The FAIR Institute Blog

Building Out the FAIR CRM Framework: A Look Inside the Standards Committee's Work

Written by Todd Tucker, Standards Director, FAIR Institute | Jul 22, 2026 12:11:41 PM

If you attended our Standards Committee open forums earlier this year, you heard us talk about the FAIR Cyber Risk Management (CRM) Framework. If not, let me explain what that actually means in practice, because "framework" can sound abstract until you see the work happening underneath it.

Here's the simplest way I can put it. The FAIR Model has always been our foundation, the core method for quantifying cyber risk in financial terms. But a foundation isn't a house. Over the past couple of years, the Standards Committee and our working groups have been building out everything around that foundation, and this year a lot of that work went into giving the whole thing a clear shape.

We spent real time in Committee sessions landing on a structure with three tiers. Standards sit at the center: FAIR-CRMP as the governing program standard, the FAIR Model itself, and its extensions, FAIR-CAM, FAIR-MAM, and FAIR-CRS. Domains are where FAIR actually gets put into practice, and we deliberately debated the label here. An earlier draft called this tier "Applications," but that read too much like software, so we settled on Domains instead, since these are risk management disciplines, not products. Candidate domains we've been working through include things like AI Risk, CTEM, TPRM, Product Development, and Security Operations, though the Standards Committee will ultimately decide the final set as the framework matures. And Enablers are the official resources meant to help practitioners actually use all of this. We've been discussing items like a CRM Framework white paper, a Controls Library, a Data Guide, a CRM Maturity Model, and a CRM Competency Model as candidates, again subject to the Committee's review.

That three-tier structure, Standards, Domains, Enablers, is what we now call the FAIR CRM Framework, and most of my time this year has gone into filling it out.

Why expand it now

A framework only earns its name if it's actually useful across the situations practitioners face. Sketching candidate domains on a diagram is the easy part. The harder, ongoing work is deciding which ones deserve real substance behind them, and then building it, then getting that content formally reviewed and ratified so members know it carries the Institute's backing.

That's exactly what the Standards Committee is doing right now. We recently kicked off a review initiative to formally ratify three specific artifacts, one at each tier of the framework, as a way to start building out approved content rather than leaving the framework as an outline. The Cyber Risk Scenario Taxonomy is up for review as a candidate Standard. A TPRM Guide, developed by our TPRM workgroup and informed by the Third Party Risk Management Association's 101 guide, is up for review as a candidate Domain resource. And a Data Guide, built to answer the practitioner question of "what data do I need and where do I get it," is up for review as a candidate Enabler. Committee members have volunteered in pairs to review each draft and present their assessment at our next meeting, and that meeting will largely be structured around those three presentations. It's a small, concrete step, but it's the kind of unglamorous governance work that turns a framework diagram into something members can actually rely on.

Alongside that review initiative, two of our workgroups have been doing the deeper work of filling in specific domains.

The first is our FAIR-CTEM workgroup, where Chris Griffith (from SAFE) and a great group of practitioners from companies like Verizon, ADP, and Victoria's Secret have been working through how FAIR connects to Continuous Threat Exposure Management. Vulnerability management has always run on a different clock than risk analysis. VM teams triage by the thousands, on a near-daily cadence, while a full FAIR scenario is a more deliberate exercise. Our in-progress white paper is really about bridging those two clocks so that a CVSS score and a business-relevant risk number aren't living in separate universes anymore.

The second is our FAIR-CAM workgroup, where Zach Cossairt is leading a practical guidance track and Jack Jones is leading work on controls and mapping. This one is less flashy but arguably just as important. It's about giving organizations a rigorous way to understand which controls actually reduce risk, and by how much, rather than relying on control checklists that treat every safeguard as equally valuable.

What's next

Between now and our next round of publications, you'll see the CTEM white paper expand to cover culture as a cross-cutting factor in vulnerability management, and a set of practical tools, things like a RACI template for risk-based VM and a tiering model for managing exceptions, that turn the concepts into something a team can actually run with on a Monday morning. The FAIR-CAM workgroup will keep pushing on both the practical guidance and controls mapping fronts. And our next Standards Committee meeting will be largely built around hearing out the Cyber Risk Scenario Taxonomy, TPRM Guide, and Data Guide reviews and deciding whether they're ready to formally join the framework.

We also spent a few minutes in our last Committee meeting just talking about where the Domains tier could go next. It's not capped at any particular number, and candidates like GRC, cyber insurance, and portfolio management came up as natural extensions alongside AI Risk, CTEM, and TPRM. The rule of thumb we're using is that a domain earns a spot when it represents a real operational function or practice where a FAIR-based risk discipline genuinely integrates, not just anywhere FAIR could theoretically apply. That's a Committee decision, not something I want to get ahead of here, but it gives you a sense of how we're thinking about where this goes.

Behind the scenes, we're also building out the broader content ecosystem that supports all of this, including a curated body of FAIR Institute material we can point practitioners to with confidence.

None of this work happens without the volunteers who show up to workgroup calls, argue about terminology with us, and pressure-test drafts before they see daylight. If you're a FAIR Institute member and any of this resonates with where your own program is stuck, I'd genuinely like to hear from you. That's usually how the next workgroup gets started.