Escalation Rules
Escalation rules ensure that overdue findings and action plans are automatically brought to management attention. AIIA supports configurable escalation chains based on severity, time overdue, and organizational hierarchy.
How Escalation Works
When an action plan's due_date passes and its status remains OPEN, the system triggers an escalation chain:
Default Escalation Tiers
| Tier | Trigger | Action |
|---|---|---|
| Reminder | 1 day overdue | Email notification to action plan owner |
| Level 1 | 7 days overdue | Notify Audit Manager, flag in tracker |
| Level 2 | 14 days overdue | Notify CAE, escalation marker on finding |
| Level 3 | 30 days overdue | Auto-include in executive dashboard and board pack |
Configuration
Escalation rules are configured per organization in Administration → Notifications → Escalation Rules.
Configurable Settings
| Setting | Description | Default |
|---|---|---|
| Reminder Frequency | How often to re-send reminder to owner | Weekly |
| Level 1 Threshold | Days before Manager notification | 7 |
| Level 2 Threshold | Days before CAE notification | 14 |
| Level 3 Threshold | Days before board-level flagging | 30 |
| Email Enabled | Send escalation emails | Yes |
| Dashboard Alert | Show alerts on main dashboard | Yes |
Severity-Based Overrides
Critical and High severity findings can have shorter escalation timelines:
| Severity | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Critical | 3 days | 7 days | 14 days |
| High | 5 days | 10 days | 21 days |
| Medium | 7 days | 14 days | 30 days |
| Low | 14 days | 30 days | 60 days |
Escalation in the Dashboard
Escalated items appear in:
- Main Dashboard — "Escalated Findings" widget showing count by tier
- Remediation Tracker — red highlight on escalated items
- Executive Dashboard — management visibility of overdue remediation
- Board Pack — automatically included when configured
Audit Trail
All escalation events are logged:
- When escalation was triggered
- Who was notified
- What action was taken (if any)
- Whether the escalation was resolved
Permissions
| Action | Permission |
|---|---|
| Configure escalation rules | admin:notifications (Admin) |
| View escalations | finding:read (all audit roles) |
| Acknowledge escalation | Action owner, Manager, CAE |
| Override escalation | admin:override (Admin, CAE) |