SECAI Core · phase 14 of 15
Incident response plan
Specific procedures that must be performed if a certain type of event is detected or reported.
The Explain card
- Plain English
- An incident response plan is the documented set of procedures that must be followed when a particular kind of event is detected or reported: who does what, in what order, and who decides.
- Example
- A company's plan for "model produces harmful or leaked content" specifies pulling the model from production, preserving logs, notifying legal, and issuing a pre-approved customer statement within two hours.
- Why it matters
- AI incidents are new, fast and public. Without a plan, teams argue about whether to switch the model off while screenshots spread. With one, the first hour is rehearsed.
- Hook
- Decide now, while calm, so nobody has to decide at two in the morning.
Where it sits in the deck
Phase 14: Incident Response, Evaluation, and Knowledge Bases
When detection fires, teams need structured response plans, scoring frameworks, and curated knowledge bases to triage, measure, and learn from AI security events.