Methodology v1.0 · Last updated September 2026. AI-CRRQ™ is under active development; this page is revised as the model and its evidence base change.
AI-CRRQ™ is a deterministic model. The same inputs always produce the same score. There is no machine learning, no probabilistic inference, and no hidden layer. The structure is published below so that any assessor, auditor or board member can see how the vectors combine. The scoring weights, normalization and tier calibration are provided to clients under agreement rather than published here.
ORCI — Operational Response Capability. Leadership clarity, crisis command structure, practiced escalation, cross-functional coordination.
RVI — Recovery Velocity. Speed and completeness of operational restoration, backup integrity, tested recovery capability.
TEI — Threat Exposure. Attack surface, third-party dependency, sector threat pressure, and regulatory exposure.
Structure. ORCI and RVI combine multiplicatively; TEI sits in the denominator, so threat pressure scales the whole result rather than subtracting from it.
ORCI is weighted as the primary determinant of survivability. This weighting reflects a design decision grounded in three decades of practitioner observation across healthcare, financial services and public sector environments, including direct tabletop exercise facilitation: organizations with mature, well-tooled security programs can still suffer operational collapse when leadership lacks tested crisis-command structure. That observation is the origin of the model. It is a hypothesis the framework is built to test, not a demonstrated statistical relationship. The Survival Index™ is therefore most sensitive to ORCI by construction, and a reader should treat that sensitivity as a property of the model, not as evidence about the world.
TEI is placed in the denominator rather than treated as an additive term. The reasoning is that threat pressure should scale resilience capability rather than offset it: an organization with strong response and recovery capability operating under severe threat exposure should not score the same as one with identical capability under low exposure. This is a modeling judgment about how the vectors should interact. It has not been empirically tested.
Inputs are self-reported and ordinal. Scores derive from structured self-assessment, not from instrumented measurement or independent audit. This is a known limitation. It means two assessors scoring the same organization may not agree, and establishing inter-rater reliability is a prerequisite to any stronger claim about the model, see the validation roadmap below.
A new measurement methodology earns confidence in stages. AI-CRRQ™ is at stage one. Publishing where it actually stands is more useful to a board than claiming a maturity it has not reached.
Conceptual validity, current stage. Framework construction, documented design rationale, practitioner review, and positioning against established frameworks.
Internal validity. Sensitivity analysis, boundary testing, and an inter-rater reliability study establishing that independent assessors scoring the same organization agree within a defined tolerance.
Retrospective testing. Reconstructing ORCI, RVI and TEI for publicly documented incidents where enough pre-incident detail exists, and comparing modeled scores against recorded operational outcomes.
Field calibration. A structured cohort of participating organizations establishing baseline score distributions by sector and size.
Longitudinal validation. Baseline scores observed against measurable outcomes over time, exercise performance, actual versus stated recovery time, and incident response where it occurs.
Independent replication. An external research partner applying the methodology independently and publishing the result.
Probabilistic outputs, confidence intervals, and simulation-based uncertainty quantification are deliberately not offered at this stage. Applying them to self-reported ordinal inputs would produce false precision rather than genuine uncertainty measurement. They become appropriate once stages two and three are complete.
AI-CRRQ™ was stress-tested against established risk and regulatory frameworks to identify gaps, confirm complementary positioning, and ensure regulatory alignment across major compliance regimes.
Outcome-based cybersecurity risk framework spanning Govern, Identify, Protect, Detect, Respond and Recover. AI-CRRQ™ complements CSF 2.0 by consolidating response and recovery capability into a single directional survivability measure.
Information security management system. AI-CRRQ™ complements with operational continuity quantification under active threat conditions.
Financial loss quantification model. AI-CRRQ™ adds operational survival dimension that FAIR's financial lens does not cover.
72-hour breach notification requirement. AI-CRRQ™ RVI scores map directly to notification and recovery timeline obligations.
Material incident disclosure within four business days. AI-CRRQ™ supports operational impact quantification for disclosure decisions.
EU Digital Operational Resilience Act. AI-CRRQ™ can support analysis of operational resilience themes relevant to DORA, including ICT disruption, recovery capability, resilience testing and third-party dependencies. It does not constitute DORA compliance certification.
The AI-CRRQ™ model is revised as the threat landscape changes and as evidence accumulates through the validation roadmap above. Revisions are versioned and dated on this page. Where the model changes in a way that affects scoring, the change and its rationale are documented for organizations tracking their score over time.
While all 20 disruption scenarios apply to every organization, historical data and regulatory patterns show that certain scenarios carry disproportionate survivability risk by sector. Use this as a starting point for scenario prioritization.
Ransomware — Clinical operations and patient care continuity
Mass Data Breach — PHI exposure, HIPAA/HITECH breach assessment and notification obligations
Key Person Loss — Clinical technology leadership single points of failure
Pandemic / Workforce Crisis — Mass staff unavailability during patient surge
AI Model Failure — Clinical decision support systems acting outside boundaries
Regulatory Enforcement Action — NYDFS exam failure, SEC consent order, Fed scrutiny
Business Email Compromise — Wire fraud at scale, C-suite impersonation
Cloud Provider Outage — Trading systems, payment processing, core banking
Supply Chain Attack — Third-party fintech and data vendor compromise
AI-Enabled Attack — Deepfake wire fraud, AI-powered phishing targeting finance teams
Power Grid Failure — Extended utility outage affecting critical operations
Natural Disaster — Geographic risk and supply chain concentration
Internet / Connectivity Takedown — Nation-state BGP hijack or ISP attack
Insider Threat — Privileged access abuse with national security implications
Data Center Fire — Physical infrastructure redundancy for critical services
Industry prioritization guidance is included in the facilitated Survival Index™ assessment scoping conversation. A multi-scenario portfolio assessment covers all relevant scenarios for your sector and produces a complete Operational Survivability Portfolio for board reporting. Request a scoping conversation →
Ongoing validation: AI-CRRQ™ is building a live client outcome research program. Organizations completing a Facilitated Survival Index™ Assessment may opt in to longitudinal outcome tracking, so that future Survival Index™ scores can be validated against real-world results rather than simulation alone.
Detailed scoring guidance, the assessment instrument, and tier calibration are available under NDA for enterprise clients, research partners, and qualified organizations. The framework is designed to complement, not replace, your existing risk, governance, and compliance programs. It provides a shared survivability lens that security, GRC, legal, finance, and business teams can use collaboratively.
Request Methodology Brief →The free Survivability Indicator applies the AI-CRRQ™ scoring model to generate a directional survivability posture. For a facilitated Survival Index™ assessment with the full methodology, request a briefing.