Public AI Governance Documentation
AI Incident Register Template
A lightweight template for confirmed or suspected AI, privacy, security, provider, and voice-practice incidents.
This document is a public governance summary. It does not publish raw AI instructions, exact internal eval cases, source code, tenant data, incident details, database schema, or provider-console settings.
Use this register for confirmed or suspected AI, privacy, security, provider, voice-practice, or data-boundary incidents.
Severity Guide
- Sev 1: confirmed cross-tenant data exposure, security breach, or personal data exposure.
- Sev 2: materially false AI statement likely to affect hiring, reputation, or user trust.
- Sev 3: low-impact incorrect, incomplete, or poor-quality AI output.
- Sev 4: harmless quality issue, documentation gap, or near miss.
Register
| ID | Date opened | Source | Surface | Severity | NIST AI 600-1 category | Summary | User impact | Containment | Root cause | Corrective action | Notification | Date closed | Owner |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AI-YYYY-001 | YYYY-MM-DD | Report abuse / Sentry / support / internal review | Career agent / fit memo / interview prep / voice practice / other | Sev 1-4 | Confabulation / Data Privacy / Information Security / other | Short description | Affected candidate, visitor, or internal only | Immediate action taken | Known / unknown | Fix, prompt update, data edit, provider action, documentation update | Who was notified and when | YYYY-MM-DD | Owner |
Closure Criteria
Close an incident only when:
- The affected scope is understood.
- Any necessary user notification has been completed or explicitly deemed not required.
- The incorrect public content, data exposure, or product issue has been contained.
- The corrective action is deployed or intentionally accepted as residual risk.
- The relevant system card, risk map, or public governance page has been updated if the incident changed the risk posture.