MN-4.3 Incidents and errors are communicated to relevant AI actors including affected communities, and processes for tracking, responding to, and recovering from incidents and errors are followed and documented
Incidents and errors are communicated to relevant AI actors including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. Incidents and error
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- The incident and error record showing how each was identified · Document repository
- Communication records to relevant AI actors and affected communities · Policy repository / GRC workspace
- Evidence of whether the error was repaired and how the repair was distributed to impacted users · Document repository
governing documentDocuments that govern the control
- The followed process for tracking, response and recovery · Document repository
First move
Common gaps auditors find
- Incidents communicated internally only, never to affected communities
- Repair applied to the primary deployment while other users keep the defective version
- Record shows closure with no account of how the error was identified or fixed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMN-4.2 Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including relevant AI actors · MP-1.1 Intended purpose, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented