{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-011.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-011",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-011.json",
    "title": "Serious incident reporting clocks",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Each incident record keeps severity and reportability in separate fields set by named people with timestamps, and records when the organisation became aware and one entry per regime assessed; a deployer that identifies a serious incident informs the provider first, then the importer or distributor and the authority, and starts the Art. 73 timers on its own record when the provider cannot be reached.",
    "failureModes": [
      "A single priority field is read one way by engineering and another by legal, so the reportability decision is never taken.",
      "A deadline is missed because detection, triage and reporting are disconnected manual steps.",
      "A \"not applicable\" decision leaves no rationale or owner, so the organisation cannot show later why it did not report.",
      "The provider does not answer and no clock starts on the deployer's own record."
    ],
    "scope": "Incidents in deployed AI systems, whoever built them. The AI Act clocks bind providers of high-risk systems and, when the provider cannot be reached, their deployers; a personal data breach inside an AI incident adds the GDPR clock.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Incident record with its reporting block (awareness time, one entry per regime with rationale, deadline and submission) and the timestamp of each notification",
        "schemaId": "incident-record",
        "schema": "https://aigovernanceengineer.com/schemas/incident-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "The pipeline alerts on the nearest reporting deadline and pages the system owner and legal; a person can override the first classification, and the override is logged with a reason."
    },
    "layer": 5,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "incident-pipeline",
        "title": "Incident Pipeline",
        "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "incident-pipeline",
        "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
      },
      {
        "kind": "schema",
        "ref": "incident-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-incident-record"
      },
      {
        "kind": "chapter",
        "ref": "incidents",
        "url": "https://aigovernanceengineer.com/bok/incidents"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART73",
          "name": "EU AI Act Art. 73 serious-incident reporting",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART26-5",
          "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5"
        },
        {
          "id": "AIGE-OBL-GDPR-ART33-34",
          "name": "GDPR Arts. 33–34 personal data breach notification",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art33-34"
        }
      ],
      "iso42001": [
        {
          "id": "A.8.4",
          "title": "Communication of incidents"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MANAGE 4.3",
          "title": "Incidents and errors are communicated to relevant AI actors, including affected communities."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 39,
        "title": "Incidents, issues and root causes",
        "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"The overlapping clocks\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/incidents#the-overlapping-clocks",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "Incidents, issues and root causes",
        "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Deployer duties: inform the provider, suspend use\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/incidents#deployer-duties-inform-the-provider-suspend-use",
        "verified": "primary"
      },
      {
        "n": 40,
        "title": "Incidents, issues and root causes",
        "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"A severity scale mapped to the clocks\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/incidents#a-severity-scale-mapped-to-the-clocks",
        "verified": "primary"
      },
      {
        "n": 41,
        "title": "Incidents, issues and root causes",
        "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"The incident record\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/incidents#the-incident-record",
        "verified": "primary"
      },
      {
        "n": 37,
        "title": "Pattern: Incident Pipeline",
        "text": "Pattern: Incident Pipeline (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/incident-pipeline",
        "verified": "primary"
      },
      {
        "n": 42,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 73",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 73 (reporting of serious incidents: no later than 2, 10 or 15 days from awareness). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_73",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
        "verified": "primary"
      },
      {
        "n": 43,
        "title": "Regulation (EU) 2016/679 (GDPR), Art. 33",
        "text": "Regulation (EU) 2016/679 (GDPR), Art. 33 (notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours). Publications Office of the EU (EUR-Lex). 2016-04-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_33",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Classify up and downgrade with evidence: the deadlines run from awareness, and a reasonable likelihood of a causal link is enough to start them.",
      "Hold the facts once and render each regime's report from the record, never retyped; keep the provider's incident contact and channel on the registry entry and test the notification terms in drills."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "Which regimes count as equivalent for a given system, which narrows Art. 73 reporting to fundamental-rights infringements, is a legal call the source material says to record per system; who records it awaits review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
