FRAMEWORK VALIDATION & METHODOLOGY

A Documented Model.
Honestly Scoped.

AI-CRRQ™ is a structured, deterministic decision-support model built on documented design assumptions and three decades of practitioner observation. It has not yet been validated against real-world incident outcomes, and it does not predict whether a specific organization will survive a specific event. This page sets out how the model is constructed, what it establishes today, what it does not, and the steps required to establish empirical validity.

Get Your Survival Score → Request Full Methodology Brief
3
Scoring Vectors
ORCI · RVI · TEI
20
Disruption Scenarios
Cyber, operational, physical and environmental
6+
Frameworks Positioned Against
NIST · ISO · FAIR · NYDFS · SEC · DORA

Methodology v1.0 · Last updated September 2026. AI-CRRQ™ is under active development; this page is revised as the model and its evidence base change.

Model Construction and Design Rationale

AI-CRRQ™ is a deterministic model. The same inputs always produce the same score. There is no machine learning, no probabilistic inference, and no hidden layer. The structure is published below so that any assessor, auditor or board member can see how the vectors combine. The scoring weights, normalization and tier calibration are provided to clients under agreement rather than published here.

The Three Vectors

ORCI — Operational Response Capability. Leadership clarity, crisis command structure, practiced escalation, cross-functional coordination.

RVI — Recovery Velocity. Speed and completeness of operational restoration, backup integrity, tested recovery capability.

TEI — Threat Exposure. Attack surface, third-party dependency, sector threat pressure, and regulatory exposure.

Structure. ORCI and RVI combine multiplicatively; TEI sits in the denominator, so threat pressure scales the whole result rather than subtracting from it.

Design Assumptions — Stated, Not Proven

01

ORCI is weighted as the primary determinant of survivability. This weighting reflects a design decision grounded in three decades of practitioner observation across healthcare, financial services and public sector environments, including direct tabletop exercise facilitation: organizations with mature, well-tooled security programs can still suffer operational collapse when leadership lacks tested crisis-command structure. That observation is the origin of the model. It is a hypothesis the framework is built to test, not a demonstrated statistical relationship. The Survival Index™ is therefore most sensitive to ORCI by construction, and a reader should treat that sensitivity as a property of the model, not as evidence about the world.

02

TEI is placed in the denominator rather than treated as an additive term. The reasoning is that threat pressure should scale resilience capability rather than offset it: an organization with strong response and recovery capability operating under severe threat exposure should not score the same as one with identical capability under low exposure. This is a modeling judgment about how the vectors should interact. It has not been empirically tested.

03

Inputs are self-reported and ordinal. Scores derive from structured self-assessment, not from instrumented measurement or independent audit. This is a known limitation. It means two assessors scoring the same organization may not agree, and establishing inter-rater reliability is a prerequisite to any stronger claim about the model, see the validation roadmap below.

Validation Roadmap

A new measurement methodology earns confidence in stages. AI-CRRQ™ is at stage one. Publishing where it actually stands is more useful to a board than claiming a maturity it has not reached.

STAGE 1

Conceptual validity, current stage. Framework construction, documented design rationale, practitioner review, and positioning against established frameworks.

STAGE 2

Internal validity. Sensitivity analysis, boundary testing, and an inter-rater reliability study establishing that independent assessors scoring the same organization agree within a defined tolerance.

STAGE 3

Retrospective testing. Reconstructing ORCI, RVI and TEI for publicly documented incidents where enough pre-incident detail exists, and comparing modeled scores against recorded operational outcomes.

STAGE 4

Field calibration. A structured cohort of participating organizations establishing baseline score distributions by sector and size.

STAGE 5

Longitudinal validation. Baseline scores observed against measurable outcomes over time, exercise performance, actual versus stated recovery time, and incident response where it occurs.

STAGE 6

Independent replication. An external research partner applying the methodology independently and publishing the result.

Probabilistic outputs, confidence intervals, and simulation-based uncertainty quantification are deliberately not offered at this stage. Applying them to self-reported ordinal inputs would produce false precision rather than genuine uncertainty measurement. They become appropriate once stages two and three are complete.

Mapped Against Established Frameworks

AI-CRRQ™ was stress-tested against established risk and regulatory frameworks to identify gaps, confirm complementary positioning, and ensure regulatory alignment across major compliance regimes.

NIST CSF 2.0

Outcome-based cybersecurity risk framework spanning Govern, Identify, Protect, Detect, Respond and Recover. AI-CRRQ™ complements CSF 2.0 by consolidating response and recovery capability into a single directional survivability measure.

ISO 27001

Information security management system. AI-CRRQ™ complements with operational continuity quantification under active threat conditions.

FAIR

Financial loss quantification model. AI-CRRQ™ adds operational survival dimension that FAIR's financial lens does not cover.

NYDFS Part 500

72-hour breach notification requirement. AI-CRRQ™ RVI scores map directly to notification and recovery timeline obligations.

SEC Cyber Rules

Material incident disclosure within four business days. AI-CRRQ™ supports operational impact quantification for disclosure decisions.

DORA

EU Digital Operational Resilience Act. AI-CRRQ™ can support analysis of operational resilience themes relevant to DORA, including ICT disruption, recovery capability, resilience testing and third-party dependencies. It does not constitute DORA compliance certification.

Ongoing Development

The AI-CRRQ™ model is revised as the threat landscape changes and as evidence accumulates through the validation roadmap above. Revisions are versioned and dated on this page. Where the model changes in a way that affects scoring, the change and its rationale are documented for organizations tracking their score over time.

Which Scenarios Matter Most for Your Sector

While all 20 disruption scenarios apply to every organization, historical data and regulatory patterns show that certain scenarios carry disproportionate survivability risk by sector. Use this as a starting point for scenario prioritization.

Healthcare

Priority Scenarios

1

Ransomware — Clinical operations and patient care continuity

2

Mass Data Breach — PHI exposure, HIPAA/HITECH breach assessment and notification obligations

3

Key Person Loss — Clinical technology leadership single points of failure

4

Pandemic / Workforce Crisis — Mass staff unavailability during patient surge

5

AI Model Failure — Clinical decision support systems acting outside boundaries

Financial Services

Priority Scenarios

1

Regulatory Enforcement Action — NYDFS exam failure, SEC consent order, Fed scrutiny

2

Business Email Compromise — Wire fraud at scale, C-suite impersonation

3

Cloud Provider Outage — Trading systems, payment processing, core banking

4

Supply Chain Attack — Third-party fintech and data vendor compromise

5

AI-Enabled Attack — Deepfake wire fraud, AI-powered phishing targeting finance teams

Government / Critical Infrastructure

Priority Scenarios

1

Power Grid Failure — Extended utility outage affecting critical operations

2

Natural Disaster — Geographic risk and supply chain concentration

3

Internet / Connectivity Takedown — Nation-state BGP hijack or ISP attack

4

Insider Threat — Privileged access abuse with national security implications

5

Data Center Fire — Physical infrastructure redundancy for critical services

Industry prioritization guidance is included in the facilitated Survival Index™ assessment scoping conversation. A multi-scenario portfolio assessment covers all relevant scenarios for your sector and produces a complete Operational Survivability Portfolio for board reporting. Request a scoping conversation →

What the Data Shows. What It Doesn't Claim.

What AI-CRRQ™ Produces

  • A directional, scored survivability posture for executive decision-making
  • Specific gap identification at the vector level (ORCI, RVI, TEI)
  • Prioritized 30–90 day improvement roadmap
  • Board-ready documentation of operational resilience posture
  • Regulatory alignment mapping for NYDFS, SEC, DORA, FFIEC (advisory only, not legal or compliance advice)

What AI-CRRQ™ Does Not Claim

  • Actuarially precise risk probability predictions
  • A replacement for professional risk assessments or audits
  • Guaranteed security or resilience outcomes
  • Compliance certification of any kind
  • Specific incident outcome prediction
  • Demonstrated predictive accuracy against real-world incident outcomes
  • Simulation-based or probabilistic uncertainty quantification

Ongoing validation: AI-CRRQ™ is building a live client outcome research program. Organizations completing a Facilitated Survival Index™ Assessment may opt in to longitudinal outcome tracking, so that future Survival Index™ scores can be validated against real-world results rather than simulation alone.

Access to Full Technical Methodology

Detailed scoring guidance, the assessment instrument, and tier calibration are available under NDA for enterprise clients, research partners, and qualified organizations. The framework is designed to complement, not replace, your existing risk, governance, and compliance programs. It provides a shared survivability lens that security, GRC, legal, finance, and business teams can use collaboratively.

Request Methodology Brief →

Ready to Apply the Framework?

The free Survivability Indicator applies the AI-CRRQ™ scoring model to generate a directional survivability posture. For a facilitated Survival Index™ assessment with the full methodology, request a briefing.

Get Free Survivability Indicator → Request Facilitated Survival Index™ Assessment