Risk Register
Last updated: 16 June 2026
Provider: Resourcehip Ltd (SC873386, Scotland)
System: HIP Score (Human Impact Profile Scoring System)
Next Review: 16 December 2026
Risk classification
The HIP Score is not a high-risk AI system under the EU AI Act (Regulation 2024/1689). High-risk classification under Article 6(2) applies to systems listed in Annex III; a consumer product sustainability rating is not in that list.
This risk register is maintained voluntarily as good practice. We apply these safeguards because they make the system more trustworthy, not because a regulator requires them at our risk level.
Systemic Risks Identified
| Risk | Severity | Likelihood | Potential Harm | Mitigation | Monitoring |
|---|---|---|---|---|---|
| Category Bias: Model systematically under/over-scores a product category due to training data gaps | HIGH | LOW | Discriminatory impact on manufacturers in underrepresented sectors; false sustainability claims | Conservative category defaults (bias toward lower scores); quarterly bias audit; explicit rubrics (not pure neural) | Monthly re-test of 5 reference products, one from each major category; flag any score change >0.5 points |
| Data Quality / Hallucination: Model produces scores outside 0-10 range or contradicts input data on out-of-distribution products | MEDIUM | MEDIUM | Nonsensical ratings; erosion of user trust | Rubric-based scoring (explicit criteria, not pure black-box); manual human review before publication; conservative defaults | Monthly reference product scoring; escalation if score violates rubric or data logic |
| Model Drift: Score changes unexpectedly if model version updates without re-validation | MEDIUM | MEDIUM | Sudden unexpected changes in existing ratings; user confusion; claims of unfairness | Version-pinned model (specific SHA256 hash); notification and re-validation required before any update | Monthly version audit; production alerts if model version changes without authorisation |
| Appeal Backlog: User appeal not resolved within SLA; complaint escalates publicly | MEDIUM | LOW | Reputational harm; regulator attention | Published appeal SOP; 30-day response SLA; escalation to CEO if resolution blocked | Weekly appeal queue review; monthly SLA compliance report |
| Incomplete Input Data: Manufacturer submits product with missing sustainability data; model must gracefully degrade | LOW | HIGH | Conservative defaults mask missing data; manufacturer may dispute score as unfair | Documented fallback strategy per dimension; human reviewer notes which data was missing; scorecard flags partial data | Per-rating human checklist: confirm data sources logged |
Mitigations in Place
Technical (Pipeline Design)
- Local-only deployment
- No product data sent to external cloud AI services
- Local Ollama deployment on Resourcehip-controlled hardware
-
Reduces regulatory scrutiny on data transfer
-
Explicit scoring rubrics
- Seven dimensions use written criteria (not pure neural black-box)
- Scores auditable against stated criteria
-
Examples: SEI rubric includes material durability, repairability, and certifications; Carbon rubric uses LCA peer-reviewed data and manufacturer disclosures
-
Version pinning
- Model locked to specific version with SHA256 hash stored in pipeline configuration
-
No automatic updates; update requires re-testing and human sign-off
-
Manual human review
- Every rating reviewed before publication
- Reviewer confirms data sources, flags anomalies, re-scores if rubric mismatch detected
- Non-automation rule: scores published only after human approval
Data Quality (Input Standards)
- Conservative category defaults
- Where manufacturer data unavailable, default to lower (more conservative) score
- Bias is transparent and intentional (honest uncertainty, not harmful)
-
Bias audit quarterly to confirm less than 20% variance from category distribution
-
Peer-reviewed source data
- Input sourced from public datasets: USGS, EPA, peer-reviewed lifecycle assessments (LCA), official regulatory filings
- Traceability: each rating links to its source data
-
Reduces hallucination risk: model is anchored to real data
-
Manufacturer data validation
- Submitted claims require evidence (e.g., "certified recyclable" requires certification URL or document)
- Conservative defaults if evidence missing
- Prevents adversarial injection (e.g., false sustainability claims)
Governance and Accountability
- Public transparency
- Methodology page: explicit disclosure of AI model and scoring approach
- No claims to editorial independence; positioned as "evidence-based AI-scored"
-
Users can discover AI involvement and assess trustworthiness
-
Appeal procedure
- Published Appeal Procedure
- 30-day human response SLA
- Escalation path to CEO if resolution blocked
- Right to request re-review with new data
Monitoring and Remediation Plan
Monthly (Operational)
- Reference Product Test: Re-score 5 reference products (one from each major category: furniture, textiles, packaging, electronics, appliances)
- Target: Each score stable within plus or minus 0.5 points month-on-month
- Failure path: Pause new ratings; investigate model/data drift; escalate to CTO
- Evidence stored in internal monitoring log (available on regulator request)
Quarterly (Audit)
- Bias Audit: Score distribution by category
- Calculate mean score and standard deviation per category
- Flag any category with mean more than 20% outside global mean or flagged variance increase
- Review 5 lowest-scoring products in flagged category to confirm scores are justified (not hallucination)
-
Evidence stored in internal monitoring log (available on regulator request)
-
Hallucination Detection: Audit 10 random published ratings
- Confirm score logic matches rubric and input data (no contradictions)
- Confirm score in valid range (0-10)
- Failure: Escalate to human reviewer; may require retraction and re-score
Incident Response
- If bias audit flags category: Pause new ratings in that category; CTO investigates training data; human review of all recent ratings in category; notify affected manufacturers
- If score goes out of range or contradicts data: Retract score; publish notice explaining nature of error; offer re-review
- If appeal backlog exceeds 2 weeks: Escalate to CEO; divert resources to appeal resolution; pause new ratings if needed to clear backlog
Performance Testing (Pre-Launch)
Bias Testing
- Test 10 reference products (2 from each major category)
- Vary product metadata: gender-coded names, nationality-coded manufacturers
- Pass criteria: Score variance less than 0.5 points across variants; no systematic bias detected
Robustness Testing
- Remove 30% of input fields (simulate incomplete data)
- Test edge cases: luxury goods, second-hand products, non-Western manufacturers, low-cost alternatives
- Pass criteria: Model gracefully degrades to conservative default; no out-of-range scores; no nonsensical output
Performance Baseline
- Score 20 representative products from each major category
- Measure: Score distribution, inference time, consistency with rubric
- Pass criteria: Mean score within expected range; all scores justified via rubric
Out-of-Domain Testing
- Attempt to score products outside intended scope (e.g., software, services, financial products)
- Pass criteria: Model gracefully rejects or returns "out of scope"; no hallucinated scores cross domains
For full pre-launch test results, see the Pre-Launch Baseline Audit.
Current Compliance Status
| Requirement | Status | Evidence | Next Step |
|---|---|---|---|
| Risk Register Published | ✅ Complete | This document; Responsible AI & Governance page | Ongoing disclosure |
| Systemic Risk Assessment | ✅ Complete | Risk table above; mitigations detailed | Quarterly monitoring; first audit due Sep 2026 |
| Performance Testing | ✅ Complete | Pre-Launch Baseline Audit | Annual re-testing scheduled |
| Dispute and Appeal Procedures | ✅ Complete | Dispute a Rating; Appeal Procedure | Ongoing |
| Human Oversight | ✅ Complete | Pipeline: manual review before publish | Ongoing; audit monthly |
| Data Quality Standards | ✅ Complete | Conservative defaults; peer-reviewed sources | Ongoing; bias audit quarterly |
| Transparency / User Info | ✅ Complete | Methodology page; AI disclosure | Ongoing |
Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Risk Assessor | Internal risk assessment, CEO approved |
| Technical Owner | CTO — performance testing, model versioning, monitoring infrastructure, incident investigation |
| Data Owner | CTO — data quality audit, source validation, bias detection thresholds |
| Approver | Chris Bowness (CEO) — sign-off on risk classification, approval of monitoring plan |
| Appeal Handler | Support team and CEO — response to user appeals within 30-day SLA |
| Reviewer | Every rating before publication — catch anomalies, confirm rubric match |
Sign-Off
Approved By: Chris Bowness, CEO
Classification Date: 16 June 2026
Next Review Date: 16 December 2026
Status: Approved and in force. Monitoring plan effective immediately.
Appendices
Appendix A: Reference Product Monitoring Template
Use this template monthly for reference product re-tests.
## Monthly Reference Product Test
Test Date:
Tester:
Result: PASS / FAIL
| Product | Category | Previous Score | Current Score | Change | Rubric Match | Data Sources Match | Notes |
|---------|----------|-----------------|--------------|--------|--------------|-------------------|-------|
| [Name] | [Cat] | [x.x] | [x.x] | [+/-] | Yes/No | Yes/No | [Any anomalies?] |
Findings: [Pass/Fail; any trends or anomalies?]
Action: [If fail: CTO investigation required by [date]]
Appendix B: Quarterly Bias Audit Template
## Bias Audit
| Category | N Ratings | Mean Score | Std Dev | vs Global Mean | Variance Trend | Action |
|----------|-----------|------------|---------|----------------|----------------|--------|
| [Cat] | [N] | [x.x] | [x.xx] | [+/-x%] | [up/down/stable] | [Review/OK] |
Global Mean: [x.x]
Outlier Threshold: >20% variance
Findings: [Any flagged categories?]
Action: [If flagged: review lowest 5 scores in category; CTO investigate; notify manufacturers if systematic bias confirmed]
Appendix C: Regulatory References
- EU Regulation 2024/1689 (EU AI Act)
- Relevant articles (for reference — these safeguards are applied voluntarily):
- Article 4: AI literacy
- Article 6: Risk classification
- Article 16: Provider obligations
- Article 50: Transparency obligations
- Article 85: Complaints to market surveillance authorities
Questions about this register? Email hello@resourcehip.com. To dispute a score, see Dispute a Rating. For our governance disclosure, see Responsible AI & Governance.