SECAI Core · phase 14 of 15

Incident response plan

Specific procedures that must be performed if a certain type of event is detected or reported.

The Explain card

Plain English
An incident response plan is the documented set of procedures that must be followed when a particular kind of event is detected or reported: who does what, in what order, and who decides.
Example
A company's plan for "model produces harmful or leaked content" specifies pulling the model from production, preserving logs, notifying legal, and issuing a pre-approved customer statement within two hours.
Why it matters
AI incidents are new, fast and public. Without a plan, teams argue about whether to switch the model off while screenshots spread. With one, the first hour is rehearsed.
Hook
Decide now, while calm, so nobody has to decide at two in the morning.

Where it sits in the deck

Phase 14: Incident Response, Evaluation, and Knowledge Bases

When detection fires, teams need structured response plans, scoring frameworks, and curated knowledge bases to triage, measure, and learn from AI security events.