Scale: likelihood and impact are Low / Medium / High. Product lead reviews weekly; High-impact triggers are reviewed immediately with the governance lead.
| ID | Risk | L | I | Early signal / trigger | Prevention | Contingency | Owner |
|---|---|---|---|---|---|---|---|
| R1 | wrong “no change” because the monitored surface misses policy action | H | H | a consumer finds an unobserved change; internal directive has no page edit | explicit observability limit, source mapping/gaps, weekly health, consumer reports | correct affected claims, incident review, add honest source if available; never claim exhaustiveness | Product |
| R2 | incorrect URL is presented as official | M | H | verification rejection, redirect/title mismatch, consumer report | 100% named verification, expiry/recheck, visible status | quarantine source/items; correction; repair or named gap | Verification |
| R3 | noisy source creates reviewer fatigue/rubber-stamping | H | H | repeat dismissals, review time/backlog rising | stability checks, passage diffs, workload cap, source quarantine | pause noisy source, retain visible gap, add reviewer capacity | Operations |
| R4 | machine classification or summary creeps into product | M | H | feature proposal/pre-sort language; generated legal wording | structural no-auto-classification gates and governance invariant | block release, remove output, incident review | Governance |
| R5 | unreviewed or single-reviewed high-impact item publishes | L | H | state-machine/test failure or credential misuse | multi-layer constraints, distinct actors, release validation | freeze feed, withdraw item, notify consumers, Sev-1 postmortem | Engineering |
| R6 | collection/logging exposes people interested in trans ID law | L | H | analytics/account/third-party dependency proposal; host logs retained | anonymous static feed, byte scans, vendor-log review | remove collection, rotate data, assess notification, migrate host | Privacy lead |
| R7 | public page unexpectedly contains personal data and diff republishes it | M | H | names/addresses in fetched text or canary match | quarantine and PII screening, bounded excerpts, private raw evidence | withdraw/redact, contain evidence, privacy incident workflow | Security |
| R8 | government host blocks crawler or changes terms | H | M | 403/robots/terms change/retrieval drop | polite weekly cadence, descriptive UA, terms review, no evasion | record gap, contact operator where appropriate, find equally official surface | Operations |
| R9 | source or supply chain is compromised | M | H | anomalous redirect/content, dependency/workflow alert | verification, protected Git/deploy, pinned dependencies, signed manifest | stop publish, restore trusted release, rotate credentials, reverify | Security |
| R10 | single reviewer/maintainer unavailable | H | H | queue age, missed run, burnout | named backup, documented runbooks, paid panel, workload limits | pause publication rather than bypass review; activate backup | Product |
| R13 | excerpt retention/publication creates copyright or terms issue | M | M | takedown or counsel concern | minimal excerpts, citations, private originals, documented rationale | remove public excerpt while preserving hashes/status; counsel response | Legal |
| R14 | accessibility barrier blocks a reviewer/consumer | M | H | failed manual task or complaint | WCAG 2.2 AA, disabled reviewer, accessible diff/CLI | provide immediate alternative, fix before release/resume | Accessibility |
| R15 | schema change breaks a consumer workflow | M | H | conformance failure or consumer parse error | versioning, fixtures, dual-publish/deprecation policy | restore prior artifact, issue migration/incident notice | Engineering |
| R16 | backup exists but cannot restore | M | H | checksum/integrity/restore drill fails | encrypted automated backups and quarterly clean restore | halt destructive maintenance; recover last verified backup; rebuild from evidence/Git | Operations |
| R17 | a funder pressures editorial decisions | M | H | suppression/priority request or conflict | public conflict rules; community-panel veto | refuse request, disclose conflict, replace funding if necessary | Governance |
| R18 | Spanish copy becomes stale or overstates evidence | M | M | English string changes without review; user report | message IDs, stale flag, two-person reviewed glossary | fall back visibly to current English; remove unsafe translation until reviewed | Language lead |
| R19 | schedule pressure turns release checklist into paperwork | M | H | missing receipts, retroactive sign-offs, concurrent P0 churn | gate owners, scope cut rule, hold authority | declare release hold and publish revised critical path | Release authority |
| R20 | active PDF changes cannot yield the promised cited passage | H | H | empty normalized text, extractor confidence failure, byte-only alert | bounded versioned extractor plus retained original and manual comparator | mark source comparison-limited, hold publication, complete reproducible manual receipt or declare gap | Engineering |
| R21 | count-based pruning destroys publication evidence | H | H | sixth snapshot deletes a referenced baseline; restore lacks old bytes | time-based retention, evidence pins, backup-before-delete, boundary tests | freeze pruning/publication, restore verified backup, reconstruct and incident-review affected chain | Operations |
| R22 | free-form notes publish a legal conclusion | M | H | words such as “requires,” “operative,” or directive advice appear in output | separate internal/public fields, constrained templates, legacy audit, publisher tests | withdraw/correct item, notify consumers, legal-boundary review | Governance |
| R23 | ephemeral automation loses operational history or cannot recover | H | H | fresh database each schedule; no named volume/backup/promotion owner | persistent runner, encrypted volume, off-host backup, reproducible deployment and restore | stop production claim, restore last verified state, run diagnostic workflow only | Operations |
| R24 | signing key or verifier trust state is ambiguous/compromised | M | H | unknown key accepted, revocation unavailable, signature mismatch | pinned trust manifest, purpose binding, offline custody, rotation/revocation tests | freeze promotion, revoke/rotate, republish trusted manifest, notify consumers | Security |
R1 is inherent and can only be reduced, never closed. V1 accepts it only with explicit language, health/gap visibility, and a missed-change correction path. R8 is also structurally expected; honest loss of coverage is safer than circumvention. R10 determines whether the service is sustainable: if no backup reviewer exists at the release decision, hold rather than label an unattended prototype “V1.0.”