTL-05NIST SP 800-218A COMPLIANCE CHECK

9. Additional Physical-AI Checklist — 7 Controls

Control IDControl titleApplicability decisionStatusEvidence reference
D9-CTL-01PHYSICAL HARM BOUNDARY ENFORCEMENT
D9-CTL-02SAFE STATE AND GRACEFUL DEGRADATION
D9-CTL-03HUMAN OVERRIDE AND EMERGENCY STOP
D9-CTL-04CYBER-PHYSICAL ATTACK DETECTION
D9-CTL-05PHYSICAL ENVIRONMENT INTEGRITY MONITORING
D9-CTL-06ACTUATOR COMMAND VERIFICATION
D9-CTL-07PHYSICAL INCIDENT EVIDENCE PRESERVATION

10. Readiness Gate

Do not proceed to certification assessment until scope is approved, all applicable controls are represented in the SoA, required evidence is available, tests have been executed, major gaps are closed, exceptions are valid and time-bound, and public claims are controlled. Certification may be offered or claimed only under a separately issued GAISSF certification scheme, assessment rules and claims policy.

Annex A — Complete 59-Control Reference

Control Index

Control IDControl titleDomainFoundational scope
D1-CTL-01DATASET PROVENANCE & POISONING PREVENTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-02MODEL EXTRACTION RESISTANCED1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-03BEHAVIORAL DRIFT DETECTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-04FEDERATED LEARNING POISONING PREVENTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-05EMBEDDING SPACE ROBUSTNESSD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-06POST-QUANTUM MODEL SIGNING & CRYPTO HARDENINGD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-07LORA/ADAPTER INTEGRITY VERIFICATIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-08MODEL MERGE ATTACK DETECTIOND1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D1-CTL-09QUANTIZATION BACKDOOR SCREENINGD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESSYes
D2-CTL-01DIRECT PROMPT INJECTION PREVENTIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-02INDIRECT PROMPT INJECTION PREVENTIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-03JAILBREAK RESISTANCE TESTINGD2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-04MULTI-MODAL INJECTION DEFENSED2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-05FUNCTION CALL/TOOL CALL INJECTION PREVENTIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D2-CTL-06CROSS-CONTEXT HIJACKING MITIGATIOND2: RUNTIME SECURITY & ADVERSARIAL DEFENSEYes
D3-CTL-01LEAST AGENCY ENFORCEMENTD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-02INTER-AGENT COMMUNICATION SECURITYD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-03AGENTIC PROMPT CHAINING DETECTIOND3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-04EMBODIED AI SAFETY CONTROLSD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-05MULTI-AGENT TRUST CHAIN ATTESTATIOND3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-06PERSISTENT MEMORY EXFILTRATION PREVENTIOND3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D3-CTL-07SECURE MEMORY LIFECYCLE MANAGEMENTD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITYYes
D4-CTL-01AI BILL OF MATERIALS (AI BOM) MAINTENANCED4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-02MODEL FILE & ARTIFACT SCANNINGD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-03MODEL HUB & REGISTRY VETTINGD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-04MCP SERVER BEHAVIORAL MONITORINGD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-05THIRD-PARTY AI API SECURITY ASSESSMENTD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-06SHADOW AI DISCOVERY & GOVERNANCED4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D4-CTL-07AI SOFTWARE COMPOSITION ANALYSIS (SCA)D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITYYes
D5-CTL-01HARMFUL CONTENT BLOCKINGD5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-02PII LEAKAGE PREVENTIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-03COPYRIGHT DETECTIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-04AI WATERMARKING ROBUSTNESSD5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-05PRIVACY-BY-DESIGN VERIFICATIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D5-CTL-06PRIVACY-PRESERVING ML VALIDATIOND5: CONTENT SAFETY & OUTPUT INTEGRITYYes
D6-CTL-01HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-02AUDIT TRAIL COMPLETENESSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-03AI MODEL CARD COMPLETENESSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-04AI INCIDENT RESPONSE READINESSD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-05MODEL DEPRECATION & DECOMMISSIONINGD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-06THIRD-PARTY AI VENDOR GOVERNANCED6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D6-CTL-07AI RESILIENCE & BUSINESS CONTINUITYD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHTYes
D7-CTL-H01AI-GENERATED PHISHING SIMULATIOND7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H02DEEPFAKE DETECTION TRAININGD7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H03OUT-OF-BAND AUTHENTICATIOND7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H04AI SOCIAL ENGINEERING IRD7: HUMAN & SOCIETAL HARMSYes
D7-CTL-H05AI-ENHANCED EXTERNAL ATTACK DEFENSED7: HUMAN & SOCIETAL HARMSYes
D8-CTL-01EU AI ACT RISK TIER MAPPINGD8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-02ISO 42001 GAP ANALYSISD8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-03GPAI TECHNICAL DOCUMENTATION VERIFICATIOND8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-04DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)D8: REGULATORY ALIGNMENT & COMPLIANCEYes
D8-CTL-05NIST SP 800-218A COMPLIANCE CHECKD8: REGULATORY ALIGNMENT & COMPLIANCEYes
D9-CTL-01PHYSICAL HARM BOUNDARY ENFORCEMENTD9: PHYSICAL AI SAFETYNo — apply where physical AI is in scope
D9-CTL-02SAFE STATE AND GRACEFUL DEGRADATIOND9: PHYSICAL AI SAFETYNo — apply where physical AI is in scope
D9-CTL-03HUMAN OVERRIDE AND EMERGENCY STOPD9: PHYSICAL AI SAFETYNo — apply where physical AI is in scope
D9-CTL-04CYBER-PHYSICAL ATTACK DETECTIOND9: PHYSICAL AI SAFETYNo — apply where physical AI is in scope
D9-CTL-05PHYSICAL ENVIRONMENT INTEGRITY MONITORINGD9: PHYSICAL AI SAFETYNo — apply where physical AI is in scope
D9-CTL-06ACTUATOR COMMAND VERIFICATIOND9: PHYSICAL AI SAFETYNo — apply where physical AI is in scope
D9-CTL-07PHYSICAL INCIDENT EVIDENCE PRESERVATIOND9: PHYSICAL AI SAFETYNo — apply where physical AI is in scope

Controlled Profile Reconciliation Notice

The Foundational profile comprises the 52 canonical controls in D1-D8. The seven D9 controls are additional mandatory controls whenever physical AI or cyber-physical actuation is within the assessed scope.

Any earlier wording that described the Foundational profile as spanning all nine domains, or that treated D9 as universally mandatory or universally excluded, is superseded by this statement. D9 applicability shall be determined and justified for every assessed scope.

Complete Quick-Start Sequence

StepActionOutput
1Appoint sponsor and program leadApproved mandate and charter
2Create AI inventorySystem, model, data, agent and supplier register
3Define scopeApproved organizational and system boundary
4Select conformance profileVersion-controlled profile and SoA
5Assign ownersRACI and control-owner register
6Assess all applicable controlsGap and risk register
7Contain critical exposureInterim safeguards and executive decisions
8Build remediation roadmapFunded plan with owners and dates
9Establish evidence repositoryEvidence index and retention rules
10Operate and monitorControl-health dashboard and incidents
11Perform internal assuranceReadiness report and corrective actions
12Decide certification pathApproved external-assessment plan

First Assessment Workshop

  • Bring system, security, data, legal, risk, privacy, safety, procurement and operations representatives.
  • Review scope before discussing scores.
  • Use exact control text and evidence requirements.
  • Record disagreements and assumptions rather than forcing consensus.
  • End with owners, actions, dates and escalation decisions.

Minimum Viable Evidence Pack

Evidence classMinimum examples
GovernanceCharter, scope, inventory, RACI, risk decisions
ArchitectureData flows, trust boundaries, model and supplier dependencies
TechnicalConfigurations, evaluation results, scans, logs and release records
OperationalTickets, reviews, incidents, access records and monitoring
AssuranceTest plan, samples, findings, corrective actions and management review

The Foundational profile comprises the 52 canonical controls in D1-D8. The seven D9 controls are additional mandatory controls whenever physical AI or cyber-physical actuation is within the assessed scope.

Publication Completeness and Intended Use

This full publication edition of GAISSF-NOR-003 is designed to stand on its own for its stated role: rapid but complete onboarding and initial adoption sequence. It includes purpose, scope, governance, operating guidance, evidence expectations, limitations, decision criteria and reusable records appropriate to that role.

Completeness does not mean that the document replaces the normative control statements, applicable law, sector-specific engineering, organizational procedures or professional judgement. Cross-referenced GAISSF documents remain part of the controlled document system.

Completeness dimensionTreatment in this edition
Normative alignmentReconciled to the authoritative 59-control baseline and controlled profile structure.
Operational usabilityIncludes roles, workflows, gates, evidence, metrics, escalation and examples where relevant.
TraceabilityIdentifies dependencies and preserves the distinction between requirements, guidance and examples.
LimitationsStates what the document does not establish or guarantee.
MaintenanceIncludes review triggers, change control and publication status.

Evidence-State and Reassessment Rules

Configuration, policy, architecture, and deployment records demonstrate design or implementation. They do not, by themselves, demonstrate sustained operating effectiveness. Period-of-operation evidence shall cover a duration and event population appropriate to the control, risk, deployment stage, and assessment objective; no universal 30-day threshold applies to every control.

Material changes to the assessed system, model, data, prompts, tools, privileges, deployment context, suppliers, interfaces, intended use, or physical-actuation capability shall trigger documented impact analysis. Where applicability, risk, implementation, or evidence requirements may have changed, the affected Statement of Applicability entries shall be reassessed.