SECTOR GUIDANCE

Government Sector Guidance

GAISSF implementation guidance for AI systems and assurance programmes in the government sector.

GAISSF

Government Sector Implementation Guidance

June 2026 Release | Publication Candidate

FieldValue
Public releaseJune 2026
ClassificationInformative sector implementation guidance
StatusPublication Candidate — specialist gates open
PublisherODA3 Institute
Legal entityODA3 Pvt Ltd
Normative sourceGAISSF-NOR-001 Framework Standard v1.0
Control baseline59 controls across nine domains
Research cut-off30 June 2026
Publication channelWebsite / GitHub

Informative, evidence-driven implementation guidance for government security, governance, legal, procurement, audit, programme, and oversight stakeholders.

Document Control

AttributeControlled value
StatusPublication Candidate
Version1.0
Normative statusInformative; subordinate to GAISSF-NOR-001
Change authorityODA3 Institute document-control process
Review cycleAt least annually and on material legal, threat, technology, or GAISSF change
Open gatesJurisdiction-specific legal review; accessibility/rights review; current-policy verification; trademark-status verification

Classification determination: this publication is informative sector implementation guidance, not an applied research report. The mandatory Technical Report / Executive Brief pairing for research reports is therefore not triggered. A separate executive brief is provided as a usability companion.

Copyright, Licensing and Reliance Notice

© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. Trademark status verification remains an open publication gate; the public candidate does not use a registered-trademark symbol. Use, reproduction, adaptation, certification, credential, and trademark rights are governed by the applicable GAISSF publication terms and licensing instruments.

This guide is not legal advice, does not determine whether a deployment is lawful, does not establish certification, and does not guarantee security, safety, fairness, accuracy, availability, regulatory compliance, or absence of harmful outcomes.

Release History

ReleaseDateStatusChange summary
June 202630 June 2026Publication CandidateControl-specific semantic rewrite; public identifier sanitisation; workbook, machine-readable and evidence refinements.

Contents

  1. Executive Summary
  2. Purpose, Scope and Audience
  3. How to Use This Guide
  4. Government Operating Context
  5. Use-Case Taxonomy
  6. Risk Taxonomy
  7. Decision-Authority Model
  8. Public-Law and Accountability Considerations
  9. Data, Records, Privacy and Information Management
  10. Procurement and Third-Party Governance
  11. Security Architecture
  12. Human Oversight
  13. Transparency, Contestability and Appeal
  14. Incident Management and Continuity
  15. GAISSF Control Interpretations
  16. Assessment Model
  17. Maturity Model
  18. Implementation Roadmap
  19. Worked Examples
  20. Notably Absent
  21. Limitations
  22. Source Register

1. Executive Summary

The central government-sector AI risk is not the mere presence of an AI model. It is the unsafe, insecure, opaque, or unlawful translation of AI output into public authority, public action, public records, or material consequences for people and institutions.

Government organisations should distinguish informational assistance, recommendation or prioritisation, constrained operational action, and material or determinative public decisions. Control intensity should rise with decision consequence, data sensitivity, autonomy, affected-person impact, and difficulty of correction.

Accountability remains with the authorised public body and responsible officials. Procurement, outsourcing, managed services, model hosting, or supplier certification do not transfer statutory or public accountability to a vendor.

Not every government AI system is inherently high risk. Risk becomes materially greater where systems affect rights, eligibility, liberty, legal status, public safety, taxation, licensing, immigration, enforcement, identity, access to essential services, or authoritative government records.

Five decisions for senior leadership

  1. Define permitted, restricted, and prohibited AI uses and exception authority.
  2. Assign accountable owners for authority, operation, security, data, records, suppliers, and affected-person safeguards.
  3. Require a documented decision-authority level for every use case.
  4. Set minimum evidence and independent-assurance requirements for material public-impact systems.
  5. Fund continuity, appeal, correction, incident response, and decommissioning.

Notably Absent — executive view

This guide does not assert that all government AI is high risk; that human review is inherently effective; that model accuracy establishes legality or fairness; that vendor certification transfers accountability; or that framework adoption alone proves operational security.

2. Purpose, Scope and Audience

This guide translates the authoritative GAISSF control baseline into government-sector implementation guidance, evidence expectations, assessment considerations, examples, and operating records. It does not alter normative GAISSF requirements.

  • central/federal, state/provincial, regional, and local government
  • ministries, departments, agencies, regulators, authorities, and commissions
  • shared services and government-controlled entities where relevant
  • benefits, taxation, licensing, grants, procurement, regulatory, public-safety, emergency, border, justice-administration, public-health-administration, education-administration, identity, citizen-service, records, cybersecurity, and policy-support functions

Boundary conditions

Defence, intelligence, law-enforcement, healthcare, education, and critical-infrastructure activities may require specialist sector guides and additional controls.

Intended audience

Government CISOs, security architects, AI governance leads, chief data officers, digital-transformation leaders, procurement officials, legal and compliance personnel, internal auditors, inspectors general, programme owners, standards participants, and risk committees.

3. How to Use This Guide

  1. Inventory the AI system, use case, supplier, data, integration, decision role, affected parties, and environment.
  2. Assign a decision-authority level and public-impact classification before production use.
  3. Map all 59 GAISSF controls and document applicability; no control may be silently omitted.
  4. Implement sector interpretations without changing authoritative control text.
  5. Collect operating-effectiveness evidence, not only policy or design intent.
  6. Record legal and policy dependencies, exceptions, residual risk, review dates, and approvals.
  7. Use the workbook and disposition log to prepare for independent assessment.

4. Government Operating Context

Government AI operates within delegated authority, administrative procedure, records obligations, procurement constraints, rights protections, accessibility duties, public accountability, and continuity expectations. These vary by jurisdiction and function.

Operating characteristicImplementation consequence
Delegated public authoritySystem roles must remain within lawful delegation; authority must not emerge implicitly from automation.
Affected-person consequencesNotice, reasons, review, correction, appeal, and redress may be required.
Public records and auditInputs, outputs, versions, approvals, and actions may require preservation and retrieval.
Procurement dependenceContracts must provide evidence, change control, incident notification, audit rights, portability, and exit.
Continuity obligationManual fallback and degraded-mode service must be tested where interruption would cause harm.
Public trustDisclosure, communications integrity, accessibility, and documented limitations are operational controls.

5. Government AI Use-Case Taxonomy

IDUse caseFunctionRoleAuthorityImpact
UC-01Citizen-facing conversational assistantsCitizen servicesAdvisory2Medium to High
UC-02Benefits eligibility and prioritisationSocial protectionRecommendatory4High
UC-03Fraud, waste, and abuse detectionIntegrity and assuranceRecommendatory3High
UC-04Tax risk scoring and audit selectionRevenue administrationRecommendatory4High
UC-05Licensing and permit processingRegulatory administrationRecommendatory4High
UC-06Public procurement analysisProcurementAdvisory3High
UC-07Grant application screeningPublic fundingRecommendatory4High
UC-08Regulatory inspection prioritisationRegulationRecommendatory4High
UC-09Policy modelling and forecastingPolicyAdvisory2Medium
UC-10Document classification and records managementInformation managementOperational2Medium
UC-11Public-records processingTransparencyAdvisory3High
UC-12Translation and accessibility servicesCitizen accessAdvisory2Medium
UC-13Identity verification and biometric matchingDigital identityRecommendatory4Very High
UC-14Public safety decision supportPublic safetyRecommendatory4Very High
UC-15Emergency response resource allocationEmergency managementOperational4Very High
UC-16Immigration, customs, and border processingBorder administrationRecommendatory4Very High
UC-17Justice-sector administrative supportJustice administrationAdvisory4Very High
UC-18Government HR screening and workforce analyticsWorkforceRecommendatory4High
UC-19Cybersecurity monitoring and incident analysisCybersecurityOperational3High
UC-20Intelligence summarisation using authorised dataAnalysisAdvisory3Very High
UC-21Code generation and development supportDigital deliveryAdvisory2High
UC-22Automated drafting of notices and decisionsAdministrationAdvisory4Very High
UC-23Regulatory enforcement supportEnforcementRecommendatory4Very High
UC-24Public consultation and sentiment analysisDemocratic participationAdvisory3High
UC-25Synthetic media for government communicationsCommunicationsOperational3High
UC-26Inter-agency data matchingShared servicesOperational4Very High
UC-27Vendor-hosted AI servicesCross-governmentOperational3High
UC-28General-purpose AI assistants for officialsCross-governmentAdvisory2High

6. Government AI Risk Taxonomy

Risk IDRiskCategoryRatingOperational description
R-AUTH-01Unlawful delegation of statutory authorityAuthority and legalityHighAI output is treated as binding without a valid delegation or accountable official decision.
R-RIGHTS-01Discriminatory or disparate effectsRights and public impactHighModel errors or data bias produce unequal access, burden, delay, scrutiny, or denial.
R-SEC-01Prompt injection and malicious content ingestionSecurityHighUntrusted content alters instructions, causes data disclosure, or triggers unauthorised actions.
R-DATA-01Inaccurate, incompatible, or unlawful data useData and recordsHighData lacks provenance, is stale, or is used outside authorised purpose.
R-PROC-01Opaque supplier and weak contractual controlProcurement and vendorHighGovernment cannot inspect, test, preserve evidence, or manage supplier changes.
R-OPS-01Automation bias and ineffective human reviewOperationalHighReviewers defer to AI without sufficient competence, time, authority, or evidence.
R-INST-01Erosion of public trust and institutional accountabilityDemocratic and institutionalHighAI use is opaque, politically sensitive, misleading, or not contestable.
R-CONT-01Loss of public-service continuityOperationalHighAI dependency prevents service delivery or manual fallback during outage or degradation.
R-PHYS-01Unsafe physical actionPhysical safetyVery HighAI commands affect people, vehicles, facilities, or equipment outside safe limits.

Risk treatment should identify the government function, lawful authority, data, users, affected persons, threat actors, failure modes, detectability, reversibility, service continuity, and evidence required to accept residual risk.

7. Decision-Authority Model

LevelPermitted roleMinimum expectations
Level 1 — Informational assistanceDrafting, search, summarisation, translation, or administration; no direct material decision.Logging, data controls, training, output labelling, periodic review.
Level 2 — Recommendation or prioritisationAI ranks, scores, flags, or recommends; an authorised official independently decides.Decision records, reviewer competence, override, explanation, monitoring, escalation.
Level 3 — Constrained operational actionAI performs predefined reversible actions inside approved limits.Least privilege, action logs, change control, kill switch, rollback, incident response.
Level 4 — Material or determinative public decisionAI materially influences or executes decisions affecting rights, status, enforcement, benefits, taxation, licensing, immigration, safety, or essential services.Jurisdiction-specific legal validation, independent assurance, reasons, notice, contestability, authority, records, enhanced monitoring, executive risk acceptance.

Level 4 is not presumed lawful or appropriate.

8. Public-Law, Rights and Accountability Considerations

Document the legal or administrative basis for the function and the official who retains decision authority.

Separate advisory AI output from official reasons and decisions.

Assess notice, explanation, accessibility, procedural fairness, equality, contestability, correction, appeal, and remedy requirements.

Provide oversight bodies sufficient evidence to inspect the system, supplier dependencies, decisions, exceptions, incidents, and remediation.

9. Data, Records, Privacy and Information Management

Maintain inventories of datasets, prompts, retrieval sources, models, versions, tools, integrations, logs, and records classifications.

Preserve evidence needed to reconstruct material decisions.

Do not enter controlled or protected information into unapproved services.

Retention follows the longest applicable statutory, archival, litigation-hold, security, contractual, or GAISSF requirement.

10. Procurement and Third-Party Governance

Contracts should cover authorised use, prohibited use, data ownership, training restrictions, confidentiality, security, vulnerabilities, incidents, subcontractors, changes, audits, evidence, logging, retention, continuity, portability, exit, deletion, and suspension.

Supplier certifications are due-diligence inputs, not substitutes for verification.

Government should retain suspension, evidence-preservation, migration, and continuity rights.

11. Security Architecture Considerations

Use environment separation, least privilege, identity-bound access, approved data paths, prompt isolation, secure retrieval, egress control, secrets management, tool allowlists, monitoring, and recovery.

Public-facing systems require abuse controls, filtering, rate limiting, prompt-injection testing, leakage prevention, and human escalation.

Agentic systems require action boundaries, transaction limits, approvals, rollback, and emergency stop.

12. Human Oversight and Administrative Accountability

Human involvement is effective only when reviewers are competent, able to challenge the output, given sufficient time, and provided evidence.

Measure override rates, review quality, reversals, appeal outcomes, workload, and automation-bias indicators.

A nominal approval click is not meaningful oversight.

13. Transparency, Notice, Explanation, Contestability and Appeal

Identify AI interaction where relevant and distinguish automated content from approved government decisions.

Material decisions should provide appropriate reasons and routes for review or correction.

Explanations must be useful; technical feature importance alone may be insufficient.

14. Incident Management, Escalation and Continuity

Define incidents for security compromise, harmful output, unlawful action, data exposure, supplier change, disparity, records failure, outage, and physical safety.

Preserve evidence, constrain unsafe operation, notify accountable officials, correct records and decisions, and communicate where required.

Test manual fallback, degraded operation, supplier failure, model withdrawal, data restoration, and emergency shutdown.

15. GAISSF Government-Sector Control Interpretations

Every authoritative control ID and title is preserved. Sector treatment is informative; authoritative control detail remains in GAISSF-NOR-001.

D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleDATASET PROVENANCE & POISONING PREVENTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Dataset Provenance & Poisoning Prevention, government entities should apply the control to dataset lineage, authorised sources, integrity and poisoning controls. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceMaintain a dataset register with source, licence, collection purpose, transformations, hashes, approvals and poisoning-test results; quarantine unverified data before training or retrieval use.
Minimum evidencedataset register; source approvals; hashes; poisoning-test report; quarantine record
Enhanced evidencedataset register; source approvals; hashes; poisoning-test report; quarantine record; independent test evidence; affected-person or service-impact analysis where material
AssessmentSample source records, reproduce integrity checks, and confirm unverified data cannot enter production pipelines.
Common failure modesUntraceable datasets, unverifiable licences, missing hashes, or poisoning scans performed only after deployment.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-02 — MODEL EXTRACTION RESISTANCE

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleMODEL EXTRACTION RESISTANCE
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Model Extraction Resistance, government entities should apply the control to resistance to model extraction through rate, query and output controls. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine extraction threat scenarios; apply authentication, rate limits, query-pattern detection, output minimisation and response actions for suspicious harvesting.
Minimum evidenceextraction threat model; rate-limit policy; anomalous-query alerts; response logs
Enhanced evidenceextraction threat model; rate-limit policy; anomalous-query alerts; response logs; independent test evidence; affected-person or service-impact analysis where material
AssessmentRun controlled extraction attempts and verify detection, throttling and escalation without materially blocking legitimate public access.
Common failure modesUnlimited high-volume querying, excessive confidence/logit exposure, or no investigation path for extraction alerts.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-03 — BEHAVIORAL DRIFT DETECTION

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleBEHAVIORAL DRIFT DETECTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Behavioral Drift Detection, government entities should apply the control to behavioural drift detection across population, language, season and policy changes. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceEstablish approved baselines and monitor performance, safety, fairness and refusal behaviour by relevant cohort; define drift thresholds, review cadence and rollback criteria.
Minimum evidencebaseline report; drift metrics; cohort analysis; alert history; rollback decision record
Enhanced evidencebaseline report; drift metrics; cohort analysis; alert history; rollback decision record; independent test evidence; affected-person or service-impact analysis where material
AssessmentIntroduce representative distribution shifts and verify alerts, investigation and corrective action occur within approved thresholds.
Common failure modesOnly aggregate accuracy is monitored; drift thresholds are undocumented; affected cohorts are invisible.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleFEDERATED LEARNING POISONING PREVENTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Federated Learning Poisoning Prevention, government entities should apply the control to poisoning resistance in federated or distributed training. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceAuthenticate participants, validate updates, use robust aggregation, detect anomalous gradients and retain participant/update provenance.
Minimum evidenceparticipant register; update signatures; anomaly reports; aggregation configuration; exclusion decisions
Enhanced evidenceparticipant register; update signatures; anomaly reports; aggregation configuration; exclusion decisions; independent test evidence; affected-person or service-impact analysis where material
AssessmentSubmit malicious or anomalous updates in a controlled test and confirm they are detected, contained and excluded.
Common failure modesUnauthenticated participants, blind aggregation, or inability to reconstruct which update changed the model.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleEMBEDDING SPACE ROBUSTNESS
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Embedding Space Robustness, government entities should apply the control to robustness of embeddings and vector retrieval against manipulation and collision. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceValidate embedding models and indexes; test adversarial nearest-neighbour manipulation, tenant separation, poisoned documents and retrieval relevance for protected workflows.
Minimum evidenceembedding evaluation; index access controls; poisoned-document tests; retrieval logs
Enhanced evidenceembedding evaluation; index access controls; poisoned-document tests; retrieval logs; independent test evidence; affected-person or service-impact analysis where material
AssessmentSeed adversarial and cross-tenant documents and verify isolation, retrieval integrity and alerting.
Common failure modesShared indexes without tenant controls, no retrieval attack testing, or silent index replacement.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titlePOST-QUANTUM MODEL SIGNING & CRYPTO HARDENING
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Post-Quantum Model Signing & Crypto Hardening, government entities should apply the control to cryptographic authenticity and migration readiness for model artifacts. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceSign model artifacts and manifests, protect signing keys, verify signatures before load, inventory algorithms and maintain a risk-based cryptographic migration plan.
Minimum evidencesigned manifest; key-management record; verification logs; algorithm inventory; migration plan
Enhanced evidencesigned manifest; key-management record; verification logs; algorithm inventory; migration plan; independent test evidence; affected-person or service-impact analysis where material
AssessmentAttempt to load altered and unsigned artifacts and confirm rejection; review migration triggers and key-rotation evidence.
Common failure modesSignatures not checked at runtime, shared signing keys, or unsupported post-quantum claims presented as current assurance.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleLORA/ADAPTER INTEGRITY VERIFICATION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Lora/Adapter Integrity Verification, government entities should apply the control to integrity and compatibility of LoRA, adapters and other parameter-efficient modifications. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceTreat adapters as executable model changes: approve sources, hash and scan artifacts, test compatibility and safety, and bind each adapter to an authorised base model/version.
Minimum evidenceadapter inventory; hashes; compatibility tests; approval record; deployment binding
Enhanced evidenceadapter inventory; hashes; compatibility tests; approval record; deployment binding; independent test evidence; affected-person or service-impact analysis where material
AssessmentLoad an altered or mismatched adapter and verify rejection or safe quarantine.
Common failure modesAdapters deployed outside change control or accepted solely because the base model was approved.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-08 — MODEL MERGE ATTACK DETECTION

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleMODEL MERGE ATTACK DETECTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Model Merge Attack Detection, government entities should apply the control to detection of unsafe or malicious behaviour introduced through model merging. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceRecord component models and merge method, scan components, compare pre/post-merge behaviour and require approval before release.
Minimum evidencemerge manifest; component provenance; differential evaluation; approval; rollback package
Enhanced evidencemerge manifest; component provenance; differential evaluation; approval; rollback package; independent test evidence; affected-person or service-impact analysis where material
AssessmentPerform differential tests for backdoors, capability shifts and safety regressions against component baselines.
Common failure modesMerged models lack component lineage or are approved on benchmark averages that conceal targeted regressions.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING

FieldGovernment-sector treatment
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative titleQUANTIZATION BACKDOOR SCREENING
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Quantization Backdoor Screening, government entities should apply the control to backdoor and safety regression screening after quantisation or compression. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceTreat quantisation as a material model change; compare full-precision and quantised behaviour, test trigger sets and preserve conversion parameters and toolchain provenance.
Minimum evidenceconversion manifest; tool versions; differential tests; trigger-set results; approval
Enhanced evidenceconversion manifest; tool versions; differential tests; trigger-set results; approval; independent test evidence; affected-person or service-impact analysis where material
AssessmentExecute targeted trigger and regression tests across precision variants and verify release thresholds.
Common failure modesQuantised artifacts inherit approval automatically from the source model without re-testing.
Related risksD; a; t; a; ; a; n; d; ; r; e; c; o; r; d; s; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION

FieldGovernment-sector treatment
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative titleDIRECT PROMPT INJECTION PREVENTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Direct Prompt Injection Prevention, government entities should apply the control to direct prompt-injection resistance for user-controlled inputs. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceSeparate instructions from user data, constrain tool access, apply input/output controls, test known attack patterns and log attempted instruction override.
Minimum evidenceprompt architecture; attack tests; tool policy; alert logs; remediation records
Enhanced evidenceprompt architecture; attack tests; tool policy; alert logs; remediation records; independent test evidence; affected-person or service-impact analysis where material
AssessmentRun representative direct-injection attacks and verify privileged instructions, data and tools remain protected.
Common failure modesReliance on a single system prompt or keyword blocklist with no tool-boundary testing.
Related risksS; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION

FieldGovernment-sector treatment
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative titleINDIRECT PROMPT INJECTION PREVENTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Indirect Prompt Injection Prevention, government entities should apply the control to indirect prompt-injection resistance in retrieved documents, webpages, email and files. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceLabel external content as untrusted, sanitise and isolate retrieval, restrict tool actions, and require confirmation for consequential operations.
Minimum evidencecontent trust policy; retrieval filters; sandbox configuration; indirect-injection tests
Enhanced evidencecontent trust policy; retrieval filters; sandbox configuration; indirect-injection tests; independent test evidence; affected-person or service-impact analysis where material
AssessmentEmbed malicious instructions in authorised source formats and verify they cannot override policy or trigger unauthorised actions.
Common failure modesRetrieved content is treated as trusted instruction or can silently influence tool calls.
Related risksS; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D2-CTL-03 — JAILBREAK RESISTANCE TESTING

FieldGovernment-sector treatment
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative titleJAILBREAK RESISTANCE TESTING
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Jailbreak Resistance Testing, government entities should apply the control to systematic jailbreak and policy-bypass testing. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceMaintain a risk-based adversarial test suite covering multi-turn, encoding, role-play and multilingual attacks; track attack success rate and remediation.
Minimum evidencejailbreak suite; test results; defect tickets; retest evidence; accepted-risk record
Enhanced evidencejailbreak suite; test results; defect tickets; retest evidence; accepted-risk record; independent test evidence; affected-person or service-impact analysis where material
AssessmentRe-run fixed and novel attacks against each release and verify residual bypasses are documented and bounded.
Common failure modesOne-time testing, undocumented prompts, or pass criteria based only on vendor statements.
Related risksS; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE

FieldGovernment-sector treatment
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative titleMULTI-MODAL INJECTION DEFENSE
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Multi-Modal Injection Defense, government entities should apply the control to injection defence across text, image, audio, video and document channels. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceThreat-model each modality and cross-modal interaction; validate parsers, metadata and OCR/transcription outputs before they reach privileged prompts or tools.
Minimum evidencemodality threat model; parser tests; sample corpus; cross-modal attack results
Enhanced evidencemodality threat model; parser tests; sample corpus; cross-modal attack results; independent test evidence; affected-person or service-impact analysis where material
AssessmentInsert hidden or conflicting instructions in supported media and verify isolation and safe handling.
Common failure modesSecurity testing covers text only while images, documents or audio can carry instructions.
Related risksS; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION

FieldGovernment-sector treatment
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative titleFUNCTION CALL/TOOL CALL INJECTION PREVENTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Function Call/Tool Call Injection Prevention, government entities should apply the control to prevention of malicious or unauthorised function and tool calls. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceUse explicit allowlists, typed schemas, least privilege, parameter validation, transaction limits and human approval for consequential actions.
Minimum evidencetool catalogue; permission matrix; schema validation; transaction logs; approval evidence
Enhanced evidencetool catalogue; permission matrix; schema validation; transaction logs; approval evidence; independent test evidence; affected-person or service-impact analysis where material
AssessmentAttempt unauthorised tools, malformed parameters and privilege escalation; confirm block, alert and audit trail.
Common failure modesTools inherit broad service-account permissions or model-generated parameters are executed without validation.
Related risksS; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION

FieldGovernment-sector treatment
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative titleCROSS-CONTEXT HIJACKING MITIGATION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Cross-Context Hijacking Mitigation, government entities should apply the control to prevention of session, tenant or task context hijacking. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceIsolate sessions and tenants, bind context to authenticated principals, minimise persistent state and detect cross-context references or memory leakage.
Minimum evidencesession design; tenant tests; memory policy; access logs; isolation test results
Enhanced evidencesession design; tenant tests; memory policy; access logs; isolation test results; independent test evidence; affected-person or service-impact analysis where material
AssessmentAttempt cross-user context retrieval and session fixation; verify isolation and incident detection.
Common failure modesShared conversation state, weak tenant keys, or cached context reused across unrelated cases.
Related risksS; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D3-CTL-01 — LEAST AGENCY ENFORCEMENT

FieldGovernment-sector treatment
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative titleLEAST AGENCY ENFORCEMENT
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Least Agency Enforcement, government entities should apply the control to least-agency enforcement for autonomous planning and action. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine allowed goals, actions, resources, time and spend; require explicit approval for authority expansion and enforce stop conditions.
Minimum evidenceagent authority statement; action allowlist; budget limits; intervention logs
Enhanced evidenceagent authority statement; action allowlist; budget limits; intervention logs; independent test evidence; affected-person or service-impact analysis where material
AssessmentTest out-of-scope goals and actions and confirm the agent stops or seeks authorised approval.
Common failure modesAgent capability is assumed to equal authorised agency.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY

FieldGovernment-sector treatment
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative titleINTER-AGENT COMMUNICATION SECURITY
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Inter-Agent Communication Security, government entities should apply the control to secure and authenticated inter-agent communication. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceAuthenticate agents and messages, validate schemas, apply trust boundaries, prevent confused-deputy behaviour and log delegation chains.
Minimum evidenceagent registry; message signatures; schema rules; delegation logs; trust-boundary tests
Enhanced evidenceagent registry; message signatures; schema rules; delegation logs; trust-boundary tests; independent test evidence; affected-person or service-impact analysis where material
AssessmentInject spoofed, replayed and malformed agent messages and verify rejection and traceability.
Common failure modesAgents trust names or natural-language assertions without cryptographic or policy verification.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION

FieldGovernment-sector treatment
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative titleAGENTIC PROMPT CHAINING DETECTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Agentic Prompt Chaining Detection, government entities should apply the control to detection of unsafe prompt chains and emergent multi-step action paths. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceInspect plans and intermediate steps, constrain recursion and tool sequences, and detect policy-violating chains before execution.
Minimum evidenceplan logs; chain policy; recursion limits; prohibited-sequence tests
Enhanced evidenceplan logs; chain policy; recursion limits; prohibited-sequence tests; independent test evidence; affected-person or service-impact analysis where material
AssessmentConstruct benign-looking steps that combine into a prohibited outcome and verify detection before execution.
Common failure modesControls inspect individual calls but not the cumulative effect of a chain.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D3-CTL-04 — EMBODIED AI SAFETY CONTROLS

FieldGovernment-sector treatment
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative titleEMBODIED AI SAFETY CONTROLS
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Embodied Ai Safety Controls, government entities should apply the control to safety controls for agents that influence physical or operational environments. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine operational envelopes, simulation and staged testing, human override, safe state and continuity controls before real-world action.
Minimum evidenceoperational envelope; simulation results; override tests; safe-state evidence
Enhanced evidenceoperational envelope; simulation results; override tests; safe-state evidence; independent test evidence; affected-person or service-impact analysis where material
AssessmentTest boundary violations, sensor faults and communication loss under controlled conditions.
Common failure modesDigital approval is treated as sufficient for physical deployment without hazard analysis.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION

FieldGovernment-sector treatment
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative titleMULTI-AGENT TRUST CHAIN ATTESTATION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Multi-Agent Trust Chain Attestation, government entities should apply the control to attestation of identity, capability and trust across multi-agent chains. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceRequire verifiable agent identity, approved capability claims, provenance of delegated tasks and expiry/revocation of trust.
Minimum evidenceattestation records; capability registry; delegation chain; revocation tests
Enhanced evidenceattestation records; capability registry; delegation chain; revocation tests; independent test evidence; affected-person or service-impact analysis where material
AssessmentIntroduce an untrusted or expired agent into a chain and confirm refusal and alerting.
Common failure modesTrust propagates transitively without verification or revocation.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION

FieldGovernment-sector treatment
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative titlePERSISTENT MEMORY EXFILTRATION PREVENTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Persistent Memory Exfiltration Prevention, government entities should apply the control to prevention of sensitive-data exfiltration through persistent agent memory. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceClassify memory content, minimise retention, isolate tenants, apply DLP and access controls, and test extraction through prompts and tools.
Minimum evidencememory inventory; retention rules; DLP logs; access tests; deletion evidence
Enhanced evidencememory inventory; retention rules; DLP logs; access tests; deletion evidence; independent test evidence; affected-person or service-impact analysis where material
AssessmentAttempt to retrieve another case's or user's memory and verify prevention and detection.
Common failure modesPersistent memory stores secrets or citizen data without classification, expiry or tenant isolation.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT

FieldGovernment-sector treatment
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative titleSECURE MEMORY LIFECYCLE MANAGEMENT
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Secure Memory Lifecycle Management, government entities should apply the control to secure creation, use, review, correction and deletion of agent memory. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceEstablish memory lifecycle states, provenance, correction rights, retention schedules, deletion verification and backup handling.
Minimum evidencememory lifecycle procedure; provenance logs; correction records; deletion tests
Enhanced evidencememory lifecycle procedure; provenance logs; correction records; deletion tests; independent test evidence; affected-person or service-impact analysis where material
AssessmentCreate, amend and delete test memories and verify changes propagate to indexes, caches and backups as required.
Common failure modesDeleted or corrected memory remains available to the agent through secondary stores.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE

FieldGovernment-sector treatment
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative titleAI BILL OF MATERIALS (AI BOM) MAINTENANCE
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai Bill Of Materials (Ai Bom) Maintenance, government entities should apply the control to complete AI bill of materials for models, data, code, services and tools. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceMaintain versioned inventories of models, datasets, adapters, libraries, APIs, tools, licences, owners and deployment locations.
Minimum evidenceAI BOM; dependency versions; owners; licence records; change history
Enhanced evidenceAI BOM; dependency versions; owners; licence records; change history; independent test evidence; affected-person or service-impact analysis where material
AssessmentSample deployed systems and reconcile observed dependencies to the AI BOM.
Common failure modesInventory stops at the primary model and omits retrieval stores, adapters, plugins or hosted dependencies.
Related risksP; r; o; c; u; r; e; m; e; n; t; ; a; n; d; ; v; e; n; d; o; r; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING

FieldGovernment-sector treatment
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative titleMODEL FILE & ARTIFACT SCANNING
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Model File & Artifact Scanning, government entities should apply the control to malware, secrets, unsafe deserialisation and integrity scanning of model artifacts. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceScan files in quarantine, verify hashes/signatures, block unsafe formats and retain scan results before promotion.
Minimum evidencequarantine logs; scanner outputs; hashes; format policy; release approval
Enhanced evidencequarantine logs; scanner outputs; hashes; format policy; release approval; independent test evidence; affected-person or service-impact analysis where material
AssessmentSubmit altered, malicious and unsafe-serialisation artifacts and verify quarantine and block.
Common failure modesArtifacts are downloaded directly into production or scans exclude large model files.
Related risksP; r; o; c; u; r; e; m; e; n; t; ; a; n; d; ; v; e; n; d; o; r; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D4-CTL-03 — MODEL HUB & REGISTRY VETTING

FieldGovernment-sector treatment
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative titleMODEL HUB & REGISTRY VETTING
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Model Hub & Registry Vetting, government entities should apply the control to governance of model hubs, registries and provenance sources. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceApprove registries and publishers, verify identity and licence, pin versions, monitor takedowns and preserve acquisition evidence.
Minimum evidenceapproved registry list; publisher verification; acquisition record; licence review; takedown monitoring
Enhanced evidenceapproved registry list; publisher verification; acquisition record; licence review; takedown monitoring; independent test evidence; affected-person or service-impact analysis where material
AssessmentAttempt acquisition from an unapproved or impersonated source and verify prevention.
Common failure modesPopularity or download count is treated as assurance.
Related risksP; r; o; c; u; r; e; m; e; n; t; ; a; n; d; ; v; e; n; d; o; r; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING

FieldGovernment-sector treatment
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative titleMCP SERVER BEHAVIORAL MONITORING
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Mcp Server Behavioral Monitoring, government entities should apply the control to behavioural monitoring of Model Context Protocol and comparable tool servers. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceInventory servers and exposed tools, authenticate connections, constrain permissions, monitor changes and anomalous calls, and support rapid disablement.
Minimum evidenceserver inventory; tool schemas; permissions; monitoring alerts; disable test
Enhanced evidenceserver inventory; tool schemas; permissions; monitoring alerts; disable test; independent test evidence; affected-person or service-impact analysis where material
AssessmentChange a server tool or return malicious content and verify detection, containment and revocation.
Common failure modesMCP servers are treated as passive data sources rather than privileged execution dependencies.
Related risksP; r; o; c; u; r; e; m; e; n; t; ; a; n; d; ; v; e; n; d; o; r; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT

FieldGovernment-sector treatment
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative titleTHIRD-PARTY AI API SECURITY ASSESSMENT
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Third-Party Ai Api Security Assessment, government entities should apply the control to security assessment of third-party AI APIs. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceAssess data handling, authentication, rate limits, logging, residency, model changes, incident notification and exit arrangements before use.
Minimum evidencesupplier assessment; data-flow map; contract clauses; API test results; exit plan
Enhanced evidencesupplier assessment; data-flow map; contract clauses; API test results; exit plan; independent test evidence; affected-person or service-impact analysis where material
AssessmentVerify supplier controls and simulate service/model change and incident notification workflows.
Common failure modesAPI use begins under standard SaaS terms with no AI-specific evidence or change rights.
Related risksP; r; o; c; u; r; e; m; e; n; t; ; a; n; d; ; v; e; n; d; o; r; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE

FieldGovernment-sector treatment
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative titleSHADOW AI DISCOVERY & GOVERNANCE
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Shadow Ai Discovery & Governance, government entities should apply the control to discovery and governance of unapproved or shadow AI use. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceUse network, identity, expense, browser and endpoint signals consistent with law and policy; provide approved alternatives and remediation paths.
Minimum evidencediscovery method; approved-service register; findings; remediation and exception records
Enhanced evidencediscovery method; approved-service register; findings; remediation and exception records; independent test evidence; affected-person or service-impact analysis where material
AssessmentSeed a controlled unapproved service and confirm detection, triage and proportionate response.
Common failure modesDiscovery relies only on staff self-reporting or suppresses use without providing safe alternatives.
Related risksP; r; o; c; u; r; e; m; e; n; t; ; a; n; d; ; v; e; n; d; o; r; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA)

FieldGovernment-sector treatment
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative titleAI SOFTWARE COMPOSITION ANALYSIS (SCA)
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai Software Composition Analysis (Sca), government entities should apply the control to software composition analysis for AI applications and supporting stacks. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceScan code, containers and dependencies; correlate vulnerabilities with reachability and AI-specific exposure; track remediation and exceptions.
Minimum evidenceSBOM/SCA results; reachability analysis; remediation tickets; exception approvals
Enhanced evidenceSBOM/SCA results; reachability analysis; remediation tickets; exception approvals; independent test evidence; affected-person or service-impact analysis where material
AssessmentIntroduce a vulnerable reachable dependency and verify detection, prioritisation and closure.
Common failure modesSCA excludes notebooks, model-serving images, GPU libraries or generated code.
Related risksP; r; o; c; u; r; e; m; e; n; t; ; a; n; d; ; v; e; n; d; o; r; ;; ; S; e; c; u; r; i; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D5-CTL-01 — HARMFUL CONTENT BLOCKING

FieldGovernment-sector treatment
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative titleHARMFUL CONTENT BLOCKING
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Harmful Content Blocking, government entities should apply the control to blocking or safe handling of harmful content within lawful government purpose. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine prohibited and restricted content by use case, test over- and under-blocking, support escalation and preserve lawful access and records duties.
Minimum evidencecontent policy; evaluation set; false-positive/negative analysis; escalation logs
Enhanced evidencecontent policy; evaluation set; false-positive/negative analysis; escalation logs; independent test evidence; affected-person or service-impact analysis where material
AssessmentTest harmful and legitimate edge cases, including protected speech and statutory-service contexts.
Common failure modesA generic vendor safety filter is used without government-purpose calibration or appeal.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D5-CTL-02 — PII LEAKAGE PREVENTION

FieldGovernment-sector treatment
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative titlePII LEAKAGE PREVENTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Pii Leakage Prevention, government entities should apply the control to prevention of personal and protected information leakage. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceClassify data, minimise prompts and context, apply DLP and output checks, isolate tenants and test memorisation or retrieval leakage.
Minimum evidencedata-flow map; DLP rules; leakage tests; access logs; incident records
Enhanced evidencedata-flow map; DLP rules; leakage tests; access logs; incident records; independent test evidence; affected-person or service-impact analysis where material
AssessmentUse canary identifiers and cross-tenant tests to verify prevention and alerting.
Common failure modesSensitive data is placed in prompts because the supplier claims not to train on it.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D5-CTL-03 — COPYRIGHT DETECTION

FieldGovernment-sector treatment
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative titleCOPYRIGHT DETECTION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Copyright Detection, government entities should apply the control to copyright and rights-risk detection for inputs and outputs. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceRecord source and licence constraints, screen outputs where appropriate, provide review for publication and retain attribution or permission evidence.
Minimum evidencerights register; licence records; output review; attribution/permission evidence
Enhanced evidencerights register; licence records; output review; attribution/permission evidence; independent test evidence; affected-person or service-impact analysis where material
AssessmentTest representative copyrighted inputs and publication workflows; verify escalation for uncertain rights.
Common failure modesAutomated similarity detection is treated as a legal conclusion.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D5-CTL-04 — AI WATERMARKING ROBUSTNESS

FieldGovernment-sector treatment
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative titleAI WATERMARKING ROBUSTNESS
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai Watermarking Robustness, government entities should apply the control to robust provenance and disclosure for AI-generated government content. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceApply durable provenance metadata or disclosure appropriate to channel, test transformations and define exceptions for security or accessibility.
Minimum evidencecontent provenance records; disclosure policy; transformation tests; exception approvals
Enhanced evidencecontent provenance records; disclosure policy; transformation tests; exception approvals; independent test evidence; affected-person or service-impact analysis where material
AssessmentResize, transcode and repost marked content and verify provenance/disclosure remains usable.
Common failure modesWatermarking is claimed to prove authenticity without key, custody and verification controls.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION

FieldGovernment-sector treatment
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative titlePRIVACY-BY-DESIGN VERIFICATION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Privacy-By-Design Verification, government entities should apply the control to privacy-by-design throughout purpose, data, architecture and lifecycle decisions. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDocument purpose and lawful basis, minimise data, assess privacy impacts, implement rights and retention controls, and review changes.
Minimum evidenceprivacy impact assessment; minimisation record; retention schedule; rights workflow
Enhanced evidenceprivacy impact assessment; minimisation record; retention schedule; rights workflow; independent test evidence; affected-person or service-impact analysis where material
AssessmentTrace a data subject request and a purpose change through the system and verify controls.
Common failure modesPrivacy is reviewed only at procurement or after deployment.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION

FieldGovernment-sector treatment
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative titlePRIVACY-PRESERVING ML VALIDATION
ApplicabilityApplicable with Government Interpretation
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Privacy-Preserving Ml Validation, government entities should apply the control to validation of privacy-preserving machine-learning techniques and their limits. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine the privacy threat model, parameters and utility trade-offs; test attacks relevant to the chosen technique and monitor configuration drift.
Minimum evidencethreat model; parameter record; attack tests; utility analysis; approval
Enhanced evidencethreat model; parameter record; attack tests; utility analysis; approval; independent test evidence; affected-person or service-impact analysis where material
AssessmentRun membership, reconstruction or linkage tests as applicable and verify claimed protection.
Common failure modesUse of differential privacy, federated learning or synthetic data is asserted without measured guarantees.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS

FieldGovernment-sector treatment
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative titleHUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Human-In-The-Loop For High-Risk Actions, government entities should apply the control to effective human control over high-impact or irreversible actions. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceIdentify decisions requiring human authority, ensure reviewers have competence, time, evidence and power to change outcomes, and test override effectiveness.
Minimum evidencedecision-rights matrix; reviewer training; review logs; override tests; quality metrics
Enhanced evidencedecision-rights matrix; reviewer training; review logs; override tests; quality metrics; independent test evidence; affected-person or service-impact analysis where material
AssessmentSample decisions and confirm meaningful independent review, reasons and correction capability.
Common failure modesA click-through approval is counted as human oversight.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D6-CTL-02 — AUDIT TRAIL COMPLETENESS

FieldGovernment-sector treatment
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative titleAUDIT TRAIL COMPLETENESS
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Audit Trail Completeness, government entities should apply the control to complete and reconstructable audit trails. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceLog inputs, outputs, model/version, retrieval context, tools, approvals, changes and outcomes with integrity, access and retention controls.
Minimum evidencelogging standard; sample logs; integrity controls; retention evidence; reconstruction test
Enhanced evidencelogging standard; sample logs; integrity controls; retention evidence; reconstruction test; independent test evidence; affected-person or service-impact analysis where material
AssessmentReconstruct a material decision end-to-end from retained records.
Common failure modesLogs omit prompts, retrieval sources, tool actions or human edits needed to explain the outcome.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D6-CTL-03 — AI MODEL CARD COMPLETENESS

FieldGovernment-sector treatment
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative titleAI MODEL CARD COMPLETENESS
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai Model Card Completeness, government entities should apply the control to complete, current and decision-useful model and system cards. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDocument purpose, limitations, data, performance, risks, authority level, dependencies, monitoring and change history; update after material change.
Minimum evidenceapproved system card; review history; linked evaluations; change records
Enhanced evidenceapproved system card; review history; linked evaluations; change records; independent test evidence; affected-person or service-impact analysis where material
AssessmentCompare the card with the deployed system and verify accuracy and currency.
Common failure modesModel cards repeat supplier marketing and omit local use, limitations or modifications.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D6-CTL-04 — AI INCIDENT RESPONSE READINESS

FieldGovernment-sector treatment
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative titleAI INCIDENT RESPONSE READINESS
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai Incident Response Readiness, government entities should apply the control to AI-specific incident readiness integrated with government escalation. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine triggers, roles, evidence preservation, citizen-impact response, supplier coordination, notification and lessons learned.
Minimum evidenceincident plan; exercises; contact list; evidence procedure; corrective-action log
Enhanced evidenceincident plan; exercises; contact list; evidence procedure; corrective-action log; independent test evidence; affected-person or service-impact analysis where material
AssessmentRun a tabletop covering harmful output, data exposure and unauthorised action.
Common failure modesAI incidents are forced into generic cyber playbooks with no affected-person or model-change response.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING

FieldGovernment-sector treatment
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative titleMODEL DEPRECATION & DECOMMISSIONING
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Model Deprecation & Decommissioning, government entities should apply the control to controlled model deprecation and system decommissioning. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidancePlan replacement, notice, records preservation, data and credential removal, dependency closure, citizen continuity and post-retirement monitoring.
Minimum evidencedecommission plan; migration record; deletion evidence; archive record; dependency closure
Enhanced evidencedecommission plan; migration record; deletion evidence; archive record; dependency closure; independent test evidence; affected-person or service-impact analysis where material
AssessmentRetire a test component and verify no residual access, calls or unsupported dependencies remain.
Common failure modesA model is disabled but data, keys, endpoints and downstream references remain active.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE

FieldGovernment-sector treatment
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative titleTHIRD-PARTY AI VENDOR GOVERNANCE
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Third-Party Ai Vendor Governance, government entities should apply the control to ongoing governance of third-party AI vendors. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceAssign accountable owners, monitor evidence and changes, enforce audit/incident rights, manage subcontractors and maintain exit capability.
Minimum evidencevendor register; review cadence; contract evidence; change notices; exit test
Enhanced evidencevendor register; review cadence; contract evidence; change notices; exit test; independent test evidence; affected-person or service-impact analysis where material
AssessmentReview a material supplier change and verify risk reassessment and approval before use.
Common failure modesInitial due diligence is treated as permanent assurance.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY

FieldGovernment-sector treatment
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative titleAI RESILIENCE & BUSINESS CONTINUITY
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai Resilience & Business Continuity, government entities should apply the control to resilience and continuity of AI-enabled public services. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine service tolerances, manual alternatives, degraded modes, backup dependencies, recovery objectives and exercise results.
Minimum evidencecontinuity plan; manual procedure; dependency map; recovery test; lessons learned
Enhanced evidencecontinuity plan; manual procedure; dependency map; recovery test; lessons learned; independent test evidence; affected-person or service-impact analysis where material
AssessmentSimulate model/API outage and data-quality degradation and verify essential service continuity.
Common failure modesContinuity assumes the same unavailable AI supplier or omits staff capacity for manual fallback.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l; ;; ; O; p; e; r; a; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION

FieldGovernment-sector treatment
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative titleAI-GENERATED PHISHING SIMULATION
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai-Generated Phishing Simulation, government entities should apply the control to safe simulation of AI-generated phishing for workforce preparedness. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceAuthorise scope, protect participants, avoid real credential capture, measure learning and prevent simulation content from escaping.
Minimum evidenceexercise approval; scenario design; participant safeguards; metrics; deletion evidence
Enhanced evidenceexercise approval; scenario design; participant safeguards; metrics; deletion evidence; independent test evidence; affected-person or service-impact analysis where material
AssessmentConfirm simulations cannot collect live secrets or send outside approved recipients.
Common failure modesRealistic simulation is prioritised over proportionality, consent/policy and data protection.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D7-CTL-H02 — DEEPFAKE DETECTION TRAINING

FieldGovernment-sector treatment
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative titleDEEPFAKE DETECTION TRAINING
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Deepfake Detection Training, government entities should apply the control to workforce capability to detect and escalate deepfakes. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceTrain staff using role-relevant media, verification channels and escalation procedures; test performance and refresh for emerging techniques.
Minimum evidencetraining materials; attendance; exercise results; escalation logs
Enhanced evidencetraining materials; attendance; exercise results; escalation logs; independent test evidence; affected-person or service-impact analysis where material
AssessmentRun controlled deepfake recognition and verification exercises for high-risk roles.
Common failure modesTraining focuses on visual artefacts only and omits process verification.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION

FieldGovernment-sector treatment
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative titleOUT-OF-BAND AUTHENTICATION
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Out-Of-Band Authentication, government entities should apply the control to independent authentication for high-risk requests and communications. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceRequire out-of-band verification through a separately controlled channel for payments, credentials, sensitive disclosure and authority changes.
Minimum evidenceauthentication procedure; protected contact registry; verification logs; exception records
Enhanced evidenceauthentication procedure; protected contact registry; verification logs; exception records; independent test evidence; affected-person or service-impact analysis where material
AssessmentSimulate spoofed executive or citizen requests and verify independent confirmation.
Common failure modesThe second channel relies on contact details supplied in the suspicious message.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D7-CTL-H04 — AI SOCIAL ENGINEERING IR

FieldGovernment-sector treatment
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative titleAI SOCIAL ENGINEERING IR
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai Social Engineering Ir, government entities should apply the control to incident response for AI-enabled social engineering. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceInclude deepfake, synthetic identity, automated targeting and impersonation in triage, containment, evidence and communications plans.
Minimum evidenceplaybook; exercises; evidence checklist; coordination records
Enhanced evidenceplaybook; exercises; evidence checklist; coordination records; independent test evidence; affected-person or service-impact analysis where material
AssessmentRun a scenario combining synthetic media and credential abuse and verify coordinated response.
Common failure modesCases are classified only as user error and synthetic evidence is not preserved.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE

FieldGovernment-sector treatment
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative titleAI-ENHANCED EXTERNAL ATTACK DEFENSE
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Ai-Enhanced External Attack Defense, government entities should apply the control to defence against AI-enhanced external attacks. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceUse threat intelligence to adapt detection, rate limits, identity controls and response for automated reconnaissance, exploitation and evasion.
Minimum evidencethreat model; detection updates; exercise results; incident metrics
Enhanced evidencethreat model; detection updates; exercise results; incident metrics; independent test evidence; affected-person or service-impact analysis where material
AssessmentExercise high-volume adaptive attacks and verify detection and service protection.
Common failure modesClaims of 'AI-powered attack' are accepted without evidence, or controls focus on attribution rather than observable behaviour.
Related risksR; i; g; h; t; s; ; a; n; d; ; p; u; b; l; i; c; ; i; m; p; a; c; t; ;; ; D; e; m; o; c; r; a; t; i; c; ; a; n; d; ; i; n; s; t; i; t; u; t; i; o; n; a; l
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D8-CTL-01 — EU AI ACT RISK TIER MAPPING

FieldGovernment-sector treatment
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative titleEU AI ACT RISK TIER MAPPING
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Eu Ai Act Risk Tier Mapping, government entities should apply the control to documented mapping to the EU AI Act where the organisation and use are legally in scope. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceIdentify actor role, system classification, applicable dates and obligations using current official text; obtain qualified legal review and avoid globalising EU requirements.
Minimum evidencejurisdiction map; legal applicability record; system classification; review date
Enhanced evidencejurisdiction map; legal applicability record; system classification; review date; independent test evidence; affected-person or service-impact analysis where material
AssessmentSample systems and verify role, risk classification and effective-date assumptions against official sources.
Common failure modesThe EU AI Act is treated as universally applicable or a framework mapping is presented as legal compliance.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; L; e; g; a; l; ; a; n; d; ; p; o; l; i; c; y; ; d; e; p; e; n; d; e; n; c; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D8-CTL-02 — ISO 42001 GAP ANALYSIS

FieldGovernment-sector treatment
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative titleISO 42001 GAP ANALYSIS
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Iso 42001 Gap Analysis, government entities should apply the control to gap analysis against ISO/IEC 42001 without equating mapping to certification. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine scope, compare requirements to implemented practices, record objective evidence, gaps and treatment, and use licensed standard text appropriately.
Minimum evidencescope statement; gap matrix; evidence references; remediation plan
Enhanced evidencescope statement; gap matrix; evidence references; remediation plan; independent test evidence; affected-person or service-impact analysis where material
AssessmentVerify sampled 'met' ratings against objective evidence and current standard edition.
Common failure modesSelf-assessment is labelled certification or controls are inferred from secondary summaries.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; L; e; g; a; l; ; a; n; d; ; p; o; l; i; c; y; ; d; e; p; e; n; d; e; n; c; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION

FieldGovernment-sector treatment
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative titleGPAI TECHNICAL DOCUMENTATION VERIFICATION
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Gpai Technical Documentation Verification, government entities should apply the control to verification of technical documentation obligations for general-purpose AI where applicable. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDetermine provider/deployer role, preserve model and system documentation, limitations, evaluation and downstream information, and obtain legal review for applicability.
Minimum evidencerole assessment; technical documentation; evaluation summary; downstream notices; update history
Enhanced evidencerole assessment; technical documentation; evaluation summary; downstream notices; update history; independent test evidence; affected-person or service-impact analysis where material
AssessmentTrace required documentation through a material model update and downstream deployment.
Common failure modesGeneric model cards are assumed to satisfy all GPAI legal obligations.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; L; e; g; a; l; ; a; n; d; ; p; o; l; i; c; y; ; d; e; p; e; n; d; e; n; c; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)

FieldGovernment-sector treatment
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative titleDORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Dora Ict Incident Reporting (Financial Sector), government entities should apply the control to incident-reporting readiness for DORA only where financial-sector scope applies, while applying the underlying reporting discipline elsewhere. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDocument whether DORA applies; if not, map incident classification, timelines, evidence and notification to the governing public-sector regime.
Minimum evidencescope decision; reporting matrix; incident classification; notification records
Enhanced evidencescope decision; reporting matrix; incident classification; notification records; independent test evidence; affected-person or service-impact analysis where material
AssessmentTest classification and timed escalation under the applicable regime; verify DORA references are not used outside scope.
Common failure modesThe authoritative title is read as imposing DORA on every government system.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; L; e; g; a; l; ; a; n; d; ; p; o; l; i; c; y; ; d; e; p; e; n; d; e; n; c; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK

FieldGovernment-sector treatment
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative titleNIST SP 800-218A COMPLIANCE CHECK
ApplicabilityApplicable with Enhanced Evidence
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Nist Sp 800-218A Compliance Check, government entities should apply the control to secure AI software development alignment with NIST SP 800-218A or another authorised regime. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceMap AI development practices to the selected secure-development framework, retain evidence and document deviations; verify current edition and applicability.
Minimum evidenceframework mapping; secure-development records; test evidence; deviation approvals
Enhanced evidenceframework mapping; secure-development records; test evidence; deviation approvals; independent test evidence; affected-person or service-impact analysis where material
AssessmentSample releases and trace requirements through design, build, test, deployment and response.
Common failure modesA checklist is completed without evidence or is applied to acquired services as though the agency developed them.
Related risksA; u; t; h; o; r; i; t; y; ; a; n; d; ; l; e; g; a; l; i; t; y; ;; ; L; e; g; a; l; ; a; n; d; ; p; o; l; i; c; y; ; d; e; p; e; n; d; e; n; c; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT

FieldGovernment-sector treatment
DomainD9: PHYSICAL AI SAFETY
Authoritative titlePHYSICAL HARM BOUNDARY ENFORCEMENT
ApplicabilityContext Dependent
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Physical Harm Boundary Enforcement, government entities should apply the control to enforcement of physical safety and harm boundaries. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine hazards, operating envelope, prohibited states and independent safety constraints; validate before live operation.
Minimum evidencehazard analysis; boundary specification; independent interlocks; test results
Enhanced evidencehazard analysis; boundary specification; independent interlocks; test results; independent test evidence; affected-person or service-impact analysis where material
AssessmentAttempt boundary violations and sensor anomalies and verify safe prevention.
Common failure modesSafety limits exist only in the AI policy layer that can fail with the model.
Related risksP; h; y; s; i; c; a; l; ; s; a; f; e; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION

FieldGovernment-sector treatment
DomainD9: PHYSICAL AI SAFETY
Authoritative titleSAFE STATE AND GRACEFUL DEGRADATION
ApplicabilityContext Dependent
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Safe State And Graceful Degradation, government entities should apply the control to transition to a safe state and graceful degradation. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceDefine safe states for loss of model, data, communications or power; preserve essential service where possible and test degraded modes.
Minimum evidencesafe-state design; degraded-mode procedure; failure tests; recovery records
Enhanced evidencesafe-state design; degraded-mode procedure; failure tests; recovery records; independent test evidence; affected-person or service-impact analysis where material
AssessmentInduce dependency failures and verify timely safe transition and controlled recovery.
Common failure modesFail-safe behaviour creates a different public-safety or service-continuity hazard.
Related risksP; h; y; s; i; c; a; l; ; s; a; f; e; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP

FieldGovernment-sector treatment
DomainD9: PHYSICAL AI SAFETY
Authoritative titleHUMAN OVERRIDE AND EMERGENCY STOP
ApplicabilityContext Dependent
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Human Override And Emergency Stop, government entities should apply the control to effective human override and emergency stop. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceProvide accessible, independent and tested override mechanisms with clear authority, training and post-event logging.
Minimum evidenceoverride design; authority matrix; training; test logs; maintenance records
Enhanced evidenceoverride design; authority matrix; training; test logs; maintenance records; independent test evidence; affected-person or service-impact analysis where material
AssessmentTest override under realistic load, communications loss and partial system failure.
Common failure modesEmergency stop is inaccessible, shares the failed control path or is not maintained.
Related risksP; h; y; s; i; c; a; l; ; s; a; f; e; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION

FieldGovernment-sector treatment
DomainD9: PHYSICAL AI SAFETY
Authoritative titleCYBER-PHYSICAL ATTACK DETECTION
ApplicabilityContext Dependent
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Cyber-Physical Attack Detection, government entities should apply the control to detection and response to cyber-physical attacks. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceCorrelate cyber, sensor, actuator and process signals; define containment that protects people and services; preserve evidence.
Minimum evidencethreat model; correlated monitoring; response playbook; exercise evidence
Enhanced evidencethreat model; correlated monitoring; response playbook; exercise evidence; independent test evidence; affected-person or service-impact analysis where material
AssessmentSimulate spoofed sensors and malicious commands and verify detection and safe containment.
Common failure modesCyber and operational monitoring remain siloed and neither sees the complete attack.
Related risksP; h; y; s; i; c; a; l; ; s; a; f; e; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING

FieldGovernment-sector treatment
DomainD9: PHYSICAL AI SAFETY
Authoritative titlePHYSICAL ENVIRONMENT INTEGRITY MONITORING
ApplicabilityContext Dependent
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Physical Environment Integrity Monitoring, government entities should apply the control to integrity monitoring of the physical environment and sensing context. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceValidate sensor provenance, calibration, redundancy and environmental assumptions; detect tampering and implausible conditions.
Minimum evidencesensor inventory; calibration records; redundancy tests; tamper alerts
Enhanced evidencesensor inventory; calibration records; redundancy tests; tamper alerts; independent test evidence; affected-person or service-impact analysis where material
AssessmentManipulate or obstruct sensors and verify plausibility checks and escalation.
Common failure modesThe AI trusts sensor readings without independent checks or maintenance evidence.
Related risksP; h; y; s; i; c; a; l; ; s; a; f; e; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D9-CTL-06 — ACTUATOR COMMAND VERIFICATION

FieldGovernment-sector treatment
DomainD9: PHYSICAL AI SAFETY
Authoritative titleACTUATOR COMMAND VERIFICATION
ApplicabilityContext Dependent
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Actuator Command Verification, government entities should apply the control to verification of actuator commands before execution. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceAuthenticate commands, validate ranges and sequences, enforce rate and safety limits, and use independent interlocks for hazardous actions.
Minimum evidencecommand schema; authentication logs; safety rules; interlock tests
Enhanced evidencecommand schema; authentication logs; safety rules; interlock tests; independent test evidence; affected-person or service-impact analysis where material
AssessmentSubmit replayed, malformed, out-of-sequence and unsafe commands and verify rejection.
Common failure modesNatural-language or model-generated commands reach actuators without deterministic validation.
Related risksP; h; y; s; i; c; a; l; ; s; a; f; e; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION

FieldGovernment-sector treatment
DomainD9: PHYSICAL AI SAFETY
Authoritative titlePHYSICAL INCIDENT EVIDENCE PRESERVATION
ApplicabilityContext Dependent
RationaleThe control remains in the 59-control baseline. Government implementation depends on documented system scope, decision consequence, jurisdiction, data sensitivity, and operating context.
Government interpretationFor Physical Incident Evidence Preservation, government entities should apply the control to preservation of evidence after physical-AI incidents. The accountable public body retains decision and assurance responsibility even when a supplier operates the technology.
Implementation guidanceSynchronise time, retain cyber and physical logs, protect chain of custody, capture configuration and support safety/legal investigations.
Minimum evidenceevidence plan; time-sync evidence; sealed logs; custody records; configuration snapshot
Enhanced evidenceevidence plan; time-sync evidence; sealed logs; custody records; configuration snapshot; independent test evidence; affected-person or service-impact analysis where material
AssessmentRun an incident exercise and verify complete, tamper-evident evidence can be reconstructed.
Common failure modesVolatile model, sensor or actuator evidence is overwritten before investigators can preserve it.
Related risksP; h; y; s; i; c; a; l; ; s; a; f; e; t; y; ;; ; O; p; e; r; a; t; i; o; n; a; l; ;; ; P; u; b; l; i; c; -; s; e; r; v; i; c; e; ; c; o; n; t; i; n; u; i; t; y
Legal/policy dependencyJ; u; r; i; s; d; i; c; t; i; o; n; -; s; p; e; c; i; f; i; c; ; p; u; b; l; i; c; ; l; a; w; ,; ; r; e; c; o; r; d; s; ,; ; p; r; i; v; a; c; y; ,; ; p; r; o; c; u; r; e; m; e; n; t; ,; ; a; c; c; e; s; s; i; b; i; l; i; t; y; ,; ; c; y; b; e; r; s; e; c; u; r; i; t; y; ,; ; s; e; c; t; o; r; ,; ; a; n; d; ; a; g; e; n; c; y; ; r; e; q; u; i; r; e; m; e; n; t; s; .

16. Assessment Model

Assessment dimensionQuestion
Design adequacyCan the control design address the documented risk and authority model?
Implementation completenessAre required people, process, technology, supplier, and records elements present?
Operating effectivenessDid the control work consistently during the assessment period and scenarios?
Evidence sufficiencyIs evidence authentic, complete, attributable, timely, and reproducible?
Residual riskWhat material risk remains, who accepted it, and when is review due?
Legal/policy dependencyWhich conclusions require qualified jurisdiction-specific review?

17. Implementation Maturity Model

LevelObservable characteristics
1 — InitialInventories incomplete; controls reactive; ownership unclear; evidence inconsistent.
2 — DefinedPolicies, roles, classification, procedures, and minimum evidence documented.
3 — ImplementedControls operate across in-scope systems; suppliers and exceptions governed.
4 — MeasuredEffectiveness, disparities, incidents, appeals, overrides, and metrics reviewed.
5 — AdaptiveThreats, complaints, audits, incidents, legal changes, and performance drive improvement.

Documentation volume is not maturity.

18. Phased Implementation Roadmap

TimeframePhaseRequired outcomes
0–30 daysEstablish authority and scopeInventory systems and suppliers; assign owners; classify use cases; constrain unacceptable use.
31–60 daysEstablish minimum controlsImplement access, logging, data restrictions, review rules, supplier clauses, incident reporting, and evidence retention.
61–90 daysValidate operationTest security, oversight, notice, contestability, fallback, supplier evidence, and reconstruction.
3–6 monthsInstitutionalise assurancePeriodic assessment, model-change governance, independent review, reporting, remediation.
6–12 monthsImprove and adaptUse incidents, appeals, complaints, audits, threat intelligence, and performance data.

19. Worked Examples

19.1 Citizen-service chatbot

ElementTreatment
Decision-authority levelLevel 2
Context and roleAnswers service questions and triages cases; it cannot determine eligibility or alter an official record.
Material risksDirect or indirect prompt injection, inaccurate advice, sensitive-data disclosure, inaccessible interaction, and false attribution of authority.
Required safeguardsApproved knowledge base; untrusted-content isolation; disclosure that the service is automated; privacy controls; accessible human channel; query and output monitoring.
EvidenceKnowledge-source approvals; injection tests; privacy assessment; accessibility test; escalation logs; sampled-answer review.
Failure scenarioA webpage retrieved by the assistant contains hidden instructions that cause the chatbot to disclose case details or provide unauthorised procedural advice.
Detection and responseIndirect-injection monitoring or a complaint identifies the issue; disable affected retrieval sources, preserve prompts and logs, notify the service owner, correct published advice, assess affected users, and retest before restoration.
Notably AbsentNo claim is made that every citizen chatbot is high risk or that disclosure alone makes inaccurate advice safe.

19.2 Benefits eligibility support

ElementTreatment
Decision-authority levelLevel 4
Context and roleRanks or recommends benefit eligibility cases; an authorised official must determine entitlement and provide reasons.
Material risksDisparate denial or delay, unlawful delegation, stale data, automation bias, inadequate notice, and ineffective appeal.
Required safeguardsDocumented legal authority; cohort testing; independent review; reasons and notice; appeal route; correction workflow; manual fallback.
EvidenceAuthority assessment; data provenance; impact analysis; cohort metrics; reviewer records; decision notices; appeal outcomes.
Failure scenarioA historical proxy variable suppresses eligibility recommendations for a protected community, and reviewers routinely accept the score without examining evidence.
Detection and responseDisparity monitoring or appeal data triggers investigation; suspend the affected rule/model, identify and correct decisions, notify accountable officials, validate revised features, and provide redress where required.
Notably AbsentNominal human approval is not treated as evidence of meaningful oversight, and no universal fairness threshold is asserted.

19.3 Tax audit prioritisation

ElementTreatment
Decision-authority levelLevel 4
Context and rolePrioritises taxpayers for audit; the model does not establish liability and selection must remain legally authorised and reviewable.
Material risksBiased selection, opaque risk factors, strategic gaming, data incompatibility, excessive scrutiny, and inability to explain selection.
Required safeguardsFeature and purpose review; protected-attribute/proxy analysis; calibrated thresholds; reason codes; sampling of low-score cases; independent audit.
EvidenceSelection policy; model card; feature approvals; disparity and calibration tests; reviewer decisions; challenge outcomes.
Failure scenarioA geographic proxy concentrates audits in a community without a defensible risk relationship and without review of disparate impact.
Detection and responseSelection-distribution monitoring identifies concentration; freeze the model-assisted queue, conduct legal and statistical review, re-run affected selections, document corrections, and update governance thresholds.
Notably AbsentThe example does not assert that risk scoring is unlawful per se or that equal selection rates are always the correct benchmark.

19.4 Fraud detection

ElementTreatment
Decision-authority levelLevel 3
Context and roleFlags potential fraud for investigation but cannot block payment, impose sanctions, or create an adverse finding automatically.
Material risksFalse positives, adversarial evasion, sensitive-data leakage, confirmation bias, and excessive investigative burden.
Required safeguardsCase-evidence review; calibrated alert thresholds; feedback controls; adversarial testing; separation between alert and adverse action.
EvidenceAlert logic; precision/recall by segment; investigation outcomes; override reasons; adversarial tests; incident records.
Failure scenarioFraud actors learn a stable threshold and alter claims just below it, while the system continues to report apparently strong historical performance.
Detection and responseOutcome drift and threat intelligence reveal evasion; rotate detection features under change control, preserve affected cases, conduct retrospective sampling, and validate that new controls do not increase unjustified false positives.
Notably AbsentNo claim is made that every flagged case is fraudulent or that high aggregate accuracy establishes lawful investigation.

19.5 Permit processing

ElementTreatment
Decision-authority levelLevel 4
Context and roleChecks permit applications and recommends approval, refusal, or further evidence; an authorised officer owns the decision.
Material risksIncorrect refusal, missing statutory discretion, inaccessible submissions, inconsistent local rules, and weak reasons.
Required safeguardsCurrent rule base; jurisdiction and date controls; exception routing; reason generation tied to evidence; human sign-off; appeal and correction.
EvidenceRule provenance; policy-change log; test cases; officer review; notices; appeals; correction records.
Failure scenarioA planning-rule update is not propagated, causing compliant applications to be recommended for refusal under superseded criteria.
Detection and responseChange reconciliation or applicant challenge identifies the defect; stop automated recommendations, identify affected applications, issue corrected decisions or notices, update and validate the rule base, and record the incident.
Notably AbsentThe example does not assume that codified rules eliminate statutory discretion or local variation.

19.6 Procurement assistant

ElementTreatment
Decision-authority levelLevel 3
Context and roleSummarises bids and highlights risks; it cannot score, exclude, negotiate, or award without authorised procurement officials.
Material risksConfidential bid leakage, hallucinated criteria, supplier bias, prompt injection in bid documents, and inadequate auditability.
Required safeguardsIsolated document processing; approved criteria; no cross-bid leakage; source-linked summaries; conflict checks; procurement review.
EvidenceData-flow map; bid isolation tests; criteria configuration; source citations; reviewer changes; access logs.
Failure scenarioA bidder embeds instructions in a proposal that cause the assistant to suppress competitor risks and promote its own submission.
Detection and responseIndirect-injection testing or anomalous summary review detects manipulation; quarantine the document, regenerate summaries in a clean environment, inform procurement integrity personnel, preserve evidence, and assess whether the process must be repeated.
Notably AbsentNo supplier ranking or award is presumed valid because it was reviewed after generation.

19.7 Public-records classification

ElementTreatment
Decision-authority levelLevel 3
Context and roleClassifies and routes records for retention, disclosure review, or archival processing; legal disposition remains governed by records authorities.
Material risksMisclassification, premature deletion, hidden personal data, disclosure error, and loss of decision reconstruction.
Required safeguardsAuthoritative schedule mapping; confidence thresholds; human review for destructive or disclosure actions; immutable logs; sampling.
EvidenceRecords schedule mapping; labelled test corpus; error analysis; disposition approvals; audit logs; restoration test.
Failure scenarioLow-confidence records are automatically assigned a short retention category and deleted before a public-records request is processed.
Detection and responseSampling or request reconciliation detects missing records; halt automated disposition, restore recoverable records, notify records and legal owners, investigate scope, correct classifications, and strengthen destructive-action approvals.
Notably AbsentAutomation does not replace statutory records authority, and classifier confidence does not establish legal disposition.

19.8 Emergency resource allocation

ElementTreatment
Decision-authority levelLevel 4
Context and roleRecommends emergency resource allocation under time pressure; incident command retains authority and must be able to override.
Material risksUnequal service, stale situational data, communications loss, unsafe optimisation, and inability to operate manually.
Required safeguardsPredefined objectives and constraints; real-time data quality checks; command approval; manual fallback; degraded-mode exercises; post-event review.
EvidenceAuthority plan; data feeds; allocation logs; override records; continuity exercise; after-action report.
Failure scenarioA communications outage makes one district appear to have low demand, diverting resources away from a severely affected population.
Detection and responseData-quality alarms and field reports trigger degraded mode; incident command overrides the recommendation, switches to verified manual reports, documents reallocations, preserves telemetry, and reviews model assumptions after stabilisation.
Notably AbsentNo claim is made that optimisation alone can resolve competing emergency duties or that speed eliminates accountability.

19.9 Regulatory inspection prioritisation

ElementTreatment
Decision-authority levelLevel 4
Context and rolePrioritises entities for inspection; inspectors and enforcement officials retain authority over inspection, findings, and sanctions.
Material risksSelective enforcement, stale compliance data, vendor opacity, strategic evasion, and weak explanation of prioritisation.
Required safeguardsLegally relevant factors; random and risk-based sampling; bias and drift monitoring; reason codes; independent review; challenge process.
EvidenceInspection policy; feature rationale; selection distributions; random-sample results; inspector feedback; complaints and reviews.
Failure scenarioThe model learns that entities using a particular reporting format are higher risk, producing a persistent but spurious enforcement concentration.
Detection and responseFeature review and distribution monitoring detect the proxy; suspend the feature, re-evaluate queued inspections, assess past decisions, document legal review, and validate a revised model with random controls.
Notably AbsentThe example does not assert that equal inspection rates are required or that model opacity automatically proves discrimination.

19.10 Drafting official notices

ElementTreatment
Decision-authority levelLevel 4
Context and roleDrafts notices or decisions from case evidence; an authorised official must verify facts, law, reasons, remedy and final text.
Material risksFabricated facts or citations, omitted evidence, unlawful reasons, privacy disclosure, and false appearance of official approval.
Required safeguardsSource-grounded drafting; citation verification; controlled templates; redaction; mandatory substantive review; signed approval; version history.
EvidenceSource links; draft/final comparison; reviewer checklist; approval signature; notice delivery; correction and appeal records.
Failure scenarioThe system invents a statutory reference and omits contrary evidence, and the reviewer approves the notice because the prose appears authoritative.
Detection and responseLegal quality review or appeal identifies the defect; withdraw or correct the notice, preserve draft and approval evidence, assess similarly generated notices, retrain reviewers, and update citation and contrary-evidence checks.
Notably AbsentProfessional wording, source citations, or a signature do not by themselves establish factual or legal correctness.

20. Notably Absent

  • No verified basis is presented for claiming that all public-sector AI deployments are high risk.
  • No framework adoption, policy, model card, attestation, or certification alone proves operating effectiveness.
  • No assumption is made that human approval is effective without competence, time, authority, independence, and evidence.
  • No claim is made that model accuracy alone establishes legality, fairness, security, accessibility, procedural validity, or fitness.
  • No claim is made that procurement or supplier certification transfers public accountability.
  • No verified evidence is asserted here of autonomous AI lawmaking or wholesale replacement of constitutional or statutory authority.
  • No absence of reported incidents is treated as proof of safety.
  • No universal threshold, maturity score, or profile establishes a government acceptance criterion.

21. Limitations

  • This guide is implementation guidance, not legal advice.
  • Jurisdiction-specific legal authority and public-law duties require qualified review.
  • Conformance evidence does not by itself prove operating effectiveness.
  • Absence of a reported incident does not prove safety.
  • GAISSF implementation does not eliminate residual risk.
  • Government functions, legal systems, records regimes, procurement rules, and oversight structures differ materially.
  • Threat conditions, models, suppliers, integrations, and system behaviour change over time.
  • External sources are contextual unless legally applicable; verify status, edition, date, and jurisdiction.
  • This public candidate contains no universal financial exposure range, cost estimate, ROI claim, or dependency on an unverified ODA3 test repository. Test specifications are illustrative and must be adapted to the implementing entity's architecture and assurance method.

22. Source and Evidence Register

IDSourceIssuerDateTier/statusURL or locationLimitationsLast verified
SRC-001GAISSF-NOR-001 Framework Standard v1.0ODA3 Institute2026-06-29Authoritative / NormativeInternal controlled sourceCanonical 59-control baseline30 Jun 2026
SRC-002Artificial Intelligence Risk Management Framework (AI RMF 1.0)NIST2023-01-26Tier 1 / Advisoryhttps://doi.org/10.6028/NIST.AI.100-1Voluntary risk-management framework30 Jun 2026
SRC-003Regulation (EU) 2024/1689 (Artificial Intelligence Act)European Union2024-06-13Tier 1 / Binding where applicablehttps://eur-lex.europa.eu/eli/reg/2024/1689/ojJurisdiction-specific; verify applicability and phased dates30 Jun 2026
SRC-004G7 Toolkit for Artificial Intelligence in the Public SectorOECD/G72024Tier 2 / Advisoryhttps://www.oecd.org/en/publications/g7-toolkit-for-artificial-intelligence-in-the-public-sector_421c1244-en.htmlPublic-sector implementation context30 Jun 2026
SRC-005OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public TrustUS OMB2025-04-03Tier 1 / Binding for covered US federal agencieshttps://www.whitehouse.gov/omb/information-resources/guidance/memoranda/Jurisdiction-specific and subject to supersession30 Jun 2026
SRC-006NIST AI 600-1 Generative AI ProfileNIST2024-07-26Tier 1 / Advisoryhttps://doi.org/10.6028/NIST.AI.600-1Generative AI risk profile30 Jun 2026

22.1 Evidence-tier model

TierMeaning
Tier 1 — AuthoritativeLegislation, regulation, binding policy, official standards/directives, formal decisions, audit findings, and primary government sources.
Tier 2 — Strong supportingRecognised standards-body guidance, cybersecurity guidance, peer-reviewed research, and formal assurance frameworks.
Tier 3 — ContextualCredible incident reporting, technical analysis, public case studies, and documented operational experience.
Tier 4 — IllustrativeHypothetical or composite examples, practitioner observations, and unverified public claims.

Source verification note: time-sensitive legal, regulatory, directive and policy sources must be reverified immediately before publication. NIST AI RMF 1.0 is voluntary guidance; Regulation (EU) 2024/1689 is binding only where applicable; WCAG 2.2 is an advisory web accessibility standard unless adopted by the governing regime. [T1]

Appendix A — Package Validation Checklist

☐ 59 source controls represented in all core artifacts.

☐ Control IDs and titles match GAISSF-NOR-001.

☐ Normative and informative text are separated.

☐ JSON parses and CSV column parity is validated.

☐ Workbook formulas, lists, and formatting are checked.

☐ External legal and policy claims are reverified.

☐ Open review gates are closed or disclosed.

☐ Final DOCX is rendered and visually inspected.