RB-006 High
Repeat offender — second or subsequent violation
Same user triggers shadow AI detection after a prior warning has been documented. Identified when SOC analyst enriches a new alert and finds a prior case in the AI Governance Risk Register for the same user within 90 days.
Triggers
Immediate response (first hours)
- L1 SOC analyst: Confirm repeat status: query the AI Governance Risk Register for prior cases involving this user. Retrieve prior case ID, date, and outcome.
- L2 SOC analyst: Document the repeat violation with full context: prior warning date, current detection details, time elapsed since prior warning, and whether the same or different AI service is involved.
- L2 SOC analyst: Escalate to the user's direct manager and HR Business Partner simultaneously. Use comms/individual-warning-repeat template. (Within 4 hours of confirmation)
Short-term response (within days)
- HR Business Partner + Direct manager: Initiate formal disciplinary documentation per HR policy. Conduct formal meeting with the employee. Document the meeting outcome and any commitments. (Within 10 business days)
- AI Governance triage: Assess whether access restriction is warranted. Options: enhanced DLP monitoring, conditional-access policy restricting AI domains for the user, or device-level browser policy changes. (Within 5 business days)
- AI Governance triage: If access restriction is applied: document the restriction, set a review date (30 days), and notify the user and manager of the restriction scope and duration.
Long-term response (weeks+)
- AI Governance triage: Review enforcement effectiveness. If repeat offender rate exceeds 10%, escalate to the AI Governance Committee for program-level review of comms clarity, approved-tool availability, and policy enforceability.
- AI Governance Committee: Update policy if patterns indicate systemic issues (e.g., lack of approved alternatives, unclear AUP language, insufficient training). Adjust comms cadence for affected business units.
Decision tree
- Is this the second or a subsequent violation?
- Yes → Follow repeat-offender escalation path.
- No → Route to RB-001 first-occurrence process.
- Was the prior warning issued within the last 90 days?
- Yes → Formal escalation with HR involvement.
- No → Treat as soft repeat; re-issue warning with manager CC.
- Is there evidence of sensitive data involvement in this occurrence?
- Yes → Escalate to RB-002 in parallel with disciplinary process.
- No → Continue with disciplinary process only.
RACI
- Responsible: L2 SOC analyst
- Accountable: AI Governance triage lead
- Consulted: Direct manager, HR Business Partner, Legal (if disciplinary action escalates)
- Informed: AI Governance Committee (aggregate quarterly), CISO (if access restrictions applied)
Metrics to capture
- Time from detection to escalation (target: ≤ 4 hours)
- Time from escalation to formal HR meeting (target: ≤ 10 business days)
- Repeat offender rate across the program (target: < 10% within 90 days)
- Percentage of repeat cases resulting in access restriction
- Third-violation rate after formal warning (target: < 2%)
Comms templates
comms-individual-warning-repeatcomms-manager-talking-points
Framework mappings
- NIST AI RMF: GOVERN-4.1, MANAGE-2.2, MANAGE-4.1
- ISO/IEC 42001: 8.2, 8.4, 10.2
- NIST CSF: RS.AN-1, RS.MI-1