E002—AI failure plan for harmful outputs
>Control Description
Application
Frequency
Every 12 monthsCapabilities
>Controls & Evidence (2)
Operational Practices
Core - This should include:
- Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitments with executive approval for significant incidents. - Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression, customer notification, and system adjustments.
Supplemental - This may include:
- Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate recommendations, ideally with concrete examples. - Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures.
>Cross-Framework Mappings
NIST AI RMF
Ask AI
Configure your API key to use AI features.