Skip to content

Define Risk levels/Classification/management and escalation paths #23

@shabarikk

Description

@shabarikk

Risks may be identified through multiple channels, including:

  1. User feedback or complaints
  2. Monitoring and logging alerts
  3. Security or privacy reviews
  4. Red-teaming or testing exercises
  5. Policy or compliance checks
  6. Cost overruns

Common risk types include data exposure, incorrect or misleading outputs, service outages, cost overruns, and misuse of AI capabilities.

Escalation Paths

Clear escalation paths are established so everyone knows what to do when an issue arises:

Level 1 – Operational Support
Handled by the delivery or platform team (e.g., configuration issues, minor errors).

Level 2 – Technical & Security Review
Escalated to architecture, security, or privacy teams for deeper investigation.

Level 3 – Governance & Leadership
High-risk issues involving policy, legal, privacy, or public impact are escalated to senior leadership, legal counsel, or executive governance bodies.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions