ODA3 InstituteODA3 INSTITUTE
ODA3 InstituteODA3INSTITUTE
GAISSFGlobal AI Safety and Security FrameworkUAIFUnified AI Incident FrameworkAI-IRFAI Incident Response Framework
Start Here
HomeGetting StartedGAISSF EcosystemFramework ComparisonAbout ODA3
Library & Documentation
Documentation OverviewStandardsImplementation GuidanceReferenceFAQPublication CatalogDownloads CenterCrosswalksSector GuidanceSchema CenterCheat Sheet Library
Assurance
Assurance OverviewEvidenceAssessment MethodologyConformance
Research & Insights
Research ProgrammeResearch PublicationsInsights & AnalysisEvidence Methodology
Training
Training OverviewPlanned CurriculumRegister InterestFaculty & Research Team
Institute
PartnershipContact
Legal
GEL v1.0Privacy PolicyGrievance Redressal
Portal v1.0 © 2026 ODA3 Pvt Ltd
Home/Frameworks/GAISSF/Supply Chain & Third-Party Ai Security
GAISSF / D4

Supply Chain & Third-Party Ai Security

FrameworkGAISSF
Version1.0
Records7
StatusFinal Publication v1.0

Domain purpose

Controls and requirements

D4-CTL-01

Ai Bill Of Materials (Ai Bom) Maintenance

Maintain complete inventory of all AI models, datasets, dependencies, and third-party components.

↗
D4-CTL-02

Model File & Artifact Scanning

Detect malware, backdoors, and unsafe serialization in model files before deployment.

↗
D4-CTL-03

Model Hub & Registry Vetting

Assess and approve models from public/private hubs before production use.

↗
D4-CTL-04

Mcp Server Behavioral Monitoring

Monitor Model Context Protocol (MCP) servers for unauthorized tool access or anomalous behaviour.

↗
D4-CTL-05

Third-Party Ai Api Security Assessment

Evaluate third-party AI APIs for security, privacy, and compliance posture.

↗
D4-CTL-06

Shadow Ai Discovery & Governance

Detect and govern unauthorized AI tools and deployments bypassing IT controls.

↗
D4-CTL-07

Ai Software Composition Analysis (Sca)

Identify and remediate vulnerabilities in AI framework dependencies and libraries.

↗

Implementation use

Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.

Notably absent

A domain count or control listing does not establish implementation, operating effectiveness or conformance.

ON THIS PAGE
Domain purposeControls and requirementsImplementation use
FrameworksGAISSF™ — Govern & AssureUAIF™ — ClassifyAI-IRF™ — RespondFramework Comparison
LibrariesStandards & GuidanceResearch PublicationsInsights & AnalysisCrosswalksSchema CenterDownloads
InstituteAbout ODA3Training — DevelopingPartnershipResearch CollaborationContact
Legal & TransparencyGEL v1.0Privacy PolicyGrievance RedressalEvidence StandardPublication Limits

© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. Framework content remains subject to the applicable publication and licensing instruments.

Where AI Governance meets Operational Reality.
Search control IDs, titles, evidence terms, schema fields, or framework concepts.