Governance framework & guidance
What is an AI Governance Incident?
An AI Governance Incident is an event or circumstance involving AI that may require governance attention. Examples include materially incorrect output, unexpected disclosure of information, Control failure, inappropriate reliance on AI, use outside approved scope, unfair outcomes, supplier events or unexpected automated action.
The person reporting the Incident does not need to diagnose its legal or technical significance. They need to report what happened.
Swell does not replace specialist incident systems
An AI event may require privacy, security, legal, safety or other specialist processes. Swell can record that those escalations are required but does not determine that an event is legally a notifiable data breach, a cybersecurity incident or another regulated event.
Its role is to preserve the governance facts and ensure the event is reflected in the organisation’s AI governance position.
Incidents can change Risks and Controls
An Incident can provide new evidence about likelihood, consequence or Control effectiveness. If a Control that supported the residual Risk position is shown to be ineffective, the organisation may need corrective Action, Risk reconsideration, reassessment or reapproval.
An Incident does not automatically mean the AI Use was badly governed. Strong governance includes detecting issues, responding appropriately and learning from them.
Using Swell AI
Reporting an Incident
- Record a clear title and plain-language description of what happened.
- Select severity: Not yet assessed, Low, Moderate, High or Critical.
- Record when it occurred and when it was detected where known.
- Record immediate action already taken.
- Link the Incident to the affected AI Use where known.
Incident triage
Governance triage asks what needs to happen because of the Incident. The Governance Manager can identify privacy, security or legal escalation needs and determine whether reassessment, reapproval or another governance response is required.
“Not yet assessed” is a valid starting point where the person reporting the Incident cannot reasonably judge severity.
Incident lifecycle
Swell supports a controlled lifecycle: Reported → Triage → Investigating → Containment → Remediation → Review & Assurance → Closed.
Specialist work may occur outside Swell while the governance status remains visible. Closure requires an outcome so the record explains what was established or resolved.