# SEC-046 - GAISSF Retail Sector Implementation Guide - Technical Report **Status:** Publication Candidate - Open Review Gates **Publication date:** 1 July 2026 **Authoritative source:** GAISSF-NOR-001 ## Contents - [Start Here](#start-here) - [Methodology](#methodology) - [Retail use cases](#retail-use-cases) - [Threat landscape](#threat-landscape) - [Complete control mapping](#complete-control-mapping) - [Worked scenarios](#worked-scenarios) - [Notably Absent](#notably-absent) ## Start Here Prioritise inventory, accountability, applicability, prompt/tool boundaries, supplier governance, personal-data protection, human review, auditability, incident readiness and continuity. Priority labels sequence implementation; they do not change GAISSF applicability. ## Methodology Analysis of public disclosures and authoritative standards informs external context [T1-T2]. Technical research supports demonstrated classes [T2]; practitioner patterns and scenarios are contextual [T3-T4]. No proprietary retail telemetry was used. ## Retail use cases - **RET-UC-001 - Personalised recommendations:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-002 - Product search and ranking:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-003 - Dynamic pricing:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-004 - Promotion optimisation:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-005 - Demand forecasting:** Warehouse and store workers; supply-chain leaders; suppliers; customers affected by availability; environment: Warehouse edge, supply-chain platform and cloud analytics. - **RET-UC-006 - Inventory allocation:** Warehouse and store workers; supply-chain leaders; suppliers; customers affected by availability; environment: Warehouse edge, supply-chain platform and cloud analytics. - **RET-UC-007 - Automated replenishment:** Warehouse and store workers; supply-chain leaders; suppliers; customers affected by availability; environment: Warehouse edge, supply-chain platform and cloud analytics. - **RET-UC-008 - Warehouse robotics:** Warehouse and store workers; supply-chain leaders; suppliers; customers affected by availability; environment: Warehouse edge, supply-chain platform and cloud analytics. - **RET-UC-009 - Route and delivery optimisation:** Warehouse and store workers; supply-chain leaders; suppliers; customers affected by availability; environment: Warehouse edge, supply-chain platform and cloud analytics. - **RET-UC-010 - Self-checkout vision:** Customers and store workers; loss-prevention and store operations; privacy/compliance teams; environment: Store edge, cameras and sensors, local network and central cloud services. - **RET-UC-011 - Computer-vision loss prevention:** Customers and store workers; loss-prevention and store operations; privacy/compliance teams; environment: Store edge, cameras and sensors, local network and central cloud services. - **RET-UC-012 - Fraud detection:** Customers; fraud and payments teams; customer service; payment and identity providers; environment: Payment/fraud platform, e-commerce and point-of-sale integrations. - **RET-UC-013 - Payment-risk scoring:** Customers; fraud and payments teams; customer service; payment and identity providers; environment: Payment/fraud platform, e-commerce and point-of-sale integrations. - **RET-UC-014 - Customer-service chatbot:** Customers and customer-service staff; product and operations owners; privacy and security functions; environment: Customer-service platform, e-commerce account systems and cloud AI service. - **RET-UC-015 - Generative product descriptions:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-016 - Marketing-content generation:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-017 - Customer segmentation:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-018 - Loyalty analytics:** Customers; fraud and payments teams; customer service; payment and identity providers; environment: Payment/fraud platform, e-commerce and point-of-sale integrations. - **RET-UC-019 - Retail media targeting:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-020 - Facial recognition:** Customers and store workers; loss-prevention and store operations; privacy/compliance teams; environment: Store edge, cameras and sensors, local network and central cloud services. - **RET-UC-021 - Age estimation:** Customers and store workers; loss-prevention and store operations; privacy/compliance teams; environment: Store edge, cameras and sensors, local network and central cloud services. - **RET-UC-022 - Workforce scheduling:** Applicants and employees; human resources; line managers; worker representatives where applicable; environment: Human-resources platform, software-as-a-service and enterprise data environment. - **RET-UC-023 - Employee productivity monitoring:** Applicants and employees; human resources; line managers; worker representatives where applicable; environment: Human-resources platform, software-as-a-service and enterprise data environment. - **RET-UC-024 - Hiring and screening:** Applicants and employees; human resources; line managers; worker representatives where applicable; environment: Human-resources platform, software-as-a-service and enterprise data environment. - **RET-UC-025 - Returns-abuse detection:** Customers; fraud and payments teams; customer service; payment and identity providers; environment: Payment/fraud platform, e-commerce and point-of-sale integrations. - **RET-UC-026 - Counterfeit detection:** Customers and customer-service staff; product and operations owners; privacy and security functions; environment: Customer-service platform, e-commerce account systems and cloud AI service. - **RET-UC-027 - Visual search and virtual try-on:** Customers; merchandising and marketing teams; sellers/advertisers where applicable; consumer-protection and privacy functions; environment: E-commerce, mobile application, customer-data platform and cloud inference. - **RET-UC-028 - Smart shelves and store analytics:** Customers and store workers; loss-prevention and store operations; privacy/compliance teams; environment: Store edge, cameras and sensors, local network and central cloud services. - **RET-UC-029 - Autonomous store systems:** Customers and store workers; loss-prevention and store operations; privacy/compliance teams; environment: Store edge, cameras and sensors, local network and central cloud services. - **RET-UC-030 - Developer copilots and code generation:** Developers and technology teams; security; data owners; downstream customers and workers; environment: Developer environment, repositories, cloud AI platform and enterprise integrations. - **RET-UC-031 - Third-party foundation-model API:** Developers and technology teams; security; data owners; downstream customers and workers; environment: Developer environment, repositories, cloud AI platform and enterprise integrations. - **RET-UC-032 - Synthetic retail data generation:** Customers and customer-service staff; product and operations owners; privacy and security functions; environment: Customer-service platform, e-commerce account systems and cloud AI service. ## Threat landscape Retail prevalence and loss magnitude are not inferred from incomplete public reporting [T2-T3]. - **RET-THR-001 - Training-data poisoning:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for training-data poisoning are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-002 - Retrieval poisoning:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for retrieval poisoning are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-003 - Prompt injection:** Likelihood High; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for prompt injection are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-004 - Indirect prompt injection:** Likelihood High; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for indirect prompt injection are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-005 - Model extraction:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for model extraction are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-006 - Membership or data inference:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for membership or data inference are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-007 - API credential theft:** Likelihood High; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for api credential theft are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-008 - Agent tool abuse:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for agent tool abuse are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-009 - Inter-agent trust failure:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for inter-agent trust failure are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-010 - Uncontrolled model update:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for uncontrolled model update are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-011 - Vendor outage or withdrawal:** Likelihood High; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for vendor outage or withdrawal are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-012 - Supplier data reuse:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for supplier data reuse are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-013 - Synthetic identity fraud:** Likelihood Medium; impact High. Public evidence supports the threat class, but retail frequency and loss magnitude for synthetic identity fraud are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-014 - Loyalty-account takeover:** Likelihood High; impact High. Public evidence supports the threat class, but retail frequency and loss magnitude for loyalty-account takeover are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-015 - Promotion and coupon abuse:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for promotion and coupon abuse are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-016 - Returns fraud adaptation:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for returns fraud adaptation are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-017 - Pricing manipulation:** Likelihood Medium; impact High. Public evidence supports the threat class, but retail frequency and loss magnitude for pricing manipulation are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-018 - Inventory forecast manipulation:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for inventory forecast manipulation are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-019 - Recommendation manipulation:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for recommendation manipulation are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-020 - Hallucinated product claims:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for hallucinated product claims are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-021 - Deceptive synthetic reviews:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for deceptive synthetic reviews are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-022 - Biometric false match:** Likelihood Medium; impact High. Public evidence supports the threat class, but retail frequency and loss magnitude for biometric false match are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-023 - Age-estimation error:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for age-estimation error are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-024 - Loss-prevention false positive:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for loss-prevention false positive are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-025 - Discriminatory segmentation:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for discriminatory segmentation are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-026 - Employment decision bias:** Likelihood Medium; impact High. Public evidence supports the threat class, but retail frequency and loss magnitude for employment decision bias are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-027 - Edge-device tampering:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for edge-device tampering are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-028 - Warehouse command manipulation:** Likelihood Medium; impact High. Public evidence supports the threat class, but retail frequency and loss magnitude for warehouse command manipulation are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-029 - Catalogue corruption:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for catalogue corruption are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-030 - Insufficient audit logging:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for insufficient audit logging are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-031 - Model drift:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for model drift are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-032 - Seasonal distribution shift:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for seasonal distribution shift are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-033 - Generated phishing:** Likelihood High; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for generated phishing are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-034 - Deepfake executive or supplier fraud:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for deepfake executive or supplier fraud are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-035 - Sensitive prompt leakage:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for sensitive prompt leakage are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. - **RET-THR-036 - Open-source model compromise:** Likelihood Medium; impact Moderate to High. Public evidence supports the threat class, but retail frequency and loss magnitude for open-source model compromise are not established; validate exposure using the retailer’s architecture, incidents and control telemetry. ## Complete control mapping ### D1-CTL-01 - DATASET PROVENANCE & POISONING PREVENTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Retail training, tuning and evaluation data often arrive from point-of-sale feeds, loyalty platforms, sellers, suppliers and franchise locations. Preserve source lineage, quarantine abnormal submissions and require approval before contaminated catalogue, fraud or demand data can influence a production model. - **Use cases:** RET-UC-001; RET-UC-008; RET-UC-015 - **Threats:** RET-THR-001; RET-THR-006; RET-THR-011 - **Evidence:** RET-EVD-001; RET-EVD-004 ### D1-CTL-02 - MODEL EXTRACTION RESISTANCE - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Recommendation, pricing and fraud APIs can expose commercially valuable decision logic through high-volume queries. Apply rate limits, behavioural detection, response minimisation and contractual controls to make systematic model replication detectable and costly. - **Use cases:** RET-UC-002; RET-UC-009; RET-UC-016; RET-UC-023 - **Threats:** RET-THR-002; RET-THR-007; RET-THR-012; RET-THR-017 - **Evidence:** RET-EVD-002; RET-EVD-005; RET-EVD-008 ### D1-CTL-03 - BEHAVIORAL DRIFT DETECTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Retail behaviour changes sharply during promotions, holidays, product launches and fraud campaigns. Monitor performance by channel, store cohort and affected population so seasonal change is distinguished from security manipulation or silent model degradation. - **Use cases:** RET-UC-003; RET-UC-010; RET-UC-017; RET-UC-024; RET-UC-031 - **Threats:** RET-THR-003; RET-THR-008; RET-THR-013 - **Evidence:** RET-EVD-003; RET-EVD-006; RET-EVD-009; RET-EVD-012 ### D1-CTL-04 - FEDERATED LEARNING POISONING PREVENTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Where stores, franchisees or regional entities train locally, validate and bound each submitted update before aggregation. A compromised edge node must not be able to poison group-wide fraud, forecasting or recommendation behaviour. - **Use cases:** RET-UC-004; RET-UC-011; RET-UC-018 - **Threats:** RET-THR-004; RET-THR-009; RET-THR-014; RET-THR-019 - **Evidence:** RET-EVD-004; RET-EVD-007 ### D1-CTL-05 - EMBEDDING SPACE ROBUSTNESS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Product search, visual search and retrieval systems depend on embedding similarity. Test whether adversarial images, seller text or catalogue attributes can move prohibited, counterfeit or irrelevant items into trusted result neighbourhoods. - **Use cases:** RET-UC-005; RET-UC-012; RET-UC-019; RET-UC-026 - **Threats:** RET-THR-005; RET-THR-010; RET-THR-015 - **Evidence:** RET-EVD-005; RET-EVD-008; RET-EVD-011 ### D1-CTL-06 - POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Long-lived model artefacts, signed releases and warehouse or store-edge devices may outlive current cryptographic assumptions. Maintain crypto-agility and migration plans; do not represent post-quantum readiness as achieved unless the full signing and verification chain has been tested. - **Use cases:** RET-UC-006; RET-UC-013; RET-UC-020; RET-UC-027; RET-UC-002 - **Threats:** RET-THR-006; RET-THR-011; RET-THR-016; RET-THR-021 - **Evidence:** RET-EVD-006; RET-EVD-009; RET-EVD-012; RET-EVD-015 ### D1-CTL-07 - LORA/ADAPTER INTEGRITY VERIFICATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Low-rank adaptation and other adapters may be used to localise models for brands, regions or franchises. Verify adapter origin, hash, approved base-model compatibility and behaviour before loading it into production. - **Use cases:** RET-UC-007; RET-UC-014; RET-UC-021 - **Threats:** RET-THR-007; RET-THR-012; RET-THR-017 - **Evidence:** RET-EVD-007; RET-EVD-010 ### D1-CTL-08 - MODEL MERGE ATTACK DETECTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Retail teams may merge models or checkpoints to combine language, vision or fraud capabilities. Treat every merge as a new artefact requiring provenance, behavioural comparison and backdoor testing rather than inheriting trust from the source models. - **Use cases:** RET-UC-008; RET-UC-015; RET-UC-022; RET-UC-029 - **Threats:** RET-THR-008; RET-THR-013; RET-THR-018; RET-THR-023 - **Evidence:** RET-EVD-008; RET-EVD-011; RET-EVD-014 ### D1-CTL-09 - QUANTIZATION BACKDOOR SCREENING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Quantised models are common on cameras, kiosks and store-edge hardware. Re-test quantised builds because compression can expose or preserve behaviours that were not visible in the full-precision model. - **Use cases:** RET-UC-009; RET-UC-016; RET-UC-023; RET-UC-030; RET-UC-005 - **Threats:** RET-THR-009; RET-THR-014; RET-THR-019 - **Evidence:** RET-EVD-009; RET-EVD-012; RET-EVD-015; RET-EVD-018 ### D2-CTL-01 - DIRECT PROMPT INJECTION PREVENTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Customer-service and shopping assistants must treat customer prompts as untrusted input. Separate instructions from customer content, constrain account actions and prevent a conversational request from bypassing refund, discount or identity controls. - **Use cases:** RET-UC-010; RET-UC-017; RET-UC-024 - **Threats:** RET-THR-010; RET-THR-015; RET-THR-020; RET-THR-025 - **Evidence:** RET-EVD-010; RET-EVD-013 ### D2-CTL-02 - INDIRECT PROMPT INJECTION PREVENTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Retail assistants ingest product pages, reviews, supplier documents and support content. Sanitise retrieved material and isolate tool instructions so hidden text in a listing or document cannot redirect the model or exfiltrate data. - **Use cases:** RET-UC-011; RET-UC-018; RET-UC-025; RET-UC-032 - **Threats:** RET-THR-011; RET-THR-016; RET-THR-021 - **Evidence:** RET-EVD-011; RET-EVD-014; RET-EVD-017 ### D2-CTL-03 - JAILBREAK RESISTANCE TESTING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Test retail assistants against attempts to produce prohibited product advice, reveal policies, create fraudulent discounts or evade age and account controls. Re-test after model, prompt, retrieval or tool changes. - **Use cases:** RET-UC-012; RET-UC-019; RET-UC-026; RET-UC-001; RET-UC-008 - **Threats:** RET-THR-012; RET-THR-017; RET-THR-022; RET-THR-027 - **Evidence:** RET-EVD-012; RET-EVD-015; RET-EVD-018; RET-EVD-021 ### D2-CTL-04 - MULTI-MODAL INJECTION DEFENSE - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Visual-search, receipt, shelf-image and voice systems can carry adversarial instructions outside ordinary text prompts. Validate each modality independently and at the point where modalities are fused. - **Use cases:** RET-UC-013; RET-UC-020; RET-UC-027 - **Threats:** RET-THR-013; RET-THR-018; RET-THR-023 - **Evidence:** RET-EVD-013; RET-EVD-016 ### D2-CTL-05 - FUNCTION CALL/TOOL CALL INJECTION PREVENTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Agents connected to refunds, inventory, customer records or campaigns must validate every function call against user identity, transaction state and approved limits. Model-generated arguments are not trusted authorisation. - **Use cases:** RET-UC-014; RET-UC-021; RET-UC-028; RET-UC-003 - **Threats:** RET-THR-014; RET-THR-019; RET-THR-024; RET-THR-029 - **Evidence:** RET-EVD-014; RET-EVD-017; RET-EVD-020 ### D2-CTL-06 - CROSS-CONTEXT HIJACKING MITIGATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** A retailer may reuse one model across customer, employee, seller and developer contexts. Enforce context separation so content or memory from one tenant, account or workflow cannot influence another. - **Use cases:** RET-UC-015; RET-UC-022; RET-UC-029; RET-UC-004; RET-UC-011 - **Threats:** RET-THR-015; RET-THR-020; RET-THR-025 - **Evidence:** RET-EVD-015; RET-EVD-018; RET-EVD-021; RET-EVD-024 ### D3-CTL-01 - LEAST AGENCY ENFORCEMENT - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Retail agents should receive only the tools and transaction authority required for the current task. A product assistant should not obtain refund, pricing or inventory-write capability merely because those tools exist in the same platform. - **Use cases:** RET-UC-016; RET-UC-023; RET-UC-030 - **Threats:** RET-THR-016; RET-THR-021; RET-THR-026; RET-THR-031 - **Evidence:** RET-EVD-016; RET-EVD-019 ### D3-CTL-02 - INTER-AGENT COMMUNICATION SECURITY - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** When merchandising, inventory, fraud and customer-service agents exchange messages, authenticate the sender, validate message schemas and record delegated authority. Do not allow one agent to create authority for another through natural-language assertions. - **Use cases:** RET-UC-017; RET-UC-024; RET-UC-031; RET-UC-006 - **Threats:** RET-THR-017; RET-THR-022; RET-THR-027 - **Evidence:** RET-EVD-017; RET-EVD-020; RET-EVD-023 ### D3-CTL-03 - AGENTIC PROMPT CHAINING DETECTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Multi-step retail workflows can hide unsafe intent across individually benign prompts. Detect chains that progressively obtain customer data, alter promotions or prepare unauthorised transactions. - **Use cases:** RET-UC-018; RET-UC-025; RET-UC-032; RET-UC-007; RET-UC-014 - **Threats:** RET-THR-018; RET-THR-023; RET-THR-028; RET-THR-033 - **Evidence:** RET-EVD-018; RET-EVD-021; RET-EVD-024; RET-EVD-002 ### D3-CTL-04 - EMBODIED AI SAFETY CONTROLS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Warehouse robots, autonomous stores and AI-enabled handling equipment require bounded operating zones, tested safety interlocks and controlled behaviour when sensors, networks or models fail. - **Use cases:** RET-UC-019; RET-UC-026; RET-UC-001 - **Threats:** RET-THR-019; RET-THR-024; RET-THR-029 - **Evidence:** RET-EVD-019; RET-EVD-022 ### D3-CTL-05 - MULTI-AGENT TRUST CHAIN ATTESTATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** For multi-agent retail operations, preserve an attested chain showing which agent, identity, model version and policy authorised each consequential action. Break the chain when any participant cannot be verified. - **Use cases:** RET-UC-020; RET-UC-027; RET-UC-002; RET-UC-009 - **Threats:** RET-THR-020; RET-THR-025; RET-THR-030; RET-THR-035 - **Evidence:** RET-EVD-020; RET-EVD-023; RET-EVD-001 ### D3-CTL-06 - PERSISTENT MEMORY EXFILTRATION PREVENTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Persistent assistant memory may accumulate customer, employee, seller or source-code information. Prevent retrieval or export of memory outside the originating account and monitor bulk or unusual memory access. - **Use cases:** RET-UC-021; RET-UC-028; RET-UC-003; RET-UC-010; RET-UC-017 - **Threats:** RET-THR-021; RET-THR-026; RET-THR-031 - **Evidence:** RET-EVD-021; RET-EVD-024; RET-EVD-002; RET-EVD-005 ### D3-CTL-07 - SECURE MEMORY LIFECYCLE MANAGEMENT - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Define retention, correction, deletion and re-indexing rules for conversational and agent memory. Account closure, employee departure and model retirement must trigger removal or controlled archival of associated memory. - **Use cases:** RET-UC-022; RET-UC-029; RET-UC-004 - **Threats:** RET-THR-022; RET-THR-027; RET-THR-032; RET-THR-001 - **Evidence:** RET-EVD-022; RET-EVD-025 ### D4-CTL-01 - AI BILL OF MATERIALS (AI BOM) MAINTENANCE - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Maintain an AI bill of materials for each retail service covering models, adapters, datasets, retrieval stores, prompts, agents, tools, libraries, providers and edge deployments. Link changes to release and incident records. - **Use cases:** RET-UC-023; RET-UC-030; RET-UC-005; RET-UC-012 - **Threats:** RET-THR-023; RET-THR-028; RET-THR-033 - **Evidence:** RET-EVD-023; RET-EVD-001; RET-EVD-004 ### D4-CTL-02 - MODEL FILE & ARTIFACT SCANNING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Scan downloaded models, adapters and serialized artefacts before use. Retail data-science teams must treat model files from public hubs, vendors and internal experiments as executable supply-chain content. - **Use cases:** RET-UC-024; RET-UC-031; RET-UC-006; RET-UC-013; RET-UC-020 - **Threats:** RET-THR-024; RET-THR-029; RET-THR-034; RET-THR-003 - **Evidence:** RET-EVD-024; RET-EVD-002; RET-EVD-005; RET-EVD-008 ### D4-CTL-03 - MODEL HUB & REGISTRY VETTING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Approve model hubs and registries based on provenance, moderation, vulnerability response and licence controls. Prevent unreviewed models from moving directly from an analyst notebook into a customer or store workflow. - **Use cases:** RET-UC-025; RET-UC-032; RET-UC-007 - **Threats:** RET-THR-025; RET-THR-030; RET-THR-035 - **Evidence:** RET-EVD-025; RET-EVD-003 ### D4-CTL-04 - MCP SERVER BEHAVIORAL MONITORING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Model Context Protocol servers can expose inventory, customer relationship management and order systems to agents. Monitor server discovery, tool enumeration, read/write patterns and unexpected access to high-value retail data. - **Use cases:** RET-UC-026; RET-UC-001; RET-UC-008; RET-UC-015 - **Threats:** RET-THR-026; RET-THR-031; RET-THR-036; RET-THR-005 - **Evidence:** RET-EVD-001; RET-EVD-004; RET-EVD-007 ### D4-CTL-05 - THIRD-PARTY AI API SECURITY ASSESSMENT - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Assess external AI application programming interfaces for authentication, tenant isolation, data retention, training use, regional processing, model-change notice, rate limits and incident support before sending customer or commercial data. - **Use cases:** RET-UC-027; RET-UC-002; RET-UC-009; RET-UC-016; RET-UC-023 - **Threats:** RET-THR-027; RET-THR-032; RET-THR-001 - **Evidence:** RET-EVD-002; RET-EVD-005; RET-EVD-008; RET-EVD-011 ### D4-CTL-06 - SHADOW AI DISCOVERY & GOVERNANCE - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Shadow AI commonly appears in marketing, buying, store and franchise teams using consumer tools for copy, images or analysis. Discover unsanctioned use through procurement, network, browser and data-loss signals, then provide an approved alternative and enforce data boundaries. - **Use cases:** RET-UC-028; RET-UC-003; RET-UC-010 - **Threats:** RET-THR-028; RET-THR-033; RET-THR-002; RET-THR-007 - **Evidence:** RET-EVD-003; RET-EVD-006 ### D4-CTL-07 - AI SOFTWARE COMPOSITION ANALYSIS (SCA) - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Software Composition Analysis for retail AI must include orchestration frameworks, vector databases, model loaders, plugins, computer-vision packages and agent tools, not only the conventional web application dependencies. - **Use cases:** RET-UC-029; RET-UC-004; RET-UC-011; RET-UC-018 - **Threats:** RET-THR-029; RET-THR-034; RET-THR-003 - **Evidence:** RET-EVD-004; RET-EVD-007; RET-EVD-010 ### D5-CTL-01 - HARMFUL CONTENT BLOCKING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Block outputs that facilitate fraud, unsafe product use, harassment, prohibited goods or harmful employee/customer interactions. Calibrate controls to the channel and provide escalation instead of silently failing consequential requests. - **Use cases:** RET-UC-030; RET-UC-005; RET-UC-012; RET-UC-019; RET-UC-026 - **Threats:** RET-THR-030; RET-THR-035; RET-THR-004; RET-THR-009 - **Evidence:** RET-EVD-005; RET-EVD-008; RET-EVD-011; RET-EVD-014 ### D5-CTL-02 - PII LEAKAGE PREVENTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Prevent customer, payment, loyalty, employee and supplier identifiers from appearing in prompts, retrieved context or outputs beyond the approved transaction. Test redaction and access boundaries with realistic retail records. - **Use cases:** RET-UC-031; RET-UC-006; RET-UC-013 - **Threats:** RET-THR-031; RET-THR-036; RET-THR-005 - **Evidence:** RET-EVD-006; RET-EVD-009 ### D5-CTL-03 - COPYRIGHT DETECTION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Product descriptions, advertising and generated imagery may reproduce protected material. Record source rights, detect suspicious similarity and route uncertain content for review before publication. - **Use cases:** RET-UC-032; RET-UC-007; RET-UC-014; RET-UC-021 - **Threats:** RET-THR-032; RET-THR-001; RET-THR-006; RET-THR-011 - **Evidence:** RET-EVD-007; RET-EVD-010; RET-EVD-013 ### D5-CTL-04 - AI WATERMARKING ROBUSTNESS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Where watermarks or provenance markers are used for retail media, test whether resizing, cropping, recompression and marketplace reposting remove them. Do not treat watermark presence as proof that content is authentic. - **Use cases:** RET-UC-001; RET-UC-008; RET-UC-015; RET-UC-022; RET-UC-029 - **Threats:** RET-THR-033; RET-THR-002; RET-THR-007 - **Evidence:** RET-EVD-008; RET-EVD-011; RET-EVD-014; RET-EVD-017 ### D5-CTL-05 - PRIVACY-BY-DESIGN VERIFICATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Verify privacy controls at design and release gates for loyalty profiling, retail media, biometrics, employee monitoring and conversational systems. Data minimisation and purpose boundaries must be visible in architecture and operating evidence. - **Use cases:** RET-UC-002; RET-UC-009; RET-UC-016 - **Threats:** RET-THR-034; RET-THR-003; RET-THR-008; RET-THR-013 - **Evidence:** RET-EVD-009; RET-EVD-012 ### D5-CTL-06 - PRIVACY-PRESERVING ML VALIDATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Where federated learning, differential privacy, synthetic data or secure computation is claimed, test the privacy parameters and residual leakage against the retail use case. A technique label alone is not evidence of effective protection. - **Use cases:** RET-UC-003; RET-UC-010; RET-UC-017; RET-UC-024 - **Threats:** RET-THR-035; RET-THR-004; RET-THR-009 - **Evidence:** RET-EVD-010; RET-EVD-013; RET-EVD-016 ### D6-CTL-01 - HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Require authorised human review before consequential actions such as account suspension, return denial, biometric intervention, hiring rejection, high-value refund or unsafe warehouse movement. Reviewers need the evidence and authority to reverse the model outcome. - **Use cases:** RET-UC-004; RET-UC-011; RET-UC-018; RET-UC-025; RET-UC-032 - **Threats:** RET-THR-036; RET-THR-005; RET-THR-010; RET-THR-015 - **Evidence:** RET-EVD-011; RET-EVD-014; RET-EVD-017; RET-EVD-020 ### D6-CTL-02 - AUDIT TRAIL COMPLETENESS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Logs must reconstruct the customer or operational journey: identity, input, retrieved data, model and prompt version, output, tool call, override and final action. Logging only the final response is insufficient for disputes or incidents. - **Use cases:** RET-UC-005; RET-UC-012; RET-UC-019 - **Threats:** RET-THR-001; RET-THR-006; RET-THR-011 - **Evidence:** RET-EVD-012; RET-EVD-015 ### D6-CTL-03 - AI MODEL CARD COMPLETENESS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Retail model cards should state channel, population, data origin, decision authority, known failure modes, seasonal limits, supplier dependencies and prohibited uses. Generic vendor documentation does not replace a retailer-specific deployment record. - **Use cases:** RET-UC-006; RET-UC-013; RET-UC-020; RET-UC-027 - **Threats:** RET-THR-002; RET-THR-007; RET-THR-012; RET-THR-017 - **Evidence:** RET-EVD-013; RET-EVD-016; RET-EVD-019 ### D6-CTL-04 - AI INCIDENT RESPONSE READINESS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** AI incident plans should cover misleading product content, pricing errors, fraud-control failure, biometric misidentification, agent misuse, model compromise and provider outages. Preserve model and prompt versions before rollback. - **Use cases:** RET-UC-007; RET-UC-014; RET-UC-021; RET-UC-028; RET-UC-003 - **Threats:** RET-THR-003; RET-THR-008; RET-THR-013 - **Evidence:** RET-EVD-014; RET-EVD-017; RET-EVD-020; RET-EVD-023 ### D6-CTL-05 - MODEL DEPRECATION & DECOMMISSIONING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** When retiring a model, remove endpoints, credentials, cached artefacts and dependent agent routes; archive required evidence; migrate open cases; and verify that stores or franchisees are not still using the superseded version. - **Use cases:** RET-UC-008; RET-UC-015; RET-UC-022 - **Threats:** RET-THR-004; RET-THR-009; RET-THR-014; RET-THR-019 - **Evidence:** RET-EVD-015; RET-EVD-018 ### D6-CTL-06 - THIRD-PARTY AI VENDOR GOVERNANCE - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Retail contracts should secure evidence access, data-use limits, change notice, incident cooperation, subcontractor transparency, continuity and exit support. Procurement approval without enforceable operating rights leaves a control gap. - **Use cases:** RET-UC-009; RET-UC-016; RET-UC-023; RET-UC-030 - **Threats:** RET-THR-005; RET-THR-010; RET-THR-015 - **Evidence:** RET-EVD-016; RET-EVD-019; RET-EVD-022 ### D6-CTL-07 - AI RESILIENCE & BUSINESS CONTINUITY - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P1 - Start first - **Retail interpretation [T3]:** Define degraded modes for payment risk, inventory, checkout, customer service and physical operations. Test manual or rules-based fallback under peak demand rather than assuming the provider will remain available. - **Use cases:** RET-UC-010; RET-UC-017; RET-UC-024; RET-UC-031; RET-UC-006 - **Threats:** RET-THR-006; RET-THR-011; RET-THR-016; RET-THR-021 - **Evidence:** RET-EVD-017; RET-EVD-020; RET-EVD-023; RET-EVD-001 ### D7-CTL-H01 - AI-GENERATED PHISHING SIMULATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Simulate AI-generated phishing against store, finance, buying and supplier-management staff using realistic seasonal and invoice themes. Measure reporting and verification behaviour, not just click rates. - **Use cases:** RET-UC-011; RET-UC-018; RET-UC-025 - **Threats:** RET-THR-007; RET-THR-012; RET-THR-017 - **Evidence:** RET-EVD-018; RET-EVD-021 ### D7-CTL-H02 - DEEPFAKE DETECTION TRAINING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Train staff who approve payments, supplier changes or executive instructions to recognise deepfake voice and video indicators and to use an independent verification channel. - **Use cases:** RET-UC-012; RET-UC-019; RET-UC-026; RET-UC-001 - **Threats:** RET-THR-008; RET-THR-013; RET-THR-018; RET-THR-023 - **Evidence:** RET-EVD-019; RET-EVD-022; RET-EVD-025 ### D7-CTL-H03 - OUT-OF-BAND AUTHENTICATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Changes to bank details, high-value refunds, privileged access and emergency supplier requests should be confirmed through a pre-registered channel independent of the initiating message or call. - **Use cases:** RET-UC-013; RET-UC-020; RET-UC-027; RET-UC-002; RET-UC-009 - **Threats:** RET-THR-009; RET-THR-014; RET-THR-019 - **Evidence:** RET-EVD-020; RET-EVD-023; RET-EVD-001; RET-EVD-004 ### D7-CTL-H04 - AI SOCIAL ENGINEERING IR - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Incident procedures must recognise AI-assisted impersonation, synthetic documents and coordinated social engineering. Preserve media and communications while validating the claimed identity through trusted records. - **Use cases:** RET-UC-014; RET-UC-021; RET-UC-028 - **Threats:** RET-THR-010; RET-THR-015; RET-THR-020; RET-THR-025 - **Evidence:** RET-EVD-021; RET-EVD-024 ### D7-CTL-H05 - AI-ENHANCED EXTERNAL ATTACK DEFENSE - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Tune email, identity, endpoint and fraud defences for AI-scaled reconnaissance, credential attacks and content variation. Retail peak periods require heightened monitoring because staffing and transaction volume reduce review time. - **Use cases:** RET-UC-015; RET-UC-022; RET-UC-029; RET-UC-004 - **Threats:** RET-THR-011; RET-THR-016; RET-THR-021 - **Evidence:** RET-EVD-022; RET-EVD-025; RET-EVD-003 ### D8-CTL-01 - EU AI ACT RISK TIER MAPPING - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Map each retail AI use case to the European Union Artificial Intelligence Act role and risk analysis where the regulation applies. Do not classify an entire retailer once; assess hiring, biometrics, customer and operational systems separately. - **Use cases:** RET-UC-016; RET-UC-023; RET-UC-030; RET-UC-005; RET-UC-012 - **Threats:** RET-THR-012; RET-THR-017; RET-THR-022; RET-THR-027 - **Evidence:** RET-EVD-023; RET-EVD-001; RET-EVD-004; RET-EVD-007 ### D8-CTL-02 - ISO 42001 GAP ANALYSIS - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Use an International Organization for Standardization/International Electrotechnical Commission 42001 gap analysis to compare management-system practices, but preserve GAISSF control-level evidence and do not claim equivalence between the instruments. - **Use cases:** RET-UC-017; RET-UC-024; RET-UC-031 - **Threats:** RET-THR-013; RET-THR-018; RET-THR-023 - **Evidence:** RET-EVD-024; RET-EVD-002 ### D8-CTL-03 - GPAI TECHNICAL DOCUMENTATION VERIFICATION - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Where a general-purpose AI provider is in scope, verify that the technical documentation available to the retailer is sufficient for integration, risk assessment, monitoring and downstream instructions. Record unavailable evidence as a supplier limitation. - **Use cases:** RET-UC-018; RET-UC-025; RET-UC-032; RET-UC-007 - **Threats:** RET-THR-014; RET-THR-019; RET-THR-024; RET-THR-029 - **Evidence:** RET-EVD-025; RET-EVD-003; RET-EVD-006 ### D8-CTL-04 - DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR) - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Digital Operational Resilience Act incident reporting is relevant only where the retail entity or service falls within its financial-sector scope. Record the applicability decision instead of presenting the control as universally required for retail. - **Use cases:** RET-UC-019; RET-UC-026; RET-UC-001; RET-UC-008; RET-UC-015 - **Threats:** RET-THR-015; RET-THR-020; RET-THR-025 - **Evidence:** RET-EVD-001; RET-EVD-004; RET-EVD-007; RET-EVD-010 ### D8-CTL-05 - NIST SP 800-218A COMPLIANCE CHECK - **Scope:** Foundational - canonical D1-D8 scope - **Priority:** P2 - Risk-triggered / capability-specific - **Retail interpretation [T3]:** Apply National Institute of Standards and Technology Special Publication 800-218A practices to AI model and software development where relevant, including provenance, secure build, testing and release evidence. Document gaps for acquired services that the retailer cannot inspect. - **Use cases:** RET-UC-020; RET-UC-027; RET-UC-002 - **Threats:** RET-THR-016; RET-THR-021; RET-THR-026; RET-THR-031 - **Evidence:** RET-EVD-002; RET-EVD-005 ### D9-CTL-01 - PHYSICAL HARM BOUNDARY ENFORCEMENT - **Scope:** Conditional - physical AI in scope - **Priority:** P3 - Conditional physical AI - **Retail interpretation [T3]:** Set explicit physical limits for warehouse robots, automated handling, smart carts and autonomous store systems. Software optimisation must not permit speed, force, route or proximity beyond the approved safety boundary. - **Use cases:** RET-UC-021; RET-UC-028; RET-UC-003; RET-UC-010 - **Threats:** RET-THR-017; RET-THR-022; RET-THR-027 - **Evidence:** RET-EVD-003; RET-EVD-006; RET-EVD-009 ### D9-CTL-02 - SAFE STATE AND GRACEFUL DEGRADATION - **Scope:** Conditional - physical AI in scope - **Priority:** P3 - Conditional physical AI - **Retail interpretation [T3]:** On model, sensor, network or cloud failure, physical retail systems must enter a defined safe or controlled state without depending on continued model inference. Test degraded operation during realistic store and warehouse conditions. - **Use cases:** RET-UC-022; RET-UC-029; RET-UC-004; RET-UC-011; RET-UC-018 - **Threats:** RET-THR-018; RET-THR-023; RET-THR-028; RET-THR-033 - **Evidence:** RET-EVD-004; RET-EVD-007; RET-EVD-010; RET-EVD-013 ### D9-CTL-03 - HUMAN OVERRIDE AND EMERGENCY STOP - **Scope:** Conditional - physical AI in scope - **Priority:** P3 - Conditional physical AI - **Retail interpretation [T3]:** Warehouse robotics and autonomous store systems require accessible local emergency stops and authorised human override. Remote vendor commands or software updates must not disable the emergency function. - **Use cases:** RET-UC-023; RET-UC-030; RET-UC-005 - **Threats:** RET-THR-019; RET-THR-024; RET-THR-029 - **Evidence:** RET-EVD-005; RET-EVD-008 ### D9-CTL-04 - CYBER-PHYSICAL ATTACK DETECTION - **Scope:** Conditional - physical AI in scope - **Priority:** P3 - Conditional physical AI - **Retail interpretation [T3]:** Correlate cyber indicators with physical anomalies such as unexpected routes, repeated sensor disagreement, command bursts or safety-zone violations. Cyber monitoring alone may miss an emerging physical incident. - **Use cases:** RET-UC-024; RET-UC-031; RET-UC-006; RET-UC-013 - **Threats:** RET-THR-020; RET-THR-025; RET-THR-030; RET-THR-035 - **Evidence:** RET-EVD-006; RET-EVD-009; RET-EVD-012 ### D9-CTL-05 - PHYSICAL ENVIRONMENT INTEGRITY MONITORING - **Scope:** Conditional - physical AI in scope - **Priority:** P3 - Conditional physical AI - **Retail interpretation [T3]:** Monitor camera position, sensor obstruction, lighting, floor layout, shelf movement and other environmental changes that can invalidate a physical AI system’s assumptions. - **Use cases:** RET-UC-025; RET-UC-032; RET-UC-007; RET-UC-014; RET-UC-021 - **Threats:** RET-THR-021; RET-THR-026; RET-THR-031 - **Evidence:** RET-EVD-007; RET-EVD-010; RET-EVD-013; RET-EVD-016 ### D9-CTL-06 - ACTUATOR COMMAND VERIFICATION - **Scope:** Conditional - physical AI in scope - **Priority:** P3 - Conditional physical AI - **Retail interpretation [T3]:** Validate actuator commands against identity, authorised workflow, current sensor state and physical limits before execution. Reject stale, duplicated or out-of-sequence commands. - **Use cases:** RET-UC-026; RET-UC-001; RET-UC-008 - **Threats:** RET-THR-022; RET-THR-027; RET-THR-032; RET-THR-001 - **Evidence:** RET-EVD-008; RET-EVD-011 ### D9-CTL-07 - PHYSICAL INCIDENT EVIDENCE PRESERVATION - **Scope:** Conditional - physical AI in scope - **Priority:** P3 - Conditional physical AI - **Retail interpretation [T3]:** For physical incidents, preserve commands, sensor streams, model version, safety interlock state, operator actions and relevant video with synchronized time. Ordinary application logs are not sufficient for reconstruction. - **Use cases:** RET-UC-027; RET-UC-002; RET-UC-009; RET-UC-016 - **Threats:** RET-THR-023; RET-THR-028; RET-THR-033 - **Evidence:** RET-EVD-009; RET-EVD-012; RET-EVD-015 ## Worked scenarios ### RET-SCN-001 - E-commerce recommendation manipulation - Detection: Detect abnormal seller/bot engagement, ranking shifts and conversion patterns; compare against clean holdout queries. - Immediate action: Freeze suspicious ranking signals, remove manipulated inputs, revert the ranking model and review affected seller decisions. - Containment: Freeze suspicious ranking signals, remove manipulated inputs, revert the ranking model and review affected seller decisions. - Lesson: Ranking integrity requires adversarial engagement monitoring, not only offline relevance testing. ### RET-SCN-002 - Loyalty takeover with AI-assisted fraud - Detection: Correlate impossible travel, device change, reward redemption and AI-generated support interactions. - Immediate action: Lock redemption, preserve account/session evidence, step up identity verification and reverse unauthorised reward transfers. - Containment: Lock redemption, preserve account/session evidence, step up identity verification and reverse unauthorised reward transfers. - Lesson: Loyalty value should be protected with payment-grade identity and recovery controls. ### RET-SCN-003 - Hallucinated product information - Detection: Sample generated specifications against authoritative supplier data and monitor corrections, returns and complaints. - Immediate action: Unpublish affected content, revert to approved catalogue text, notify owners and correct customers where reliance may have occurred. - Containment: Unpublish affected content, revert to approved catalogue text, notify owners and correct customers where reliance may have occurred. - Lesson: Generated retail content needs authoritative attribute validation before publication. ### RET-SCN-004 - Promotion-engine abuse - Detection: Detect unusual coupon combinations, account clusters, rapid redemptions and margin anomalies. - Immediate action: Disable the promotion rule, block abusive sessions, preserve transaction evidence and reissue corrected terms where needed. - Containment: Disable the promotion rule, block abusive sessions, preserve transaction evidence and reissue corrected terms where needed. - Lesson: Promotion optimisation and promotion enforcement must be separated and independently tested. ### RET-SCN-005 - Self-checkout vision failure - Detection: Monitor mismatch between vision events, scanned items, weight sensors, payment events and staff overrides. - Immediate action: Place lanes in assisted mode, isolate the failing model/device and preserve video and sensor logs before recalibration. - Containment: Place lanes in assisted mode, isolate the failing model/device and preserve video and sensor logs before recalibration. - Lesson: Store vision controls need tested human fallback during peak operations. ### RET-SCN-006 - Facial-recognition false match - Detection: Track match confidence, demographic/environmental performance and intervention outcomes; investigate complaints immediately. - Immediate action: Stop automated matching, prevent enforcement action, preserve evidence and route the event to authorised manual review. - Containment: Stop automated matching, prevent enforcement action, preserve evidence and route the event to authorised manual review. - Lesson: A biometric alert is an investigative signal, not proof of identity. ### RET-SCN-007 - Returns model false positive - Detection: Analyse appeal reversals, customer complaints, cohort disparities and sudden threshold changes. - Immediate action: Pause automated denial, permit manual returns review, restore wrongly affected accounts and recalibrate only after impact analysis. - Containment: Pause automated denial, permit manual returns review, restore wrongly affected accounts and recalibrate only after impact analysis. - Lesson: Fraud loss reduction does not justify unreviewable customer decisions. ### RET-SCN-008 - Inventory forecast poisoning - Detection: Compare supplier/store submissions, forecast residuals and peer-location updates for abnormal influence. - Immediate action: Quarantine suspect data or model updates, rerun the forecast from a trusted baseline and review resulting orders. - Containment: Quarantine suspect data or model updates, rerun the forecast from a trusted baseline and review resulting orders. - Lesson: Forecast provenance must cover local and supplier-originated updates. ### RET-SCN-009 - Third-party chatbot data leakage - Detection: Use data-loss alerts, prompt/output sampling and provider logs to identify sensitive fields leaving the approved boundary. - Immediate action: Disable the integration, revoke credentials, request provider preservation/deletion evidence and assess affected customers. - Containment: Disable the integration, revoke credentials, request provider preservation/deletion evidence and assess affected customers. - Lesson: Chatbot privacy depends on upstream retrieval and provider data-use controls. ### RET-SCN-010 - AI-generated phishing against staff - Detection: Correlate email telemetry, identity anomalies, supplier-change requests and employee reporting. - Immediate action: Block the campaign, reset affected credentials, suspend requested payment changes and verify identities out of band. - Containment: Block the campaign, reset affected credentials, suspend requested payment changes and verify identities out of band. - Lesson: AI-scaled variation makes process verification more durable than content-only detection. ### RET-SCN-011 - Warehouse-agent malfunction - Detection: Detect route deviation, command anomalies, sensor disagreement and safety-zone violations. - Immediate action: Trigger the local emergency stop, isolate the robotic cell, prevent remote restart and verify the physical area before recovery. - Containment: Trigger the local emergency stop, isolate the robotic cell, prevent remote restart and verify the physical area before recovery. - Lesson: Physical containment must remain available when cloud control and inference are unavailable. ### RET-SCN-012 - Retail-media targeting misuse - Detection: Audit audience construction, sensitive proxies, advertiser queries and complaint patterns. - Immediate action: Suspend the audience/campaign, prevent further data export, preserve targeting logic and conduct privacy and consumer-impact review. - Containment: Suspend the audience/campaign, prevent further data export, preserve targeting logic and conduct privacy and consumer-impact review. - Lesson: Retail media governance must cover inference and advertiser use, not only raw data access. ### RET-SCN-013 - Franchise deployment without approval - Detection: Reconcile network, expense, browser and data-access signals against the approved AI inventory across franchise locations. - Immediate action: Block data access to the unapproved service, preserve usage records and require franchise remediation through contractual governance. - Containment: Block data access to the unapproved service, preserve usage records and require franchise remediation through contractual governance. - Lesson: Corporate policy alone does not control independent franchise technology without enforceable operational levers. ### RET-SCN-014 - Dynamic-pricing governance failure - Detection: Monitor unexplained price dispersion, rapid changes, protected/proxy cohorts, complaints and competitor-input anomalies. - Immediate action: Freeze automated repricing, restore the last approved price rules, preserve inputs and provide correction/escalation for affected customers. - Containment: Freeze automated repricing, restore the last approved price rules, preserve inputs and provide correction/escalation for affected customers. - Lesson: Pricing systems require explicit authority, explainability and rollback limits. ## Notably Absent - No proprietary retail telemetry or complete sector incident denominator. - No automatic legal, payment, biometric, employment, accessibility, consumer-protection or certification conclusion. - Specialist review gates remain open.