Templates
AI incident runbook
Triggers
- unauthorized or irreversible effect;
- disclosure, unauthorized access, or compliance with a malicious instruction;
- discrimination or severe error;
- loss of logging or identity attribution;
- loop, consumption, or volume beyond limits;
- unevaluated supplier change;
- inability to obtain recourse or return to the manual process.
0–15 minutes — Contain
- suspend the affected workflow or tool;
- revoke exposed access or secrets;
- prevent propagation without destroying evidence;
- switch to the manual process;
- name the incident commander.
15–60 minutes — Assess
- record timestamps, versions, users, data, tools, and destinations;
- distinguish actions requested, dispatched, confirmed, and persistent;
- identify affected people or systems;
- determine notification duties;
- preserve evidence proportionately.
Resolve
- correct or reverse effects where possible;
- notify accountable roles and competent authorities according to the plan;
- communicate without speculation;
- test the fix against the incident case and variants;
- obtain a new gate decision before resuming.
After the incident
- root cause and organizational contributors;
- controls expected, present, and effective;
- updates to tests, risks, training, and supplier controls;
- decision: resume, restrict, replace, or retire;
- owner and deadline for every action.
To print or save as PDF: Ctrl+P (⌘P on Mac).
Source and history · GitHub