AI That Works  ·  AI6 Guidance
AI6-T03.3
Process Document — Pillar 03
AI Incident Response & Reporting Plan
Document No.AI6-T03.3Version[1.0]
Document Owner[Name / Role]Date[DD/MM/YYYY]
Review Date[DD/MM/YYYY]Status[ Draft / In Review / Approved ]
Organisation[Organisation Name]
This plan must be tested at least annually. All personnel with AI oversight responsibilities must be briefed on their specific obligations under this plan before taking up their role. Legal review is recommended for regulatory notification obligations.
1. Incident Classification
SeverityDefinitionExamplesRequired Response Time
CriticalHarm to person; regulatory breach; major operational failure; data breach affecting personal informationAI-influenced decision causes workplace injury; PII leak; system failure on safety-critical functionImmediate — within 1 hour. Notify Executive AI Officer, Legal, and Board same day.
HighMaterial error in AI output; significant operational impact; near-miss with potential harmEstimating error >10%; scheduling failure causing fatigue non-compliance; model output used without required reviewWithin 4 hours. Notify Risk & Compliance and Executive AI Officer within 24 hours.
MediumIdentifiable AI error with limited operational impact; detected before consequential useErroneous classification caught by human reviewer; minor drift detected in monitoring dashboardWithin 24 hours. Log in AI Risk Register. Root cause analysis within 5 business days.
2. Regulatory Notification Obligations
  • OAIC (Office of the Australian Information Commissioner): Data breaches involving personal information that are likely to result in serious harm must be notified within 30 days under the Privacy Act 1988 (NDB scheme).
  • Sector regulators: Notify relevant sector regulators (SafeWork, ASIC, ACCC) as applicable to the nature and context of the incident.
  • Clients / principals: Notify affected clients within [24/48] hours as required under contract or where the incident affects their operations or data.
3. Post-Incident Review
Root cause analysis — required within
[ 5 / 10 / 15 ] business days of incident containment. Document findings and corrective actions in the AI Risk Register.
Corrective action sign-off
Executive Accountable Official must approve all corrective actions before the affected system is returned to operational use.