Supply Chain & Update Assurance
Integrity of components, dependencies, maintenance paths and deployed updates.
Domain controls
The following identifiers, titles, objectives and implementation expectations reproduce the canonical public PAI-SF™ v1.0 Control Catalogue. Evidence requirements, assurance expectations, dependencies, exclusions and conformance relevance remain available in the full catalogue.
Objective: Establish provenance of safety-relevant hardware, software, and model components. Requirement: Maintained HBOM/SBOM/AI-BOM with vendor attestations.
Objective: Prevent updates (model, firmware) from introducing unsafe physical behavior. Requirement: Staged rollout with mandatory physical safety regression testing before fleet-wide deployment.
Objective: Ensure third-party sensors, actuators, and models meet PAI-SF™ assurance expectations, not only internally developed components. Requirement: Contractual/assurance requirements for suppliers, including vulnerability-notification obligations.