Manufacturing Sector Guidance
GAISSF implementation guidance for AI systems and assurance programmes in the manufacturing sector.
GAISSF Manufacturing Sector Implementation Guide
Operational guidance for enterprise, OT, edge and physical AI
SEC-045 | Version 1.1 | Final Review Candidate
| Field | Value |
|---|---|
| Publisher | ODA3 Institute |
| Legal entity | ODA3 Pvt Ltd |
| Publication date | 1 July 2026 |
| Normative status | Informative sector implementation guidance |
| Authoritative baseline | GAISSF-NOR-001 v1.0 corrected final publication edition; 59 controls |
| Release status | Final Review Candidate — trademark and authorised release-signing gates remain controlled |
Methodology Note
ODA3 Institute is an applied research and advisory firm founded in March 2026. It does not maintain a historical proprietary client incident dataset covering manufacturing AI events. Sector interpretations and threat scenarios are derived from authoritative standards, public disclosures, regulatory and official materials, peer-reviewed or academic research, controlled technical demonstrations and explicitly labelled analytical scenarios. Absence of proprietary telemetry limits frequency estimation and must not be interpreted as evidence that an event has or has not occurred.
Normative, Legal and Safety Boundaries
- GAISSF control identifiers, official titles and authoritative requirements remain unchanged. All manufacturing interpretation is informative.
- GAISSF tier classification and SEC-045 assessment do not constitute an EU Artificial Intelligence Act legal classification or conformity assessment. They do not replace technical documentation, quality-management, risk-management, human-oversight, registration, post-market monitoring, fundamental-rights impact assessment or other obligations where those requirements apply.
- GAISSF security controls do not calculate, demonstrate or satisfy probability of failure on demand, probability of dangerous failure per hour, safety integrity level, performance level or equivalent functional-safety metrics. Security approval does not replace machinery- or process-safety lifecycle approval.
- An AI system must not be treated as the sole safety protection layer unless it has been engineered, assessed and approved under the applicable functional-safety and machinery-safety regime.
Evidence Classification
| Tier | Name | Definition |
|---|---|---|
| T1 | Authoritative primary evidence | Legislation, regulator findings, official investigations, standards records, authenticated first-party technical notices. |
| T2 | Corroborated evidence | Multiple independent credible sources or replicated findings. |
| T3 | Controlled research or credible proxy | Peer-reviewed research, controlled experiments, simulations or documented technical demonstrations with stated limits. |
| T4 | Analytical or hypothetical | Reasoned interpretation or scenario analysis not established as a field incident. |
Assurance Artifact Strength
| Class | Name | Definition |
|---|---|---|
| A1 | Direct technical artifact | System-generated log, signed hash, configuration export, measured test result. |
| A2 | Controlled implementation record | Approved change record, signed test report, risk decision, deployment approval. |
| A3 | Independent assurance or attestation | Independent assessment, certification report, supplier assurance with defined scope. |
| A4 | Management assertion or contextual support | Interview, policy statement or unsupported supplier statement; requires corroboration for high-consequence claims. |
Inline [T1]–[T4] tags classify externally verifiable analytical claims and threat scenarios. They are not applied mechanically to procedural guidance or authoritative GAISSF requirements.
Executive Summary
Manufacturing AI spans enterprise assistance, production advice, quality decisions, control-influencing systems and autonomous physical operation. Assurance depth must follow authority and consequence, not marketing labels.
- Operate two implementation tracks: enterprise/advisory AI and OT/edge/physical AI.
- Preserve independent safety functions, engineering change control, quality release authority and deterministic fallback.
- Use human-in-the-loop approval where process timing permits; use human-on-the-loop supervision or independent protection where real-time intervention is infeasible.
- Estimate financial exposure with traceable formulas, low/base/high ranges and explicit assumptions.
- Record what was not established, including the absence of proprietary ODA3 telemetry and verified public frequency data.
1. Purpose and Scope
This guide translates the 59-control GAISSF baseline into manufacturing implementation, assessment and evidence guidance across enterprise IT, operational technology, industrial control, connected machinery, robotics, industrial Internet of Things, digital twins, quality, safety and supply chains.
2. Two-Track Implementation Model
| Track | Primary concerns | Typical systems | Control emphasis |
|---|---|---|---|
| Enterprise / Advisory AI | Data leakage, intellectual property, unreliable advice, automation bias, identity, cloud and supplier dependency | Knowledge assistants, contract analysis, forecasting, maintenance copilots | Governance, data, output integrity, identity, supplier assurance and human approval |
| OT / Edge / Physical AI | Determinism, actuation, sensor integrity, safe state, constrained devices, downtime, product conformity | Machine vision, predictive maintenance, robotics, process optimisation, autonomous vehicles | Independent protection, operating envelope, command mediation, rollback, local resilience and physical validation |
3. Manufacturing AI Classification
| Tier | Description | Oversight model | Minimum assurance |
|---|---|---|---|
| Tier 1 — Enterprise Support | No direct production or safety authority | Human-in-the-loop or ordinary managerial review | Inventory, owner, data rules, acceptable use, monitoring |
| Tier 2 — Production Advisory | Influences operators or planning without direct actuation | Human-in-the-loop or human-on-the-loop | Plant validation, trained oversight, fallback and change control |
| Tier 3 — Decision or Control Influencing | Material effect on quality, release, settings or production actions | Human-in-the-loop where feasible; otherwise supervised veto and command mediation | Independent verification, enhanced monitoring, tested rollback |
| Tier 4 — Safety-Critical or Autonomous Control | Direct actuation or material physical consequence | Human-on-the-loop or human-out-of-the-loop with independent protection | Formal engineering and safety approval, independent protection, validated operating envelope and safe-state response |
4. Human Factors Implementation Pattern
- Calibrate operator trust by presenting limits, uncertainty and required action rather than unsupported confidence.
- Design alerts for actionability, priority and rate; monitor alert fatigue and override behaviour.
- Run periodic manual or degraded-mode drills to preserve competence where safe and operationally feasible.
- Measure whether the operator has sufficient information and intervention time; nominal presence is not meaningful oversight.
- Review task de-skilling, workarounds, unsafe reliance and loss of situational awareness.
This pattern is informative and does not create a new GAISSF control.
5. Conditional Applicability Trigger Matrix
| Control | Official title | Trigger | Required treatment | OT friction |
|---|---|---|---|---|
| D1-CTL-04 | FEDERATED LEARNING POISONING PREVENTION | Triggered when model training or parameter aggregation occurs across plants, suppliers or edge nodes without centralising raw operational data. | Document participating nodes, aggregation trust, poisoning resistance, privacy assumptions and rollback. | High |
| D1-CTL-06 | POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING | Triggered when the model-signing trust period, confidentiality lifetime, equipment lifetime, regulatory obligation or approved cryptographic transition horizon creates material post-quantum exposure. | Perform a cryptographic-agility and migration assessment; do not use a fixed ten-year trigger without context. | High |
| D1-CTL-07 | LORA/ADAPTER INTEGRITY VERIFICATION | Triggered when low-rank adaptations, adapters or other detachable model components are loaded, exchanged or updated separately from the base model. | Verify provenance, compatibility, signatures, privilege and rollback for each adapter. | Moderate |
| D1-CTL-08 | MODEL MERGE ATTACK DETECTION | Applicable when the scoped system uses the capability or faces the risk addressed by the control. | Apply proportionately to architecture, consequence and deployment context. | Moderate |
| D1-CTL-09 | QUANTIZATION BACKDOOR SCREENING | Applicable when the scoped system uses the capability or faces the risk addressed by the control. | Apply proportionately to architecture, consequence and deployment context. | Moderate |
| D5-CTL-04 | AI WATERMARKING ROBUSTNESS | Core for public-facing synthetic media or externally distributed content; generally low relevance to internal OT telemetry and machine-vision inspection unless outputs leave the controlled environment. | Document why provenance or watermarking is required or not required for the scoped output channel. | Low |
| D9-CTL-03 | HUMAN OVERRIDE AND EMERGENCY STOP | Applicable when the scoped system uses the capability or faces the risk addressed by the control. | Apply proportionately to architecture, consequence and deployment context. | High |
6. Functional Safety and Machinery Safety Integration
GAISSF security controls do not calculate, demonstrate or satisfy probability of failure on demand, probability of dangerous failure per hour, safety integrity level, performance level or equivalent functional-safety metrics. Security approval does not replace machinery- or process-safety lifecycle approval.
| GAISSF activity | Safety-lifecycle interface | Security contribution | Required authority | Boundary |
|---|---|---|---|---|
| Authority and agency controls | Hazard analysis and safety requirements specification | Defines permitted AI actions and prohibited command paths | Engineering and functional-safety authority | Does not establish a safety integrity level |
| Safe-state and fallback controls | Architecture, validation, operation and maintenance | Tests transition under model, data, communications or compute failure | Functional-safety and plant authority | Does not establish probability of dangerous failure |
| Human override and emergency response | Design and operational procedures | Defines supervisory veto, isolation and shutdown coordination | Machinery-safety authority and plant management | Software override must not inhibit independent emergency stop |
| Model and data change controls | Modification lifecycle | Prevents unreviewed updates and preserves rollback evidence | Engineering, quality and safety authorities | Security approval alone is insufficient |
| Monitoring and incident controls | Operation, maintenance and proof-test planning | Correlates AI, OT, quality and safety evidence | Operations, safety, quality and security | Monitoring does not replace required proof testing |
7. Financial Exposure Estimation
Use plant-specific low, base and high estimates. Fixed confidence percentages must not be used unless supported by observed variance or explicit expert judgement.
| Exposure | Formula | Required assumptions |
|---|---|---|
| Daily quality escape cost | Units inspected × defect prevalence × AI false-negative rate × average escape cost per defective unit | Inspection population, defect prevalence, measured false-negative rate, rework/replacement/logistics/warranty/recall allocation |
| Tier 4 interruption cost | (Detection + isolation + fallback activation + safety revalidation + quality revalidation + restart time) × contribution margin per line hour + restart scrap + expediting cost | Time distributions, contribution margin, validation steps, restart yield |
| Annualised expected exposure | Estimated event frequency × estimated cost per event | Frequency basis, low/base/high bounds, excluded costs and review date |
8. Tier 4 Operational Metrics
| Metric | Definition | Interpretation caution |
|---|---|---|
| Safety-related false-negative rate | Missed hazardous conditions / all verified hazardous conditions | Requires a defensible ground truth and sufficient sample size |
| Safe-state transition time | Elapsed time from qualifying failure to validated safe state | Compare with the documented requirement and operating condition |
| Safe-state transition success rate | Successful validated transitions / attempted transitions | Classify failed and partial transitions |
| Command override rate | Human vetoes or overrides / AI physical-command recommendations | High rate may indicate poor calibration, weak trust or changing conditions |
| Emergency-stop activation rate | Emergency stops by human and automated cause category / operating hours | A rising rate is not automatically model degradation |
| Sensor-integrity alert rate | Calibration, plausibility or drift alerts / operating period | Separate true integrity issues from threshold noise |
| Operating-envelope violation rate | Detected boundary violations / operating hours or cycles | Investigate model, data, process and configuration causes |
| Fallback activation and success | Fallback attempts and successful completions | Record degraded-mode capacity and product impact |
| Post-update validation failure rate | Updates failing safety or quality validation / updates assessed | Leading indicator of change-control quality |
9. Reference Architecture Examples
- Data and model provenance for a computer numerical control machine may include sensor identity, calibration records, toolpath metadata, maintenance state, model hash, training dataset version and deployment approval.
- Behavioural drift detection should segment performance by plant, line, machine, product family, tooling condition, shift and environmental regime rather than rely only on an enterprise-wide average.
- An OT/edge deployment should use signed artifacts, secure boot where available, hardened management, local monitoring, validated rollback and compensating controls for constrained legacy devices.
- An enterprise assistant should prevent confidential design or process data from being used for provider training unless explicitly authorised.
10. GAISSF Control Implementation Records
Each record preserves the authoritative identifier and official title. Source requirements remain normative only through GAISSF-NOR-001. Manufacturing content below is informative.
D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Hash verification + source allowlist + poisoning detection.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply dataset provenance & poisoning prevention in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-02 — MODEL EXTRACTION RESISTANCE
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Rate limiting + diversity detection + extraction monitoring.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply model extraction resistance in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-03 — BEHAVIORAL DRIFT DETECTION
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Baseline profiling + KL divergence monitoring + accuracy tracking.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply behavioral drift detection in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Conditionally applicable |
| Sector relevance | Conditional |
| Implementation track | Both |
| OT friction | High |
| Conditional trigger | Triggered when model training or parameter aggregation occurs across plants, suppliers or edge nodes without centralising raw operational data. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Gradient anomaly detection + robust aggregation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply federated learning poisoning prevention in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Document participating nodes, aggregation trust, poisoning resistance, privacy assumptions and rollback.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Adversarial training + certified robustness measurement.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply embedding space robustness in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Conditionally applicable |
| Sector relevance | Conditional |
| Implementation track | Both |
| OT friction | High |
| Conditional trigger | Triggered when the model-signing trust period, confidentiality lifetime, equipment lifetime, regulatory obligation or approved cryptographic transition horizon creates material post-quantum exposure. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
PQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply post-quantum model signing & crypto hardening in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Perform a cryptographic-agility and migration assessment; do not use a fixed ten-year trigger without context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Conditionally applicable |
| Sector relevance | Conditional |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Triggered when low-rank adaptations, adapters or other detachable model components are loaded, exchanged or updated separately from the base model. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Adapter scanning + provenance verification + registry allowlist.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply lora/adapter integrity verification in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Verify provenance, compatibility, signatures, privilege and rollback for each adapter.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-08 — MODEL MERGE ATTACK DETECTION
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Conditionally applicable |
| Sector relevance | Conditional |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Pre-registration behavioural evaluation + regression testing.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply model merge attack detection in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING
| Field | Content |
|---|---|
| Domain | D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS |
| Applicability | Conditionally applicable |
| Sector relevance | Conditional |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Cross-precision behavioural comparison + delta threshold monitoring.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply quantization backdoor screening in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain model and dataset provenance, integrity checks, approved sources, version control, plant-specific validation, and documented acceptance criteria before production use.
- Use signed artifacts, automated integrity verification, adversarial testing, drift detection by plant and operating regime, independent review, and tested rollback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; dataset/model provenance; hash or signature verification; drift and rollback records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- enterprise-only validation
- no plant-specific baseline
- unsigned model updates
- unmonitored drift
- weak dataset lineage
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION
| Field | Content |
|---|---|
| Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Input validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply direct prompt injection prevention in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Validate and constrain inputs, isolate untrusted content, enforce tool permissions, log security-relevant interactions, and require human approval for production-affecting actions.
- Deploy context separation, deterministic policy enforcement, adversarial testing, runtime anomaly detection, content provenance checks, and automatic containment.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; input/output filtering tests; tool permission logs; adversarial test results
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- treating all plant data as trusted
- unrestricted tool calls
- missing context separation
- no production-action approval gate
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION
| Field | Content |
|---|---|
| Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Contextual separation + source allowlisting + output validation + RAG sanitization pipeline.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply indirect prompt injection prevention in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Validate and constrain inputs, isolate untrusted content, enforce tool permissions, log security-relevant interactions, and require human approval for production-affecting actions.
- Deploy context separation, deterministic policy enforcement, adversarial testing, runtime anomaly detection, content provenance checks, and automatic containment.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; input/output filtering tests; tool permission logs; adversarial test results
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- treating all plant data as trusted
- unrestricted tool calls
- missing context separation
- no production-action approval gate
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D2-CTL-03 — JAILBREAK RESISTANCE TESTING
| Field | Content |
|---|---|
| Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Quarterly red-team prompt library + adversarial training + automated refusal monitoring.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply jailbreak resistance testing in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Validate and constrain inputs, isolate untrusted content, enforce tool permissions, log security-relevant interactions, and require human approval for production-affecting actions.
- Deploy context separation, deterministic policy enforcement, adversarial testing, runtime anomaly detection, content provenance checks, and automatic containment.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; input/output filtering tests; tool permission logs; adversarial test results
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- treating all plant data as trusted
- unrestricted tool calls
- missing context separation
- no production-action approval gate
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE
| Field | Content |
|---|---|
| Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Multi-modal content scanning + steganography detection + modality-specific guardrails.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply multi-modal injection defense in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Validate and constrain inputs, isolate untrusted content, enforce tool permissions, log security-relevant interactions, and require human approval for production-affecting actions.
- Deploy context separation, deterministic policy enforcement, adversarial testing, runtime anomaly detection, content provenance checks, and automatic containment.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; input/output filtering tests; tool permission logs; adversarial test results
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- treating all plant data as trusted
- unrestricted tool calls
- missing context separation
- no production-action approval gate
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION
| Field | Content |
|---|---|
| Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Parameter schema validation + allowlist enforcement + sandboxed execution.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply function call/tool call injection prevention in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Validate and constrain inputs, isolate untrusted content, enforce tool permissions, log security-relevant interactions, and require human approval for production-affecting actions.
- Deploy context separation, deterministic policy enforcement, adversarial testing, runtime anomaly detection, content provenance checks, and automatic containment.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; input/output filtering tests; tool permission logs; adversarial test results
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- treating all plant data as trusted
- unrestricted tool calls
- missing context separation
- no production-action approval gate
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION
| Field | Content |
|---|---|
| Domain | D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Context window segmentation + prompt anchoring + attention boundary enforcement.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply cross-context hijacking mitigation in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Validate and constrain inputs, isolate untrusted content, enforce tool permissions, log security-relevant interactions, and require human approval for production-affecting actions.
- Deploy context separation, deterministic policy enforcement, adversarial testing, runtime anomaly detection, content provenance checks, and automatic containment.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; input/output filtering tests; tool permission logs; adversarial test results
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- treating all plant data as trusted
- unrestricted tool calls
- missing context separation
- no production-action approval gate
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D3-CTL-01 — LEAST AGENCY ENFORCEMENT
| Field | Content |
|---|---|
| Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Role-based tool scoping + policy-as-code + dynamic permission revocation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply least agency enforcement in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define authority boundaries, approved actions, human override, fail-safe behavior, segregation of duties, and explicit approval for control-affecting operations.
- Use independent safety interlocks, formal policy constraints, simulation and boundary testing, command mediation, real-time authority monitoring, and tested emergency fallback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; authority matrix; simulation results; override and fail-safe test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- unclear action authority
- ineffective human oversight
- AI path bypasses engineering change control
- no tested fallback
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY
| Field | Content |
|---|---|
| Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
mTLS for agent mesh + message signing + payload validation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply inter-agent communication security in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define authority boundaries, approved actions, human override, fail-safe behavior, segregation of duties, and explicit approval for control-affecting operations.
- Use independent safety interlocks, formal policy constraints, simulation and boundary testing, command mediation, real-time authority monitoring, and tested emergency fallback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; authority matrix; simulation results; override and fail-safe test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- unclear action authority
- ineffective human oversight
- AI path bypasses engineering change control
- no tested fallback
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION
| Field | Content |
|---|---|
| Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Cross-session behavioural correlation + chain pattern detection + anomaly scoring.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply agentic prompt chaining detection in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define authority boundaries, approved actions, human override, fail-safe behavior, segregation of duties, and explicit approval for control-affecting operations.
- Use independent safety interlocks, formal policy constraints, simulation and boundary testing, command mediation, real-time authority monitoring, and tested emergency fallback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; authority matrix; simulation results; override and fail-safe test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- unclear action authority
- ineffective human oversight
- AI path bypasses engineering change control
- no tested fallback
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D3-CTL-04 — EMBODIED AI SAFETY CONTROLS
| Field | Content |
|---|---|
| Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Sensor integrity verification + safety interlocks + fail-safe state enforcement.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply embodied ai safety controls in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define authority boundaries, approved actions, human override, fail-safe behavior, segregation of duties, and explicit approval for control-affecting operations.
- Use independent safety interlocks, formal policy constraints, simulation and boundary testing, command mediation, real-time authority monitoring, and tested emergency fallback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; authority matrix; simulation results; override and fail-safe test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- unclear action authority
- ineffective human oversight
- AI path bypasses engineering change control
- no tested fallback
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION
| Field | Content |
|---|---|
| Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
SPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply multi-agent trust chain attestation in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define authority boundaries, approved actions, human override, fail-safe behavior, segregation of duties, and explicit approval for control-affecting operations.
- Use independent safety interlocks, formal policy constraints, simulation and boundary testing, command mediation, real-time authority monitoring, and tested emergency fallback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; authority matrix; simulation results; override and fail-safe test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- unclear action authority
- ineffective human oversight
- AI path bypasses engineering change control
- no tested fallback
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION
| Field | Content |
|---|---|
| Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
User-scoped memory isolation + encryption at rest + query-level access controls.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply persistent memory exfiltration prevention in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define authority boundaries, approved actions, human override, fail-safe behavior, segregation of duties, and explicit approval for control-affecting operations.
- Use independent safety interlocks, formal policy constraints, simulation and boundary testing, command mediation, real-time authority monitoring, and tested emergency fallback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; authority matrix; simulation results; override and fail-safe test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- unclear action authority
- ineffective human oversight
- AI path bypasses engineering change control
- no tested fallback
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT
| Field | Content |
|---|---|
| Domain | D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Cryptographic deletion + lifecycle policy enforcement + retention auditing.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply secure memory lifecycle management in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define authority boundaries, approved actions, human override, fail-safe behavior, segregation of duties, and explicit approval for control-affecting operations.
- Use independent safety interlocks, formal policy constraints, simulation and boundary testing, command mediation, real-time authority monitoring, and tested emergency fallback.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; authority matrix; simulation results; override and fail-safe test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- unclear action authority
- ineffective human oversight
- AI path bypasses engineering change control
- no tested fallback
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE
| Field | Content |
|---|---|
| Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Automated BOM generation + version tracking + registry synchronization.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai bill of materials (ai bom) maintenance in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Inventory suppliers and dependencies, define security requirements, obtain provenance and update commitments, restrict access, and maintain exit and continuity plans.
- Require signed releases, independent assurance, SBOM/AI-BOM evidence, continuous supplier monitoring, escrow or fallback arrangements, and tested replacement procedures.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; contract clauses; supplier evidence; AI-BOM/SBOM; remote-access review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- accepting marketing claims as evidence
- persistent vendor access
- no model provenance
- no cloud outage contingency
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING
| Field | Content |
|---|---|
| Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Static analysis + deserialization sandboxing + signature verification.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply model file & artifact scanning in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Inventory suppliers and dependencies, define security requirements, obtain provenance and update commitments, restrict access, and maintain exit and continuity plans.
- Require signed releases, independent assurance, SBOM/AI-BOM evidence, continuous supplier monitoring, escrow or fallback arrangements, and tested replacement procedures.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; contract clauses; supplier evidence; AI-BOM/SBOM; remote-access review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- accepting marketing claims as evidence
- persistent vendor access
- no model provenance
- no cloud outage contingency
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D4-CTL-03 — MODEL HUB & REGISTRY VETTING
| Field | Content |
|---|---|
| Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Provenance verification + license compliance + security scorecard.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply model hub & registry vetting in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Inventory suppliers and dependencies, define security requirements, obtain provenance and update commitments, restrict access, and maintain exit and continuity plans.
- Require signed releases, independent assurance, SBOM/AI-BOM evidence, continuous supplier monitoring, escrow or fallback arrangements, and tested replacement procedures.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; contract clauses; supplier evidence; AI-BOM/SBOM; remote-access review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- accepting marketing claims as evidence
- persistent vendor access
- no model provenance
- no cloud outage contingency
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING
| Field | Content |
|---|---|
| Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Tool-call logging + anomaly detection + access control enforcement.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply mcp server behavioral monitoring in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Inventory suppliers and dependencies, define security requirements, obtain provenance and update commitments, restrict access, and maintain exit and continuity plans.
- Require signed releases, independent assurance, SBOM/AI-BOM evidence, continuous supplier monitoring, escrow or fallback arrangements, and tested replacement procedures.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; contract clauses; supplier evidence; AI-BOM/SBOM; remote-access review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- accepting marketing claims as evidence
- persistent vendor access
- no model provenance
- no cloud outage contingency
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT
| Field | Content |
|---|---|
| Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Contractual security requirements + penetration testing + data flow mapping.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply third-party ai api security assessment in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Inventory suppliers and dependencies, define security requirements, obtain provenance and update commitments, restrict access, and maintain exit and continuity plans.
- Require signed releases, independent assurance, SBOM/AI-BOM evidence, continuous supplier monitoring, escrow or fallback arrangements, and tested replacement procedures.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; contract clauses; supplier evidence; AI-BOM/SBOM; remote-access review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- accepting marketing claims as evidence
- persistent vendor access
- no model provenance
- no cloud outage contingency
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE
| Field | Content |
|---|---|
| Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Network traffic analysis + SaaS discovery + policy enforcement.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply shadow ai discovery & governance in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Inventory suppliers and dependencies, define security requirements, obtain provenance and update commitments, restrict access, and maintain exit and continuity plans.
- Require signed releases, independent assurance, SBOM/AI-BOM evidence, continuous supplier monitoring, escrow or fallback arrangements, and tested replacement procedures.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; contract clauses; supplier evidence; AI-BOM/SBOM; remote-access review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- accepting marketing claims as evidence
- persistent vendor access
- no model provenance
- no cloud outage contingency
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA)
| Field | Content |
|---|---|
| Domain | D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Dependency scanning + CVE matching + automated patching.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai software composition analysis (sca) in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Inventory suppliers and dependencies, define security requirements, obtain provenance and update commitments, restrict access, and maintain exit and continuity plans.
- Require signed releases, independent assurance, SBOM/AI-BOM evidence, continuous supplier monitoring, escrow or fallback arrangements, and tested replacement procedures.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; contract clauses; supplier evidence; AI-BOM/SBOM; remote-access review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- accepting marketing claims as evidence
- persistent vendor access
- no model provenance
- no cloud outage contingency
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D5-CTL-01 — HARMFUL CONTENT BLOCKING
| Field | Content |
|---|---|
| Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Content safety classifier + refusal engine.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply harmful content blocking in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define acceptable outputs, validate critical results, communicate uncertainty, maintain human review, and prevent unsafe or prohibited content from entering production workflows.
- Use independent verification, output policy enforcement, confidence calibration, structured validation, traceable citations, and automatic quarantine of suspect outputs.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; output acceptance criteria; quality verification; exception and quarantine records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- confidence treated as correctness
- no independent verification
- generated instructions used without engineering approval
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D5-CTL-02 — PII LEAKAGE PREVENTION
| Field | Content |
|---|---|
| Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
PII detection + masking + access controls.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply pii leakage prevention in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define acceptable outputs, validate critical results, communicate uncertainty, maintain human review, and prevent unsafe or prohibited content from entering production workflows.
- Use independent verification, output policy enforcement, confidence calibration, structured validation, traceable citations, and automatic quarantine of suspect outputs.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; output acceptance criteria; quality verification; exception and quarantine records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- confidence treated as correctness
- no independent verification
- generated instructions used without engineering approval
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D5-CTL-03 — COPYRIGHT DETECTION
| Field | Content |
|---|---|
| Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
n-gram overlap detection + refusal.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply copyright detection in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define acceptable outputs, validate critical results, communicate uncertainty, maintain human review, and prevent unsafe or prohibited content from entering production workflows.
- Use independent verification, output policy enforcement, confidence calibration, structured validation, traceable citations, and automatic quarantine of suspect outputs.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; output acceptance criteria; quality verification; exception and quarantine records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- confidence treated as correctness
- no independent verification
- generated instructions used without engineering approval
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D5-CTL-04 — AI WATERMARKING ROBUSTNESS
| Field | Content |
|---|---|
| Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY |
| Applicability | Applicable |
| Sector relevance | Conditional |
| Implementation track | Both |
| OT friction | Low |
| Conditional trigger | Core for public-facing synthetic media or externally distributed content; generally low relevance to internal OT telemetry and machine-vision inspection unless outputs leave the controlled environment. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
C2PA-compliant watermarking + tamper resistance testing.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai watermarking robustness in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define acceptable outputs, validate critical results, communicate uncertainty, maintain human review, and prevent unsafe or prohibited content from entering production workflows.
- Use independent verification, output policy enforcement, confidence calibration, structured validation, traceable citations, and automatic quarantine of suspect outputs.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; output acceptance criteria; quality verification; exception and quarantine records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Document why provenance or watermarking is required or not required for the scoped output channel.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- confidence treated as correctness
- no independent verification
- generated instructions used without engineering approval
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION
| Field | Content |
|---|---|
| Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Data minimization + purpose limitation + machine unlearning.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply privacy-by-design verification in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define acceptable outputs, validate critical results, communicate uncertainty, maintain human review, and prevent unsafe or prohibited content from entering production workflows.
- Use independent verification, output policy enforcement, confidence calibration, structured validation, traceable citations, and automatic quarantine of suspect outputs.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; output acceptance criteria; quality verification; exception and quarantine records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- confidence treated as correctness
- no independent verification
- generated instructions used without engineering approval
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION
| Field | Content |
|---|---|
| Domain | D5: CONTENT SAFETY & OUTPUT INTEGRITY |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Differential privacy + membership inference testing.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply privacy-preserving ml validation in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define acceptable outputs, validate critical results, communicate uncertainty, maintain human review, and prevent unsafe or prohibited content from entering production workflows.
- Use independent verification, output policy enforcement, confidence calibration, structured validation, traceable citations, and automatic quarantine of suspect outputs.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; output acceptance criteria; quality verification; exception and quarantine records
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- confidence treated as correctness
- no independent verification
- generated instructions used without engineering approval
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS
| Field | Content |
|---|---|
| Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT |
| Applicability | Applicable |
| Sector relevance | Core |
| Implementation track | Enterprise Governance |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Approval workflow + policy enforcement + audit log.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply human-in-the-loop for high-risk actions in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain an AI inventory, assign accountable owners, classify criticality, approve risk, define policies, and retain evidence.
- Integrate plant-level assurance with enterprise governance, continuous control monitoring, independent challenge, board reporting, and multi-site conformance review.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; AI inventory; RACI; risk acceptance; governance minutes
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- central policy without plant implementation
- incomplete inventory
- unclear ownership
- undocumented exceptions
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D6-CTL-02 — AUDIT TRAIL COMPLETENESS
| Field | Content |
|---|---|
| Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT |
| Applicability | Applicable |
| Sector relevance | Core |
| Implementation track | Enterprise Governance |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Structured logging + SIEM integration + retention enforcement.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply audit trail completeness in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain an AI inventory, assign accountable owners, classify criticality, approve risk, define policies, and retain evidence.
- Integrate plant-level assurance with enterprise governance, continuous control monitoring, independent challenge, board reporting, and multi-site conformance review.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; AI inventory; RACI; risk acceptance; governance minutes
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- central policy without plant implementation
- incomplete inventory
- unclear ownership
- undocumented exceptions
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D6-CTL-03 — AI MODEL CARD COMPLETENESS
| Field | Content |
|---|---|
| Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT |
| Applicability | Applicable |
| Sector relevance | Core |
| Implementation track | Enterprise Governance |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Standardized template + version control + public accessibility.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai model card completeness in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain an AI inventory, assign accountable owners, classify criticality, approve risk, define policies, and retain evidence.
- Integrate plant-level assurance with enterprise governance, continuous control monitoring, independent challenge, board reporting, and multi-site conformance review.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; AI inventory; RACI; risk acceptance; governance minutes
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- central policy without plant implementation
- incomplete inventory
- unclear ownership
- undocumented exceptions
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D6-CTL-04 — AI INCIDENT RESPONSE READINESS
| Field | Content |
|---|---|
| Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT |
| Applicability | Applicable |
| Sector relevance | Core |
| Implementation track | Enterprise Governance |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
AI-IR runbook + tabletop exercises + containment automation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai incident response readiness in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain an AI inventory, assign accountable owners, classify criticality, approve risk, define policies, and retain evidence.
- Integrate plant-level assurance with enterprise governance, continuous control monitoring, independent challenge, board reporting, and multi-site conformance review.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; AI inventory; RACI; risk acceptance; governance minutes
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- central policy without plant implementation
- incomplete inventory
- unclear ownership
- undocumented exceptions
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING
| Field | Content |
|---|---|
| Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT |
| Applicability | Applicable |
| Sector relevance | Core |
| Implementation track | Enterprise Governance |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Access revocation + decommission audit + scheduled lifecycle.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply model deprecation & decommissioning in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain an AI inventory, assign accountable owners, classify criticality, approve risk, define policies, and retain evidence.
- Integrate plant-level assurance with enterprise governance, continuous control monitoring, independent challenge, board reporting, and multi-site conformance review.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; AI inventory; RACI; risk acceptance; governance minutes
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- central policy without plant implementation
- incomplete inventory
- unclear ownership
- undocumented exceptions
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE
| Field | Content |
|---|---|
| Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT |
| Applicability | Applicable |
| Sector relevance | Core |
| Implementation track | Enterprise Governance |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Contractual security requirements + annual assessment + audit rights.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply third-party ai vendor governance in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain an AI inventory, assign accountable owners, classify criticality, approve risk, define policies, and retain evidence.
- Integrate plant-level assurance with enterprise governance, continuous control monitoring, independent challenge, board reporting, and multi-site conformance review.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; AI inventory; RACI; risk acceptance; governance minutes
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- central policy without plant implementation
- incomplete inventory
- unclear ownership
- undocumented exceptions
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY
| Field | Content |
|---|---|
| Domain | D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT |
| Applicability | Applicable |
| Sector relevance | Core |
| Implementation track | Enterprise Governance |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Failover systems + degraded mode + RTO/RPO definition.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai resilience & business continuity in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain an AI inventory, assign accountable owners, classify criticality, approve risk, define policies, and retain evidence.
- Integrate plant-level assurance with enterprise governance, continuous control monitoring, independent challenge, board reporting, and multi-site conformance review.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; AI inventory; RACI; risk acceptance; governance minutes
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- central policy without plant implementation
- incomplete inventory
- unclear ownership
- undocumented exceptions
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION
| Field | Content |
|---|---|
| Domain | D7: HUMAN & SOCIETAL HARMS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Simulation campaigns + click tracking + remedial training.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai-generated phishing simulation in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define human authority, train users, test usability, provide escalation and override, and monitor adverse human-factor effects.
- Conduct human-factors engineering, competence validation, fatigue and workload assessment, independent ethics review where relevant, and recurring operator drills.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; training records; human-factors test; override drill; complaint or adverse-impact review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- nominal human-in-the-loop
- operators cannot realistically intervene
- training not role-specific
- alert fatigue
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D7-CTL-H02 — DEEPFAKE DETECTION TRAINING
| Field | Content |
|---|---|
| Domain | D7: HUMAN & SOCIETAL HARMS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Training modules + quiz + simulated attacks.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply deepfake detection training in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define human authority, train users, test usability, provide escalation and override, and monitor adverse human-factor effects.
- Conduct human-factors engineering, competence validation, fatigue and workload assessment, independent ethics review where relevant, and recurring operator drills.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; training records; human-factors test; override drill; complaint or adverse-impact review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- nominal human-in-the-loop
- operators cannot realistically intervene
- training not role-specific
- alert fatigue
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION
| Field | Content |
|---|---|
| Domain | D7: HUMAN & SOCIETAL HARMS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Independent channel verification + policy enforcement.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply out-of-band authentication in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define human authority, train users, test usability, provide escalation and override, and monitor adverse human-factor effects.
- Conduct human-factors engineering, competence validation, fatigue and workload assessment, independent ethics review where relevant, and recurring operator drills.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; training records; human-factors test; override drill; complaint or adverse-impact review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- nominal human-in-the-loop
- operators cannot realistically intervene
- training not role-specific
- alert fatigue
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D7-CTL-H04 — AI SOCIAL ENGINEERING IR
| Field | Content |
|---|---|
| Domain | D7: HUMAN & SOCIETAL HARMS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Tabletop exercises + IR plan + verification triggers.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai social engineering ir in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define human authority, train users, test usability, provide escalation and override, and monitor adverse human-factor effects.
- Conduct human-factors engineering, competence validation, fatigue and workload assessment, independent ethics review where relevant, and recurring operator drills.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; training records; human-factors test; override drill; complaint or adverse-impact review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- nominal human-in-the-loop
- operators cannot realistically intervene
- training not role-specific
- alert fatigue
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE
| Field | Content |
|---|---|
| Domain | D7: HUMAN & SOCIETAL HARMS |
| Applicability | Applicable |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Low |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
AI-generated phishing detection + SOC tuning + response automation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply ai-enhanced external attack defense in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Define human authority, train users, test usability, provide escalation and override, and monitor adverse human-factor effects.
- Conduct human-factors engineering, competence validation, fatigue and workload assessment, independent ethics review where relevant, and recurring operator drills.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; training records; human-factors test; override drill; complaint or adverse-impact review
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- nominal human-in-the-loop
- operators cannot realistically intervene
- training not role-specific
- alert fatigue
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D8-CTL-01 — EU AI ACT RISK TIER MAPPING
| Field | Content |
|---|---|
| Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Risk classification framework + conformity assessment.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply eu ai act risk tier mapping in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Log material events, define incident criteria, preserve evidence, test rollback and manual fallback, and conduct post-incident review.
- Correlate AI, OT, safety and quality telemetry; automate containment; test cross-plant recovery; and independently validate restart readiness.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; incident playbook; logs; exercise results; recovery and restart approval
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- monitoring only accuracy
- no production stop criteria
- untested fallback
- restart without quality and safety revalidation
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D8-CTL-02 — ISO 42001 GAP ANALYSIS
| Field | Content |
|---|---|
| Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Gap analysis methodology + remediation tracking.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply iso 42001 gap analysis in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Log material events, define incident criteria, preserve evidence, test rollback and manual fallback, and conduct post-incident review.
- Correlate AI, OT, safety and quality telemetry; automate containment; test cross-plant recovery; and independently validate restart readiness.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; incident playbook; logs; exercise results; recovery and restart approval
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- monitoring only accuracy
- no production stop criteria
- untested fallback
- restart without quality and safety revalidation
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION
| Field | Content |
|---|---|
| Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Technical documentation + training data summary + copyright attestation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply gpai technical documentation verification in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Log material events, define incident criteria, preserve evidence, test rollback and manual fallback, and conduct post-incident review.
- Correlate AI, OT, safety and quality telemetry; automate containment; test cross-plant recovery; and independently validate restart readiness.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; incident playbook; logs; exercise results; recovery and restart approval
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- monitoring only accuracy
- no production stop criteria
- untested fallback
- restart without quality and safety revalidation
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)
| Field | Content |
|---|---|
| Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Incident classification + notification workflow + SLA monitoring.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply dora ict incident reporting (financial sector) in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Log material events, define incident criteria, preserve evidence, test rollback and manual fallback, and conduct post-incident review.
- Correlate AI, OT, safety and quality telemetry; automate containment; test cross-plant recovery; and independently validate restart readiness.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; incident playbook; logs; exercise results; recovery and restart approval
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- monitoring only accuracy
- no production stop criteria
- untested fallback
- restart without quality and safety revalidation
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK
| Field | Content |
|---|---|
| Domain | D8: REGULATORY ALIGNMENT & COMPLIANCE |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | High |
| Implementation track | Both |
| OT friction | Moderate |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Human-in-the-loop for advisory/approval workflows; human-on-the-loop or independent protection for high-speed OT. |
Authoritative Requirement
Secure development practices + attestation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply nist sp 800-218a compliance check in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Log material events, define incident criteria, preserve evidence, test rollback and manual fallback, and conduct post-incident review.
- Correlate AI, OT, safety and quality telemetry; automate containment; test cross-plant recovery; and independently validate restart readiness.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; incident playbook; logs; exercise results; recovery and restart approval
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- monitoring only accuracy
- no production stop criteria
- untested fallback
- restart without quality and safety revalidation
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT
| Field | Content |
|---|---|
| Domain | D9: PHYSICAL AI SAFETY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | Core |
| Implementation track | OT/Edge and Physical AI |
| OT friction | High |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Independent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity/temperature/current limits; geofencing for autonomous systems; exclusion zones; rate-of-change limits for safety-critical parameters. AI output gated through safety monitor — monitor vetoes any out-of-boundary command without AI system awareness.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply physical harm boundary enforcement in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain independent safety functions, constrained actuation, validated operating envelopes, emergency stop, physical access controls, and safe-state behavior.
- Apply defence-in-depth across perception, planning and actuation; independent monitoring; formal safety cases; adversarial physical testing; and validated degraded modes.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; safety case; operating envelope; interlock test; physical access and emergency-stop test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- AI relied on as sole safety control
- unsafe operating envelope
- no physical adversarial testing
- safety and security reviews disconnected
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION
| Field | Content |
|---|---|
| Domain | D9: PHYSICAL AI SAFETY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | Core |
| Implementation track | OT/Edge and Physical AI |
| OT friction | High |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
For each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); transition time to safe state (must be within stopping distance/reaction time for physical context); trigger conditions for safe state entry; recovery procedure. Implement degraded mode ladder: Full AI control → AI-assisted human control → Manual-only → Safe state.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply safe state and graceful degradation in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain independent safety functions, constrained actuation, validated operating envelopes, emergency stop, physical access controls, and safe-state behavior.
- Apply defence-in-depth across perception, planning and actuation; independent monitoring; formal safety cases; adversarial physical testing; and validated degraded modes.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; safety case; operating envelope; interlock test; physical access and emergency-stop test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- AI relied on as sole safety control
- unsafe operating envelope
- no physical adversarial testing
- safety and security reviews disconnected
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP
| Field | Content |
|---|---|
| Domain | D9: PHYSICAL AI SAFETY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | Conditional |
| Implementation track | OT/Edge and Physical AI |
| OT friction | High |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Hardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human operator interface that immediately transfers control to safe state. Override must be possible when: AI communication is disrupted; AI system is under adversarial attack; AI model is producing anomalous outputs. Override authority must be unconditional — no AI reasoning, confidence scoring, or approval process may delay or prevent override activation.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply human override and emergency stop in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain independent safety functions, constrained actuation, validated operating envelopes, emergency stop, physical access controls, and safe-state behavior.
- Apply defence-in-depth across perception, planning and actuation; independent monitoring; formal safety cases; adversarial physical testing; and validated degraded modes.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; safety case; operating envelope; interlock test; physical access and emergency-stop test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- AI relied on as sole safety control
- unsafe operating envelope
- no physical adversarial testing
- safety and security reviews disconnected
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION
| Field | Content |
|---|---|
| Domain | D9: PHYSICAL AI SAFETY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | Core |
| Implementation track | OT/Edge and Physical AI |
| OT friction | High |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Three-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-validate against redundant sensor channels. (2) Actuator layer — monitor command streams for sequences inconsistent with operating context; flag commands outside physically feasible envelope. (3) AI inference layer — apply GAISSF™ D2-CTL-01 (Prompt Injection Detection) equivalent for physical AI inputs; monitor input feature distributions for adversarial perturbation signatures. All detections trigger immediate safe state entry (D9-CTL-02) and incident record with root_cause_category = Adversarial_Attack, root_cause_specific_type = Cyber_Physical_Attack.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply cyber-physical attack detection in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain independent safety functions, constrained actuation, validated operating envelopes, emergency stop, physical access controls, and safe-state behavior.
- Apply defence-in-depth across perception, planning and actuation; independent monitoring; formal safety cases; adversarial physical testing; and validated degraded modes.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; safety case; operating envelope; interlock test; physical access and emergency-stop test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- AI relied on as sole safety control
- unsafe operating envelope
- no physical adversarial testing
- safety and security reviews disconnected
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING
| Field | Content |
|---|---|
| Domain | D9: PHYSICAL AI SAFETY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | Core |
| Implementation track | OT/Edge and Physical AI |
| OT friction | High |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Sensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence falls below threshold. (2) Data plausibility — real-time statistical validation against physical laws, historical baselines, and redundant sensor cross-validation. (3) Degraded sensor handling — explicit policy for each sensor failure mode: degrade gracefully (reduce AI authority, increase human oversight) or enter safe state. (4) Calibration management — automated alert when calibration certificates expire; block AI system from operational use with expired sensor calibration.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply physical environment integrity monitoring in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain independent safety functions, constrained actuation, validated operating envelopes, emergency stop, physical access controls, and safe-state behavior.
- Apply defence-in-depth across perception, planning and actuation; independent monitoring; formal safety cases; adversarial physical testing; and validated degraded modes.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; safety case; operating envelope; interlock test; physical access and emergency-stop test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- AI relied on as sole safety control
- unsafe operating envelope
- no physical adversarial testing
- safety and security reviews disconnected
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D9-CTL-06 — ACTUATOR COMMAND VERIFICATION
| Field | Content |
|---|---|
| Domain | D9: PHYSICAL AI SAFETY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | Core |
| Implementation track | OT/Edge and Physical AI |
| OT friction | High |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
Pre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibility check — command consistent with prior sequence; flag implausible state transitions for human review. (3) Rate-of-change check — rate of change does not exceed safe limits (acceleration rate, force application rate, temperature change rate). (4) Dual-approval for irreversible actions — actuator commands causing irreversible physical changes (cutting, welding, demolition, high-energy discharge) require hardware interlock confirmation. Verification gate implemented in IEC 61508 SIL 3 certified software or hardware logic independent of AI model.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply actuator command verification in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain independent safety functions, constrained actuation, validated operating envelopes, emergency stop, physical access controls, and safe-state behavior.
- Apply defence-in-depth across perception, planning and actuation; independent monitoring; formal safety cases; adversarial physical testing; and validated degraded modes.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; safety case; operating envelope; interlock test; physical access and emergency-stop test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- AI relied on as sole safety control
- unsafe operating envelope
- no physical adversarial testing
- safety and security reviews disconnected
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION
| Field | Content |
|---|---|
| Domain | D9: PHYSICAL AI SAFETY |
| Applicability | Applicable with manufacturing interpretation |
| Sector relevance | Core |
| Implementation track | OT/Edge and Physical AI |
| OT friction | High |
| Conditional trigger | Applicable when the scoped system uses the capability or faces the risk addressed by the control. |
| Human oversight mode | Select human-in-the-loop, human-on-the-loop, or human-out-of-the-loop with independent protection based on process speed and consequence. |
Authoritative Requirement
(1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safety monitor decisions; all human override activations; system health telemetry. Safety-critical systems retain 300 seconds minimum. (2) Incident freeze — on any safety-relevant event, automatically freeze buffer and begin extended logging. Frozen buffer write-protected. (3) Cryptographic integrity — all records SHA-256 hashed and ECDSA signed at point of creation. For Optimized tier: CRYSTALS-Dilithium signing (post-quantum). (4) Regulatory retention — ICAO Annex 13: 5 years minimum; EU AI Act Art. 19: 10 years; DORA Art. 12: 5 years. (5) UAIF® integration — automatically populate UAIF® incident record from evidence package.
Manufacturing Interpretation
In manufacturing, this control requires the organisation to apply physical incident evidence preservation in a way that accounts for long-lived assets, constrained maintenance windows, plant-specific conditions, product conformity, physical consequences and separation of safety functions from AI.
Minimum and Enhanced Implementation
- Maintain independent safety functions, constrained actuation, validated operating envelopes, emergency stop, physical access controls, and safe-state behavior.
- Apply defence-in-depth across perception, planning and actuation; independent monitoring; formal safety cases; adversarial physical testing; and validated degraded modes.
Evidence and Assessment
approved scope and owner; risk assessment; architecture or data-flow diagram; configuration and change records; test results; monitoring or review records; safety case; operating envelope; interlock test; physical access and emergency-stop test
Confirm the control operates at sampled plants and not only in corporate policy. Trace one deployed system from intake through validation, deployment, monitoring, change and recovery. Challenge supplier assertions and verify evidence quality.
Legacy OT and Compensating Controls
Apply proportionately to architecture, consequence and deployment context.
Use compensating monitoring, gateways, signed offline transfer, procedural approval or independent protection where direct implementation is technically infeasible.
Failure Modes, Residual Risk and Limits
- AI relied on as sole safety control
- unsafe operating envelope
- no physical adversarial testing
- safety and security reviews disconnected
Residual risk remains from unknown failure modes, incomplete data, supplier opacity, plant variation, human factors and correlated dependencies. Risk acceptance must be explicit for production- or safety-affecting systems.
Implementation of this control does not establish functional safety, product conformity, legal compliance or incident prevention by itself.
11. Manufacturing Threat Scenarios
| ID | Scenario and claim tier | Actor/cause | AI tier | Confidence | Evidence status |
|---|---|---|---|---|---|
| TS-01 | Poisoned predictive-maintenance data [T4] | Malicious insider or compromised data source | Tier 3 | Moderate | Plausible; not confirmed for a specific site |
| TS-02 | Manipulated machine-vision inspection [T4] | External attacker or insider | Tier 3 | Moderate | Observed technique; manufacturing occurrence context-dependent |
| TS-03 | Compromised edge inference device [T3] | Cybercriminal or supplier compromise | Tier 3 | Moderate | Credible observed technique |
| TS-04 | Malicious model update [T3] | Supplier, attacker or insider | Tier 3 | Moderate | Credible scenario |
| TS-05 | Cloud AI outage affecting scheduling [T2] | Cloud/service failure | Tier 2 | High | Common dependency failure pattern |
| TS-06 | Generative AI leakage of proprietary design data [T4] | Negligent user or provider exposure | Tier 2 | High | Observed class of risk |
| TS-07 | Adversarial input to robotic vision [T4] | External or insider | Tier 4 | Low | Plausible; site-specific feasibility required |
| TS-08 | False sensor data drives incorrect optimisation [T3] | Compromised sensor or network path | Tier 4 | Moderate | Credible industrial attack path |
| TS-09 | Compromised supplier model [T3] | Supply-chain actor | Tier 3 | Moderate | Plausible; evidence depends on supplier |
| TS-10 | Unauthorised AI connection to OT [T4] | Employee, contractor or integrator | Tier 3 | High | Common governance failure pattern |
| TS-11 | Operator overreliance on incorrect maintenance advice [T2] | Human factors / model error | Tier 2 | High | Well-established automation-bias mechanism |
| TS-12 | Manipulated digital twin [T4] | Attacker or data integrity failure | Tier 3 | Moderate | Plausible |
| TS-13 | Quality drift remains undetected [T2] | Model/data drift | Tier 3 | High | Common model lifecycle risk |
| TS-14 | AI-enabled insider theft [T4] | Malicious insider | Tier 2 | Moderate | Credible |
| TS-15 | Ransomware disrupts AI-dependent production [T2] | Cybercriminal | Tier 3 | High | Observed industrial threat class |
| TS-16 | Unauthorised threshold modification [T3] | Insider or compromised admin | Tier 3 | Moderate | Credible |
| TS-17 | Compromised autonomous mobile robot [T3] | External attacker or supplier | Tier 4 | Moderate | Plausible/observed component techniques |
| TS-18 | Model rollback failure [T4] | Operational failure | Tier 3 | Moderate | Credible |
| TS-19 | Defective model propagates across plants [T4] | Central deployment pipeline failure | Tier 3 | Moderate | Credible |
| TS-20 | Supplier remote-access abuse [T3] | Supplier or compromised account | Tier 3 | High | Observed industrial access pattern |
| TS-21 | Synthetic data creates unsafe blind spots [T4] | Development error | Tier 3 | Moderate | Plausible |
| TS-22 | Shadow generative AI handles confidential data [T2] | Negligent employee | Tier 2 | High | Common enterprise risk |
| TS-23 | AI recommendation bypasses engineering change control [T4] | Process design failure | Tier 4 | Moderate | Credible |
| TS-24 | Worker-safety detection false negative [T4] | Model/data failure | Tier 4 | High | Intrinsic performance risk |
| TS-25 | Environmental change collapses performance [T2] | Distribution shift | Tier 3 | High | Established ML failure mode |
The tags classify the evidentiary basis for the scenario description, not the severity of the scenario. No site-specific access path, occurrence or consequence is established without supporting evidence.
12. EU Artificial Intelligence Act Boundary
GAISSF tier classification and SEC-045 assessment do not constitute an EU Artificial Intelligence Act legal classification or conformity assessment. They do not replace technical documentation, quality-management, risk-management, human-oversight, registration, post-market monitoring, fundamental-rights impact assessment or other obligations where those requirements apply.
Manufacturing organisations must determine legal classification from intended purpose, role in the value chain, product integration, applicable annexes, sector legislation and jurisdiction. GAISSF tiers are an operational assurance model, not a legal classification.
13. Notably Absent
- Verified public disclosures establishing the frequency of AI-driven operational-technology disruption in manufacturing were not identified.
- Proprietary internal ODA3 telemetry confirming the frequency of AI-driven operational-technology disruption is absent because ODA3 Institute was founded in March 2026 and does not maintain a historical proprietary client incident dataset.
- Malicious AI-model manipulation, kinetic sabotage, cross-plant propagation or direct safety-system compromise is not treated as confirmed merely because it is technically plausible.
- Any assertion that GAISSF security controls replace or satisfy probability-of-failure metrics required for functional-safety certification is notably absent and expressly disclaimed.
- The review did not establish that reported manufacturing incidents are predominantly attributable to any single AI failure category.
14. Limitations
ODA3 Institute is an applied research and advisory firm founded in March 2026. It does not maintain a historical proprietary client incident dataset covering manufacturing AI events. Sector interpretations and threat scenarios are derived from authoritative standards, public disclosures, regulatory and official materials, peer-reviewed or academic research, controlled technical demonstrations and explicitly labelled analytical scenarios. Absence of proprietary telemetry limits frequency estimation and must not be interpreted as evidence that an event has or has not occurred.
Public disclosure is incomplete, architectures are often confidential, attribution is difficult, and controlled research does not establish field frequency. External standards, legal obligations and supplier products must be reverified at release and use.
15. Worked Example — Tier 2 Predictive Maintenance for a CNC Machine
| Stage | Worked example |
|---|---|
| Intake | Single high-value CNC machine; vibration, temperature and maintenance records; advisory maintenance recommendation; no direct actuation. |
| Classification | Tier 2 because recommendations influence maintenance timing but do not command the machine. Escalate to Tier 3 if work orders or production release decisions are automated. |
| Primary controls | D1-CTL-01 provenance; D1-CTL-03 drift; relevant input/runtime controls; supplier controls; output integrity; governance and monitoring controls. |
| Threat scenarios | TS-01 poisoned maintenance data; TS-11 operator overreliance; TS-13 undetected drift; TS-25 changed environmental conditions. |
| Evidence | Sensor calibration, data lineage, model hash, validation by operating regime, maintenance-owner approval, drift dashboard, rollback package and operator training. |
| Fallback | Use the approved preventive-maintenance schedule and engineering inspection process if the model is unavailable or unreliable. |
| Financial estimate | Expected avoidable downtime and maintenance exposure using low/base/high event frequency and line-hour contribution margin. |
| Notably absent | No claim that the model directly controls the machine or that a malicious poisoning event has occurred. |
A separately populated worked-example workbook is included in the package.
16. Final Validation and Publication Gates
| Gate | Status | Required action |
|---|---|---|
| 59-control integrity | Closed | 59 unique authoritative identifiers represented; no normative control added. |
| Evidence model | Closed | Claim tiers and artifact-strength classes separated. |
| Functional-safety boundary | Closed | Lifecycle interface and non-equivalence language added. |
| External standards verification | Closed for cited edition status as of 1 July 2026 | Reverify at future releases. |
| Trademark status | Open controlled gate | Authorised legal owner must verify status immediately before publication. |
| Release signing | Open controlled gate | Create detached signature only after authorised signing identity and key-custody process exist. |
| Final public status | Conditional | Do not label Final Publication v1.0 until open gates are signed off. |