**Article 9**  

**Establishment and Scope of the Risk Management System**  
Norwin Industrial Technologies has instituted a risk management system for Gas Safety Insight that aligns with the continuous, lifecycle-oriented approach mandated for high-risk AI systems. This system documents and maintains procedures for identifying, analyzing, and addressing risks related to the AI-based detection of anomalies indicative of gas leaks or pressure abnormalities within natural gas infrastructure. The scope of risks assessed primarily encompasses operational safety hazards arising from algorithmic detection performance, sensor data quality, and contextual environment variability, exclusively within the intended use parameters of the system. Known risks include false alarms leading to unnecessary maintenance interventions and sensor signal degradation affecting detection sensitivity. The boundaries of mitigatable risks have been delineated to focus on those addressable through system design, model parameters, and technical information provision to operators.  

**Identification and Evaluation of Known and Foreseeable Risks**  
The principal risk identified relates to the balance between false positives—which provoke maintenance escalations—and false negatives, where critical leaks may remain undetected. Gas Safety Insight implements an anomaly detection threshold calibrated through supervised training on a dataset of over 250,000 labeled sensor and operational log records collected from representative EU gas networks over two years. This threshold prioritizes reduction of false alarms to limit maintenance burden and system operator fatigue, as supported by a target false positive rate below 0.5% under nominal conditions. However, investigations conducted in laboratory simulations and limited field trials reveal reduced sensor signal fidelity in low-pressure or noisy environments can degrade detection sensitivity, raising the residual risk of missed critical leaks in such scenarios. Comprehensive probabilistic risk quantification connecting undetected leak probabilities to operational safety outcomes has not been fully established. The foreseeable misuse analysis considers conditions of intermittent sensor failure and data latency, which can further impair leak indication.  

**Evaluation of Risks From Post-Market Data and Interaction Effects**  
While Gas Safety Insight is not yet widely deployed in operational EU gas networks, the post-market monitoring framework is designed to aggregate incident logs, false alarm rates, and operator feedback systematically. This data will inform iterative reassessments of residual risks and detection thresholds. Presently, initial field pilot data from 12 months of limited deployment covering approximately 1,200 sensor nodes reports a false alarm reduction of 38% over legacy systems but confirms some missed leak events correlated with sporadic sensor signal degradation. Interaction analyses consider the combined effect of sensor fusion and Transformer-based contextual encoding in the detection performance, demonstrating robustness to isolated noisy inputs but vulnerability to consistent low-amplitude signal conditions. Consequently, iterative risk management updates are planned to refine thresholding and model retraining strategies, acknowledging the present gaps in residual risk characterization under degraded input conditions.  

**Adopted Risk Management Measures and Their Rationale**  
The principal technical risk mitigation measure involves threshold calibration to minimize false alarms, supported by a hybrid GBDT-Transformer model architecture enabling flexible feature integration and temporal pattern recognition. This approach reduces unnecessary maintenance activations, which in past operational environments have been linked to increased system downtime and personnel resource strain. Additional measures include a tiered alert categorization system whereby notifications are classified by confidence level, allowing deployer discretion in action prioritization. Provision of detailed technical documentation equips deployers with guidance on sensor maintenance and signal integrity assessment, facilitating early detection of potential data degradation. Training materials focus on interpreting model outputs and recognizing system limitations, targeting operational staff with technical competence in gas infrastructure monitoring. Nonetheless, no automated override mechanism or probabilistic safety envelope currently complements these measures to explicitly guarantee residual risk below an objectively quantified acceptable level, particularly under low-sensor-signal conditions.  

**Testing, Validation, and Performance Assessment**  
Gas Safety Insight underwent extensive testing throughout its development lifecycle, spanning initial prototype validation, controlled laboratory simulations, and field pilot testing. Performance metrics include receiver operating characteristic (ROC) analyses and area under the curve (AUC) evaluations of detection sensitivity across varying sensor signal quality conditions. During testing, the system consistently achieved a detection AUC of 0.92 under nominal sensor signal scenarios but declined to approximately 0.75 under artificially induced low-amplitude sensor input conditions. Testing was conducted against predefined thresholds set to maintain the false positive rate below 0.5%, with no explicit probabilistic threshold established to constrain undetected leak probabilities in degraded signal environments. Validation cycles include periodic retraining on updated labeled datasets to adjust to evolving operational patterns but do not incorporate formal probabilistic risk modelling linking missed detection likelihoods with potential safety impacts. Prior to market release and field deployment, all testing adhered to industry-standard protocols for anomaly detection in safety-critical contexts and complied with relevant EU technical standards applicable in 2025.  

**Consideration of Vulnerable Groups and User Competence**  
While the primary safety outcomes concern physical infrastructure and gas supply continuity, the indirect risk to end-users, including vulnerable populations such as children, is acknowledged in documentation relating to safety-critical failure modes. Deployers—predominantly network operators and maintenance personnel with technical training—are assumed to possess competence consistent with industry norms. The system’s user information materials reflect this, emphasizing the technical requirements for sensor upkeep and alert interpretation. No dedicated measures beyond standard technical instruction address potential adverse impacts specifically for underage or otherwise vulnerable groups. The system’s architecture does not incorporate mechanisms to adapt or escalate interventions based on user vulnerability profiles.  

**Summary of Residual Risks and Planned Future Enhancements**  
The residual risk framework currently accepts the trade-off favoring low false alarm rates to reduce maintenance demands, recognizing that this approach implies a non-negligible risk of missed critical leak detections in certain low-sensor-signal conditions. Although this design choice is supported by operational experience and dataset-driven threshold tuning, no explicit probabilistic risk evaluation has demonstrated that such residual risk conforms to an objectively justified safety criterion. Post-market monitoring and planned model updates aim to enhance detection sensitivity and close this gap incrementally. Further developments under consideration include integration of probabilistic risk assessment modules to quantify undetected leak risks relative to safety consequences and dynamic threshold adjustment responsive to real-time sensor quality metrics.