Legal, Regulatory & Stakeholder Notification
Operational controls for legal, regulatory & stakeholder notification.
Domain purpose
Operational controls for legal, regulatory & stakeholder notification.
Controls and requirements
D16-CTL-01Notification assessment
Establish a repeatable and accountable capability for notification assessment during AI security incident handling.
D16-CTL-02Regulatory evidence package
Establish a repeatable and accountable capability for regulatory evidence package during AI security incident handling.
D16-CTL-03Customer communication
Establish a repeatable and accountable capability for customer communication during AI security incident handling.
D16-CTL-04Executive reporting
Establish a repeatable and accountable capability for executive reporting during AI security incident handling.
Implementation use
Determine applicability using the framework scope and system context. Implementation should be proportionate to risk and supported by evidence sufficient to validate the intended outcome.