# SEC-049 — GAISSF Pharmaceutical Sector Implementation Guide **Version:** 1.1 **Status:** Controlled pre-release **Classification:** Informative sector implementation guidance **Publisher:** ODA3 Institute **Authoritative control source:** GAISSF-NOR-004 v1.0, corrected final publication edition **Publication channel:** Website / GitHub Copyright © 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. Use is governed by the licence and legal notices accompanying the official GAISSF release package. ## Document Control | Field | Value | | --- | --- | | Document ID | SEC-049 | | Version | 1.1 | | Status | Controlled pre-release | | Owner | ODA3 Institute | | Control baseline | 59 controls across nine domains | | Primary audience | CISOs, security architects, AI governance, quality, validation, clinical, safety, regulatory and assurance leaders | | Publication date | Not assigned | | Review cycle | At least annually and after material GAISSF, regulatory, incident or technology change | ## Legal and Use Disclaimer This guide is an implementation aid. It does not amend GAISSF, provide legal or regulatory advice, determine GxP applicability, establish validation adequacy, confer certification, or guarantee security, safety, product quality, clinical integrity, regulatory compliance or absence of harm. External requirements must be verified for the applicable product, process, jurisdiction and effective date. ## Executive Summary Pharmaceutical AI security is not a standalone cyber-control problem. It intersects with patient safety, product quality, clinical integrity, pharmacovigilance, data integrity, validated-state maintenance, regulated records and supplier dependence. SEC-049 translates each authoritative GAISSF control into sector implementation considerations while preserving the boundary between the normative requirement and informative guidance. The recommended operating model begins with an AI system inventory, intended-use and GxP determination, criticality classification, accountable ownership and explicit authority boundaries. Higher-criticality uses require proportionately stronger validation or assurance, source and output traceability, qualified human review, change control, monitoring, incident/deviation/CAPA integration and supplier evidence. ## 1. Purpose, Scope and Audience The guide applies to AI used across discovery, preclinical development, clinical trials, pharmacovigilance, regulatory operations, quality systems, manufacturing, laboratories, supply chain, medical information and supporting enterprise platforms. It distinguishes research from production, GxP from non-GxP, decision support from autonomous execution, and internally developed from externally supplied models. ## 2. Relationship to GAISSF GAISSF-NOR-004 remains the authoritative control catalogue. The 59 identifiers and titles below are preserved. Pharmaceutical interpretations, examples, mappings, evidence suggestions and maturity statements are informative and do not create new conformance obligations. ## 3. How to Use This Guide Use SEC-049 with the workbook as a controlled implementation record: inventory each system; determine intended use and GxP/regulated-record impact; assign criticality; select applicable controls; document inherited and supplier controls; collect design, implementation, operating and effectiveness evidence; record limitations; and route unresolved material risk to the accountable governance body. Illustrative evidence is a starting point, not a mandatory checklist. Tailor artifact names, depth and retention to the system, intended use, criticality and the organisation's existing quality management system. Use the workbook's `AI System Inventory`, `GxP Applicability`, `Criticality Assessment`, `Control Implementation` and `Evidence Register` sheets as the controlled record. ## 4. Pharmaceutical AI Criticality Model | Tier | Name | Entry criteria | Minimum governance | | --- | --- | --- | --- | | Tier 1 | Administrative or low-impact support | No direct GxP decision or regulated-record effect; reversible; qualified review available. | Inventory, approved use, data handling, access, basic testing, supplier terms and periodic review. | | Tier 2 | Controlled operational support | Operational dependency or sensitive data, but limited direct patient/product/regulated-decision impact. | Documented risk assessment, monitoring, change control, fallback and supplier assurance. | | Tier 3 | GxP-significant or regulated decision support | Supports regulated records, clinical conduct, safety, quality or submission evidence; human decision remains accountable. | Validation/assurance plan, traceability, qualified review, robust audit trail, periodic review, incident/deviation integration. | | Tier 4 | Safety-critical, quality-critical or high-autonomy regulated use | Failure can materially affect patient safety, product quality, critical clinical/safety decisions, or executes high-consequence actions. | Independent approval, rigorous assurance, hard authority limits, continuous monitoring, tested fallback/override, enhanced supplier and incident controls. | The model is informative and is not regulator-approved. Organizations should calibrate scoring thresholds and approval authority to product, process, jurisdiction and quality-system requirements. ### Criticality decision safeguard The workbook score is an **indicative screening aid**, not an automated ruling. Unassessed factors must remain blank or Undetermined rather than defaulting to the lowest score. GxP significance, direct regulated-record impact, material patient or product risk, or high-consequence autonomous action may require qualitative escalation regardless of the numeric total. The approved tier requires a named approver and documented rationale. ## 5. Use-Case Catalogue | ID | Use case | Owner | Indicative criticality | | --- | --- | --- | --- | | PHAR-UC-001 | Generative AI for regulatory-document drafting | Regulatory Affairs | GxP-significant | | PHAR-UC-002 | AI-assisted medical writing | Medical Affairs | Controlled operational | | PHAR-UC-003 | Clinical protocol generation | Clinical Development | GxP-significant | | PHAR-UC-004 | Participant recruitment and eligibility screening | Clinical Operations | Safety-significant | | PHAR-UC-005 | Clinical-site selection | Clinical Operations | Controlled operational | | PHAR-UC-006 | Clinical-data anomaly detection | Clinical Data Management | GxP-significant | | PHAR-UC-007 | Synthetic control arms | Biostatistics | Safety-significant | | PHAR-UC-008 | Medical image analysis in trials | Clinical Development | Safety-significant | | PHAR-UC-009 | Adverse-event intake automation | Pharmacovigilance | Safety-significant | | PHAR-UC-010 | Adverse-event coding assistance | Pharmacovigilance | GxP-significant | | PHAR-UC-011 | Pharmacovigilance case prioritisation | Pharmacovigilance | Safety-critical | | PHAR-UC-012 | Safety signal detection | Pharmacovigilance | Safety-critical | | PHAR-UC-013 | Literature surveillance | Pharmacovigilance | GxP-significant | | PHAR-UC-014 | Benefit-risk analysis support | Safety Governance | Safety-critical | | PHAR-UC-015 | Target identification | Discovery Research | Research | | PHAR-UC-016 | Molecular generation | Discovery Research | Research | | PHAR-UC-017 | Compound screening | Discovery Research | Research | | PHAR-UC-018 | Toxicology prediction | Preclinical Safety | Safety-significant | | PHAR-UC-019 | Formulation optimisation | Pharmaceutical Development | GxP-significant | | PHAR-UC-020 | Manufacturing process optimisation | Manufacturing Science | Quality-critical | | PHAR-UC-021 | Batch record review | Quality Assurance | Quality-critical | | PHAR-UC-022 | Predictive maintenance | Engineering | Controlled operational | | PHAR-UC-023 | Automated visual inspection | Quality Control | Quality-critical | | PHAR-UC-024 | Environmental monitoring analytics | Microbiology / Quality | Quality-critical | | PHAR-UC-025 | Laboratory result interpretation | Quality Control | Quality-critical | | PHAR-UC-026 | Deviation investigation support | Quality Assurance | GxP-significant | | PHAR-UC-027 | CAPA recommendation support | Quality Assurance | GxP-significant | | PHAR-UC-028 | Quality complaint triage | Product Quality | Safety-significant | | PHAR-UC-029 | Supply forecasting | Supply Chain | Controlled operational | | PHAR-UC-030 | Cold-chain anomaly detection | Supply Chain Quality | Quality-critical | | PHAR-UC-031 | Counterfeit detection | Product Security | Safety-significant | | PHAR-UC-032 | Serialization analytics | Supply Chain / Compliance | GxP-significant | | PHAR-UC-033 | Controlled-document knowledge retrieval | Quality Systems | GxP-significant | | PHAR-UC-034 | Employee training assistant | Learning and Development | Controlled operational | | PHAR-UC-035 | Inspection-readiness support | Quality Assurance | GxP-significant | | PHAR-UC-036 | Regulatory intelligence | Regulatory Affairs | Controlled operational | | PHAR-UC-037 | Product-label content support | Regulatory Affairs | Safety-significant | | PHAR-UC-038 | Medical-information chat system | Medical Information | Safety-significant | | PHAR-UC-039 | Patient-facing support tool | Patient Services | Safety-significant | | PHAR-UC-040 | Third-party foundation-model integration | Enterprise Technology | Variable | ## 6. Pharmaceutical Threat Landscape The threat register includes malicious, accidental, supplier, model, data and process failure modes. A listed scenario is not evidence that it has occurred. Frequency and loss estimates are intentionally omitted where reliable public data is unavailable. Review the threat model after a new use case, model/provider change, new tool authority, material architecture change, physical/OT connection, confirmed vulnerability or incident, regulatory change, drift/control failure or new supplier dependency. | ID | Scenario | Potential patient/product consequence | Detectability | Evidence status | | --- | --- | --- | --- | --- | | PHAR-THR-001 | Manipulation of drug-discovery training data | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-002 | Poisoning of experimental datasets | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-003 | Compromise of proprietary molecular data | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-004 | Theft of clinical-trial information | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-005 | Participant re-identification | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-006 | Manipulation of eligibility-screening logic | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-007 | Protocol-generation errors | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-008 | Fabrication of scientific references | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-009 | Inaccurate regulatory content generation | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-010 | Unauthorised modification of controlled documents | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-011 | Unreviewed model output inserted into regulated records | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-012 | Pharmacovigilance case suppression | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-013 | Adverse-event misclassification | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-014 | Delayed safety-signal detection | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-015 | False safety signals | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-016 | Hallucinated medical information | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-017 | Batch-release decision corruption | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-018 | Manufacturing parameter manipulation | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-019 | Laboratory-result alteration | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-020 | Visual-inspection evasion | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-021 | Model drift affecting quality decisions | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-022 | Unapproved model updates | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-023 | Loss of validated state | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-024 | Insufficient audit trails | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-025 | Weak electronic-signature attribution | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-026 | Training-serving skew | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-027 | Prompt injection through controlled or supplier documents | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-028 | Retrieval corpus poisoning | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-029 | Malicious content embedded in scientific literature | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-030 | Third-party model compromise | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-031 | Cloud-service concentration failure | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-032 | Model extraction | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-033 | Sensitive-data leakage | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-034 | Insecure agentic actions | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-035 | Excessive system permissions | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-036 | Unauthorised tool use | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-037 | Supplier software-update compromise | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-038 | Counterfeit-classification evasion | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-039 | Cold-chain anomaly concealment | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-040 | Business-continuity failure caused by AI dependency | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-041 | Integrity failure in CAPA or deviation analysis | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-042 | Automation bias | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-043 | Underqualified human review | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-044 | Inadequate segregation of duties | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-045 | Incomplete traceability | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-046 | Insufficient reproducibility | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-047 | Inability to reconstruct model-supported decisions | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-048 | Jurisdictionally incompatible data processing | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-049 | Unauthorised cross-border data exposure | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | | PHAR-THR-050 | Intellectual-property contamination from external models | Context-dependent; potentially material where the use case influences safety surveillance, clinical conduct, product quality or patient communication. Context-dependent; potentially material for manufacturing, laboratory, batch, complaint, cold-chain and quality-system uses. | Variable; define indicators and tested detection coverage. | Threat-model entry; not evidence that the event has occurred. | Detailed failure paths, controls and response fields are maintained in the workbook and JSON register. ## 7. Control-by-Control Pharmaceutical Implementation Guidance ### D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Hash verification + source allowlist + poisoning detection. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-02 — MODEL EXTRACTION RESISTANCE | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Rate limiting + diversity detection + extraction monitoring. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-03 — BEHAVIORAL DRIFT DETECTION | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Baseline profiling + KL divergence monitoring + accuracy tracking. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Gradient anomaly detection + robust aggregation. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Adversarial training + certified robustness measurement. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM). | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Adapter scanning + provenance verification + registry allowlist. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-08 — MODEL MERGE ATTACK DETECTION | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Pre-registration behavioural evaluation + regression testing. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING | Element | Content | | --- | --- | | Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS | | Authoritative source statement | Cross-precision behavioural comparison + delta threshold monitoring. | | Pharmaceutical interpretation | Protect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION | Element | Content | | --- | --- | | Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE | | Authoritative source statement | Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar. | | Pharmaceutical interpretation | Prevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION | Element | Content | | --- | --- | | Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE | | Authoritative source statement | Contextual separation + source allowlisting + output validation + RAG sanitization pipeline. | | Pharmaceutical interpretation | Prevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D2-CTL-03 — JAILBREAK RESISTANCE TESTING | Element | Content | | --- | --- | | Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE | | Authoritative source statement | Quarterly red-team prompt library + adversarial training + automated refusal monitoring. | | Pharmaceutical interpretation | Prevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE | Element | Content | | --- | --- | | Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE | | Authoritative source statement | Multi-modal content scanning + steganography detection + modality-specific guardrails. | | Pharmaceutical interpretation | Prevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION | Element | Content | | --- | --- | | Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE | | Authoritative source statement | Parameter schema validation + allowlist enforcement + sandboxed execution. | | Pharmaceutical interpretation | Prevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION | Element | Content | | --- | --- | | Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE | | Authoritative source statement | Context window segmentation + prompt anchoring + attention boundary enforcement. | | Pharmaceutical interpretation | Prevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D3-CTL-01 — LEAST AGENCY ENFORCEMENT | Element | Content | | --- | --- | | Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY | | Authoritative source statement | Role-based tool scoping + policy-as-code + dynamic permission revocation. | | Pharmaceutical interpretation | Constrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047 | | Mapped use cases | PHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY | Element | Content | | --- | --- | | Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY | | Authoritative source statement | mTLS for agent mesh + message signing + payload validation. | | Pharmaceutical interpretation | Constrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047 | | Mapped use cases | PHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION | Element | Content | | --- | --- | | Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY | | Authoritative source statement | Cross-session behavioural correlation + chain pattern detection + anomaly scoring. | | Pharmaceutical interpretation | Constrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047 | | Mapped use cases | PHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D3-CTL-04 — EMBODIED AI SAFETY CONTROLS | Element | Content | | --- | --- | | Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY | | Authoritative source statement | Sensor integrity verification + safety interlocks + fail-safe state enforcement. | | Pharmaceutical interpretation | Constrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047 | | Mapped use cases | PHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION | Element | Content | | --- | --- | | Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY | | Authoritative source statement | SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation. | | Pharmaceutical interpretation | Constrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047 | | Mapped use cases | PHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION | Element | Content | | --- | --- | | Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY | | Authoritative source statement | User-scoped memory isolation + encryption at rest + query-level access controls. | | Pharmaceutical interpretation | Constrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047 | | Mapped use cases | PHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT | Element | Content | | --- | --- | | Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY | | Authoritative source statement | Cryptographic deletion + lifecycle policy enforcement + retention auditing. | | Pharmaceutical interpretation | Constrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047 | | Mapped use cases | PHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE | Element | Content | | --- | --- | | Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY | | Authoritative source statement | Automated BOM generation + version tracking + registry synchronization. | | Pharmaceutical interpretation | Govern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050 | | Mapped use cases | PHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING | Element | Content | | --- | --- | | Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY | | Authoritative source statement | Static analysis + deserialization sandboxing + signature verification. | | Pharmaceutical interpretation | Govern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050 | | Mapped use cases | PHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D4-CTL-03 — MODEL HUB & REGISTRY VETTING | Element | Content | | --- | --- | | Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY | | Authoritative source statement | Provenance verification + license compliance + security scorecard. | | Pharmaceutical interpretation | Govern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050 | | Mapped use cases | PHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING | Element | Content | | --- | --- | | Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY | | Authoritative source statement | Tool-call logging + anomaly detection + access control enforcement. | | Pharmaceutical interpretation | Govern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050 | | Mapped use cases | PHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT | Element | Content | | --- | --- | | Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY | | Authoritative source statement | Contractual security requirements + penetration testing + data flow mapping. | | Pharmaceutical interpretation | Govern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050 | | Mapped use cases | PHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE | Element | Content | | --- | --- | | Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY | | Authoritative source statement | Network traffic analysis + SaaS discovery + policy enforcement. | | Pharmaceutical interpretation | Govern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050 | | Mapped use cases | PHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA) | Element | Content | | --- | --- | | Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY | | Authoritative source statement | Dependency scanning + CVE matching + automated patching. | | Pharmaceutical interpretation | Govern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050 | | Mapped use cases | PHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D5-CTL-01 — HARMFUL CONTENT BLOCKING | Element | Content | | --- | --- | | Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY | | Authoritative source statement | Content safety classifier + refusal engine. | | Pharmaceutical interpretation | Maintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013 | | Mapped use cases | PHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D5-CTL-02 — PII LEAKAGE PREVENTION | Element | Content | | --- | --- | | Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY | | Authoritative source statement | PII detection + masking + access controls. | | Pharmaceutical interpretation | Maintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013 | | Mapped use cases | PHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D5-CTL-03 — COPYRIGHT DETECTION | Element | Content | | --- | --- | | Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY | | Authoritative source statement | n-gram overlap detection + refusal. | | Pharmaceutical interpretation | Maintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013 | | Mapped use cases | PHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D5-CTL-04 — AI WATERMARKING ROBUSTNESS | Element | Content | | --- | --- | | Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY | | Authoritative source statement | C2PA-compliant watermarking + tamper resistance testing. | | Pharmaceutical interpretation | Maintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013 | | Mapped use cases | PHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION | Element | Content | | --- | --- | | Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY | | Authoritative source statement | Data minimization + purpose limitation + machine unlearning. | | Pharmaceutical interpretation | Maintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013 | | Mapped use cases | PHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION | Element | Content | | --- | --- | | Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY | | Authoritative source statement | Differential privacy + membership inference testing. | | Pharmaceutical interpretation | Maintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013 | | Mapped use cases | PHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS | Element | Content | | --- | --- | | Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT | | Authoritative source statement | Approval workflow + policy enforcement + audit log. | | Pharmaceutical interpretation | Establish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D6-CTL-02 — AUDIT TRAIL COMPLETENESS | Element | Content | | --- | --- | | Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT | | Authoritative source statement | Structured logging + SIEM integration + retention enforcement. | | Pharmaceutical interpretation | Establish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D6-CTL-03 — AI MODEL CARD COMPLETENESS | Element | Content | | --- | --- | | Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT | | Authoritative source statement | Standardized template + version control + public accessibility. | | Pharmaceutical interpretation | Establish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D6-CTL-04 — AI INCIDENT RESPONSE READINESS | Element | Content | | --- | --- | | Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT | | Authoritative source statement | AI-IR runbook + tabletop exercises + containment automation. | | Pharmaceutical interpretation | Establish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING | Element | Content | | --- | --- | | Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT | | Authoritative source statement | Access revocation + decommission audit + scheduled lifecycle. | | Pharmaceutical interpretation | Establish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE | Element | Content | | --- | --- | | Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT | | Authoritative source statement | Contractual security requirements + annual assessment + audit rights. | | Pharmaceutical interpretation | Establish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY | Element | Content | | --- | --- | | Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT | | Authoritative source statement | Failover systems + degraded mode + RTO/RPO definition. | | Pharmaceutical interpretation | Establish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043 | | Mapped use cases | PHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION | Element | Content | | --- | --- | | Domain | D7: HUMAN & SOCIETAL HARMS | | Authoritative source statement | Simulation campaigns + click tracking + remedial training. | | Pharmaceutical interpretation | Assess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D7-CTL-H02 — DEEPFAKE DETECTION TRAINING | Element | Content | | --- | --- | | Domain | D7: HUMAN & SOCIETAL HARMS | | Authoritative source statement | Training modules + quiz + simulated attacks. | | Pharmaceutical interpretation | Assess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION | Element | Content | | --- | --- | | Domain | D7: HUMAN & SOCIETAL HARMS | | Authoritative source statement | Independent channel verification + policy enforcement. | | Pharmaceutical interpretation | Assess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D7-CTL-H04 — AI SOCIAL ENGINEERING IR | Element | Content | | --- | --- | | Domain | D7: HUMAN & SOCIETAL HARMS | | Authoritative source statement | Tabletop exercises + IR plan + verification triggers. | | Pharmaceutical interpretation | Assess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE | Element | Content | | --- | --- | | Domain | D7: HUMAN & SOCIETAL HARMS | | Authoritative source statement | AI-generated phishing detection + SOC tuning + response automation. | | Pharmaceutical interpretation | Assess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D8-CTL-01 — EU AI ACT RISK TIER MAPPING | Element | Content | | --- | --- | | Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE | | Authoritative source statement | Risk classification framework + conformity assessment. | | Pharmaceutical interpretation | Map legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D8-CTL-02 — ISO 42001 GAP ANALYSIS | Element | Content | | --- | --- | | Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE | | Authoritative source statement | Gap analysis methodology + remediation tracking. | | Pharmaceutical interpretation | Map legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION | Element | Content | | --- | --- | | Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE | | Authoritative source statement | Technical documentation + training data summary + copyright attestation. | | Pharmaceutical interpretation | Map legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR) | Element | Content | | --- | --- | | Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE | | Authoritative source statement | Incident classification + notification workflow + SLA monitoring. | | Pharmaceutical interpretation | Preserve the authoritative DORA control unchanged. Determine whether the organization, service, contractual arrangement or regulated affiliate is within DORA's legal scope. A pharmaceutical organization is not subject to DORA merely because it uses AI. Where DORA is not applicable, record a justified Not Applicable decision and separately map applicable pharmaceutical quality, safety, privacy, cybersecurity and regulatory-reporting pathways without treating them as substitutes for DORA. | | Applicability | Applicable only where a documented DORA nexus exists. Otherwise record Not Applicable with scope analysis, accountable approval and reassessment triggers. Analogous pharmaceutical incident processes remain informative sector context and do not alter the authoritative requirement. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036 | | Limitations / confidence | DORA is a financial-sector instrument. This guide does not determine legal scope or replace jurisdiction-specific counsel. FDA, EMA, pharmacovigilance, privacy or quality reporting duties must be assessed separately and are not semantic replacements for D8-CTL-04. Confidence: High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK | Element | Content | | --- | --- | | Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE | | Authoritative source statement | Secure development practices + attestation. | | Pharmaceutical interpretation | Map legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049 | | Mapped use cases | PHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT | Element | Content | | --- | --- | | Domain | D9: PHYSICAL AI SAFETY | | Authoritative source statement | Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity/temperature/current limits; geofencing for autonomous systems; exclusion zones; rate-of-change limits for safety-critical parameters. AI output gated through safety monitor — monitor vetoes any out-of-boundary command without AI system awareness. | | Pharmaceutical interpretation | Apply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040 | | Mapped use cases | PHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION | Element | Content | | --- | --- | | Domain | D9: PHYSICAL AI SAFETY | | Authoritative source statement | For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); transition time to safe state (must be within stopping distance/reaction time for physical context); trigger conditions for safe state entry; recovery procedure. Implement degraded mode ladder: Full AI control → AI-assisted human control → Manual-only → Safe state. | | Pharmaceutical interpretation | Apply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040 | | Mapped use cases | PHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP | Element | Content | | --- | --- | | Domain | D9: PHYSICAL AI SAFETY | | Authoritative source statement | Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human operator interface that immediately transfers control to safe state. Override must be possible when: AI communication is disrupted; AI system is under adversarial attack; AI model is producing anomalous outputs. Override authority must be unconditional — no AI reasoning, confidence scoring, or approval process may delay or prevent override activation. | | Pharmaceutical interpretation | Apply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040 | | Mapped use cases | PHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION | Element | Content | | --- | --- | | Domain | D9: PHYSICAL AI SAFETY | | Authoritative source statement | Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-validate against redundant sensor channels. (2) Actuator layer — monitor command streams for sequences inconsistent with operating context; flag commands outside physically feasible envelope. (3) AI inference layer — apply GAISSF™ D2-CTL-01 (Prompt Injection Detection) equivalent for physical AI inputs; monitor input feature distributions for adversarial perturbation signatures. All detections trigger immediate safe state entry (D9-CTL-02) and incident record with root_cause_category = Adversarial_Attack, root_cause_specific_type = Cyber_Physical_Attack. | | Pharmaceutical interpretation | Apply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040 | | Mapped use cases | PHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING | Element | Content | | --- | --- | | Domain | D9: PHYSICAL AI SAFETY | | Authoritative source statement | Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence falls below threshold. (2) Data plausibility — real-time statistical validation against physical laws, historical baselines, and redundant sensor cross-validation. (3) Degraded sensor handling — explicit policy for each sensor failure mode: degrade gracefully (reduce AI authority, increase human oversight) or enter safe state. (4) Calibration management — automated alert when calibration certificates expire; block AI system from operational use with expired sensor calibration. | | Pharmaceutical interpretation | Apply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040 | | Mapped use cases | PHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D9-CTL-06 — ACTUATOR COMMAND VERIFICATION | Element | Content | | --- | --- | | Domain | D9: PHYSICAL AI SAFETY | | Authoritative source statement | Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibility check — command consistent with prior sequence; flag implausible state transitions for human review. (3) Rate-of-change check — rate of change does not exceed safe limits (acceleration rate, force application rate, temperature change rate). (4) Dual-approval for irreversible actions — actuator commands causing irreversible physical changes (cutting, welding, demolition, high-energy discharge) require hardware interlock confirmation. Verification gate implemented in IEC 61508 SIL 3 certified software or hardware logic independent of AI model. | | Pharmaceutical interpretation | Apply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes. | | Applicability | Apply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040 | | Mapped use cases | PHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030 | | Limitations / confidence | Sector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ### D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION | Element | Content | | --- | --- | | Domain | D9: PHYSICAL AI SAFETY | | Authoritative source statement | (1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safety monitor decisions; all human override activations; system health telemetry. Safety-critical systems retain 300 seconds minimum. (2) Incident freeze — on any safety-relevant event, automatically freeze buffer and begin extended logging. Frozen buffer write-protected. (3) Cryptographic integrity — all records SHA-256 hashed and ECDSA signed at point of creation. For Optimized tier: CRYSTALS-Dilithium signing (post-quantum). (4) Regulatory retention — ICAO Annex 13: 5 years minimum; EU AI Act Art. 19: 10 years; DORA Art. 12: 5 years. (5) UAIF® integration — automatically populate UAIF® incident record from evidence package. | | Pharmaceutical interpretation | Apply evidence-preservation controls where AI directly or indirectly influences manufacturing equipment, laboratory automation, robotics, cold-chain systems or other physical processes. Treat ICAO and DORA retention periods in the authoritative source as source-specific examples, not universal pharmaceutical retention rules. Select and document retention using applicable GxP predicate rules, clinical, pharmacovigilance, product, privacy, litigation-hold and local legal requirements. | | Applicability | Apply where physical/OT interaction, actuator authority or safety-function dependency is present. Record the selected retention basis, owner, approval, integrity controls and reassessment trigger. Do not adopt a listed period solely because it is the longest period in the authoritative statement. | | Recommended practices | Define an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence. | | GxP / validation | Where GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change. | | Patient / product / clinical / PV | Escalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope. | | Data integrity | Maintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable. | | Third parties | Obtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit. | | Illustrative evidence | Approved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts. | | Assessment questions | Is scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed? | | Common failure modes | Unclear intended use; inherited control assumed without evidence; unapproved model change; incomplete logging; weak reviewer criteria; missing supplier notification; stale validation. | | Mapped threats | PHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040 | | Mapped use cases | PHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030 | | Limitations / confidence | ICAO and DORA references ordinarily do not apply to pharmaceutical operations absent a specific legal or operational nexus. Retention decisions require qualified quality, records, privacy and legal review. Confidence: High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review. | ## 8. Lifecycle Implementation Apply controlled gates for intake, intended use, GxP determination, criticality, data provenance, model selection, threat modelling, development, testing, validation/assurance, approval, deployment, access, monitoring, drift, change control, periodic review, incident/deviation/CAPA, retirement, retention and supplier exit. Foundation-model and generative-AI uses should additionally control prompts, retrieval sources, grounding, source citation, confidential data, provider retention/training, version changes, tool permissions, agentic actions and insertion into regulated systems. ## 9. Validation and Assurance Validation or assurance should demonstrate fitness for the approved intended use, not merely model accuracy. The record should cover requirements, data suitability, representative and edge-case testing, robustness, cybersecurity, reproducibility, traceability, explainability where needed, human factors, supplier controls, configuration/version management, acceptance criteria, release approval, regression testing and periodic review. For probabilistic and externally updated systems, define tolerances, repeated-test methods, version pinning or change-detection controls, and evidence sufficient to reconstruct the evaluated state. ## 10. Incident, Deviation, CAPA and Escalation Maintain a coordinated triage process that can classify the same event across cybersecurity, AI failure, data integrity, quality deviation, clinical issue, pharmacovigilance failure, privacy, supplier and continuity pathways. Decision criteria should address containment, suspension, rollback, affected subject/patient/product/batch/record assessment, evidence preservation, reconciliation, CAPA, legal and regulatory review, and external communication. Reporting deadlines are not stated because they depend on jurisdiction and event type. ## 11. Evidence and Assessment Evidence should be attributable, time-bounded, scope-specific and protected against unauthorized alteration. Typical evidence includes inventory and intended-use approvals, GxP determinations, architecture/data-flow diagrams, model/system cards, provenance, supplier assessments, risk/threat assessments, validation plans and results, access and audit logs, change records, monitoring/drift reports, human-review records, incident/deviation/CAPA records and periodic reviews. Examples are not mandatory artifact names. ## 12. Maturity Model | Level | Description | | --- | --- | | 1 — Initial | Ad hoc ownership, incomplete inventory and reactive evidence. | | 2 — Repeatable | Documented minimum process for recurring use cases. | | 3 — Defined | Integrated governance, quality, security, validation and supplier processes. | | 4 — Managed | Performance, control effectiveness, exceptions and residual risk are measured and reviewed. | | 5 — Adaptive | Controlled automation, continuous assurance and improvement based on evidence and change signals. | ## 13. Implementation Roadmap | Period | Priority actions | Completion evidence | | --- | --- | --- | | First 30 days | Inventory AI; stop unapproved regulated use; identify Tier 3/4 systems; assign owners; establish escalation. | Approved inventory, restrictions, ownership and risk register. | | Days 31–90 | Complete GxP/criticality determinations; supplier reviews; output-review rules; change control; incident/deviation linkage; minimum evidence and priority testing. | Signed determinations, supplier records, procedures, test evidence and governance report. | | Months 4–6 | Expand validation, monitoring, traceability, resilience, training and assessment coverage. | Validated/assured priority systems, dashboards, trained roles and closed high-risk findings. | | Months 7–12 | Institutionalize periodic review, metrics, continuous assurance and cross-site consistency. | Management review, trend evidence, repeat assessment and improvement backlog. | ## 14. Exceptions, Legacy Systems and Practical Constraints ### 14.1 Documented exceptions and justified exclusions An exclusion is not complete merely because a control is marked Not Applicable. Record the system and control, factual rationale, risk assessment, compensating safeguards, residual risk, accountable Quality and Information Security approvals, legal or regulatory review where relevant, expiry date and reassessment trigger. A convenience, cost or supplier limitation alone is not a sufficient rationale without documented risk acceptance. ### 14.2 Legacy and embedded AI systems For AI embedded in older or validated systems, a new control may require a broader validated-system change. Document validated-state constraints, unavailable model internals, unsupported suppliers, logging or provenance limitations, compensating controls and a time-bound remediation or retirement plan. Risk acceptance should be periodically reviewed and should not become an indefinite substitute for remediation. ### 14.3 Resource constraints and implementation sequencing Organisations with limited resources should first identify GxP-relevant and Tier 3/4 systems, restrict unapproved regulated use, establish accountable human review, preserve evidence and address high-consequence supplier and physical/OT dependencies. Vendor attestations may support an assessment but do not replace organisation-specific evidence of intended-use fitness or operating effectiveness. ### 14.4 Physical and OT scope Record whether the AI system has no, indirect, advisory or direct interaction with physical processes. Document affected equipment or process, actuator authority, safety-function dependency, override or emergency-stop dependency, site or manufacturing area and the rationale for D9 applicability. Administrative labels alone do not prove D9 is inapplicable where outputs can alter recipes, commands, work instructions or safety-critical actions. ## 15. Notably Absent **NA-001. No reliable public evidence was identified that autonomous AI compromise of pharmaceutical manufacturing is widespread.** Treat as a plausible high-impact scenario, not a prevalence claim. Confidence: Moderate; public reporting is incomplete. **NA-002. No claim is made that malicious manipulation of a pharmaceutical AI system has directly caused confirmed patient harm at scale.** Do not infer occurrence from threat plausibility. Confidence: Moderate; confidential incidents may not be public. **NA-003. No evidence supports routine regulator acceptance of fully autonomous regulated decisions without accountable human and organizational controls.** Default to explicit decision rights, qualified oversight and traceability. Confidence: High as a guide boundary; jurisdiction-specific review remains required. **NA-004. No universal global regulatory classification or validation method for pharmaceutical AI is assumed.** Determine requirements by jurisdiction, intended use and lifecycle stage. Confidence: High. **NA-005. Public incident datasets do not provide complete coverage of AI failures in pharmaceutical operations.** Frequency estimates are not supplied. Confidence: High. **NA-006. Conventional cybersecurity controls alone are not shown to be sufficient for GxP-relevant AI systems.** Integrate quality, validation, data integrity, human oversight and regulated escalation. Confidence: High as an implementation principle. **NA-007. Model accuracy alone is not treated as evidence of clinical, safety, quality or regulatory fitness.** Assess intended use, data, robustness, security, human factors, traceability and lifecycle control. Confidence: High. **NA-008. The guide does not establish that every listed threat has occurred.** Threat entries are explicitly classified as scenarios unless confirmed evidence is cited. Confidence: High. ## 16. Limitations - Organization-specific GxP, regulatory, legal and quality review is required. - External references must be checked for current version and jurisdictional applicability. - Examples do not create additional GAISSF requirements. - Threat catalogue does not establish prevalence or incident occurrence. ## 17. External Reference Register | ID | Issuer / title | Date / status | Applicability limit | Official URL | | --- | --- | --- | --- | --- | | SRC-001 | US Food and Drug Administration - Guiding Principles of Good AI Practice in Drug Development | 2026; Regulatory principles / non-binding context | Does not itself establish universal validation or compliance requirements. | https://www.fda.gov/about-fda/artificial-intelligence-drug-development/guiding-principles-good-ai-practice-drug-development | | SRC-002 | European Medicines Agency - Reflection paper on the use of AI in the medicinal product lifecycle | 2024; Scientific reflection paper | Applicability depends on lifecycle stage, regulatory use and current agency position. | https://www.ema.europa.eu/en/use-artificial-intelligence-ai-medicinal-product-lifecycle | | SRC-003 | US Food and Drug Administration - E6(R3) Good Clinical Practice (GCP) | 2025; FDA guidance adopting ICH E6(R3) | Clinical-trial scope; regional implementation and annex status must be verified. | https://www.fda.gov/regulatory-information/search-fda-guidance-documents/e6r3-good-clinical-practice-gcp | | SRC-004 | European Commission - EudraLex Volume 4, Annex 11 - Computerised Systems | 2011; EU GMP guidance | Current revision, national interpretation and product/manufacturing applicability must be verified. | https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en | | SRC-005 | US Food and Drug Administration - 21 CFR Part 11 - Electronic Records; Electronic Signatures | Current codification to be verified; Regulation | Applicability depends on predicate rules and record use. | https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11 | | SRC-006 | NIST - Artificial Intelligence Risk Management Framework (AI RMF 1.0) | 2023; Voluntary framework | Not pharmaceutical regulation and not a compliance certification. | https://www.nist.gov/itl/ai-risk-management-framework | | SRC-007 | NIST - Cybersecurity Framework 2.0 | 2024; Voluntary framework | Requires tailoring; does not replace GxP or product-specific requirements. | https://www.nist.gov/cyberframework | | SRC-008 | ICH - ICH Q9 Quality Risk Management | Current adopted revision to be verified; Harmonised guideline | Regional implementation and current revision must be confirmed. | https://www.ich.org/page/quality-guidelines | | SRC-009 | European Union - Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) | 2022; applicable from 2025-01-17; Binding EU regulation within defined financial-sector scope | Not generally applicable to pharmaceutical entities absent a covered financial-entity, ICT-provider, affiliate or contractual nexus. | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554 | | SRC-010 | European Union - Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) | 2024; phased application; Binding EU regulation with phased obligations and scope conditions | Applicability depends on role, system classification, use, territory, transition period and current implementing measures. | https://eur-lex.europa.eu/eli/reg/2024/1689/oj | | SRC-011 | ISO/IEC - ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system | 2023; International management-system standard; licensed text | Certification or conformity is separate from GAISSF implementation and does not itself establish pharmaceutical regulatory compliance. | https://www.iso.org/standard/42001 | | SRC-012 | National Institute of Standards and Technology - NIST SP 800-218A - Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile | 2024; Final NIST Special Publication; voluntary guidance unless adopted | Use with SSDF as applicable; it is not pharmaceutical regulation and does not establish universal attestation or retention requirements. | https://csrc.nist.gov/pubs/sp/800/218/a/final | ## 18. Glossary | Term | Meaning in SEC-049 | | --- | --- | | ALCOA+ | Data-integrity principles covering attributable, legible, contemporaneous, original or true-copy, accurate, complete, consistent, enduring and available records. | | CAPA | Corrective and preventive action managed through the applicable quality system. | | Criticality tier | Informative SEC-049 implementation classification; not a regulator-approved category or GAISSF conformance tier. | | GxP | Collective term for applicable regulated good-practice requirements, determined by intended use, product, process and jurisdiction. | | Human oversight | Assigned, competent and effective human authority to review, challenge, approve, reject, suspend or override an AI-supported action. | | Intended use | The approved purpose, users, environment, inputs, outputs, decision role and constraints of an AI system. | | Legacy system | Existing system whose architecture, validation state, supplier support or technical constraints materially limit implementation of current controls. | | OPA | Open Policy Agent, where used as an example of policy-as-code enforcement; no specific product is required. | | Physical/OT interaction | Direct or indirect AI influence over equipment, actuators, industrial controls, laboratory automation, cold-chain systems or other physical processes. | | QMS | Quality management system governing applicable procedures, records, deviations, change and CAPA. | | Regulated record | A record whose creation, maintenance, use or retention is governed by applicable predicate rules or regulated processes. | | SIEM | Security information and event management capability; the guide does not require a specific platform. | | Validated state | Controlled condition in which a system remains fit for its approved intended use under documented configuration and change controls. | ## 19. Publication Gates Before public release, close or explicitly accept: qualified pharmaceutical quality/GxP review; pharmacovigilance review; clinical review; manufacturing/laboratory review; privacy and legal review; jurisdiction-specific regulatory applicability; final trademark/licence wording; named approvals; publication URLs; and cross-artifact QA. ## 20. Change Log | Version | Date | Change | Owner | | --- | --- | --- | --- | | 1.0 | 30 June 2026 | Initial controlled pre-release pharmaceutical sector implementation package. | ODA3 Institute | | 1.1 | 30 June 2026 | Verified feedback incorporated: schema parity, references, D8/D9 applicability, physical/OT scope, criticality safeguards, glossary, exceptions, legacy and workbook usability. | ODA3 Institute | ## Publication-Readiness Decision **NOT PUBLICATION READY — CONTROLLED PRE-RELEASE ONLY.** The authoritative 59-control mapping and artifact structure are complete. Public release is not authorised until the listed pharmaceutical, regulatory, legal and publication gates are closed or formally accepted as limitations.