| Current-state assessment | AI inventory coverage, incident pathways, controls, evidence, gaps, and priorities | Assessment report and register | Assess | Systems, policies, incidents, interviews | AI governance lead |
| Incident taxonomy and severity model | Event categories, harm dimensions, thresholds, examples, and escalation triggers | Standard and decision matrix | Establish | Risk appetite and materiality | Enterprise risk owner |
| Operating model and RACI | Roles, decision rights, forums, handoffs, approvals, and accountability | Operating model pack | Establish | Organisation and committee design | Executive sponsor |
| Incident response playbook | Intake, triage, containment, investigation, remediation, validation, reporting, and closure | Procedure and templates | Establish | Existing response processes | Incident governance owner |
| Evidence and decision toolkit | Intake form, evidence checklist, investigation plan, decision log, action register, closure record | Reusable templates | Implement | Legal, audit, security requirements | Case manager |
| Exercise and training pack | Scenario, facilitator guide, participant materials, findings, and improvement backlog | Workshop and report | Validate | Participants and scenarios | Governance programme lead |
| Reporting and assurance framework | KPIs, dashboards, review cadence, control tests, and committee reporting | Dashboard specification | Operate | Reporting needs and data sources | Risk and assurance owner |