FAIR (Factor Analysis of Information Risk) is an open, internationally recognised model for quantifying information and operational risk in financial terms. Instead of labelling a risk simply “high” or “medium”, FAIR decomposes it into measurable factors — the frequency of loss events and the magnitude of loss when they occur — and expresses the result as a probable financial loss, often a range or distribution.
By breaking risk down into components such as threat event frequency, vulnerability, and primary and secondary loss, FAIR lets teams reason about uncertainty explicitly and compare risks on a common monetary scale. This makes risk discussions far more useful to executives and boards, who can weigh mitigation spending against the loss exposure it actually reduces.
FAIR complements control frameworks like ISO 27001: the frameworks tell you what to control, while FAIR helps you prioritise where to invest based on quantified exposure.
Comply automates this — see the risk platform page.