SenangAI: your data, your infrastructure, your control
Home · Blog · Governance
Governance · 18 August 2026 · 7 min read

ISO 42001 and Article 73: incident timelines that cannot wait.

ISO/IEC 42001 asks you to write the communication plan before the incident. EU AI Act Article 73 then starts a 2, 10 or 15 day clock. If you have to reconstruct what the system did, you have already missed it.

GovernanceEvaluation
Official forms, a calculator and a coffee cup on a desk, standing in for records that have to exist before a report is due
Photo by Kelly Sikkema on Unsplash.

Two instruments, two jobs

ISO/IEC 42001:2023 is an AI management system. It asks an organisation to decide how it will run AI on purpose: roles, impact assessment, life cycle, and how it talks to the people affected when something goes wrong. Annex A control A.8.4 is the incident communication plan: determine and document how incidents will be communicated to users of the AI system.

The EU AI Act is a law. Article 73 is not a plan. It is a clock. Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred. TCSA maps Article 73 to A.8.4. That mapping is useful. It is not equivalence. A documented plan does not file the report.

This is not legal advice. Confirm classification and dates with counsel. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moves Annex III high-risk duties, which include Article 73, to 2 December 2027, and Annex I embedded high-risk duties to 2 August 2028. ComplyDrive is clear on the part that did not move: the 2, 10 and 15 day outer limits in Article 73 itself.

The Article 73 clocks

The European Commission’s AI Act Service Desk publishes the operative text. The default is Article 73(2): report immediately after a causal link is established, or the reasonable likelihood of such a link, and in any event not later than 15 days after the provider or, where applicable, the deployer becomes aware of the serious incident. Awareness starts the clock, not the date the harm occurred.

Two shorter ceilings sit on top of that default:

  • Two days for a widespread infringement, or a serious incident as defined in Article 3, point (49)(b), which covers serious and irreversible disruption of critical infrastructure.
  • Ten days where a person has died, once a causal relationship is established or suspected.

ComplyDrive’s reading is the one risk teams should test against: these are ceilings. Establishing causation on day three and filing on day fourteen is not the “immediately after” duty. Article 73(5) allows an incomplete initial report, then a complete one. Article 73(6) then requires investigation, a risk assessment, and corrective action, without altering the system in a way that affects later evaluation of the causes, before informing the competent authorities of that change.

QueryNow’s governance stack puts the practical test in one drill: reconstruct one automated decision end to end from logs alone, and time it. If the answer exceeds two days, the audit layer does not exist yet. That is the two-day ceiling, not the fifteen-day backstop.

What ISO 42001 actually requires

ISO 42001 does not write the 2, 10 and 15 day numbers. Watchdog Security reads A.8.4 as a plan: what counts as an incident, who is told, how soon, through which channel, and which authorities. The plan has to cover AI-specific failures, not only a generic security playbook.

That is why a certificate on the wall is not the same as a fileable record. If the communication plan assumes someone will later pull chat logs from a vendor dashboard, Article 73(6) is already in trouble. The record has to sit where the organisation can export it. See Understand and Govern and Govern on the platform.

Prove the reconstruction exists

A serious-incident file needs more than a prompt and an answer. It needs who asked, which sources were retrieved, which were denied, which model ran, what it cost, who approved an action, and whether a person halted it. Agents that can act make that last item non-optional. Read skills and human approval.

Ask a vendor to produce that file for a denied request and for an approved action, without a reconstruction project. If they cannot, the Article 73 clock is theoretical. The buyer questions in the sovereign AI guide are written for that meeting. For how deletion and data placement are designed, see security and trust controls.

When you want us in the room, book a demo and ask to see a denied request and the exportable event it produced. That is the rehearsal. The two-day clock is not.

Sources and references

  1. ISO/IEC 42001:2023, Artificial intelligence management system. International Organization for Standardization.
  2. Article 73: Reporting of serious incidents. European Commission AI Act Service Desk.
  3. Regulation (EU) 2026/1744. Digital Omnibus on AI. Official Journal of the European Union.
  4. Article 73. Artificial Intelligence Act (Regulation (EU) 2024/1689) unofficial consolidation.
  5. When AI Incident Reporting Obligations Actually Start. ComplyDrive.
  6. EU AI Act Article 73: tiered serious-incident reporting. ISO 42001 Toolkit.
  7. ISO 42001 and the EU AI Act: Control-by-Control Mapping. TCSA.
  8. ISO 42001 A.8.4: AI Incident Communication Plan Requirements. Watchdog Security.
  9. The six-layer AI governance stack. QueryNow.