SECTOR GUIDANCE

Retail Sector Guidance

GAISSF implementation guidance for AI systems and assurance programmes in the retail sector.

ODA3 Institute

Operational interpretation, evidence and assessment package

SEC-046 | Version 1.0 | Publication Candidate - Open Review Gates | 1 July 2026

FieldValue
Document IDSEC-046
Version1.0
ClassificationInformative sector implementation guidance
StatusPublication Candidate - Open Review Gates
PublisherODA3 Institute
Legal entityODA3 Pvt Ltd
Authoritative sourceGAISSF-NOR-001 v1.0, Final Publication v1.0
Control baseline59 controls across nine domains
Publication channelODA3 Institute website and GitHub

Table of Contents

Contents: Executive overview; Start Here; Methodology; 1 Scope; 2 Retail context; 3 AI taxonomy; 4 Threat landscape; 5 Control profiles; 6 Complete control interpretation; 7 Data governance; 8 Supply chain; 9 Lifecycle; 10 Testing; 11 Human oversight; 12 Consumer protection; 13 Metrics; 14 Incident management; 15 Roles; 16 Roadmap; 17 Evidence; 18 Maturity; 19 Failures; 20 Scenarios; 21 Crosswalk; 22 Notably Absent; 23 Limitations; Appendices A-F.

How to use this guide

Use this guide to scope retail AI systems, interpret the authoritative GAISSF controls, prioritise implementation, collect evidence and prepare for internal or independent assessment. GAISSF-NOR-001 remains authoritative where wording differs.

Evidence tiers

TierMeaning
T1Primary authoritative evidence: legislation, regulation, official standards and government or regulator material.
T2Strong secondary evidence: peer-reviewed research, recognised industry bodies and independently verified technical research.
T3Contextual evidence: vendor disclosures, credible reporting, practitioner case studies and limited datasets.
T4Illustrative material: hypothetical scenarios and implementation examples; not evidence of prevalence.

Executive overview

Retail AI operates across customer-facing digital services, payment and fraud systems, distributed stores, warehouses, workforce systems, marketplaces and supplier platforms. The practical risk is not simply model accuracy. It is whether AI behaviour, data use, tool access, model changes, human escalation and fallback remain controlled across a fragmented operating environment.

  • Highest-consequence profiles commonly include payment and fraud decisions, biometric identification, hiring, autonomous stores and warehouse robotics.
  • High-volume moderate-consequence systems can still create material aggregate harm through pricing errors, misleading product content, discriminatory targeting or uncontrolled provider changes.
  • Assurance requires operating evidence: approved scope, tested safeguards, monitoring, exceptions, incident records and supplier evidence rights.
  • This package does not claim that one control set proves legal compliance, payment compliance, employment-law compliance, biometric legality or consumer-protection compliance.

1. Inventory every production and pilot AI system, including embedded software-as-a-service, franchise and store-edge deployments. 2. Approve accountable owners and a 59-control Statement of Applicability. 3. Implement the P1 controls first: data provenance, drift, prompt/tool boundaries, supplier governance, personal-data protection, human review, complete audit trails, incident readiness and continuity. 4. Apply D9 only where physical AI is in scope; apply biometric, workforce and other high-impact safeguards when the use-case trigger exists. 5. Collect operating evidence before describing a control as implemented.

Start Here - first implementation decisions

Analysis of public disclosures and authoritative standards informs the external context [T1-T2]. Peer-reviewed and technical research supports demonstrated attack classes [T2], while practitioner patterns and illustrative scenarios are contextual [T3-T4]. No proprietary retailer telemetry or internal incident dataset was used. Threat frequency and loss magnitude are not inferred where public evidence is insufficient.

Methodology and evidence boundary

1. Scope and normative boundary

The guide applies to retailers, marketplaces, direct-to-consumer businesses, franchise systems, fulfilment operations and retail technology functions that develop, acquire, integrate, deploy, operate, monitor or retire AI systems. It covers internally developed systems, commercial AI, embedded AI, generative AI, agentic systems, computer vision, predictive models and physical AI.

GAISSF conformance scope remains authoritative: D1-D8 are the 52-control canonical Foundational scope; D9 contains seven additional controls that apply where physical AI is in scope. The P1/P2/P3 labels in this guide are implementation sequencing aids only and do not change normative applicability.

SHALL and SHALL NOT are used only when reproducing or referring to authoritative GAISSF requirements. Sector guidance uses should, may and can. A contractual or certification instrument may separately make defined guidance mandatory.

2. Retail operating context

  • High transaction and customer-data volumes with low-latency availability requirements.
  • Distributed store, edge, warehouse, mobile and cloud infrastructure, often combined with legacy systems.
  • Substantial dependence on payment processors, e-commerce platforms, fraud vendors, customer-data platforms, logistics providers and foundation-model services.
  • Seasonal demand shifts, promotion spikes, workforce turnover and franchise variation that can degrade controls or model performance.
  • Direct consumer and worker impacts from pricing, fraud, biometric, recommendation, scheduling and hiring systems.

3. Retail AI system taxonomy

IDUse caseBusiness areaDataAuthorityCriticalityOversight
RET-UC-001Personalised recommendationsCustomer experienceCustomer account, browsing, transaction and catalogue dataDecision supportModerateRisk-based review and escalation
RET-UC-002Product search and rankingE-commerceQueries, clicks, catalogue and availabilityDecision supportModerateRisk-based review and escalation
RET-UC-003Dynamic pricingMerchandisingDemand, inventory, competitor and customer contextAutomated decisionHighMandatory pre- or post-decision review
RET-UC-004Promotion optimisationMarketingCampaign, customer, basket and margin dataAutomated decisionModerateRisk-based review and escalation
RET-UC-005Demand forecastingSupply chainSales, seasonality, weather and eventsDecision supportModerateRisk-based review and escalation
RET-UC-006Inventory allocationSupply chainStock, sales, lead time and store dataAutomated decisionModerateRisk-based review and escalation
RET-UC-007Automated replenishmentStore operationsInventory, sales and supplier feedsAutomated actionModerateRisk-based review and escalation
RET-UC-008Warehouse roboticsFulfilmentSensor, order and route dataPhysical AICriticalMandatory pre- or post-decision review
RET-UC-009Route and delivery optimisationLogisticsAddress, location, capacity and trafficDecision supportModerateRisk-based review and escalation
RET-UC-010Self-checkout visionStore operationsVideo, item and payment eventsDecision supportHighMandatory pre- or post-decision review
RET-UC-011Computer-vision loss preventionLoss preventionVideo, behavioural and transaction signalsHigh-impact alertingHighMandatory pre- or post-decision review
RET-UC-012Fraud detectionPayments and fraudPayment, device, identity and transaction dataAutomated decisionCriticalMandatory pre- or post-decision review
RET-UC-013Payment-risk scoringPayments and fraudPayment, identity and behavioural signalsHigh-impact decisionCriticalMandatory pre- or post-decision review
RET-UC-014Customer-service chatbotCustomer serviceConversation, account and product dataConversational assistanceModerateRisk-based review and escalation
RET-UC-015Generative product descriptionsContent operationsCatalogue, supplier and brand dataContent generationModerateRisk-based review and escalation
RET-UC-016Marketing-content generationMarketingCampaign, brand and audience dataContent generationModerateRisk-based review and escalation
RET-UC-017Customer segmentationMarketing analyticsDemographic, behavioural and transaction dataProfilingModerateRisk-based review and escalation
RET-UC-018Loyalty analyticsLoyalty operationsIdentity, purchases, rewards and locationProfilingModerateRisk-based review and escalation
RET-UC-019Retail media targetingRetail mediaAudience, purchase and browsing dataAutomated targetingModerateRisk-based review and escalation
RET-UC-020Facial recognitionStore securityBiometric templates and videoIdentificationCriticalMandatory pre- or post-decision review
RET-UC-021Age estimationRestricted salesFacial image or videoDecision supportHighMandatory pre- or post-decision review
RET-UC-022Workforce schedulingHuman resourcesAvailability, performance and demandEmployment decision supportModerateRisk-based review and escalation
RET-UC-023Employee productivity monitoringHuman resourcesActivity, location and performance dataMonitoringModerateRisk-based review and escalation
RET-UC-024Hiring and screeningHuman resourcesApplications, assessments and interviewsHigh-impact decisionCriticalMandatory pre- or post-decision review
RET-UC-025Returns-abuse detectionReturns and fraudReturns, identity, transaction and device dataAutomated decisionHighMandatory pre- or post-decision review
RET-UC-026Counterfeit detectionMarketplace integrityImages, listings, seller and provenance dataDecision supportModerateRisk-based review and escalation
RET-UC-027Visual search and virtual try-onCustomer experienceImages, body or facial features and catalogueInteractive assistanceModerateRisk-based review and escalation
RET-UC-028Smart shelves and store analyticsStore operationsSensor, shelf, video and inventory dataEdge analyticsModerateRisk-based review and escalation
RET-UC-029Autonomous store systemsStore operationsVideo, sensor, identity and transaction dataAutonomous systemCriticalMandatory pre- or post-decision review
RET-UC-030Developer copilots and code generationRetail technologySource code, prompts, repositories and ticketsEngineering assistanceModerateRisk-based review and escalation
RET-UC-031Third-party foundation-model APIEnterprise AIPrompts, retrieval data and generated outputsExternal dependencyModerateRisk-based review and escalation
RET-UC-032Synthetic retail data generationData scienceProduction distributions and schemasData generationModerateRisk-based review and escalation

4. Retail threat and failure landscape

Analysis of public disclosures supports several demonstrated AI attack classes [T2], while retail-specific frequency and loss data remain incomplete. Academic and technical simulations support plausible attack paths [T3]. The register below separates demonstrated classes from contextual sector exposures [T2-T3].

IDThreat or failureActor/sourcePathwayEvidenceUncertainty
RET-THR-001Training-data poisoningMalicious supplier, insider or external attackerCorrupts model behaviour through manipulated dataT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-002Retrieval poisoningSeller, advertiser or content attackerInjects misleading catalogue or knowledge-base contentT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-003Prompt injectionCustomer, attacker or compromised content sourceOverrides intended chatbot or agent instructionsT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-004Indirect prompt injectionCompromised webpage, email, review or documentTriggers hidden instructions through retrieved contentT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-005Model extractionCompetitor or cybercriminalSteals model behaviour through systematic queryingT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-006Membership or data inferenceExternal attackerInfers sensitive customer or training-set informationT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-007API credential theftCybercriminal or insiderObtains privileged access to model or platform APIsT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-008Agent tool abuseCustomer, insider or attackerCauses agent to invoke refunds, promotions or account actionsT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-009Inter-agent trust failureCompromised autonomous componentPropagates untrusted instructions across agentsT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-010Uncontrolled model updateProvider or change-management failureChanges behaviour without retailer approval or validationT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-011Vendor outage or withdrawalThird-party providerRemoves critical AI service or supportT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-012Supplier data reuseThird-party providerUses retailer data for training beyond agreed purposeT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-013Synthetic identity fraudFraud ringUses generated identities and documents to open accountsT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-014Loyalty-account takeoverCybercriminalSteals rewards, profile data or payment instrumentsT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-015Promotion and coupon abuseFraud ring or malicious customerOptimises exploitation of promotion logicT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-016Returns fraud adaptationFraud ringLearns thresholds and evades returns-abuse modelsT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-017Pricing manipulationCompetitor, scraper or compromised inputInfluences dynamic pricing through false signalsT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-018Inventory forecast manipulationSupplier, insider or attackerCreates shortage, overstock or allocation distortionT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-019Recommendation manipulationSeller, advertiser or bot networkImproves ranking through adversarial engagementT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-020Hallucinated product claimsModel or workflow failureGenerates false specifications, compatibility or safety informationT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-021Deceptive synthetic reviewsSeller or content generatorCreates misleading consumer endorsementsT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-022Biometric false matchModel limitations or poor conditionsMisidentifies a customer or workerT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-023Age-estimation errorModel limitations or demographic disparityIncorrectly permits or denies restricted saleT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-024Loss-prevention false positiveModel limitations or biased dataTriggers unjustified interventionT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-025Discriminatory segmentationDesign or data biasProduces unequal targeting, service or offersT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-026Employment decision biasDesign or data biasUnfairly affects hiring, scheduling or performance outcomesT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-027Edge-device tamperingPhysical attacker or insiderManipulates cameras, sensors or smart shelvesT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-028Warehouse command manipulationCyber-physical attackerIssues unsafe or unauthorised robotic actionsT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-029Catalogue corruptionSupplier, seller or integration failurePropagates incorrect attributes and product informationT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-030Insufficient audit loggingDesign or operational failurePrevents reconstruction, challenge or accountabilityT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-031Model driftChanging demand or environmentDegrades performance after deploymentT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-032Seasonal distribution shiftDemand volatilityCauses forecast and fraud models to misperformT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-033Generated phishingCybercriminalScales targeted attacks against retail workers and suppliersT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-034Deepfake executive or supplier fraudFraudsterImpersonates authorised persons to change payments or ordersT2 demonstrated/observed classRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-035Sensitive prompt leakageEmployee or system errorExposes customer, supplier or source-code dataT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.
RET-THR-036Open-source model compromiseSupply-chain attackerIntroduces malicious or vulnerable model artefactT3 plausible sector exposureRetail prevalence and loss data are incomplete; validate against internal telemetry.

5. Risk-based retail control profiles

E-commerce and customer interaction

  • Recommendations, search, chatbots, product content, visual search and account services require output validation, prompt-injection controls, customer escalation and change monitoring.

Payments, fraud and loyalty

  • Fraud, payment-risk, returns and loyalty decisions require low-latency controls without removing contestability, evidence retention, fraud monitoring and fallback.

Stores, computer vision and biometrics

  • Store analytics, loss prevention, facial recognition and age estimation require physical-environment testing, privacy and legal review, false-match monitoring and controlled intervention.

Supply chain, warehouse and physical AI

  • Forecasting, replenishment, robotics and autonomous store systems require safe state, command validation, environmental integrity, business continuity and evidence preservation.

Workforce AI

  • Hiring, scheduling and productivity monitoring require documented purpose, impact assessment, human review, appeal routes, access restriction and worker transparency.

Generative and agentic AI

  • Generative content, developer copilots and agents require tool-boundary controls, retrieval security, output validation, supplier governance, logging and rollback.

6. Complete GAISSF retail control interpretation

The following records preserve authoritative GAISSF identifiers and titles [T1]. Retail interpretations are practitioner guidance based on public evidence and operational analysis [T3]; they are not prevalence claims or substitutes for system-specific testing.

D1-CTL-01 - DATASET PROVENANCE & POISONING PREVENTION

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRetail training, tuning and evaluation data often arrive from point-of-sale feeds, loyalty platforms, sellers, suppliers and franchise locations. Preserve source lineage, quarantine abnormal submissions and require approval before contaminated catalogue, fraud or demand data can influence a production model. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-001; RET-UC-008; RET-UC-015
Related threatsRET-THR-001; RET-THR-006; RET-THR-011
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-001; RET-EVD-004
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-001; RET-MET-008
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-02 - MODEL EXTRACTION RESISTANCE

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRecommendation, pricing and fraud APIs can expose commercially valuable decision logic through high-volume queries. Apply rate limits, behavioural detection, response minimisation and contractual controls to make systematic model replication detectable and costly. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-002; RET-UC-009; RET-UC-016; RET-UC-023
Related threatsRET-THR-002; RET-THR-007; RET-THR-012; RET-THR-017
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-002; RET-EVD-005; RET-EVD-008
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-002; RET-MET-009
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-03 - BEHAVIORAL DRIFT DETECTION

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRetail behaviour changes sharply during promotions, holidays, product launches and fraud campaigns. Monitor performance by channel, store cohort and affected population so seasonal change is distinguished from security manipulation or silent model degradation. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-003; RET-UC-010; RET-UC-017; RET-UC-024; RET-UC-031
Related threatsRET-THR-003; RET-THR-008; RET-THR-013
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-003; RET-EVD-006; RET-EVD-009; RET-EVD-012
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-003; RET-MET-010
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-04 - FEDERATED LEARNING POISONING PREVENTION

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWhere stores, franchisees or regional entities train locally, validate and bound each submitted update before aggregation. A compromised edge node must not be able to poison group-wide fraud, forecasting or recommendation behaviour. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-004; RET-UC-011; RET-UC-018
Related threatsRET-THR-004; RET-THR-009; RET-THR-014; RET-THR-019
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-004; RET-EVD-007
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-004; RET-MET-011
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-05 - EMBEDDING SPACE ROBUSTNESS

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationProduct search, visual search and retrieval systems depend on embedding similarity. Test whether adversarial images, seller text or catalogue attributes can move prohibited, counterfeit or irrelevant items into trusted result neighbourhoods. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-005; RET-UC-012; RET-UC-019; RET-UC-026
Related threatsRET-THR-005; RET-THR-010; RET-THR-015
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-005; RET-EVD-008; RET-EVD-011
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-005; RET-MET-012
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-06 - POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationLong-lived model artefacts, signed releases and warehouse or store-edge devices may outlive current cryptographic assumptions. Maintain crypto-agility and migration plans; do not represent post-quantum readiness as achieved unless the full signing and verification chain has been tested. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-006; RET-UC-013; RET-UC-020; RET-UC-027; RET-UC-002
Related threatsRET-THR-006; RET-THR-011; RET-THR-016; RET-THR-021
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-006; RET-EVD-009; RET-EVD-012; RET-EVD-015
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-006; RET-MET-013
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-07 - LORA/ADAPTER INTEGRITY VERIFICATION

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationLow-rank adaptation and other adapters may be used to localise models for brands, regions or franchises. Verify adapter origin, hash, approved base-model compatibility and behaviour before loading it into production. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-007; RET-UC-014; RET-UC-021
Related threatsRET-THR-007; RET-THR-012; RET-THR-017
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-007; RET-EVD-010
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-007; RET-MET-014
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-08 - MODEL MERGE ATTACK DETECTION

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRetail teams may merge models or checkpoints to combine language, vision or fraud capabilities. Treat every merge as a new artefact requiring provenance, behavioural comparison and backdoor testing rather than inheriting trust from the source models. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-008; RET-UC-015; RET-UC-022; RET-UC-029
Related threatsRET-THR-008; RET-THR-013; RET-THR-018; RET-THR-023
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-008; RET-EVD-011; RET-EVD-014
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-008; RET-MET-015
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D1-CTL-09 - QUANTIZATION BACKDOOR SCREENING

FieldRetail implementation record
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationQuantised models are common on cameras, kiosks and store-edge hardware. Re-test quantised builds because compression can expose or preserve behaviours that were not visible in the full-precision model. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-009; RET-UC-016; RET-UC-023; RET-UC-030; RET-UC-005
Related threatsRET-THR-009; RET-THR-014; RET-THR-019
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-009; RET-EVD-012; RET-EVD-015; RET-EVD-018
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-009; RET-MET-016
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D2-CTL-01 - DIRECT PROMPT INJECTION PREVENTION

FieldRetail implementation record
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationCustomer-service and shopping assistants must treat customer prompts as untrusted input. Separate instructions from customer content, constrain account actions and prevent a conversational request from bypassing refund, discount or identity controls. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-010; RET-UC-017; RET-UC-024
Related threatsRET-THR-010; RET-THR-015; RET-THR-020; RET-THR-025
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-010; RET-EVD-013
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-010; RET-MET-017
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D2-CTL-02 - INDIRECT PROMPT INJECTION PREVENTION

FieldRetail implementation record
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRetail assistants ingest product pages, reviews, supplier documents and support content. Sanitise retrieved material and isolate tool instructions so hidden text in a listing or document cannot redirect the model or exfiltrate data. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-011; RET-UC-018; RET-UC-025; RET-UC-032
Related threatsRET-THR-011; RET-THR-016; RET-THR-021
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-011; RET-EVD-014; RET-EVD-017
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-011; RET-MET-018
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D2-CTL-03 - JAILBREAK RESISTANCE TESTING

FieldRetail implementation record
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationTest retail assistants against attempts to produce prohibited product advice, reveal policies, create fraudulent discounts or evade age and account controls. Re-test after model, prompt, retrieval or tool changes. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-012; RET-UC-019; RET-UC-026; RET-UC-001; RET-UC-008
Related threatsRET-THR-012; RET-THR-017; RET-THR-022; RET-THR-027
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-012; RET-EVD-015; RET-EVD-018; RET-EVD-021
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-012; RET-MET-019
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D2-CTL-04 - MULTI-MODAL INJECTION DEFENSE

FieldRetail implementation record
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationVisual-search, receipt, shelf-image and voice systems can carry adversarial instructions outside ordinary text prompts. Validate each modality independently and at the point where modalities are fused. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-013; RET-UC-020; RET-UC-027
Related threatsRET-THR-013; RET-THR-018; RET-THR-023
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-013; RET-EVD-016
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-013; RET-MET-020
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D2-CTL-05 - FUNCTION CALL/TOOL CALL INJECTION PREVENTION

FieldRetail implementation record
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationAgents connected to refunds, inventory, customer records or campaigns must validate every function call against user identity, transaction state and approved limits. Model-generated arguments are not trusted authorisation. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-014; RET-UC-021; RET-UC-028; RET-UC-003
Related threatsRET-THR-014; RET-THR-019; RET-THR-024; RET-THR-029
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-014; RET-EVD-017; RET-EVD-020
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-014; RET-MET-001
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D2-CTL-06 - CROSS-CONTEXT HIJACKING MITIGATION

FieldRetail implementation record
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationA retailer may reuse one model across customer, employee, seller and developer contexts. Enforce context separation so content or memory from one tenant, account or workflow cannot influence another. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-015; RET-UC-022; RET-UC-029; RET-UC-004; RET-UC-011
Related threatsRET-THR-015; RET-THR-020; RET-THR-025
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-015; RET-EVD-018; RET-EVD-021; RET-EVD-024
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-015; RET-MET-002
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D3-CTL-01 - LEAST AGENCY ENFORCEMENT

FieldRetail implementation record
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRetail agents should receive only the tools and transaction authority required for the current task. A product assistant should not obtain refund, pricing or inventory-write capability merely because those tools exist in the same platform. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-016; RET-UC-023; RET-UC-030
Related threatsRET-THR-016; RET-THR-021; RET-THR-026; RET-THR-031
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-016; RET-EVD-019
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-016; RET-MET-003
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D3-CTL-02 - INTER-AGENT COMMUNICATION SECURITY

FieldRetail implementation record
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWhen merchandising, inventory, fraud and customer-service agents exchange messages, authenticate the sender, validate message schemas and record delegated authority. Do not allow one agent to create authority for another through natural-language assertions. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-017; RET-UC-024; RET-UC-031; RET-UC-006
Related threatsRET-THR-017; RET-THR-022; RET-THR-027
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-017; RET-EVD-020; RET-EVD-023
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-017; RET-MET-004
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D3-CTL-03 - AGENTIC PROMPT CHAINING DETECTION

FieldRetail implementation record
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationMulti-step retail workflows can hide unsafe intent across individually benign prompts. Detect chains that progressively obtain customer data, alter promotions or prepare unauthorised transactions. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-018; RET-UC-025; RET-UC-032; RET-UC-007; RET-UC-014
Related threatsRET-THR-018; RET-THR-023; RET-THR-028; RET-THR-033
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-018; RET-EVD-021; RET-EVD-024; RET-EVD-002
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-018; RET-MET-005
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D3-CTL-04 - EMBODIED AI SAFETY CONTROLS

FieldRetail implementation record
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWarehouse robots, autonomous stores and AI-enabled handling equipment require bounded operating zones, tested safety interlocks and controlled behaviour when sensors, networks or models fail. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-019; RET-UC-026; RET-UC-001
Related threatsRET-THR-019; RET-THR-024; RET-THR-029
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-019; RET-EVD-022
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-019; RET-MET-006
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D3-CTL-05 - MULTI-AGENT TRUST CHAIN ATTESTATION

FieldRetail implementation record
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationFor multi-agent retail operations, preserve an attested chain showing which agent, identity, model version and policy authorised each consequential action. Break the chain when any participant cannot be verified. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-020; RET-UC-027; RET-UC-002; RET-UC-009
Related threatsRET-THR-020; RET-THR-025; RET-THR-030; RET-THR-035
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-020; RET-EVD-023; RET-EVD-001
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-020; RET-MET-007
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D3-CTL-06 - PERSISTENT MEMORY EXFILTRATION PREVENTION

FieldRetail implementation record
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationPersistent assistant memory may accumulate customer, employee, seller or source-code information. Prevent retrieval or export of memory outside the originating account and monitor bulk or unusual memory access. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-021; RET-UC-028; RET-UC-003; RET-UC-010; RET-UC-017
Related threatsRET-THR-021; RET-THR-026; RET-THR-031
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-021; RET-EVD-024; RET-EVD-002; RET-EVD-005
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-001; RET-MET-008
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D3-CTL-07 - SECURE MEMORY LIFECYCLE MANAGEMENT

FieldRetail implementation record
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationDefine retention, correction, deletion and re-indexing rules for conversational and agent memory. Account closure, employee departure and model retirement must trigger removal or controlled archival of associated memory. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-022; RET-UC-029; RET-UC-004
Related threatsRET-THR-022; RET-THR-027; RET-THR-032; RET-THR-001
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-022; RET-EVD-025
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-002; RET-MET-009
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D4-CTL-01 - AI BILL OF MATERIALS (AI BOM) MAINTENANCE

FieldRetail implementation record
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationMaintain an AI bill of materials for each retail service covering models, adapters, datasets, retrieval stores, prompts, agents, tools, libraries, providers and edge deployments. Link changes to release and incident records. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-023; RET-UC-030; RET-UC-005; RET-UC-012
Related threatsRET-THR-023; RET-THR-028; RET-THR-033
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-023; RET-EVD-001; RET-EVD-004
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-003; RET-MET-010
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D4-CTL-02 - MODEL FILE & ARTIFACT SCANNING

FieldRetail implementation record
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationScan downloaded models, adapters and serialized artefacts before use. Retail data-science teams must treat model files from public hubs, vendors and internal experiments as executable supply-chain content. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-024; RET-UC-031; RET-UC-006; RET-UC-013; RET-UC-020
Related threatsRET-THR-024; RET-THR-029; RET-THR-034; RET-THR-003
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-024; RET-EVD-002; RET-EVD-005; RET-EVD-008
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-004; RET-MET-011
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D4-CTL-03 - MODEL HUB & REGISTRY VETTING

FieldRetail implementation record
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationApprove model hubs and registries based on provenance, moderation, vulnerability response and licence controls. Prevent unreviewed models from moving directly from an analyst notebook into a customer or store workflow. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-025; RET-UC-032; RET-UC-007
Related threatsRET-THR-025; RET-THR-030; RET-THR-035
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-025; RET-EVD-003
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-005; RET-MET-012
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D4-CTL-04 - MCP SERVER BEHAVIORAL MONITORING

FieldRetail implementation record
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationModel Context Protocol servers can expose inventory, customer relationship management and order systems to agents. Monitor server discovery, tool enumeration, read/write patterns and unexpected access to high-value retail data. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-026; RET-UC-001; RET-UC-008; RET-UC-015
Related threatsRET-THR-026; RET-THR-031; RET-THR-036; RET-THR-005
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-001; RET-EVD-004; RET-EVD-007
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-006; RET-MET-013
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D4-CTL-05 - THIRD-PARTY AI API SECURITY ASSESSMENT

FieldRetail implementation record
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationAssess external AI application programming interfaces for authentication, tenant isolation, data retention, training use, regional processing, model-change notice, rate limits and incident support before sending customer or commercial data. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-027; RET-UC-002; RET-UC-009; RET-UC-016; RET-UC-023
Related threatsRET-THR-027; RET-THR-032; RET-THR-001
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-002; RET-EVD-005; RET-EVD-008; RET-EVD-011
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-007; RET-MET-014
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D4-CTL-06 - SHADOW AI DISCOVERY & GOVERNANCE

FieldRetail implementation record
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationShadow AI commonly appears in marketing, buying, store and franchise teams using consumer tools for copy, images or analysis. Discover unsanctioned use through procurement, network, browser and data-loss signals, then provide an approved alternative and enforce data boundaries. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-028; RET-UC-003; RET-UC-010
Related threatsRET-THR-028; RET-THR-033; RET-THR-002; RET-THR-007
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-003; RET-EVD-006
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-008; RET-MET-015
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D4-CTL-07 - AI SOFTWARE COMPOSITION ANALYSIS (SCA)

FieldRetail implementation record
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationSoftware Composition Analysis for retail AI must include orchestration frameworks, vector databases, model loaders, plugins, computer-vision packages and agent tools, not only the conventional web application dependencies. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-029; RET-UC-004; RET-UC-011; RET-UC-018
Related threatsRET-THR-029; RET-THR-034; RET-THR-003
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-004; RET-EVD-007; RET-EVD-010
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-009; RET-MET-016
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D5-CTL-01 - HARMFUL CONTENT BLOCKING

FieldRetail implementation record
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationBlock outputs that facilitate fraud, unsafe product use, harassment, prohibited goods or harmful employee/customer interactions. Calibrate controls to the channel and provide escalation instead of silently failing consequential requests. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-030; RET-UC-005; RET-UC-012; RET-UC-019; RET-UC-026
Related threatsRET-THR-030; RET-THR-035; RET-THR-004; RET-THR-009
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-005; RET-EVD-008; RET-EVD-011; RET-EVD-014
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-010; RET-MET-017
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D5-CTL-02 - PII LEAKAGE PREVENTION

FieldRetail implementation record
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationPrevent customer, payment, loyalty, employee and supplier identifiers from appearing in prompts, retrieved context or outputs beyond the approved transaction. Test redaction and access boundaries with realistic retail records. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-031; RET-UC-006; RET-UC-013
Related threatsRET-THR-031; RET-THR-036; RET-THR-005
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-006; RET-EVD-009
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-011; RET-MET-018
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D5-CTL-03 - COPYRIGHT DETECTION

FieldRetail implementation record
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationProduct descriptions, advertising and generated imagery may reproduce protected material. Record source rights, detect suspicious similarity and route uncertain content for review before publication. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-032; RET-UC-007; RET-UC-014; RET-UC-021
Related threatsRET-THR-032; RET-THR-001; RET-THR-006; RET-THR-011
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-007; RET-EVD-010; RET-EVD-013
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-012; RET-MET-019
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D5-CTL-04 - AI WATERMARKING ROBUSTNESS

FieldRetail implementation record
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWhere watermarks or provenance markers are used for retail media, test whether resizing, cropping, recompression and marketplace reposting remove them. Do not treat watermark presence as proof that content is authentic. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-001; RET-UC-008; RET-UC-015; RET-UC-022; RET-UC-029
Related threatsRET-THR-033; RET-THR-002; RET-THR-007
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-008; RET-EVD-011; RET-EVD-014; RET-EVD-017
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-013; RET-MET-020
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D5-CTL-05 - PRIVACY-BY-DESIGN VERIFICATION

FieldRetail implementation record
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationVerify privacy controls at design and release gates for loyalty profiling, retail media, biometrics, employee monitoring and conversational systems. Data minimisation and purpose boundaries must be visible in architecture and operating evidence. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-002; RET-UC-009; RET-UC-016
Related threatsRET-THR-034; RET-THR-003; RET-THR-008; RET-THR-013
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-009; RET-EVD-012
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-014; RET-MET-001
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D5-CTL-06 - PRIVACY-PRESERVING ML VALIDATION

FieldRetail implementation record
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWhere federated learning, differential privacy, synthetic data or secure computation is claimed, test the privacy parameters and residual leakage against the retail use case. A technique label alone is not evidence of effective protection. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-003; RET-UC-010; RET-UC-017; RET-UC-024
Related threatsRET-THR-035; RET-THR-004; RET-THR-009
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-010; RET-EVD-013; RET-EVD-016
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-015; RET-MET-002
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D6-CTL-01 - HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS

FieldRetail implementation record
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRequire authorised human review before consequential actions such as account suspension, return denial, biometric intervention, hiring rejection, high-value refund or unsafe warehouse movement. Reviewers need the evidence and authority to reverse the model outcome. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-004; RET-UC-011; RET-UC-018; RET-UC-025; RET-UC-032
Related threatsRET-THR-036; RET-THR-005; RET-THR-010; RET-THR-015
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-011; RET-EVD-014; RET-EVD-017; RET-EVD-020
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-016; RET-MET-003
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D6-CTL-02 - AUDIT TRAIL COMPLETENESS

FieldRetail implementation record
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationLogs must reconstruct the customer or operational journey: identity, input, retrieved data, model and prompt version, output, tool call, override and final action. Logging only the final response is insufficient for disputes or incidents. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-005; RET-UC-012; RET-UC-019
Related threatsRET-THR-001; RET-THR-006; RET-THR-011
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-012; RET-EVD-015
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-017; RET-MET-004
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D6-CTL-03 - AI MODEL CARD COMPLETENESS

FieldRetail implementation record
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRetail model cards should state channel, population, data origin, decision authority, known failure modes, seasonal limits, supplier dependencies and prohibited uses. Generic vendor documentation does not replace a retailer-specific deployment record. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-006; RET-UC-013; RET-UC-020; RET-UC-027
Related threatsRET-THR-002; RET-THR-007; RET-THR-012; RET-THR-017
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-013; RET-EVD-016; RET-EVD-019
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-018; RET-MET-005
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D6-CTL-04 - AI INCIDENT RESPONSE READINESS

FieldRetail implementation record
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationAI incident plans should cover misleading product content, pricing errors, fraud-control failure, biometric misidentification, agent misuse, model compromise and provider outages. Preserve model and prompt versions before rollback. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-007; RET-UC-014; RET-UC-021; RET-UC-028; RET-UC-003
Related threatsRET-THR-003; RET-THR-008; RET-THR-013
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-014; RET-EVD-017; RET-EVD-020; RET-EVD-023
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-019; RET-MET-006
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D6-CTL-05 - MODEL DEPRECATION & DECOMMISSIONING

FieldRetail implementation record
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWhen retiring a model, remove endpoints, credentials, cached artefacts and dependent agent routes; archive required evidence; migrate open cases; and verify that stores or franchisees are not still using the superseded version. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-008; RET-UC-015; RET-UC-022
Related threatsRET-THR-004; RET-THR-009; RET-THR-014; RET-THR-019
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-015; RET-EVD-018
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-020; RET-MET-007
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D6-CTL-06 - THIRD-PARTY AI VENDOR GOVERNANCE

FieldRetail implementation record
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationRetail contracts should secure evidence access, data-use limits, change notice, incident cooperation, subcontractor transparency, continuity and exit support. Procurement approval without enforceable operating rights leaves a control gap. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-009; RET-UC-016; RET-UC-023; RET-UC-030
Related threatsRET-THR-005; RET-THR-010; RET-THR-015
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-016; RET-EVD-019; RET-EVD-022
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-001; RET-MET-008
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D6-CTL-07 - AI RESILIENCE & BUSINESS CONTINUITY

FieldRetail implementation record
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationDefine degraded modes for payment risk, inventory, checkout, customer service and physical operations. Test manual or rules-based fallback under peak demand rather than assuming the provider will remain available. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-010; RET-UC-017; RET-UC-024; RET-UC-031; RET-UC-006
Related threatsRET-THR-006; RET-THR-011; RET-THR-016; RET-THR-021
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-017; RET-EVD-020; RET-EVD-023; RET-EVD-001
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-002; RET-MET-009
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP1 - Start first
Scope labelFoundational - canonical D1-D8 scope

D7-CTL-H01 - AI-GENERATED PHISHING SIMULATION

FieldRetail implementation record
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationSimulate AI-generated phishing against store, finance, buying and supplier-management staff using realistic seasonal and invoice themes. Measure reporting and verification behaviour, not just click rates. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-011; RET-UC-018; RET-UC-025
Related threatsRET-THR-007; RET-THR-012; RET-THR-017
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-018; RET-EVD-021
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-003; RET-MET-010
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D7-CTL-H02 - DEEPFAKE DETECTION TRAINING

FieldRetail implementation record
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationTrain staff who approve payments, supplier changes or executive instructions to recognise deepfake voice and video indicators and to use an independent verification channel. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-012; RET-UC-019; RET-UC-026; RET-UC-001
Related threatsRET-THR-008; RET-THR-013; RET-THR-018; RET-THR-023
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-019; RET-EVD-022; RET-EVD-025
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-004; RET-MET-011
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D7-CTL-H03 - OUT-OF-BAND AUTHENTICATION

FieldRetail implementation record
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationChanges to bank details, high-value refunds, privileged access and emergency supplier requests should be confirmed through a pre-registered channel independent of the initiating message or call. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-013; RET-UC-020; RET-UC-027; RET-UC-002; RET-UC-009
Related threatsRET-THR-009; RET-THR-014; RET-THR-019
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-020; RET-EVD-023; RET-EVD-001; RET-EVD-004
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-005; RET-MET-012
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D7-CTL-H04 - AI SOCIAL ENGINEERING IR

FieldRetail implementation record
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationIncident procedures must recognise AI-assisted impersonation, synthetic documents and coordinated social engineering. Preserve media and communications while validating the claimed identity through trusted records. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-014; RET-UC-021; RET-UC-028
Related threatsRET-THR-010; RET-THR-015; RET-THR-020; RET-THR-025
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-021; RET-EVD-024
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-006; RET-MET-013
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D7-CTL-H05 - AI-ENHANCED EXTERNAL ATTACK DEFENSE

FieldRetail implementation record
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationTune email, identity, endpoint and fraud defences for AI-scaled reconnaissance, credential attacks and content variation. Retail peak periods require heightened monitoring because staffing and transaction volume reduce review time. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-015; RET-UC-022; RET-UC-029; RET-UC-004
Related threatsRET-THR-011; RET-THR-016; RET-THR-021
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-022; RET-EVD-025; RET-EVD-003
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-007; RET-MET-014
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D8-CTL-01 - EU AI ACT RISK TIER MAPPING

FieldRetail implementation record
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationMap each retail AI use case to the European Union Artificial Intelligence Act role and risk analysis where the regulation applies. Do not classify an entire retailer once; assess hiring, biometrics, customer and operational systems separately. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-016; RET-UC-023; RET-UC-030; RET-UC-005; RET-UC-012
Related threatsRET-THR-012; RET-THR-017; RET-THR-022; RET-THR-027
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-023; RET-EVD-001; RET-EVD-004; RET-EVD-007
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-008; RET-MET-015
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D8-CTL-02 - ISO 42001 GAP ANALYSIS

FieldRetail implementation record
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationUse an International Organization for Standardization/International Electrotechnical Commission 42001 gap analysis to compare management-system practices, but preserve GAISSF control-level evidence and do not claim equivalence between the instruments. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-017; RET-UC-024; RET-UC-031
Related threatsRET-THR-013; RET-THR-018; RET-THR-023
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-024; RET-EVD-002
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-009; RET-MET-016
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D8-CTL-03 - GPAI TECHNICAL DOCUMENTATION VERIFICATION

FieldRetail implementation record
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWhere a general-purpose AI provider is in scope, verify that the technical documentation available to the retailer is sufficient for integration, risk assessment, monitoring and downstream instructions. Record unavailable evidence as a supplier limitation. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-018; RET-UC-025; RET-UC-032; RET-UC-007
Related threatsRET-THR-014; RET-THR-019; RET-THR-024; RET-THR-029
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-025; RET-EVD-003; RET-EVD-006
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-010; RET-MET-017
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D8-CTL-04 - DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)

FieldRetail implementation record
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationDigital Operational Resilience Act incident reporting is relevant only where the retail entity or service falls within its financial-sector scope. Record the applicability decision instead of presenting the control as universally required for retail. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-019; RET-UC-026; RET-UC-001; RET-UC-008; RET-UC-015
Related threatsRET-THR-015; RET-THR-020; RET-THR-025
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-001; RET-EVD-004; RET-EVD-007; RET-EVD-010
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-011; RET-MET-018
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D8-CTL-05 - NIST SP 800-218A COMPLIANCE CHECK

FieldRetail implementation record
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationApply National Institute of Standards and Technology Special Publication 800-218A practices to AI model and software development where relevant, including provenance, secure build, testing and release evidence. Document gaps for acquired services that the retailer cannot inspect. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-020; RET-UC-027; RET-UC-002
Related threatsRET-THR-016; RET-THR-021; RET-THR-026; RET-THR-031
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-002; RET-EVD-005
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-012; RET-MET-019
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gateRetail AI security specialist review required
Implementation priorityP2 - Risk-triggered / capability-specific
Scope labelFoundational - canonical D1-D8 scope

D9-CTL-01 - PHYSICAL HARM BOUNDARY ENFORCEMENT

FieldRetail implementation record
DomainD9: PHYSICAL AI SAFETY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationSet explicit physical limits for warehouse robots, automated handling, smart carts and autonomous store systems. Software optimisation must not permit speed, force, route or proximity beyond the approved safety boundary. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-021; RET-UC-028; RET-UC-003; RET-UC-010
Related threatsRET-THR-017; RET-THR-022; RET-THR-027
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-003; RET-EVD-006; RET-EVD-009
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-013; RET-MET-020
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gatePhysical-AI specialist review required
Implementation priorityP3 - Conditional physical AI
Scope labelConditional - physical AI in scope

D9-CTL-02 - SAFE STATE AND GRACEFUL DEGRADATION

FieldRetail implementation record
DomainD9: PHYSICAL AI SAFETY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationOn model, sensor, network or cloud failure, physical retail systems must enter a defined safe or controlled state without depending on continued model inference. Test degraded operation during realistic store and warehouse conditions. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-022; RET-UC-029; RET-UC-004; RET-UC-011; RET-UC-018
Related threatsRET-THR-018; RET-THR-023; RET-THR-028; RET-THR-033
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-004; RET-EVD-007; RET-EVD-010; RET-EVD-013
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-014; RET-MET-001
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gatePhysical-AI specialist review required
Implementation priorityP3 - Conditional physical AI
Scope labelConditional - physical AI in scope

D9-CTL-03 - HUMAN OVERRIDE AND EMERGENCY STOP

FieldRetail implementation record
DomainD9: PHYSICAL AI SAFETY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationWarehouse robotics and autonomous store systems require accessible local emergency stops and authorised human override. Remote vendor commands or software updates must not disable the emergency function. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-023; RET-UC-030; RET-UC-005
Related threatsRET-THR-019; RET-THR-024; RET-THR-029
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-005; RET-EVD-008
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-015; RET-MET-002
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gatePhysical-AI specialist review required
Implementation priorityP3 - Conditional physical AI
Scope labelConditional - physical AI in scope

D9-CTL-04 - CYBER-PHYSICAL ATTACK DETECTION

FieldRetail implementation record
DomainD9: PHYSICAL AI SAFETY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationCorrelate cyber indicators with physical anomalies such as unexpected routes, repeated sensor disagreement, command bursts or safety-zone violations. Cyber monitoring alone may miss an emerging physical incident. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-024; RET-UC-031; RET-UC-006; RET-UC-013
Related threatsRET-THR-020; RET-THR-025; RET-THR-030; RET-THR-035
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-006; RET-EVD-009; RET-EVD-012
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-016; RET-MET-003
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gatePhysical-AI specialist review required
Implementation priorityP3 - Conditional physical AI
Scope labelConditional - physical AI in scope

D9-CTL-05 - PHYSICAL ENVIRONMENT INTEGRITY MONITORING

FieldRetail implementation record
DomainD9: PHYSICAL AI SAFETY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationMonitor camera position, sensor obstruction, lighting, floor layout, shelf movement and other environmental changes that can invalidate a physical AI system’s assumptions. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-025; RET-UC-032; RET-UC-007; RET-UC-014; RET-UC-021
Related threatsRET-THR-021; RET-THR-026; RET-THR-031
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-007; RET-EVD-010; RET-EVD-013; RET-EVD-016
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-017; RET-MET-004
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gatePhysical-AI specialist review required
Implementation priorityP3 - Conditional physical AI
Scope labelConditional - physical AI in scope

D9-CTL-06 - ACTUATOR COMMAND VERIFICATION

FieldRetail implementation record
DomainD9: PHYSICAL AI SAFETY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationValidate actuator commands against identity, authorised workflow, current sensor state and physical limits before execution. Reject stale, duplicated or out-of-sequence commands. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-026; RET-UC-001; RET-UC-008
Related threatsRET-THR-022; RET-THR-027; RET-THR-032; RET-THR-001
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-008; RET-EVD-011
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-018; RET-MET-005
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gatePhysical-AI specialist review required
Implementation priorityP3 - Conditional physical AI
Scope labelConditional - physical AI in scope

D9-CTL-07 - PHYSICAL INCIDENT EVIDENCE PRESERVATION

FieldRetail implementation record
DomainD9: PHYSICAL AI SAFETY
Authoritative requirementRefer to GAISSF-NOR-001 v1.0 for the complete normative requirement.
Retail interpretationFor physical incidents, preserve commands, sensor streams, model version, safety interlock state, operator actions and relevant video with synchronized time. Ordinary application logs are not sufficient for reconstruction. [T3]
ApplicabilityDetermine for every in-scope system. Record Not Applicable only with approved, risk-based rationale.
Related use casesRET-UC-027; RET-UC-002; RET-UC-009; RET-UC-016
Related threatsRET-THR-023; RET-THR-028; RET-THR-033
Minimum implementationApproved scope and owner; documented applicability; baseline technical or procedural safeguard; retained design and operating evidence; exception and escalation route.
Enhanced implementationAutomated enforcement and telemetry; independent testing; supplier evidence rights; change-triggered reassessment; cross-channel correlation where relevant.
Illustrative evidenceRET-EVD-009; RET-EVD-012; RET-EVD-015
Test procedureInspect design evidence, sample operating records, test one representative failure or attack path, verify exceptions and confirm change triggers.
Illustrative metricsRET-MET-019; RET-MET-006
Responsible rolesAI Security Lead / relevant retail system owner / independent reviewer
Common failurePolicy exists but scope, operating evidence, supplier coverage or remediation closure is missing.
Compensating controlDocumented manual review, constrained functionality, segmented deployment, enhanced monitoring or service fallback pending remediation.
Maturity indicatorCurrent evidence for all applicable systems, measured effectiveness and no overdue high-risk exception.
Review gatePhysical-AI specialist review required
Implementation priorityP3 - Conditional physical AI
Scope labelConditional - physical AI in scope

7. Data governance and retail information assets

  • Retail data classification and purpose controls are grounded in applicable legal and standards obligations [T1], while the specific implementation examples are contextual retail guidance [T3].
  • Document purpose, lawful or contractual basis where applicable, lineage, retention, access, transfers, deletion and production-data use in testing.
  • Separate data required for fraud and security from data reused for marketing, model training or provider improvement.
  • Treat prompts, retrieved context, model outputs, embeddings and agent action logs as governed information assets.

8. AI supply-chain and third-party risk

Supplier evidence, data-use and change-notification requirements are implementation guidance [T3] that should be reconciled with applicable contracts, laws and standards [T1].

9. Secure retail AI lifecycle

StageRequired retail gate
Use-case approvalDocument purpose, owner, affected persons, authority, legal review triggers and prohibited uses.
ProcurementComplete due diligence, data-use restrictions, evidence rights, exit and change notification.
Design and developmentThreat model, data lineage, architecture review, access boundaries and human oversight.
TestingSecurity, adversarial, fraud, privacy, fairness, accessibility, output, fallback and physical-environment tests as applicable.
ReleaseApproved evidence pack, residual risk, rollback, monitoring and incident ownership.
OperationMonitor drift, abuse, complaints, provider changes, exceptions and business continuity.
RetirementRevoke access, preserve required evidence, delete or archive data and manage dependent systems.

10. Testing and evaluation catalogue

IDTestTriggerMethodAcceptance
RET-TST-001Prompt-injection and tool-abuse testOn deployment and material changeRepresentative direct and indirect attacksNo unauthorised action or sensitive disclosure
RET-TST-002Fraud resilience testAt least quarterly for critical fraud systemsKnown fraud, adaptive evasion and false-positive samplingApproved detection and customer-impact thresholds
RET-TST-003Product-information accuracy testEach release and catalogue-model changeSample specifications, compatibility, safety and restricted claimsCritical factual errors blocked or escalated
RET-TST-004Pricing and promotion integrity testBefore campaign or model releaseBoundary, adversarial and rollback testsNo unauthorised or unexplained price/promotion outcome
RET-TST-005Biometric and vision performance testBefore use and periodicallyRepresentative environment and demographic slicesApproved performance, escalation and intervention limits
RET-TST-006Seasonal drift and stress testBefore major seasonal eventsPeak load and shifted distributionsFallback and thresholds operate under peak conditions
RET-TST-007Third-party outage and fallback testAt least annuallyProvider loss, degraded mode and data recoveryApproved service continuity and manual fallback
RET-TST-008Physical AI safe-state testBefore release and after safety-relevant changeSensor, command, network and emergency-stop failuresSystem enters defined safe or controlled state

11. Human oversight and accountability

Oversight must be more than nominal [T3]. High-risk retail actions include payment or account blocking, return denial, biometric intervention, hiring rejection, high-value refunds, personalised-pricing exceptions and physical movement by autonomous equipment. The reviewer should receive the model rationale, relevant source records, confidence or uncertainty, policy limits and prior overrides; have authority to pause or reverse the action; and record the decision, evidence and escalation. Sampling after the event is not an adequate substitute where harm occurs immediately.

12. Consumer protection and transparency

  • Identify when customers are interacting with AI and when generated content could affect a purchasing decision.
  • Prevent unsupported product, safety, compatibility, pricing and promotional claims.
  • Provide escalation and correction routes for consequential account, fraud, returns, biometric or age decisions.
  • Assess dark-pattern, personalised-pricing, vulnerable-consumer, child, accessibility and synthetic-review risks by jurisdiction.

13. Monitoring metrics

IDMetricDefinitionData sourceFrequencyLimitationEscalation
RET-MET-001Applicable controls with current evidenceDocumented measure of applicable controls with current evidence for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-002High-risk systems with approved human oversightDocumented measure of high-risk systems with approved human oversight for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-003AI-related customer escalationsDocumented measure of ai-related customer escalations for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-004Prompt-injection detectionsDocumented measure of prompt-injection detections for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-005Fraud false-positive rateDocumented measure of fraud false-positive rate for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-006Fraud false-negative estimateDocumented measure of fraud false-negative estimate for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-007Pricing anomaly rateDocumented measure of pricing anomaly rate for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-008Product-output correction rateDocumented measure of product-output correction rate for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-009Recommendation complaint rateDocumented measure of recommendation complaint rate for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-010Model drift alertsDocumented measure of model drift alerts for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-011Third-party AI outagesDocumented measure of third-party ai outages for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-012Unapproved model changesDocumented measure of unapproved model changes for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-013Privileged AI access eventsDocumented measure of privileged ai access events for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-014Blocked agent actionsDocumented measure of blocked agent actions for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-015Biometric false-match rateDocumented measure of biometric false-match rate for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-016Loss-prevention intervention precisionDocumented measure of loss-prevention intervention precision for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-017Rollback frequencyDocumented measure of rollback frequency for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-018Overdue high-risk exceptionsDocumented measure of overdue high-risk exceptions for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-019Mean time to detect AI incidentsDocumented measure of mean time to detect ai incidents for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation
RET-MET-020Mean time to contain AI incidentsDocumented measure of mean time to contain ai incidents for the approved retail AI scope.Security, model, fraud, customer-service, IAM, change or incident telemetryMonthly for critical systems; quarterly otherwiseThresholds require internal baseline; cross-retailer comparisons may be invalid.Board- or executive-approved threshold for material deviation

14. AI incident management and resilience

AI incidents should be triaged by customer, worker, financial, operational, legal, privacy, safety and evidence impact. Response plans should preserve model versions, prompts, retrieved context, outputs, decisions, agent actions, access records and supplier communications. Retail fallback may include manual review, static rules, disabling personalisation, suspending biometric matching or operating warehouse systems in constrained mode.

15. Roles and responsibilities

RoleGovernanceImplementationTestingOperationAssurance
Board/risk committeeAIIII
Executive sponsorARIII
CISO / AI Security LeadCRRRC
AI Governance LeadRRCCR
Privacy / Legal / ComplianceCCCCR
Retail system ownerIRRRR
Fraud / Loss PreventionICRRR
Procurement / Supplier AssuranceICRCR
Internal Audit / Independent AssessorICCCR

16. Implementation roadmap

PhaseIndicative windowOutputs
1 - Discovery and inventoryDays 0-30Scope, owners, inventory, suppliers, data flows and criticality.
2 - Risk and gap assessmentDays 31-60Statement of Applicability, risk profiles, threat models and remediation plan.
3 - Control implementationDays 61-120Technical and procedural controls, supplier clauses, testing and monitoring.
4 - AssuranceDays 121-180Evidence pack, internal assessment, issue closure and management review.
5 - Continuous improvementOngoingChange monitoring, incidents, drift, regulatory review and reassessment.

Planning estimates are informative. Small retailers may use simpler governance and tooling, but should not omit applicable outcomes without documented rationale.

17. Evidence catalogue

IDEvidenceOwnerMinimum contentsFrequencyCommon deficiency
RET-EVD-001AI system inventoryAI Security LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-002Statement of ApplicabilityData Governance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-003Retail AI risk assessmentSupplier Assurance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-004Threat modelRetail Operations LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-005Data-flow diagramPrivacy LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-006Data provenance and lineage recordFraud LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-007Model or system cardAI Governance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-008Supplier due-diligence recordAI Security LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-009AI bill of materialsData Governance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-010Security architecture reviewSupplier Assurance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-011Adversarial test reportRetail Operations LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-012Fraud-resilience test reportPrivacy LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-013Privacy impact assessmentFraud LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-014Fairness and impact assessmentAI Governance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-015Human-oversight procedureAI Security LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-016Access-control reviewData Governance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-017Change and release approvalSupplier Assurance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-018Model monitoring reportRetail Operations LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-019Incident recordPrivacy LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-020Business continuity and fallback testFraud LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-021Customer disclosure and escalation recordAI Governance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-022Biometric or computer-vision approval recordAI Security LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-023Training and competency recordData Governance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-024Exception registerSupplier Assurance LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence
RET-EVD-025Management review minutesRetail Operations LeadScope, owner, date, method, result, exceptions, approvals and referenced systemsAt least annually and on material changeMissing scope, stale approval, unsupported assertion or absent operating evidence

18. Maturity model

LevelDescription
1 - InitialAI systems and controls are incomplete, reactive or undocumented.
2 - RepeatablePriority systems have owners and recurring control activity, but coverage is inconsistent.
3 - DefinedCommon governance, lifecycle, supplier and evidence methods are implemented across scope.
4 - MeasuredEffectiveness, drift, incidents, exceptions and customer impacts are measured and reviewed.
5 - AdaptiveControls are adjusted from telemetry, incidents, threat change and independent assurance.

19. Common implementation failures

FailureConsequenceCorrective action
Treating AI as ordinary softwareModel behaviour, data and provider change are not separately governedInventory model and data dependencies; add change triggers and monitoring.
Incomplete inventoryEmbedded, franchise or SaaS AI remains outside assuranceReconcile procurement, architecture, data and supplier records.
Reliance on vendor assurancesNo retailer-specific operating evidenceContract for evidence and test representative controls.
No tested fallbackOutage or model failure stops retail operationsDefine and exercise manual or degraded modes.
Policy without evidenceAssessment cannot establish effectivenessCollect sampled operating records, logs and approvals.
Uncontrolled generative AIData leakage and misleading contentApply approved tools, retrieval controls, output checks and logging.

20. Worked scenarios

RET-SCN-001 - E-commerce recommendation manipulation

FieldScenario record
Use caseRET-UC-001
Threat/failureRET-THR-019
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-001 and RET-THR-019 were absent, ineffective or not evidenced in operation.
DetectionDetect abnormal seller/bot engagement, ranking shifts and conversion patterns; compare against clean holdout queries.
ContainmentFreeze suspicious ranking signals, remove manipulated inputs, revert the ranking model and review affected seller decisions.
LessonRanking integrity requires adversarial engagement monitoring, not only offline relevance testing.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionFreeze suspicious ranking signals, remove manipulated inputs, revert the ranking model and review affected seller decisions.

RET-SCN-002 - Loyalty takeover with AI-assisted fraud

FieldScenario record
Use caseRET-UC-018
Threat/failureRET-THR-014
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-018 and RET-THR-014 were absent, ineffective or not evidenced in operation.
DetectionCorrelate impossible travel, device change, reward redemption and AI-generated support interactions.
ContainmentLock redemption, preserve account/session evidence, step up identity verification and reverse unauthorised reward transfers.
LessonLoyalty value should be protected with payment-grade identity and recovery controls.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionLock redemption, preserve account/session evidence, step up identity verification and reverse unauthorised reward transfers.

RET-SCN-003 - Hallucinated product information

FieldScenario record
Use caseRET-UC-015
Threat/failureRET-THR-020
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-015 and RET-THR-020 were absent, ineffective or not evidenced in operation.
DetectionSample generated specifications against authoritative supplier data and monitor corrections, returns and complaints.
ContainmentUnpublish affected content, revert to approved catalogue text, notify owners and correct customers where reliance may have occurred.
LessonGenerated retail content needs authoritative attribute validation before publication.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionUnpublish affected content, revert to approved catalogue text, notify owners and correct customers where reliance may have occurred.

RET-SCN-004 - Promotion-engine abuse

FieldScenario record
Use caseRET-UC-004
Threat/failureRET-THR-015
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-004 and RET-THR-015 were absent, ineffective or not evidenced in operation.
DetectionDetect unusual coupon combinations, account clusters, rapid redemptions and margin anomalies.
ContainmentDisable the promotion rule, block abusive sessions, preserve transaction evidence and reissue corrected terms where needed.
LessonPromotion optimisation and promotion enforcement must be separated and independently tested.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionDisable the promotion rule, block abusive sessions, preserve transaction evidence and reissue corrected terms where needed.

RET-SCN-005 - Self-checkout vision failure

FieldScenario record
Use caseRET-UC-010
Threat/failureRET-THR-024
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-010 and RET-THR-024 were absent, ineffective or not evidenced in operation.
DetectionMonitor mismatch between vision events, scanned items, weight sensors, payment events and staff overrides.
ContainmentPlace lanes in assisted mode, isolate the failing model/device and preserve video and sensor logs before recalibration.
LessonStore vision controls need tested human fallback during peak operations.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionPlace lanes in assisted mode, isolate the failing model/device and preserve video and sensor logs before recalibration.

RET-SCN-006 - Facial-recognition false match

FieldScenario record
Use caseRET-UC-020
Threat/failureRET-THR-022
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-020 and RET-THR-022 were absent, ineffective or not evidenced in operation.
DetectionTrack match confidence, demographic/environmental performance and intervention outcomes; investigate complaints immediately.
ContainmentStop automated matching, prevent enforcement action, preserve evidence and route the event to authorised manual review.
LessonA biometric alert is an investigative signal, not proof of identity.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionStop automated matching, prevent enforcement action, preserve evidence and route the event to authorised manual review.

RET-SCN-007 - Returns model false positive

FieldScenario record
Use caseRET-UC-025
Threat/failureRET-THR-016
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-025 and RET-THR-016 were absent, ineffective or not evidenced in operation.
DetectionAnalyse appeal reversals, customer complaints, cohort disparities and sudden threshold changes.
ContainmentPause automated denial, permit manual returns review, restore wrongly affected accounts and recalibrate only after impact analysis.
LessonFraud loss reduction does not justify unreviewable customer decisions.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionPause automated denial, permit manual returns review, restore wrongly affected accounts and recalibrate only after impact analysis.

RET-SCN-008 - Inventory forecast poisoning

FieldScenario record
Use caseRET-UC-005
Threat/failureRET-THR-001
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-005 and RET-THR-001 were absent, ineffective or not evidenced in operation.
DetectionCompare supplier/store submissions, forecast residuals and peer-location updates for abnormal influence.
ContainmentQuarantine suspect data or model updates, rerun the forecast from a trusted baseline and review resulting orders.
LessonForecast provenance must cover local and supplier-originated updates.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionQuarantine suspect data or model updates, rerun the forecast from a trusted baseline and review resulting orders.

RET-SCN-009 - Third-party chatbot data leakage

FieldScenario record
Use caseRET-UC-014
Threat/failureRET-THR-035
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-014 and RET-THR-035 were absent, ineffective or not evidenced in operation.
DetectionUse data-loss alerts, prompt/output sampling and provider logs to identify sensitive fields leaving the approved boundary.
ContainmentDisable the integration, revoke credentials, request provider preservation/deletion evidence and assess affected customers.
LessonChatbot privacy depends on upstream retrieval and provider data-use controls.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionDisable the integration, revoke credentials, request provider preservation/deletion evidence and assess affected customers.

RET-SCN-010 - AI-generated phishing against staff

FieldScenario record
Use caseRET-UC-030
Threat/failureRET-THR-033
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-030 and RET-THR-033 were absent, ineffective or not evidenced in operation.
DetectionCorrelate email telemetry, identity anomalies, supplier-change requests and employee reporting.
ContainmentBlock the campaign, reset affected credentials, suspend requested payment changes and verify identities out of band.
LessonAI-scaled variation makes process verification more durable than content-only detection.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionBlock the campaign, reset affected credentials, suspend requested payment changes and verify identities out of band.

RET-SCN-011 - Warehouse-agent malfunction

FieldScenario record
Use caseRET-UC-008
Threat/failureRET-THR-028
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-008 and RET-THR-028 were absent, ineffective or not evidenced in operation.
DetectionDetect route deviation, command anomalies, sensor disagreement and safety-zone violations.
ContainmentTrigger the local emergency stop, isolate the robotic cell, prevent remote restart and verify the physical area before recovery.
LessonPhysical containment must remain available when cloud control and inference are unavailable.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionTrigger the local emergency stop, isolate the robotic cell, prevent remote restart and verify the physical area before recovery.

RET-SCN-012 - Retail-media targeting misuse

FieldScenario record
Use caseRET-UC-019
Threat/failureRET-THR-025
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-019 and RET-THR-025 were absent, ineffective or not evidenced in operation.
DetectionAudit audience construction, sensitive proxies, advertiser queries and complaint patterns.
ContainmentSuspend the audience/campaign, prevent further data export, preserve targeting logic and conduct privacy and consumer-impact review.
LessonRetail media governance must cover inference and advertiser use, not only raw data access.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionSuspend the audience/campaign, prevent further data export, preserve targeting logic and conduct privacy and consumer-impact review.

RET-SCN-013 - Franchise deployment without approval

FieldScenario record
Use caseRET-UC-031
Threat/failureRET-THR-010
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-031 and RET-THR-010 were absent, ineffective or not evidenced in operation.
DetectionReconcile network, expense, browser and data-access signals against the approved AI inventory across franchise locations.
ContainmentBlock data access to the unapproved service, preserve usage records and require franchise remediation through contractual governance.
LessonCorporate policy alone does not control independent franchise technology without enforceable operational levers.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionBlock data access to the unapproved service, preserve usage records and require franchise remediation through contractual governance.

RET-SCN-014 - Dynamic-pricing governance failure

FieldScenario record
Use caseRET-UC-003
Threat/failureRET-THR-017
ContextIllustrative, non-vendor-specific retail scenario.
Likely control failuresControls linked to RET-UC-003 and RET-THR-017 were absent, ineffective or not evidenced in operation.
DetectionMonitor unexplained price dispersion, rapid changes, protected/proxy cohorts, complaints and competitor-input anomalies.
ContainmentFreeze automated repricing, restore the last approved price rules, preserve inputs and provide correction/escalation for affected customers.
LessonPricing systems require explicit authority, explainability and rollback limits.
Notably AbsentThis is not represented as a confirmed incident or prevalence estimate.
Recommended immediate actionFreeze automated repricing, restore the last approved price rules, preserve inputs and provide correction/escalation for affected customers.

21. External standards and regulatory crosswalk

The crosswalk identifies relationship types, not equivalence. Applicability and clause-level obligations must be verified by jurisdiction and system role.

IDSourceIssuerRelationshipJurisdictionVerification date
EXT-001NIST AI RMF 1.0NISTSupporting controlUnited States / international use2026-07-01
EXT-002Regulation (EU) 2024/1689 (AI Act)European UnionContextual and partial alignmentEuropean Union2026-07-01
EXT-003PCI DSS v4.0.1PCI Security Standards CouncilSupporting controlContractual payment ecosystem2026-07-01
EXT-004ISO/IEC 42001:2023ISO/IECContextual and partial alignmentInternational2026-07-01
EXT-005ISO/IEC 27001:2022ISO/IECSupporting controlInternational2026-07-01
EXT-006NIST Cybersecurity Framework 2.0NISTSupporting controlUnited States / international use2026-07-01
EXT-007FTC Consumer Review RuleU.S. Federal Trade CommissionContextual relevanceUnited States2026-07-01
EXT-008Web Content Accessibility Guidelines 2.2W3CSupporting controlInternational2026-07-01
EXT-009GDPR Regulation (EU) 2016/679European UnionContextual and partial alignmentEuropean Union / EEA2026-07-01
EXT-010NIST Privacy Framework 1.0NISTSupporting controlUnited States / international use2026-07-01

22. Notably Absent

  • No proprietary retailer telemetry, confirmed field-exploitation corpus or sector-wide incident denominator was available.
  • No claim is made that the listed threats have equal probability or that public reporting reflects actual prevalence.
  • No automatic legal, privacy, employment, consumer-protection, accessibility, payment-card, biometric or certification conclusion is provided.
  • No independent validation of retailer-specific performance, loss, false-positive or false-negative rates was performed.
  • Jurisdiction-specific biometric, employment, pharmacy, age-restricted sales and personalised-pricing obligations require separate legal review.
  • The guide does not establish that all retail AI systems are high risk; classification depends on function, authority, affected persons, jurisdiction and deployment.

23. Limitations

The guide depends on public evidence and the authoritative GAISSF baseline. Retail architectures, contracts, jurisdictions and operating data differ materially. Public incident data is incomplete, vendors may not disclose relevant model changes, and rapidly changing technology can make implementation examples stale. Specialist review is required before publication or use as an assessment basis.

Appendix A - Retail AI inventory template

System IDNameUse caseOwnerSupplierDeploymentDataCriticalityOversightStatusLast review
RET-SYS-___

Appendix B - Risk assessment template

Risk IDSystemThreatImpactLikelihood basisControlsResidual riskOwnerDecision
RET-RSK-___

Appendix C - Supplier due-diligence questions

  • What data is collected, retained, transferred, used for provider training or disclosed to subprocessors?
  • How are model versions, material behavioural changes, vulnerabilities and incidents notified?
  • What evidence, testing results, logs, model documentation and audit rights are available?
  • How are access, tenant isolation, deletion, portability, continuity and termination handled?
  • Which safety, security, privacy, accessibility and human-oversight limitations remain unverified?

Appendix D - Deployment readiness checklist

Readiness itemStatus
Scope and accountable owner approvedOpen
Use case and criticality classifiedOpen
Data flows and suppliers documentedOpen
Applicable controls and exceptions approvedOpen
Security and misuse testing passedOpen
Human oversight testedOpen
Monitoring and thresholds configuredOpen
Incident and fallback procedures exercisedOpen
Legal/privacy/consumer review completed where triggeredOpen
Residual risk accepted by authorised roleOpen

Appendix E - Source and evidence register

Source IDTitleIssuerClassURLVerified
EXT-001NIST AI RMF 1.0NISTVoluntary AI risk management frameworkhttps://www.nist.gov/itl/ai-risk-management-framework2026-07-01
EXT-002Regulation (EU) 2024/1689 (AI Act)European UnionRisk-based AI regulationhttps://eur-lex.europa.eu/eli/reg/2024/1689/oj2026-07-01
EXT-003PCI DSS v4.0.1PCI Security Standards CouncilPayment-card data security standardhttps://www.pcisecuritystandards.org/document_library/2026-07-01
EXT-004ISO/IEC 42001:2023ISO/IECAI management system standardhttps://www.iso.org/standard/81230.html2026-07-01
EXT-005ISO/IEC 27001:2022ISO/IECInformation security management systemhttps://www.iso.org/standard/270012026-07-01
EXT-006NIST Cybersecurity Framework 2.0NISTCybersecurity risk management frameworkhttps://www.nist.gov/cyberframework2026-07-01
EXT-007FTC Consumer Review RuleU.S. Federal Trade CommissionProhibitions concerning fake reviews and testimonialshttps://www.ftc.gov/business-guidance/resources/consumer-reviews-testimonials-rule-questions-answers2026-07-01
EXT-008Web Content Accessibility Guidelines 2.2W3CAccessibility guidancehttps://www.w3.org/TR/WCAG22/2026-07-01
EXT-009GDPR Regulation (EU) 2016/679European UnionPersonal-data protection regulationhttps://eur-lex.europa.eu/eli/reg/2016/679/oj2026-07-01
EXT-010NIST Privacy Framework 1.0NISTPrivacy risk management frameworkhttps://www.nist.gov/privacy-framework2026-07-01

Appendix F - Open review gates

GateReviewerStatusClosure requirement
RG-01Retail cybersecurity specialistOpenValidate sector threat and control interpretation.
RG-02Payments / PCI specialistOpenValidate payment-system scope and PCI references.
RG-03Privacy and data protectionOpenValidate personal-data, profiling and transfer guidance.
RG-04Biometric and computer visionOpenValidate biometric, age-estimation and intervention guidance.
RG-05Employment and workforce AIOpenValidate hiring, scheduling and monitoring guidance.
RG-06Consumer protectionOpenValidate pricing, reviews, claims, transparency and contestability.
RG-07AccessibilityOpenValidate accessibility testing and customer interaction guidance.
RG-08Retail fraud and loss preventionOpenValidate fraud scenarios, metrics and evidence.
RG-09Supply chain and warehouse operationsOpenValidate robotics, fulfilment and continuity guidance.
RG-10Franchise and marketplace operationsOpenValidate decentralised governance and seller impacts.
RG-11Legal/editorial citation reviewOpenVerify jurisdictional claims and source register.
RG-12Final publication QAOpenClose all material defects and approve release.