Decision, waiver, incident, and review
These four objects have different statuses; merging them erases who decided, what deviated, and what still needs correction.
Objectives
- Classify a decision, exception, and incident.
- Define a review with evidence and open actions.
- Duration
- 11 min
- Level
- Intermediate
Prerequisites
- Policy, roles, and responsibilities
Concepts
Concepts
Documented decision
A dated, attributed, and bounded outcome of an authorised process, retaining its evidence, open questions, and limitations.
Waiver and emergency stop
A waiver is explicitly approved, bounded, and tracked; an emergency stop suspends the action without retroactively creating a waiver.
Incident, reconciliation, and review
Reconciliation compares expected and observed states; the post-incident review separates facts, unknowns, decisions, actions, and follow-up.
DAGR candidate concept
In the Learning Hub, DAGR is only an advanced-research candidate concept. No public specification or public implementation is referenced here, and no operational capability is claimed.
Visual guide
Retaining statuses
- Classify the decision, waiver, or incident.
- Trigger the emergency stop when needed.
- Reconcile expected and observed states.
- Retain evidence, open questions, and limitations.
- Plan the post-incident review and follow-up.
Synthetic example
Synthetic example
An action deviates from policy without approval. It must be treated as an incident or deviation, not retrospectively renamed an exception.
A status must not be rewritten to hide a deviation.
Lesson scope
This lesson proposes a record structure for keeping decisions, exceptions, incidents, and reviews distinct.
What this lesson does not demonstrate
It classifies no real event and replaces no legal, regulatory, or contractual obligation.
Check question
Which characteristic distinguishes a governed exception?
Choose an answer to read its feedback.
Local checklist
Synthetic register
Classify a fictional event without erasing unknowns.
This activity is neither an incident report nor an official decision.
Sources and limitations
Sources and limitations
- Source repository
- https://github.com/SwissTokint/swisstokint-website
- Source reference
- codex/learning-hub-v3-autonomous-controls
- Content commit
- 29c88f79cee07a72804bc017b92fab9200fd3734
- Source version
- learning-v3
- Artificial Intelligence Risk Management Framework (AI RMF 1.0)
NIST-AIRMF-1.0- Publisher
- National Institute of Standards and Technology (NIST)
- Version or date
- AI RMF 1.0, 2023-01-26
- Link verified on
- 2026-08-13
- Scope used
- Governance, measurement, and continuous risk management.
- Limitation
- The framework prescribes no single procedure.
- Artificial Intelligence Risk Management Framework: Generative AI Profile
NIST-AI-600-1- Publisher
- National Institute of Standards and Technology (NIST)
- Version or date
- 2024-07-26
- Link verified on
- 2026-08-13
- Scope used
- Candidate actions and risks specific to generative uses.
- Limitation
- The profile classifies no real incident.