AI Risk Management Framework
Last updated: May 4, 2026
1. Governance Structure
DingDawg maintains a three-tier AI governance structure:
- Oversight Board — reviews AI risk policies, incident reports, and compliance posture monthly
- Risk Committee — evaluates individual findings, assigns severity, tracks remediation
- Engineering — implements fixes, maintains scanner accuracy, documents methodology
2. Risk Identification
Our compliance scanner evaluates AI systems against seven risk categories derived from EU AI Act Annex III high-risk classifications:
- Critical infrastructure impact
- Employment and worker management
- Essential public and private services
- Law enforcement and justice
- Biometric categorization
- Education and credentialing
- Insurance and financial services
3. Continuous Monitoring
Scans run automatically on every deployment. Results are logged with SHA-256 integrity hashes and stored in an append-only audit trail. Severity thresholds are calibrated against regulatory guidance and reviewed quarterly.
4. Human Oversight
All findings are reviewed by a human before being published or actioned. Automated scans flag potential issues; the Risk Committee determines severity and remediation priority. No automated action is taken without human approval.
5. Incident Response
Critical findings trigger immediate notification to the Oversight Board. High findings are reviewed within 24 hours. Medium findings are reviewed within one week. All incidents are logged with timestamps, remediation steps, and verification of fix.
This framework is reviewed and updated quarterly. Last reviewed: May 4, 2026. Questions: hello@dingdawg.com