AI-IRF / D11 / D11-CTL-04

Third-party component escalation

Objective

Establish a repeatable and accountable capability for third-party component escalation during AI security incident handling.

Control / requirement

The organization should define ownership, decision criteria, technical procedures, dependencies, and escalation conditions for third-party component escalation.

Business impact

Failure may increase incident duration, uncertainty, evidence loss, propagation, or regulatory exposure.

Validation approach

Inspect approved procedure; test through scenario or technical exercise; verify retained evidence and action records.

Expected evidence

Policy or playbook; exercise or incident record; technical logs; decision and approval evidence.

Mapping and source

Prototype website catalogue — replace with the authoritative approved AI-IRF control record.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.