The Self-Inflicted Incident Plan
Your incident plan assumes an attacker and the next AI failure will come from a system your board approved: audit the plan and settle the hard decisions while the room is calm.
Scope. About 7-page playbook: six-assumption audit, shutdown authority, return-to-use and insurance questions, with a worksheet. Governance toolkit: practitioner-designed, for use in your context.
The complaint arrives eleven months after the first customer was affected. An AI system had been applying a slightly wrong rule to a large volume of transactions — mispricing, in breach of regulation, every individual decision looking reasonable. The board reaches for the incident protocol built after the cyber scare two years earlier. Contain. Notify. Investigate. Report back. Most of that protocol still works. But six of the assumptions underneath it belong to cyber alone, and each one changes what the board does on the day.
An incident plan fit for the failure you caused
The Self-Inflicted Incident Plan audits an existing crisis protocol against the failure it was never built for: an AI system the board approved, quietly harming customers while every operational check passed. It sets out the six assumptions that hold for a cyber event and break for an AI failure, and the decisions the board must settle in advance — while the room is calm — because they cannot be settled in the hours after the complaint arrives.
Use it by auditing your existing incident protocol against the six assumptions, then settling shutdown authority, return to use and the insurance questions, and taking each decision to the minutes.
Six assumptions, four advance decisions
- The six-assumption audit of an existing incident plan
- The shutdown-authority decision
- The return-to-use decision reserved to the board
- The insurance-renewal questions that establish what the company would actually recover
- A worksheet: the audit, shutdown authority, return to use, and insurance answers, ready for the minutes
Before an incident, while the room is calm
Built for the people who own the crisis response
Written for the Chair responsible for the incident protocol. It also serves risk managers who own the crisis response, and whoever signs off the insurance programme, because the renewal in front of them may quietly move a category of AI loss onto the company's own balance sheet.
Decisions made while the room is calm
You'll test your incident plan against a failure you caused rather than one done to you. Who can stop which AI systems, and when, is settled in advance, the return-to-use decision sits with the board, and you'll have in writing what your insurance would actually pay if an AI system caused a significant loss.
A practitioner-designed toolkit to be applied in your own context.
The Self-Inflicted Incident Plan
Catalogue No. 09 · €[PRICE] · Digital delivery