A mandatory guide for Banking and Telecom compliance departments regarding serious incident notifications.
Immediate reporting to National Competent Authorities (NCA) upon awareness of a serious incident.
Verify if the system is classified as High-Risk under Annex III.
Identify potential breaches involving Personally Identifiable Information.
Ensure immutable logs are maintained for forensic analysis.
Establish a direct communication channel with the relevant NCA.
Trigger internal review boards immediately following an incident.
Initiate an RCA within the stipulated timeframe.
Deploy temporary or permanent fixes to halt ongoing harm.
If affecting multiple member states, coordinate with the AI Office.
Inform affected individuals transparently and promptly.
Feed incident data back into continuous risk management systems.
Maintain detailed dossiers of the incident and response for 10 years.