Escalation Protocols for AI-Related Concerns
Introduction
To establish clear, systematic protocols for escalating concerns about AI adequacy, appropriateness, or results, ensuring that issues are addressed promptly and at the appropriate organizational level.
At the Independent Application level, you are expected to apply AI tools and techniques without direct supervision in routine scenarios. You should be able to independently assess AI output quality, identify when outputs require additional review, and produce work products that meet professional standards with AI assistance.
This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.
Core Concepts
Practical Use Cases
Use Case 1: Escalating Insufficient Validation
Situation: You are using AI to test authorization controls. Pre-test validation identified that AI is flagging false positives at 15% rate (testing 20 exceptions, only 17 are genuine control failures; 3 are false positives due to system timing lags).
Escalation Process:
- Identify concern: AI validation accuracy is insufficient. 15% false positive rate means conclusions about control effectiveness cannot be reliably reached.
- Escalation trigger: Yes. This meets trigger #1 (AI output doesn't pass validation).
- Appropriate recipient: Audit manager (supervisor of the control testing work).
- Communication:
- - "During pre-test validation of AI testing logic, I identified a 15% false positive rate. Specifically, of 20 sample transactions reviewed, AI flagged 3 as control violations when they were actually timing-related system lags, not control deficiencies. At this false positive rate, I cannot reliably conclude that the control is effective based on AI results. I recommend [alternative approach]."
- Propose resolution:
- - Option A: Refine AI logic to exclude timing-lag transactions, then re-run testing
- - Option B: Conduct manual testing of sample and use results to extrapolate (reduces AI reliance)
- - Option C: Use AI for initial flagging but perform 100% review of flagged exceptions to confirm
- - Option D: Escalate to audit leadership if this testing is critical to the audit scope
- Follow up:
- - Manager directs: "Use Option C -- AI flags, but audit team reviews all flagged exceptions."
- - Audit proceeds with refined approach
- - Document decision: "Due to false positive concerns identified during validation, control testing combined AI identification with 100% manual review of flagged exceptions to confirm control deficiency vs. data/timing issues."
- Learning:
- - For future AI testing, establish higher pre-test validation standard to catch false positive rates before relying on full population analysis
- - Consider whether external AI tool needs additional configuration or whether the specific control area (with its timing lags) is poorly suited to automated testing
Use Case 2: Escalating Data Confidentiality Concern
Situation: You are asked to use an external AI tool to analyze customer data. You are unsure whether this is authorized.
Escalation Process:
- Identify concern: Uncertainty about whether the external AI tool is authorized for processing customer data with identifiers.
- Escalation trigger: Yes. Escalation trigger #5 (organizational policy unclear).
- Appropriate recipient: Compliance or privacy function (who oversees data protection policies).
- Communication:
- - "I am being asked to use [external AI tool] to analyze customer transaction data (including customer identifiers) to identify control exceptions. Before proceeding, I want to confirm that this tool is authorized under our data protection policies. Can you advise whether [tool] is approved for this data type? If not, should I mask customer identifiers before providing to the tool?"
- Receive guidance:
- - Compliance: "Tool is not approved for unmasked customer data. Option A: Mask customer identifiers. Option B: Use internal tools instead."
- - Audit team proceeds with Option B (internal tools)
- - Document: "Used internal tools instead of external tool due to data protection policy requirements for customer data."
- Follow up:
- - Compliance confirms: "Correct approach. Internal tools are available for this work."
- - No further escalation needed
- Learning:
- - Establish checklist for data protection review before using external AI tools
- - Document which AI tools are approved for which data types
- - Include data protection review as standard part of AI methodology decisions
Use Case 3: Escalating Bias/Fairness Concern
Situation: AI-based testing is identifying exceptions disproportionately in certain departments. You are concerned whether this represents real control risk or AI bias.
Escalation Process:
- Identify concern: AI exceptions are concentrated in [Department X/Y] at higher rates than other departments. Unclear whether this represents real control risk or whether AI is biased toward flagging that population.
- Escalation trigger: Yes. Escalation trigger #7 (bias or fairness concerns).
- Appropriate recipient: Audit leadership and/or ethics/compliance function (depending on organizational structure).
- Communication:
- - "During control testing, AI identified exceptions concentrated in [Department X/Y]: [X]% of exceptions vs. [Y]% of transactions in that department. I am concerned whether this represents real control deficiency or potential AI bias. I recommend [independent review / supplemental analysis] before escalating these as findings."
- Receive guidance:
- - Audit leadership directs: "Perform supplemental manual testing of [Department X/Y] to validate whether exceptions are real control issues or data/AI artifacts."
- - Results confirm: [Exceptions are genuine / Exceptions are false positives due to data characteristics]
- - Proceed accordingly
- Follow up:
- - If exceptions are genuine: Explain why Department X/Y has higher exception rates (control design differences, staffing composition, volume differences)
- - If exceptions are false positives: Adjust AI logic and note limitation for future use
- - Document the escalation, supplemental testing, and conclusion
- Learning:
- - Establish protocol for assessing whether AI-flagged patterns correlate with protected characteristics
- - When they do, perform supplemental analysis before escalating as findings
- - Review AI tool for potential bias in pattern recognition
Anti-patterns / Misuse Risks
Anti-pattern 1: Over-Escalating Risk: You escalate every concern about AI, creating escalation workload and training people to ignore your escalations.
Why it fails: - Not all concerns warrant escalation - You develop reputation as someone who cannot use AI independently - Escalation loses credibility when overused - People stop taking your escalations seriously
Better approach: Escalate material concerns that you cannot resolve independently. Resolve minor issues through normal discussion.
Anti-pattern 2: Under-Escalating Risk: You have a material concern about AI but do not escalate because you are uncomfortable questioning the work or you want to avoid additional work.
Why it fails: - Material issues go unaddressed - Conclusions may be based on inadequate validation - Organizational risk is not properly managed - You are personally at risk if issues are later discovered
Better approach: Escalate material concerns regardless of discomfort. This is your professional responsibility.
Anti-pattern 3: Escalating Without Clear Information Risk: You escalate a concern but do not clearly explain what the issue is, what evidence supports it, or what resolution would address it.
Why it fails: - Recipient doesn't understand the concern - Response may not address the real issue - Escalation is inefficient and may be dismissed - Follow-up is difficult
Better approach: Clearly articulate the concern, provide supporting evidence, and propose solutions.
[Practical Tip]
As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.
Human Judgment Checkpoints
Checkpoint 1: Concern Clarity Before escalating: - Can I articulate the concern clearly in 2-3 sentences? - What specific evidence supports the concern? - What would resolve the concern?
Checkpoint 2: Escalation Appropriateness Ask yourself: - Is this a material concern that warrants escalation? - Or is this a minor issue I should resolve myself? - What is the threshold for my escalation?
Checkpoint 3: Recipient Appropriateness Confirm: - Who is the right person to receive this escalation? - Does the issue fall within their responsibility/expertise? - Would a different recipient be more appropriate?
Checkpoint 4: Timing Assess: - Is this time-sensitive? - Should I escalate immediately or is it okay to wait for next review meeting? - What is the deadline for resolution?
Traceability / Defensibility Considerations
Document Escalations: For governance and audit trail purposes: - Document the concern you escalated - Document who you escalated to and when - Document the guidance or decision received - Document how the concern was addressed - Document the outcome
Example documentation: "Escalated concern [specific issue] to [person] on [date] due to [reason]. Guidance received: [direction]. Outcome: [how it was resolved]."
Maintain Escalation Log: As an organization, maintain a log of escalations to: - Track patterns in AI-related concerns - Identify systemic issues that need policy updates - Monitor whether escalations are being resolved appropriately - Use for continuous improvement in AI governance
[Practical Tip]
As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.
Responsible AI and Control Considerations
Organizational Learning: Escalations are opportunities for organizational learning: - Each escalation reveals something about AI tool limitations, gaps in policy, or training needs - Track escalations to identify patterns - Use patterns to improve governance, tools, or training - Communicate learnings across the organization
Accountability: Escalations should be treated seriously: - Ensure that escalated concerns are addressed, not dismissed - Provide timely feedback to the person who escalated - Document the resolution - Hold people accountable for following up on escalations
Practice / Reflection Prompts
- Escalation Triggers: Identify the escalation triggers in your organization. When would you escalate?
- Escalation Paths: Map out escalation paths for different types of concerns. Who would you escalate to for [data confidentiality / methodology / findings] concerns?
- Communication Practice: Draft an escalation communication for a concern you anticipate. Is it clear? Does it provide evidence and propose solutions?
- Documentation: Design an escalation log for your organization. What information would you track?
- Organizational Culture: How can you foster a culture where escalating concerns is seen as professional responsibility, not failure?
[Practical Tip]
As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.
Glossary / Terms
- Escalation: Referring a concern or decision to a higher authority or more appropriate resource for resolution.
- Escalation trigger: Specific condition or circumstance that indicates a concern should be escalated.
- Escalation path: Defined organizational chain or process for escalating specific types of concerns.
Related Lessons
- Lesson 1: Recognizing When AI Assistance Is Insufficient or Inappropriate (identifying when to escalate)
- Lesson 3: Human Override: Maintaining Control Over AI-Assisted Processes (maintaining human control after escalation)
- Chapter 3, Lesson 3: Peer Review and Quality Assurance for AI-Assisted Work Products (collaborative oversight)
- Chapter 4, Lesson 1: What Makes an AI-Assisted Work Product Defensible (standards for AI-assisted work)
Detailed Examples
The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.
Example 1: Effective Escalation Communication
POOR ESCALATION: "I am not confident in the AI testing results. Something seems off. Can someone review?" - Vague description of concern - No specific issue identified - No proposed solution - Unclear what is expected
STRONG ESCALATION: "During pre-test validation of AI control testing, I identified [specific concern]. Testing [sample size] showed [specific result]. This indicates [implication]. I recommend [proposed approach] to address the concern. If you agree, I will proceed with [next steps]. If not, I need guidance on [specific decision]." - Clear, specific concern identified - Evidence provided - Implication explained - Proposed solutions offered - Clear request for guidance
Example 2: When NOT to Escalate
Escalation is appropriate for material concerns, but do NOT escalate every minor issue: - Minor false positives (1-2 in sample of 100) do not necessarily require escalation; address through minor methodology adjustment - Isolated questions about AI appropriateness (I am unsure about one aspect) do not require escalation; can be resolved through discussion with supervisor - Uncertainties that can be resolved through minor clarification do not require escalation; clarify with the responsible party
Escalate when: - The concern would materially impact the audit conclusion - The concern cannot be resolved through normal discussion - The concern involves policy compliance or appropriateness - You are genuinely uncertain about the right approach
Putting It Into Practice
Independent application requires a disciplined approach to integrating these concepts into your workflow:
- Establish personal standards: Define your own quality criteria for AI-assisted work products. What level of verification satisfies you professionally? Document these standards and apply them consistently.
- Build verification routines: Create repeatable processes for checking AI outputs against source materials, professional standards, and organizational requirements.
- Exercise professional judgment: Identify situations where AI assistance is appropriate and where human judgment must prevail. This discernment is the hallmark of Level 3 competence.
- Contribute to organizational learning: Share your experiences -- both successes and challenges -- with your team. Your practical insights help improve AI governance for everyone.
Key Takeaways
- Escalate systematically when:
- - AI output doesn't validate
- - AI is assigned to inappropriate task
- - Data confidentiality is uncertain
- - Results are unexplainable
- - Material conclusions depend on AI output
- - Bias or fairness concerns emerge
- Escalate clearly: Articulate concern, provide evidence, propose solutions.
- Escalate to the right person: Identify who is accountable for addressing the concern.
- Escalate in time: Address material concerns promptly; don't delay in hopes of resolving independently.
- Follow up: Ensure escalated concerns are resolved and document the resolution.
As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.
Skill.re