Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create new AI issue form

Use the Create New Issue form to identify and manage issues related to the impacted areas for the reported AI case.

See the following table for a description of the field values.

FieldDescription
NumberNumber of the issue. This field is automatically set to a request number.
NameName of the issue. For example, `Cyber Attack on Acme`.
Issue sourceSource from where the issue was created. This field is automatically set to AI case.
Issue typeType of the issue. The options are as follows:- Control design effectiveness failure: The control was poorly designed and cannot effectively prevent or detect the intended risk. - Control operative effectiveness failure: The control was well-designed but failed during execution or wasn't followed correctly. - Control doesn’t meet requirement: The control is in place but doesn't satisfy regulatory, policy, or business requirements. - Control doesn’t exist: There is no control present to address a known risk or requirement. - Non-compliance to a regulation: A law or regulation was not followed, potentially exposing the organization to penalties. - Non-compliance to a policy: An internal policy was not adhered to, which could lead to risks or inefficiencies. - Improvement or suggestion to an existing policy: A recommendation to enhance an existing policy for better clarity, coverage, or effectiveness. - Recommendation for a new policy: A proposal to create a new policy to address a gap or need that currently isn’t covered. - Process optimization or improvement: Opportunities identified to improve efficiency, accuracy, or effectiveness of a business process. - Observation: A general note or finding that may not be an issue now but could warrant attention. - Data breach: Unauthorized access, disclosure, or loss of sensitive or personal data. - Fraud: Intentional deception for personal or organizational gain, such as misappropriation of assets. - Misstatement: Errors or omissions in financial or operational reporting that misrepresent facts. - Training: Gaps or needs identified in knowledge or skills that require attention. - Documentation: Issues related to missing, outdated, or inaccurate documentation. - Risk issue: A broad risk-related concern that may not fall under other specific categories. - Other: Any issue that doesn't fit into the above types but is still worth tracking and resolving.
ClassificationClassification of the issue. The options are as follows:- Compliance - Risk - Audit - Vendor Risk
LocationLocation where the issue occurred. For example, Japan.
State

Workflow state of the issue. This field is automatically set to Review. The options are as follows:- New - Analyze - Respond - Review - Closed Complete - Closed Incomplete

For more information on Issue management workflow and life cycle, see View AI assets by life-cycle stage.

SubstateSubstate of the issue. This field is auto-filled.
PriorityUrgency of the issue. It enables the team to triage requests effectively and respond based on how critical the request is. This field is automatically set to Review. The options are as follows:- Critical - High - Moderate - Low - Planning
Issue ratingRating of the issue. The options are as follows:- Very High - High - Moderate - Low - Very Low
DescriptionDescription about the issue in detail. For example, ACME experienced a cyber attack that resulted in unauthorized access to internal systems.
Assignment
Assignment groupGroup to whom the issue is assigned. For example, Risk Managers.
Assigned toUser to whom the issue is assigned.
Issue manager groupManager group that the issue is assigned to. The options are as follows:- Compliance Managers - IT Risk Managers - Risk Managers
Issue managerManager to whom the issue is assigned.
Watch listPerson who must be informed about the issue.
Schedule
Due dateDate when the issue is due.
Confirmed dateConfirmation date for the issue. This field is auto-filled.
CreatedDate on which the issue is created. This field is automatically set to the current date and time.
ClosedDate on which the issue is closed.
Planned start datePlanned start date for the issue.
Planned end datePlanned end date for the issue.
DurationDuration for the issue in days, hours, minutes, and seconds.
Actual start dateActual start date for the issue.
Actual end dateActual end date for the issue.
Actual durationActual duration for the issue in days, hours, minutes, and seconds.
Issue grouping
Issue group ruleGroup rule for the issue. This field is auto-filled.
Parent issueParent issue that is associated with the issue.
Action plan
RecommendationRecommendation for the issue. For example, `Enhance cybersecurity measures and provide regular security training`.
Action planAction plan for the issue. For example, `Upgrade the firewall to the latest version and implement multi-factor authentication for all administrative accounts`.
Activity
Work notes \(Private\)Notes or information about the issue.
Additional comments \(Customer visible\)Additional information about the issue that you want to share with your customers.
Settings
Functional domainFunctional domain that the issue belongs to. For example, an issue may belong to the AI Risk and Compliance domain.