{
  "$schema": "https://oda3.org/schemas/gaissf/crosswalk-register-v1.0.schema.json",
  "document_id": "GAISSF-CRO-019",
  "title": "GAISSF v1.0 to ISO/IEC 42001:2023 Verified Mapping Register",
  "version": "1.0",
  "status": "Draft for Publication",
  "classification": "Informative crosswalk / public",
  "mapping_direction": "GAISSF control to ISO/IEC 42001 clause, Annex A control and Annex B guidance",
  "source_use_notice": "ISO/IEC text was used as an internal controlled source. This register contains identifiers and original paraphrase only and does not reproduce the standard.",
  "limitations": [
    "No mapping establishes equivalence, evidence sufficiency, operating effectiveness, ISO certification, GAISSF certification, legal compliance or automatic conformance.",
    "ISO-aligned evidence is reusable only after scope, provenance, authenticity, currency, completeness, relevance and operating-effectiveness review.",
    "Held/internal GAISSF VTS and unpublished test harnesses are not public-package dependencies.",
    "D9 is additional/conditional and must be included only where Physical AI or cyber-physical actuation is in scope.",
    "Independent crosswalk review and explicit publication approval remain open."
  ],
  "records": [
    {
      "control_id": "D1-CTL-01",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Dataset Provenance & Poisoning Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with hash, source, scan results, poisoning_score",
      "iso_42001_references": "6.1.2; 6.1.3; 8.1; 8.2; 8.3; A.4.3; A.6.2.4; A.7.2; A.7.3; A.7.4; A.7.5; B.4.3; B.6.2.4; B.7.2-B.7.5",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-02",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Model Extraction Resistance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with extraction_success_count, detection_alerts, rate_limit_logs",
      "iso_42001_references": "6.1.2; 6.1.3; 8.1; 8.3; 9.1; A.6.2.4; A.6.2.6; B.6.2.4; B.6.2.6",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-03",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Behavioral Drift Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with daily_kl_divergence_values, accuracy_trend, alert_log",
      "iso_42001_references": "6.1.2; 6.1.3; 8.1-8.3; 9.1; 10.1-10.2; A.6.2.4; A.6.2.6; A.6.2.8; B.6.2.4; B.6.2.6; B.6.2.8",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-04",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Federated Learning Poisoning Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with detection_rate, aggregation_log, client_anomaly_scores",
      "iso_42001_references": "6.1.2; 6.1.3; 8.1; A.4.2-A.4.5; A.6.1.3; A.6.2.4; A.7.2-A.7.5; B.4; B.6.1.3; B.6.2.4; B.7",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-05",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Embedding Space Robustness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with classification_change_rate, certified_radius, attack_log",
      "iso_42001_references": "6.1.2; 6.1.3; 8.1; 9.1; A.6.2.4; A.6.2.6; B.6.2.4; B.6.2.6",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-06",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with signature_verification_log, tls_cipher_suite_audit, pqc_migration_plan",
      "iso_42001_references": "6.1.3; 7.5.3; 8.1; A.4.4; A.4.5; A.6.2.3-A.6.2.5; B.4.4-B.4.5; B.6.2.3-B.6.2.5",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-07",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "LoRA/Adapter Integrity Verification",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with scan_results, hash, source_verification, detection_flag",
      "iso_42001_references": "6.1.2; 6.1.3; 7.5.3; 8.1; A.4.2-A.4.5; A.6.2.3-A.6.2.5; B.4; B.6.2.3-B.6.2.5",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-08",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Model Merge Attack Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with behavioral_test_results, regression_delta, registration_audit",
      "iso_42001_references": "6.1.2; 6.1.3; 8.1; A.4.2-A.4.5; A.6.2.3-A.6.2.5; B.4; B.6.2.3-B.6.2.5",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D1-CTL-09",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Quantization Backdoor Screening",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with pre_quant_results, post_quant_results, behavioral_delta, audit_log",
      "iso_42001_references": "6.1.2; 6.1.3; 8.1; A.6.2.4-A.6.2.6; B.6.2.4-B.6.2.6",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports data, resource, lifecycle, validation, and monitoring governance but does not prescribe this model-integrity technique or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D2-CTL-01",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Direct Prompt Injection Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with bypass_count, refusal_rate, payload_hashes",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.6.1.3; A.6.2.2; A.6.2.4; A.6.2.6; A.9.2; B.6.1.3; B.6.2.2; B.6.2.4; B.6.2.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D2-CTL-02",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Indirect Prompt Injection Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with sanitization_log, execution_rate, source_audit",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.6.1.3; A.6.2.2; A.6.2.4; A.6.2.6; A.9.2; A.10.2; B.6; B.9.2; B.10.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D2-CTL-03",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Jailbreak Resistance Testing",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with success_rate, technique_breakdown, refusal_log",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.6.2.4; A.6.2.6; A.9.2; B.6.2.4; B.6.2.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D2-CTL-04",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Multi-Modal Injection Defense",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with modality_scan_results, detection_rate, payload_metadata",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.4.4-A.4.5; A.6.2.4; A.6.2.6; A.9.2; B.4.4-B.4.5; B.6.2.4; B.6.2.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D2-CTL-05",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Function Call/Tool Call Injection Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with validation_log, allowlist_hits, rejection_reasons",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; A.4.4-A.4.5; A.6.1.3; A.6.2.4; A.6.2.6; A.9.2; B.4.4-B.4.5; B.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D2-CTL-06",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Cross-Context Hijacking Mitigation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with position_test_results, adherence_score, override_log",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.6.1.3; A.6.2.4; A.6.2.6; A.9.2; B.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D3-CTL-01",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Least Agency Enforcement",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with permission_audit_log, denial_rate, revocation_latency",
      "iso_42001_references": "5.3; 6.1.2-6.1.3; 8.1; A.3.2; A.6.1.3; A.6.2.2; A.9.2-A.9.3; B.3.2; B.6; B.9",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D3-CTL-02",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Inter-Agent Communication Security",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with tls_audit, message_validation_log, rejection_count",
      "iso_42001_references": "5.3; 6.1.2-6.1.3; 8.1; A.3.2; A.4.2; A.6.1.3; A.6.2.4; A.6.2.6; A.10.2-A.10.3; B.3.2; B.4.2; B.6; B.10",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D3-CTL-03",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Agentic Prompt Chaining Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with chain_detection_log, correlation_scores, latency_metrics",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.6.2.4; A.6.2.6; A.9.2; B.6.2.4; B.6.2.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D3-CTL-04",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Embodied AI Safety Controls",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with sensor_integrity_log, interlock_activation_log, fail_safe_metrics",
      "iso_42001_references": "6.1.2-6.1.4; 8.1-8.4; A.4.5; A.5.2-A.5.5; A.6.2.2-A.6.2.6; A.9.2; B.4.5; B.5; B.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D3-CTL-05",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Multi-Agent Trust Chain Attestation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with attestation_log, certificate_rotation_audit, rejection_rate",
      "iso_42001_references": "5.3; 6.1.3; 7.5.3; 8.1; A.3.2; A.4.2; A.6.2.3-A.6.2.6; A.10.2-A.10.3; B.3.2; B.4.2; B.6; B.10",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D3-CTL-06",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Persistent Memory Exfiltration Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with isolation_audit_log, leakage_rate, access_control_hits",
      "iso_42001_references": "6.1.2-6.1.3; 7.5.3; 8.1-8.3; A.6.2.4; A.6.2.6; A.7.2-A.7.5; A.9.2; B.6; B.7; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D3-CTL-07",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Secure Memory Lifecycle Management",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with lifecycle_audit, wipe_verification_log, retention_compliance",
      "iso_42001_references": "6.1.2-6.1.3; 7.5.3; 8.1; A.6.2.2-A.6.2.8; A.7.2-A.7.6; B.6; B.7",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports risk treatment and lifecycle governance but does not expressly prescribe this agentic/runtime attack mechanism, defense design, or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D4-CTL-01",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "AI Bill Of Materials (AI Bom) Maintenance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON/SBOM-compatible with component_list, version_hashes, coverage_metric",
      "iso_42001_references": "4.3; 6.1.2-6.1.3; 7.5; 8.1; A.4.2-A.4.5; A.6.2.3; A.10.2-A.10.3; B.4; B.6.2.3; B.10",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports resource and supplier governance but does not prescribe the named GAISSF inventory, scanning, monitoring, or discovery mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D4-CTL-02",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Model File & Artifact Scanning",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with scan_results, quarantine_log, detection_metrics",
      "iso_42001_references": "6.1.2-6.1.3; 8.1; A.4.2-A.4.5; A.6.2.4-A.6.2.5; A.10.2-A.10.3; B.4; B.6.2.4-B.6.2.5; B.10",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports resource and supplier governance but does not prescribe the named GAISSF inventory, scanning, monitoring, or discovery mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D4-CTL-03",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Model Hub & Registry Vetting",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with provenance_log, license_audit, security_scorecard",
      "iso_42001_references": "6.1.2-6.1.3; 8.1; A.4.2-A.4.5; A.10.2-A.10.3; B.4; B.10",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports resource and supplier governance but does not prescribe the named GAISSF inventory, scanning, monitoring, or discovery mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D4-CTL-04",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "MCP Server Behavioral Monitoring",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with tool_call_log, anomaly_scores, block_metrics",
      "iso_42001_references": "6.1.2-6.1.3; 8.1; 9.1; A.4.4-A.4.5; A.6.2.6; A.10.2-A.10.3; B.4.4-B.4.5; B.6.2.6; B.10",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports resource and supplier governance but does not prescribe the named GAISSF inventory, scanning, monitoring, or discovery mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D4-CTL-05",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Third-Party AI Api Security Assessment",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with vendor_name, assessment_date, security_gaps, remediation_plan",
      "iso_42001_references": "4.2-4.3; 6.1.2-6.1.3; 8.1; A.10.2-A.10.3; B.10",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports resource and supplier governance but does not prescribe the named GAISSF inventory, scanning, monitoring, or discovery mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D4-CTL-06",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Shadow AI Discovery & Governance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with discovery_log, unauthorized_count, governance_actions",
      "iso_42001_references": "4.1-4.3; 6.1.2-6.1.3; 8.1; A.4.2; A.9.2; A.10.2; B.4.2; B.9.2; B.10.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports resource and supplier governance but does not prescribe the named GAISSF inventory, scanning, monitoring, or discovery mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D4-CTL-07",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "AI Software Composition Analysis (SCA)",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with dependency_list, cve_matches, remediation_status",
      "iso_42001_references": "6.1.2-6.1.3; 8.1; A.4.4-A.4.5; A.6.2.3-A.6.2.5; A.10.2-A.10.3; B.4; B.6; B.10",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports resource and supplier governance but does not prescribe the named GAISSF inventory, scanning, monitoring, or discovery mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D5-CTL-01",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Harmful Content Blocking",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with refusal_rate, harmful_content_categories, refusal_log",
      "iso_42001_references": "6.1.2-6.1.4; 8.1-8.4; 9.1; A.5.2-A.5.5; A.6.2.4; A.6.2.6; A.8.2; A.9.2; B.5; B.6.2.4; B.6.2.6; B.8.2; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports impact, data, lifecycle, and user-information controls but does not prescribe the named technical safeguard or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D5-CTL-02",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "PII Leakage Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with pii_detection_recall, false_positive_rate, redaction_log",
      "iso_42001_references": "6.1.2-6.1.4; 7.5.3; 8.1-8.4; A.5.2-A.5.5; A.6.2.4; A.7.2-A.7.6; A.8.2; B.5; B.6.2.4; B.7; B.8.2",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports impact, data, lifecycle, and user-information controls but does not prescribe the named technical safeguard or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D5-CTL-03",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Copyright Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with ngram_overlap_scores, reproduction_rate, refusal_log",
      "iso_42001_references": "4.2; 6.1.2-6.1.3; 8.1; A.5.2-A.5.5; A.6.2.4; A.8.2; B.5; B.6.2.4; B.8.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports impact, data, lifecycle, and user-information controls but does not prescribe the named technical safeguard or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D5-CTL-04",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "AI Watermarking Robustness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with detection_rate_by_attack, false_positives, c2pa_compliance_certificate",
      "iso_42001_references": "6.1.2-6.1.3; 8.1; 9.1; A.6.2.4; A.6.2.6; A.8.2; B.6.2.4; B.6.2.6; B.8.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports impact, data, lifecycle, and user-information controls but does not prescribe the named technical safeguard or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D5-CTL-05",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Privacy-By-Design Verification",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with data_inventory, purpose_audit_log, erasure_request_log, unlearning_attestation",
      "iso_42001_references": "4.2; 6.1.2-6.1.4; 8.1-8.4; A.5.2-A.5.5; A.6.1.3; A.6.2.2-A.6.2.4; A.7.2-A.7.6; B.5-B.7",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports impact, data, lifecycle, and user-information controls but does not prescribe the named technical safeguard or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D5-CTL-06",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Privacy-Preserving Ml Validation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with dp_epsilon_value, membership_inference_results, dp_training_certificate",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.6.2.4; A.7.2-A.7.6; B.6.2.4; B.7",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 supports impact, data, lifecycle, and user-information controls but does not prescribe the named technical safeguard or GAISSF validation tooling threshold.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D6-CTL-01",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Human-In-The-Loop For High-Risk Actions",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with approval_request_log, approver_id, timestamp, justification",
      "iso_42001_references": "5.3; 6.1.2-6.1.4; 8.1; A.3.2; A.5.2-A.5.5; A.6.2.2; A.9.2-A.9.3; B.3.2; B.5; B.6.2.2; B.9",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides strong management-system support, but GAISSF retains its control-specific evidence, test, retention, and operating-effectiveness requirements.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D6-CTL-02",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Audit Trail Completeness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON/SIEM log with decision_id, timestamp, input_hash, output_hash, system_id, approver_id",
      "iso_42001_references": "7.5; 8.1; 9.1-9.3; 10.2; A.6.2.8; A.8.5; B.6.2.8; B.8.5",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides strong management-system support, but GAISSF retains its control-specific evidence, test, retention, and operating-effectiveness requirements.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D6-CTL-03",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "AI Model Card Completeness",
      "foundational_required": true,
      "gaissf_evidence_format": "Markdown/JSON with model_id, owner, purpose, data_sources, limitations, risk_tier, review_date",
      "iso_42001_references": "7.4-7.5; 8.1; A.6.2.3; A.6.2.7; A.8.2; A.8.5; B.6.2.3; B.6.2.7; B.8.2; B.8.5",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides strong management-system support, but GAISSF retains its control-specific evidence, test, retention, and operating-effectiveness requirements.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D6-CTL-04",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "AI Incident Response Readiness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with exercise_date, participants, mttc_achieved, lessons_learned, improvement_tracker",
      "iso_42001_references": "5.3; 7.4-7.5; 8.1; 9.1; 10.2; A.3.3; A.8.3-A.8.5; B.3.3; B.8.3-B.8.5",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides strong management-system support, but GAISSF retains its control-specific evidence, test, retention, and operating-effectiveness requirements.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D6-CTL-05",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Model Deprecation & Decommissioning",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with model_id, decommission_date, access_revocation_log, traffic_verification",
      "iso_42001_references": "6.3; 7.5.3; 8.1; 10.1-10.2; A.6.2.6-A.6.2.8; B.6.2.6-B.6.2.8",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides strong management-system support, but GAISSF retains its control-specific evidence, test, retention, and operating-effectiveness requirements.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D6-CTL-06",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Third-Party AI Vendor Governance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with vendor_name, assessment_date, soc2_status, contract_review_summary",
      "iso_42001_references": "4.2-4.3; 6.1.2-6.1.3; 8.1; A.10.2-A.10.3; B.10",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides strong management-system support, but GAISSF retains its control-specific evidence, test, retention, and operating-effectiveness requirements.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D6-CTL-07",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "AI Resilience & Business Continuity",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with bcp_test_date, rto_achieved, rpo_achieved, degraded_mode_capabilities, improvement_tracker",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; 10.1-10.2; A.4.2-A.4.6; A.6.2.6; B.4; B.6.2.6",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides strong management-system support, but GAISSF retains its control-specific evidence, test, retention, and operating-effectiveness requirements.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D7-CTL-H01",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "AI-Generated Phishing Simulation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with simulation_date, click_rate, coverage_percentage, training_completion",
      "iso_42001_references": "6.1.2-6.1.4; 7.2-7.3; 8.1; A.5.2-A.5.5; A.9.2; B.5; B.9.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides related governance support but does not prescribe the named GAISSF technical or operational mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D7-CTL-H02",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "Deepfake Detection Training",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with training_date, completion_rate_by_role, quiz_pass_rate",
      "iso_42001_references": "6.1.2-6.1.4; 7.2-7.3; 8.1; A.5.2-A.5.5; A.8.2; A.9.2; B.5; B.8.2; B.9.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides related governance support but does not prescribe the named GAISSF technical or operational mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D7-CTL-H03",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "Out-Of-Band Authentication",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with oob_enforcement_log, policy_compliance_report, exception_log",
      "iso_42001_references": "6.1.2-6.1.3; 8.1; A.9.2; B.9.2",
      "relationship": "Supporting",
      "mapping_confidence": "Low",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides related governance support but does not prescribe the named GAISSF technical or operational mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D7-CTL-H04",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "AI Social Engineering IR",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with exercise_date, participants, verification_triggered, financial_hold_applied, improvements",
      "iso_42001_references": "6.1.2-6.1.4; 7.2-7.4; 8.1; 10.2; A.3.3; A.5.2-A.5.5; A.8.3-A.8.5; B.3.3; B.5; B.8",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides related governance support but does not prescribe the named GAISSF technical or operational mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D7-CTL-H05",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "AI-Enhanced External Attack Defense",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with detection_time, quarantine_action, soc_alert_log",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.6.2.4; A.6.2.6; A.9.2; B.6.2.4; B.6.2.6; B.9.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides related governance support but does not prescribe the named GAISSF technical or operational mechanism.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D8-CTL-01",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "Eu AI Act Risk Tier Mapping",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with system_id, risk_tier, classification_justification, conformity_evidence",
      "iso_42001_references": "4.1-4.3; 6.1.1-6.1.4; 7.5; 8.1-8.4; A.5; A.8; B.5; B.8",
      "relationship": "Contextual",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 does not establish conformity with the external law, regulation, or framework named by this GAISSF control; separate authoritative interpretation and evidence remain required.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D8-CTL-02",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "Iso 42001 Gap Analysis",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with clause_by_clause_status, remediation_plan, completion_tracker",
      "iso_42001_references": "4-10; A.2-A.10; B.2-B.10",
      "relationship": "Direct enablement",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 does not establish conformity with the external law, regulation, or framework named by this GAISSF control; separate authoritative interpretation and evidence remain required.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D8-CTL-03",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "Gpai Technical Documentation Verification",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with model_id, technical_doc_hash, training_data_summary, copyright_attestation",
      "iso_42001_references": "4.2; 7.4-7.5; 8.1; A.6.2.3; A.6.2.7; A.8.2; A.8.5; B.6.2.3; B.6.2.7; B.8.2; B.8.5",
      "relationship": "Contextual",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 does not establish conformity with the external law, regulation, or framework named by this GAISSF control; separate authoritative interpretation and evidence remain required.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D8-CTL-04",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with incident_id, classification, notification_timestamp, nca_submission",
      "iso_42001_references": "4.2; 7.4-7.5; 8.1; 10.2; A.8.4-A.8.5; A.10.2-A.10.3; B.8.4-B.8.5; B.10",
      "relationship": "Contextual",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 does not establish conformity with the external law, regulation, or framework named by this GAISSF control; separate authoritative interpretation and evidence remain required.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D8-CTL-05",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "Nist Sp 800-218A Compliance Check",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with sp800_218a_practice_status, attestation_statement, continuous_monitoring_log",
      "iso_42001_references": "6.1.3; 8.1; A.6.1.3; A.6.2.2-A.6.2.5; A.10.2-A.10.3; B.6; B.10",
      "relationship": "Contextual",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 does not establish conformity with the external law, regulation, or framework named by this GAISSF control; separate authoritative interpretation and evidence remain required.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_method": "Use an independently controlled validation method appropriate to the control, system boundary and assurance objective.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D9-CTL-01",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Physical Harm Boundary Enforcement",
      "foundational_required": false,
      "gaissf_evidence_format": "Hardware-in-the-loop test report (JSON with command_id, value, blocked, monitor_response_time_ms); safety monitor certification certificate (DO-178C / IEC 61508)",
      "iso_42001_references": "6.1.2-6.1.4; 8.1-8.4; A.4.5; A.5.2-A.5.5; A.6.2.2-A.6.2.5; B.4.5; B.5; B.6.2.2-B.6.2.5",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides risk, impact, resource, and lifecycle governance but does not prescribe this functional-safety or cyber-physical mechanism or its implementation-specific acceptance criteria.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D9-CTL-02",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Safe State And Graceful Degradation",
      "foundational_required": false,
      "gaissf_evidence_format": "Safe state test report (JSON with trigger_condition, transition_time_ms, safe_state_achieved, assessor_verification)",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; A.6.2.2; A.6.2.4-A.6.2.6; B.6.2.2; B.6.2.4-B.6.2.6",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides risk, impact, resource, and lifecycle governance but does not prescribe this functional-safety or cyber-physical mechanism or its implementation-specific acceptance criteria.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D9-CTL-03",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Human Override And Emergency Stop",
      "foundational_required": false,
      "gaissf_evidence_format": "Override test report (JSON with override_type, test_condition, latency_ms, outcome). Physical E-stop certification documentation",
      "iso_42001_references": "5.3; 6.1.2-6.1.4; 8.1; A.3.2; A.5.2-A.5.5; A.6.2.2-A.6.2.5; A.9.2; B.3.2; B.5; B.6; B.9.2",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides risk, impact, resource, and lifecycle governance but does not prescribe this functional-safety or cyber-physical mechanism or its implementation-specific acceptance criteria.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D9-CTL-04",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Cyber-Physical Attack Detection",
      "foundational_required": false,
      "gaissf_evidence_format": "Hardware-in-the-loop detection test report (JSON with attack_type, injected_count, detected_count, detection_rate, false_positive_rate, mean_time_to_safe_state_ms)",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; 9.1; A.4.5; A.6.2.4; A.6.2.6; A.6.2.8; B.4.5; B.6.2.4; B.6.2.6; B.6.2.8",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides risk, impact, resource, and lifecycle governance but does not prescribe this functional-safety or cyber-physical mechanism or its implementation-specific acceptance criteria.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D9-CTL-05",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Physical Environment Integrity Monitoring",
      "foundational_required": false,
      "gaissf_evidence_format": "Sensor failure injection test report (JSON with failure_mode, response_time_ms, system_response, assessor_verification); calibration certificate register",
      "iso_42001_references": "6.1.2-6.1.3; 8.1; 9.1; A.4.5; A.6.2.4; A.6.2.6; B.4.5; B.6.2.4; B.6.2.6",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides risk, impact, resource, and lifecycle governance but does not prescribe this functional-safety or cyber-physical mechanism or its implementation-specific acceptance criteria.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D9-CTL-06",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Actuator Command Verification",
      "foundational_required": false,
      "gaissf_evidence_format": "Hardware-in-the-loop verification test report (JSON with command_id, command_type, block_reason, gate_response_time_ms, dual_approval_test_result). IEC 61508 SIL 3 certification certificate for verification gate",
      "iso_42001_references": "6.1.2-6.1.3; 8.1-8.3; A.6.2.2; A.6.2.4-A.6.2.6; B.6.2.2; B.6.2.4-B.6.2.6",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides risk, impact, resource, and lifecycle governance but does not prescribe this functional-safety or cyber-physical mechanism or its implementation-specific acceptance criteria.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    },
    {
      "control_id": "D9-CTL-07",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Physical Incident Evidence Preservation",
      "foundational_required": false,
      "gaissf_evidence_format": "Incident evidence package (OSCAL-compatible JSON bundle with sensor_stream, model_input_output_stream, actuator_command_stream, safety_monitor_log, human_override_log, cryptographic_chain_of_custody)",
      "iso_42001_references": "7.5.3; 8.1; 9.1; 10.2; A.6.2.8; A.8.4-A.8.5; B.6.2.8; B.8.4-B.8.5",
      "relationship": "Strong partial",
      "mapping_confidence": "High",
      "iso_evidence_reuse": "Risk/impact assessments; treatment and SoA records; controlled lifecycle documentation; monitoring, audit, supplier, competence, or communication records applicable to the cited locations.",
      "additional_gaissf_validation": "Execute or independently verify the linked GAISSF validation tooling using scope-appropriate, non-demo fixtures and preserve schema-valid signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 42001 provides risk, impact, resource, and lifecycle governance but does not prescribe this functional-safety or cyber-physical mechanism or its implementation-specific acceptance criteria.",
      "source_baseline": "ISO/IEC 42001:2023, Edition 1; GAISSF-NOR-001 v1.0; GAISSF-NOR-004 v1.0; publication reconciliation updated 2026-10-05.",
      "baseline_scope": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "validation_evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations.",
      "records_retention": "Follow the approved records schedule and applicable legal, contractual and evidence-preservation requirements; GAISSF conformance tiers do not define universal retention periods."
    }
  ],
  "updated": "2026-10-05",
  "applicable_control_baseline": "All 52 controls in D1-D8 plus D9 where Physical AI or cyber-physical actuation is in scope",
  "external_source_status": "ISO/IEC 42001:2023, Edition 1 (2023-12), remains the mapped external baseline.",
  "publication_boundary": [
    "Mapping establishes correspondence only.",
    "No mapping establishes equivalence, evidence sufficiency, operating effectiveness, ISO certification, GAISSF certification, legal compliance or automatic conformance.",
    "GAISSF certification is not currently offered.",
    "Held/internal GAISSF VTS, unpublished benchmark suites and test harnesses are not publication dependencies of this public crosswalk.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only."
  ]
}