Track 12Compliance InfrastructureLocked by prerequisiteRecommended

AI Incident Reporting & Response

Enable learners to recognise an AI incident, report it correctly and promptly, contribute to investigation and containment, and support corrective action that actually prevents recurrence.

6 lessons · 5 frameworks · 3–4 hours · 0/6 complete · 0/6 exercises recorded

Locked by prerequisite

This track opens once its prerequisites are complete. Prerequisites are sequenced deliberately: each one supplies a competency this track assumes you already hold.

  • Track 01 — AI Fundamentals
  • Track 02 — AI Governance & Regulatory Expectations
  • Track 05 — Risk Assessment & Risk Recognition
  • Track 07 — Human Accountability & Oversight

Orientation

Why this matters

AI incidents rarely announce themselves. They surface as a wrong number in a report, a rising correction rate, or a colleague's unease — and the interval between first suspicion and first report determines how much exposure accumulates.

What you will be able to do (5)

  • Recognise the signals that indicate an AI incident
  • Report an AI incident through the correct channel within the required timeframe
  • Contribute to containment and impact assessment
  • Support root cause analysis that reaches beyond the model
  • Apply corrective actions and verify their effectiveness

Aligned with (5)

ICH Q9(R1) — quality risk managementICH Q10 — corrective and preventive actionEU AI Act — serious incident reporting obligationsEU GMP Annex 11 — incident and deviation managementNIST AI RMF — manage function

Maps to published expectations. Competency demonstrated through assessment.

Regulatory alignment indicates that curriculum topics map to published regulatory expectations. It does not constitute agency approval, certification, legal advice or a determination of organizational compliance.

View source evidence, status and applicability

ICH Q9(R1) — quality risk management

Harmonised guidelineICH regions; implemented through regional frameworks
ICH Q9(R1) — Quality Risk Management
Relevant provisions
Sections 4–6 and Annexes I–II
Status and date
Step 4, 18 January 2023. Implementation depends on the relevant regional authority and regulated activity.
Why it maps
Supports the track's stated mapping to ICH Q9(R1) — quality risk management without transferring duties beyond the source's scope.
Applicability limit
Supplies quality-risk principles. It does not independently classify an AI system or prescribe one universal control set.

Primary source last verified 2026-08-24

ICH Q10 — corrective and preventive action

Harmonised guidelineICH regions; implemented through regional frameworks
ICH Q10 — Pharmaceutical Quality System
Relevant provisions
Sections 2–4: management responsibility, lifecycle elements and continual improvement
Status and date
Step 4, 4 June 2008. Implementation depends on the relevant regional authority and product lifecycle.
Why it maps
Supports the track's stated mapping to ICH Q10 — corrective and preventive action without transferring duties beyond the source's scope.
Applicability limit
Provides the pharmaceutical quality-system model used to place AI controls within governance, CAPA, change and management review.

Primary source last verified 2026-08-24

EU AI Act — serious incident reporting obligations

Binding lawEuropean Union
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Relevant provisions
Article 73 — reporting of serious incidents
Status and date
Official Journal, 12 July 2024. Entered into force 1 August 2024; phased application through 2 August 2027.
Why it maps
Connects the lesson to the Act's conditional duties while preserving classification, role and application-date limits.
Applicability limit
Specific duties depend on system classification, actor role, territorial scope and the applicable date. No duty should be extended beyond those conditions.

Primary source last verified 2026-08-24

EU GMP Annex 11 — incident and deviation management

GMP requirementEuropean Union GMP
EudraLex Volume 4, Annex 11 — Computerised Systems
Relevant provisions
Section 13 — incident management
Status and date
Revision January 2011. Current Annex 11; came into operation 30 June 2011.
Why it maps
Supports the track's stated mapping to EU GMP Annex 11 — incident and deviation management without transferring duties beyond the source's scope.
Applicability limit
Applies to computerised systems used as part of GMP-regulated activities. Applicability follows the regulated process and intended use.

Primary source last verified 2026-08-24

NIST AI RMF — manage function

Voluntary frameworkNon-sector-specific; international use
NIST AI Risk Management Framework 1.0
Relevant provisions
MANAGE function
Status and date
26 January 2023. Voluntary; AI RMF 1.0 is under revision as of August 2026.
Why it maps
Provides a voluntary operating structure for the risk-management decisions practised in the lesson.
Applicability limit
Provides risk-management outcomes and practices. It does not create a legal mandate unless adopted through contract, policy or another authority.

Primary source last verified 2026-08-24

Full source register and editorial method →

Credential

AI Incident Recognition and Response Badge

Duration

3–4 hours

Audience

  • All AI users in regulated environments
  • Quality, safety and manufacturing professionals
  • System owners and incident investigators

Prerequisites

  • Track 01
  • Track 02
  • Track 05
  • Track 07

Behaviours practised (3)

EscalateVerifyDocument
A reviewer notices that an AI tool has attributed a result to the wrong batch. It is the second time this month. Neither instance was reported, because each looked like a one-off — and the tool has produced four hundred outputs since the first.

Badge requirements (6)

  1. Complete all six lessons and their knowledge checks
  2. Achieve at least 80% across the final badge assessment
  3. Answer every safety-critical question correctly
  4. Classify every near miss as reportable
  5. Place evidence preservation before containment in the response sequence
  6. Produce corrective actions above the level of reminders with measurable effectiveness criteria

Lessons (6)

Final badge assessment

AI Incident Recognition and Response Badge

  • Incident recognition

    Select all that apply and scenario classificationSafety-critical

    Classify eight events as incident, near miss or expected variability.

  • Reporting and escalation

    Choose the correct escalation pathSafety-critical

    Select the correct reporting channels and timeframe for five incidents.

  • Response sequence and cause analysis

    Ordering workflow steps and match a control to a riskSafety-critical

    Order the immediate response steps and match corrective actions to identified causes.

  • Practical exercise — incident report and investigation

    Practical exercise

    Produce a first incident report, a containment plan and an actionable root cause statement.

Next recommended track

← All tracks