The AI Incident Response Playbook ensures that every AI-related malfunction, breach, or non-compliance event is handled systematically and documented end-to-end. It applies to all AI systems under Zen AI Governance’s AIMS, whether internal or client-deployed, across pre-deployment, live operation, and post-market monitoring stages.
| Severity | Description | Response SLA | Regulatory Reporting |
|---|---|---|---|
| SEV-1 Critical | AI causes or could cause harm to safety, rights, or compliance breach. | Immediate (≤ 1h) | EU AI Act Art 62: Report ≤ 15 days |
| SEV-2 Major | Significant operational disruption or risk to fairness, privacy, or bias exposure. | 4 hours | Escalate internally; regulator if systemic |
| SEV-3 Moderate | Contained event with no external impact but requires correction. | 24 hours | Record internally only |
| SEV-4 Minor | Observation or near miss; training or procedural improvement. | 72 hours | Include in audit trail |
| Role | Responsibilities |
|---|---|
| Incident Commander (IC) | Leads response, authorises containment, and coordinates teams. |
| AI Ethics Officer | Assesses human rights or fairness implications. |
| ML Ops Lead | Executes technical rollback or hotfixes. |
| Legal/DPO | Evaluates data protection & legal notification obligations. |
| Comms Manager | Handles internal/external communications. |
| Audit Lead | Links incident record to evidence repository (EV-IDs). |
Incident_ID,Severity,System,Detected_By,Detection_Date,Description,Impact,Containment_Action,Root_Cause,Corrective_Action,Preventive_Action,Owner,Status,Report_Due,Evidence_ID,Closure_Date
All incident records are logged in the Firestore “incidents” collection and mirrored nightly to Drive under /Evidence/Incident_Reports/.
| Framework | Reference | Relevance |
|---|---|---|
| ISO/IEC 42001 | §10.2 | Corrective & preventive action process for nonconformities. |
| NIST AI RMF | Manage Function | Operational incident management and resilience. |
| EU AI Act | Articles 62–65 | Serious incident definition, reporting, and CAPA linkage. |
| UK DSIT AI Principles | Principle 6 | Ensures accountability and transparency in AI failures. |
© Zen AI Governance UK Ltd • Regulatory Knowledge • v1 20 Nov 2025 • This page is general guidance, not legal advice.