Governance & Compliance · Data artifact
AI Incident Classification Policy
Data artifactGovernance & ComplianceSafety, Security & Governancearc:AIIncidentClassificationPolicy
A policy defining what constitutes an AI incident (performance degradation beyond thresholds, bias exceeding acceptable levels, security compromise, harmful outputs reaching users, regulatory violation) and its severity classes.
Responsibility. Determines which AI events are incidents and how severe they are.
Also known as: Incident criteria, Incident classification
Relationships
configures structural
Design guidance
- MUST define incident triggers for fairness and harmful-output events, not only availability failures.
- SHOULD specify that a system is withdrawn from use pending investigation when accuracy or bias thresholds are breached in high-stakes settings.
Classification
- Quality attributes
- Performance efficiency (ISO/IEC 25010)Reliability (ISO/IEC 25010 | NIST AI RMF: valid and reliable)
- Risks mitigated
- Improvised response under pressureUnreported AI harms
- Frameworks & regulations
- NIST AI RMF: MANAGEISO/IEC 42001 Annex A: incident management controlsHIPAA breach notification
Sources
- Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.
- Ref9.06: "Auditing and Compliance Monitoring for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/06-Auditing-Compliance-Monitoring.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note