{
  "document": {
    "document_id": "GAISSF-CRO-022",
    "title": "GAISSF™–NIST AI RMF Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "classification": "Informative public crosswalk",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "candidate_date": "2026-06-29",
    "updated": "2026-10-05",
    "publication_channels": [
      "docs.oda3.org",
      "official ODA3 publication channels"
    ],
    "schema_version": "1.0"
  },
  "source_baseline": {
    "gaissf": {
      "framework_standard": "GAISSF-NOR-001 v1.0",
      "control_catalogue": "GAISSF-NOR-004 v1.0",
      "published": "2026-07-01",
      "updated": "2026-10-04",
      "control_count": 59,
      "domain_count": 9,
      "applicable_control_baseline": "52 controls in D1-D8 plus D9 where Physical AI or cyber-physical actuation is in scope"
    },
    "nist": {
      "identifier": "NIST AI 100-1",
      "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)",
      "published": "2023-01-26",
      "target_edition": "AI RMF 1.0",
      "core_subcategories": 72,
      "revision_status": "AI RMF 1.0 is being revised during 2026; a released revision triggers crosswalk revalidation"
    }
  },
  "mapping_boundary": [
    "Mapping establishes correspondence only.",
    "No mapping establishes equivalence, evidence sufficiency, operating effectiveness, NIST endorsement, NIST certification, legal or regulatory compliance, or automatic conformance.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only and does not establish equivalence, evidence sufficiency, or automatic conformance.",
    "Independent crosswalk review and explicit publication approval remain open."
  ],
  "controlled_vocabulary": {
    "relationship": {
      "SP": "Strong partial",
      "P": "Partial",
      "S": "Supporting",
      "C": "Contextual",
      "N": "No material mapping",
      "O": "Outside scope",
      "U": "Unable to determine"
    },
    "confidence": [
      "High",
      "Medium-High",
      "Medium",
      "Low",
      "Not Rated"
    ]
  },
  "statistics": {
    "gaissf_controls": 59,
    "nist_core_subcategories": 72,
    "forward_mapping_records": 167,
    "reverse_mapping_records": 72
  },
  "gaissf_controls": [
    {
      "id": "D1-CTL-01",
      "title": "Dataset Provenance & Poisoning Prevention",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-02",
      "title": "Model Extraction Resistance",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-03",
      "title": "Behavioral Drift Detection",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-04",
      "title": "Federated Learning Poisoning Prevention",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-05",
      "title": "Embedding Space Robustness",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-06",
      "title": "Post-Quantum Model Signing & Crypto Hardening",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-07",
      "title": "Lora/Adapter Integrity Verification",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-08",
      "title": "Model Merge Attack Detection",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-09",
      "title": "Quantization Backdoor Screening",
      "domain_id": "D1",
      "domain": "Model Integrity & Adversarial Robustness",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-01",
      "title": "Direct Prompt Injection Prevention",
      "domain_id": "D2",
      "domain": "Runtime Security & Adversarial Defense",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-02",
      "title": "Indirect Prompt Injection Prevention",
      "domain_id": "D2",
      "domain": "Runtime Security & Adversarial Defense",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-03",
      "title": "Jailbreak Resistance Testing",
      "domain_id": "D2",
      "domain": "Runtime Security & Adversarial Defense",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-04",
      "title": "Multi-Modal Injection Defense",
      "domain_id": "D2",
      "domain": "Runtime Security & Adversarial Defense",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-05",
      "title": "Function Call/Tool Call Injection Prevention",
      "domain_id": "D2",
      "domain": "Runtime Security & Adversarial Defense",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-06",
      "title": "Cross-Context Hijacking Mitigation",
      "domain_id": "D2",
      "domain": "Runtime Security & Adversarial Defense",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-01",
      "title": "Least Agency Enforcement",
      "domain_id": "D3",
      "domain": "Agentic Risk & Autonomous System Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-02",
      "title": "Inter-Agent Communication Security",
      "domain_id": "D3",
      "domain": "Agentic Risk & Autonomous System Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-03",
      "title": "Agentic Prompt Chaining Detection",
      "domain_id": "D3",
      "domain": "Agentic Risk & Autonomous System Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-04",
      "title": "Embodied Ai Safety Controls",
      "domain_id": "D3",
      "domain": "Agentic Risk & Autonomous System Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-05",
      "title": "Multi-Agent Trust Chain Attestation",
      "domain_id": "D3",
      "domain": "Agentic Risk & Autonomous System Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-06",
      "title": "Persistent Memory Exfiltration Prevention",
      "domain_id": "D3",
      "domain": "Agentic Risk & Autonomous System Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-07",
      "title": "Secure Memory Lifecycle Management",
      "domain_id": "D3",
      "domain": "Agentic Risk & Autonomous System Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-01",
      "title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "domain_id": "D4",
      "domain": "Supply Chain & Third-Party AI Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-02",
      "title": "Model File & Artifact Scanning",
      "domain_id": "D4",
      "domain": "Supply Chain & Third-Party AI Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-03",
      "title": "Model Hub & Registry Vetting",
      "domain_id": "D4",
      "domain": "Supply Chain & Third-Party AI Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-04",
      "title": "Mcp Server Behavioral Monitoring",
      "domain_id": "D4",
      "domain": "Supply Chain & Third-Party AI Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-05",
      "title": "Third-Party Ai Api Security Assessment",
      "domain_id": "D4",
      "domain": "Supply Chain & Third-Party AI Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-06",
      "title": "Shadow Ai Discovery & Governance",
      "domain_id": "D4",
      "domain": "Supply Chain & Third-Party AI Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-07",
      "title": "Ai Software Composition Analysis (Sca)",
      "domain_id": "D4",
      "domain": "Supply Chain & Third-Party AI Security",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-01",
      "title": "Harmful Content Blocking",
      "domain_id": "D5",
      "domain": "Content Safety & Output Integrity",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-02",
      "title": "Pii Leakage Prevention",
      "domain_id": "D5",
      "domain": "Content Safety & Output Integrity",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-03",
      "title": "Copyright Detection",
      "domain_id": "D5",
      "domain": "Content Safety & Output Integrity",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-04",
      "title": "Ai Watermarking Robustness",
      "domain_id": "D5",
      "domain": "Content Safety & Output Integrity",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-05",
      "title": "Privacy-By-Design Verification",
      "domain_id": "D5",
      "domain": "Content Safety & Output Integrity",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-06",
      "title": "Privacy-Preserving Ml Validation",
      "domain_id": "D5",
      "domain": "Content Safety & Output Integrity",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-01",
      "title": "Human-In-The-Loop For High-Risk Actions",
      "domain_id": "D6",
      "domain": "Governance, Accountability & Human Oversight",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-02",
      "title": "Audit Trail Completeness",
      "domain_id": "D6",
      "domain": "Governance, Accountability & Human Oversight",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-03",
      "title": "Ai Model Card Completeness",
      "domain_id": "D6",
      "domain": "Governance, Accountability & Human Oversight",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-04",
      "title": "Ai Incident Response Readiness",
      "domain_id": "D6",
      "domain": "Governance, Accountability & Human Oversight",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-05",
      "title": "Model Deprecation & Decommissioning",
      "domain_id": "D6",
      "domain": "Governance, Accountability & Human Oversight",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-06",
      "title": "Third-Party Ai Vendor Governance",
      "domain_id": "D6",
      "domain": "Governance, Accountability & Human Oversight",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-07",
      "title": "Ai Resilience & Business Continuity",
      "domain_id": "D6",
      "domain": "Governance, Accountability & Human Oversight",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H01",
      "title": "Ai-Generated Phishing Simulation",
      "domain_id": "D7",
      "domain": "Human & Societal Harms",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H02",
      "title": "Deepfake Detection Training",
      "domain_id": "D7",
      "domain": "Human & Societal Harms",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H03",
      "title": "Out-Of-Band Authentication",
      "domain_id": "D7",
      "domain": "Human & Societal Harms",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H04",
      "title": "Ai Social Engineering Ir",
      "domain_id": "D7",
      "domain": "Human & Societal Harms",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H05",
      "title": "Ai-Enhanced External Attack Defense",
      "domain_id": "D7",
      "domain": "Human & Societal Harms",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-01",
      "title": "Eu Ai Act Risk Tier Mapping",
      "domain_id": "D8",
      "domain": "Regulatory Alignment & Compliance",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-02",
      "title": "Iso 42001 Gap Analysis",
      "domain_id": "D8",
      "domain": "Regulatory Alignment & Compliance",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-03",
      "title": "Gpai Technical Documentation Verification",
      "domain_id": "D8",
      "domain": "Regulatory Alignment & Compliance",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-04",
      "title": "Dora Ict Incident Reporting (Financial Sector)",
      "domain_id": "D8",
      "domain": "Regulatory Alignment & Compliance",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-05",
      "title": "Nist Sp 800-218A Compliance Check",
      "domain_id": "D8",
      "domain": "Regulatory Alignment & Compliance",
      "baseline_scope": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D9-CTL-01",
      "title": "Physical Harm Boundary Enforcement",
      "domain_id": "D9",
      "domain": "Physical AI Safety",
      "baseline_scope": "Additional / conditional; include when Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-02",
      "title": "Safe State And Graceful Degradation",
      "domain_id": "D9",
      "domain": "Physical AI Safety",
      "baseline_scope": "Additional / conditional; include when Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-03",
      "title": "Human Override And Emergency Stop",
      "domain_id": "D9",
      "domain": "Physical AI Safety",
      "baseline_scope": "Additional / conditional; include when Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-04",
      "title": "Cyber-Physical Attack Detection",
      "domain_id": "D9",
      "domain": "Physical AI Safety",
      "baseline_scope": "Additional / conditional; include when Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-05",
      "title": "Physical Environment Integrity Monitoring",
      "domain_id": "D9",
      "domain": "Physical AI Safety",
      "baseline_scope": "Additional / conditional; include when Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-06",
      "title": "Actuator Command Verification",
      "domain_id": "D9",
      "domain": "Physical AI Safety",
      "baseline_scope": "Additional / conditional; include when Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-07",
      "title": "Physical Incident Evidence Preservation",
      "domain_id": "D9",
      "domain": "Physical AI Safety",
      "baseline_scope": "Additional / conditional; include when Physical AI or cyber-physical actuation is in scope"
    }
  ],
  "nist_core_subcategories": [
    {
      "id": "GOVERN 1.1",
      "function": "GOVERN",
      "text": "Legal and regulatory requirements involving AI are understood, managed, and documented."
    },
    {
      "id": "GOVERN 1.2",
      "function": "GOVERN",
      "text": "The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices."
    },
    {
      "id": "GOVERN 1.3",
      "function": "GOVERN",
      "text": "Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance."
    },
    {
      "id": "GOVERN 1.4",
      "function": "GOVERN",
      "text": "The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued)"
    },
    {
      "id": "GOVERN 1.5",
      "function": "GOVERN",
      "text": "Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review."
    },
    {
      "id": "GOVERN 1.6",
      "function": "GOVERN",
      "text": "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities."
    },
    {
      "id": "GOVERN 1.7",
      "function": "GOVERN",
      "text": "Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness. GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks."
    },
    {
      "id": "GOVERN 2.1",
      "function": "GOVERN",
      "text": "Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization."
    },
    {
      "id": "GOVERN 2.2",
      "function": "GOVERN",
      "text": "The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements."
    },
    {
      "id": "GOVERN 2.3",
      "function": "GOVERN",
      "text": "Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment. GOVERN 3: Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle."
    },
    {
      "id": "GOVERN 3.1",
      "function": "GOVERN",
      "text": "Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, experience, expertise, and backgrounds)."
    },
    {
      "id": "GOVERN 3.2",
      "function": "GOVERN",
      "text": "Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems. GOVERN 4: Organizational teams are committed to a culture"
    },
    {
      "id": "GOVERN 4.1",
      "function": "GOVERN",
      "text": "Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) that considers and communicates AI risk."
    },
    {
      "id": "GOVERN 4.2",
      "function": "GOVERN",
      "text": "Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly."
    },
    {
      "id": "GOVERN 4.3",
      "function": "GOVERN",
      "text": "Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. GOVERN 5: Processes are in place for robust engagement with relevant AI actors."
    },
    {
      "id": "GOVERN 5.1",
      "function": "GOVERN",
      "text": "Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks."
    },
    {
      "id": "GOVERN 5.2",
      "function": "GOVERN",
      "text": "Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues."
    },
    {
      "id": "GOVERN 6.1",
      "function": "GOVERN",
      "text": "Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights."
    },
    {
      "id": "GOVERN 6.2",
      "function": "GOVERN",
      "text": "Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. Categories Subcategories 5.2 Map The MAP function establishes the context to frame risks related to an AI system. The AI lifecycle consists of many interdependent activities involving a diverse set of actors (See Figure 3). In practice, AI actors in charge of one part of the process often do not have full visibility or control over other parts and their associated contexts."
    },
    {
      "id": "MAP 1.1",
      "function": "MAP",
      "text": "Intended purposes, potentially beneficial uses, contextspecific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics."
    },
    {
      "id": "MAP 1.2",
      "function": "MAP",
      "text": "Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their participation is documented. Opportunities for interdisciplinary collaboration are prioritized."
    },
    {
      "id": "MAP 1.3",
      "function": "MAP",
      "text": "The organization’s mission and relevant goals for AI technology are understood and documented."
    },
    {
      "id": "MAP 1.4",
      "function": "MAP",
      "text": "The business value or context of business use has been clearly defined or - in the case of assessing existing AI systems - re-evaluated."
    },
    {
      "id": "MAP 1.5",
      "function": "MAP",
      "text": "Organizational risk tolerances are determined and documented."
    },
    {
      "id": "MAP 1.6",
      "function": "MAP",
      "text": "System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks. MAP 2: Categorization of the AI system is performed."
    },
    {
      "id": "MAP 2.1",
      "function": "MAP",
      "text": "The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders)."
    },
    {
      "id": "MAP 2.2",
      "function": "MAP",
      "text": "Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued)"
    },
    {
      "id": "MAP 2.3",
      "function": "MAP",
      "text": "Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation. MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood."
    },
    {
      "id": "MAP 3.1",
      "function": "MAP",
      "text": "Potential benefits of intended AI system functionality and performance are examined and documented."
    },
    {
      "id": "MAP 3.2",
      "function": "MAP",
      "text": "Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness - as connected to organizational risk tolerance - are examined and documented."
    },
    {
      "id": "MAP 3.3",
      "function": "MAP",
      "text": "Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization."
    },
    {
      "id": "MAP 3.4",
      "function": "MAP",
      "text": "Processes for operator and practitioner proficiency with AI system performance and trustworthiness - and relevant technical standards and certifications - are defined, assessed, and documented."
    },
    {
      "id": "MAP 3.5",
      "function": "MAP",
      "text": "Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. MAP 4: Risks and benefits are mapped for all components of the AI system including third-party software and data."
    },
    {
      "id": "MAP 4.1",
      "function": "MAP",
      "text": "Approaches for mapping AI technology and legal risks of its components - including the use of third-party data or software - are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights."
    },
    {
      "id": "MAP 4.2",
      "function": "MAP",
      "text": "Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized."
    },
    {
      "id": "MAP 5.1",
      "function": "MAP",
      "text": "Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident reports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued)"
    },
    {
      "id": "MAP 5.2",
      "function": "MAP",
      "text": "Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. Categories Subcategories 5.3 Measure The MEASURE function employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts. It uses knowledge relevant to AI risks identified in the MAP function and informs the MANAGE function. AI systems should be tested before their deployment and regularly while in operation."
    },
    {
      "id": "MEASURE 1.1",
      "function": "MEASURE",
      "text": "Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not - or cannot - be measured are properly documented."
    },
    {
      "id": "MEASURE 1.2",
      "function": "MEASURE",
      "text": "Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities."
    },
    {
      "id": "MEASURE 1.3",
      "function": "MEASURE",
      "text": "Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. MEASURE 2: AI systems are evaluated for trustworthy characteristics."
    },
    {
      "id": "MEASURE 2.1",
      "function": "MEASURE",
      "text": "Test sets, metrics, and details about the tools used during TEVV are documented."
    },
    {
      "id": "MEASURE 2.2",
      "function": "MEASURE",
      "text": "Evaluations involving human subjects meet applicable requirements (including human subject protection) and are representative of the relevant population."
    },
    {
      "id": "MEASURE 2.3",
      "function": "MEASURE",
      "text": "AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented."
    },
    {
      "id": "MEASURE 2.4",
      "function": "MEASURE",
      "text": "The functionality and behavior of the AI system and its components - as identified in the MAP function - are monitored when in production."
    },
    {
      "id": "MEASURE 2.5",
      "function": "MEASURE",
      "text": "The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued)"
    },
    {
      "id": "MEASURE 2.6",
      "function": "MEASURE",
      "text": "The AI system is evaluated regularly for safety risks - as identified in the MAP function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures."
    },
    {
      "id": "MEASURE 2.7",
      "function": "MEASURE",
      "text": "AI system security and resilience - as identified in the MAP function - are evaluated and documented."
    },
    {
      "id": "MEASURE 2.8",
      "function": "MEASURE",
      "text": "Risks associated with transparency and accountability - as identified in the MAP function - are examined and documented."
    },
    {
      "id": "MEASURE 2.9",
      "function": "MEASURE",
      "text": "The AI model is explained, validated, and documented, and AI system output is interpreted within its context - as identified in the MAP function - to inform responsible use and governance."
    },
    {
      "id": "MEASURE 2.10",
      "function": "MEASURE",
      "text": "Privacy risk of the AI system - as identified in the MAP function - is examined and documented."
    },
    {
      "id": "MEASURE 2.11",
      "function": "MEASURE",
      "text": "Fairness and bias - as identified in the MAP function - are evaluated and results are documented."
    },
    {
      "id": "MEASURE 2.12",
      "function": "MEASURE",
      "text": "Environmental impact and sustainability of AI model training and management activities - as identified in the MAP function - are assessed and documented."
    },
    {
      "id": "MEASURE 2.13",
      "function": "MEASURE",
      "text": "Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. MEASURE 3: Mechanisms for tracking identified AI risks over time are in place."
    },
    {
      "id": "MEASURE 3.1",
      "function": "MEASURE",
      "text": "Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts."
    },
    {
      "id": "MEASURE 3.2",
      "function": "MEASURE",
      "text": "Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued)"
    },
    {
      "id": "MEASURE 3.3",
      "function": "MEASURE",
      "text": "Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. MEASURE 4: Feedback about efficacy of measurement is gathered and assessed."
    },
    {
      "id": "MEASURE 4.1",
      "function": "MEASURE",
      "text": "Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Approaches are documented."
    },
    {
      "id": "MEASURE 4.2",
      "function": "MEASURE",
      "text": "Measurement results regarding AI system trustworthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI actors to validate whether the system is performing consistently as intended. Results are documented."
    },
    {
      "id": "MEASURE 4.3",
      "function": "MEASURE",
      "text": "Measurable performance improvements or declines based on consultations with relevant AI actors, including affected communities, and field data about contextrelevant risks and trustworthiness characteristics are identified and documented. Categories Subcategories 5.4 Manage The MANAGE function entails allocating risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function. Risk treatment comprises plans to respond to, recover from, and communicate about incidents or events."
    },
    {
      "id": "MANAGE 1.1",
      "function": "MANAGE",
      "text": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed."
    },
    {
      "id": "MANAGE 1.2",
      "function": "MANAGE",
      "text": "Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods."
    },
    {
      "id": "MANAGE 1.3",
      "function": "MANAGE",
      "text": "Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting."
    },
    {
      "id": "MANAGE 1.4",
      "function": "MANAGE",
      "text": "Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors."
    },
    {
      "id": "MANAGE 2.1",
      "function": "MANAGE",
      "text": "Resources required to manage AI risks are taken into account - along with viable non-AI alternative systems, approaches, or methods - to reduce the magnitude or likelihood of potential impacts."
    },
    {
      "id": "MANAGE 2.2",
      "function": "MANAGE",
      "text": "Mechanisms are in place and applied to sustain the value of deployed AI systems."
    },
    {
      "id": "MANAGE 2.3",
      "function": "MANAGE",
      "text": "Procedures are followed to respond to and recover from a previously unknown risk when it is identified."
    },
    {
      "id": "MANAGE 2.4",
      "function": "MANAGE",
      "text": "Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. MANAGE 3: AI risks and benefits from third-party entities are managed."
    },
    {
      "id": "MANAGE 3.1",
      "function": "MANAGE",
      "text": "AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented."
    },
    {
      "id": "MANAGE 3.2",
      "function": "MANAGE",
      "text": "Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 4: Categories and subcategories for the MANAGE function. (Continued) MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly."
    },
    {
      "id": "MANAGE 4.1",
      "function": "MANAGE",
      "text": "Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management."
    },
    {
      "id": "MANAGE 4.2",
      "function": "MANAGE",
      "text": "Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including relevant AI actors."
    },
    {
      "id": "MANAGE 4.3",
      "function": "MANAGE",
      "text": "Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. Categories Subcategories 6. AI RMF Profiles AI RMF use-case profiles are implementations of the AI RMF functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the Framework user: for example, an AI RMF hiring profile or an AI RMF fair housing profile."
    }
  ],
  "gaissf_to_nist_mappings": [
    {
      "record_id": "GAISSF-CRO-022-MAP-0001",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-01 supports MEASURE 4.3 through the control objective for dataset provenance & poisoning prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0002",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-01 supports GOVERN 6.2 through the control objective for dataset provenance & poisoning prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0003",
      "gaissf_control_id": "D1-CTL-01",
      "gaissf_control_title": "Dataset Provenance & Poisoning Prevention",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MANAGE 2.4",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-01 supports MANAGE 2.4 through the control objective for dataset provenance & poisoning prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0004",
      "gaissf_control_id": "D1-CTL-02",
      "gaissf_control_title": "Model Extraction Resistance",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-02 supports MAP 5.2 through the control objective for model extraction resistance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0005",
      "gaissf_control_id": "D1-CTL-02",
      "gaissf_control_title": "Model Extraction Resistance",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-02 supports MEASURE 2.6 through the control objective for model extraction resistance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0006",
      "gaissf_control_id": "D1-CTL-02",
      "gaissf_control_title": "Model Extraction Resistance",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MANAGE 3.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-02 supports MANAGE 3.2 through the control objective for model extraction resistance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0007",
      "gaissf_control_id": "D1-CTL-03",
      "gaissf_control_title": "Behavioral Drift Detection",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-03 supports MANAGE 4.1 through the control objective for behavioral drift detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0008",
      "gaissf_control_id": "D1-CTL-03",
      "gaissf_control_title": "Behavioral Drift Detection",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MANAGE 3.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-03 supports MANAGE 3.2 through the control objective for behavioral drift detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0009",
      "gaissf_control_id": "D1-CTL-03",
      "gaissf_control_title": "Behavioral Drift Detection",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-03 supports MAP 5.2 through the control objective for behavioral drift detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0010",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-04 supports MEASURE 2.1 through the control objective for federated learning poisoning prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0011",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-04 supports MEASURE 2.7 through the control objective for federated learning poisoning prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0012",
      "gaissf_control_id": "D1-CTL-04",
      "gaissf_control_title": "Federated Learning Poisoning Prevention",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-04 supports MEASURE 4.3 through the control objective for federated learning poisoning prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0013",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-05 supports MEASURE 2.6 through the control objective for embedding space robustness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0014",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MAP 5.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-05 supports MAP 5.1 through the control objective for embedding space robustness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0015",
      "gaissf_control_id": "D1-CTL-05",
      "gaissf_control_title": "Embedding Space Robustness",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-05 supports GOVERN 4.1 through the control objective for embedding space robustness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0016",
      "gaissf_control_id": "D1-CTL-06",
      "gaissf_control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-06 supports MEASURE 2.1 through the control objective for post-quantum model signing & crypto hardening. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0017",
      "gaissf_control_id": "D1-CTL-06",
      "gaissf_control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-06 supports MEASURE 2.7 through the control objective for post-quantum model signing & crypto hardening. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0018",
      "gaissf_control_id": "D1-CTL-06",
      "gaissf_control_title": "Post-Quantum Model Signing & Crypto Hardening",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-06 supports MEASURE 4.3 through the control objective for post-quantum model signing & crypto hardening. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0019",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-07 supports MEASURE 4.3 through the control objective for lora/adapter integrity verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0020",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MANAGE 2.4",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-07 supports MANAGE 2.4 through the control objective for lora/adapter integrity verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0021",
      "gaissf_control_id": "D1-CTL-07",
      "gaissf_control_title": "Lora/Adapter Integrity Verification",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MANAGE 3.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-07 supports MANAGE 3.1 through the control objective for lora/adapter integrity verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0022",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 supports MEASURE 2.6 through the control objective for model merge attack detection. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0023",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 supports MEASURE 2.1 through the control objective for model merge attack detection. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0024",
      "gaissf_control_id": "D1-CTL-08",
      "gaissf_control_title": "Model Merge Attack Detection",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 supports MEASURE 2.7 through the control objective for model merge attack detection. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0025",
      "gaissf_control_id": "D1-CTL-09",
      "gaissf_control_title": "Quantization Backdoor Screening",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-09 supports MEASURE 2.6 through the control objective for quantization backdoor screening. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0026",
      "gaissf_control_id": "D1-CTL-09",
      "gaissf_control_title": "Quantization Backdoor Screening",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D1-CTL-09 supports MAP 5.2 through the control objective for quantization backdoor screening. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0027",
      "gaissf_control_id": "D1-CTL-09",
      "gaissf_control_title": "Quantization Backdoor Screening",
      "gaissf_domain_id": "D1",
      "gaissf_domain": "Model Integrity & Adversarial Robustness",
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D1-CTL-09 supports MANAGE 4.1 through the control objective for quantization backdoor screening. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0028",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "GOVERN 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-01 supports GOVERN 4.3 through the control objective for direct prompt injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0029",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-01 supports MEASURE 4.3 through the control objective for direct prompt injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0030",
      "gaissf_control_id": "D2-CTL-01",
      "gaissf_control_title": "Direct Prompt Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-01 supports MEASURE 2.7 through the control objective for direct prompt injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0031",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-02 supports MAP 5.2 through the control objective for indirect prompt injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0032",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-02 supports MEASURE 2.7 through the control objective for indirect prompt injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0033",
      "gaissf_control_id": "D2-CTL-02",
      "gaissf_control_title": "Indirect Prompt Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-02 supports MEASURE 2.6 through the control objective for indirect prompt injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0034",
      "gaissf_control_id": "D2-CTL-03",
      "gaissf_control_title": "Jailbreak Resistance Testing",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-03 supports MEASURE 2.6 through the control objective for jailbreak resistance testing. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0035",
      "gaissf_control_id": "D2-CTL-03",
      "gaissf_control_title": "Jailbreak Resistance Testing",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-03 supports MAP 5.2 through the control objective for jailbreak resistance testing. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0036",
      "gaissf_control_id": "D2-CTL-03",
      "gaissf_control_title": "Jailbreak Resistance Testing",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-03 supports GOVERN 4.1 through the control objective for jailbreak resistance testing. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0037",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-04 supports MAP 5.2 through the control objective for multi-modal injection defense. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0038",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D2-CTL-04 supports MEASURE 2.7 through the control objective for multi-modal injection defense. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0039",
      "gaissf_control_id": "D2-CTL-04",
      "gaissf_control_title": "Multi-Modal Injection Defense",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 1.2",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D2-CTL-04 supports MEASURE 1.2 through the control objective for multi-modal injection defense. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0040",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-05 supports MEASURE 2.7 through the control objective for function call/tool call injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0041",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D2-CTL-05 supports MAP 5.2 through the control objective for function call/tool call injection prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0042",
      "gaissf_control_id": "D2-CTL-05",
      "gaissf_control_title": "Function Call/Tool Call Injection Prevention",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 1.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D2-CTL-05 supports MEASURE 1.1 through the control objective for function call/tool call injection prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0043",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D2-CTL-06 supports MEASURE 2.7 through the control objective for cross-context hijacking mitigation. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0044",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "MEASURE 2.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D2-CTL-06 supports MEASURE 2.1 through the control objective for cross-context hijacking mitigation. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0045",
      "gaissf_control_id": "D2-CTL-06",
      "gaissf_control_title": "Cross-Context Hijacking Mitigation",
      "gaissf_domain_id": "D2",
      "gaissf_domain": "Runtime Security & Adversarial Defense",
      "nist_ai_rmf_subcategory": "GOVERN 4.3",
      "relationship": "S",
      "confidence": "Medium",
      "rationale": "D2-CTL-06 supports GOVERN 4.3 through the control objective for cross-context hijacking mitigation. Relationship: S; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0046",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 3.5",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-01 supports MAP 3.5 through the control objective for least agency enforcement. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0047",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 2.9",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-01 supports MEASURE 2.9 through the control objective for least agency enforcement. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0048",
      "gaissf_control_id": "D3-CTL-01",
      "gaissf_control_title": "Least Agency Enforcement",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-01 supports MEASURE 4.3 through the control objective for least agency enforcement. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0049",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 2.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-02 supports MAP 2.3 through the control objective for inter-agent communication security. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0050",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 1.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-02 supports MEASURE 1.3 through the control objective for inter-agent communication security. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0051",
      "gaissf_control_id": "D3-CTL-02",
      "gaissf_control_title": "Inter-Agent Communication Security",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-02 supports MEASURE 2.7 through the control objective for inter-agent communication security. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0052",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-03 supports MEASURE 2.7 through the control objective for agentic prompt chaining detection. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0053",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 1.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-03 supports MAP 1.1 through the control objective for agentic prompt chaining detection. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0054",
      "gaissf_control_id": "D3-CTL-03",
      "gaissf_control_title": "Agentic Prompt Chaining Detection",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 1.6",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-03 supports MAP 1.6 through the control objective for agentic prompt chaining detection. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0055",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-04 supports MEASURE 2.6 through the control objective for embodied ai safety controls. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0056",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-04 supports GOVERN 4.1 through the control objective for embodied ai safety controls. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0057",
      "gaissf_control_id": "D3-CTL-04",
      "gaissf_control_title": "Embodied Ai Safety Controls",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 2.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-04 supports MAP 2.3 through the control objective for embodied ai safety controls. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0058",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-05 supports MEASURE 2.7 through the control objective for multi-agent trust chain attestation. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0059",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 1.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-05 supports MAP 1.1 through the control objective for multi-agent trust chain attestation. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0060",
      "gaissf_control_id": "D3-CTL-05",
      "gaissf_control_title": "Multi-Agent Trust Chain Attestation",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 1.6",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-05 supports MAP 1.6 through the control objective for multi-agent trust chain attestation. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0061",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-06 supports MEASURE 2.7 through the control objective for persistent memory exfiltration prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0062",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 1.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-06 supports MAP 1.1 through the control objective for persistent memory exfiltration prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0063",
      "gaissf_control_id": "D3-CTL-06",
      "gaissf_control_title": "Persistent Memory Exfiltration Prevention",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 1.6",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D3-CTL-06 supports MAP 1.6 through the control objective for persistent memory exfiltration prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0064",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MAP 3.5",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-07 supports MAP 3.5 through the control objective for secure memory lifecycle management. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0065",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "MEASURE 2.9",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-07 supports MEASURE 2.9 through the control objective for secure memory lifecycle management. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0066",
      "gaissf_control_id": "D3-CTL-07",
      "gaissf_control_title": "Secure Memory Lifecycle Management",
      "gaissf_domain_id": "D3",
      "gaissf_domain": "Agentic Risk & Autonomous System Security",
      "nist_ai_rmf_subcategory": "GOVERN 2.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D3-CTL-07 supports GOVERN 2.3 through the control objective for secure memory lifecycle management. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0067",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-01 supports GOVERN 6.2 through the control objective for ai bill of materials (ai bom) maintenance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0068",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-01 supports MEASURE 4.3 through the control objective for ai bill of materials (ai bom) maintenance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0069",
      "gaissf_control_id": "D4-CTL-01",
      "gaissf_control_title": "Ai Bill Of Materials (Ai Bom) Maintenance",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 1.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-01 supports GOVERN 1.6 through the control objective for ai bill of materials (ai bom) maintenance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0070",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-02 supports GOVERN 5.2 through the control objective for model file & artifact scanning. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0071",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 6.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-02 supports GOVERN 6.1 through the control objective for model file & artifact scanning. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0072",
      "gaissf_control_id": "D4-CTL-02",
      "gaissf_control_title": "Model File & Artifact Scanning",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-02 supports GOVERN 6.2 through the control objective for model file & artifact scanning. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0073",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-03 supports GOVERN 5.2 through the control objective for model hub & registry vetting. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0074",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 6.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-03 supports GOVERN 6.1 through the control objective for model hub & registry vetting. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0075",
      "gaissf_control_id": "D4-CTL-03",
      "gaissf_control_title": "Model Hub & Registry Vetting",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-03 supports GOVERN 6.2 through the control objective for model hub & registry vetting. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0076",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MANAGE 3.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-04 supports MANAGE 3.1 through the control objective for mcp server behavioral monitoring. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0077",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-04 supports GOVERN 5.2 through the control objective for mcp server behavioral monitoring. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0078",
      "gaissf_control_id": "D4-CTL-04",
      "gaissf_control_title": "Mcp Server Behavioral Monitoring",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-04 supports GOVERN 6.2 through the control objective for mcp server behavioral monitoring. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0079",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MAP 1.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-05 supports MAP 1.6 through the control objective for third-party ai api security assessment. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0080",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MAP 4.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D4-CTL-05 supports MAP 4.1 through the control objective for third-party ai api security assessment. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0081",
      "gaissf_control_id": "D4-CTL-05",
      "gaissf_control_title": "Third-Party Ai Api Security Assessment",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D4-CTL-05 supports GOVERN 5.2 through the control objective for third-party ai api security assessment. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0082",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-06 supports GOVERN 5.2 through the control objective for shadow ai discovery & governance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0083",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MAP 3.5",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-06 supports MAP 3.5 through the control objective for shadow ai discovery & governance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0084",
      "gaissf_control_id": "D4-CTL-06",
      "gaissf_control_title": "Shadow Ai Discovery & Governance",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-06 supports MEASURE 4.3 through the control objective for shadow ai discovery & governance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0085",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D4-CTL-07 supports GOVERN 5.2 through the control objective for ai software composition analysis (sca). Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0086",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MAP 3.5",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D4-CTL-07 supports MAP 3.5 through the control objective for ai software composition analysis (sca). Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0087",
      "gaissf_control_id": "D4-CTL-07",
      "gaissf_control_title": "Ai Software Composition Analysis (Sca)",
      "gaissf_domain_id": "D4",
      "gaissf_domain": "Supply Chain & Third-Party AI Security",
      "nist_ai_rmf_subcategory": "MANAGE 4.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D4-CTL-07 supports MANAGE 4.3 through the control objective for ai software composition analysis (sca). Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0088",
      "gaissf_control_id": "D5-CTL-01",
      "gaissf_control_title": "Harmful Content Blocking",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-01 supports GOVERN 4.1 through the control objective for harmful content blocking. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0089",
      "gaissf_control_id": "D5-CTL-01",
      "gaissf_control_title": "Harmful Content Blocking",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-01 supports MEASURE 2.6 through the control objective for harmful content blocking. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0090",
      "gaissf_control_id": "D5-CTL-01",
      "gaissf_control_title": "Harmful Content Blocking",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MAP 5.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D5-CTL-01 supports MAP 5.1 through the control objective for harmful content blocking. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0091",
      "gaissf_control_id": "D5-CTL-02",
      "gaissf_control_title": "Pii Leakage Prevention",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-02 supports MEASURE 2.6 through the control objective for pii leakage prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0092",
      "gaissf_control_id": "D5-CTL-02",
      "gaissf_control_title": "Pii Leakage Prevention",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-02 supports GOVERN 4.1 through the control objective for pii leakage prevention. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0093",
      "gaissf_control_id": "D5-CTL-02",
      "gaissf_control_title": "Pii Leakage Prevention",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MAP 2.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D5-CTL-02 supports MAP 2.3 through the control objective for pii leakage prevention. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0094",
      "gaissf_control_id": "D5-CTL-03",
      "gaissf_control_title": "Copyright Detection",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-03 supports MEASURE 2.6 through the control objective for copyright detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0095",
      "gaissf_control_id": "D5-CTL-03",
      "gaissf_control_title": "Copyright Detection",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-03 supports GOVERN 4.1 through the control objective for copyright detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0096",
      "gaissf_control_id": "D5-CTL-03",
      "gaissf_control_title": "Copyright Detection",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MAP 2.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D5-CTL-03 supports MAP 2.3 through the control objective for copyright detection. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0097",
      "gaissf_control_id": "D5-CTL-04",
      "gaissf_control_title": "Ai Watermarking Robustness",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-04 supports MEASURE 2.6 through the control objective for ai watermarking robustness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0098",
      "gaissf_control_id": "D5-CTL-04",
      "gaissf_control_title": "Ai Watermarking Robustness",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "GOVERN 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-04 supports GOVERN 4.3 through the control objective for ai watermarking robustness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0099",
      "gaissf_control_id": "D5-CTL-04",
      "gaissf_control_title": "Ai Watermarking Robustness",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MAP 5.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-04 supports MAP 5.1 through the control objective for ai watermarking robustness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0100",
      "gaissf_control_id": "D5-CTL-05",
      "gaissf_control_title": "Privacy-By-Design Verification",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-05 supports MEASURE 2.6 through the control objective for privacy-by-design verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0101",
      "gaissf_control_id": "D5-CTL-05",
      "gaissf_control_title": "Privacy-By-Design Verification",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-05 supports GOVERN 4.1 through the control objective for privacy-by-design verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0102",
      "gaissf_control_id": "D5-CTL-05",
      "gaissf_control_title": "Privacy-By-Design Verification",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MAP 1.6",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D5-CTL-05 supports MAP 1.6 through the control objective for privacy-by-design verification. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0103",
      "gaissf_control_id": "D5-CTL-06",
      "gaissf_control_title": "Privacy-Preserving Ml Validation",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-06 supports MEASURE 2.6 through the control objective for privacy-preserving ml validation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0104",
      "gaissf_control_id": "D5-CTL-06",
      "gaissf_control_title": "Privacy-Preserving Ml Validation",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-06 supports GOVERN 4.1 through the control objective for privacy-preserving ml validation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0105",
      "gaissf_control_id": "D5-CTL-06",
      "gaissf_control_title": "Privacy-Preserving Ml Validation",
      "gaissf_domain_id": "D5",
      "gaissf_domain": "Content Safety & Output Integrity",
      "nist_ai_rmf_subcategory": "MAP 2.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D5-CTL-06 supports MAP 2.3 through the control objective for privacy-preserving ml validation. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0106",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-01 supports MEASURE 4.3 through the control objective for human-in-the-loop for high-risk actions. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0107",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-01 supports GOVERN 1.7 through the control objective for human-in-the-loop for high-risk actions. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0108",
      "gaissf_control_id": "D6-CTL-01",
      "gaissf_control_title": "Human-In-The-Loop For High-Risk Actions",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 3.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-01 supports GOVERN 3.2 through the control objective for human-in-the-loop for high-risk actions. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0109",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-02 supports GOVERN 4.3 through the control objective for audit trail completeness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0110",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-02 supports MEASURE 4.3 through the control objective for audit trail completeness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0111",
      "gaissf_control_id": "D6-CTL-02",
      "gaissf_control_title": "Audit Trail Completeness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D6-CTL-02 supports GOVERN 1.7 through the control objective for audit trail completeness. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0112",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D6-CTL-03 supports GOVERN 1.7 through the control objective for ai model card completeness. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0113",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 2.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D6-CTL-03 supports GOVERN 2.3 through the control objective for ai model card completeness. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0114",
      "gaissf_control_id": "D6-CTL-03",
      "gaissf_control_title": "Ai Model Card Completeness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 3.2",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D6-CTL-03 supports GOVERN 3.2 through the control objective for ai model card completeness. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0115",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-04 supports MEASURE 4.3 through the control objective for ai incident response readiness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0116",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-04 supports GOVERN 1.7 through the control objective for ai incident response readiness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0117",
      "gaissf_control_id": "D6-CTL-04",
      "gaissf_control_title": "Ai Incident Response Readiness",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.4",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-04 supports GOVERN 1.4 through the control objective for ai incident response readiness. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0118",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.5",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-05 supports GOVERN 1.5 through the control objective for model deprecation & decommissioning. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0119",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-05 supports MANAGE 4.1 through the control objective for model deprecation & decommissioning. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0120",
      "gaissf_control_id": "D6-CTL-05",
      "gaissf_control_title": "Model Deprecation & Decommissioning",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-05 supports GOVERN 1.7 through the control objective for model deprecation & decommissioning. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0121",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 supports MEASURE 4.3 through the control objective for third-party ai vendor governance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0122",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 supports GOVERN 5.2 through the control objective for third-party ai vendor governance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0123",
      "gaissf_control_id": "D6-CTL-06",
      "gaissf_control_title": "Third-Party Ai Vendor Governance",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "MANAGE 4.3",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 supports MANAGE 4.3 through the control objective for third-party ai vendor governance. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0124",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 supports GOVERN 1.7 through the control objective for ai resilience & business continuity. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0125",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 3.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 supports GOVERN 3.2 through the control objective for ai resilience & business continuity. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0126",
      "gaissf_control_id": "D6-CTL-07",
      "gaissf_control_title": "Ai Resilience & Business Continuity",
      "gaissf_domain_id": "D6",
      "gaissf_domain": "Governance, Accountability & Human Oversight",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 supports GOVERN 4.1 through the control objective for ai resilience & business continuity. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0127",
      "gaissf_control_id": "D7-CTL-H01",
      "gaissf_control_title": "Ai-Generated Phishing Simulation",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 2.2",
      "relationship": "C",
      "confidence": "Low",
      "rationale": "D7-CTL-H01 supports GOVERN 2.2 through the control objective for ai-generated phishing simulation. Relationship: C; confidence: Low. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0128",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 4.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D7-CTL-H02 supports GOVERN 4.3 through the control objective for deepfake detection training. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0129",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D7-CTL-H02 supports GOVERN 6.2 through the control objective for deepfake detection training. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0130",
      "gaissf_control_id": "D7-CTL-H02",
      "gaissf_control_title": "Deepfake Detection Training",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D7-CTL-H02 supports MEASURE 4.3 through the control objective for deepfake detection training. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0131",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 1.4",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D7-CTL-H03 supports GOVERN 1.4 through the control objective for out-of-band authentication. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0132",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 1.5",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D7-CTL-H03 supports GOVERN 1.5 through the control objective for out-of-band authentication. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0133",
      "gaissf_control_id": "D7-CTL-H03",
      "gaissf_control_title": "Out-Of-Band Authentication",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D7-CTL-H03 supports GOVERN 1.7 through the control objective for out-of-band authentication. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0134",
      "gaissf_control_id": "D7-CTL-H04",
      "gaissf_control_title": "Ai Social Engineering Ir",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 2.2",
      "relationship": "C",
      "confidence": "Low",
      "rationale": "D7-CTL-H04 supports GOVERN 2.2 through the control objective for ai social engineering ir. Relationship: C; confidence: Low. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0135",
      "gaissf_control_id": "D7-CTL-H05",
      "gaissf_control_title": "Ai-Enhanced External Attack Defense",
      "gaissf_domain_id": "D7",
      "gaissf_domain": "Human & Societal Harms",
      "nist_ai_rmf_subcategory": "GOVERN 5.1",
      "relationship": "C",
      "confidence": "Low",
      "rationale": "D7-CTL-H05 supports GOVERN 5.1 through the control objective for ai-enhanced external attack defense. Relationship: C; confidence: Low. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0136",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "relationship": "S",
      "confidence": "Medium",
      "rationale": "D8-CTL-01 supports GOVERN 6.2 through the control objective for eu ai act risk tier mapping. Relationship: S; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0137",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "MAP 2.2",
      "relationship": "S",
      "confidence": "Medium",
      "rationale": "D8-CTL-01 supports MAP 2.2 through the control objective for eu ai act risk tier mapping. Relationship: S; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0138",
      "gaissf_control_id": "D8-CTL-01",
      "gaissf_control_title": "Eu Ai Act Risk Tier Mapping",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "MAP 3.2",
      "relationship": "S",
      "confidence": "Medium",
      "rationale": "D8-CTL-01 supports MAP 3.2 through the control objective for eu ai act risk tier mapping. Relationship: S; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0139",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D8-CTL-02 supports GOVERN 5.2 through the control objective for iso 42001 gap analysis. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0140",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "MANAGE 2.1",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D8-CTL-02 supports MANAGE 2.1 through the control objective for iso 42001 gap analysis. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0141",
      "gaissf_control_id": "D8-CTL-02",
      "gaissf_control_title": "Iso 42001 Gap Analysis",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "GOVERN 1.6",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D8-CTL-02 supports GOVERN 1.6 through the control objective for iso 42001 gap analysis. Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0142",
      "gaissf_control_id": "D8-CTL-03",
      "gaissf_control_title": "Gpai Technical Documentation Verification",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "GOVERN 1.1",
      "relationship": "C",
      "confidence": "Low",
      "rationale": "D8-CTL-03 supports GOVERN 1.1 through the control objective for gpai technical documentation verification. Relationship: C; confidence: Low. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0143",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D8-CTL-04 supports MANAGE 4.1 through the control objective for dora ict incident reporting (financial sector). Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0144",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "MANAGE 3.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D8-CTL-04 supports MANAGE 3.2 through the control objective for dora ict incident reporting (financial sector). Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0145",
      "gaissf_control_id": "D8-CTL-04",
      "gaissf_control_title": "Dora Ict Incident Reporting (Financial Sector)",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "GOVERN 1.5",
      "relationship": "P",
      "confidence": "Medium",
      "rationale": "D8-CTL-04 supports GOVERN 1.5 through the control objective for dora ict incident reporting (financial sector). Relationship: P; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0146",
      "gaissf_control_id": "D8-CTL-05",
      "gaissf_control_title": "Nist Sp 800-218A Compliance Check",
      "gaissf_domain_id": "D8",
      "gaissf_domain": "Regulatory Alignment & Compliance",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "S",
      "confidence": "Medium",
      "rationale": "D8-CTL-05 supports GOVERN 4.1 through the control objective for nist sp 800-218a compliance check. Relationship: S; confidence: Medium. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0147",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-01 supports MEASURE 2.6 through the control objective for physical harm boundary enforcement. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0148",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-01 supports MAP 5.2 through the control objective for physical harm boundary enforcement. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0149",
      "gaissf_control_id": "D9-CTL-01",
      "gaissf_control_title": "Physical Harm Boundary Enforcement",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-01 supports MANAGE 4.1 through the control objective for physical harm boundary enforcement. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0150",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-02 supports MEASURE 2.6 through the control objective for safe state and graceful degradation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0151",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-02 supports MEASURE 2.7 through the control objective for safe state and graceful degradation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0152",
      "gaissf_control_id": "D9-CTL-02",
      "gaissf_control_title": "Safe State And Graceful Degradation",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-02 supports GOVERN 4.1 through the control objective for safe state and graceful degradation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0153",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-03 supports MEASURE 2.6 through the control objective for human override and emergency stop. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0154",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-03 supports MAP 5.2 through the control objective for human override and emergency stop. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0155",
      "gaissf_control_id": "D9-CTL-03",
      "gaissf_control_title": "Human Override And Emergency Stop",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-03 supports GOVERN 4.1 through the control objective for human override and emergency stop. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0156",
      "gaissf_control_id": "D9-CTL-04",
      "gaissf_control_title": "Cyber-Physical Attack Detection",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MANAGE 3.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-04 supports MANAGE 3.2 through the control objective for cyber-physical attack detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0157",
      "gaissf_control_id": "D9-CTL-04",
      "gaissf_control_title": "Cyber-Physical Attack Detection",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-04 supports MAP 5.2 through the control objective for cyber-physical attack detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0158",
      "gaissf_control_id": "D9-CTL-04",
      "gaissf_control_title": "Cyber-Physical Attack Detection",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-04 supports MEASURE 2.6 through the control objective for cyber-physical attack detection. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0159",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-05 supports MEASURE 2.6 through the control objective for physical environment integrity monitoring. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0160",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-05 supports MANAGE 4.1 through the control objective for physical environment integrity monitoring. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0161",
      "gaissf_control_id": "D9-CTL-05",
      "gaissf_control_title": "Physical Environment Integrity Monitoring",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MANAGE 3.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-05 supports MANAGE 3.2 through the control objective for physical environment integrity monitoring. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0162",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-06 supports MEASURE 2.6 through the control objective for actuator command verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0163",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-06 supports MAP 5.2 through the control objective for actuator command verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0164",
      "gaissf_control_id": "D9-CTL-06",
      "gaissf_control_title": "Actuator Command Verification",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-06 supports GOVERN 4.1 through the control objective for actuator command verification. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0165",
      "gaissf_control_id": "D9-CTL-07",
      "gaissf_control_title": "Physical Incident Evidence Preservation",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-07 supports MEASURE 2.6 through the control objective for physical incident evidence preservation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0166",
      "gaissf_control_id": "D9-CTL-07",
      "gaissf_control_title": "Physical Incident Evidence Preservation",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-07 supports MAP 5.2 through the control objective for physical incident evidence preservation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    },
    {
      "record_id": "GAISSF-CRO-022-MAP-0167",
      "gaissf_control_id": "D9-CTL-07",
      "gaissf_control_title": "Physical Incident Evidence Preservation",
      "gaissf_domain_id": "D9",
      "gaissf_domain": "Physical AI Safety",
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "relationship": "SP",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-07 supports MANAGE 4.1 through the control objective for physical incident evidence preservation. Relationship: SP; confidence: Medium-High. Correspondence only; no equivalence, evidence sufficiency, operating effectiveness, certification credit, or automatic conformance is established.",
      "residual_gap": "Context-specific actors, affected parties, risk tolerance, metrics, lifecycle evidence, and residual-risk decisions remain necessary where required by the NIST outcome."
    }
  ],
  "nist_to_gaissf_reverse_coverage": [
    {
      "nist_ai_rmf_subcategory": "GOVERN 1.1",
      "nist_outcome": "Legal and regulatory requirements involving AI are understood, managed, and documented.",
      "gaissf_control_ids": [
        "D8-CTL-03"
      ],
      "coverage_status": "Indirectly Supported",
      "relationship": "C",
      "confidence": "Low",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 1.2",
      "nist_outcome": "The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 1.3",
      "nist_outcome": "Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 1.4",
      "nist_outcome": "The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued)",
      "gaissf_control_ids": [
        "D6-CTL-04",
        "D7-CTL-H03"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 1.5",
      "nist_outcome": "Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review.",
      "gaissf_control_ids": [
        "D6-CTL-05",
        "D7-CTL-H03",
        "D8-CTL-04"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 1.6",
      "nist_outcome": "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.",
      "gaissf_control_ids": [
        "D4-CTL-01",
        "D8-CTL-02"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 1.7",
      "nist_outcome": "Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness. GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks.",
      "gaissf_control_ids": [
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-07"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 2.1",
      "nist_outcome": "Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 2.2",
      "nist_outcome": "The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements.",
      "gaissf_control_ids": [
        "D7-CTL-H01",
        "D7-CTL-H04"
      ],
      "coverage_status": "Indirectly Supported",
      "relationship": "C",
      "confidence": "Low",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 2.3",
      "nist_outcome": "Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment. GOVERN 3: Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle.",
      "gaissf_control_ids": [
        "D3-CTL-07",
        "D6-CTL-03"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 3.1",
      "nist_outcome": "Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, experience, expertise, and backgrounds).",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 3.2",
      "nist_outcome": "Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems. GOVERN 4: Organizational teams are committed to a culture",
      "gaissf_control_ids": [
        "D6-CTL-01",
        "D6-CTL-03",
        "D6-CTL-07"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 4.1",
      "nist_outcome": "Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 1: Categories and subcategories for the GOVERN function. (Continued) that considers and communicates AI risk.",
      "gaissf_control_ids": [
        "D1-CTL-05",
        "D2-CTL-03",
        "D3-CTL-04",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 4.2",
      "nist_outcome": "Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 4.3",
      "nist_outcome": "Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. GOVERN 5: Processes are in place for robust engagement with relevant AI actors.",
      "gaissf_control_ids": [
        "D2-CTL-01",
        "D2-CTL-06",
        "D5-CTL-04",
        "D6-CTL-02",
        "D7-CTL-H02"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 5.1",
      "nist_outcome": "Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks.",
      "gaissf_control_ids": [
        "D7-CTL-H05"
      ],
      "coverage_status": "Indirectly Supported",
      "relationship": "C",
      "confidence": "Low",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 5.2",
      "nist_outcome": "Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues.",
      "gaissf_control_ids": [
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 6.1",
      "nist_outcome": "Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights.",
      "gaissf_control_ids": [
        "D4-CTL-02",
        "D4-CTL-03"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "GOVERN 6.2",
      "nist_outcome": "Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. Categories Subcategories 5.2 Map The MAP function establishes the context to frame risks related to an AI system. The AI lifecycle consists of many interdependent activities involving a diverse set of actors (See Figure 3). In practice, AI actors in charge of one part of the process often do not have full visibility or control over other parts and their associated contexts.",
      "gaissf_control_ids": [
        "D1-CTL-01",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D7-CTL-H02"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 1.1",
      "nist_outcome": "Intended purposes, potentially beneficial uses, contextspecific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics.",
      "gaissf_control_ids": [
        "D3-CTL-03",
        "D3-CTL-05",
        "D3-CTL-06"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 1.2",
      "nist_outcome": "Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their participation is documented. Opportunities for interdisciplinary collaboration are prioritized.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 1.3",
      "nist_outcome": "The organization’s mission and relevant goals for AI technology are understood and documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 1.4",
      "nist_outcome": "The business value or context of business use has been clearly defined or - in the case of assessing existing AI systems - re-evaluated.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 1.5",
      "nist_outcome": "Organizational risk tolerances are determined and documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 1.6",
      "nist_outcome": "System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks. MAP 2: Categorization of the AI system is performed.",
      "gaissf_control_ids": [
        "D3-CTL-03",
        "D3-CTL-05",
        "D3-CTL-06",
        "D4-CTL-05",
        "D5-CTL-05"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 2.1",
      "nist_outcome": "The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders).",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 2.2",
      "nist_outcome": "Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued)",
      "gaissf_control_ids": [
        "D8-CTL-01"
      ],
      "coverage_status": "Indirectly Supported",
      "relationship": "S",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 2.3",
      "nist_outcome": "Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation. MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood.",
      "gaissf_control_ids": [
        "D3-CTL-02",
        "D3-CTL-04",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-06"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 3.1",
      "nist_outcome": "Potential benefits of intended AI system functionality and performance are examined and documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 3.2",
      "nist_outcome": "Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness - as connected to organizational risk tolerance - are examined and documented.",
      "gaissf_control_ids": [
        "D8-CTL-01"
      ],
      "coverage_status": "Indirectly Supported",
      "relationship": "S",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 3.3",
      "nist_outcome": "Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 3.4",
      "nist_outcome": "Processes for operator and practitioner proficiency with AI system performance and trustworthiness - and relevant technical standards and certifications - are defined, assessed, and documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 3.5",
      "nist_outcome": "Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. MAP 4: Risks and benefits are mapped for all components of the AI system including third-party software and data.",
      "gaissf_control_ids": [
        "D3-CTL-01",
        "D3-CTL-07",
        "D4-CTL-06",
        "D4-CTL-07"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 4.1",
      "nist_outcome": "Approaches for mapping AI technology and legal risks of its components - including the use of third-party data or software - are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights.",
      "gaissf_control_ids": [
        "D4-CTL-05"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 4.2",
      "nist_outcome": "Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 5.1",
      "nist_outcome": "Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident reports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 2: Categories and subcategories for the MAP function. (Continued)",
      "gaissf_control_ids": [
        "D1-CTL-05",
        "D5-CTL-01",
        "D5-CTL-04"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MAP 5.2",
      "nist_outcome": "Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. Categories Subcategories 5.3 Measure The MEASURE function employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts. It uses knowledge relevant to AI risks identified in the MAP function and informs the MANAGE function. AI systems should be tested before their deployment and regularly while in operation.",
      "gaissf_control_ids": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-09",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 1.1",
      "nist_outcome": "Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not - or cannot - be measured are properly documented.",
      "gaissf_control_ids": [
        "D2-CTL-05"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 1.2",
      "nist_outcome": "Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities.",
      "gaissf_control_ids": [
        "D2-CTL-04"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 1.3",
      "nist_outcome": "Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. MEASURE 2: AI systems are evaluated for trustworthy characteristics.",
      "gaissf_control_ids": [
        "D3-CTL-02"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.1",
      "nist_outcome": "Test sets, metrics, and details about the tools used during TEVV are documented.",
      "gaissf_control_ids": [
        "D1-CTL-04",
        "D1-CTL-06",
        "D1-CTL-08",
        "D2-CTL-06"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.2",
      "nist_outcome": "Evaluations involving human subjects meet applicable requirements (including human subject protection) and are representative of the relevant population.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.3",
      "nist_outcome": "AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.4",
      "nist_outcome": "The functionality and behavior of the AI system and its components - as identified in the MAP function - are monitored when in production.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.5",
      "nist_outcome": "The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued)",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.6",
      "nist_outcome": "The AI system is evaluated regularly for safety risks - as identified in the MAP function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures.",
      "gaissf_control_ids": [
        "D1-CTL-02",
        "D1-CTL-05",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-02",
        "D2-CTL-03"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.7",
      "nist_outcome": "AI system security and resilience - as identified in the MAP function - are evaluated and documented.",
      "gaissf_control_ids": [
        "D1-CTL-04",
        "D1-CTL-06",
        "D1-CTL-08",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-04"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.8",
      "nist_outcome": "Risks associated with transparency and accountability - as identified in the MAP function - are examined and documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.9",
      "nist_outcome": "The AI model is explained, validated, and documented, and AI system output is interpreted within its context - as identified in the MAP function - to inform responsible use and governance.",
      "gaissf_control_ids": [
        "D3-CTL-01",
        "D3-CTL-07"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.10",
      "nist_outcome": "Privacy risk of the AI system - as identified in the MAP function - is examined and documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.11",
      "nist_outcome": "Fairness and bias - as identified in the MAP function - are evaluated and results are documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.12",
      "nist_outcome": "Environmental impact and sustainability of AI model training and management activities - as identified in the MAP function - are assessed and documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 2.13",
      "nist_outcome": "Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. MEASURE 3: Mechanisms for tracking identified AI risks over time are in place.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 3.1",
      "nist_outcome": "Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 3.2",
      "nist_outcome": "Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 3: Categories and subcategories for the MEASURE function. (Continued)",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 3.3",
      "nist_outcome": "Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. MEASURE 4: Feedback about efficacy of measurement is gathered and assessed.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 4.1",
      "nist_outcome": "Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Approaches are documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 4.2",
      "nist_outcome": "Measurement results regarding AI system trustworthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI actors to validate whether the system is performing consistently as intended. Results are documented.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MEASURE 4.3",
      "nist_outcome": "Measurable performance improvements or declines based on consultations with relevant AI actors, including affected communities, and field data about contextrelevant risks and trustworthiness characteristics are identified and documented. Categories Subcategories 5.4 Manage The MANAGE function entails allocating risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function. Risk treatment comprises plans to respond to, recover from, and communicate about incidents or events.",
      "gaissf_control_ids": [
        "D1-CTL-01",
        "D1-CTL-04",
        "D1-CTL-06",
        "D1-CTL-07",
        "D2-CTL-01",
        "D3-CTL-01"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 1.1",
      "nist_outcome": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 1.2",
      "nist_outcome": "Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 1.3",
      "nist_outcome": "Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 1.4",
      "nist_outcome": "Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 2.1",
      "nist_outcome": "Resources required to manage AI risks are taken into account - along with viable non-AI alternative systems, approaches, or methods - to reduce the magnitude or likelihood of potential impacts.",
      "gaissf_control_ids": [
        "D8-CTL-02"
      ],
      "coverage_status": "Partially Addressed",
      "relationship": "P",
      "confidence": "Medium",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 2.2",
      "nist_outcome": "Mechanisms are in place and applied to sustain the value of deployed AI systems.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 2.3",
      "nist_outcome": "Procedures are followed to respond to and recover from a previously unknown risk when it is identified.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 2.4",
      "nist_outcome": "Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. MANAGE 3: AI risks and benefits from third-party entities are managed.",
      "gaissf_control_ids": [
        "D1-CTL-01",
        "D1-CTL-07"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 3.1",
      "nist_outcome": "AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.",
      "gaissf_control_ids": [
        "D1-CTL-07",
        "D4-CTL-04"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 3.2",
      "nist_outcome": "Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance. Categories Subcategories Continued on next page NIST AI 100-1 AI RMF 1.0 Table 4: Categories and subcategories for the MANAGE function. (Continued) MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly.",
      "gaissf_control_ids": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D8-CTL-04",
        "D9-CTL-04",
        "D9-CTL-05"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 4.1",
      "nist_outcome": "Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.",
      "gaissf_control_ids": [
        "D1-CTL-03",
        "D1-CTL-09",
        "D6-CTL-05",
        "D8-CTL-04",
        "D9-CTL-01",
        "D9-CTL-05"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 4.2",
      "nist_outcome": "Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including relevant AI actors.",
      "gaissf_control_ids": [
        "—"
      ],
      "coverage_status": "Not Addressed",
      "relationship": "N",
      "confidence": "Not Rated",
      "residual_gap": "No sufficiently direct GAISSF control mapping was identified in this edition."
    },
    {
      "nist_ai_rmf_subcategory": "MANAGE 4.3",
      "nist_outcome": "Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. Categories Subcategories 6. AI RMF Profiles AI RMF use-case profiles are implementations of the AI RMF functions, categories, and subcategories for a specific setting or application based on the requirements, risk tolerance, and resources of the Framework user: for example, an AI RMF hiring profile or an AI RMF fair housing profile.",
      "gaissf_control_ids": [
        "D4-CTL-07",
        "D6-CTL-06"
      ],
      "coverage_status": "Substantially Addressed",
      "relationship": "SP",
      "confidence": "Medium-High",
      "residual_gap": "NIST requires organizationand context-specific application; additional evidence may be needed for actors, impacts, risk tolerance, and lifecycle context."
    }
  ]
}