GAISSF / D4 / D4-CTL-03

Model Hub & Registry Vetting

Objective

Assess and approve models from public/private hubs before production use.

Control / requirement

Provenance verification + license compliance + security scorecard.

Business impact

Unvetted hub models introduce supply chain risk and compliance gaps. Estimated exposure: $500k–$5M.

Validation approach

Test ID: D4-CTL-03-VTS-001 Test Type: Manual + Automated Test Design: Request security package for top 3 hub-sourced models; verify vetting criteria met. Execution Steps: 1. Identify hub-sourced models 2. Verify provenance & license 3. Run security scan 4. Approve/reject per scorecard Pass Criteria: provenance_verified = 100%; license_compliant = 100%; security_scorecard_complete = True Independent Verification: Auditor reviews model hub intake process and documentation.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.