{
  "metadata": {
    "document_id": "GAISSF-CRO-028",
    "title": "GAISSF-DORA Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "publication_date": "29 June 2026",
    "gaissf_baseline": "GAISSF v1.0, 59 controls",
    "external_baseline": "Regulation (EU) 2022/2554 (DORA)",
    "application_date": "17 January 2025",
    "verification_date": "29 June 2026"
  },
  "articles": [
    {
      "article": 1,
      "title": "Subject matter",
      "chapter": "General provisions"
    },
    {
      "article": 2,
      "title": "Scope",
      "chapter": "General provisions"
    },
    {
      "article": 3,
      "title": "Definitions",
      "chapter": "General provisions"
    },
    {
      "article": 4,
      "title": "Principle of proportionality",
      "chapter": "General provisions"
    },
    {
      "article": 5,
      "title": "Governance and organisation",
      "chapter": "ICT risk management"
    },
    {
      "article": 6,
      "title": "ICT risk management framework",
      "chapter": "ICT risk management"
    },
    {
      "article": 7,
      "title": "ICT systems, protocols and tools",
      "chapter": "ICT risk management"
    },
    {
      "article": 8,
      "title": "Identification",
      "chapter": "ICT risk management"
    },
    {
      "article": 9,
      "title": "Protection and prevention",
      "chapter": "ICT risk management"
    },
    {
      "article": 10,
      "title": "Detection",
      "chapter": "ICT risk management"
    },
    {
      "article": 11,
      "title": "Response and recovery",
      "chapter": "ICT risk management"
    },
    {
      "article": 12,
      "title": "Backup policies and procedures, restoration and recovery procedures and methods",
      "chapter": "ICT risk management"
    },
    {
      "article": 13,
      "title": "Learning and evolving",
      "chapter": "ICT risk management"
    },
    {
      "article": 14,
      "title": "Communication",
      "chapter": "ICT risk management"
    },
    {
      "article": 15,
      "title": "Further harmonisation of ICT risk management tools, methods, processes and policies",
      "chapter": "ICT risk management"
    },
    {
      "article": 16,
      "title": "Simplified ICT risk management framework",
      "chapter": "ICT risk management"
    },
    {
      "article": 17,
      "title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting"
    },
    {
      "article": 18,
      "title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting"
    },
    {
      "article": 19,
      "title": "Reporting of major ICT-related incidents and voluntary notification of significant cyber threats",
      "chapter": "ICT-related incident management, classification and reporting"
    },
    {
      "article": 20,
      "title": "Harmonisation of reporting content and templates",
      "chapter": "ICT-related incident management, classification and reporting"
    },
    {
      "article": 21,
      "title": "Centralisation of reporting of major ICT-related incidents",
      "chapter": "ICT-related incident management, classification and reporting"
    },
    {
      "article": 22,
      "title": "Supervisory feedback",
      "chapter": "ICT-related incident management, classification and reporting"
    },
    {
      "article": 23,
      "title": "Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers and electronic money institutions",
      "chapter": "ICT-related incident management, classification and reporting"
    },
    {
      "article": 24,
      "title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing"
    },
    {
      "article": 25,
      "title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing"
    },
    {
      "article": 26,
      "title": "Advanced testing of ICT tools, systems and processes based on TLPT",
      "chapter": "Digital operational resilience testing"
    },
    {
      "article": 27,
      "title": "Requirements for testers for the carrying out of TLPT",
      "chapter": "Digital operational resilience testing"
    },
    {
      "article": 28,
      "title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 29,
      "title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 30,
      "title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 31,
      "title": "Designation of critical ICT third-party service providers",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 32,
      "title": "Structure of the Oversight Framework",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 33,
      "title": "Tasks of the Lead Overseer",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 34,
      "title": "Operational coordination between Lead Overseers",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 35,
      "title": "Powers of the Lead Overseer",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 36,
      "title": "Exercise of the powers of the Lead Overseer outside the Union",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 37,
      "title": "Requests for information",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 38,
      "title": "General investigations",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 39,
      "title": "Inspections",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 40,
      "title": "Ongoing oversight",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 41,
      "title": "Harmonisation of conditions enabling the conduct of oversight activities",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 42,
      "title": "Follow-up by competent authorities",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 43,
      "title": "Oversight fees",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 44,
      "title": "International cooperation",
      "chapter": "Managing ICT third-party risk and oversight"
    },
    {
      "article": 45,
      "title": "Information-sharing arrangements on cyber threat information and intelligence",
      "chapter": "Information-sharing arrangements"
    },
    {
      "article": 46,
      "title": "Competent authorities",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 47,
      "title": "Cooperation with structures and authorities established by Directive (EU) 2022/2555",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 48,
      "title": "Cooperation between authorities",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 49,
      "title": "Financial cross-sector exercises, communication and cooperation",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 50,
      "title": "Administrative penalties and remedial measures",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 51,
      "title": "Exercise of the power to impose administrative penalties and remedial measures",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 52,
      "title": "Criminal penalties",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 53,
      "title": "Notification duties",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 54,
      "title": "Publication of administrative penalties",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 55,
      "title": "Professional secrecy",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 56,
      "title": "Data protection",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 57,
      "title": "Processing of personal data outside the Union",
      "chapter": "Competent authorities, cooperation and enforcement"
    },
    {
      "article": 58,
      "title": "Review clause",
      "chapter": "Transitional and final provisions"
    },
    {
      "article": 59,
      "title": "Amendments to Regulation (EC) No 1060/2009",
      "chapter": "Transitional and final provisions"
    },
    {
      "article": 60,
      "title": "Amendments to Regulation (EU) No 648/2012",
      "chapter": "Transitional and final provisions"
    },
    {
      "article": 61,
      "title": "Amendments to Regulation (EU) No 909/2014",
      "chapter": "Transitional and final provisions"
    },
    {
      "article": 62,
      "title": "Amendments to Regulation (EU) No 600/2014",
      "chapter": "Transitional and final provisions"
    },
    {
      "article": 63,
      "title": "Amendments to Regulation (EU) 2016/1011",
      "chapter": "Transitional and final provisions"
    },
    {
      "article": 64,
      "title": "Entry into force and date of application",
      "chapter": "Transitional and final provisions"
    }
  ],
  "controls": [
    {
      "id": "D1-CTL-01",
      "title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-02",
      "title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-03",
      "title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-04",
      "title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-05",
      "title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-06",
      "title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-07",
      "title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-08",
      "title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D1-CTL-09",
      "title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-01",
      "title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-02",
      "title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-03",
      "title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-04",
      "title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-05",
      "title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D2-CTL-06",
      "title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-01",
      "title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-02",
      "title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-03",
      "title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-04",
      "title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-05",
      "title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-06",
      "title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D3-CTL-07",
      "title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-01",
      "title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-02",
      "title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-03",
      "title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-04",
      "title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-05",
      "title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-06",
      "title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D4-CTL-07",
      "title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-01",
      "title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-02",
      "title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-03",
      "title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-04",
      "title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-05",
      "title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D5-CTL-06",
      "title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-01",
      "title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-02",
      "title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-03",
      "title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-04",
      "title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-05",
      "title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-06",
      "title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D6-CTL-07",
      "title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H01",
      "title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H02",
      "title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H03",
      "title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H04",
      "title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D7-CTL-H05",
      "title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-01",
      "title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-02",
      "title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-03",
      "title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-04",
      "title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D8-CTL-05",
      "title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "foundational": "Yes"
    },
    {
      "id": "D9-CTL-01",
      "title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-02",
      "title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-03",
      "title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-04",
      "title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-05",
      "title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-06",
      "title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    },
    {
      "id": "D9-CTL-07",
      "title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "foundational": "No — apply where physical AI is in scope"
    }
  ],
  "mappings": [
    {
      "record_id": "GAISSF-CRO-028-0001",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-01 supports part of DORA Article 6 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0002",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-01 supports part of DORA Article 9 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0003",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-01 supports part of DORA Article 10 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0004",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-01 supports part of DORA Article 24 through Hash verification + source allowlist + poisoning detection.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0005",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-02 supports part of DORA Article 10 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0006",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-02 supports part of DORA Article 6 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0007",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-02 supports part of DORA Article 9 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0008",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-02 supports part of DORA Article 24 through Rate limiting + diversity detection + extraction monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0009",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-03 supports part of DORA Article 10 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0010",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-03 supports part of DORA Article 17 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0011",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-03 supports part of DORA Article 18 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 18 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 18"
    },
    {
      "record_id": "GAISSF-CRO-028-0012",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-03 supports part of DORA Article 24 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0013",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-04 supports part of DORA Article 10 through Gradient anomaly detection + robust aggregation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0014",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-04 supports part of DORA Article 9 through Gradient anomaly detection + robust aggregation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0015",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-04 supports part of DORA Article 24 through Gradient anomaly detection + robust aggregation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0016",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 7,
      "article_title": "ICT systems, protocols and tools",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-04 supports part of DORA Article 7 through Gradient anomaly detection + robust aggregation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 7 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 7"
    },
    {
      "record_id": "GAISSF-CRO-028-0017",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-05 supports part of DORA Article 6 through Adversarial training + certified robustness measurement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0018",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-05 supports part of DORA Article 24 through Adversarial training + certified robustness measurement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0019",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-05 supports part of DORA Article 11 through Adversarial training + certified robustness measurement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0020",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-05 supports part of DORA Article 9 through Adversarial training + certified robustness measurement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0021",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-06 supports part of DORA Article 24 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0022",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-06 supports part of DORA Article 25 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 25 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 25"
    },
    {
      "record_id": "GAISSF-CRO-028-0023",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-06 supports part of DORA Article 28 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0024",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-06 supports part of DORA Article 6 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0025",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-07 supports part of DORA Article 9 through Adapter scanning + provenance verification + registry allowlist.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0026",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-07 supports part of DORA Article 24 through Adapter scanning + provenance verification + registry allowlist.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0027",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 7,
      "article_title": "ICT systems, protocols and tools",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-07 supports part of DORA Article 7 through Adapter scanning + provenance verification + registry allowlist.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 7 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 7"
    },
    {
      "record_id": "GAISSF-CRO-028-0028",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-07 supports part of DORA Article 25 through Adapter scanning + provenance verification + registry allowlist.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 25 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 25"
    },
    {
      "record_id": "GAISSF-CRO-028-0029",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-08 supports part of DORA Article 24 through Pre-registration behavioural evaluation + regression testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0030",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-08 supports part of DORA Article 10 through Pre-registration behavioural evaluation + regression testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0031",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-08 supports part of DORA Article 25 through Pre-registration behavioural evaluation + regression testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 25 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 25"
    },
    {
      "record_id": "GAISSF-CRO-028-0032",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-08 supports part of DORA Article 6 through Pre-registration behavioural evaluation + regression testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0033",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-09 supports part of DORA Article 24 through Cross-precision behavioural comparison + delta threshold monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0034",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-09 supports part of DORA Article 10 through Cross-precision behavioural comparison + delta threshold monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0035",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D1-CTL-09 supports part of DORA Article 25 through Cross-precision behavioural comparison + delta threshold monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 25 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 25"
    },
    {
      "record_id": "GAISSF-CRO-028-0036",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D1-CTL-09 supports part of DORA Article 6 through Cross-precision behavioural comparison + delta threshold monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0037",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-01 supports part of DORA Article 24 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0038",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-01 supports part of DORA Article 6 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0039",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-01 supports part of DORA Article 11 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0040",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-01 supports part of DORA Article 17 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0041",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-02 supports part of DORA Article 24 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0042",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-02 supports part of DORA Article 25 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 25 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 25"
    },
    {
      "record_id": "GAISSF-CRO-028-0043",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 26,
      "article_title": "Advanced testing of ICT tools, systems and processes based on TLPT",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-02 supports part of DORA Article 26 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 26 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 26"
    },
    {
      "record_id": "GAISSF-CRO-028-0044",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 27,
      "article_title": "Requirements for testers for the carrying out of TLPT",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-02 supports part of DORA Article 27 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 27 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 27"
    },
    {
      "record_id": "GAISSF-CRO-028-0045",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D2-CTL-03 supports part of DORA Article 24 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0046",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D2-CTL-03 supports part of DORA Article 6 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0047",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D2-CTL-03 supports part of DORA Article 10 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0048",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D2-CTL-03 supports part of DORA Article 9 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0049",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-04 supports part of DORA Article 10 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0050",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-04 supports part of DORA Article 17 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0051",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-04 supports part of DORA Article 24 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0052",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-04 supports part of DORA Article 18 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 18 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 18"
    },
    {
      "record_id": "GAISSF-CRO-028-0053",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-05 supports part of DORA Article 24 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0054",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-05 supports part of DORA Article 25 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 25 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 25"
    },
    {
      "record_id": "GAISSF-CRO-028-0055",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 26,
      "article_title": "Advanced testing of ICT tools, systems and processes based on TLPT",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-05 supports part of DORA Article 26 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 26 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 26"
    },
    {
      "record_id": "GAISSF-CRO-028-0056",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 27,
      "article_title": "Requirements for testers for the carrying out of TLPT",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-05 supports part of DORA Article 27 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 27 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 27"
    },
    {
      "record_id": "GAISSF-CRO-028-0057",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-06 supports part of DORA Article 24 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0058",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 7,
      "article_title": "ICT systems, protocols and tools",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-06 supports part of DORA Article 7 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 7 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 7"
    },
    {
      "record_id": "GAISSF-CRO-028-0059",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-06 supports part of DORA Article 9 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0060",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D2-CTL-06 supports part of DORA Article 10 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0061",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-01 supports part of DORA Article 6 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0062",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-01 supports part of DORA Article 9 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0063",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-01 supports part of DORA Article 11 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0064",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-01 supports part of DORA Article 24 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0065",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-02 supports part of DORA Article 9 through mTLS for agent mesh + message signing + payload validation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0066",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-02 supports part of DORA Article 24 through mTLS for agent mesh + message signing + payload validation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0067",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-02 supports part of DORA Article 6 through mTLS for agent mesh + message signing + payload validation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0068",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-02 supports part of DORA Article 11 through mTLS for agent mesh + message signing + payload validation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0069",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-03 supports part of DORA Article 10 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0070",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-03 supports part of DORA Article 6 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0071",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-03 supports part of DORA Article 9 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0072",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-03 supports part of DORA Article 11 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0073",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-04 supports part of DORA Article 6 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0074",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-04 supports part of DORA Article 9 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0075",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-04 supports part of DORA Article 11 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0076",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-04 supports part of DORA Article 24 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0077",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-05 supports part of DORA Article 24 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0078",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-05 supports part of DORA Article 6 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0079",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-05 supports part of DORA Article 9 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0080",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-05 supports part of DORA Article 11 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0081",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-06 supports part of DORA Article 9 through User-scoped memory isolation + encryption at rest + query-level access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0082",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 7,
      "article_title": "ICT systems, protocols and tools",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-06 supports part of DORA Article 7 through User-scoped memory isolation + encryption at rest + query-level access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 7 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 7"
    },
    {
      "record_id": "GAISSF-CRO-028-0083",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 15,
      "article_title": "Further harmonisation of ICT risk management tools, methods, processes and policies",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-06 supports part of DORA Article 15 through User-scoped memory isolation + encryption at rest + query-level access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 15 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 15"
    },
    {
      "record_id": "GAISSF-CRO-028-0084",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D3-CTL-06 supports part of DORA Article 6 through User-scoped memory isolation + encryption at rest + query-level access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0085",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-07 supports part of DORA Article 6 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0086",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-07 supports part of DORA Article 11 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0087",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-07 supports part of DORA Article 9 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0088",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D3-CTL-07 supports part of DORA Article 24 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0089",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-01 supports part of DORA Article 28 through Automated BOM generation + version tracking + registry synchronization.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0090",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-01 supports part of DORA Article 29 through Automated BOM generation + version tracking + registry synchronization.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0091",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 8,
      "article_title": "Identification",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-01 supports part of DORA Article 8 through Automated BOM generation + version tracking + registry synchronization.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 8 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 8"
    },
    {
      "record_id": "GAISSF-CRO-028-0092",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-01 supports part of DORA Article 11 through Automated BOM generation + version tracking + registry synchronization.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0093",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-02 supports part of DORA Article 28 through Static analysis + deserialization sandboxing + signature verification.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0094",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-02 supports part of DORA Article 29 through Static analysis + deserialization sandboxing + signature verification.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0095",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-02 supports part of DORA Article 30 through Static analysis + deserialization sandboxing + signature verification.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0096",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-02 supports part of DORA Article 10 through Static analysis + deserialization sandboxing + signature verification.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0097",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-03 supports part of DORA Article 28 through Provenance verification + license compliance + security scorecard.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0098",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-03 supports part of DORA Article 29 through Provenance verification + license compliance + security scorecard.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0099",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-03 supports part of DORA Article 30 through Provenance verification + license compliance + security scorecard.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0100",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 31,
      "article_title": "Designation of critical ICT third-party service providers",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-03 supports part of DORA Article 31 through Provenance verification + license compliance + security scorecard.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 31 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 31"
    },
    {
      "record_id": "GAISSF-CRO-028-0101",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-04 supports part of DORA Article 10 through Tool-call logging + anomaly detection + access control enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0102",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-04 supports part of DORA Article 17 through Tool-call logging + anomaly detection + access control enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0103",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-04 supports part of DORA Article 18 through Tool-call logging + anomaly detection + access control enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 18 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 18"
    },
    {
      "record_id": "GAISSF-CRO-028-0104",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-04 supports part of DORA Article 28 through Tool-call logging + anomaly detection + access control enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0105",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-05 supports part of DORA Article 28 through Contractual security requirements + penetration testing + data flow mapping.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0106",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-05 supports part of DORA Article 29 through Contractual security requirements + penetration testing + data flow mapping.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0107",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-05 supports part of DORA Article 30 through Contractual security requirements + penetration testing + data flow mapping.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0108",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 31,
      "article_title": "Designation of critical ICT third-party service providers",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-05 supports part of DORA Article 31 through Contractual security requirements + penetration testing + data flow mapping.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 31 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 31"
    },
    {
      "record_id": "GAISSF-CRO-028-0109",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-06 supports part of DORA Article 28 through Network traffic analysis + SaaS discovery + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0110",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-06 supports part of DORA Article 29 through Network traffic analysis + SaaS discovery + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0111",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D4-CTL-06 supports part of DORA Article 30 through Network traffic analysis + SaaS discovery + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0112",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-06 supports part of DORA Article 5 through Network traffic analysis + SaaS discovery + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0113",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-07 supports part of DORA Article 28 through Dependency scanning + CVE matching + automated patching.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0114",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-07 supports part of DORA Article 29 through Dependency scanning + CVE matching + automated patching.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0115",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 8,
      "article_title": "Identification",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-07 supports part of DORA Article 8 through Dependency scanning + CVE matching + automated patching.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 8 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 8"
    },
    {
      "record_id": "GAISSF-CRO-028-0116",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D4-CTL-07 supports part of DORA Article 30 through Dependency scanning + CVE matching + automated patching.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0117",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-01 supports part of DORA Article 6 through Content safety classifier + refusal engine.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0118",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-01 supports part of DORA Article 9 through Content safety classifier + refusal engine.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0119",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-01 supports part of DORA Article 11 through Content safety classifier + refusal engine.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0120",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-01 supports part of DORA Article 24 through Content safety classifier + refusal engine.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0121",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-02 supports part of DORA Article 9 through PII detection + masking + access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0122",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-02 supports part of DORA Article 10 through PII detection + masking + access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0123",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-02 supports part of DORA Article 6 through PII detection + masking + access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0124",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 7,
      "article_title": "ICT systems, protocols and tools",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-02 supports part of DORA Article 7 through PII detection + masking + access controls.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 7 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 7"
    },
    {
      "record_id": "GAISSF-CRO-028-0125",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-03 supports part of DORA Article 10 through n-gram overlap detection + refusal.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0126",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-03 supports part of DORA Article 6 through n-gram overlap detection + refusal.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0127",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-03 supports part of DORA Article 9 through n-gram overlap detection + refusal.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0128",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-03 supports part of DORA Article 17 through n-gram overlap detection + refusal.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0129",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-04 supports part of DORA Article 9 through C2PA-compliant watermarking + tamper resistance testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0130",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-04 supports part of DORA Article 11 through C2PA-compliant watermarking + tamper resistance testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0131",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-04 supports part of DORA Article 24 through C2PA-compliant watermarking + tamper resistance testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0132",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-04 supports part of DORA Article 6 through C2PA-compliant watermarking + tamper resistance testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0133",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-05 supports part of DORA Article 6 through Data minimization + purpose limitation + machine unlearning.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0134",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-05 supports part of DORA Article 9 through Data minimization + purpose limitation + machine unlearning.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0135",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 55,
      "article_title": "Professional secrecy",
      "chapter": "Competent authorities, cooperation and enforcement",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 supports part of DORA Article 55 through Data minimization + purpose limitation + machine unlearning.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 55 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 55"
    },
    {
      "record_id": "GAISSF-CRO-028-0136",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 56,
      "article_title": "Data protection",
      "chapter": "Competent authorities, cooperation and enforcement",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 supports part of DORA Article 56 through Data minimization + purpose limitation + machine unlearning.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 56 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 56"
    },
    {
      "record_id": "GAISSF-CRO-028-0137",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-06 supports part of DORA Article 6 through Differential privacy + membership inference testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0138",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-06 supports part of DORA Article 24 through Differential privacy + membership inference testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0139",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D5-CTL-06 supports part of DORA Article 9 through Differential privacy + membership inference testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0140",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D5-CTL-06 supports part of DORA Article 14 through Differential privacy + membership inference testing.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0141",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-01 supports part of DORA Article 6 through Approval workflow + policy enforcement + audit log.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0142",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 supports part of DORA Article 5 through Approval workflow + policy enforcement + audit log.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0143",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 supports part of DORA Article 13 through Approval workflow + policy enforcement + audit log.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0144",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 supports part of DORA Article 14 through Approval workflow + policy enforcement + audit log.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0145",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 supports part of DORA Article 6 through Structured logging + SIEM integration + retention enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0146",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 supports part of DORA Article 5 through Structured logging + SIEM integration + retention enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0147",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 supports part of DORA Article 13 through Structured logging + SIEM integration + retention enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0148",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 supports part of DORA Article 14 through Structured logging + SIEM integration + retention enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0149",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-03 supports part of DORA Article 6 through Standardized template + version control + public accessibility.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0150",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 supports part of DORA Article 5 through Standardized template + version control + public accessibility.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0151",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 supports part of DORA Article 13 through Standardized template + version control + public accessibility.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0152",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 supports part of DORA Article 14 through Standardized template + version control + public accessibility.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0153",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 supports part of DORA Article 5 through AI-IR runbook + tabletop exercises + containment automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0154",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-04 supports part of DORA Article 6 through AI-IR runbook + tabletop exercises + containment automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0155",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 supports part of DORA Article 13 through AI-IR runbook + tabletop exercises + containment automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0156",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 supports part of DORA Article 14 through AI-IR runbook + tabletop exercises + containment automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0157",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 supports part of DORA Article 6 through Access revocation + decommission audit + scheduled lifecycle.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0158",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 supports part of DORA Article 5 through Access revocation + decommission audit + scheduled lifecycle.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0159",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 supports part of DORA Article 13 through Access revocation + decommission audit + scheduled lifecycle.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0160",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 supports part of DORA Article 14 through Access revocation + decommission audit + scheduled lifecycle.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0161",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 supports part of DORA Article 6 through Contractual security requirements + annual assessment + audit rights.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0162",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 supports part of DORA Article 30 through Contractual security requirements + annual assessment + audit rights.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0163",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-06 supports part of DORA Article 5 through Contractual security requirements + annual assessment + audit rights.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0164",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-06 supports part of DORA Article 13 through Contractual security requirements + annual assessment + audit rights.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0165",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 supports part of DORA Article 6 through Failover systems + degraded mode + RTO/RPO definition.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0166",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 supports part of DORA Article 5 through Failover systems + degraded mode + RTO/RPO definition.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0167",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 supports part of DORA Article 13 through Failover systems + degraded mode + RTO/RPO definition.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0168",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 supports part of DORA Article 14 through Failover systems + degraded mode + RTO/RPO definition.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0169",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H01 supports part of DORA Article 6 through Simulation campaigns + click tracking + remedial training.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0170",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H01 supports part of DORA Article 5 through Simulation campaigns + click tracking + remedial training.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0171",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H01 supports part of DORA Article 13 through Simulation campaigns + click tracking + remedial training.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0172",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H01 supports part of DORA Article 14 through Simulation campaigns + click tracking + remedial training.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0173",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H02 supports part of DORA Article 6 through Training modules + quiz + simulated attacks.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0174",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H02 supports part of DORA Article 14 through Training modules + quiz + simulated attacks.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0175",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H02 supports part of DORA Article 17 through Training modules + quiz + simulated attacks.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0176",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H02 supports part of DORA Article 18 through Training modules + quiz + simulated attacks.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 18 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 18"
    },
    {
      "record_id": "GAISSF-CRO-028-0177",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H03 supports part of DORA Article 6 through Independent channel verification + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0178",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H03 supports part of DORA Article 5 through Independent channel verification + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 5 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 5"
    },
    {
      "record_id": "GAISSF-CRO-028-0179",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H03 supports part of DORA Article 13 through Independent channel verification + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 13 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 13"
    },
    {
      "record_id": "GAISSF-CRO-028-0180",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H03 supports part of DORA Article 14 through Independent channel verification + policy enforcement.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 14 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 14"
    },
    {
      "record_id": "GAISSF-CRO-028-0181",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H04 supports part of DORA Article 11 through Tabletop exercises + IR plan + verification triggers.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0182",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 12,
      "article_title": "Backup policies and procedures, restoration and recovery procedures and methods",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H04 supports part of DORA Article 12 through Tabletop exercises + IR plan + verification triggers.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 12 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 12"
    },
    {
      "record_id": "GAISSF-CRO-028-0183",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H04 supports part of DORA Article 17 through Tabletop exercises + IR plan + verification triggers.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0184",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H04 supports part of DORA Article 18 through Tabletop exercises + IR plan + verification triggers.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 18 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 18"
    },
    {
      "record_id": "GAISSF-CRO-028-0185",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H05 supports part of DORA Article 17 through AI-generated phishing detection + SOC tuning + response automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0186",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H05 supports part of DORA Article 18 through AI-generated phishing detection + SOC tuning + response automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 18 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 18"
    },
    {
      "record_id": "GAISSF-CRO-028-0187",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H05 supports part of DORA Article 11 through AI-generated phishing detection + SOC tuning + response automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0188",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D7-CTL-H05 supports part of DORA Article 10 through AI-generated phishing detection + SOC tuning + response automation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0189",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-01 supports part of DORA Article 28 through Risk classification framework + conformity assessment.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0190",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 8,
      "article_title": "Identification",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-01 supports part of DORA Article 8 through Risk classification framework + conformity assessment.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 8 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 8"
    },
    {
      "record_id": "GAISSF-CRO-028-0191",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-01 supports part of DORA Article 6 through Risk classification framework + conformity assessment.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0192",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-01 supports part of DORA Article 29 through Risk classification framework + conformity assessment.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0193",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-02 supports part of DORA Article 28 through Gap analysis methodology + remediation tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0194",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-02 supports part of DORA Article 29 through Gap analysis methodology + remediation tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 29 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 29"
    },
    {
      "record_id": "GAISSF-CRO-028-0195",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-02 supports part of DORA Article 30 through Gap analysis methodology + remediation tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0196",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-02 supports part of DORA Article 6 through Gap analysis methodology + remediation tracking.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0197",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-03 supports part of DORA Article 6 through Technical documentation + training data summary + copyright attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0198",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 15,
      "article_title": "Further harmonisation of ICT risk management tools, methods, processes and policies",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-03 supports part of DORA Article 15 through Technical documentation + training data summary + copyright attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 15 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 15"
    },
    {
      "record_id": "GAISSF-CRO-028-0199",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-03 supports part of DORA Article 30 through Technical documentation + training data summary + copyright attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 30 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 30"
    },
    {
      "record_id": "GAISSF-CRO-028-0200",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-03 supports part of DORA Article 17 through Technical documentation + training data summary + copyright attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0201",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 20,
      "article_title": "Harmonisation of reporting content and templates",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-04 supports part of DORA Article 20 through Incident classification + notification workflow + SLA monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 20 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 20"
    },
    {
      "record_id": "GAISSF-CRO-028-0202",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-04 supports part of DORA Article 17 through Incident classification + notification workflow + SLA monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0203",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 19,
      "article_title": "Reporting of major ICT-related incidents and voluntary notification of significant cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-04 supports part of DORA Article 19 through Incident classification + notification workflow + SLA monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 19 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 19"
    },
    {
      "record_id": "GAISSF-CRO-028-0204",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-04 supports part of DORA Article 18 through Incident classification + notification workflow + SLA monitoring.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 18 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 18"
    },
    {
      "record_id": "GAISSF-CRO-028-0205",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-05 supports part of DORA Article 24 through Secure development practices + attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0206",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-05 supports part of DORA Article 28 through Secure development practices + attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 28 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 28"
    },
    {
      "record_id": "GAISSF-CRO-028-0207",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D8-CTL-05 supports part of DORA Article 6 through Secure development practices + attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0208",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D8-CTL-05 supports part of DORA Article 25 through Secure development practices + attestation.. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 25 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 25"
    },
    {
      "record_id": "GAISSF-CRO-028-0209",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-01 supports part of DORA Article 11 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity/temperatu. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0210",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-01 supports part of DORA Article 24 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity/temperatu. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0211",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-01 supports part of DORA Article 6 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity/temperatu. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0212",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-01 supports part of DORA Article 9 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity/temperatu. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0213",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-02 supports part of DORA Article 11 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); transition tim. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0214",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-02 supports part of DORA Article 24 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); transition tim. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0215",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-02 supports part of DORA Article 6 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); transition tim. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0216",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-02 supports part of DORA Article 9 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); transition tim. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0217",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-03 supports part of DORA Article 6 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human operator inte. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0218",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-03 supports part of DORA Article 9 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human operator inte. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0219",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-03 supports part of DORA Article 24 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human operator inte. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0220",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-03 supports part of DORA Article 11 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human operator inte. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0221",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-04 supports part of DORA Article 24 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-validate against. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0222",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-04 supports part of DORA Article 11 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-validate against. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0223",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-04 supports part of DORA Article 6 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-validate against. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0224",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-04 supports part of DORA Article 10 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-validate against. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 10 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 10"
    },
    {
      "record_id": "GAISSF-CRO-028-0225",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-05 supports part of DORA Article 6 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence falls below th. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0226",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-05 supports part of DORA Article 24 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence falls below th. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0227",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-05 supports part of DORA Article 11 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence falls below th. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0228",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-05 supports part of DORA Article 9 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence falls below th. The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0229",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-06 supports part of DORA Article 24 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibility check . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 24 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 24"
    },
    {
      "record_id": "GAISSF-CRO-028-0230",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-06 supports part of DORA Article 6 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibility check . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0231",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-06 supports part of DORA Article 9 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibility check . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0232",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-06 supports part of DORA Article 11 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibility check . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    },
    {
      "record_id": "GAISSF-CRO-028-0233",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-07 supports part of DORA Article 6 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safety monitor . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 6 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 6"
    },
    {
      "record_id": "GAISSF-CRO-028-0234",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-07 supports part of DORA Article 9 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safety monitor . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 9 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 9"
    },
    {
      "record_id": "GAISSF-CRO-028-0235",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-07 supports part of DORA Article 17 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safety monitor . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 17 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 17"
    },
    {
      "record_id": "GAISSF-CRO-028-0236",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D9-CTL-07 supports part of DORA Article 11 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safety monitor . The mapping is outcome-based and does not establish regulatory compliance.",
      "residual_gap": "Article 11 also depends on DORA entity scope, proportionality, financial-sector governance, reporting, supervisory and evidentiary requirements not established by this control alone.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "dora_source": "Regulation (EU) 2022/2554, Article 11"
    }
  ],
  "reverse": [
    {
      "article": 1,
      "article_title": "Subject matter",
      "chapter": "General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 2,
      "article_title": "Scope",
      "chapter": "General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 3,
      "article_title": "Definitions",
      "chapter": "General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 4,
      "article_title": "Principle of proportionality",
      "chapter": "General provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 5,
      "article_title": "Governance and organisation",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D4-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H03"
      ],
      "mapped_count": 10,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 6,
      "article_title": "ICT risk management framework",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-03",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D8-CTL-01",
        "D8-CTL-02",
        "D8-CTL-03",
        "D8-CTL-05",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 42,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 7,
      "article_title": "ICT systems, protocols and tools",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D1-CTL-04",
        "D1-CTL-07",
        "D2-CTL-06",
        "D3-CTL-06",
        "D5-CTL-02"
      ],
      "mapped_count": 5,
      "coverage_status": "Partially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 8,
      "article_title": "Identification",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-07",
        "D8-CTL-01"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 9,
      "article_title": "Protection and prevention",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-07",
        "D2-CTL-03",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 26,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 10,
      "article_title": "Detection",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-06",
        "D3-CTL-03",
        "D4-CTL-02",
        "D4-CTL-04",
        "D5-CTL-02",
        "D5-CTL-03",
        "D7-CTL-H05",
        "D9-CTL-04"
      ],
      "mapped_count": 16,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 11,
      "article_title": "Response and recovery",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D1-CTL-05",
        "D2-CTL-01",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-07",
        "D4-CTL-01",
        "D5-CTL-01",
        "D5-CTL-04",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 20,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 12,
      "article_title": "Backup policies and procedures, restoration and recovery procedures and methods",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D7-CTL-H04"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 13,
      "article_title": "Learning and evolving",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H03"
      ],
      "mapped_count": 9,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 14,
      "article_title": "Communication",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03"
      ],
      "mapped_count": 10,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 15,
      "article_title": "Further harmonisation of ICT risk management tools, methods, processes and policies",
      "chapter": "ICT risk management",
      "mapped_controls": [
        "D3-CTL-06",
        "D8-CTL-03"
      ],
      "mapped_count": 2,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 16,
      "article_title": "Simplified ICT risk management framework",
      "chapter": "ICT risk management",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 17,
      "article_title": "ICT-related incident management process",
      "chapter": "ICT-related incident management, classification and reporting",
      "mapped_controls": [
        "D1-CTL-03",
        "D2-CTL-01",
        "D2-CTL-04",
        "D4-CTL-04",
        "D5-CTL-03",
        "D7-CTL-H02",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D8-CTL-03",
        "D8-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 11,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 18,
      "article_title": "Classification of ICT-related incidents and cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "mapped_controls": [
        "D1-CTL-03",
        "D2-CTL-04",
        "D4-CTL-04",
        "D7-CTL-H02",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D8-CTL-04"
      ],
      "mapped_count": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 19,
      "article_title": "Reporting of major ICT-related incidents and voluntary notification of significant cyber threats",
      "chapter": "ICT-related incident management, classification and reporting",
      "mapped_controls": [
        "D8-CTL-04"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 20,
      "article_title": "Harmonisation of reporting content and templates",
      "chapter": "ICT-related incident management, classification and reporting",
      "mapped_controls": [
        "D8-CTL-04"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 21,
      "article_title": "Centralisation of reporting of major ICT-related incidents",
      "chapter": "ICT-related incident management, classification and reporting",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 22,
      "article_title": "Supervisory feedback",
      "chapter": "ICT-related incident management, classification and reporting",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 23,
      "article_title": "Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers and electronic money institutions",
      "chapter": "ICT-related incident management, classification and reporting",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 24,
      "article_title": "General requirements for the performance of digital operational resilience testing",
      "chapter": "Digital operational resilience testing",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-07",
        "D5-CTL-01",
        "D5-CTL-04",
        "D5-CTL-06",
        "D8-CTL-05",
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06"
      ],
      "mapped_count": 30,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 25,
      "article_title": "Testing of ICT tools and systems",
      "chapter": "Digital operational resilience testing",
      "mapped_controls": [
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-02",
        "D2-CTL-05",
        "D8-CTL-05"
      ],
      "mapped_count": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 26,
      "article_title": "Advanced testing of ICT tools, systems and processes based on TLPT",
      "chapter": "Digital operational resilience testing",
      "mapped_controls": [
        "D2-CTL-02",
        "D2-CTL-05"
      ],
      "mapped_count": 2,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 27,
      "article_title": "Requirements for testers for the carrying out of TLPT",
      "chapter": "Digital operational resilience testing",
      "mapped_controls": [
        "D2-CTL-02",
        "D2-CTL-05"
      ],
      "mapped_count": 2,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 28,
      "article_title": "General principles for the sound management of ICT third-party risk",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [
        "D1-CTL-06",
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D8-CTL-01",
        "D8-CTL-02",
        "D8-CTL-05"
      ],
      "mapped_count": 11,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 29,
      "article_title": "Preliminary assessment of ICT concentration risk at entity level",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D8-CTL-01",
        "D8-CTL-02"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 30,
      "article_title": "Key contractual provisions",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D6-CTL-06",
        "D8-CTL-02",
        "D8-CTL-03"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 31,
      "article_title": "Designation of critical ICT third-party service providers",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [
        "D4-CTL-03",
        "D4-CTL-05"
      ],
      "mapped_count": 2,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 32,
      "article_title": "Structure of the Oversight Framework",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 33,
      "article_title": "Tasks of the Lead Overseer",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 34,
      "article_title": "Operational coordination between Lead Overseers",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 35,
      "article_title": "Powers of the Lead Overseer",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 36,
      "article_title": "Exercise of the powers of the Lead Overseer outside the Union",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 37,
      "article_title": "Requests for information",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 38,
      "article_title": "General investigations",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 39,
      "article_title": "Inspections",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 40,
      "article_title": "Ongoing oversight",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 41,
      "article_title": "Harmonisation of conditions enabling the conduct of oversight activities",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 42,
      "article_title": "Follow-up by competent authorities",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 43,
      "article_title": "Oversight fees",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 44,
      "article_title": "International cooperation",
      "chapter": "Managing ICT third-party risk and oversight",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 45,
      "article_title": "Information-sharing arrangements on cyber threat information and intelligence",
      "chapter": "Information-sharing arrangements",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 46,
      "article_title": "Competent authorities",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 47,
      "article_title": "Cooperation with structures and authorities established by Directive (EU) 2022/2555",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 48,
      "article_title": "Cooperation between authorities",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 49,
      "article_title": "Financial cross-sector exercises, communication and cooperation",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 50,
      "article_title": "Administrative penalties and remedial measures",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 51,
      "article_title": "Exercise of the power to impose administrative penalties and remedial measures",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 52,
      "article_title": "Criminal penalties",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 53,
      "article_title": "Notification duties",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 54,
      "article_title": "Publication of administrative penalties",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 55,
      "article_title": "Professional secrecy",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [
        "D5-CTL-05"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 56,
      "article_title": "Data protection",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [
        "D5-CTL-05"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 57,
      "article_title": "Processing of personal data outside the Union",
      "chapter": "Competent authorities, cooperation and enforcement",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 58,
      "article_title": "Review clause",
      "chapter": "Transitional and final provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 59,
      "article_title": "Amendments to Regulation (EC) No 1060/2009",
      "chapter": "Transitional and final provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 60,
      "article_title": "Amendments to Regulation (EU) No 648/2012",
      "chapter": "Transitional and final provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 61,
      "article_title": "Amendments to Regulation (EU) No 909/2014",
      "chapter": "Transitional and final provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 62,
      "article_title": "Amendments to Regulation (EU) No 600/2014",
      "chapter": "Transitional and final provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 63,
      "article_title": "Amendments to Regulation (EU) 2016/1011",
      "chapter": "Transitional and final provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    },
    {
      "article": 64,
      "article_title": "Entry into force and date of application",
      "chapter": "Transitional and final provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "DORA-specific legal scope, proportionality, financial-entity duties, supervisory procedures, reporting templates and Level 2 measures require separate implementation."
    }
  ],
  "limitations": [
    "Mapping does not establish DORA compliance or supervisory acceptance.",
    "Level 2 delegated and implementing acts must be assessed separately.",
    "Applicability depends on entity type, exemptions, proportionality and service arrangements.",
    "Operating effectiveness must be independently tested."
  ]
}
