Skip to content

Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support

Leadership guide/Operations & assurance

Operations & assurance

Monitoring and incident response

Who notices a problem and who can act?

Download the guide↓Editable working records→

In this guidePurpose and responsibilityWhat to put in placeA campus exampleDecide locallyYour working recordPolicy and sourcesThe arrangement to establish.

Approval begins an operating responsibility. Establish how the institution will notice changing performance, protect affected people and decide whether to continue, change, restrict or retire the use.

Responsible roles: Service owner with existing incident, security, privacy and specialist teams.

Leave with: A working monitoring and response plan with accountable restart authority.

What to put in place.

Choose signals that matter

Track the outcomes and failure conditions defined for release. Add complaints, appeals, access barriers, disparate effects, human overrides, unusual actions, workload, cost and service interruptions as appropriate. Name each signal's owner, review frequency, threshold and response.

Review changes and exceptions

Maintain the service inventory, current configuration and approval conditions. Review material model, data, feature, vendor or permission changes before expanding exposure. Trend exceptions and unresolved issues, and require renewed evidence when the use or its effects change.

Contain and protect

Make reporting easy for staff and affected people. Route AI failures through existing incident arrangements with the relevant specialists. Pause harmful actions, revoke affected permissions, preserve necessary evidence and activate the fallback. Address urgent service and safety needs without waiting for a complete diagnosis.

Investigate and repair

Identify affected people, records and downstream actions. Determine what was authorized, what happened and what failed. Correct records and services, provide an accessible human route and assess required notifications with responsible offices. Protect confidentiality and avoid copying sensitive material into an unrestricted incident log.

Authorize recovery and learn

Test the correction and reconcile partial or duplicate actions. The designated authority records restart conditions and remaining limits. Complete a review of causes, control changes, training and related uses. Report material risk and remediation to leadership; route board assurance through the president and established channels.

Test it with a real situation.

Illustrative campus example

A scheduling agent changes appointments before a connected service fails. Stopping it prevents further actions, but recovery also means identifying which appointments changed, restoring or confirming them and informing affected people. Restart follows a tested correction and an authorized decision.

Make the arrangements yours.

Take a record into the work.

Use the editable companion to capture the decision in your institution’s own systems. These prompts are also available in the printable guide.

Monitoring arrangement

Record signals, thresholds, owners, review intervals and alert destinations.

Incident and containment

Capture what happened, affected uses, immediate protections, evidence location and incident lead.

People and correction

Identify affected people or records, specialist decisions, communications and remedial actions.

Restart and learning

Record test evidence, restart authority, remaining conditions and follow-up owners and dates.

Download the working records→

Connect policy to practice.

Model policy: Section 6 · Section 9 · Section 11 · Section 12.

HumanSkills implementation recommendations informed by the sources below. These voluntary resources are not legal requirements or a certification. Apply current institutional requirements and specialist review to the actual use.

Explore the other operating guides→