{
  "$schema": "https://oda3.org/schemas/gaissf/crosswalk-register-v1.0.schema.json",
  "document_id": "GAISSF-CRO-021",
  "title": "GAISSF v1.0 ISO/IEC 23894:2023 Mapping",
  "version": "1.2",
  "status": "Draft for Publication",
  "classification": "Informative source-bounded crosswalk / public; not full-text verified",
  "coordinated_publication_pair": [
    "Technical Report",
    "Executive Brief"
  ],
  "mapping_direction": "GAISSF controls to ISO/IEC 23894 risk-management structure, with reverse process index",
  "external_source_status": "ISO/IEC 23894:2023 Edition 1 remains published. The full licensed text was not supplied. Document identity, scope and clause/annex structure are bounded to the ISO official record/abstract and ANSI-authorized preview. Detailed semantic mappings remain ODA3 analytical inferences pending licensed full-text verification.",
  "verified_structure": [
    "4 Principles of AI risk management",
    "5 Framework",
    "5.1 General",
    "5.2 Leadership and commitment",
    "5.3 Integration",
    "5.4 Design",
    "5.4.1 Understanding the organization and its context",
    "5.4.2 Articulating risk management commitment",
    "5.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities",
    "5.4.4 Allocating resources",
    "5.4.5 Establishing communication and consultation",
    "5.5 Implementation",
    "5.6 Evaluation",
    "5.7 Improvement",
    "5.7.1 Adapting",
    "5.7.2 Continually improving",
    "6 Risk management process",
    "6.1 General",
    "6.2 Communication and consultation",
    "6.3 Scope, context and criteria",
    "6.3.1 General",
    "6.3.2 Defining the scope",
    "6.3.3 External and internal context",
    "6.3.4 Defining risk criteria",
    "6.4 Risk assessment",
    "6.4.1 General",
    "6.4.2 Risk identification",
    "6.4.3 Risk analysis",
    "6.4.4 Risk evaluation",
    "6.5 Risk treatment",
    "6.5.1 General",
    "6.5.2 Selection of risk treatment options",
    "6.5.3 Preparing and implementing risk treatment plans",
    "6.6 Monitoring and review",
    "6.7 Recording and reporting",
    "Annex A Objectives",
    "Annex B Risk sources",
    "Annex C Risk management and AI system life cycle"
  ],
  "domain_lifecycle_map": {
    "D1": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
    "D2": "Verification and validation; deployment; operation and monitoring; incident response and change management.",
    "D3": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
    "D4": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
    "D5": "Data preparation; design and development; verification and validation; deployment; operation and user interaction.",
    "D6": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
    "D7": "Design and impact assessment; verification and validation; deployment; operation; stakeholder communication and incident response.",
    "D8": "All lifecycle stages through legal, regulatory and assurance checkpoints, with periodic re-evaluation.",
    "D9": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning."
  },
  "review_policy": "Revalidate at least annually, when ISO/IEC 23894 or GAISSF changes, when material implementation/threat context changes, and when a licensed full-text review becomes available.",
  "limitations": [
    "ISO/IEC 23894 is guidance, not a certifiable requirements or control standard.",
    "The complete licensed text was not available; no claim of full-text verification is made.",
    "Clause headings and document structure are confirmed; detailed semantic mappings are original analytical inferences.",
    "A mapping does not demonstrate implementation, risk reduction, control effectiveness, conformity, certification or legal compliance.",
    "ISO/IEC 23894 evidence can be reused only after scope, authenticity, currency, completeness and operating-effectiveness qualification.",
    "GAISSF VTS execution or equivalent independent verification remains necessary for technical outcomes.",
    "Do not redistribute or reproduce the ISO/IEC preview or substantial protected text.",
    "This is a source-bounded mapping; it is not full-text verified against a licensed ISO/IEC 23894:2023 copy.",
    "No mapping establishes equivalence, evidence sufficiency, certification, legal compliance or automatic conformance.",
    "GAISSF VTS remains outside this public crosswalk; held/internal test assets are not publication dependencies.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only."
  ],
  "records": [
    {
      "control_id": "D1-CTL-01",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Dataset Provenance & Poisoning Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with hash, source, scan results, poisoning_score",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Dataset Provenance & Poisoning Prevention; execute or independently verify D1-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Dataset Provenance & Poisoning Prevention; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-02",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Model Extraction Resistance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with extraction_success_count, detection_alerts, rate_limit_logs",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Model Extraction Resistance; execute or independently verify D1-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Model Extraction Resistance; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-03",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Behavioral Drift Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with daily_kl_divergence_values, accuracy_trend, alert_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.6; 5.7.1; 5.7.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Behavioral Drift Detection; execute or independently verify D1-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Behavioral Drift Detection; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-04",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Federated Learning Poisoning Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with detection_rate, aggregation_log, client_anomaly_scores",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Federated Learning Poisoning Prevention; execute or independently verify D1-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Federated Learning Poisoning Prevention; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-05",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Embedding Space Robustness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with classification_change_rate, certified_radius, attack_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Embedding Space Robustness; execute or independently verify D1-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Embedding Space Robustness; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-06",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with signature_verification_log, tls_cipher_suite_audit, pqc_migration_plan",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-06-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Post-Quantum Model Signing & Crypto Hardening; execute or independently verify D1-CTL-06-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Post-Quantum Model Signing & Crypto Hardening; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-07",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "LoRA/Adapter Integrity Verification",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with scan_results, hash, source_verification, detection_flag",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-07-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for LoRA/Adapter Integrity Verification; execute or independently verify D1-CTL-07-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review LoRA/Adapter Integrity Verification; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-08",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Model Merge Attack Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with behavioral_test_results, regression_delta, registration_audit",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-08-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Model Merge Attack Detection; execute or independently verify D1-CTL-08-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Model Merge Attack Detection; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D1-CTL-09",
      "domain_code": "D1",
      "domain_name": "Model Integrity & Adversarial Robustness",
      "control_title": "Quantization Backdoor Screening",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with pre_quant_results, post_quant_results, behavioral_delta, audit_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D1-CTL-09-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Quantization Backdoor Screening; execute or independently verify D1-CTL-09-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Quantization Backdoor Screening; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new model version or fine-tuning; training-data or provenance change; material drift or robustness finding",
      "primary_ai_lifecycle_stage": "Data collection, processing and labelling; modelling and training; verification and validation; operation and monitoring.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D2-CTL-01",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Direct Prompt Injection Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with bypass_count, refusal_rate, payload_hashes",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D2-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Direct Prompt Injection Prevention; execute or independently verify D2-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Direct Prompt Injection Prevention; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; runtime architecture, prompt, tool or interface change; new adversarial technique or vulnerability; significant security incident",
      "primary_ai_lifecycle_stage": "Verification and validation; deployment; operation and monitoring; incident response and change management.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D2-CTL-02",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Indirect Prompt Injection Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with sanitization_log, execution_rate, source_audit",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D2-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Indirect Prompt Injection Prevention; execute or independently verify D2-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Indirect Prompt Injection Prevention; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; runtime architecture, prompt, tool or interface change; new adversarial technique or vulnerability; significant security incident",
      "primary_ai_lifecycle_stage": "Verification and validation; deployment; operation and monitoring; incident response and change management.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D2-CTL-03",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Jailbreak Resistance Testing",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with success_rate, technique_breakdown, refusal_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D2-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Jailbreak Resistance Testing; execute or independently verify D2-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Jailbreak Resistance Testing; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; runtime architecture, prompt, tool or interface change; new adversarial technique or vulnerability; significant security incident",
      "primary_ai_lifecycle_stage": "Verification and validation; deployment; operation and monitoring; incident response and change management.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D2-CTL-04",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Multi-Modal Injection Defense",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with modality_scan_results, detection_rate, payload_metadata",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D2-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Multi-Modal Injection Defense; execute or independently verify D2-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Multi-Modal Injection Defense; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; runtime architecture, prompt, tool or interface change; new adversarial technique or vulnerability; significant security incident",
      "primary_ai_lifecycle_stage": "Verification and validation; deployment; operation and monitoring; incident response and change management.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D2-CTL-05",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Function Call/Tool Call Injection Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with validation_log, allowlist_hits, rejection_reasons",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D2-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Function Call/Tool Call Injection Prevention; execute or independently verify D2-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Function Call/Tool Call Injection Prevention; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; runtime architecture, prompt, tool or interface change; new adversarial technique or vulnerability; significant security incident",
      "primary_ai_lifecycle_stage": "Verification and validation; deployment; operation and monitoring; incident response and change management.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D2-CTL-06",
      "domain_code": "D2",
      "domain_name": "Runtime Security & Adversarial Defense",
      "control_title": "Cross-Context Hijacking Mitigation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with position_test_results, adherence_score, override_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D2-CTL-06-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Cross-Context Hijacking Mitigation; execute or independently verify D2-CTL-06-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Cross-Context Hijacking Mitigation; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; runtime architecture, prompt, tool or interface change; new adversarial technique or vulnerability; significant security incident",
      "primary_ai_lifecycle_stage": "Verification and validation; deployment; operation and monitoring; incident response and change management.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D3-CTL-01",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Least Agency Enforcement",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with permission_audit_log, denial_rate, revocation_latency",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D3-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Least Agency Enforcement; execute or independently verify D3-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Least Agency Enforcement; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; agent authority, tools, memory or inter-agent topology change; new autonomous action type; material change to human oversight",
      "primary_ai_lifecycle_stage": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D3-CTL-02",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Inter-Agent Communication Security",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with tls_audit, message_validation_log, rejection_count",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D3-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Inter-Agent Communication Security; execute or independently verify D3-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Inter-Agent Communication Security; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; agent authority, tools, memory or inter-agent topology change; new autonomous action type; material change to human oversight",
      "primary_ai_lifecycle_stage": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D3-CTL-03",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Agentic Prompt Chaining Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with chain_detection_log, correlation_scores, latency_metrics",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D3-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Agentic Prompt Chaining Detection; execute or independently verify D3-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Agentic Prompt Chaining Detection; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; agent authority, tools, memory or inter-agent topology change; new autonomous action type; material change to human oversight",
      "primary_ai_lifecycle_stage": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D3-CTL-04",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Embodied AI Safety Controls",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with sensor_integrity_log, interlock_activation_log, fail_safe_metrics",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D3-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Embodied AI Safety Controls; execute or independently verify D3-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Embodied AI Safety Controls; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; agent authority, tools, memory or inter-agent topology change; new autonomous action type; material change to human oversight",
      "primary_ai_lifecycle_stage": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D3-CTL-05",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Multi-Agent Trust Chain Attestation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with attestation_log, certificate_rotation_audit, rejection_rate",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D3-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Multi-Agent Trust Chain Attestation; execute or independently verify D3-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Multi-Agent Trust Chain Attestation; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; agent authority, tools, memory or inter-agent topology change; new autonomous action type; material change to human oversight",
      "primary_ai_lifecycle_stage": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D3-CTL-06",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Persistent Memory Exfiltration Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with isolation_audit_log, leakage_rate, access_control_hits",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D3-CTL-06-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Persistent Memory Exfiltration Prevention; execute or independently verify D3-CTL-06-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Persistent Memory Exfiltration Prevention; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; agent authority, tools, memory or inter-agent topology change; new autonomous action type; material change to human oversight",
      "primary_ai_lifecycle_stage": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D3-CTL-07",
      "domain_code": "D3",
      "domain_name": "Agentic Risk & Autonomous System Security",
      "control_title": "Secure Memory Lifecycle Management",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with lifecycle_audit, wipe_verification_log, retention_compliance",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D3-CTL-07-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Secure Memory Lifecycle Management; execute or independently verify D3-CTL-07-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Secure Memory Lifecycle Management; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; agent authority, tools, memory or inter-agent topology change; new autonomous action type; material change to human oversight",
      "primary_ai_lifecycle_stage": "System design; integration; deployment; operation and monitoring; change, transfer and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D4-CTL-01",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "AI Bill Of Materials (AI BOM) Maintenance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON/SBOM-compatible with component_list, version_hashes, coverage_metric",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D4-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI Bill Of Materials (AI Bom) Maintenance; execute or independently verify D4-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review AI Bill Of Materials (AI BOM) Maintenance; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; supplier, model, API, MCP server or dependency change; new supply-chain threat intelligence; contract or assurance change",
      "primary_ai_lifecycle_stage": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D4-CTL-02",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Model File & Artifact Scanning",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with scan_results, quarantine_log, detection_metrics",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D4-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Model File & Artifact Scanning; execute or independently verify D4-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Model File & Artifact Scanning; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; supplier, model, API, MCP server or dependency change; new supply-chain threat intelligence; contract or assurance change",
      "primary_ai_lifecycle_stage": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D4-CTL-03",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Model Hub & Registry Vetting",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with provenance_log, license_audit, security_scorecard",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D4-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Model Hub & Registry Vetting; execute or independently verify D4-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Model Hub & Registry Vetting; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; supplier, model, API, MCP server or dependency change; new supply-chain threat intelligence; contract or assurance change",
      "primary_ai_lifecycle_stage": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D4-CTL-04",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "MCP Server Behavioral Monitoring",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with tool_call_log, anomaly_scores, block_metrics",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.6; 5.7.1; 5.7.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D4-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for MCP Server Behavioral Monitoring; execute or independently verify D4-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review MCP Server Behavioral Monitoring; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; supplier, model, API, MCP server or dependency change; new supply-chain threat intelligence; contract or assurance change",
      "primary_ai_lifecycle_stage": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D4-CTL-05",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Third-Party AI API Security Assessment",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with vendor_name, assessment_date, security_gaps, remediation_plan",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D4-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Third-Party AI Api Security Assessment; execute or independently verify D4-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Third-Party AI API Security Assessment; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; supplier, model, API, MCP server or dependency change; new supply-chain threat intelligence; contract or assurance change",
      "primary_ai_lifecycle_stage": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D4-CTL-06",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "Shadow AI Discovery & Governance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with discovery_log, unauthorized_count, governance_actions",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D4-CTL-06-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Shadow AI Discovery & Governance; execute or independently verify D4-CTL-06-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for Shadow AI Discovery & Governance, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; supplier, model, API, MCP server or dependency change; new supply-chain threat intelligence; contract or assurance change",
      "primary_ai_lifecycle_stage": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D4-CTL-07",
      "domain_code": "D4",
      "domain_name": "Supply Chain & Third-Party AI Security",
      "control_title": "AI Software Composition Analysis (SCA)",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with dependency_list, cve_matches, remediation_status",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D4-CTL-07-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI Software Composition Analysis (SCA); execute or independently verify D4-CTL-07-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review AI Software Composition Analysis (SCA); the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; supplier, model, API, MCP server or dependency change; new supply-chain threat intelligence; contract or assurance change",
      "primary_ai_lifecycle_stage": "Acquisition and sourcing; system integration; deployment; supplier monitoring; change and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D5-CTL-01",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Harmful Content Blocking",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with refusal_rate, harmful_content_categories, refusal_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2; Annex A",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D5-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Harmful Content Blocking; execute or independently verify D5-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Harmful Content Blocking; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; content policy, data category, privacy requirement or output modality change; new harm taxonomy or evaluation method",
      "primary_ai_lifecycle_stage": "Data preparation; design and development; verification and validation; deployment; operation and user interaction.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D5-CTL-02",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "PII Leakage Prevention",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with pii_detection_recall, false_positive_rate, redaction_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D5-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for PII Leakage Prevention; execute or independently verify D5-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review PII Leakage Prevention; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; content policy, data category, privacy requirement or output modality change; new harm taxonomy or evaluation method",
      "primary_ai_lifecycle_stage": "Data preparation; design and development; verification and validation; deployment; operation and user interaction.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D5-CTL-03",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Copyright Detection",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with ngram_overlap_scores, reproduction_rate, refusal_log",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2; Annex A",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D5-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Copyright Detection; execute or independently verify D5-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Copyright Detection; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; content policy, data category, privacy requirement or output modality change; new harm taxonomy or evaluation method",
      "primary_ai_lifecycle_stage": "Data preparation; design and development; verification and validation; deployment; operation and user interaction.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D5-CTL-04",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "AI Watermarking Robustness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with detection_rate_by_attack, false_positives, c2pa_compliance_certificate",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2; Annex A",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D5-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI Watermarking Robustness; execute or independently verify D5-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review AI Watermarking Robustness; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; content policy, data category, privacy requirement or output modality change; new harm taxonomy or evaluation method",
      "primary_ai_lifecycle_stage": "Data preparation; design and development; verification and validation; deployment; operation and user interaction.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D5-CTL-05",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Privacy-By-Design Verification",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with data_inventory, purpose_audit_log, erasure_request_log, unlearning_attestation",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2; Annex A",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D5-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Privacy-By-Design Verification; execute or independently verify D5-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Privacy-By-Design Verification; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; content policy, data category, privacy requirement or output modality change; new harm taxonomy or evaluation method",
      "primary_ai_lifecycle_stage": "Data preparation; design and development; verification and validation; deployment; operation and user interaction.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D5-CTL-06",
      "domain_code": "D5",
      "domain_name": "Content Safety & Output Integrity",
      "control_title": "Privacy-Preserving ML Validation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with dp_epsilon_value, membership_inference_results, dp_training_certificate",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.5; 6.3.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5.2; 6.5.3; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2; Annex A",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D5-CTL-06-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Privacy-Preserving ML Validation; execute or independently verify D5-CTL-06-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Privacy-Preserving ML Validation; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; content policy, data category, privacy requirement or output modality change; new harm taxonomy or evaluation method",
      "primary_ai_lifecycle_stage": "Data preparation; design and development; verification and validation; deployment; operation and user interaction.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D6-CTL-01",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Human-In-The-Loop For High-Risk Actions",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with approval_request_log, approver_id, timestamp, justification",
      "iso_23894_references": "4; 5.1; 5.2; 5.3; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.5; 5.6; 5.7; 6.2; 6.3; 6.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C; 6.3.3",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D6-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Human-In-The-Loop For High-Risk Actions; execute or independently verify D6-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for Human-In-The-Loop For High-Risk Actions, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; governance, owner, policy or approval-process change; major incident or exercise finding; business continuity or decommissioning change",
      "primary_ai_lifecycle_stage": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "The supplied human-in-the-loop VTS is a reference pattern. The blocked action, intervention point, escalation path, response time and acceptance criteria shall be adapted to the specific high-risk context, such as clinical decision support, financial authorization or autonomous-vehicle intervention.",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D6-CTL-02",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Audit Trail Completeness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON/SIEM log with decision_id, timestamp, input_hash, output_hash, system_id, approver_id",
      "iso_23894_references": "4; 5.1; 5.2; 5.3; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.5; 5.6; 5.7; 6.2; 6.3; 6.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C; 5.7.1; 5.7.2",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D6-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Audit Trail Completeness; execute or independently verify D6-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for Audit Trail Completeness, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; governance, owner, policy or approval-process change; major incident or exercise finding; business continuity or decommissioning change",
      "primary_ai_lifecycle_stage": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D6-CTL-03",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "AI Model Card Completeness",
      "foundational_required": true,
      "gaissf_evidence_format": "Markdown/JSON with model_id, owner, purpose, data_sources, limitations, risk_tier, review_date",
      "iso_23894_references": "4; 5.1; 5.2; 5.3; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.5; 5.6; 5.7; 6.2; 6.3; 6.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D6-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI Model Card Completeness; execute or independently verify D6-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for AI Model Card Completeness, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; governance, owner, policy or approval-process change; major incident or exercise finding; business continuity or decommissioning change",
      "primary_ai_lifecycle_stage": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D6-CTL-04",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "AI Incident Response Readiness",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with exercise_date, participants, mttc_achieved, lessons_learned, improvement_tracker",
      "iso_23894_references": "4; 5.1; 5.2; 5.3; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.5; 5.6; 5.7; 6.2; 6.3; 6.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C; 5.7.1; 5.7.2",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D6-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI Incident Response Readiness; execute or independently verify D6-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for AI Incident Response Readiness, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; governance, owner, policy or approval-process change; major incident or exercise finding; business continuity or decommissioning change",
      "primary_ai_lifecycle_stage": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "Recommended supplementary automated validation profile (not a new GAISSF control): exercise automated detection, containment, rollback, evidence capture and escalation actions against approved AI incident-response playbooks, with human authorization retained where required.",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D6-CTL-05",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Model Deprecation & Decommissioning",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with model_id, decommission_date, access_revocation_log, traffic_verification",
      "iso_23894_references": "4; 5.1; 5.2; 5.3; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.5; 5.6; 5.7; 6.2; 6.3; 6.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C; 5.7.1; 5.7.2",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D6-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Model Deprecation & Decommissioning; execute or independently verify D6-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for Model Deprecation & Decommissioning, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; governance, owner, policy or approval-process change; major incident or exercise finding; business continuity or decommissioning change",
      "primary_ai_lifecycle_stage": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D6-CTL-06",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "Third-Party AI Vendor Governance",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with vendor_name, assessment_date, soc2_status, contract_review_summary",
      "iso_23894_references": "4; 5.1; 5.2; 5.3; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.5; 5.6; 5.7; 6.2; 6.3; 6.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C; 6.3.3; 6.4.2; 6.5.3",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D6-CTL-06-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Third-Party AI Vendor Governance; execute or independently verify D6-CTL-06-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for Third-Party AI Vendor Governance, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; governance, owner, policy or approval-process change; major incident or exercise finding; business continuity or decommissioning change",
      "primary_ai_lifecycle_stage": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D6-CTL-07",
      "domain_code": "D6",
      "domain_name": "Governance, Accountability & Human Oversight",
      "control_title": "AI Resilience & Business Continuity",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with bcp_test_date, rto_achieved, rpo_achieved, degraded_mode_capabilities, improvement_tracker",
      "iso_23894_references": "4; 5.1; 5.2; 5.3; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.5; 5.6; 5.7; 6.2; 6.3; 6.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C; 5.7.1; 5.7.2",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D6-CTL-07-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI Resilience & Business Continuity; execute or independently verify D6-CTL-07-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for AI Resilience & Business Continuity, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; governance, owner, policy or approval-process change; major incident or exercise finding; business continuity or decommissioning change",
      "primary_ai_lifecycle_stage": "All lifecycle stages, with emphasis on governance, approval gates, monitoring, incident response and retirement.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D7-CTL-H01",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "AI-Generated Phishing Simulation",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with simulation_date, click_rate, coverage_percentage, training_completion",
      "iso_23894_references": "4; 5.4.1; 5.4.5; 5.5; 5.6; 6.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D7-CTL-H01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI-Generated Phishing Simulation; execute or independently verify D7-CTL-H01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 supports identification, analysis, treatment and monitoring of the risks addressed by AI-Generated Phishing Simulation, but only partially addresses the operational safeguards and evidence granularity required by GAISSF.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new human/social harm scenario; training or authentication process change; material external threat trend",
      "primary_ai_lifecycle_stage": "Design and impact assessment; verification and validation; deployment; operation; stakeholder communication and incident response.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D7-CTL-H02",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "Deepfake Detection Training",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with training_date, completion_rate_by_role, quiz_pass_rate",
      "iso_23894_references": "4; 5.4.1; 5.4.5; 5.5; 5.6; 6.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D7-CTL-H02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Deepfake Detection Training; execute or independently verify D7-CTL-H02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 supports identification, analysis, treatment and monitoring of the risks addressed by Deepfake Detection Training, but only partially addresses the operational safeguards and evidence granularity required by GAISSF.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new human/social harm scenario; training or authentication process change; material external threat trend",
      "primary_ai_lifecycle_stage": "Design and impact assessment; verification and validation; deployment; operation; stakeholder communication and incident response.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D7-CTL-H03",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "Out-Of-Band Authentication",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with oob_enforcement_log, policy_compliance_report, exception_log",
      "iso_23894_references": "4; 5.4.1; 5.4.5; 5.5; 5.6; 6.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D7-CTL-H03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Out-Of-Band Authentication; execute or independently verify D7-CTL-H03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 supports identification, analysis, treatment and monitoring of the risks addressed by Out-Of-Band Authentication, but only partially addresses the operational safeguards and evidence granularity required by GAISSF.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new human/social harm scenario; training or authentication process change; material external threat trend",
      "primary_ai_lifecycle_stage": "Design and impact assessment; verification and validation; deployment; operation; stakeholder communication and incident response.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D7-CTL-H04",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "AI Social Engineering IR",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with exercise_date, participants, verification_triggered, financial_hold_applied, improvements",
      "iso_23894_references": "4; 5.4.1; 5.4.5; 5.5; 5.6; 6.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D7-CTL-H04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI Social Engineering IR; execute or independently verify D7-CTL-H04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 supports identification, analysis, treatment and monitoring of the risks addressed by AI Social Engineering IR, but only partially addresses the operational safeguards and evidence granularity required by GAISSF.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new human/social harm scenario; training or authentication process change; material external threat trend",
      "primary_ai_lifecycle_stage": "Design and impact assessment; verification and validation; deployment; operation; stakeholder communication and incident response.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D7-CTL-H05",
      "domain_code": "D7",
      "domain_name": "Human & Societal Harms",
      "control_title": "AI-Enhanced External Attack Defense",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with detection_time, quarantine_action, soc_alert_log",
      "iso_23894_references": "4; 5.4.1; 5.4.5; 5.5; 5.6; 6.2; 6.3.3; 6.3.4; 6.4.2; 6.4.3; 6.4.4; 6.5; 6.6; 6.7; Annex A; Annex B; Annex C",
      "relationship": "Partial",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D7-CTL-H05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for AI-Enhanced External Attack Defense; execute or independently verify D7-CTL-H05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 supports identification, analysis, treatment and monitoring of the risks addressed by AI-Enhanced External Attack Defense, but only partially addresses the operational safeguards and evidence granularity required by GAISSF.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; new human/social harm scenario; training or authentication process change; material external threat trend",
      "primary_ai_lifecycle_stage": "Design and impact assessment; verification and validation; deployment; operation; stakeholder communication and incident response.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D8-CTL-01",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "EU AI Act Risk Tier Mapping",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with system_id, risk_tier, classification_justification, conformity_evidence",
      "iso_23894_references": "4; 5.1-5.7; 6.1-6.7; Annex A; Annex B; Annex C",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D8-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for EU AI Act Risk Tier Mapping; execute or independently verify D8-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for EU AI Act Risk Tier Mapping, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; change in law, regulation or authoritative guidance; new jurisdiction or sector; regulatory enforcement development",
      "primary_ai_lifecycle_stage": "All lifecycle stages through legal, regulatory and assurance checkpoints, with periodic re-evaluation.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D8-CTL-02",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "ISO 42001 Gap Analysis",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with clause_by_clause_status, remediation_plan, completion_tracker",
      "iso_23894_references": "4; 5.1-5.7; 6.1-6.7; Annex A; Annex B; Annex C",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D8-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for ISO 42001 Gap Analysis; execute or independently verify D8-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for ISO 42001 Gap Analysis, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; change in law, regulation or authoritative guidance; new jurisdiction or sector; regulatory enforcement development",
      "primary_ai_lifecycle_stage": "All lifecycle stages through legal, regulatory and assurance checkpoints, with periodic re-evaluation.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D8-CTL-03",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "GPAI Technical Documentation Verification",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with model_id, technical_doc_hash, training_data_summary, copyright_attestation",
      "iso_23894_references": "4; 5.1-5.7; 6.1-6.7; Annex A; Annex B; Annex C",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D8-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for GPAI Technical Documentation Verification; execute or independently verify D8-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for GPAI Technical Documentation Verification, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; change in law, regulation or authoritative guidance; new jurisdiction or sector; regulatory enforcement development",
      "primary_ai_lifecycle_stage": "All lifecycle stages through legal, regulatory and assurance checkpoints, with periodic re-evaluation.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D8-CTL-04",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "DORA Ict Incident Reporting (Financial Sector)",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with incident_id, classification, notification_timestamp, nca_submission",
      "iso_23894_references": "4; 5.1-5.7; 6.1-6.7; Annex A; Annex B; Annex C; 5.6; 5.7.1; 5.7.2; 6.6; 6.7",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D8-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Dora Ict Incident Reporting (Financial Sector); execute or independently verify D8-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for DORA Ict Incident Reporting (Financial Sector), but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; change in law, regulation or authoritative guidance; new jurisdiction or sector; regulatory enforcement development",
      "primary_ai_lifecycle_stage": "All lifecycle stages through legal, regulatory and assurance checkpoints, with periodic re-evaluation.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D8-CTL-05",
      "domain_code": "D8",
      "domain_name": "Regulatory Alignment & Compliance",
      "control_title": "Nist Sp 800-218A Compliance Check",
      "foundational_required": true,
      "gaissf_evidence_format": "JSON with sp800_218a_practice_status, attestation_statement, continuous_monitoring_log",
      "iso_23894_references": "4; 5.1-5.7; 6.1-6.7; Annex A; Annex B; Annex C",
      "relationship": "Strong partial",
      "mapping_confidence": "Medium-High",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D8-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Nist Sp 800-218A Compliance Check; execute or independently verify D8-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 strongly aligns with the governance, ownership, assessment, treatment, monitoring and reporting processes needed for Nist Sp 800-218A Compliance Check, but it does not prescribe the GAISSF-specific technical mechanism, measurable threshold or validation evidence needed to demonstrate the control outcome.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; change in law, regulation or authoritative guidance; new jurisdiction or sector; regulatory enforcement development",
      "primary_ai_lifecycle_stage": "All lifecycle stages through legal, regulatory and assurance checkpoints, with periodic re-evaluation.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Canonical D1-D8 baseline",
      "validation_method": "Independently controlled validation appropriate to the control, system boundary, threat/harm scenario and assurance objective. Where a GAISSF validation asset is published, current and applicable, it may be used as one method.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D9-CTL-01",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Physical Harm Boundary Enforcement",
      "foundational_required": false,
      "gaissf_evidence_format": "Hardware-in-the-loop test report (JSON with command_id, value, blocked, monitor_response_time_ms); safety monitor certification certificate (DO-178C / IEC 61508)",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.4.4; 5.5; 6.3; 6.4; 6.5; 6.6; 6.7; Annex B; Annex C; 6.3.2; 6.3.3; 6.4.2; 6.4.3; 6.5.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D9-CTL-01-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Physical Harm Boundary Enforcement; execute or independently verify D9-CTL-01-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Physical Harm Boundary Enforcement; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; hardware, firmware, actuator, sensor or deployment-environment change; HIL/simulator change; physical safety incident or near miss",
      "primary_ai_lifecycle_stage": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D9-CTL-02",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Safe State And Graceful Degradation",
      "foundational_required": false,
      "gaissf_evidence_format": "Safe state test report (JSON with trigger_condition, transition_time_ms, safe_state_achieved, assessor_verification)",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.4.4; 5.5; 6.3; 6.4; 6.5; 6.6; 6.7; Annex B; Annex C; 6.3.2; 6.3.3; 6.4.2; 6.4.3; 6.5.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D9-CTL-02-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Safe State And Graceful Degradation; execute or independently verify D9-CTL-02-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Safe State And Graceful Degradation; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; hardware, firmware, actuator, sensor or deployment-environment change; HIL/simulator change; physical safety incident or near miss",
      "primary_ai_lifecycle_stage": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D9-CTL-03",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Human Override And Emergency Stop",
      "foundational_required": false,
      "gaissf_evidence_format": "Override test report (JSON with override_type, test_condition, latency_ms, outcome). Physical E-stop certification documentation",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.4.4; 5.5; 6.3; 6.4; 6.5; 6.6; 6.7; Annex B; Annex C; 5.4.5; 6.2; 6.3.3; Annex A; 6.3.2; 6.4.2; 6.4.3; 6.5.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D9-CTL-03-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Human Override And Emergency Stop; execute or independently verify D9-CTL-03-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Human Override And Emergency Stop; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; hardware, firmware, actuator, sensor or deployment-environment change; HIL/simulator change; physical safety incident or near miss",
      "primary_ai_lifecycle_stage": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D9-CTL-04",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Cyber-Physical Attack Detection",
      "foundational_required": false,
      "gaissf_evidence_format": "Hardware-in-the-loop detection test report (JSON with attack_type, injected_count, detected_count, detection_rate, false_positive_rate, mean_time_to_safe_state_ms)",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.4.4; 5.5; 6.3; 6.4; 6.5; 6.6; 6.7; Annex B; Annex C; 6.3.2; 6.3.3; 6.4.2; 6.4.3; 6.5.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D9-CTL-04-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Cyber-Physical Attack Detection; execute or independently verify D9-CTL-04-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Cyber-Physical Attack Detection; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; hardware, firmware, actuator, sensor or deployment-environment change; HIL/simulator change; physical safety incident or near miss",
      "primary_ai_lifecycle_stage": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D9-CTL-05",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Physical Environment Integrity Monitoring",
      "foundational_required": false,
      "gaissf_evidence_format": "Sensor failure injection test report (JSON with failure_mode, response_time_ms, system_response, assessor_verification); calibration certificate register",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.4.4; 5.5; 6.3; 6.4; 6.5; 6.6; 6.7; Annex B; Annex C; 5.6; 5.7.1; 5.7.2; 6.3.2; 6.3.3; 6.4.2; 6.4.3; 6.5.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D9-CTL-05-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Physical Environment Integrity Monitoring; execute or independently verify D9-CTL-05-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Physical Environment Integrity Monitoring; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; hardware, firmware, actuator, sensor or deployment-environment change; HIL/simulator change; physical safety incident or near miss",
      "primary_ai_lifecycle_stage": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D9-CTL-06",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Actuator Command Verification",
      "foundational_required": false,
      "gaissf_evidence_format": "Hardware-in-the-loop verification test report (JSON with command_id, command_type, block_reason, gate_response_time_ms, dual_approval_test_result). IEC 61508 SIL 3 certification certificate for verification gate",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.4.4; 5.5; 6.3; 6.4; 6.5; 6.6; 6.7; Annex B; Annex C; 6.3.2; 6.3.3; 6.4.2; 6.4.3; 6.5.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D9-CTL-06-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Actuator Command Verification; execute or independently verify D9-CTL-06-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Actuator Command Verification; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; hardware, firmware, actuator, sensor or deployment-environment change; HIL/simulator change; physical safety incident or near miss",
      "primary_ai_lifecycle_stage": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    },
    {
      "control_id": "D9-CTL-07",
      "domain_code": "D9",
      "domain_name": "Physical AI Safety",
      "control_title": "Physical Incident Evidence Preservation",
      "foundational_required": false,
      "gaissf_evidence_format": "Incident evidence package (OSCAL-compatible JSON bundle with sensor_stream, model_input_output_stream, actuator_command_stream, safety_monitor_log, human_override_log, cryptographic_chain_of_custody)",
      "iso_23894_references": "4; 5.3; 5.4.1; 5.4.4; 5.5; 6.3; 6.4; 6.5; 6.6; 6.7; Annex B; Annex C; 5.6; 5.7.1; 5.7.2; 6.3.2; 6.3.3; 6.4.2; 6.4.3; 6.5.2",
      "relationship": "Supporting",
      "mapping_confidence": "Medium",
      "source_status": "Clause structure confirmed from authorized preview; detailed semantic alignment is ODA3 analytical inference pending licensed full-text verification.",
      "risk_evidence_reuse": "AI risk policy, scope/context record, risk criteria, risk register entry, risk analysis and evaluation record, risk-treatment plan, accountable owner approval, communication/consultation record, monitoring results, and review/reporting evidence, subject to GAISSF scope, authenticity, currency and operating-effectiveness checks.",
      "oda3_derived_risk_extension": "ODA3-derived risk extension: record the AI asset/system boundary, threat or harm scenario, affected stakeholders, likelihood/consequence rationale, risk owner, treatment decision, measurable acceptance criteria, validation evidence, residual risk, review trigger and linkage to the GAISSF control/validation.",
      "additional_gaissf_validation": "Execute or independently verify D9-CTL-07-validation-001 using assurance-appropriate fixtures and signed evidence.",
      "gaissf_residual_notably_absent": "ISO/IEC 23894 provides risk-management guidance rather than a control-specific technical pass criterion. It does not, by itself, demonstrate the GAISSF outcome for Physical Incident Evidence Preservation; execute or independently verify D9-CTL-07-validation-001 and retain schema-conformant evidence.",
      "source_baseline": "ISO/IEC 23894:2023 official ISO abstract and authorized ANSI preview; ISO 31000 relationship as stated in preview; GAISSF v1.0 normative/validation sources.",
      "relationship_justification": "ISO/IEC 23894 provides the risk-management process used to justify, prioritize and review Physical Incident Evidence Preservation; the technical design, test procedure and pass criteria remain GAISSF-specific.",
      "revalidation_trigger": "annual scheduled review; revision to ISO/IEC 23894; material GAISSF/validation revision; hardware, firmware, actuator, sensor or deployment-environment change; HIL/simulator change; physical safety incident or near miss",
      "primary_ai_lifecycle_stage": "System design; physical integration; HIL validation; deployment; operation and monitoring; emergency response and decommissioning.",
      "source_tier_basis": "[Authoritative GAISSF source] GAISSF normative control and validation release; [Verified external source] ISO official metadata and authorized ANSI preview structure; [ODA3 analysis] ODA3 analytical semantic mapping; [Implementation recommendation] implementation and re-validation recommendations.",
      "context_adaptation_note": "",
      "supplementary_validation_profile": "",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_method": "System- and hazard-appropriate simulation/HIL/physical testing where D9 applies; no universal SIL/DAL or certification level is implied.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations."
    }
  ],
  "source_claim_classes": {
    "authoritative_gaissf": "Current GAISSF normative publication set; excludes held/internal VTS material.",
    "verified_external_public": "ISO official metadata/abstract and authorized preview; publicly verifiable structure only.",
    "oda3_analytical_mapping": "Source-bounded ODA3 analytical inference; not full-text verification.",
    "implementation_recommendation": "Non-normative implementation/revalidation guidance."
  }
}