In general a Risk Management Service would be a hosted co-signing service. It would be up to a specific implementation how your device is notified.
I chose WebFist, because most users don't have a domain they control.
Do you happen to know if there is any solid implementation of the Fist Bump server except Brad Fitzpatrick's go implementation?
One month later...
Sorry about the really slow reply. Somehow, I missed this entirely. But, I do have an excuse: two weeks traveling and then, as always, slammed at work for another couple of weeks.
Anyway, I'm not aware of other implementations. I'd suggest pinging Brad to find out.
You're right that few users have domains they control. However, for WebFinger to be useful, it doesn't necessarily have to be one they control. For example, if Coinbase offered a WF server, I could tell people to send money to me at [email protected]. The address would not necessarily have to be my personal email address, after all. It's nice that it might be, but what I personally think is more important is that one can offer an address that is easier to deal with than a big string of base53 characters.