AI Governance Institute logo
AI Governance Institute

Practical Governance for Enterprise AI

Incident Response
IRC · Incident ResponseIRC-002Medium effortAgent-relevant

AI Incident Response Playbook

Document step-by-step procedures for identifying, containing, investigating, and resolving AI system incidents, including role assignments and escalation paths.

Objective

Enable fast, coordinated, and consistent responses to AI incidents by ensuring response procedures are documented and tested before incidents occur.

Maturity Levels

1

Initial

No AI incident response playbook exists; response is improvised.

2

Developing

General IT incident response procedures are used for AI incidents without AI-specific guidance.

3

Defined

An AI-specific incident response playbook covers detection, triage, containment, notification, and resolution for key incident types.

4

Managed

The playbook is tested through tabletop exercises annually; gaps identified in exercises are resolved.

5

Optimizing

Playbook is updated after every significant incident; response time metrics are tracked and improved.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • AI incident response playbook document with role assignments, communication templates, and step-by-step response procedures by severity tier
  • Tabletop exercise or drill records showing the playbook was tested with key responders
  • Post-incident review records for actual incidents confirming the playbook was followed and documenting any deviations
  • Playbook review and update records showing it is revised after incidents and at least annually
  • Role assignment records confirming all named responders have acknowledged their responsibilities

Implementation Notes

Key steps

  • Build the playbook around your incident taxonomy (IRC-001) — each incident type may require a different response sequence.
  • Include model containment procedures: when should the model be taken offline vs. limited vs. monitored? The decision framework should be pre-defined.
  • Define cross-functional response roles: AI incidents often require coordinated response from engineering, legal, privacy, communications, and business operations.
  • Include regulatory notification procedures with clock-start definitions — ambiguity about when a notification obligation is triggered is a common compliance failure.

Example Implementation

Enterprise SaaS company responding to a confirmed P2 AI incident (discriminatory output pattern detected)

AI Incident Response — P2 Discrimination Pattern (IRC-INC-0031)

Detection: MON-003 bias monitoring flagged 8.3 pp approval rate disparity for Age 18–25 group (threshold: 5 pp) at 14:20 UTC

Response timeline:

TimeActionOwner
14:20Automated alert fired; IRC-INC-0031 createdMonitoring system
14:35AI Lead confirms alert is valid; classifies P2AI Lead
14:40Model output rate-limited for affected segment pending investigationEngineering on-call
15:00Legal and Compliance notifiedAI Lead
15:30Root cause identified: training data underrepresentation of age groupML Engineer
16:00Mitigation deployed: fallback to rule-based decision for 18–25 segmentEngineering
T+2 daysPost-incident review scheduledAI Governance Team
T+5 daysModel retrain plan approvedML Lead

Containment decision criteria used: Limit AI decision-making for affected demographic until disparity resolved; do not roll back entire model as other segments unaffected

Regulatory notification assessment: Documented — disparity identified and mitigated within same business day; no individual harm confirmed; no regulatory notification triggered

Control Details

Control ID
IRC-002
Typical owner
AI Governance Team / CISO / Legal
Implementation effort
Medium effort
Agent-relevant
Yes

Tags

incident responseplaybookcrisis managementAI incidents