{
  "meta": {
    "document_id": "GAISSF-CRO-031",
    "title": "GAISSF-SOC 2 Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "publication_date": "29 June 2026",
    "publisher": "ODA3 Institute",
    "legal_entity": "ODA3 Pvt Ltd",
    "gaissf_baseline": "GAISSF™ v1.0; GAISSF-NOR-001 and GAISSF-NOR-004; 59 controls / 9 domains; Applicable-Control Baseline = all 52 controls in D1-D8 plus D9 where Physical AI or cyber-physical actuation is in scope.",
    "external_baseline": "AICPA 2017 Trust Services Criteria (with Revised Points of Focus – 2022); 60 mapped criterion identifiers.",
    "verification_date": "2026-10-06",
    "scope": "Bidirectional outcome-based crosswalk between 59 GAISSF™ v1.0 controls and all 60 criterion identifiers in the mapped Trust Services Criteria baseline. The 2018 SOC 2 Description Criteria, management system description/assertion, Type I/Type II examination procedures and CPA reporting remain separate assurance layers."
  },
  "controls": [
    {
      "id": "D1-CTL-01",
      "title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-02",
      "title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-03",
      "title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-04",
      "title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-05",
      "title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-06",
      "title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-07",
      "title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-08",
      "title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D1-CTL-09",
      "title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D2-CTL-01",
      "title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D2-CTL-02",
      "title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D2-CTL-03",
      "title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D2-CTL-04",
      "title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D2-CTL-05",
      "title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D2-CTL-06",
      "title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D3-CTL-01",
      "title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D3-CTL-02",
      "title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D3-CTL-03",
      "title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D3-CTL-04",
      "title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D3-CTL-05",
      "title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D3-CTL-06",
      "title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D3-CTL-07",
      "title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D4-CTL-01",
      "title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D4-CTL-02",
      "title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D4-CTL-03",
      "title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D4-CTL-04",
      "title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D4-CTL-05",
      "title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D4-CTL-06",
      "title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D4-CTL-07",
      "title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D5-CTL-01",
      "title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D5-CTL-02",
      "title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D5-CTL-03",
      "title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D5-CTL-04",
      "title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D5-CTL-05",
      "title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D5-CTL-06",
      "title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D6-CTL-01",
      "title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D6-CTL-02",
      "title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D6-CTL-03",
      "title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D6-CTL-04",
      "title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D6-CTL-05",
      "title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D6-CTL-06",
      "title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D6-CTL-07",
      "title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D7-CTL-H01",
      "title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D7-CTL-H02",
      "title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D7-CTL-H03",
      "title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D7-CTL-H04",
      "title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D7-CTL-H05",
      "title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D8-CTL-01",
      "title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D8-CTL-02",
      "title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D8-CTL-03",
      "title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D8-CTL-04",
      "title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D8-CTL-05",
      "title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D9-CTL-01",
      "title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D9-CTL-02",
      "title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D9-CTL-03",
      "title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D9-CTL-04",
      "title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D9-CTL-05",
      "title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D9-CTL-06",
      "title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    },
    {
      "id": "D9-CTL-07",
      "title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope",
      "validation_boundary": "Use independently controlled validation appropriate to the control and service-organization system context. Held/internal GAISSF VTS, benchmark suites and unpublished test harnesses are not public-package dependencies.",
      "evidence_expectation": "Scope-linked implementation and validation records with provenance, configuration/version, inputs, outputs, exceptions, reviewer identity, date and limitations. SOC 2 evidence sufficiency and operating effectiveness are determined through the engagement and independent CPA procedures."
    }
  ],
  "criteria": [
    {
      "id": "CC1.1",
      "category": "Security / Common Criteria - Control Environment",
      "title": "Integrity and ethical values"
    },
    {
      "id": "CC1.2",
      "category": "Security / Common Criteria - Control Environment",
      "title": "Board oversight"
    },
    {
      "id": "CC1.3",
      "category": "Security / Common Criteria - Control Environment",
      "title": "Structures, reporting lines, authority and responsibility"
    },
    {
      "id": "CC1.4",
      "category": "Security / Common Criteria - Control Environment",
      "title": "Commitment to competence"
    },
    {
      "id": "CC1.5",
      "category": "Security / Common Criteria - Control Environment",
      "title": "Accountability"
    },
    {
      "id": "CC2.1",
      "category": "Security / Common Criteria - Communication and Information",
      "title": "Quality information"
    },
    {
      "id": "CC2.2",
      "category": "Security / Common Criteria - Communication and Information",
      "title": "Internal communication"
    },
    {
      "id": "CC2.3",
      "category": "Security / Common Criteria - Communication and Information",
      "title": "External communication"
    },
    {
      "id": "CC3.1",
      "category": "Security / Common Criteria - Risk Assessment",
      "title": "Suitable objectives"
    },
    {
      "id": "CC3.2",
      "category": "Security / Common Criteria - Risk Assessment",
      "title": "Risk identification and analysis"
    },
    {
      "id": "CC3.3",
      "category": "Security / Common Criteria - Risk Assessment",
      "title": "Fraud risk"
    },
    {
      "id": "CC3.4",
      "category": "Security / Common Criteria - Risk Assessment",
      "title": "Significant change"
    },
    {
      "id": "CC4.1",
      "category": "Security / Common Criteria - Monitoring",
      "title": "Ongoing and separate evaluations"
    },
    {
      "id": "CC4.2",
      "category": "Security / Common Criteria - Monitoring",
      "title": "Deficiency evaluation and communication"
    },
    {
      "id": "CC5.1",
      "category": "Security / Common Criteria - Control Activities",
      "title": "Control activity selection and development"
    },
    {
      "id": "CC5.2",
      "category": "Security / Common Criteria - Control Activities",
      "title": "Technology general controls"
    },
    {
      "id": "CC5.3",
      "category": "Security / Common Criteria - Control Activities",
      "title": "Policies and procedures"
    },
    {
      "id": "CC6.1",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "Logical access security architecture"
    },
    {
      "id": "CC6.2",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "User registration and authorization"
    },
    {
      "id": "CC6.3",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "Access modification and removal"
    },
    {
      "id": "CC6.4",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "Physical access restrictions"
    },
    {
      "id": "CC6.5",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "Asset disposal and removal"
    },
    {
      "id": "CC6.6",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "System boundary protection"
    },
    {
      "id": "CC6.7",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "Secure transmission and movement"
    },
    {
      "id": "CC6.8",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "title": "Malicious software prevention and detection"
    },
    {
      "id": "CC7.1",
      "category": "Security / Common Criteria - System Operations",
      "title": "Configuration and vulnerability management"
    },
    {
      "id": "CC7.2",
      "category": "Security / Common Criteria - System Operations",
      "title": "Security event monitoring"
    },
    {
      "id": "CC7.3",
      "category": "Security / Common Criteria - System Operations",
      "title": "Security event evaluation"
    },
    {
      "id": "CC7.4",
      "category": "Security / Common Criteria - System Operations",
      "title": "Incident response"
    },
    {
      "id": "CC7.5",
      "category": "Security / Common Criteria - System Operations",
      "title": "Recovery from incidents"
    },
    {
      "id": "CC8.1",
      "category": "Security / Common Criteria - Change Management",
      "title": "Authorized and controlled changes"
    },
    {
      "id": "CC9.1",
      "category": "Security / Common Criteria - Risk Mitigation",
      "title": "Risk mitigation activities"
    },
    {
      "id": "CC9.2",
      "category": "Security / Common Criteria - Risk Mitigation",
      "title": "Vendor and business-partner risk"
    },
    {
      "id": "A1.1",
      "category": "Availability",
      "title": "Capacity and availability commitments"
    },
    {
      "id": "A1.2",
      "category": "Availability",
      "title": "Environmental protections and recovery infrastructure"
    },
    {
      "id": "A1.3",
      "category": "Availability",
      "title": "Recovery plan testing"
    },
    {
      "id": "PI1.1",
      "category": "Processing Integrity",
      "title": "Processing objectives and specifications"
    },
    {
      "id": "PI1.2",
      "category": "Processing Integrity",
      "title": "Input completeness and accuracy"
    },
    {
      "id": "PI1.3",
      "category": "Processing Integrity",
      "title": "Processing completeness and accuracy"
    },
    {
      "id": "PI1.4",
      "category": "Processing Integrity",
      "title": "Output completeness and accuracy"
    },
    {
      "id": "PI1.5",
      "category": "Processing Integrity",
      "title": "Data storage integrity"
    },
    {
      "id": "C1.1",
      "category": "Confidentiality",
      "title": "Identification and protection of confidential information"
    },
    {
      "id": "C1.2",
      "category": "Confidentiality",
      "title": "Confidential information disposal"
    },
    {
      "id": "P1.1",
      "category": "Privacy",
      "title": "Privacy notice and communication"
    },
    {
      "id": "P2.1",
      "category": "Privacy",
      "title": "Choice and consent"
    },
    {
      "id": "P3.1",
      "category": "Privacy",
      "title": "Collection limitation"
    },
    {
      "id": "P3.2",
      "category": "Privacy",
      "title": "Collection from third parties"
    },
    {
      "id": "P4.1",
      "category": "Privacy",
      "title": "Use limitation"
    },
    {
      "id": "P4.2",
      "category": "Privacy",
      "title": "Retention"
    },
    {
      "id": "P4.3",
      "category": "Privacy",
      "title": "Disposal"
    },
    {
      "id": "P5.1",
      "category": "Privacy",
      "title": "Data-subject access"
    },
    {
      "id": "P6.1",
      "category": "Privacy",
      "title": "Disclosure to third parties"
    },
    {
      "id": "P6.2",
      "category": "Privacy",
      "title": "Third-party data handling agreements"
    },
    {
      "id": "P6.3",
      "category": "Privacy",
      "title": "Third-party monitoring"
    },
    {
      "id": "P6.4",
      "category": "Privacy",
      "title": "Unauthorized disclosure response"
    },
    {
      "id": "P6.5",
      "category": "Privacy",
      "title": "Data quality communication"
    },
    {
      "id": "P6.6",
      "category": "Privacy",
      "title": "Correction and amendment"
    },
    {
      "id": "P6.7",
      "category": "Privacy",
      "title": "Disclosure accounting"
    },
    {
      "id": "P7.1",
      "category": "Privacy",
      "title": "Privacy data quality"
    },
    {
      "id": "P8.1",
      "category": "Privacy",
      "title": "Privacy inquiry, complaint and dispute handling"
    }
  ],
  "mappings": [
    {
      "record_id": "GAISSF-CRO-031-MAP-0001",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0002",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0003",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0004",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0005",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0006",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0007",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0008",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0009",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0010",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0011",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0012",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0013",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0014",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0015",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0016",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0017",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0018",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0019",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0020",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0021",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "CC8.1",
      "criterion_title": "Authorized and controlled changes",
      "category": "Security / Common Criteria - Change Management",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to CC8.1 (Authorized and controlled changes). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0022",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0023",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0024",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-06 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0025",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0026",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0027",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0028",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-07 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0029",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0030",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0031",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0032",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-08 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0033",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0034",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0035",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0036",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D1-CTL-09 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0037",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0038",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0039",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0040",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0041",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0042",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0043",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0044",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0045",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0046",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0047",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0048",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-03 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0049",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0050",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0051",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0052",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0053",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0054",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0055",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0056",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-05 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0057",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0058",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0059",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0060",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D2-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0061",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0062",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0063",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0064",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0065",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0066",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0067",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0068",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-02 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0069",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC8.1",
      "criterion_title": "Authorized and controlled changes",
      "category": "Security / Common Criteria - Change Management",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-03 provides governance, technical, or evidentiary capability relevant to CC8.1 (Authorized and controlled changes). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0070",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.8",
      "criterion_title": "Malicious software prevention and detection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.8 (Malicious software prevention and detection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0071",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.7",
      "criterion_title": "Secure transmission and movement",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.7 (Secure transmission and movement). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0072",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.6",
      "criterion_title": "System boundary protection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.6 (System boundary protection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0073",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.5",
      "criterion_title": "Asset disposal and removal",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.5 (Asset disposal and removal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0074",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.8",
      "criterion_title": "Malicious software prevention and detection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to CC6.8 (Malicious software prevention and detection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0075",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.7",
      "criterion_title": "Secure transmission and movement",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to CC6.7 (Secure transmission and movement). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0076",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.6",
      "criterion_title": "System boundary protection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to CC6.6 (System boundary protection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0077",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC6.5",
      "criterion_title": "Asset disposal and removal",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-05 provides governance, technical, or evidentiary capability relevant to CC6.5 (Asset disposal and removal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0078",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0079",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0080",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0081",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-06 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0082",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides governance, technical, or evidentiary capability relevant to P4.3 (Disposal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0083",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "P4.2",
      "criterion_title": "Retention",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides governance, technical, or evidentiary capability relevant to P4.2 (Retention). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0084",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "criterion_id": "P4.1",
      "criterion_title": "Use limitation",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D3-CTL-07 provides governance, technical, or evidentiary capability relevant to P4.1 (Use limitation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0085",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0086",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0087",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to P6.5 (Data quality communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0088",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.4",
      "criterion_title": "Unauthorized disclosure response",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-01 provides governance, technical, or evidentiary capability relevant to P6.4 (Unauthorized disclosure response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0089",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0090",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0091",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to P6.5 (Data quality communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0092",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.4",
      "criterion_title": "Unauthorized disclosure response",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-02 provides governance, technical, or evidentiary capability relevant to P6.4 (Unauthorized disclosure response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0093",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P3.2",
      "criterion_title": "Collection from third parties",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to P3.2 (Collection from third parties). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0094",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P3.1",
      "criterion_title": "Collection limitation",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to P3.1 (Collection limitation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0095",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0096",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-03 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0097",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0098",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0099",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0100",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0101",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0102",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0103",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to P6.5 (Data quality communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0104",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.4",
      "criterion_title": "Unauthorized disclosure response",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-05 provides governance, technical, or evidentiary capability relevant to P6.4 (Unauthorized disclosure response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0105",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P8.1",
      "criterion_title": "Privacy inquiry, complaint and dispute handling",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to P8.1 (Privacy inquiry, complaint and dispute handling). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0106",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0107",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0108",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-06 provides governance, technical, or evidentiary capability relevant to P6.5 (Data quality communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0109",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0110",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0111",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.5 (Data quality communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0112",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "criterion_id": "P6.4",
      "criterion_title": "Unauthorized disclosure response",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D4-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.4 (Unauthorized disclosure response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0113",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0114",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0115",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0116",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-01 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0117",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0118",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0119",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0120",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0121",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0122",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0123",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0124",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-03 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0125",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0126",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0127",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0128",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-04 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0129",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "P2.1",
      "criterion_title": "Choice and consent",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides governance, technical, or evidentiary capability relevant to P2.1 (Choice and consent). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0130",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "P1.1",
      "criterion_title": "Privacy notice and communication",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides governance, technical, or evidentiary capability relevant to P1.1 (Privacy notice and communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0131",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0132",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0133",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "P2.1",
      "criterion_title": "Choice and consent",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides governance, technical, or evidentiary capability relevant to P2.1 (Choice and consent). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0134",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "P1.1",
      "criterion_title": "Privacy notice and communication",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides governance, technical, or evidentiary capability relevant to P1.1 (Privacy notice and communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0135",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0136",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D5-CTL-06 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0137",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC9.2",
      "criterion_title": "Vendor and business-partner risk",
      "category": "Security / Common Criteria - Risk Mitigation",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to CC9.2 (Vendor and business-partner risk). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0138",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC9.1",
      "criterion_title": "Risk mitigation activities",
      "category": "Security / Common Criteria - Risk Mitigation",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to CC9.1 (Risk mitigation activities). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0139",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC3.4",
      "criterion_title": "Significant change",
      "category": "Security / Common Criteria - Risk Assessment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to CC3.4 (Significant change). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0140",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC3.3",
      "criterion_title": "Fraud risk",
      "category": "Security / Common Criteria - Risk Assessment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-01 provides governance, technical, or evidentiary capability relevant to CC3.3 (Fraud risk). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0141",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC4.2",
      "criterion_title": "Deficiency evaluation and communication",
      "category": "Security / Common Criteria - Monitoring",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to CC4.2 (Deficiency evaluation and communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0142",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC4.1",
      "criterion_title": "Ongoing and separate evaluations",
      "category": "Security / Common Criteria - Monitoring",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to CC4.1 (Ongoing and separate evaluations). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0143",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.5",
      "criterion_title": "Accountability",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to CC1.5 (Accountability). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0144",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.4",
      "criterion_title": "Commitment to competence",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-02 provides governance, technical, or evidentiary capability relevant to CC1.4 (Commitment to competence). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0145",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.5",
      "criterion_title": "Accountability",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to CC1.5 (Accountability). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0146",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.4",
      "criterion_title": "Commitment to competence",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to CC1.4 (Commitment to competence). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0147",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.3",
      "criterion_title": "Structures, reporting lines, authority and responsibility",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to CC1.3 (Structures, reporting lines, authority and responsibility). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0148",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.2",
      "criterion_title": "Board oversight",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-03 provides governance, technical, or evidentiary capability relevant to CC1.2 (Board oversight). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0149",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.5",
      "criterion_title": "Accountability",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to CC1.5 (Accountability). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0150",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.4",
      "criterion_title": "Commitment to competence",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to CC1.4 (Commitment to competence). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0151",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.3",
      "criterion_title": "Structures, reporting lines, authority and responsibility",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to CC1.3 (Structures, reporting lines, authority and responsibility). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0152",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.2",
      "criterion_title": "Board oversight",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-04 provides governance, technical, or evidentiary capability relevant to CC1.2 (Board oversight). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0153",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.5",
      "criterion_title": "Accountability",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to CC1.5 (Accountability). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0154",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.4",
      "criterion_title": "Commitment to competence",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to CC1.4 (Commitment to competence). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0155",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.3",
      "criterion_title": "Structures, reporting lines, authority and responsibility",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to CC1.3 (Structures, reporting lines, authority and responsibility). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0156",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.2",
      "criterion_title": "Board oversight",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-05 provides governance, technical, or evidentiary capability relevant to CC1.2 (Board oversight). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0157",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC9.2",
      "criterion_title": "Vendor and business-partner risk",
      "category": "Security / Common Criteria - Risk Mitigation",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to CC9.2 (Vendor and business-partner risk). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0158",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC9.1",
      "criterion_title": "Risk mitigation activities",
      "category": "Security / Common Criteria - Risk Mitigation",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to CC9.1 (Risk mitigation activities). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0159",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.5",
      "criterion_title": "Accountability",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to CC1.5 (Accountability). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0160",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.4",
      "criterion_title": "Commitment to competence",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "High",
      "rationale": "GAISSF D6-CTL-06 provides governance, technical, or evidentiary capability relevant to CC1.4 (Commitment to competence). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0161",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "A1.3",
      "criterion_title": "Recovery plan testing",
      "category": "Availability",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to A1.3 (Recovery plan testing). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0162",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "A1.2",
      "criterion_title": "Environmental protections and recovery infrastructure",
      "category": "Availability",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to A1.2 (Environmental protections and recovery infrastructure). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0163",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "A1.1",
      "criterion_title": "Capacity and availability commitments",
      "category": "Availability",
      "relationship": "SP",
      "coverage": "Substantially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to A1.1 (Capacity and availability commitments). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0164",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "criterion_id": "CC1.5",
      "criterion_title": "Accountability",
      "category": "Security / Common Criteria - Control Environment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D6-CTL-07 provides governance, technical, or evidentiary capability relevant to CC1.5 (Accountability). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0165",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides governance, technical, or evidentiary capability relevant to P4.3 (Disposal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0166",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.2",
      "criterion_title": "Retention",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides governance, technical, or evidentiary capability relevant to P4.2 (Retention). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0167",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.1",
      "criterion_title": "Use limitation",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H01 provides governance, technical, or evidentiary capability relevant to P4.1 (Use limitation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0168",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides governance, technical, or evidentiary capability relevant to P4.3 (Disposal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0169",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.2",
      "criterion_title": "Retention",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides governance, technical, or evidentiary capability relevant to P4.2 (Retention). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0170",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.1",
      "criterion_title": "Use limitation",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H02 provides governance, technical, or evidentiary capability relevant to P4.1 (Use limitation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0171",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides governance, technical, or evidentiary capability relevant to P4.3 (Disposal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0172",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.2",
      "criterion_title": "Retention",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides governance, technical, or evidentiary capability relevant to P4.2 (Retention). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0173",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.1",
      "criterion_title": "Use limitation",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides governance, technical, or evidentiary capability relevant to P4.1 (Use limitation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0174",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "CC6.8",
      "criterion_title": "Malicious software prevention and detection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H03 provides governance, technical, or evidentiary capability relevant to CC6.8 (Malicious software prevention and detection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0175",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0176",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0177",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides governance, technical, or evidentiary capability relevant to P6.5 (Data quality communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0178",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P6.4",
      "criterion_title": "Unauthorized disclosure response",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H04 provides governance, technical, or evidentiary capability relevant to P6.4 (Unauthorized disclosure response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0179",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides governance, technical, or evidentiary capability relevant to P4.3 (Disposal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0180",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.2",
      "criterion_title": "Retention",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides governance, technical, or evidentiary capability relevant to P4.2 (Retention). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0181",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "criterion_id": "P4.1",
      "criterion_title": "Use limitation",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D7-CTL-H05 provides governance, technical, or evidentiary capability relevant to P4.1 (Use limitation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0182",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC3.4",
      "criterion_title": "Significant change",
      "category": "Security / Common Criteria - Risk Assessment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides governance, technical, or evidentiary capability relevant to CC3.4 (Significant change). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0183",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC3.3",
      "criterion_title": "Fraud risk",
      "category": "Security / Common Criteria - Risk Assessment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides governance, technical, or evidentiary capability relevant to CC3.3 (Fraud risk). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0184",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC3.2",
      "criterion_title": "Risk identification and analysis",
      "category": "Security / Common Criteria - Risk Assessment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides governance, technical, or evidentiary capability relevant to CC3.2 (Risk identification and analysis). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0185",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC3.1",
      "criterion_title": "Suitable objectives",
      "category": "Security / Common Criteria - Risk Assessment",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-01 provides governance, technical, or evidentiary capability relevant to CC3.1 (Suitable objectives). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0186",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-02 provides governance, technical, or evidentiary capability relevant to P4.3 (Disposal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0187",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC2.3",
      "criterion_title": "External communication",
      "category": "Security / Common Criteria - Communication and Information",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides governance, technical, or evidentiary capability relevant to CC2.3 (External communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0188",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC2.2",
      "criterion_title": "Internal communication",
      "category": "Security / Common Criteria - Communication and Information",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides governance, technical, or evidentiary capability relevant to CC2.2 (Internal communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0189",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC2.1",
      "criterion_title": "Quality information",
      "category": "Security / Common Criteria - Communication and Information",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-03 provides governance, technical, or evidentiary capability relevant to CC2.1 (Quality information). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0190",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0191",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0192",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0193",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-04 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0194",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D8-CTL-05 provides governance, technical, or evidentiary capability relevant to P4.3 (Disposal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0195",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.8",
      "criterion_title": "Malicious software prevention and detection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-01 provides governance, technical, or evidentiary capability relevant to CC6.8 (Malicious software prevention and detection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0196",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.7",
      "criterion_title": "Secure transmission and movement",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-01 provides governance, technical, or evidentiary capability relevant to CC6.7 (Secure transmission and movement). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0197",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.6",
      "criterion_title": "System boundary protection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-01 provides governance, technical, or evidentiary capability relevant to CC6.6 (System boundary protection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0198",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.5",
      "criterion_title": "Asset disposal and removal",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "GAISSF D9-CTL-01 provides governance, technical, or evidentiary capability relevant to CC6.5 (Asset disposal and removal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0199",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "A1.3",
      "criterion_title": "Recovery plan testing",
      "category": "Availability",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-02 provides governance, technical, or evidentiary capability relevant to A1.3 (Recovery plan testing). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0200",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "A1.2",
      "criterion_title": "Environmental protections and recovery infrastructure",
      "category": "Availability",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-02 provides governance, technical, or evidentiary capability relevant to A1.2 (Environmental protections and recovery infrastructure). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0201",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "A1.1",
      "criterion_title": "Capacity and availability commitments",
      "category": "Availability",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-02 provides governance, technical, or evidentiary capability relevant to A1.1 (Capacity and availability commitments). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0202",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.8",
      "criterion_title": "Malicious software prevention and detection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-03 provides governance, technical, or evidentiary capability relevant to CC6.8 (Malicious software prevention and detection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0203",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.8",
      "criterion_title": "Malicious software prevention and detection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.8 (Malicious software prevention and detection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0204",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.7",
      "criterion_title": "Secure transmission and movement",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.7 (Secure transmission and movement). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0205",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.6",
      "criterion_title": "System boundary protection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.6 (System boundary protection). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0206",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "CC6.5",
      "criterion_title": "Asset disposal and removal",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-04 provides governance, technical, or evidentiary capability relevant to CC6.5 (Asset disposal and removal). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0207",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0208",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0209",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.3 (Processing completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0210",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-05 provides governance, technical, or evidentiary capability relevant to PI1.2 (Input completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0211",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "A1.3",
      "criterion_title": "Recovery plan testing",
      "category": "Availability",
      "relationship": "S",
      "coverage": "Indirectly Supported",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-06 provides governance, technical, or evidentiary capability relevant to A1.3 (Recovery plan testing). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0212",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.7 (Disclosure accounting). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0213",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.6 (Correction and amendment). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0214",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.5 (Data quality communication). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    },
    {
      "record_id": "GAISSF-CRO-031-MAP-0215",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "criterion_id": "P6.4",
      "criterion_title": "Unauthorized disclosure response",
      "category": "Privacy",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "GAISSF D9-CTL-07 provides governance, technical, or evidentiary capability relevant to P6.4 (Unauthorized disclosure response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement.",
      "residual_gap": "Criterion correspondence only. A SOC 2 engagement still requires the defined system and boundaries, management's description and assertion, applicable trust services categories, control design/implementation, examination evidence, subservice-organization and complementary user-entity control treatment as applicable, and independent CPA procedures and reporting. Mapping does not establish evidence sufficiency or operating effectiveness.",
      "gaissf_source": "GAISSF-NOR-004 v1.0",
      "soc2_source": "AICPA 2017 Trust Services Criteria (revised points of focus 2022)"
    }
  ],
  "reverse": [
    {
      "criterion_id": "CC1.1",
      "criterion_title": "Integrity and ethical values",
      "category": "Security / Common Criteria - Control Environment",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC1.2",
      "criterion_title": "Board oversight",
      "category": "Security / Common Criteria - Control Environment",
      "mapped_controls": [
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC1.3",
      "criterion_title": "Structures, reporting lines, authority and responsibility",
      "category": "Security / Common Criteria - Control Environment",
      "mapped_controls": [
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC1.4",
      "criterion_title": "Commitment to competence",
      "category": "Security / Common Criteria - Control Environment",
      "mapped_controls": [
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06"
      ],
      "mapped_count": 5,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC1.5",
      "criterion_title": "Accountability",
      "category": "Security / Common Criteria - Control Environment",
      "mapped_controls": [
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07"
      ],
      "mapped_count": 6,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC2.1",
      "criterion_title": "Quality information",
      "category": "Security / Common Criteria - Communication and Information",
      "mapped_controls": [
        "D8-CTL-03"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC2.2",
      "criterion_title": "Internal communication",
      "category": "Security / Common Criteria - Communication and Information",
      "mapped_controls": [
        "D8-CTL-03"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC2.3",
      "criterion_title": "External communication",
      "category": "Security / Common Criteria - Communication and Information",
      "mapped_controls": [
        "D8-CTL-03"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC3.1",
      "criterion_title": "Suitable objectives",
      "category": "Security / Common Criteria - Risk Assessment",
      "mapped_controls": [
        "D8-CTL-01"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC3.2",
      "criterion_title": "Risk identification and analysis",
      "category": "Security / Common Criteria - Risk Assessment",
      "mapped_controls": [
        "D8-CTL-01"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC3.3",
      "criterion_title": "Fraud risk",
      "category": "Security / Common Criteria - Risk Assessment",
      "mapped_controls": [
        "D6-CTL-01",
        "D8-CTL-01"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC3.4",
      "criterion_title": "Significant change",
      "category": "Security / Common Criteria - Risk Assessment",
      "mapped_controls": [
        "D6-CTL-01",
        "D8-CTL-01"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC4.1",
      "criterion_title": "Ongoing and separate evaluations",
      "category": "Security / Common Criteria - Monitoring",
      "mapped_controls": [
        "D6-CTL-02"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC4.2",
      "criterion_title": "Deficiency evaluation and communication",
      "category": "Security / Common Criteria - Monitoring",
      "mapped_controls": [
        "D6-CTL-02"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC5.1",
      "criterion_title": "Control activity selection and development",
      "category": "Security / Common Criteria - Control Activities",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC5.2",
      "criterion_title": "Technology general controls",
      "category": "Security / Common Criteria - Control Activities",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC5.3",
      "criterion_title": "Policies and procedures",
      "category": "Security / Common Criteria - Control Activities",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.1",
      "criterion_title": "Logical access security architecture",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.2",
      "criterion_title": "User registration and authorization",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.3",
      "criterion_title": "Access modification and removal",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.4",
      "criterion_title": "Physical access restrictions",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.5",
      "criterion_title": "Asset disposal and removal",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [
        "D3-CTL-04",
        "D3-CTL-05",
        "D9-CTL-01",
        "D9-CTL-04"
      ],
      "mapped_count": 4,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.6",
      "criterion_title": "System boundary protection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [
        "D3-CTL-04",
        "D3-CTL-05",
        "D9-CTL-01",
        "D9-CTL-04"
      ],
      "mapped_count": 4,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.7",
      "criterion_title": "Secure transmission and movement",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [
        "D3-CTL-04",
        "D3-CTL-05",
        "D9-CTL-01",
        "D9-CTL-04"
      ],
      "mapped_count": 4,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC6.8",
      "criterion_title": "Malicious software prevention and detection",
      "category": "Security / Common Criteria - Logical and Physical Access",
      "mapped_controls": [
        "D3-CTL-04",
        "D3-CTL-05",
        "D7-CTL-H03",
        "D9-CTL-01",
        "D9-CTL-03",
        "D9-CTL-04"
      ],
      "mapped_count": 6,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC7.1",
      "criterion_title": "Configuration and vulnerability management",
      "category": "Security / Common Criteria - System Operations",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC7.2",
      "criterion_title": "Security event monitoring",
      "category": "Security / Common Criteria - System Operations",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-04",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-06",
        "D4-CTL-04",
        "D8-CTL-04"
      ],
      "mapped_count": 13,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC7.3",
      "criterion_title": "Security event evaluation",
      "category": "Security / Common Criteria - System Operations",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-04",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-06",
        "D4-CTL-04",
        "D8-CTL-04"
      ],
      "mapped_count": 13,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC7.4",
      "criterion_title": "Incident response",
      "category": "Security / Common Criteria - System Operations",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-04",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-06",
        "D4-CTL-04",
        "D8-CTL-04"
      ],
      "mapped_count": 13,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC7.5",
      "criterion_title": "Recovery from incidents",
      "category": "Security / Common Criteria - System Operations",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-04",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-06",
        "D4-CTL-04",
        "D8-CTL-04"
      ],
      "mapped_count": 13,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC8.1",
      "criterion_title": "Authorized and controlled changes",
      "category": "Security / Common Criteria - Change Management",
      "mapped_controls": [
        "D1-CTL-06",
        "D3-CTL-03"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC9.1",
      "criterion_title": "Risk mitigation activities",
      "category": "Security / Common Criteria - Risk Mitigation",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-06"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "CC9.2",
      "criterion_title": "Vendor and business-partner risk",
      "category": "Security / Common Criteria - Risk Mitigation",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-06"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "A1.1",
      "criterion_title": "Capacity and availability commitments",
      "category": "Availability",
      "mapped_controls": [
        "D6-CTL-07",
        "D9-CTL-02"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "A1.2",
      "criterion_title": "Environmental protections and recovery infrastructure",
      "category": "Availability",
      "mapped_controls": [
        "D6-CTL-07",
        "D9-CTL-02"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "A1.3",
      "criterion_title": "Recovery plan testing",
      "category": "Availability",
      "mapped_controls": [
        "D6-CTL-07",
        "D9-CTL-02",
        "D9-CTL-06"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "PI1.1",
      "criterion_title": "Processing objectives and specifications",
      "category": "Processing Integrity",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "PI1.2",
      "criterion_title": "Input completeness and accuracy",
      "category": "Processing Integrity",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-05",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D9-CTL-05"
      ],
      "mapped_count": 11,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "PI1.3",
      "criterion_title": "Processing completeness and accuracy",
      "category": "Processing Integrity",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D9-CTL-05"
      ],
      "mapped_count": 12,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "PI1.4",
      "criterion_title": "Output completeness and accuracy",
      "category": "Processing Integrity",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D9-CTL-05"
      ],
      "mapped_count": 14,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "PI1.5",
      "criterion_title": "Data storage integrity",
      "category": "Processing Integrity",
      "mapped_controls": [
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D9-CTL-05"
      ],
      "mapped_count": 14,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "C1.1",
      "criterion_title": "Identification and protection of confidential information",
      "category": "Confidentiality",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "C1.2",
      "criterion_title": "Confidential information disposal",
      "category": "Confidentiality",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P1.1",
      "criterion_title": "Privacy notice and communication",
      "category": "Privacy",
      "mapped_controls": [
        "D5-CTL-05",
        "D5-CTL-06"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P2.1",
      "criterion_title": "Choice and consent",
      "category": "Privacy",
      "mapped_controls": [
        "D5-CTL-05",
        "D5-CTL-06"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P3.1",
      "criterion_title": "Collection limitation",
      "category": "Privacy",
      "mapped_controls": [
        "D4-CTL-03"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P3.2",
      "criterion_title": "Collection from third parties",
      "category": "Privacy",
      "mapped_controls": [
        "D4-CTL-03"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P4.1",
      "criterion_title": "Use limitation",
      "category": "Privacy",
      "mapped_controls": [
        "D3-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H05"
      ],
      "mapped_count": 5,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P4.2",
      "criterion_title": "Retention",
      "category": "Privacy",
      "mapped_controls": [
        "D3-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H05"
      ],
      "mapped_count": 5,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P4.3",
      "criterion_title": "Disposal",
      "category": "Privacy",
      "mapped_controls": [
        "D3-CTL-07",
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H05",
        "D8-CTL-02",
        "D8-CTL-05"
      ],
      "mapped_count": 7,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P5.1",
      "criterion_title": "Data-subject access",
      "category": "Privacy",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P6.1",
      "criterion_title": "Disclosure to third parties",
      "category": "Privacy",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P6.2",
      "criterion_title": "Third-party data handling agreements",
      "category": "Privacy",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P6.3",
      "criterion_title": "Third-party monitoring",
      "category": "Privacy",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P6.4",
      "criterion_title": "Unauthorized disclosure response",
      "category": "Privacy",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-05",
        "D4-CTL-07",
        "D7-CTL-H04",
        "D9-CTL-07"
      ],
      "mapped_count": 6,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P6.5",
      "criterion_title": "Data quality communication",
      "category": "Privacy",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D7-CTL-H04",
        "D9-CTL-07"
      ],
      "mapped_count": 7,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P6.6",
      "criterion_title": "Correction and amendment",
      "category": "Privacy",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D7-CTL-H04",
        "D9-CTL-07"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P6.7",
      "criterion_title": "Disclosure accounting",
      "category": "Privacy",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D7-CTL-H04",
        "D9-CTL-07"
      ],
      "mapped_count": 8,
      "coverage_status": "Substantially Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P7.1",
      "criterion_title": "Privacy data quality",
      "category": "Privacy",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    },
    {
      "criterion_id": "P8.1",
      "criterion_title": "Privacy inquiry, complaint and dispute handling",
      "category": "Privacy",
      "mapped_controls": [
        "D4-CTL-06"
      ],
      "mapped_count": 1,
      "coverage_status": "Indirectly Supported",
      "residual_gap": "Criterion coverage does not establish management's system description/assertion, control suitability, test procedures, exceptions, period coverage, subservice-organization treatment, complementary user-entity controls, evidence sufficiency, operating effectiveness, or CPA opinion."
    }
  ],
  "limitations": [
    "Mapping is not a SOC 2 examination, attestation report, certification, readiness conclusion, CPA opinion, evidence-sufficiency finding, or operating-effectiveness conclusion.",
    "The 2018 SOC 2 Description Criteria (with Revised Implementation Guidance – 2022), management system description and management assertion are separate requirements.",
    "Type I and Type II conclusions depend on engagement scope and independent CPA examination procedures; mapped controls do not establish those conclusions.",
    "Points of focus are not reproduced or treated as a separate checklist of mandatory controls.",
    "AICPA copyrighted criteria and related materials remain subject to applicable terms; this publication uses criterion identifiers and original concise functional summaries only.",
    "No AICPA/CIMA or CPA-firm endorsement or auditor acceptance is claimed.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only.",
    "Independent SOC 2/crosswalk review and explicit publication approval remain open."
  ]
}