ChecklistFree downloadEU AI ActNIST AI RMFISO/IEC 42001

Free AI Incident Response Checklist

Detect, triage, contain, report and learn from AI incidents, including the serious-incident reporting duties in the EU AI Act.

Formats: Markdown, CSV, XLSX, DOCX · Version 1.0 · Last updated 11 Sep 2026

What it is for

AI incidents differ from ordinary outages: harm can be silent, distributed and discovered by users or journalists first. This checklist sets out detection signals, severity triage using the MIT AI Risk Repository domains, containment options (rollback, kill switch, human-only mode), regulatory reporting (EU AI Act Article 73 serious incidents, data-protection breach rules) and the post-incident review that feeds the risk register.

Preview: fields in the checklist

Fields in AI Incident Response Checklist
FieldWhat to record
StagePrepare, detect, triage, contain, notify, recover, learn.
ItemThe concrete step.
OwnerRole responsible.
Time targetExpected time from detection.
ReferenceObligation, standard clause or internal policy.
DoneYes / no / n.a. with timestamp.

How to use it

  1. Run a tabletop exercise with a recorded incident from the AI Incident Database before you need this for real.
  2. Keep the notification matrix current: regulator, customers, data-protection authority, insurer.
  3. Every incident closes with a risk-register update.

Framework and policy mapping

Create a free account to download

Get instant access to this free checklist and receive updates when related AI policy requirements change.

By downloading, you agree to the template licence and acknowledge that AIPolicyTracker provides informational resources, not legal advice.

Frequently asked questions

Is the AI Incident Response Checklist free?
Yes. Preview every field online; download the Markdown, CSV, XLSX, DOCX with a free account under a CC BY 4.0 licence.
Which frameworks does it map to?
EU AI Act, NIST AI RMF, ISO/IEC 42001. The mapping section links the recorded policy instruments and guides it draws on.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence that regulators, customers and auditors ask for.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.