Supply Chain & Third-Party Ai Security
Domain purpose
Controls and requirements
D4-CTL-01Ai Bill Of Materials (Ai Bom) Maintenance
Maintain complete inventory of all AI models, datasets, dependencies, and third-party components.
D4-CTL-02Model File & Artifact Scanning
Detect malware, backdoors, and unsafe serialization in model files before deployment.
D4-CTL-03Model Hub & Registry Vetting
Assess and approve models from public/private hubs before production use.
D4-CTL-04Mcp Server Behavioral Monitoring
Monitor Model Context Protocol (MCP) servers for unauthorized tool access or anomalous behaviour.
D4-CTL-05Third-Party Ai Api Security Assessment
Evaluate third-party AI APIs for security, privacy, and compliance posture.
D4-CTL-06Shadow Ai Discovery & Governance
Detect and govern unauthorized AI tools and deployments bypassing IT controls.
D4-CTL-07Ai Software Composition Analysis (Sca)
Identify and remediate vulnerabilities in AI framework dependencies and libraries.
Implementation use
Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.