AI Governance Institute logo
AI Governance Institute

Practical Governance for Enterprise AI

Incident Response
IRC · Incident ResponseIRC-006Medium effortAgent-relevant

Cross-Jurisdictional Incident Reporting Tracker

Maintain a live tracker of incident notification deadlines across all jurisdictions where the organization operates AI systems, pre-mapped to the incident categories that trigger each obligation.

Objective

Ensure the organization meets regulatory notification windows across every jurisdiction simultaneously when an AI incident occurs, without requiring staff to research obligations in the middle of an active incident.

Maturity Levels

1

Initial

Notification requirements are researched reactively during incidents; no pre-mapped tracker exists.

2

Developing

A list of known notification requirements exists but is not mapped to specific incident types or kept current with regulatory changes.

3

Defined

A tracker maps each jurisdiction's notification obligations (deadline, recipient, format, trigger conditions) to specific incident categories; ownership is assigned for keeping it current.

4

Managed

The tracker is embedded in the incident response playbook; tabletop exercises test notification workflow execution; the tracker is reviewed after each regulatory update.

5

Optimizing

Notification deadlines are pre-calculated automatically when an incident is logged; responsible parties are notified of their obligation and deadline without manual lookup.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • Cross-jurisdictional notification tracker document with all fields: jurisdiction, trigger type, deadline, recipient, format, internal owner
  • Evidence the tracker has been reviewed and updated within the past 12 months
  • Incident response playbook showing tracker is referenced in the notification workflow
  • Tabletop exercise records demonstrating the tracker was used to identify and manage notification obligations
  • Log of regulatory changes reviewed and incorporated into the tracker

Implementation Notes

Key steps

  • Map every jurisdiction where AI systems are deployed or where data subjects are located to its applicable incident notification laws and AI-specific requirements.
  • For each jurisdiction, document: the triggering incident types, the notification deadline (clock start, hours allowed), the required recipient (regulator name, contact), the required format or template, and the internal owner responsible for filing.
  • Identify the shortest notification window across all jurisdictions — that window drives your internal escalation timeline.
  • Build the tracker so it can be queried by incident type to immediately surface which jurisdictions' clocks are running.
  • Review and update the tracker after any regulatory change; assign this to whoever monitors regulatory developments.

Example Implementation

Global SaaS company with AI features, customers in EU, US, and Singapore

Cross-Jurisdictional AI Incident Notification Tracker

JurisdictionTriggerDeadlineRecipientFormatOwner
EU (GDPR)Personal data breach72 hoursLead supervisory authorityStandard breach formDPO
EU (AI Act — GPAI)Serious incident15 daysMarket surveillance authorityStructured reportGRC Lead
California (CPPA)Security breach with PII30 daysAG officeNotice templateLegal
Singapore (PDPA)Data breach, significant harm3 business daysPDPCOnline notificationLegal APAC
US Federal (sector-specific)Varies by regulatorSee sector annexVariesVariesCompliance

Shortest window: 72 hours (GDPR). Internal escalation must occur within 24 hours of incident discovery to meet this deadline.