SECTOR GUIDANCE

Pharmaceutical Sector Guidance

GAISSF implementation guidance for AI systems and assurance programmes in the pharmaceutical sector.

ODA3 Institute

SEC-049

GAISSF Pharmaceutical Sector Implementation Guide

Version 1.1 | Controlled Pre-Release | Informative

Authoritative baseline: GAISSF-NOR-004 v1.0 59 controls across nine domains

Document Control

FieldValue
Document IDSEC-049
Version1.1
StatusControlled pre-release
ClassificationInformative sector implementation guidance
PublisherODA3 Institute
Legal entityODA3 Pvt Ltd (legal and copyright notices only)
Authoritative control sourceGAISSF-NOR-004 v1.0 corrected final publication edition
Control baseline59 controls across nine domains
Publication dateNot assigned
DistributionWebsite / GitHub after review gates close

Executive Summary

Pharmaceutical AI security intersects with patient safety, product quality, clinical integrity, pharmacovigilance, data integrity, validated-state maintenance, regulated records and supplier dependence. SEC-049 translates each authoritative GAISSF control into sector implementation considerations while preserving the distinction between normative requirements and informative guidance.

1. Purpose, Scope and Audience

This guide supports CISOs, security architects, AI governance leads, quality and validation leaders, pharmacovigilance, clinical operations, regulatory affairs, manufacturing, laboratory, privacy, legal, audit and risk functions. It covers discovery through post-market operations and supporting technology services.

2. Relationship to GAISSF

GAISSF-NOR-004 remains authoritative. The 59 control identifiers and titles are preserved. Pharmaceutical interpretations, examples, evidence suggestions and maturity statements are informative and do not create new conformance obligations.

3. Criticality Model

TierNameEntry criteriaMinimum governance
Tier 1Administrative or low-impact supportNo direct GxP decision or regulated-record effect; reversible; qualified review available.Inventory, approved use, data handling, access, basic testing, supplier terms and periodic review.
Tier 2Controlled operational supportOperational dependency or sensitive data, but limited direct patient/product/regulated-decision impact.Documented risk assessment, monitoring, change control, fallback and supplier assurance.
Tier 3GxP-significant or regulated decision supportSupports regulated records, clinical conduct, safety, quality or submission evidence; human decision remains accountable.Validation/assurance plan, traceability, qualified review, robust audit trail, periodic review, incident/deviation integration.
Tier 4Safety-critical, quality-critical or high-autonomy regulated useFailure can materially affect patient safety, product quality, critical clinical/safety decisions, or executes high-consequence actions.Independent approval, rigorous assurance, hard authority limits, continuous monitoring, tested fallback/override, enhanced supplier and incident controls.

4. Use-Case Catalogue

IDUse caseOwnerIndicative criticality
PHAR-UC-001Generative AI for regulatory-document draftingRegulatory AffairsGxP-significant
PHAR-UC-002AI-assisted medical writingMedical AffairsControlled operational
PHAR-UC-003Clinical protocol generationClinical DevelopmentGxP-significant
PHAR-UC-004Participant recruitment and eligibility screeningClinical OperationsSafety-significant
PHAR-UC-005Clinical-site selectionClinical OperationsControlled operational
PHAR-UC-006Clinical-data anomaly detectionClinical Data ManagementGxP-significant
PHAR-UC-007Synthetic control armsBiostatisticsSafety-significant
PHAR-UC-008Medical image analysis in trialsClinical DevelopmentSafety-significant
PHAR-UC-009Adverse-event intake automationPharmacovigilanceSafety-significant
PHAR-UC-010Adverse-event coding assistancePharmacovigilanceGxP-significant
PHAR-UC-011Pharmacovigilance case prioritisationPharmacovigilanceSafety-critical
PHAR-UC-012Safety signal detectionPharmacovigilanceSafety-critical
PHAR-UC-013Literature surveillancePharmacovigilanceGxP-significant
PHAR-UC-014Benefit-risk analysis supportSafety GovernanceSafety-critical
PHAR-UC-015Target identificationDiscovery ResearchResearch
PHAR-UC-016Molecular generationDiscovery ResearchResearch
PHAR-UC-017Compound screeningDiscovery ResearchResearch
PHAR-UC-018Toxicology predictionPreclinical SafetySafety-significant
PHAR-UC-019Formulation optimisationPharmaceutical DevelopmentGxP-significant
PHAR-UC-020Manufacturing process optimisationManufacturing ScienceQuality-critical
PHAR-UC-021Batch record reviewQuality AssuranceQuality-critical
PHAR-UC-022Predictive maintenanceEngineeringControlled operational
PHAR-UC-023Automated visual inspectionQuality ControlQuality-critical
PHAR-UC-024Environmental monitoring analyticsMicrobiology / QualityQuality-critical
PHAR-UC-025Laboratory result interpretationQuality ControlQuality-critical
PHAR-UC-026Deviation investigation supportQuality AssuranceGxP-significant
PHAR-UC-027CAPA recommendation supportQuality AssuranceGxP-significant
PHAR-UC-028Quality complaint triageProduct QualitySafety-significant
PHAR-UC-029Supply forecastingSupply ChainControlled operational
PHAR-UC-030Cold-chain anomaly detectionSupply Chain QualityQuality-critical
PHAR-UC-031Counterfeit detectionProduct SecuritySafety-significant
PHAR-UC-032Serialization analyticsSupply Chain / ComplianceGxP-significant
PHAR-UC-033Controlled-document knowledge retrievalQuality SystemsGxP-significant
PHAR-UC-034Employee training assistantLearning and DevelopmentControlled operational
PHAR-UC-035Inspection-readiness supportQuality AssuranceGxP-significant
PHAR-UC-036Regulatory intelligenceRegulatory AffairsControlled operational
PHAR-UC-037Product-label content supportRegulatory AffairsSafety-significant
PHAR-UC-038Medical-information chat systemMedical InformationSafety-significant
PHAR-UC-039Patient-facing support toolPatient ServicesSafety-significant
PHAR-UC-040Third-party foundation-model integrationEnterprise TechnologyVariable

5. Threat Register

Each entry is a scenario unless a specific confirmed source is cited. Inclusion does not establish occurrence or prevalence.

IDScenarioEvidence status
PHAR-THR-001Manipulation of drug-discovery training dataThreat-model entry; not evidence that the event has occurred.
PHAR-THR-002Poisoning of experimental datasetsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-003Compromise of proprietary molecular dataThreat-model entry; not evidence that the event has occurred.
PHAR-THR-004Theft of clinical-trial informationThreat-model entry; not evidence that the event has occurred.
PHAR-THR-005Participant re-identificationThreat-model entry; not evidence that the event has occurred.
PHAR-THR-006Manipulation of eligibility-screening logicThreat-model entry; not evidence that the event has occurred.
PHAR-THR-007Protocol-generation errorsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-008Fabrication of scientific referencesThreat-model entry; not evidence that the event has occurred.
PHAR-THR-009Inaccurate regulatory content generationThreat-model entry; not evidence that the event has occurred.
PHAR-THR-010Unauthorised modification of controlled documentsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-011Unreviewed model output inserted into regulated recordsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-012Pharmacovigilance case suppressionThreat-model entry; not evidence that the event has occurred.
PHAR-THR-013Adverse-event misclassificationThreat-model entry; not evidence that the event has occurred.
PHAR-THR-014Delayed safety-signal detectionThreat-model entry; not evidence that the event has occurred.
PHAR-THR-015False safety signalsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-016Hallucinated medical informationThreat-model entry; not evidence that the event has occurred.
PHAR-THR-017Batch-release decision corruptionThreat-model entry; not evidence that the event has occurred.
PHAR-THR-018Manufacturing parameter manipulationThreat-model entry; not evidence that the event has occurred.
PHAR-THR-019Laboratory-result alterationThreat-model entry; not evidence that the event has occurred.
PHAR-THR-020Visual-inspection evasionThreat-model entry; not evidence that the event has occurred.
PHAR-THR-021Model drift affecting quality decisionsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-022Unapproved model updatesThreat-model entry; not evidence that the event has occurred.
PHAR-THR-023Loss of validated stateThreat-model entry; not evidence that the event has occurred.
PHAR-THR-024Insufficient audit trailsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-025Weak electronic-signature attributionThreat-model entry; not evidence that the event has occurred.
PHAR-THR-026Training-serving skewThreat-model entry; not evidence that the event has occurred.
PHAR-THR-027Prompt injection through controlled or supplier documentsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-028Retrieval corpus poisoningThreat-model entry; not evidence that the event has occurred.
PHAR-THR-029Malicious content embedded in scientific literatureThreat-model entry; not evidence that the event has occurred.
PHAR-THR-030Third-party model compromiseThreat-model entry; not evidence that the event has occurred.
PHAR-THR-031Cloud-service concentration failureThreat-model entry; not evidence that the event has occurred.
PHAR-THR-032Model extractionThreat-model entry; not evidence that the event has occurred.
PHAR-THR-033Sensitive-data leakageThreat-model entry; not evidence that the event has occurred.
PHAR-THR-034Insecure agentic actionsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-035Excessive system permissionsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-036Unauthorised tool useThreat-model entry; not evidence that the event has occurred.
PHAR-THR-037Supplier software-update compromiseThreat-model entry; not evidence that the event has occurred.
PHAR-THR-038Counterfeit-classification evasionThreat-model entry; not evidence that the event has occurred.
PHAR-THR-039Cold-chain anomaly concealmentThreat-model entry; not evidence that the event has occurred.
PHAR-THR-040Business-continuity failure caused by AI dependencyThreat-model entry; not evidence that the event has occurred.
PHAR-THR-041Integrity failure in CAPA or deviation analysisThreat-model entry; not evidence that the event has occurred.
PHAR-THR-042Automation biasThreat-model entry; not evidence that the event has occurred.
PHAR-THR-043Underqualified human reviewThreat-model entry; not evidence that the event has occurred.
PHAR-THR-044Inadequate segregation of dutiesThreat-model entry; not evidence that the event has occurred.
PHAR-THR-045Incomplete traceabilityThreat-model entry; not evidence that the event has occurred.
PHAR-THR-046Insufficient reproducibilityThreat-model entry; not evidence that the event has occurred.
PHAR-THR-047Inability to reconstruct model-supported decisionsThreat-model entry; not evidence that the event has occurred.
PHAR-THR-048Jurisdictionally incompatible data processingThreat-model entry; not evidence that the event has occurred.
PHAR-THR-049Unauthorised cross-border data exposureThreat-model entry; not evidence that the event has occurred.
PHAR-THR-050Intellectual-property contamination from external modelsThreat-model entry; not evidence that the event has occurred.

6. Control-by-Control Guidance

D1-CTL-01 — DATASET PROVENANCE & POISONING PREVENTION

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementHash verification + source allowlist + poisoning detection.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-02 — MODEL EXTRACTION RESISTANCE

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementRate limiting + diversity detection + extraction monitoring.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-03 — BEHAVIORAL DRIFT DETECTION

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementBaseline profiling + KL divergence monitoring + accuracy tracking.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-04 — FEDERATED LEARNING POISONING PREVENTION

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementGradient anomaly detection + robust aggregation.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-05 — EMBEDDING SPACE ROBUSTNESS

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementAdversarial training + certified robustness measurement.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-06 — POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementPQC signing (ML-DSA/SLH-DSA) + PQC key exchange (ML-KEM).
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-07 — LORA/ADAPTER INTEGRITY VERIFICATION

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementAdapter scanning + provenance verification + registry allowlist.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-08 — MODEL MERGE ATTACK DETECTION

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementPre-registration behavioural evaluation + regression testing.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D1-CTL-09 — QUANTIZATION BACKDOOR SCREENING

ElementContent
DomainD1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS
Authoritative source statementCross-precision behavioural comparison + delta threshold monitoring.
Pharmaceutical interpretationProtect provenance, integrity, versioning and behavioural stability of models, datasets, embeddings and adapters used across the medicinal-product lifecycle.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-001, PHAR-THR-002, PHAR-THR-021, PHAR-THR-022, PHAR-THR-023, PHAR-THR-026
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D2-CTL-01 — DIRECT PROMPT INJECTION PREVENTION

ElementContent
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative source statementInput validation + adversarial pattern matching + system prompt isolation + guardrail sidecar.
Pharmaceutical interpretationPrevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D2-CTL-02 — INDIRECT PROMPT INJECTION PREVENTION

ElementContent
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative source statementContextual separation + source allowlisting + output validation + RAG sanitization pipeline.
Pharmaceutical interpretationPrevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D2-CTL-03 — JAILBREAK RESISTANCE TESTING

ElementContent
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative source statementQuarterly red-team prompt library + adversarial training + automated refusal monitoring.
Pharmaceutical interpretationPrevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D2-CTL-04 — MULTI-MODAL INJECTION DEFENSE

ElementContent
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative source statementMulti-modal content scanning + steganography detection + modality-specific guardrails.
Pharmaceutical interpretationPrevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D2-CTL-05 — FUNCTION CALL/TOOL CALL INJECTION PREVENTION

ElementContent
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative source statementParameter schema validation + allowlist enforcement + sandboxed execution.
Pharmaceutical interpretationPrevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D2-CTL-06 — CROSS-CONTEXT HIJACKING MITIGATION

ElementContent
DomainD2: RUNTIME SECURITY & ADVERSARIAL DEFENSE
Authoritative source statementContext window segmentation + prompt anchoring + attention boundary enforcement.
Pharmaceutical interpretationPrevent and detect hostile or malformed inputs, unsafe runtime behaviour, identity abuse and compromise of deployed pharmaceutical AI services.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-027, PHAR-THR-029, PHAR-THR-030, PHAR-THR-033, PHAR-THR-035, PHAR-THR-036
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D3-CTL-01 — LEAST AGENCY ENFORCEMENT

ElementContent
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative source statementRole-based tool scoping + policy-as-code + dynamic permission revocation.
Pharmaceutical interpretationConstrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047
Mapped use casesPHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D3-CTL-02 — INTER-AGENT COMMUNICATION SECURITY

ElementContent
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative source statementmTLS for agent mesh + message signing + payload validation.
Pharmaceutical interpretationConstrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047
Mapped use casesPHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D3-CTL-03 — AGENTIC PROMPT CHAINING DETECTION

ElementContent
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative source statementCross-session behavioural correlation + chain pattern detection + anomaly scoring.
Pharmaceutical interpretationConstrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047
Mapped use casesPHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D3-CTL-04 — EMBODIED AI SAFETY CONTROLS

ElementContent
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative source statementSensor integrity verification + safety interlocks + fail-safe state enforcement.
Pharmaceutical interpretationConstrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047
Mapped use casesPHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D3-CTL-05 — MULTI-AGENT TRUST CHAIN ATTESTATION

ElementContent
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative source statementSPIFFE/SPIRE workload identity + short-lived certificates + continuous attestation.
Pharmaceutical interpretationConstrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047
Mapped use casesPHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D3-CTL-06 — PERSISTENT MEMORY EXFILTRATION PREVENTION

ElementContent
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative source statementUser-scoped memory isolation + encryption at rest + query-level access controls.
Pharmaceutical interpretationConstrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047
Mapped use casesPHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D3-CTL-07 — SECURE MEMORY LIFECYCLE MANAGEMENT

ElementContent
DomainD3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY
Authoritative source statementCryptographic deletion + lifecycle policy enforcement + retention auditing.
Pharmaceutical interpretationConstrain delegation, tools, permissions and autonomous actions in agentic workflows that can affect regulated records, safety, quality or operations.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-034, PHAR-THR-035, PHAR-THR-036, PHAR-THR-042, PHAR-THR-044, PHAR-THR-047
Mapped use casesPHAR-UC-001, PHAR-UC-011, PHAR-UC-021, PHAR-UC-026, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D4-CTL-01 — AI BILL OF MATERIALS (AI BOM) MAINTENANCE

ElementContent
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative source statementAutomated BOM generation + version tracking + registry synchronization.
Pharmaceutical interpretationGovern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050
Mapped use casesPHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D4-CTL-02 — MODEL FILE & ARTIFACT SCANNING

ElementContent
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative source statementStatic analysis + deserialization sandboxing + signature verification.
Pharmaceutical interpretationGovern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050
Mapped use casesPHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D4-CTL-03 — MODEL HUB & REGISTRY VETTING

ElementContent
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative source statementProvenance verification + license compliance + security scorecard.
Pharmaceutical interpretationGovern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050
Mapped use casesPHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D4-CTL-04 — MCP SERVER BEHAVIORAL MONITORING

ElementContent
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative source statementTool-call logging + anomaly detection + access control enforcement.
Pharmaceutical interpretationGovern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050
Mapped use casesPHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D4-CTL-05 — THIRD-PARTY AI API SECURITY ASSESSMENT

ElementContent
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative source statementContractual security requirements + penetration testing + data flow mapping.
Pharmaceutical interpretationGovern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050
Mapped use casesPHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D4-CTL-06 — SHADOW AI DISCOVERY & GOVERNANCE

ElementContent
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative source statementNetwork traffic analysis + SaaS discovery + policy enforcement.
Pharmaceutical interpretationGovern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050
Mapped use casesPHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D4-CTL-07 — AI SOFTWARE COMPOSITION ANALYSIS (SCA)

ElementContent
DomainD4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY
Authoritative source statementDependency scanning + CVE matching + automated patching.
Pharmaceutical interpretationGovern model, data, cloud, CRO/CMO, laboratory, platform and foundation-model suppliers across acquisition, change and exit.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-030, PHAR-THR-031, PHAR-THR-037, PHAR-THR-048, PHAR-THR-049, PHAR-THR-050
Mapped use casesPHAR-UC-040, PHAR-UC-006, PHAR-UC-020, PHAR-UC-029
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D5-CTL-01 — HARMFUL CONTENT BLOCKING

ElementContent
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative source statementContent safety classifier + refusal engine.
Pharmaceutical interpretationMaintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013
Mapped use casesPHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D5-CTL-02 — PII LEAKAGE PREVENTION

ElementContent
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative source statementPII detection + masking + access controls.
Pharmaceutical interpretationMaintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013
Mapped use casesPHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D5-CTL-03 — COPYRIGHT DETECTION

ElementContent
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative source statementn-gram overlap detection + refusal.
Pharmaceutical interpretationMaintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013
Mapped use casesPHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D5-CTL-04 — AI WATERMARKING ROBUSTNESS

ElementContent
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative source statementC2PA-compliant watermarking + tamper resistance testing.
Pharmaceutical interpretationMaintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013
Mapped use casesPHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D5-CTL-05 — PRIVACY-BY-DESIGN VERIFICATION

ElementContent
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative source statementData minimization + purpose limitation + machine unlearning.
Pharmaceutical interpretationMaintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013
Mapped use casesPHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D5-CTL-06 — PRIVACY-PRESERVING ML VALIDATION

ElementContent
DomainD5: CONTENT SAFETY & OUTPUT INTEGRITY
Authoritative source statementDifferential privacy + membership inference testing.
Pharmaceutical interpretationMaintain accuracy, grounding, source traceability, controlled-language boundaries and review of generated or classified content.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-007, PHAR-THR-008, PHAR-THR-009, PHAR-THR-010, PHAR-THR-011, PHAR-THR-013
Mapped use casesPHAR-UC-001, PHAR-UC-002, PHAR-UC-009, PHAR-UC-013, PHAR-UC-033
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D6-CTL-01 — HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS

ElementContent
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative source statementApproval workflow + policy enforcement + audit log.
Pharmaceutical interpretationEstablish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D6-CTL-02 — AUDIT TRAIL COMPLETENESS

ElementContent
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative source statementStructured logging + SIEM integration + retention enforcement.
Pharmaceutical interpretationEstablish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D6-CTL-03 — AI MODEL CARD COMPLETENESS

ElementContent
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative source statementStandardized template + version control + public accessibility.
Pharmaceutical interpretationEstablish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D6-CTL-04 — AI INCIDENT RESPONSE READINESS

ElementContent
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative source statementAI-IR runbook + tabletop exercises + containment automation.
Pharmaceutical interpretationEstablish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D6-CTL-05 — MODEL DEPRECATION & DECOMMISSIONING

ElementContent
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative source statementAccess revocation + decommission audit + scheduled lifecycle.
Pharmaceutical interpretationEstablish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D6-CTL-06 — THIRD-PARTY AI VENDOR GOVERNANCE

ElementContent
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative source statementContractual security requirements + annual assessment + audit rights.
Pharmaceutical interpretationEstablish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D6-CTL-07 — AI RESILIENCE & BUSINESS CONTINUITY

ElementContent
DomainD6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT
Authoritative source statementFailover systems + degraded mode + RTO/RPO definition.
Pharmaceutical interpretationEstablish accountability, intended-use approval, GxP determination, human oversight, evidence, escalation and periodic governance.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-022, PHAR-THR-023, PHAR-THR-024, PHAR-THR-025, PHAR-THR-042, PHAR-THR-043
Mapped use casesPHAR-UC-006, PHAR-UC-012, PHAR-UC-020, PHAR-UC-025, PHAR-UC-040
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D7-CTL-H01 — AI-GENERATED PHISHING SIMULATION

ElementContent
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative source statementSimulation campaigns + click tracking + remedial training.
Pharmaceutical interpretationAssess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D7-CTL-H02 — DEEPFAKE DETECTION TRAINING

ElementContent
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative source statementTraining modules + quiz + simulated attacks.
Pharmaceutical interpretationAssess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D7-CTL-H03 — OUT-OF-BAND AUTHENTICATION

ElementContent
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative source statementIndependent channel verification + policy enforcement.
Pharmaceutical interpretationAssess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D7-CTL-H04 — AI SOCIAL ENGINEERING IR

ElementContent
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative source statementTabletop exercises + IR plan + verification triggers.
Pharmaceutical interpretationAssess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D7-CTL-H05 — AI-ENHANCED EXTERNAL ATTACK DEFENSE

ElementContent
DomainD7: HUMAN & SOCIETAL HARMS
Authoritative source statementAI-generated phishing detection + SOC tuning + response automation.
Pharmaceutical interpretationAssess participant, patient, workforce and societal harms, including bias, accessibility, privacy, exclusion and automation bias.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-005, PHAR-THR-006, PHAR-THR-042, PHAR-THR-043, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-004, PHAR-UC-007, PHAR-UC-008, PHAR-UC-039
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D8-CTL-01 — EU AI ACT RISK TIER MAPPING

ElementContent
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative source statementRisk classification framework + conformity assessment.
Pharmaceutical interpretationMap legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D8-CTL-02 — ISO 42001 GAP ANALYSIS

ElementContent
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative source statementGap analysis methodology + remediation tracking.
Pharmaceutical interpretationMap legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D8-CTL-03 — GPAI TECHNICAL DOCUMENTATION VERIFICATION

ElementContent
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative source statementTechnical documentation + training data summary + copyright attestation.
Pharmaceutical interpretationMap legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D8-CTL-04 — DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)

ElementContent
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative source statementIncident classification + notification workflow + SLA monitoring.
Pharmaceutical interpretationMap legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D8-CTL-05 — NIST SP 800-218A COMPLIANCE CHECK

ElementContent
DomainD8: REGULATORY ALIGNMENT & COMPLIANCE
Authoritative source statementSecure development practices + attestation.
Pharmaceutical interpretationMap legal, regulatory, privacy, resilience and sector obligations without treating GAISSF as a compliance guarantee.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-004, PHAR-THR-024, PHAR-THR-048, PHAR-THR-049
Mapped use casesPHAR-UC-001, PHAR-UC-006, PHAR-UC-009, PHAR-UC-020, PHAR-UC-036
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D9-CTL-01 — PHYSICAL HARM BOUNDARY ENFORCEMENT

ElementContent
DomainD9: PHYSICAL AI SAFETY
Authoritative source statementIndependent safety monitor (hardware or DO-178C Level A / IEC 61508 SIL 3 certified software) running in parallel with AI inference. Safety monitor enforces: maximum force/velocity/temperature/current limits; geofencing for autonomous systems; exclusion zones; rate-of-change limits for safety-critical parameters. AI output gated through safety monitor — monitor vetoes any out-of-boundary command without AI system awareness.
Pharmaceutical interpretationApply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040
Mapped use casesPHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D9-CTL-02 — SAFE STATE AND GRACEFUL DEGRADATION

ElementContent
DomainD9: PHYSICAL AI SAFETY
Authoritative source statementFor each AI-controlled system, document: safe state definition (autonomous vehicle: controlled stop; surgical robot: tool withdrawal; industrial arm: immediate stop and hold); transition time to safe state (must be within stopping distance/reaction time for physical context); trigger conditions for safe state entry; recovery procedure. Implement degraded mode ladder: Full AI control → AI-assisted human control → Manual-only → Safe state.
Pharmaceutical interpretationApply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040
Mapped use casesPHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D9-CTL-03 — HUMAN OVERRIDE AND EMERGENCY STOP

ElementContent
DomainD9: PHYSICAL AI SAFETY
Authoritative source statementHardware emergency stop: physical E-stop accessible without any software mediation. AI system must not be able to disable, delay, or circumvent E-stop. Software override: human operator interface that immediately transfers control to safe state. Override must be possible when: AI communication is disrupted; AI system is under adversarial attack; AI model is producing anomalous outputs. Override authority must be unconditional — no AI reasoning, confidence scoring, or approval process may delay or prevent override activation.
Pharmaceutical interpretationApply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040
Mapped use casesPHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D9-CTL-04 — CYBER-PHYSICAL ATTACK DETECTION

ElementContent
DomainD9: PHYSICAL AI SAFETY
Authoritative source statementThree-layer anomaly detection: (1) Sensor layer — statistical validation of sensor readings against physical models; flag readings deviating >3σ from model prediction; cross-validate against redundant sensor channels. (2) Actuator layer — monitor command streams for sequences inconsistent with operating context; flag commands outside physically feasible envelope. (3) AI inference layer — apply GAISSF™ D2-CTL-01 (Prompt Injection Detection) equivalent for physical AI inputs; monitor input feature distributions for adversarial perturbation signatures. All detections trigger immediate safe state entry (D9-CTL-02) and incident record with root_cause_category = Adversarial_Attack, root_cause_specific_type = Cyber_Physical_Attack.
Pharmaceutical interpretationApply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040
Mapped use casesPHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D9-CTL-05 — PHYSICAL ENVIRONMENT INTEGRITY MONITORING

ElementContent
DomainD9: PHYSICAL AI SAFETY
Authoritative source statementSensor integrity monitoring covering: (1) Hardware health — sensor self-test results, calibration drift indicators, environmental exposure limits. Alert when sensor confidence falls below threshold. (2) Data plausibility — real-time statistical validation against physical laws, historical baselines, and redundant sensor cross-validation. (3) Degraded sensor handling — explicit policy for each sensor failure mode: degrade gracefully (reduce AI authority, increase human oversight) or enter safe state. (4) Calibration management — automated alert when calibration certificates expire; block AI system from operational use with expired sensor calibration.
Pharmaceutical interpretationApply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040
Mapped use casesPHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D9-CTL-06 — ACTUATOR COMMAND VERIFICATION

ElementContent
DomainD9: PHYSICAL AI SAFETY
Authoritative source statementPre-execution verification gate on every actuator command: (1) Physical bounds check — command value within safe operating envelope for current system state. (2) Sequence plausibility check — command consistent with prior sequence; flag implausible state transitions for human review. (3) Rate-of-change check — rate of change does not exceed safe limits (acceleration rate, force application rate, temperature change rate). (4) Dual-approval for irreversible actions — actuator commands causing irreversible physical changes (cutting, welding, demolition, high-energy discharge) require hardware interlock confirmation. Verification gate implemented in IEC 61508 SIL 3 certified software or hardware logic independent of AI model.
Pharmaceutical interpretationApply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040
Mapped use casesPHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

D9-CTL-07 — PHYSICAL INCIDENT EVIDENCE PRESERVATION

ElementContent
DomainD9: PHYSICAL AI SAFETY
Authoritative source statement(1) Continuous ring-buffer recording — minimum 60-second rolling buffer of: all sensor inputs (raw and processed); all AI model inputs and outputs; all actuator commands; all safety monitor decisions; all human override activations; system health telemetry. Safety-critical systems retain 300 seconds minimum. (2) Incident freeze — on any safety-relevant event, automatically freeze buffer and begin extended logging. Frozen buffer write-protected. (3) Cryptographic integrity — all records SHA-256 hashed and ECDSA signed at point of creation. For Optimized tier: CRYSTALS-Dilithium signing (post-quantum). (4) Regulatory retention — ICAO Annex 13: 5 years minimum; EU AI Act Art. 19: 10 years; DORA Art. 12: 5 years. (5) UAIF® integration — automatically populate UAIF® incident record from evidence package.
Pharmaceutical interpretationApply cyber-physical safety controls where AI interacts with manufacturing equipment, laboratories, robotics, cold chain or other physical processes.
ApplicabilityApply based on intended use, GxP determination, criticality, data/record impact, autonomy and supplier dependency; document justified exclusions.
Recommended practicesDefine an approved control design; assign accountable ownership; integrate with quality/change/incident processes; test operation and effectiveness; retain attributable evidence.
GxP and validationWhere GxP-relevant, preserve validated state, data integrity, traceability, change control, qualified review and reconstructability. Use intended-use and risk-based acceptance criteria; include representative normal, edge, adversarial and failure scenarios; re-assess after material change.
Safety, quality, clinical and PVEscalate where failure could delay, suppress, distort or miscommunicate information material to participant or patient safety. Assess whether failure could affect specifications, manufacturing parameters, laboratory results, batch decisions, complaints, storage or distribution. Preserve protocol, eligibility, endpoint, data lineage, statistical and source-document integrity where applicable. Test omission, prioritisation, coding and signal-detection failure modes where safety workflows are in scope.
Data integrityMaintain attributable, legible, contemporaneous, original/true-copy, accurate, complete, consistent, enduring and available records as applicable.
Third partiesObtain model/data/service transparency sufficient for risk assessment, change notification, incident support, auditability, continuity and exit.
Illustrative evidenceApproved design; risk/GxP assessment; configuration; test results; model/data version records; access/audit logs; monitoring; review and change records. Examples are informative, not mandatory artifacts.
Assessment questionsIs scope approved? Is ownership clear? Can operation and effectiveness be evidenced? Are failures detected and escalated? Can affected decisions and records be reconstructed?
Mapped threatsPHAR-THR-017, PHAR-THR-018, PHAR-THR-019, PHAR-THR-020, PHAR-THR-039, PHAR-THR-040
Mapped use casesPHAR-UC-020, PHAR-UC-022, PHAR-UC-023, PHAR-UC-024, PHAR-UC-030
Limitations and confidenceSector interpretation does not determine legal applicability, establish validation adequacy, or guarantee safety, quality, compliance or security. High for GAISSF source fidelity; Moderate for generic sector interpretation pending organization- and jurisdiction-specific review.

7. Lifecycle, Validation and Change Control

Apply controlled gates from use-case intake through retirement. Define intended use, GxP and regulated-record impact, criticality, data/model provenance, threat model, test and acceptance criteria, approval, deployment, access, monitoring, drift, change control, periodic review, incident/deviation/CAPA and supplier exit. For probabilistic or externally updated systems, establish repeated-test methods, version pinning or change detection, traceable prompts/retrieval sources and reconstructable review evidence.

8. Incident, Deviation, CAPA and Escalation

Use coordinated triage across cybersecurity, AI failure, data integrity, quality, clinical, pharmacovigilance, privacy, supplier and continuity pathways. Preserve evidence, assess patient/product/batch/record impact, contain or suspend where needed, reconcile affected records, and obtain qualified legal/regulatory review before external reporting decisions.

9. Evidence and Assessment

Maintain attributable, time-bounded and scope-specific evidence including inventory, intended-use and GxP determinations, architecture, model/data records, supplier reviews, risk/threat assessments, validation/assurance, access/audit logs, changes, monitoring, human reviews, incidents, deviations, CAPAs and periodic reviews.

10. Maturity Model

LevelDescription
1 — InitialAd hoc and reactive.
2 — RepeatableDocumented minimum process.
3 — DefinedIntegrated quality, security, validation and supplier governance.
4 — ManagedMeasured effectiveness and residual risk.
5 — AdaptiveControlled continuous assurance and improvement.

11. Implementation Roadmap

PeriodPriority actionsCompletion evidence
First 30 daysInventory, restrict unapproved regulated use, identify Tier 3/4, assign owners and escalation.Approved inventory and ownership/risk record.
Days 31–90GxP/criticality determinations, supplier reviews, review rules, change and incident/deviation linkage, priority testing.Signed determinations, procedures and test evidence.
Months 4–6Expand validation, monitoring, traceability, resilience and training.Assurance records, dashboards and closed high-risk findings.
Months 7–12Institutionalize periodic review, metrics, continuous assurance and cross-site consistency.Management review and repeat assessment.

12. Notably Absent

  • No reliable public evidence was identified that autonomous AI compromise of pharmaceutical manufacturing is widespread. Treat as a plausible high-impact scenario, not a prevalence claim. Confidence: Moderate; public reporting is incomplete.
  • No claim is made that malicious manipulation of a pharmaceutical AI system has directly caused confirmed patient harm at scale. Do not infer occurrence from threat plausibility. Confidence: Moderate; confidential incidents may not be public.
  • No evidence supports routine regulator acceptance of fully autonomous regulated decisions without accountable human and organizational controls. Default to explicit decision rights, qualified oversight and traceability. Confidence: High as a guide boundary; jurisdiction-specific review remains required.
  • No universal global regulatory classification or validation method for pharmaceutical AI is assumed. Determine requirements by jurisdiction, intended use and lifecycle stage. Confidence: High.
  • Public incident datasets do not provide complete coverage of AI failures in pharmaceutical operations. Frequency estimates are not supplied. Confidence: High.
  • Conventional cybersecurity controls alone are not shown to be sufficient for GxP-relevant AI systems. Integrate quality, validation, data integrity, human oversight and regulated escalation. Confidence: High as an implementation principle.
  • Model accuracy alone is not treated as evidence of clinical, safety, quality or regulatory fitness. Assess intended use, data, robustness, security, human factors, traceability and lifecycle control. Confidence: High.
  • The guide does not establish that every listed threat has occurred. Threat entries are explicitly classified as scenarios unless confirmed evidence is cited. Confidence: High.

13. External Reference Register

IDIssuer / titleStatusScope limitationOfficial URL
SRC-001US Food and Drug Administration — Guiding Principles of Good AI Practice in Drug Development2026; Regulatory principles / non-binding contextDoes not itself establish universal validation or compliance requirements.https://www.fda.gov/about-fda/artificial-intelligence-drug-development/guiding-principles-good-ai-practice-drug-development
SRC-002European Medicines Agency — Reflection paper on the use of AI in the medicinal product lifecycle2024; Scientific reflection paperApplicability depends on lifecycle stage, regulatory use and current agency position.https://www.ema.europa.eu/en/use-artificial-intelligence-ai-medicinal-product-lifecycle
SRC-003US Food and Drug Administration — E6(R3) Good Clinical Practice (GCP)2025; FDA guidance adopting ICH E6(R3)Clinical-trial scope; regional implementation and annex status must be verified.https://www.fda.gov/regulatory-information/search-fda-guidance-documents/e6r3-good-clinical-practice-gcp
SRC-004European Commission — EudraLex Volume 4, Annex 11 - Computerised Systems2011; EU GMP guidanceCurrent revision, national interpretation and product/manufacturing applicability must be verified.https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en
SRC-005US Food and Drug Administration — 21 CFR Part 11 - Electronic Records; Electronic SignaturesCurrent codification to be verified; RegulationApplicability depends on predicate rules and record use.https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
SRC-006NIST — Artificial Intelligence Risk Management Framework (AI RMF 1.0)2023; Voluntary frameworkNot pharmaceutical regulation and not a compliance certification.https://www.nist.gov/itl/ai-risk-management-framework
SRC-007NIST — Cybersecurity Framework 2.02024; Voluntary frameworkRequires tailoring; does not replace GxP or product-specific requirements.https://www.nist.gov/cyberframework
SRC-008ICH — ICH Q9 Quality Risk ManagementCurrent adopted revision to be verified; Harmonised guidelineRegional implementation and current revision must be confirmed.https://www.ich.org/page/quality-guidelines

14. Publication Gates

Public release requires qualified pharmaceutical quality/GxP, pharmacovigilance, clinical, manufacturing/laboratory, privacy/legal, jurisdictional regulatory and publication review; named approvals; final licence/trademark wording; and cross-artifact QA.

15. Publication-Readiness Decision

PUBLICATION READY WITH OPEN SPECIALIST REVIEW GATES — CONTROLLED PRE-RELEASE ONLY.

Verified Feedback Update Addendum - Version 1.1

This addendum records verified improvements incorporated across the SEC-049 package. It supplements the existing control-by-control guide without altering the authoritative GAISSF control identifiers, titles or source statements.

Machine-readable schema parity

The SEC-049 JSON schema now excludes inherited generic VTS, ROI, insurance and unsupported commercial-impact fields. Authoritative requirements remain identified as GAISSF controlled Tier 1 sources. The validation report now includes semantic-parity checks.

D8-CTL-04 applicability boundary

The authoritative DORA control remains unchanged. A pharmaceutical organisation is not subject to DORA merely because it uses AI. Direct applicability requires a documented financial-sector, covered ICT-provider, affiliate, contractual or other legal nexus. Where no nexus exists, record a justified Not Applicable decision and separately map applicable pharmaceutical quality, safety, privacy and incident-reporting pathways.

D9-CTL-07 retention boundary

ICAO and DORA periods in the authoritative source are source-specific examples, not universal pharmaceutical retention rules. For pharmaceutical systems, record the applicable GxP predicate rule, clinical, pharmacovigilance, product, privacy, litigation-hold or local legal basis, together with owner, approval, integrity controls and reassessment trigger.

Physical and OT scope

The workbook now records physical/OT interaction, affected equipment or process, actuator authority, safety-function dependency, override or emergency-stop dependency, site or area and the rationale for D9 applicability.

Criticality safeguard

Numeric scoring is an indicative screening aid only. Blank or undetermined factors must not default to Tier 1. GxP significance, direct regulated-record impact, material patient or product risk, and high-consequence autonomous action may require qualitative escalation regardless of score. The approved tier requires named approval and rationale.

Exceptions and justified exclusions

Record the system and control, factual rationale, risk assessment, compensating safeguards, residual risk, Quality and Information Security approvals, legal or regulatory review where relevant, expiry date and reassessment trigger.

Legacy and embedded AI

Document validated-state constraints, unavailable model internals, unsupported suppliers, logging and provenance limitations, compensating controls and a time-bound remediation or retirement plan. Periodic risk acceptance is required.

Threat model maintenance

Refresh the threat model after a new use case, model or provider change, new tool authority, material architecture change, physical/OT connection, confirmed vulnerability or incident, regulatory change, drift or control failure, or new supplier dependency.

Workbook usability

The workbook now includes a Quick Start workflow, physical/OT fields, blank-by-default criticality inputs, an Exceptions Register, flat Control-Threat and Control-Use Case mapping sheets, and a Tier 3/4 Action Plan.

Additional verified references

IDInstrumentStatusApplicability limitation
SRC-009Regulation (EU) 2022/2554 (DORA)Binding EU regulationFinancial-sector scope; not generally applicable to pharmaceutical entities without a documented nexus.
SRC-010Regulation (EU) 2024/1689 (Artificial Intelligence Act)Binding EU regulation with phased applicationDepends on role, system classification, use, territory and applicable transition dates.
SRC-011ISO/IEC 42001:2023International management-system standardConformity or certification is separate from GAISSF and does not establish pharmaceutical regulatory compliance.
SRC-012NIST SP 800-218A (2024)Final NIST Special PublicationVoluntary unless adopted; not pharmaceutical regulation and no universal attestation or retention rule is inferred.

Glossary additions

Criticality tier: Informative SEC-049 implementation classification; not a regulator-approved category or GAISSF conformance tier.

Physical/OT interaction: Direct or indirect AI influence over equipment, actuators, industrial controls, laboratory automation, cold-chain systems or other physical processes.

Legacy system: Existing system whose architecture, validation state, supplier support or technical constraints materially limit implementation of current controls.

Validated state: Controlled condition in which a system remains fit for its approved intended use under documented configuration and change controls.

QMS: Quality management system governing applicable procedures, records, deviations, change and CAPA.

Publication status

NOT PUBLICATION READY - CONTROLLED PRE-RELEASE ONLY. Structural and feedback-remediation validation has passed, but qualified pharmaceutical quality/GxP, pharmacovigilance, clinical, manufacturing/laboratory, privacy, legal and jurisdiction-specific review gates remain open.