After watching Prashanthi and Tony’s fireside chat at the 2021 FAIR Conference about getting a FAIR program started, I was struck by the simple and insightful themes that they kept repeating. Well, simple on paper, but not always easy to keep in mind when you’re in the thick of a FAIR rollout.
Evan Wheeler

Recent Posts
4 Questions and 4 Action Steps to Get a FAIR Program Off the Ground
[fa icon="calendar'] Nov 10, 2021 8:30:37 AM / by Evan Wheeler posted in Member Content, FAIR Conference 2021
Why Risk Teams Should Be Champions for Data Governance in Fintech Firms
[fa icon="calendar'] Jul 28, 2021 12:26:09 PM / by Evan Wheeler posted in Member Content
Ask a cyber risk professional about data governance practices, and they will likely tell you tales of classification schemes, access controls, and encryption … but we often overlook the importance of data quality, integrity, and usability that are core tenants of a robust data governance process.
AML & Sanctions Compliance: Top Operational “Risks” for 2017? – Part 3
[fa icon="calendar'] Oct 12, 2017 10:52:53 AM / by Evan Wheeler posted in FAIR, Member Content
After a short summer break, the FAIR Institute Operational Risk workgroup met again in August to continue our project using the FAIR methodology to revise a typical list of “top operational risks” (we found our list on Risk.net).
Risks from Regulations: Top Operational 'Risks' for 2017? – Part 2
[fa icon="calendar'] May 3, 2017 8:47:43 PM / by Evan Wheeler posted in Risk Management, Member Content
During the April meeting of the Operational Risk workgroup, the members continued working on a project to recast a list of top operational risks using the FAIR model. Quick recap of this effort so far - every year, you’ll find numerous lists of supposed “top risks” from various sources, but are they even risks?
Top Operational “Risks” for 2017? – Part 1
[fa icon="calendar'] Mar 22, 2017 12:26:31 PM / by Evan Wheeler posted in Risk Management, Member Content
During the March meeting of the Operational Risk Workgroup, the members took on a project to recast a list of top operational risks using the FAIR risk model. Every year, you’ll find numerous lists of supposed “top risks” from analysts, surveys, professional organizations, etc. with something in common: They don’t actually provide true risks.
Breaking Risk Paradigms with FAIR
[fa icon="calendar'] Mar 16, 2017 1:48:17 PM / by Evan Wheeler posted in FAIR, Member Content
Every year the masses of information security professionals gather at the Moscone Center in San Francisco for the RSA Conference looking for opportunities to learn from peers and discuss their latest challenges, and this year was no different. I had the privilege to share my own perspective as a speaker in the GRC track.
Take Another Look at Inherent Risk
[fa icon="calendar'] Feb 9, 2017 10:00:00 AM / by Evan Wheeler posted in FAIR, Risk Management
During the February meeting of the FAIR Institute's Operational Risk workgroup, members discussed the ever popular concept of “inherent risk” and how it could be best used in the context of a standard risk methodology like FAIR.
Enterprise Risk Standards – Where does FAIR fit in?
[fa icon="calendar'] Sep 14, 2016 7:30:00 AM / by Evan Wheeler posted in FAIR, Risk Management, Member Content
The Operational Risk workgroup meets monthly to discuss uses of FAIR and to share experiences.
Beginning Your Operation Risk Journey with FAIR
[fa icon="calendar'] Jul 19, 2016 5:30:00 PM / by Evan Wheeler posted in FAIR, Risk Management, Member Content
Over the years many risk professionals have found their risk religion with Factor Analysis of Information Risk (FAIR), but how to start integrating it into your organization isn’t always obvious.
FAIR Institute Operational Risk Workgroup: Using FAIR to Understand Operational Risks
[fa icon="calendar'] Jun 9, 2016 7:30:00 AM / by Evan Wheeler posted in FAIR, Risk Management, Member Content
From the desk of Evan Wheeler, chair of the Operational Risk workgroup at the FAIR Institute
What first attracted me to FAIR, was its applicability to information security risks, but it offers so much more than that.