unified
UC-AI-11 — Operate AI concern, incident, and external reporting channels
Operate channels through which personnel and other stakeholders can report concerns about the organization's role in developing or using AI systems, with documented triage and follow-up. Define and execute procedures for communicating AI incidents to affected users and interested parties, and for making required reports to regulators and other external bodies within mandated timeframes. Retain concern reports, incident communications, and resolution records as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- AI Governance
- type
- detective
- category
- administrative
Details
- unified_id
- UC-AI-11
- title
- Operate AI concern, incident, and external reporting channels
- statement
- Operate channels through which personnel and other stakeholders can report concerns about the organization's role in developing or using AI systems, with documented triage and follow-up. Define and execute procedures for communicating AI incidents to affected users and interested parties, and for making required reports to regulators and other external bodies within mandated timeframes. Retain concern reports, incident communications, and resolution records as evidence.
- domain
- AI Governance
- control_type
- detective
- control_category
- administrative
- members
- framework
- iso-42001
- control_id
- A.3.3
- coverage
- full
- relationship
- superset_of
- framework
- iso-42001
- control_id
- A.8.3
- coverage
- full
- relationship
- superset_of
- framework
- iso-42001
- control_id
- A.8.4
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- E001
- coverage
- partial
- delta
- a pre-approved failure plan for AI security breaches with containment, rollback, and customer-notification steps
- relationship
- intersects_with
- framework
- aiuc-1
- control_id
- E002
- coverage
- partial
- delta
- a pre-approved failure plan for harmful outputs with containment, rollback, and customer-notification steps
- relationship
- intersects_with
- framework
- aiuc-1
- control_id
- E003
- coverage
- partial
- delta
- a pre-approved failure plan for hallucination incidents with containment, rollback, and customer-notification steps
- relationship
- intersects_with
- framework
- eu-ai-act
- control_id
- AIA-Art20
- coverage
- partial
- delta
- provider-side corrective action (withdrawal, disabling, recall) of non-conforming systems and information to distributors, deployers, and authorities
- relationship
- intersects_with
- framework
- eu-ai-act
- control_id
- AIA-Art73
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- ISO/IEC 42001 AI Management System Internal Audit tests UC-AI-11 — Operate AI concern, incident, and external reporting channels
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to E001 — AI failure plan for security breaches
- framework
- aiuc-1
- control_id
- E001
- coverage
- partial
- delta
- a pre-approved failure plan for AI security breaches with containment, rollback, and customer-notification steps
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- AI Governance & Risk/Impact Assessment oversees UC-AI-11 — Operate AI concern, incident, and external reporting channels
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to A.8.3 — External reporting
- framework
- iso-42001
- control_id
- A.8.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels mitigates Inaccurate, unreliable or hallucinated AI outputs
- strength
- related
- rationale
- Concern channels surface complaints of erroneous outputs for follow-up and correction.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to E003 — AI failure plan for hallucinations
- framework
- aiuc-1
- control_id
- E003
- coverage
- partial
- delta
- a pre-approved failure plan for hallucination incidents with containment, rollback, and customer-notification steps
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels mitigates Harmful AI bias and discrimination against protected groups
- strength
- related
- rationale
- Stakeholder concern channels surface discrimination complaints for triage and remediation.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels mitigates AI accountability gaps and organizational liability
- strength
- related
- rationale
- Timely incident and regulator reporting discharges external duties and reduces sanction exposure, but does not close the core ambiguous-responsibility gap the risk centers on; role/owner assignment (UC-02/UC-13) is operative.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels mitigates AI safety failures causing physical or psychological harm
- strength
- related
- rationale
- Incident channels detect and communicate safety harms to affected parties for response, reducing impact.
- AI Operations Monitoring & Incident Response operates UC-AI-11 — Operate AI concern, incident, and external reporting channels
- UC-AI-11 — Operate AI concern, incident, and external reporting channels mitigates GPAI transparency, systemic-risk and synthetic-content obligations
- strength
- related
- rationale
- General incident-reporting infrastructure supports the serious-incident reporting duties for systemic models.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to A.8.4 — Communication of incidents
- framework
- iso-42001
- control_id
- A.8.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to AIA-Art73 — Reporting of serious incidents (providers; deployers inform providers)
- framework
- eu-ai-act
- control_id
- AIA-Art73
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Regulation (EU) 2024/1689
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to A.3.3 — Reporting of concerns
- framework
- iso-42001
- control_id
- A.3.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to AIA-Art20 — Corrective actions and duty of information for non-conforming high-risk AI systems
- framework
- eu-ai-act
- control_id
- AIA-Art20
- coverage
- partial
- delta
- provider-side corrective action (withdrawal, disabling, recall) of non-conforming systems and information to distributors, deployers, and authorities
- relationship
- intersects_with
- source_version
- Regulation (EU) 2024/1689
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-11 — Operate AI concern, incident, and external reporting channels maps_to E002 — AI failure plan for harmful outputs
- framework
- aiuc-1
- control_id
- E002
- coverage
- partial
- delta
- a pre-approved failure plan for harmful outputs with containment, rollback, and customer-notification steps
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.