AI incident response record#
Template ID: tpl-incident-response
Version: 1.0.0
Status: educational starter; tailor to emergency, security, privacy, safety, employment and regulatory procedures before use.
Related gates: Control, Measure, Prove and Review
Starter controls: ctrl-incident-response, ctrl-human-review, ctrl-decision-trace
Intake and safety#
- Case and incident IDs:
- Detected at / detected by:
- System, version and environment:
- Observed behavior and affected people:
- Immediate safety or rights concern:
- Evidence-preservation owner:
- Initial containment and reversibility action:
Do not delay urgent protective action to complete this template.
Triage#
- Known facts:
- Unknowns and confidence:
- Potential impact and spread:
- Data or permissions involved:
- Human override available and tested:
- Internal escalation route:
- External notification decision owner:
This record does not determine legal materiality or reporting duties.
Response log#
| Time | Action | Owner | Evidence ID | Outcome |
|---|---|---|---|---|
Reopen lifecycle gates#
- Trigger ID:
- Gates reopened:
- Controls retested:
- Indicators reviewed:
- Release/return-to-service decision:
Learning review#
- Root and contributing conditions:
- Detection/control gaps:
- Corrective actions, owners and dates:
- Source or policy updates:
- Residual uncertainty and next review:
PALO FRAMEWORK