Risk Register

Last updated: 16 June 2026

Provider: Resourcehip Ltd (SC873386, Scotland)
System: HIP Score (Human Impact Profile Scoring System)
Next Review: 16 December 2026


Risk classification

The HIP Score is not a high-risk AI system under the EU AI Act (Regulation 2024/1689). High-risk classification under Article 6(2) applies to systems listed in Annex III; a consumer product sustainability rating is not in that list.

This risk register is maintained voluntarily as good practice. We apply these safeguards because they make the system more trustworthy, not because a regulator requires them at our risk level.


Systemic Risks Identified

Risk Severity Likelihood Potential Harm Mitigation Monitoring
Category Bias: Model systematically under/over-scores a product category due to training data gaps HIGH LOW Discriminatory impact on manufacturers in underrepresented sectors; false sustainability claims Conservative category defaults (bias toward lower scores); quarterly bias audit; explicit rubrics (not pure neural) Monthly re-test of 5 reference products, one from each major category; flag any score change >0.5 points
Data Quality / Hallucination: Model produces scores outside 0-10 range or contradicts input data on out-of-distribution products MEDIUM MEDIUM Nonsensical ratings; erosion of user trust Rubric-based scoring (explicit criteria, not pure black-box); manual human review before publication; conservative defaults Monthly reference product scoring; escalation if score violates rubric or data logic
Model Drift: Score changes unexpectedly if model version updates without re-validation MEDIUM MEDIUM Sudden unexpected changes in existing ratings; user confusion; claims of unfairness Version-pinned model (specific SHA256 hash); notification and re-validation required before any update Monthly version audit; production alerts if model version changes without authorisation
Appeal Backlog: User appeal not resolved within SLA; complaint escalates publicly MEDIUM LOW Reputational harm; regulator attention Published appeal SOP; 30-day response SLA; escalation to CEO if resolution blocked Weekly appeal queue review; monthly SLA compliance report
Incomplete Input Data: Manufacturer submits product with missing sustainability data; model must gracefully degrade LOW HIGH Conservative defaults mask missing data; manufacturer may dispute score as unfair Documented fallback strategy per dimension; human reviewer notes which data was missing; scorecard flags partial data Per-rating human checklist: confirm data sources logged

Mitigations in Place

Technical (Pipeline Design)

  1. Local-only deployment
  2. No product data sent to external cloud AI services
  3. Local Ollama deployment on Resourcehip-controlled hardware
  4. Reduces regulatory scrutiny on data transfer

  5. Explicit scoring rubrics

  6. Seven dimensions use written criteria (not pure neural black-box)
  7. Scores auditable against stated criteria
  8. Examples: SEI rubric includes material durability, repairability, and certifications; Carbon rubric uses LCA peer-reviewed data and manufacturer disclosures

  9. Version pinning

  10. Model locked to specific version with SHA256 hash stored in pipeline configuration
  11. No automatic updates; update requires re-testing and human sign-off

  12. Manual human review

  13. Every rating reviewed before publication
  14. Reviewer confirms data sources, flags anomalies, re-scores if rubric mismatch detected
  15. Non-automation rule: scores published only after human approval

Data Quality (Input Standards)

  1. Conservative category defaults
  2. Where manufacturer data unavailable, default to lower (more conservative) score
  3. Bias is transparent and intentional (honest uncertainty, not harmful)
  4. Bias audit quarterly to confirm less than 20% variance from category distribution

  5. Peer-reviewed source data

  6. Input sourced from public datasets: USGS, EPA, peer-reviewed lifecycle assessments (LCA), official regulatory filings
  7. Traceability: each rating links to its source data
  8. Reduces hallucination risk: model is anchored to real data

  9. Manufacturer data validation

  10. Submitted claims require evidence (e.g., "certified recyclable" requires certification URL or document)
  11. Conservative defaults if evidence missing
  12. Prevents adversarial injection (e.g., false sustainability claims)

Governance and Accountability

  1. Public transparency
  2. Methodology page: explicit disclosure of AI model and scoring approach
  3. No claims to editorial independence; positioned as "evidence-based AI-scored"
  4. Users can discover AI involvement and assess trustworthiness

  5. Appeal procedure

  6. Published Appeal Procedure
  7. 30-day human response SLA
  8. Escalation path to CEO if resolution blocked
  9. Right to request re-review with new data

Monitoring and Remediation Plan

Monthly (Operational)

Quarterly (Audit)

Incident Response


Performance Testing (Pre-Launch)

Bias Testing

Robustness Testing

Performance Baseline

Out-of-Domain Testing

For full pre-launch test results, see the Pre-Launch Baseline Audit.


Current Compliance Status

Requirement Status Evidence Next Step
Risk Register Published ✅ Complete This document; Responsible AI & Governance page Ongoing disclosure
Systemic Risk Assessment ✅ Complete Risk table above; mitigations detailed Quarterly monitoring; first audit due Sep 2026
Performance Testing ✅ Complete Pre-Launch Baseline Audit Annual re-testing scheduled
Dispute and Appeal Procedures ✅ Complete Dispute a Rating; Appeal Procedure Ongoing
Human Oversight ✅ Complete Pipeline: manual review before publish Ongoing; audit monthly
Data Quality Standards ✅ Complete Conservative defaults; peer-reviewed sources Ongoing; bias audit quarterly
Transparency / User Info ✅ Complete Methodology page; AI disclosure Ongoing

Roles and Responsibilities

Role Responsibility
Risk Assessor Internal risk assessment, CEO approved
Technical Owner CTO — performance testing, model versioning, monitoring infrastructure, incident investigation
Data Owner CTO — data quality audit, source validation, bias detection thresholds
Approver Chris Bowness (CEO) — sign-off on risk classification, approval of monitoring plan
Appeal Handler Support team and CEO — response to user appeals within 30-day SLA
Reviewer Every rating before publication — catch anomalies, confirm rubric match

Sign-Off

Approved By: Chris Bowness, CEO
Classification Date: 16 June 2026
Next Review Date: 16 December 2026

Status: Approved and in force. Monitoring plan effective immediately.


Appendices

Appendix A: Reference Product Monitoring Template

Use this template monthly for reference product re-tests.

## Monthly Reference Product Test

Test Date:
Tester:
Result: PASS / FAIL

| Product | Category | Previous Score | Current Score | Change | Rubric Match | Data Sources Match | Notes |
|---------|----------|-----------------|--------------|--------|--------------|-------------------|-------|
| [Name] | [Cat] | [x.x] | [x.x] | [+/-] | Yes/No | Yes/No | [Any anomalies?] |

Findings: [Pass/Fail; any trends or anomalies?]
Action: [If fail: CTO investigation required by [date]]

Appendix B: Quarterly Bias Audit Template

## Bias Audit

| Category | N Ratings | Mean Score | Std Dev | vs Global Mean | Variance Trend | Action |
|----------|-----------|------------|---------|----------------|----------------|--------|
| [Cat] | [N] | [x.x] | [x.xx] | [+/-x%] | [up/down/stable] | [Review/OK] |

Global Mean: [x.x]
Outlier Threshold: >20% variance
Findings: [Any flagged categories?]
Action: [If flagged: review lowest 5 scores in category; CTO investigate; notify manufacturers if systematic bias confirmed]

Appendix C: Regulatory References


Questions about this register? Email hello@resourcehip.com. To dispute a score, see Dispute a Rating. For our governance disclosure, see Responsible AI & Governance.