Tier 3: Safety and resilience controls
AI incident detection and response
Defined capability to detect, triage, contain, and remediate AI-related failures or harms, including governance escalation and documented post-incident corrections.
Board-defensible evidence
- Incident taxonomy defining AI incident types (harm events, bias events, model failures, data leakage, security misuse) and severity levels, including escalation thresholds to leadership and legal.
- Runbooks showing detection sources, triage steps, containment actions, notification requirements, and who has authority to pause or roll back a model.
- Incident logs showing event timelines, who was notified when, decisions made, actions taken, and evidence preserved for internal review or external inquiry.
- Root-cause analysis and corrective action records showing what failed, why it failed, what was changed, and what validation confirmed the fix, including governance sign-off.
- Post-incident governance review minutes showing lessons learned, policy updates, control improvements, and tracked follow-ups with owners and deadlines.
Why this matters
When harm happens, response quality and documentation determine whether the story is "controlled event" or "governance breakdown."
How ready is your board on safety and resilience controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.