Model Risk Incident Report Template
Structured, interactive incident report to document, triage, and track model failures, bias events, or unexpected model behavior. Saves consistent, auditable information (who, what, when, evidence, mitigations, remediation plan, and lessons) to support faster remediation, clear ownership, and durable learning.
Use this form to capture a consistent, auditable record whenever a model behaves unexpectedly, shows signs of bias, or causes business or customer impact. Provide evidence, initial mitigations, a remediation plan, and the post-incident learning steps. Fields marked required help ensure regulators and auditors can follow the timeline and decisions.
","SubmitLabel":"Save Incident Report","SuccessMessage":"Incident saved. You can return to update the record, or export it for audits and reviews.","DataType":"model_incident_report","SchemaVersion":"1.0","Fields":[{"Key":"incident_id","FieldType":"text","Label":"Incident ID","HelpText":"Unique identifier (team may use existing incident number). If you don\u2019t have one, leave blank and the system will generate an ID.","Required":false},{"Key":"reported_by","FieldType":"text","Label":"Reported by (name / role)","HelpText":"Person who submitted this report.","Required":true},{"Key":"reported_date","FieldType":"text","Label":"Date and time (UTC)","HelpText":"Format: YYYY-MM-DD HH:MM, e.g. 2026-08-26 14:30. Include timezone if not UTC.","Required":true},{"Key":"incident_summary","FieldType":"textarea","Label":"Incident summary","HelpText":"Short, plain-language summary: what happened, when it was first observed, and who noticed it.","Required":true},{"Key":"detection_method","FieldType":"select","Label":"How was the incident detected?","HelpText":"Select the primary detection channel.","Required":true,"Options":[{"Value":"monitoring_alert","Label":"Monitoring / alert"},{"Value":"customer_report","Label":"Customer / user report"},{"Value":"internal_test","Label":"Internal testing or QA"},{"Value":"audit_finding","Label":"Audit or compliance finding"},{"Value":"manual_observation","Label":"Manual observation by staff"},{"Value":"other","Label":"Other"}]},{"Key":"affected_models","FieldType":"textarea","Label":"Affected model(s) and versions","HelpText":"List model names, IDs, versions, deployment IDs, and locations (prod/staging). Include URLs or pointers to model registry entries if available.","Required":true},{"Key":"business_impact","FieldType":"select","Label":"Business / customer impact","HelpText":"Select the best description of current impact.","Required":true,"Options":[{"Value":"no_customer_impact","Label":"No customer impact"},{"Value":"minor","Label":"Minor (limited scope, workaround available)"},{"Value":"moderate","Label":"Moderate (some customers affected, partial degradation)"},{"Value":"major","Label":"Major (widespread impact or revenue loss)"},{"Value":"critical","Label":"Critical (safety, legal, or major compliance exposure)"}]},{"Key":"severity_scale","FieldType":"scale","Label":"Severity (1 = low, 5 = critical)","HelpText":"Numeric severity to help prioritization.","Required":true,"Options":[{"Value":"1","Label":"1"},{"Value":"2","Label":"2"},{"Value":"3","Label":"3"},{"Value":"4","Label":"4"},{"Value":"5","Label":"5"}]},{"Key":"key_metrics_and_evidence","FieldType":"textarea","Label":"Key metrics and evidence","HelpText":"Describe metrics that changed (counts, error rates, bias metrics) and point to dashboards, logs, or example records. Paste key numbers or short JSON snippets if helpful.","Required":true},{"Key":"supporting_links","FieldType":"textarea","Label":"Supporting links and artifacts","HelpText":"URLs to dashboards, logs, model registry entries, dataset snapshots, issue trackers, or evidence files.","Required":false},{"Key":"initial_triage_steps","FieldType":"textarea","Label":"Initial triage steps taken","HelpText":"What immediate checks were performed? Who was pulled in? Include commands, queries, or scripts used if helpful.","Required":true},{"Key":"mitigations_in_place","FieldType":"textarea","Label":"Temporary mitigations / containment steps applied","HelpText":"Example: disable feature flag, rollback to prior model, throttle traffic, apply business-rule override. State start time for each mitigation.","Required":true},{"Key":"root_cause_hypothesis","FieldType":"textarea","Label":"Root cause hypothesis (initial)","HelpText":"A concise hypothesis for why the model failed (data drift, training bug, feature pipeline change, labeling issue, model degradation, external system change, adversarial input, etc.).","Required":false},{"Key":"validation_plan","FieldType":"textarea","Label":"Validation plan to confirm root cause","HelpText":"How will the hypothesis be tested? List tests, datasets, expected outcomes, and owners.","Required":false},{"Key":"stakeholder_notifications","FieldType":"checkbox","Label":"Stakeholders notified or to notify","HelpText":"Select stakeholder groups that have been or should be notified.","Required":true,"Options":[{"Value":"product","Label":"Product Management"},{"Value":"legal","Label":"Legal"},{"Value":"compliance","Label":"Compliance"},{"Value":"security","Label":"Security / InfoSec"},{"Value":"operations","Label":"Operations / SRE"},{"Value":"data_science","Label":"Data Science / ML"},{"Value":"privacy","Label":"Privacy"},{"Value":"customers","Label":"Affected customers"},{"Value":"regulators","Label":"Regulators"},{"Value":"other","Label":"Other"}]},{"Key":"regulatory_considerations","FieldType":"textarea","Label":"Regulatory or contractual considerations","HelpText":"Notes on data subject rights, breach-reporting timelines, or contract obligations. Include statutory reporting deadlines if known.","Required":false},{"Key":"remediation_steps","FieldType":"textarea","Label":"Remediation steps (planned)","HelpText":"Concrete actions to fix the problem, who will do them, and acceptance criteria.","Required":true},{"Key":"remediation_timeline_days","FieldType":"number","Label":"Planned timeline (days)","HelpText":"Estimated days to remediate from now.","Required":false},{"Key":"post_incident_review_actions","FieldType":"textarea","Label":"Post-incident review and policy updates","HelpText":"Suggested improvements to monitoring, runbooks, testing, deployment controls, or governance that will reduce recurrence.","Required":false},{"Key":"lessons_learned_owner","FieldType":"text","Label":"Owner for lessons learned / follow-up","HelpText":"Person responsible for ensuring PR, playbook, and policy updates are completed.","Required":false},{"Key":"audit_trail_preserved","FieldType":"yesno","Label":"Is an audit trail preserved (logs, snapshots)?","HelpText":"Yes = evidence is saved to a secure, immutable location; No = not yet preserved.","Required":true},{"Key":"urgent_actions_required","FieldType":"yesno","Label":"Are urgent customer-facing actions required?","HelpText":"For example, recall, customer notification, or temporary shutdown.","Required":true},{"Key":"confidential","FieldType":"yesno","Label":"Mark as confidential / restricted","HelpText":"Restrict sharing if the incident contains sensitive personal data or trade secrets.","Required":false},{"Key":"additional_notes","FieldType":"textarea","Label":"Additional notes","HelpText":"Anything else the incident team should know.","Required":false}],"Notes":"This InteractiveForm captures a complete, consistent incident record for model failures. Use the Supporting links field to attach pointers to evidence. Teams should extend this base form with site-specific required fields (for example, internal ticket numbers, product line, or regulation-specific items)."}Discussion
Comments and conversation will live here.