Skip to main content

Incident Disclosure

1. Incident Identification

Organisation: {{company_name}}
Incident reference: {{incident_reference}}
Title: {{incident_title}}
Severity: {{incident_severity}}

2. Chronology

Occurred: {{occurred_at}}
Discovered: {{discovered_at}}

The disclosure SHALL distinguish confirmed timestamps from estimates and preserve subsequent corrections in the incident record.

3. Description

{{incident_summary}}

4. Affected Parties and Impact

Known affected parties or categories: {{affected_parties}}

Material unknowns, impact boundaries, and evolving facts SHOULD be identified rather than inferred as settled facts.

5. Notifications

Required internal, regulatory, affected-party, insurer, partner, or public notifications SHALL be determined from applicable jurisdictional and incident-specific rules.

6. Containment and Remediation

{{remediation_summary}}

7. Evidence and Assurance

The disclosure SHALL remain traceable to the incident record, supporting evidence, notification decisions, approvals, and subsequent corrections.

Audit Evidence Reference Bindings

The links below demonstrate document-local evidence requirements. At runtime, ZAYAZ resolves the requirement through the Evidence Registry and the current client/document context; the template does not contain CMIDs or E-C-O Numbers.

  • Primary incident record
  • Incident root-cause analysis
  • Regulatory notifications
GitHub RepoRequest for Change (RFC)