Incident Playbooks (Safety, Security, Privacy) — Risk Management
Incident Playbooks (Safety, Security, Privacy)
EU AI Act Compliance Risk Management EU/UK aligned
+ On this page
Key takeaways
- Respond the same way every time: triage → contain → investigate → notify → fix → verify → learn.
Scope & severity
- Severity matrix by impact: user harm, legal breach, data exposure, operational outage, reputational risk.
- AI-specific triggers: bias spikes, unsafe content, model exfiltration, compromised tools, unapproved model swap.
Triage & command
- Incident Commander; Safety Lead; Security; Legal/Privacy; Comms; Product; Regulator Liaison.
- Declare incident; open ticket; start timeline clock; assign severity; page on-call roles.
Containment & kill-switch
- Rate limit, disable tools, switch to read-only, roll back model or index, or trigger full kill-switch.
Investigation & evidence
- Bundle: prompts/outputs, inputs, model/index versions, configs, logs, screenshots, user list, time-line.
- Root cause analysis with 5-Whys or fishbone; list contributing factors and control gaps.
Notifications (EU/UK)
- Serious incident definitions; initial notice clock; regulator contacts; user notifications where required.
CAPA & effectiveness
- Immediate fixes; preventive actions; owners and due dates; follow-up checks and sign-off.
Comms & stakeholders
- Internal status updates; external statements; regulator Q&A pack; press holding lines; unified messaging.
Runbooks per scenario
- Safety: harmful output, bias surge, misinformation; Security: model/key compromise, tool abuse; Privacy: data leak.
Drills & readiness
- Quarterly tabletop; live paging tests; kill-switch drills; measure MTTD/MTTR and notification timing.
Handoffs & records
- Immutable incident bundle; lessons captured; CAPA links; regulator follow-ups tracked.
Lessons learned
- Update policies, guardrails, training, PMM thresholds; share examples in internal knowledge base.
Playbook checklist
- Roles trained; paging works; evidence template ready; regulator list current; drills performed; metrics improving.
© Zen AI Governance UK Ltd • Regulatory Knowledge • v1 05 Nov 2025 • This page is general guidance, not legal advice.
Related Articles
Risk Management System (EU/UK aligned)
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ Risk Management System (EU/UK aligned) EU AI Act Compliance Regulatory Knowledge EU/UK aligned + On this page On this page Purpose & principles ...
RAG Safety & Provenance Controls — Risk Management
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ RAG Safety & Provenance Controls EU AI Act Compliance Risk Management EU/UK aligned + On this page On this page RAG patterns Ingestion & chunking ...
Security Architecture for AI Systems — Risk Management
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ Security Architecture for AI Systems EU AI Act Compliance Risk Management EU/UK aligned + On this page On this page Threats & scenarios Boundaries & ...
Logging & Traceability — Risk Management
Zen AI Governance — Knowledge Base • EU/UK alignment • Updated 05 Nov 2025 www.zenaigovernance.com ↗ Logging & Traceability — EU/UK aligned EU AI Act Compliance Risk Management EU/UK aligned + On this page On this page Telemetry schema Privacy & ...
Post-Market Monitoring & Serious Incident Management — Continuous Compliance and Reporting
Zen AI Governance — Knowledge Base • EU AI Act Compliance • Updated 17 Nov 2025 www.zenaigovernance.com ↗ Post-Market Monitoring & Serious Incident Management EU AI Act Compliance Post-Market Monitoring + On this page On this page Purpose & ...