Skip to content
Research papersAnalysis & perspective

What Open FAIR actually standardizes — and what a PE operator still decides

The Open Group’s Open FAIR Body of Knowledge is a taxonomy and an analysis process, not a loss number. Read it that way and the IC conversation gets shorter.

Most “we do FAIR” slides are doing one of three things: naming a vendor, naming a training class, or hiding a point estimate inside a method that was designed to refuse point estimates. The document that can settle the argument is not a blog post. It is The Open Group’s Open FAIR Body of Knowledge: the Risk Analysis standard (O-RA, Version 2.0.1) and the Risk Taxonomy standard (O-RT, Version 3.0.1), published together as Version 2.0 of the body of knowledge (17 October 2022).

This is a reading note, not a recitation of the paid standard text. The public Open Group pages are enough to get the claim right: Open FAIR is a vendor-neutral, consensus definition of how to decompose and analyze risk so results can be compared across scenarios. It is not a price list, and it is not a Valty feature list.

What the standard is for

O-RT is the vocabulary. It exists so two analysts do not use “threat” or “vulnerability” to mean four different things in the same IC memo. O-RA is the process for doing an analysis once you have that vocabulary. Together they are meant to be risk-domain agnostic: the same decomposition can be applied to information security and, in principle, to other loss scenarios.

That agnostic property is the part operators underuse. If the taxonomy is doing its job, a ransomware scenario and a payment-fraud scenario can be discussed in the same units — frequency and magnitude, with uncertainty kept visible — instead of one arriving as a red heatmap and the other as a legal memo.

The Open Group also publishes a process guide and a spreadsheet tool. Those are implementation aids. They are not a substitute for naming the scenario, the asset, and the evidence you actually have.

What a PE operator should demand

When a portco or an advisor says “FAIR,” ask four questions that the standard makes legitimate and a scorecard does not.

Which scenario? “Cyber risk” is not a scenario. “Credential-stuffing against the customer portal that holds billing files” is.

Which factors were estimated, and from what? A taxonomy without inputs is a poster. If frequency came from “industry average” and magnitude came from “a slide we liked,” say that out loud.

Where is the range? A single dollar is a decision to hide the tails. Open FAIR exists, in part, so that hiding is harder to defend.

What would change the range? If no input can move the result, you are not looking at an analysis. You are looking at a number that has been socially approved.

Valty’s public worked example uses a FAIR-aligned Monte Carlo mechanism to compare one fictional company’s funding options. It reports mean, median and P95 annual gross loss from 50,000 trials, with the assumptions and source revision attached. The example does not model insurance recovery, adjust EBITDA or establish customer outcomes. It is not Open FAIR product certification or a completed analysis of a fund.

What the standard does not do

It does not pull your CrowdStrike or ERP data. It does not decide risk appetite. It does not net insurance unless you model the transfer as an input. It does not tell an investment committee to cut a check. Those are operating decisions.

It also does not forgive a vendor who turns a modeled tail into an enterprise-value story and calls the result “FAIR.” If you see that move, the problem is not the taxonomy. The problem is the claim.

Inspect the fictional sample decision memo to review the method and assumptions, or request a platform demo. The free demo uses illustrative data; company scope, evidence handling, supported workflows and terms are agreed before evaluation access.

Sources

Limitations

This note cites the public catalog pages and publication metadata. It does not reproduce the paid standard text, and it does not treat “FAIR-aligned” as a certificate. A taxonomy cannot replace tenant evidence. Any range still has to show its inputs.

Product context Real application capture · illustrative data
What Open FAIR actually standardizes — and what a PE operator still decides product viewOpen full-size product view ↗
Back to blogBrowse category

Related

More in Research papers.