# CRO-027 — GAISSF–EU AI Act Mapping **Version:** 1.0 **Status:** Publication Candidate **Publisher:** ODA3 Institute **Legal baseline:** Regulation (EU) 2024/1689 **Verified:** 29 June 2026 ## Purpose This crosswalk maps GAISSF v1.0 controls to selected material provisions of the EU AI Act. It supports implementation planning, evidence reuse and gap analysis. It does not establish legal compliance, legal classification, conformity, CE marking or regulatory approval. ## Source baseline and application timing The enacted baseline is Regulation (EU) 2024/1689. Application is phased. Each record carries an application-status field, but organisations must verify current law, amendments, implementing measures and sector-specific rules at the time of use. ## Dataset summary - GAISSF controls: 59 - In-scope AI Act provisions: 51 - Forward mapping records: 236 - Reverse article coverage records: 51 ## Article-level coverage | Article | Title | Group | Mapped controls | Coverage | Application status | |---:|---|---|---:|---|---| | 1 | Subject matter | General | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 2 | Scope | General | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 3 | Definitions | General | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 4 | AI literacy | General | 4 | Partially Addressed | Applicable since 2 February 2025 | | 5 | Prohibited AI practices | Prohibited practices | 6 | Partially Addressed | Applicable since 2 February 2025 | | 6 | Classification rules for high-risk AI systems | Classification | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 8 | Compliance with the requirements | High-risk requirements | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 9 | Risk management system | High-risk requirements | 49 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 10 | Data and data governance | High-risk requirements | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 11 | Technical documentation | High-risk requirements | 7 | Partially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 12 | Record-keeping | High-risk requirements | 2 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 13 | Transparency and provision of information to deployers | High-risk requirements | 10 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 14 | Human oversight | High-risk requirements | 27 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 15 | Accuracy, robustness and cybersecurity | High-risk requirements | 44 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 16 | Obligations of providers of high-risk AI systems | Provider obligations | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 17 | Quality management system | Provider obligations | 12 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 18 | Documentation keeping | Provider obligations | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 19 | Automatically generated logs | Provider obligations | 1 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 20 | Corrective actions and duty of information | Provider obligations | 2 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 21 | Cooperation with competent authorities | Provider obligations | 1 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 22 | Authorised representatives of providers of high-risk AI systems | Supply chain roles | 1 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 23 | Obligations of importers | Supply chain roles | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 24 | Obligations of distributors | Supply chain roles | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 25 | Responsibilities along the AI value chain | Supply chain roles | 6 | Partially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 26 | Obligations of deployers of high-risk AI systems | Deployer obligations | 15 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 27 | Fundamental rights impact assessment for high-risk AI systems | Deployer obligations | 13 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 43 | Conformity assessment | Conformity | 13 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 47 | EU declaration of conformity | Conformity | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 48 | CE marking | Conformity | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 49 | Registration | Conformity | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 50 | Transparency obligations for providers and deployers of certain AI systems | Transparency | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 51 | Classification of general-purpose AI models as general-purpose AI models with systemic risk | GPAI | 1 | Indirectly Supported | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 52 | Procedure | GPAI | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 53 | Obligations for providers of general-purpose AI models | GPAI | 2 | Indirectly Supported | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 54 | Authorised representatives of providers of general-purpose AI models | GPAI | 1 | Indirectly Supported | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 55 | Obligations of providers of general-purpose AI models with systemic risk | GPAI systemic risk | 7 | Partially Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 56 | Codes of practice | GPAI | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 57 | AI regulatory sandboxes | Innovation | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 59 | Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox | Innovation | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 72 | Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | Monitoring | 10 | Substantially Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 73 | Reporting of serious incidents | Incident reporting | 2 | Indirectly Supported | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 78 | Confidentiality | Governance | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 79 | Procedure for dealing with AI systems presenting a risk at national level | Market surveillance | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 80 | Procedure for dealing with AI systems classified by the provider as non-high-risk in application of Annex III | Market surveillance | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 86 | Right to explanation of individual decision-making | Rights | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 95 | Codes of conduct for voluntary application of specific requirements | Voluntary | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 99 | Fines for providers of general-purpose AI models | Enforcement | 0 | Not Addressed | Applicable since 2 August 2025 (subject to transitional/enforcement provisions) | | 110 | Evaluation and review | Review | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 111 | AI systems already placed on the market or put into service and general-purpose AI models already placed on the market | Transition | 0 | Not Addressed | Generally applicable from 2 the amended EU AI Act timetable unless a specific derogation or later date applies | | 112 | Amendment to Regulation (EC) No 300/2008 | Amendments | 0 | Not Addressed | Amendment-specific date; verify affected sector law | | 113 | Entry into force and application | Application | 0 | Not Addressed | In force; phased application governs | ## GAISSF-to-EU AI Act mapping register | Record | GAISSF control | EU AI Act provision | Relationship | Confidence | Rationale | Residual gap | |---|---|---|---|---|---|---| | CRO-027-0001 | D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-01 operationalises part of Article 15 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0002 | D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION | Article 9 — Risk management system | SP | High | GAISSF D1-CTL-01 operationalises part of Article 9 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0003 | D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION | Article 17 — Quality management system | SP | High | GAISSF D1-CTL-01 operationalises part of Article 17 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0004 | D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION | Article 55 — Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D1-CTL-01 operationalises part of Article 55 through Hash verification + source allowlist + poisoning detection.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0005 | D1-CTL-02 — MODEL EXTRACTION RESISTANCE | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-02 operationalises part of Article 15 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0006 | D1-CTL-02 — MODEL EXTRACTION RESISTANCE | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-02 operationalises part of Article 72 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0007 | D1-CTL-02 — MODEL EXTRACTION RESISTANCE | Article 55 — Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D1-CTL-02 operationalises part of Article 55 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0008 | D1-CTL-02 — MODEL EXTRACTION RESISTANCE | Article 9 — Risk management system | SP | High | GAISSF D1-CTL-02 operationalises part of Article 9 through Rate limiting + diversity detection + extraction monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0009 | D1-CTL-03 — BEHAVIORAL DRIFT DETECTION | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-03 operationalises part of Article 72 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0010 | D1-CTL-03 — BEHAVIORAL DRIFT DETECTION | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-03 operationalises part of Article 15 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0011 | D1-CTL-03 — BEHAVIORAL DRIFT DETECTION | Article 20 — Corrective actions and duty of information | P | Medium-High | GAISSF D1-CTL-03 operationalises part of Article 20 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 20 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0012 | D1-CTL-03 — BEHAVIORAL DRIFT DETECTION | Article 73 — Reporting of serious incidents | P | Medium-High | GAISSF D1-CTL-03 operationalises part of Article 73 through Baseline profiling + KL divergence monitoring + accuracy tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 73 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0013 | D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION | Article 9 — Risk management system | SP | High | GAISSF D1-CTL-04 operationalises part of Article 9 through Gradient anomaly detection + robust aggregation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0014 | D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-04 operationalises part of Article 15 through Gradient anomaly detection + robust aggregation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0015 | D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION | Article 55 — Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D1-CTL-04 operationalises part of Article 55 through Gradient anomaly detection + robust aggregation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0016 | D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-04 operationalises part of Article 72 through Gradient anomaly detection + robust aggregation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0017 | D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS | Article 9 — Risk management system | SP | High | GAISSF D1-CTL-05 operationalises part of Article 9 through Adversarial training + certified robustness measurement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0018 | D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-05 operationalises part of Article 15 through Adversarial training + certified robustness measurement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0019 | D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-05 operationalises part of Article 72 through Adversarial training + certified robustness measurement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0020 | D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS | Article 43 — Conformity assessment | S | Medium | GAISSF D1-CTL-05 operationalises part of Article 43 through Adversarial training + certified robustness measurement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0021 | D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D1-CTL-06 operationalises part of Article 15 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0022 | D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING | Article 9 — Risk management system | S | Medium | GAISSF D1-CTL-06 operationalises part of Article 9 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0023 | D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-06 operationalises part of Article 72 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0024 | D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING | Article 43 — Conformity assessment | S | Medium | GAISSF D1-CTL-06 operationalises part of Article 43 through PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0025 | D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D1-CTL-07 operationalises part of Article 15 through Adapter scanning + provenance verification + registry allowlist.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0026 | D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION | Article 9 — Risk management system | S | Medium | GAISSF D1-CTL-07 operationalises part of Article 9 through Adapter scanning + provenance verification + registry allowlist.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0027 | D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-07 operationalises part of Article 72 through Adapter scanning + provenance verification + registry allowlist.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0028 | D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION | Article 43 — Conformity assessment | S | Medium | GAISSF D1-CTL-07 operationalises part of Article 43 through Adapter scanning + provenance verification + registry allowlist.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0029 | D1-CTL-08 — MODEL MERGE ATTACK DETECTION | Article 9 — Risk management system | S | Medium | GAISSF D1-CTL-08 operationalises part of Article 9 through Pre-registration behavioural evaluation + regression testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0030 | D1-CTL-08 — MODEL MERGE ATTACK DETECTION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D1-CTL-08 operationalises part of Article 15 through Pre-registration behavioural evaluation + regression testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0031 | D1-CTL-08 — MODEL MERGE ATTACK DETECTION | Article 43 — Conformity assessment | S | Medium | GAISSF D1-CTL-08 operationalises part of Article 43 through Pre-registration behavioural evaluation + regression testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0032 | D1-CTL-08 — MODEL MERGE ATTACK DETECTION | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-08 operationalises part of Article 72 through Pre-registration behavioural evaluation + regression testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0033 | D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D1-CTL-09 operationalises part of Article 72 through Cross-precision behavioural comparison + delta threshold monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0034 | D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING | Article 9 — Risk management system | SP | High | GAISSF D1-CTL-09 operationalises part of Article 9 through Cross-precision behavioural comparison + delta threshold monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0035 | D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D1-CTL-09 operationalises part of Article 15 through Cross-precision behavioural comparison + delta threshold monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0036 | D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING | Article 43 — Conformity assessment | S | Medium | GAISSF D1-CTL-09 operationalises part of Article 43 through Cross-precision behavioural comparison + delta threshold monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0037 | D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D2-CTL-01 operationalises part of Article 15 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0038 | D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION | Article 9 — Risk management system | SP | High | GAISSF D2-CTL-01 operationalises part of Article 9 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0039 | D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D2-CTL-01 operationalises part of Article 26 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0040 | D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D2-CTL-01 operationalises part of Article 13 through Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0041 | D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D2-CTL-02 operationalises part of Article 15 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0042 | D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION | Article 9 — Risk management system | S | Medium | GAISSF D2-CTL-02 operationalises part of Article 9 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0043 | D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION | Article 14 — Human oversight | P | Medium-High | GAISSF D2-CTL-02 operationalises part of Article 14 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0044 | D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D2-CTL-02 operationalises part of Article 13 through Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0045 | D2-CTL-03 — JAILBREAK RESISTANCE TESTING | Article 9 — Risk management system | SP | High | GAISSF D2-CTL-03 operationalises part of Article 9 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0046 | D2-CTL-03 — JAILBREAK RESISTANCE TESTING | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D2-CTL-03 operationalises part of Article 15 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0047 | D2-CTL-03 — JAILBREAK RESISTANCE TESTING | Article 14 — Human oversight | P | Medium-High | GAISSF D2-CTL-03 operationalises part of Article 14 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0048 | D2-CTL-03 — JAILBREAK RESISTANCE TESTING | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D2-CTL-03 operationalises part of Article 13 through Quarterly red-team prompt library + adversarial training + automated refusal monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0049 | D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE | Article 9 — Risk management system | S | Medium | GAISSF D2-CTL-04 operationalises part of Article 9 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0050 | D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D2-CTL-04 operationalises part of Article 15 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0051 | D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D2-CTL-04 operationalises part of Article 13 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0052 | D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE | Article 14 — Human oversight | P | Medium-High | GAISSF D2-CTL-04 operationalises part of Article 14 through Multi-modal content scanning + steganography detection + modality-specific guardrails.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0053 | D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION | Article 9 — Risk management system | S | Medium | GAISSF D2-CTL-05 operationalises part of Article 9 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0054 | D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D2-CTL-05 operationalises part of Article 15 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0055 | D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION | Article 14 — Human oversight | P | Medium-High | GAISSF D2-CTL-05 operationalises part of Article 14 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0056 | D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D2-CTL-05 operationalises part of Article 26 through Parameter schema validation + allowlist enforcement + sandboxed execution.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0057 | D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION | Article 9 — Risk management system | S | Medium | GAISSF D2-CTL-06 operationalises part of Article 9 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0058 | D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D2-CTL-06 operationalises part of Article 15 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0059 | D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION | Article 43 — Conformity assessment | S | Medium | GAISSF D2-CTL-06 operationalises part of Article 43 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0060 | D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION | Article 55 — Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D2-CTL-06 operationalises part of Article 55 through Context window segmentation + prompt anchoring + attention boundary enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0061 | D3-CTL-01 — LEAST AGENCY ENFORCEMENT | Article 9 — Risk management system | S | Medium | GAISSF D3-CTL-01 operationalises part of Article 9 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0062 | D3-CTL-01 — LEAST AGENCY ENFORCEMENT | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D3-CTL-01 operationalises part of Article 26 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0063 | D3-CTL-01 — LEAST AGENCY ENFORCEMENT | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D3-CTL-01 operationalises part of Article 27 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0064 | D3-CTL-01 — LEAST AGENCY ENFORCEMENT | Article 14 — Human oversight | P | Medium-High | GAISSF D3-CTL-01 operationalises part of Article 14 through Role-based tool scoping + policy-as-code + dynamic permission revocation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0065 | D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY | Article 9 — Risk management system | SP | High | GAISSF D3-CTL-02 operationalises part of Article 9 through mTLS for agent mesh + message signing + payload validation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0066 | D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY | Article 14 — Human oversight | P | Medium-High | GAISSF D3-CTL-02 operationalises part of Article 14 through mTLS for agent mesh + message signing + payload validation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0067 | D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D3-CTL-02 operationalises part of Article 15 through mTLS for agent mesh + message signing + payload validation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0068 | D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D3-CTL-02 operationalises part of Article 26 through mTLS for agent mesh + message signing + payload validation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0069 | D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION | Article 9 — Risk management system | S | Medium | GAISSF D3-CTL-03 operationalises part of Article 9 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0070 | D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION | Article 14 — Human oversight | P | Medium-High | GAISSF D3-CTL-03 operationalises part of Article 14 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0071 | D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D3-CTL-03 operationalises part of Article 15 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0072 | D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D3-CTL-03 operationalises part of Article 26 through Cross-session behavioural correlation + chain pattern detection + anomaly scoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0073 | D3-CTL-04 — EMBODIED AI SAFETY CONTROLS | Article 9 — Risk management system | SP | High | GAISSF D3-CTL-04 operationalises part of Article 9 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0074 | D3-CTL-04 — EMBODIED AI SAFETY CONTROLS | Article 14 — Human oversight | P | Medium-High | GAISSF D3-CTL-04 operationalises part of Article 14 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0075 | D3-CTL-04 — EMBODIED AI SAFETY CONTROLS | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D3-CTL-04 operationalises part of Article 15 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0076 | D3-CTL-04 — EMBODIED AI SAFETY CONTROLS | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D3-CTL-04 operationalises part of Article 26 through Sensor integrity verification + safety interlocks + fail-safe state enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0077 | D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION | Article 9 — Risk management system | S | Medium | GAISSF D3-CTL-05 operationalises part of Article 9 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0078 | D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D3-CTL-05 operationalises part of Article 15 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0079 | D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION | Article 14 — Human oversight | P | Medium-High | GAISSF D3-CTL-05 operationalises part of Article 14 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0080 | D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D3-CTL-05 operationalises part of Article 26 through SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0081 | D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D3-CTL-06 operationalises part of Article 15 through User-scoped memory isolation + encryption at rest + query-level access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0082 | D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION | Article 9 — Risk management system | SP | High | GAISSF D3-CTL-06 operationalises part of Article 9 through User-scoped memory isolation + encryption at rest + query-level access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0083 | D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION | Article 14 — Human oversight | P | Medium-High | GAISSF D3-CTL-06 operationalises part of Article 14 through User-scoped memory isolation + encryption at rest + query-level access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0084 | D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D3-CTL-06 operationalises part of Article 26 through User-scoped memory isolation + encryption at rest + query-level access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0085 | D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT | Article 9 — Risk management system | S | Medium | GAISSF D3-CTL-07 operationalises part of Article 9 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0086 | D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D3-CTL-07 operationalises part of Article 15 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0087 | D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D3-CTL-07 operationalises part of Article 26 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0088 | D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT | Article 14 — Human oversight | P | Medium-High | GAISSF D3-CTL-07 operationalises part of Article 14 through Cryptographic deletion + lifecycle policy enforcement + retention auditing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0089 | D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D4-CTL-01 operationalises part of Article 15 through Automated BOM generation + version tracking + registry synchronization.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0090 | D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE | Article 17 — Quality management system | S | Medium | GAISSF D4-CTL-01 operationalises part of Article 17 through Automated BOM generation + version tracking + registry synchronization.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0091 | D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE | Article 11 — Technical documentation | P | Medium-High | GAISSF D4-CTL-01 operationalises part of Article 11 through Automated BOM generation + version tracking + registry synchronization.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 11 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0092 | D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE | Article 25 — Responsibilities along the AI value chain | P | Medium-High | GAISSF D4-CTL-01 operationalises part of Article 25 through Automated BOM generation + version tracking + registry synchronization.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 25 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0093 | D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D4-CTL-02 operationalises part of Article 15 through Static analysis + deserialization sandboxing + signature verification.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0094 | D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING | Article 17 — Quality management system | S | Medium | GAISSF D4-CTL-02 operationalises part of Article 17 through Static analysis + deserialization sandboxing + signature verification.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0095 | D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING | Article 11 — Technical documentation | P | Medium-High | GAISSF D4-CTL-02 operationalises part of Article 11 through Static analysis + deserialization sandboxing + signature verification.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 11 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0096 | D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING | Article 25 — Responsibilities along the AI value chain | P | Medium-High | GAISSF D4-CTL-02 operationalises part of Article 25 through Static analysis + deserialization sandboxing + signature verification.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 25 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0097 | D4-CTL-03 — MODEL HUB & REGISTRY VETTING | Article 11 — Technical documentation | P | Medium-High | GAISSF D4-CTL-03 operationalises part of Article 11 through Provenance verification + license compliance + security scorecard.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 11 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0098 | D4-CTL-03 — MODEL HUB & REGISTRY VETTING | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D4-CTL-03 operationalises part of Article 15 through Provenance verification + license compliance + security scorecard.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0099 | D4-CTL-03 — MODEL HUB & REGISTRY VETTING | Article 17 — Quality management system | SP | High | GAISSF D4-CTL-03 operationalises part of Article 17 through Provenance verification + license compliance + security scorecard.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0100 | D4-CTL-03 — MODEL HUB & REGISTRY VETTING | Article 25 — Responsibilities along the AI value chain | P | Medium-High | GAISSF D4-CTL-03 operationalises part of Article 25 through Provenance verification + license compliance + security scorecard.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 25 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0101 | D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D4-CTL-04 operationalises part of Article 15 through Tool-call logging + anomaly detection + access control enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0102 | D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING | Article 25 — Responsibilities along the AI value chain | P | Medium-High | GAISSF D4-CTL-04 operationalises part of Article 25 through Tool-call logging + anomaly detection + access control enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 25 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0103 | D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING | Article 11 — Technical documentation | P | Medium-High | GAISSF D4-CTL-04 operationalises part of Article 11 through Tool-call logging + anomaly detection + access control enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 11 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0104 | D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING | Article 17 — Quality management system | SP | High | GAISSF D4-CTL-04 operationalises part of Article 17 through Tool-call logging + anomaly detection + access control enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0105 | D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D4-CTL-05 operationalises part of Article 15 through Contractual security requirements + penetration testing + data flow mapping.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0106 | D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT | Article 11 — Technical documentation | P | Medium-High | GAISSF D4-CTL-05 operationalises part of Article 11 through Contractual security requirements + penetration testing + data flow mapping.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 11 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0107 | D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT | Article 17 — Quality management system | SP | High | GAISSF D4-CTL-05 operationalises part of Article 17 through Contractual security requirements + penetration testing + data flow mapping.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0108 | D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT | Article 53 — Obligations for providers of general-purpose AI models | P | Medium-High | GAISSF D4-CTL-05 operationalises part of Article 53 through Contractual security requirements + penetration testing + data flow mapping.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 53 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0109 | D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE | Article 17 — Quality management system | S | Medium | GAISSF D4-CTL-06 operationalises part of Article 17 through Network traffic analysis + SaaS discovery + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0110 | D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D4-CTL-06 operationalises part of Article 15 through Network traffic analysis + SaaS discovery + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0111 | D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE | Article 25 — Responsibilities along the AI value chain | P | Medium-High | GAISSF D4-CTL-06 operationalises part of Article 25 through Network traffic analysis + SaaS discovery + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 25 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0112 | D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE | Article 9 — Risk management system | S | Medium | GAISSF D4-CTL-06 operationalises part of Article 9 through Network traffic analysis + SaaS discovery + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0113 | D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA) | Article 11 — Technical documentation | P | Medium-High | GAISSF D4-CTL-07 operationalises part of Article 11 through Dependency scanning + CVE matching + automated patching.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 11 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0114 | D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA) | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D4-CTL-07 operationalises part of Article 15 through Dependency scanning + CVE matching + automated patching.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0115 | D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA) | Article 17 — Quality management system | S | Medium | GAISSF D4-CTL-07 operationalises part of Article 17 through Dependency scanning + CVE matching + automated patching.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0116 | D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA) | Article 25 — Responsibilities along the AI value chain | P | Medium-High | GAISSF D4-CTL-07 operationalises part of Article 25 through Dependency scanning + CVE matching + automated patching.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 25 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0117 | D5-CTL-01 — HARMFUL CONTENT BLOCKING | Article 9 — Risk management system | S | Medium | GAISSF D5-CTL-01 operationalises part of Article 9 through Content safety classifier + refusal engine.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0118 | D5-CTL-01 — HARMFUL CONTENT BLOCKING | Article 5 — Prohibited AI practices | S | Medium | GAISSF D5-CTL-01 operationalises part of Article 5 through Content safety classifier + refusal engine.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 5 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0119 | D5-CTL-01 — HARMFUL CONTENT BLOCKING | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D5-CTL-01 operationalises part of Article 13 through Content safety classifier + refusal engine.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0120 | D5-CTL-01 — HARMFUL CONTENT BLOCKING | Article 14 — Human oversight | P | Medium-High | GAISSF D5-CTL-01 operationalises part of Article 14 through Content safety classifier + refusal engine.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0121 | D5-CTL-02 — PII LEAKAGE PREVENTION | Article 9 — Risk management system | SP | High | GAISSF D5-CTL-02 operationalises part of Article 9 through PII detection + masking + access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0122 | D5-CTL-02 — PII LEAKAGE PREVENTION | Article 5 — Prohibited AI practices | S | Medium | GAISSF D5-CTL-02 operationalises part of Article 5 through PII detection + masking + access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 5 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0123 | D5-CTL-02 — PII LEAKAGE PREVENTION | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D5-CTL-02 operationalises part of Article 13 through PII detection + masking + access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0124 | D5-CTL-02 — PII LEAKAGE PREVENTION | Article 14 — Human oversight | P | Medium-High | GAISSF D5-CTL-02 operationalises part of Article 14 through PII detection + masking + access controls.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0125 | D5-CTL-03 — COPYRIGHT DETECTION | Article 9 — Risk management system | S | Medium | GAISSF D5-CTL-03 operationalises part of Article 9 through n-gram overlap detection + refusal.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0126 | D5-CTL-03 — COPYRIGHT DETECTION | Article 5 — Prohibited AI practices | S | Medium | GAISSF D5-CTL-03 operationalises part of Article 5 through n-gram overlap detection + refusal.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 5 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0127 | D5-CTL-03 — COPYRIGHT DETECTION | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D5-CTL-03 operationalises part of Article 13 through n-gram overlap detection + refusal.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0128 | D5-CTL-03 — COPYRIGHT DETECTION | Article 14 — Human oversight | P | Medium-High | GAISSF D5-CTL-03 operationalises part of Article 14 through n-gram overlap detection + refusal.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0129 | D5-CTL-04 — AI WATERMARKING ROBUSTNESS | Article 9 — Risk management system | SP | High | GAISSF D5-CTL-04 operationalises part of Article 9 through C2PA-compliant watermarking + tamper resistance testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0130 | D5-CTL-04 — AI WATERMARKING ROBUSTNESS | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D5-CTL-04 operationalises part of Article 15 through C2PA-compliant watermarking + tamper resistance testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0131 | D5-CTL-04 — AI WATERMARKING ROBUSTNESS | Article 5 — Prohibited AI practices | S | Medium | GAISSF D5-CTL-04 operationalises part of Article 5 through C2PA-compliant watermarking + tamper resistance testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 5 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0132 | D5-CTL-04 — AI WATERMARKING ROBUSTNESS | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D5-CTL-04 operationalises part of Article 13 through C2PA-compliant watermarking + tamper resistance testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0133 | D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION | Article 9 — Risk management system | S | Medium | GAISSF D5-CTL-05 operationalises part of Article 9 through Data minimization + purpose limitation + machine unlearning.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0134 | D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION | Article 5 — Prohibited AI practices | S | Medium | GAISSF D5-CTL-05 operationalises part of Article 5 through Data minimization + purpose limitation + machine unlearning.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 5 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0135 | D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D5-CTL-05 operationalises part of Article 13 through Data minimization + purpose limitation + machine unlearning.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0136 | D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION | Article 14 — Human oversight | P | Medium-High | GAISSF D5-CTL-05 operationalises part of Article 14 through Data minimization + purpose limitation + machine unlearning.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0137 | D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION | Article 9 — Risk management system | S | Medium | GAISSF D5-CTL-06 operationalises part of Article 9 through Differential privacy + membership inference testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0138 | D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D5-CTL-06 operationalises part of Article 15 through Differential privacy + membership inference testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0139 | D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION | Article 13 — Transparency and provision of information to deployers | P | Medium-High | GAISSF D5-CTL-06 operationalises part of Article 13 through Differential privacy + membership inference testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 13 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0140 | D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION | Article 14 — Human oversight | P | Medium-High | GAISSF D5-CTL-06 operationalises part of Article 14 through Differential privacy + membership inference testing.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0141 | D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS | Article 9 — Risk management system | SP | High | GAISSF D6-CTL-01 operationalises part of Article 9 through Approval workflow + policy enforcement + audit log.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0142 | D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D6-CTL-01 operationalises part of Article 27 through Approval workflow + policy enforcement + audit log.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0143 | D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D6-CTL-01 operationalises part of Article 26 through Approval workflow + policy enforcement + audit log.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0144 | D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS | Article 4 — AI literacy | S | Medium | GAISSF D6-CTL-01 operationalises part of Article 4 through Approval workflow + policy enforcement + audit log.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 4 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0145 | D6-CTL-02 — AUDIT TRAIL COMPLETENESS | Article 9 — Risk management system | S | Medium | GAISSF D6-CTL-02 operationalises part of Article 9 through Structured logging + SIEM integration + retention enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0146 | D6-CTL-02 — AUDIT TRAIL COMPLETENESS | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D6-CTL-02 operationalises part of Article 27 through Structured logging + SIEM integration + retention enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0147 | D6-CTL-02 — AUDIT TRAIL COMPLETENESS | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D6-CTL-02 operationalises part of Article 26 through Structured logging + SIEM integration + retention enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0148 | D6-CTL-02 — AUDIT TRAIL COMPLETENESS | Article 4 — AI literacy | S | Medium | GAISSF D6-CTL-02 operationalises part of Article 4 through Structured logging + SIEM integration + retention enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 4 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0149 | D6-CTL-03 — AI MODEL CARD COMPLETENESS | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D6-CTL-03 operationalises part of Article 27 through Standardized template + version control + public accessibility.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0150 | D6-CTL-03 — AI MODEL CARD COMPLETENESS | Article 9 — Risk management system | SP | High | GAISSF D6-CTL-03 operationalises part of Article 9 through Standardized template + version control + public accessibility.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0151 | D6-CTL-03 — AI MODEL CARD COMPLETENESS | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D6-CTL-03 operationalises part of Article 26 through Standardized template + version control + public accessibility.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0152 | D6-CTL-03 — AI MODEL CARD COMPLETENESS | Article 17 — Quality management system | SP | High | GAISSF D6-CTL-03 operationalises part of Article 17 through Standardized template + version control + public accessibility.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0153 | D6-CTL-04 — AI INCIDENT RESPONSE READINESS | Article 9 — Risk management system | S | Medium | GAISSF D6-CTL-04 operationalises part of Article 9 through AI-IR runbook + tabletop exercises + containment automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0154 | D6-CTL-04 — AI INCIDENT RESPONSE READINESS | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D6-CTL-04 operationalises part of Article 27 through AI-IR runbook + tabletop exercises + containment automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0155 | D6-CTL-04 — AI INCIDENT RESPONSE READINESS | Article 21 — Cooperation with competent authorities | S | Medium | GAISSF D6-CTL-04 operationalises part of Article 21 through AI-IR runbook + tabletop exercises + containment automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 21 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0156 | D6-CTL-04 — AI INCIDENT RESPONSE READINESS | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D6-CTL-04 operationalises part of Article 15 through AI-IR runbook + tabletop exercises + containment automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0157 | D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING | Article 9 — Risk management system | S | Medium | GAISSF D6-CTL-05 operationalises part of Article 9 through Access revocation + decommission audit + scheduled lifecycle.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0158 | D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D6-CTL-05 operationalises part of Article 27 through Access revocation + decommission audit + scheduled lifecycle.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0159 | D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D6-CTL-05 operationalises part of Article 26 through Access revocation + decommission audit + scheduled lifecycle.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0160 | D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING | Article 4 — AI literacy | S | Medium | GAISSF D6-CTL-05 operationalises part of Article 4 through Access revocation + decommission audit + scheduled lifecycle.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 4 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0161 | D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE | Article 17 — Quality management system | SP | High | GAISSF D6-CTL-06 operationalises part of Article 17 through Contractual security requirements + annual assessment + audit rights.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0162 | D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D6-CTL-06 operationalises part of Article 15 through Contractual security requirements + annual assessment + audit rights.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0163 | D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE | Article 9 — Risk management system | SP | High | GAISSF D6-CTL-06 operationalises part of Article 9 through Contractual security requirements + annual assessment + audit rights.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0164 | D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D6-CTL-06 operationalises part of Article 27 through Contractual security requirements + annual assessment + audit rights.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0165 | D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY | Article 9 — Risk management system | S | Medium | GAISSF D6-CTL-07 operationalises part of Article 9 through Failover systems + degraded mode + RTO/RPO definition.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0166 | D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D6-CTL-07 operationalises part of Article 27 through Failover systems + degraded mode + RTO/RPO definition.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0167 | D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D6-CTL-07 operationalises part of Article 26 through Failover systems + degraded mode + RTO/RPO definition.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0168 | D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY | Article 4 — AI literacy | S | Medium | GAISSF D6-CTL-07 operationalises part of Article 4 through Failover systems + degraded mode + RTO/RPO definition.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 4 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0169 | D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION | Article 9 — Risk management system | S | Medium | GAISSF D7-CTL-H01 operationalises part of Article 9 through Simulation campaigns + click tracking + remedial training.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0170 | D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION | Article 14 — Human oversight | P | Medium-High | GAISSF D7-CTL-H01 operationalises part of Article 14 through Simulation campaigns + click tracking + remedial training.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0171 | D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D7-CTL-H01 operationalises part of Article 27 through Simulation campaigns + click tracking + remedial training.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0172 | D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D7-CTL-H01 operationalises part of Article 15 through Simulation campaigns + click tracking + remedial training.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0173 | D7-CTL-H02 — DEEPFAKE DETECTION TRAINING | Article 9 — Risk management system | S | Medium | GAISSF D7-CTL-H02 operationalises part of Article 9 through Training modules + quiz + simulated attacks.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0174 | D7-CTL-H02 — DEEPFAKE DETECTION TRAINING | Article 14 — Human oversight | P | Medium-High | GAISSF D7-CTL-H02 operationalises part of Article 14 through Training modules + quiz + simulated attacks.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0175 | D7-CTL-H02 — DEEPFAKE DETECTION TRAINING | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D7-CTL-H02 operationalises part of Article 27 through Training modules + quiz + simulated attacks.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0176 | D7-CTL-H02 — DEEPFAKE DETECTION TRAINING | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D7-CTL-H02 operationalises part of Article 15 through Training modules + quiz + simulated attacks.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0177 | D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION | Article 9 — Risk management system | S | Medium | GAISSF D7-CTL-H03 operationalises part of Article 9 through Independent channel verification + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0178 | D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D7-CTL-H03 operationalises part of Article 27 through Independent channel verification + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0179 | D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION | Article 14 — Human oversight | P | Medium-High | GAISSF D7-CTL-H03 operationalises part of Article 14 through Independent channel verification + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0180 | D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION | Article 5 — Prohibited AI practices | S | Medium | GAISSF D7-CTL-H03 operationalises part of Article 5 through Independent channel verification + policy enforcement.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 5 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0181 | D7-CTL-H04 — AI SOCIAL ENGINEERING IR | Article 9 — Risk management system | S | Medium | GAISSF D7-CTL-H04 operationalises part of Article 9 through Tabletop exercises + IR plan + verification triggers.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0182 | D7-CTL-H04 — AI SOCIAL ENGINEERING IR | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D7-CTL-H04 operationalises part of Article 27 through Tabletop exercises + IR plan + verification triggers.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0183 | D7-CTL-H04 — AI SOCIAL ENGINEERING IR | Article 14 — Human oversight | P | Medium-High | GAISSF D7-CTL-H04 operationalises part of Article 14 through Tabletop exercises + IR plan + verification triggers.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0184 | D7-CTL-H04 — AI SOCIAL ENGINEERING IR | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D7-CTL-H04 operationalises part of Article 15 through Tabletop exercises + IR plan + verification triggers.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0185 | D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE | Article 9 — Risk management system | S | Medium | GAISSF D7-CTL-H05 operationalises part of Article 9 through AI-generated phishing detection + SOC tuning + response automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0186 | D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE | Article 27 — Fundamental rights impact assessment for high-risk AI systems | P | Medium-High | GAISSF D7-CTL-H05 operationalises part of Article 27 through AI-generated phishing detection + SOC tuning + response automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 27 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0187 | D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE | Article 14 — Human oversight | P | Medium-High | GAISSF D7-CTL-H05 operationalises part of Article 14 through AI-generated phishing detection + SOC tuning + response automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0188 | D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D7-CTL-H05 operationalises part of Article 15 through AI-generated phishing detection + SOC tuning + response automation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0189 | D8-CTL-01 — EU AI ACT RISK TIER MAPPING | Article 51 — Classification of general-purpose AI models as general-purpose AI models with systemic risk | S | Medium | GAISSF D8-CTL-01 operationalises part of Article 51 through Risk classification framework + conformity assessment.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 51 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0190 | D8-CTL-01 — EU AI ACT RISK TIER MAPPING | Article 53 — Obligations for providers of general-purpose AI models | P | Medium-High | GAISSF D8-CTL-01 operationalises part of Article 53 through Risk classification framework + conformity assessment.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 53 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0191 | D8-CTL-01 — EU AI ACT RISK TIER MAPPING | Article 54 — Authorised representatives of providers of general-purpose AI models | S | Medium | GAISSF D8-CTL-01 operationalises part of Article 54 through Risk classification framework + conformity assessment.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 54 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0192 | D8-CTL-01 — EU AI ACT RISK TIER MAPPING | Article 55 — Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D8-CTL-01 operationalises part of Article 55 through Risk classification framework + conformity assessment.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0193 | D8-CTL-02 — ISO 42001 GAP ANALYSIS | Article 11 — Technical documentation | P | Medium-High | GAISSF D8-CTL-02 operationalises part of Article 11 through Gap analysis methodology + remediation tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 11 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0194 | D8-CTL-02 — ISO 42001 GAP ANALYSIS | Article 17 — Quality management system | S | Medium | GAISSF D8-CTL-02 operationalises part of Article 17 through Gap analysis methodology + remediation tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0195 | D8-CTL-02 — ISO 42001 GAP ANALYSIS | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D8-CTL-02 operationalises part of Article 15 through Gap analysis methodology + remediation tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0196 | D8-CTL-02 — ISO 42001 GAP ANALYSIS | Article 22 — Authorised representatives of providers of high-risk AI systems | S | Medium | GAISSF D8-CTL-02 operationalises part of Article 22 through Gap analysis methodology + remediation tracking.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 22 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0197 | D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION | Article 17 — Quality management system | S | Medium | GAISSF D8-CTL-03 operationalises part of Article 17 through Technical documentation + training data summary + copyright attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 17 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0198 | D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION | Article 55 — Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D8-CTL-03 operationalises part of Article 55 through Technical documentation + training data summary + copyright attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0199 | D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION | Article 43 — Conformity assessment | S | Medium | GAISSF D8-CTL-03 operationalises part of Article 43 through Technical documentation + training data summary + copyright attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0200 | D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION | Article 9 — Risk management system | S | Medium | GAISSF D8-CTL-03 operationalises part of Article 9 through Technical documentation + training data summary + copyright attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0201 | D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR) | Article 12 — Record-keeping | P | Medium-High | GAISSF D8-CTL-04 operationalises part of Article 12 through Incident classification + notification workflow + SLA monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 12 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0202 | D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR) | Article 20 — Corrective actions and duty of information | P | Medium-High | GAISSF D8-CTL-04 operationalises part of Article 20 through Incident classification + notification workflow + SLA monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 20 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0203 | D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR) | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D8-CTL-04 operationalises part of Article 72 through Incident classification + notification workflow + SLA monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0204 | D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR) | Article 73 — Reporting of serious incidents | P | Medium-High | GAISSF D8-CTL-04 operationalises part of Article 73 through Incident classification + notification workflow + SLA monitoring.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 73 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0205 | D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK | Article 43 — Conformity assessment | S | Medium | GAISSF D8-CTL-05 operationalises part of Article 43 through Secure development practices + attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0206 | D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK | Article 9 — Risk management system | S | Medium | GAISSF D8-CTL-05 operationalises part of Article 9 through Secure development practices + attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0207 | D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D8-CTL-05 operationalises part of Article 15 through Secure development practices + attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0208 | D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK | Article 55 — Obligations of providers of general-purpose AI models with systemic risk | P | Medium-High | GAISSF D8-CTL-05 operationalises part of Article 55 through Secure development practices + attestation.. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 55 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0209 | D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT | Article 9 — Risk management system | SP | High | GAISSF D9-CTL-01 operationalises part of Article 9 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0210 | D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D9-CTL-01 operationalises part of Article 15 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0211 | D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT | Article 14 — Human oversight | P | Medium-High | GAISSF D9-CTL-01 operationalises part of Article 14 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0212 | D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT | Article 43 — Conformity assessment | S | Medium | GAISSF D9-CTL-01 operationalises part of Article 43 through Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0213 | D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION | Article 9 — Risk management system | SP | High | GAISSF D9-CTL-02 operationalises part of Article 9 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); tran. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0214 | D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D9-CTL-02 operationalises part of Article 15 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); tran. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0215 | D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION | Article 14 — Human oversight | P | Medium-High | GAISSF D9-CTL-02 operationalises part of Article 14 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); tran. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0216 | D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION | Article 43 — Conformity assessment | S | Medium | GAISSF D9-CTL-02 operationalises part of Article 43 through For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); tran. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0217 | D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP | Article 9 — Risk management system | SP | High | GAISSF D9-CTL-03 operationalises part of Article 9 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human ope. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0218 | D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP | Article 14 — Human oversight | P | Medium-High | GAISSF D9-CTL-03 operationalises part of Article 14 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human ope. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0219 | D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D9-CTL-03 operationalises part of Article 15 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human ope. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0220 | D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP | Article 43 — Conformity assessment | S | Medium | GAISSF D9-CTL-03 operationalises part of Article 43 through Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human ope. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0221 | D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION | Article 9 — Risk management system | SP | High | GAISSF D9-CTL-04 operationalises part of Article 9 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-valida. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0222 | D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D9-CTL-04 operationalises part of Article 15 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-valida. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0223 | D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION | Article 43 — Conformity assessment | S | Medium | GAISSF D9-CTL-04 operationalises part of Article 43 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-valida. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0224 | D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION | Article 14 — Human oversight | P | Medium-High | GAISSF D9-CTL-04 operationalises part of Article 14 through Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-valida. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0225 | D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING | Article 9 — Risk management system | SP | High | GAISSF D9-CTL-05 operationalises part of Article 9 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence fall. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0226 | D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING | Article 15 — Accuracy, robustness and cybersecurity | SP | High | GAISSF D9-CTL-05 operationalises part of Article 15 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence fall. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0227 | D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING | Article 26 — Obligations of deployers of high-risk AI systems | P | Medium-High | GAISSF D9-CTL-05 operationalises part of Article 26 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence fall. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 26 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0228 | D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING | Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems | P | Medium-High | GAISSF D9-CTL-05 operationalises part of Article 72 through Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence fall. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 72 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0229 | D9-CTL-06 — ACTUATOR COMMAND VERIFICATION | Article 9 — Risk management system | S | Medium | GAISSF D9-CTL-06 operationalises part of Article 9 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibil. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0230 | D9-CTL-06 — ACTUATOR COMMAND VERIFICATION | Article 15 — Accuracy, robustness and cybersecurity | S | Medium | GAISSF D9-CTL-06 operationalises part of Article 15 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibil. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 15 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0231 | D9-CTL-06 — ACTUATOR COMMAND VERIFICATION | Article 14 — Human oversight | P | Medium-High | GAISSF D9-CTL-06 operationalises part of Article 14 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibil. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0232 | D9-CTL-06 — ACTUATOR COMMAND VERIFICATION | Article 43 — Conformity assessment | S | Medium | GAISSF D9-CTL-06 operationalises part of Article 43 through Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibil. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 43 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0233 | D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION | Article 9 — Risk management system | SP | High | GAISSF D9-CTL-07 operationalises part of Article 9 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safet. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 9 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0234 | D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION | Article 14 — Human oversight | P | Medium-High | GAISSF D9-CTL-07 operationalises part of Article 14 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safet. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 14 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0235 | D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION | Article 12 — Record-keeping | P | Medium-High | GAISSF D9-CTL-07 operationalises part of Article 12 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safet. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 12 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | | CRO-027-0236 | D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION | Article 19 — Automatically generated logs | S | Medium | GAISSF D9-CTL-07 operationalises part of Article 19 through (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safet. The relationship is limited to the control's stated scope and does not establish legal compliance. | Article 19 also depends on legal role, system classification, territorial scope, procedural duties, and evidence requirements not established by this control alone. | ## Notably absent This crosswalk does not establish that GAISSF certification equals EU AI Act conformity, that every GAISSF control is legally required, that every AI Act obligation is a technical security control, or that use of the crosswalk creates a presumption of conformity.