AIG-038 AI Feedback and Adverse Impact Reporting Channel
Description
A published channel lets users of an AI system, persons affected by its outputs and other interested parties report an adverse impact or give feedback, without an account or a support contract. The location of the channel, the information a reporter is asked for and the acknowledgement a reporter receives are documented. Each report is logged with a receipt date, triaged against defined severity criteria and adjudicated to a recorded outcome: no action with a stated reason, a change to the system or its documentation, an entry in the risk record, or escalation to the incident process. A report contesting an output or a decision is routed to the human oversight process and the routing is recorded. At defined intervals a review reads the adjudicated reports as a set and records what they changed in system design, in the risk assessment or in monitoring.
Rationale
AIG-021 governs an AI incident once it is known and HRS-009 is the internal reporting route for personnel. AIG-038 is the outward route, so that the people an AI system affects can tell the organisation something is wrong and see what happened to the report. AIG-031 detects the misuse the organisation can see from its own telemetry; AIG-038 catches what telemetry cannot, which is a harm experienced by a person the organisation has no signal for. Contest and appeal requests are decided by the oversight process in AIG-022, so the duty here is to route them and record the routing rather than to decide them. At a small scale a public address, a ticket queue and a documented triage rota satisfy the control: the test is the adjudication trail, not the technology. Both seats (ADR-031): a provider runs the channel for the system it builds, a deployer for the decisions it takes with a system someone else built.
Applicability (9 profiles)
The channel for the people the deployer's use affects is the deployer's. The provider's channel serves its own users.
The channel the Art.27 seat points at. Point (f) of the assessment asks for the measures to be taken if a risk materialises, including the internal governance arrangements and the complaint mechanisms. This control is the artefact that answers it. A report contesting an output routes to the oversight process under AIG-022 and to the Art.86(1) explanation route under AIG-016. The public body's statutory complaint, review and appeal routes run alongside and are not restated here.
Framework Mappings (30)
| GRC-15 | Human supervision | informative |
| EU-AI-Art.86 | Deployer Obligations — Right to Explanation of Individual Decision-Making | partial |
| COP-C-1.5 | Designate a point of contact and enable the lodging of complaints | informative |
| COP-S-9.1 | Methods for serious incident identification | informative |
| A.8.3 | External reporting | full |
| GV-1.3-004 | Risk Management Activity Level Determination | GV-1.3-004 | informative |
| GV-3.2-004 | Human-AI Configuration Roles | GV-3.2-004 | full |
| GV-4.3-003 | AI Testing and Information Sharing Practices | GV-4.3-003 | full |
| GV-5.1-001 | External Stakeholder Feedback Integration | GV-5.1-001 | partial |
| MG-2.2-006 | Deployed AI System Value Maintenance | MG-2.2-006 | full |
| MG-2.2-008 | Deployed AI System Value Maintenance | MG-2.2-008 | partial |
| MG-3.2-004 | Pre-Trained Model Monitoring | MG-3.2-004 | full |
| MG-4.1-003 | Post-Deployment AI System Monitoring | MG-4.1-003 | partial |
| MG-4.2-001 | Continual Improvement Integration | MG-4.2-001 | informative |
| MG-4.3-002 | Incident and Error Communication | MG-4.3-002 | informative |
| MP-4.1-002 | AI Technology and Legal Risk Mapping | MP-4.1-002 | informative |
| MP-5.1-004 | Impact Likelihood and Magnitude Documentation | MP-5.1-004 | partial |
| MS-1.1-004 | AI Risk Measurement Approach Selection | MS-1.1-004 | partial |
| MS-1.1-006 | AI Risk Measurement Approach Selection | MS-1.1-006 | informative |
| MS-1.3-001 | Independent AI Risk Assessment | MS-1.3-001 | informative |
| MS-2.10-002 | AI Privacy Risk Examination | MS-2.10-002 | partial |
| MS-2.7-003 | AI System Security and Resilience Evaluation | MS-2.7-003 | partial |
| MS-3.3-005 | User and Community Feedback Processes | MS-3.3-005 | partial |
| MS-4.2-005 | Trustworthiness Measurement with Expert Input | MS-4.2-005 | partial |
| GOVERN 5.1 | External Stakeholder Feedback Integration | full |
| GOVERN 5.2 | Adjudicated Feedback Incorporation | full |
| MANAGE 4.2 | Continual Improvement Integration | partial |
| MAP 5.2 | External Impact Feedback Practices | full |
| MEASURE 3.3 | User and Community Feedback Processes | full |
| ASI09 | Human-Agent Trust Exploitation | informative |
Evidence (3)
Live submission of a test report through the published channel, observing what a reporter is asked for, what acknowledgement is returned and what record the submission creates.
Example: Channel walkthrough of 14 April 2026, submitting a test adverse-impact report from an unauthenticated browser session.
Test: Verify: (1) the channel is reachable without an account and without an existing support contract, (2) the fields a reporter is asked for match the documented set, (3) an acknowledgement is returned inside the period the documentation states, (4) the submission appears in the report register with a receipt date.
Export of the report register covering a defined period, with receipt date, assigned severity, adjudicated outcome, closure date and, where the report contested an output, the oversight case it was routed to.
Example: Ticket system export ai-feedback-2026-Q1.csv, covering 1 January to 31 March 2026.
Test: Verify: (1) every report carries a receipt date and an assigned severity drawn from the documented criteria, (2) no report is open beyond the period the triage procedure allows without a recorded reason, (3) every closed report carries one of the outcomes the control names, with a no-action outcome carrying a stated reason, (4) every report that contested an output resolves to an oversight case identifier.
Periodic review that reads the adjudicated reports as a set and records what they changed in system design, in the risk assessment or in monitoring.
Example: AI feedback review, first half 2026, with the four resulting change references listed at section 3.
Test: Verify: (1) a review exists for the most recent interval, (2) it looks across the set rather than repeating individual adjudications, (3) each change it claims resolves to a design change reference, a risk record entry or a monitoring change, (4) where the review concluded that no change was needed, it says on what basis.
Questions (3)
Is there a published channel through which someone outside your organisation can report an adverse impact of an AI system?
A general support queue counts only where it is published as a route for adverse-impact reports and reaches people who are not customers. An internal reporting route for staff is HRS-009 and does not answer this question.
Which of the following apply to reports received through the channel?
Options follow the path a report takes from receipt to review. Tick the adjudication item only where the outcome is recorded against the report; closing a ticket without an outcome does not count.
Who adjudicates reports received through the channel?
Options run from the most independent to the least. Answer for the reports actually received in the last twelve months; where none were received, answer for the route the procedure assigns.