The AI governance board ensures escalation pathways for employees to report AI incidents and concerns, decides whether a reported event is an AI incident (consulting NSW GovAI if unsure) and reports AI incidents to the Accountable Official, who notifies NSW GovAI for referral to the AI Review Committee for post-incident review. Cyber security incidents involving AI follow agency procedures and are reported to Cyber Security NSW under the NSW Cyber Security Policy; data breaches caused by or arising from AI follow the NSW Mandatory Notification of Data Breach Scheme (notifying the Privacy Commissioner and affected individuals for eligible breaches), and the Senior Responsible Officer for records management reports damaged, lost or destroyed records to State Records NSW.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.