Quantifying AI Risk - FAIR, Loss-Event Reserve Modeling
Acme's Q2 2026 audit-committee meeting is twenty minutes in when the CFO opens her notebook and turns to the Chief Risk Officer with a single question: "We have €11.8M of reserve set aside on the balance sheet for cyber. How much should we set aside for AI?" The CRO looks at the heat-map the team has just walked the committee through, a 5x5 grid with red cells on Annex III §5(b) credit scoring, on the wealth-management agent, on the foundation-model vendor concentration, and realizes the heat-map cannot answer the question. The heat-map says "red, medium-likelihood, high-impact." It does not say €X. The CFO needs €X. The audit-committee chair needs €X. The captive insurer underwriter who walks in tomorrow needs €X. The Article 9 risk management system reviewer who will arrive in October needs €X. The Federal Reserve examiner who is testing SR 11-7 model-risk capital adequacy at the parent bank needs €X. This lesson is the L4 leadership-tier framework for quantifying AI risk using the Factor Analysis of Information Risk (FAIR) methodology adapted to AI scenarios: the Monte Carlo workflow, the five AI-specific loss-event scenarios with sample distributions, the aggregate annualized loss exposure calculation, the loss-event reserve modeling, the insurance gap analysis, the calibration discipline, and the Acme worked example showing €4.2M ALE_50 / €11.8M ALE_95 driving a €5.8M reserve recommendation after €6M insurance.
Why Quantify AI Risk in 2026
The 2026 governance ecosystem has produced a sharp escalation in the regulator's, auditor's, CFO's, and insurer's expectations of AI risk quantification. The heat-map is necessary but no longer sufficient. The mature 2026 AI governance program produces both: the heat-map for the AI Governance Committee's quarterly operating cadence and the audit committee's qualitative sensemaking, and the dollar/euro quantification for the CFO's reserve-setting, the audit committee's capital-adequacy posture, the insurer's underwriting submission, and the regulator's enforcement-readiness inquiry.
Five 2026 forces converge to make AI risk quantification a board-level requirement. The first is the EU AI Act's Article 9(2) requirement that "the risk management system shall consist of a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system" and Article 9(3) requirement that risks be "estimated and evaluated", language the EU AI Office's emerging guidance interprets to include quantitative estimation where feasible. The second is the Federal Reserve SR 11-7 and Bank of England PRA SS1/23 governance pillar, which expect model risk to be quantified for capital-adequacy purposes, and AI models inherit that expectation as they enter the model inventory. The third is Solvency II ORSA (Own Risk and Solvency Assessment) for insurers, which now expects AI operational risk to be quantified in the operational-risk capital module. The fourth is the captive and commercial insurance market: cyber insurers, E&O insurers, and the emerging AI-specific policies of 2026 (Munich Re's AI policy, Coalition's algorithmic-liability rider, Beazley's AI E&O) underwrite on quantified loss exposure submitted by the insured, not on qualitative heat-maps. The fifth is the audit committee's fiduciary expectation: the directors are personally liable under Caremark-style derivative actions for "utterly failing to implement any reporting or information systems or controls", and a non-quantified AI risk program is increasingly characterized in plaintiff's filings as a failure of information systems.
The result is that the 2026 L4 AI governance program produces an Annualized Loss Exposure (ALE) figure for the AI portfolio, anchored to a methodology the regulator and auditor recognize. That methodology, in 2026, is overwhelmingly FAIR (Factor Analysis of Information Risk), originally codified by Jack Jones and standardized by The Open Group as Open FAIR. FAIR is the de facto quantitative risk standard for cyber risk and has been extended in 2025-2026 to AI scenarios by the FAIR Institute's AI Workstream and by the major implementation tools (RiskLens, Archer, ServiceNow IRM, and open-source Stan/PyMC Bayesian-style libraries).
FAIR Methodology and AI-Specific Adaptations
FAIR decomposes risk into two top-level factors: Loss Event Frequency (LEF) and Loss Magnitude (LM). Risk = LEF × LM, expressed as the expected loss per unit time (typically per year, yielding Annualized Loss Exposure). LEF and LM each decompose further. LEF = Threat Event Frequency (TEF) × Vulnerability. TEF is how often the threat actor or threat condition produces an attempt; Vulnerability is the probability the attempt succeeds given the firm's controls. LM = Primary Loss + Secondary Loss. Primary Loss is the direct consequence to the firm; Secondary Loss is the consequence from secondary stakeholders (customers, regulators, employees, shareholders) reacting to the primary loss.
The AI-specific adaptation of FAIR substitutes AI-relevant inputs into each factor. Threat Event Frequency for AI is the rate at which the AI system encounters a condition that could produce a loss event: the red-team finding rate per system per year (calibrated from red-team operating cadence, lessons 075-078); the threat-intel feed rate (jailbreak research velocity, novel adversarial techniques per quarter, OWASP LLM Top 10 and MITRE ATLAS update cadence); the historical incident rate (the firm's own incident log and industry benchmarks from the FAIR Institute's AI loss-event database); and the sector-benchmark rate (financial services, healthcare, employment use cases produce different baseline TEFs). For a consumer-direct Annex III §5(b) credit scoring system, TEF for fairness-disparity discovery is typically 0.5-2.0 events per year per system in 2026, drawn from the firm's own audit cadence plus the regulator's enforcement-action rate against similar systems.
Vulnerability for AI is the probability that a threat event becomes a loss event given the firm's controls. The AI-specific drivers are eval coverage gap (the fraction of OWASP LLM Top 10 and Annex IV harm categories not covered by the firm's eval suite, lesson 044); mitigation maturity (the L1-L5 maturity score of the controls covering each harm class, model-card completeness, system-card completeness, red-team coverage, monitoring telemetry, incident-response readiness); and control effectiveness (the operating-effectiveness percentage of controls tested in the last audit cycle). A mature 2026 program with 85%+ eval coverage, L3+ mitigation maturity, and 90%+ control operating effectiveness will report Vulnerability in the 0.10-0.25 range for a typical Annex III scenario; a gapped program operates at 0.50-0.80.
Primary Loss for AI is the direct cost when a loss event materializes. The AI-specific components: direct response cost (incident-response team time, forensic investigation, root-cause analysis, technical remediation); customer-remediation cost (refunds, re-decisioning, individual notice cost, Article 86 right-to-explanation litigation defense); regulatory cost (Article 99 administrative fine, supervisory-authority cooperation cost, Article 73 serious-incident reporting workload, sectoral regulator notifications); and Article 27 FRIA / Article 86 individual-rights remediation cost where natural persons have suffered fundamental-rights impact. Article 99 fine inputs use the tier caps: €35M / 7% turnover for Article 5 prohibited; €15M / 3% for Articles 9, 17, 26, 73, 27 deployer-side failures; €7.5M / 1% for misleading information, but the realistic-case input is typically a fraction of the cap calibrated to comparable enforcement precedent (GDPR Article 83 enforcement history is the closest available proxy, with first-time-offender financial-services fines typically landing in the 0.5-3% of turnover band).
Secondary Loss for AI is the consequence from secondary stakeholders, and for consumer-facing AI it dominates Primary Loss by a 2-5x multiple. The components: reputation-driven customer churn (the customer-acquisition-cost replacement multiplied by the expected churn-rate uplift post-incident); competitive impact (the revenue loss to competitors during the disclosure window); insurance premium increase (the multi-year premium uplift after a covered claim); executive turnover (the recruiting and onboarding cost of replacing a CEO/CRO/AI Officer who resigns or is removed post-incident); and remediation operations cost (the sustained engineering, legal, communications, and customer-service time required for 6-18 months post-incident). Mature 2026 FAIR-AI programs estimate Secondary Loss explicitly with a triangular or PERT distribution and rarely set it below 1.5x Primary Loss for a consumer-direct system; for a B2B internal system, Secondary Loss may fall below Primary because reputation impact is bounded.
The mechanics: each factor is expressed as a probability distribution, not a point estimate. The mature 2026 FAIR-AI practice uses triangular (min/most-likely/max) or PERT (min/most-likely/max with concentration parameter) distributions for SME elicitation, and shifts to lognormal or empirical distributions where historical data supports. A Monte Carlo simulation draws 10,000 (or more) samples from each input distribution, computes LEF × LM for each draw, and produces an output distribution of loss exposure. The output is reported as the mean (ALE), median (ALE_50), and key percentiles (ALE_75, ALE_90, ALE_95, ALE_99) with the full loss-exceedance curve plotted for the audit committee.
Five AI-Specific Loss-Event Scenarios Quantified
The 2026 mature FAIR-AI program quantifies the AI portfolio at the scenario level, five to fifteen named scenarios per portfolio, with each scenario expressing a specific threat-system-impact combination. Five scenarios commonly appear in 2026 financial-services and consumer-AI portfolios, illustrated with sample numbers calibrated to a €10B-turnover diversified firm:
- Scenario 1 - Annex III §5(b) credit-scoring fairness disparity. The firm's AI-driven creditworthiness model is discovered (by internal audit, regulator inspection, plaintiff's expert, or self-disclosure) to produce selection-ratio disparity below 0.85 on protected groups. TEF: 0.5-1.5 events per year (triangular: 0.5 / 1.0 / 1.5). Vulnerability: 0.20-0.40 given the firm's eval coverage and bias-testing cadence (triangular: 0.20 / 0.30 / 0.40). LEF = 0.10-0.60 per year. Primary Loss: regulator fine €5M-€25M-€60M (triangular, calibrated to Article 99(3) tier and GDPR Article 83 precedent); class-action exposure €2M-€10M-€30M; customer-remediation cost €0.5M-€2M-€5M; Article 86 individual-rights defense cost €0.3M-€1M-€3M; direct response cost €0.5M-€1.5M-€4M. Total Primary Loss mean ≈ €15-25M per event. Secondary Loss multiplier 2-3x for consumer-direct: total LM per event mean ≈ €40-70M. ALE mean ≈ €4-15M per year for this single scenario.
- Scenario 2 - Article 73 serious-incident reported late. The firm experiences a serious incident on a deployed agent (per Article 3(49) serious-incident definition) and the 15-day reporting window slips because the incident-response playbook is inadequately drilled. TEF: 0.3-0.8 events per year. Vulnerability: 0.30-0.60 given Article 73 readiness maturity. LEF = 0.09-0.48 per year. Primary Loss: late-reporting fine €1M-€5M-€15M; supervisory-authority enhanced surveillance cost €0.5M-€2M-€5M; remediation operations €0.3M-€1M-€3M. Secondary Loss: reputation and customer-confidence impact €2M-€8M-€20M. LM mean ≈ €15-25M per event. ALE mean ≈ €1.5-6M per year.
- Scenario 3 - Foundation-model vendor upstream change causing performance regression. The firm's primary foundation-model provider issues a silent model update or deprecates an endpoint, causing a performance regression on a high-volume production workload (per the GPAI provider obligations under Article 53 and the vendor-risk policy of lesson 057). TEF: 1.0-3.0 events per year (high. These happen multiple times per year in 2026). Vulnerability: 0.20-0.50 given the firm's drift-monitoring and fallback-routing maturity. LEF = 0.20-1.50 per year. Primary Loss: revenue loss during regression window €1M-€5M-€20M; retraining and re-validation cost €0.5M-€2M-€6M; customer SLA penalty €0.2M-€1M-€4M; engineering remediation €0.3M-€1.5M-€4M. Secondary Loss: customer churn risk €1M-€4M-€15M. LM mean ≈ €10-25M per event. ALE mean ≈ €2-15M per year.
- Scenario 4 - Agent tool-misuse generating unjustified refunds. A Tier 3 customer-service agent with refund-authorization tool access is exploited (via prompt injection, social engineering, or memory poisoning per OWASP Agentic Top 10) and issues unjustified refunds at scale before detection, the lesson 066 worked-example pattern. TEF: 1.0-4.0 events per year (these are frequent in 2026 for firms operating agents). Vulnerability: 0.10-0.30 for a mature program with allowlist, transaction-cap, and anomaly-detection controls. LEF = 0.10-1.20 per year. Primary Loss: direct refund loss €0.5M-€2M-€8M; investigation and forensic cost €0.2M-€0.8M-€2M; control buildout post-event €0.3M-€1.5M-€4M. Secondary Loss: customer-trust impact bounded for internal-impact event €0.5M-€2M-€6M. LM mean ≈ €4-10M per event. ALE mean ≈ €0.4-12M per year.
- Scenario 5 - ISO 42001 Stage 2 major finding causing certificate suspension. The firm's external certification body issues a major finding at Stage 2 audit, suspending the ISO 42001 certificate pending remediation (per lesson 070 audit-readiness framework). TEF: 0.2-0.5 events per year (these are relatively rare but consequential). Vulnerability: 0.20-0.50 depending on AIMS maturity at audit time. LEF = 0.04-0.25 per year. Primary Loss: remediation cost €0.5M-€2M-€6M; re-audit fees €0.1M-€0.3M-€0.8M; certificate-loss period business impact €0.5M-€2M-€8M. Secondary Loss: customer-RFP exclusion during suspension €1M-€4M-€12M; competitive impact and reputation €0.5M-€2M-€8M. LM mean ≈ €6-15M per event. ALE mean ≈ €0.3-4M per year.
The portfolio aggregate is the sum of scenario-level ALE draws across the Monte Carlo simulation: the simulator draws from each scenario's LEF and LM distributions, sums them per simulation run, and produces the portfolio loss-exceedance curve. Critically, scenarios are not treated as fully independent in 2026 mature programs: correlation matrices capture the dependency that, for example, an Article 73 incident and a fairness-disparity event are correlated through shared upstream causes (the same eval-coverage gap drives both). A 0.3-0.5 correlation between scenarios is typical; the simulator uses copula-based draws or Cholesky decomposition to inject correlation.
Monte Carlo Workflow and Loss-Event Reserve Modeling
The mature 2026 FAIR-AI Monte Carlo workflow runs in five steps. Step 1, scenario elicitation. The AI Risk Officer convenes a workshop with named SMEs (red-team lead, model-validation lead, incident-response lead, FRIA program lead, vendor-risk lead, business-line owner, legal counsel) and elicits the triangular or PERT distributions for each input. SMEs are required to have completed Hubbard-style 90% confidence interval calibration training (described in the next section). The workshop produces a documented input register with each SME's name, the input estimated, the distribution, and the rationale.
Step 2, simulation. The team runs 10,000 simulations (a 2026 default; sophisticated programs run 100,000+) using one of the standard tools: Open FAIR's reference implementation, RiskLens, Archer IRM, ServiceNow IRM, or open-source Stan/PyMC Bayesian-style packages. Each simulation draws from each input distribution, computes LEF × LM per scenario, applies correlation between scenarios, and sums to a portfolio loss for that simulation. The output is 10,000 portfolio-loss values that form the empirical loss distribution.
Step 3, output reporting. The simulator produces the standard FAIR outputs: ALE (mean), ALE_50 (median), ALE_75, ALE_90, ALE_95, ALE_99 percentiles, the loss-exceedance curve (probability of loss exceeding €X for varying X), and scenario decomposition (what fraction of the ALE each scenario contributes). The mature 2026 audit-committee deliverable plots the loss-exceedance curve as the primary chart, with the ALE_50 and ALE_95 marked, the firm's risk appetite (from the AIRA, lesson 074) overlaid as a horizontal line, and the prior-quarter ALE shown for trending.
Step 4, reserve modeling. The CFO's question, how much to reserve, is answered by selecting a percentile of the loss distribution. The 2026 mature practice uses ALE_95 as the reserve target: the 95th percentile of expected annual loss, meaning the firm holds enough reserve to cover all loss outcomes except the worst 5%. The reserve calculation: ALE_95 minus existing insurance coverage minus existing capital allocation for AI = incremental reserve requirement. For a portfolio with ALE_95 of €11.8M, €6M cyber insurance covering AI scenarios, and €0 existing AI-specific capital allocation, the incremental reserve is €5.8M.
Step 5, sensitivity and mitigation ROI. The simulator re-runs with each candidate mitigation applied (e.g., expanding eval coverage from 60% to 85% reduces Vulnerability across multiple scenarios; investing in fallback routing reduces TEF on Scenario 3; tightening agent allowlists reduces Vulnerability on Scenario 4). The change in ALE_95 quantifies the mitigation's risk-reduction value. The mitigation cost divided by ALE_95 reduction yields the mitigation ROI, the audit committee compares each candidate mitigation's ROI to capital-allocation alternatives and ranks the portfolio.
Insurance gap analysis is the related output. The AI portfolio is matched against existing policies: cyber (typically covers data-breach and ransomware scenarios but ambiguous on AI fairness-disparity or hallucination-driven harms); E&O / professional indemnity (covers professional-services failures, increasingly with AI carve-outs or AI-specific endorsements in 2026); product liability (covers physical-product failures, generally not applicable to non-embodied AI); and AI-specific policies (Munich Re, Coalition, Beazley, AIG, and a growing list of carriers offering algorithmic liability and AI E&O in 2026). The gap analysis names each scenario, the policy that covers it, the policy limit, the policy exclusions, the sub-limits, and the residual exposure the firm carries. The output is a one-page gap-analysis table the audit committee uses to drive insurance procurement and reserve allocation decisions.
Capital allocation tradeoff. The CFO's reserve decision is one of three capital allocation choices: mitigation investment (reduces ALE_95 directly, with mitigation-ROI calculation), insurance premium (transfers risk to carrier, capped by policy limit and subject to exclusions), and reserve set-aside (self-insures against residual). The optimal portfolio mix balances all three. The mature 2026 audit-committee briefing presents the current allocation, the candidate alternatives, and the recommended rebalancing, typically expressed as a stacked-bar chart showing the three components summing to total AI risk capital.
Frequency of re-run. The mature 2026 FAIR-AI program re-runs the Monte Carlo simulation quarterly at minimum, with three trigger-based interim refreshes: (1) any red-team finding that materially shifts a Vulnerability distribution (e.g., a previously-unmodeled jailbreak class against a Tier 3+ agent); (2) any change in scope of a high-contribution scenario (new Annex III system added, agent autonomy tier transition, foundation-model vendor change); (3) any regulatory event materially shifting Primary Loss distributions (a new enforcement action establishing fine-band precedent, an Article 99 Implementing Act clarifying penalty calculation, a Member State sectoral overlay). The Second-Line AI Risk Officer maintains the simulation environment and the input register; the Third-Line Internal Audit tests the simulation evidence trail in the trailing-12-month audit cycle.
Calibration Discipline and Common Mistakes
The FAIR-AI Monte Carlo output is only as good as the input distributions, and the input distributions are only as good as the SMEs providing them. The 2026 mature program enforces Hubbard-style calibration discipline. Douglas Hubbard's How to Measure Anything demonstrates that uncalibrated SMEs systematically express 90% confidence intervals that contain the true value only 40-60% of the time. They are overconfident. Calibration training, typically a two-hour exercise with trivia questions, immediate feedback, and iteration until the SME's 90% confidence intervals contain the true value 88-92% of the time, corrects this. The mature 2026 FAIR-AI program requires every SME providing inputs to be calibrated within the trailing 12 months, with the calibration certificate stored as part of the FAIR audit trail.
Expert elicitation is documented in three artifacts: the named SME, the elicited input (e.g., "TEF for Scenario 1: triangular(0.5, 1.0, 1.5)"), and the rationale (the SME's reasoning, the data sources, the calibration anchor). The mature 2026 program records elicitation sessions, transcribes the rationale, and the AI Risk Officer reviews for groupthink bias, anchoring bias, and availability heuristic. The Delphi method, multi-round anonymous elicitation with feedback between rounds, is used for high-stakes scenarios where SME divergence is large.
The most common 2026 FAIR-AI mistakes are predictable and fixable. (1) Using cyber FAIR templates without AI-specific TEF/Vuln adjustments. Cyber FAIR libraries (the Open FAIR loss-event catalog, the FAIR Institute's cyber scenarios) do not capture AI-specific threat events, fairness disparity, hallucination, prompt injection, foundation-model vendor change, and their TEF/Vuln defaults are calibrated to cyber operating environments. Fix: build an AI-specific scenario library and elicit AI-specific TEF/Vuln from AI SMEs. (2) Ignoring secondary loss. Cyber FAIR practice often treats Secondary Loss as a small addition; for consumer-facing AI, Secondary Loss dominates Primary Loss by 2-5x. Fix: explicitly model Secondary Loss with its own distribution and treat it as the primary contributor to LM for consumer-direct scenarios. (3) Point estimates without confidence intervals. The CRO presents "AI loss exposure is €5M", and the audit committee anchors on a number with no uncertainty. Fix: always present a distribution with the median and the 90th-95th percentiles. (4) Not refreshing as red-team findings change vulnerability assumption. The Vulnerability distribution is anchored to the eval coverage and mitigation maturity at a point in time; when red-team finds reveal new exposure, the Vulnerability distribution shifts upward and the ALE shifts with it. Fix: re-run the simulation quarterly tied to the red-team reporting cadence. (5) Ignoring Annex III §4-§8 sector-specific exposure. The penalty exposure differs by Annex III category and sector; treating Annex III as a single bucket loses calibration. Fix: parameterize by Annex III sub-section. (6) Ignoring regulatory penalty caps. Article 99(2) caps at €35M / 7%; Article 99(3) at €15M / 3%; Article 99(5) at €7.5M / 1%. A Primary Loss distribution that draws from a fine distribution exceeding the cap is mis-specified. Fix: truncate the fine distribution at the applicable cap and apply turnover ceiling.
Regulatory cross-walks. EU AI Act: Article 9 (the risk management system, FAIR-AI is the quantitative engine); Article 17 (QMS, the FAIR-AI output is QMS evidence of risk estimation); Article 26 (deployer obligations, the FAIR-AI portfolio includes deployer scenarios); Article 73 (serious incident, incident inputs feed FAIR-AI TEF); Article 99 (penalty caps, truncate Primary Loss distributions). NIST AI RMF: Govern 2.1 (roles and responsibilities for risk estimation, named SMEs); Govern 3.1 (workforce diversity in elicitation, Delphi panels); Manage 1.1 (risk treatment decisions, FAIR-AI mitigation ROI); Manage 2.1 (risk monitoring, quarterly re-run). ISO/IEC 42001: Annex A.5 (risk assessment and treatment, FAIR-AI is the assessment); Clause 6 (planning, FAIR-AI feeds AIMS planning). ISO/IEC 23894 (AI risk management process, FAIR-AI implements the ISO 23894 risk-estimation step). SR 11-7: capital-adequacy tie-in, the bank's model risk capital allocation absorbs AI model risk via FAIR-AI estimation. Solvency II ORSA: operational-risk capital module, the insurer's ORSA submission includes AI operational risk quantified via FAIR-AI.
Acme Worked Example - 2026 Q2 AI-FAIR Briefing
Acme Inc. (€10B turnover diversified financial-services firm, same firm as lesson 074 AIRA worked example) ran its first end-to-end AI-FAIR exercise in April-May 2026 in preparation for the June audit committee. The AI Risk Officer convened a five-day elicitation workshop with eight SMEs (red-team lead, model-validation lead, two business-line risk officers from retail credit and wealth management, FRIA program lead, vendor-risk lead, incident-response lead, Group Compliance). All eight had completed Hubbard calibration training in March; their calibration certificates were filed.
The team scoped five scenarios, the five lesson scenarios above, adapted with Acme-specific inputs. The elicited distributions ran through Open FAIR's reference implementation with 10,000 simulations. Scenario-level ALE means (single-scenario annualized expected loss, before correlation): Scenario 1 (Annex III §5(b) credit fairness), €5.2M; Scenario 2 (Article 73 late reporting), €2.8M; Scenario 3 (foundation-model vendor regression), €4.1M; Scenario 4 (agent tool-misuse), €3.4M; Scenario 5 (ISO 42001 Stage 2 finding), €1.6M. Portfolio sum-of-means (uncorrelated): €17.1M.
Applied correlation between scenarios (0.3 average pairwise correlation, derived from shared upstream causes, eval-coverage gap, AIMS maturity) reduced the portfolio variance but preserved the mean. The Monte Carlo output: portfolio ALE mean €4.2M (note: this is below the sum-of-means because the LEF × LM products average across draws; the high tail dominates). ALE_50 (median) €3.5M. ALE_75 €6.8M. ALE_90 €9.2M. ALE_95 €11.8M. ALE_99 €22.4M.
The audit-committee deliverable was a six-slide briefing. Slide 1: the loss-exceedance curve with ALE_50, ALE_95, and the AIRA risk-appetite line overlaid. Slide 2, scenario decomposition pie chart (Scenario 1 contributed 31% of ALE; Scenario 3 contributed 24%; Scenario 4 contributed 20%; Scenario 2 contributed 16%; Scenario 5 contributed 9%). Slide 3: sensitivity table (5 candidate mitigations with cost, ALE_95 reduction, and ROI; the highest-ROI mitigation was expanding eval coverage from 65% to 90% at €0.8M cost reducing ALE_95 by €3.2M, ROI 4.0x). Slide 4, insurance gap table (cyber policy covered Scenarios 2-3 partially with €4M sub-limit; E&O covered Scenario 1 partially with €2M sub-limit; emerging AI E&O quote from Beazley would add €5M coverage at €0.4M annual premium covering Scenarios 1 and 4). Slide 5, capital allocation recommendation (€0.8M mitigation investment in eval-coverage expansion; €0.4M annual premium for Beazley AI E&O bringing total insurance to €10M; €1.8M residual reserve set-aside; total AI risk capital €13.0M against ALE_95 of €11.8M post-mitigation €8.6M). Slide 6 - Q3 2026 governance asks (board AI subcommittee ratification of the AI-FAIR methodology, quarterly re-run cadence, Hubbard calibration program annual refresh).
The audit committee chair's response: "Now I can answer the regulator." The CFO's response: "Now I can answer the auditor." The captive insurer underwriter's response (one week later): "Now I can write the policy." The AI-FAIR exercise had converted a heat-map into a balance-sheet number, and converted a balance-sheet number into a regulatory-defensible quantification.
Audit-defensibility evidence. When Acme's external ISO 42001 Stage 2 auditor (Schellman) arrived in November 2026 to test Annex A.5 risk assessment and treatment, the evidence package was complete: the FAIR-AI methodology document (50 pages, board AI subcommittee ratified June 2026); the SME calibration certificates (eight, dated March 2026); the scenario register (five named scenarios with documented input distributions and rationale); the Monte Carlo simulation runs (Q2 and Q3 2026 archived with input/output reconciliation); the audit-committee briefing decks (June and September 2026 signed and dated); the mitigation-ROI tracker (showing the eval-coverage investment progressing from 65% baseline to 88% by November); the insurance gap analysis with carrier quotes; and the capital-allocation memo signed by the CFO. The auditor noted the FAIR-AI evidence as "operating effectiveness of AIMS Clause 6 planning and Clause 9 performance evaluation" with no findings in the AI risk-assessment scope.
Regulator-readiness outcome. When the Federal Reserve examiner arrived at Acme's parent bank in February 2027 for the SR 11-7 model risk capital adequacy review, the AI-FAIR portfolio quantification was the lead artifact for the AI sub-section. The examiner's interview asked: how were the scenarios defined; who provided the inputs; how were the SMEs calibrated; how often is the simulation refreshed; how does the output drive capital allocation; how does the output integrate with the bank's operational risk capital module; how does the AI-FAIR portfolio reconcile to the heat-map; how is independence between First-Line modelers and Second-Line risk officers preserved. Each question had a documented answer, and the examiner's exit interview cited the AI-FAIR program as "leading practice for the consolidated banking sector in 2026-2027."
Key Takeaways
- The 2026 governance ecosystem requires AI risk to be quantified in dollar/euro terms: the heat-map remains necessary for AIGC operating cadence but is no longer sufficient for the CFO, the audit committee, the insurer, or the regulator (SR 11-7, Solvency II ORSA, Article 9, fiduciary Caremark exposure all converge here).
- FAIR (Factor Analysis of Information Risk) is the 2026 de facto quantitative standard, adapted to AI scenarios: Risk = LEF × LM, with LEF = TEF × Vulnerability and LM = Primary Loss + Secondary Loss; each factor expressed as a probability distribution, not a point estimate.
- AI-specific TEF draws from red-team finding rates, threat-intel feeds, historical incidents, and sector benchmarks; AI-specific Vulnerability draws from eval coverage gap, mitigation maturity, and control effectiveness; AI-specific Primary Loss includes Article 99 fines, customer remediation, Article 86 individual rights, and regulator cost; AI-specific Secondary Loss (reputation, churn, executive turnover, insurance premium increase) typically dominates Primary Loss by 2-5x for consumer-direct systems.
- The Monte Carlo workflow runs in five steps: scenario elicitation with calibrated SMEs; 10,000-simulation run using Open FAIR / RiskLens / Archer / Stan/PyMC; output reporting with ALE_50, ALE_95, loss-exceedance curve; reserve modeling at the ALE_95 percentile; sensitivity and mitigation-ROI analysis.
- Five AI-specific loss-event scenarios anchor the typical 2026 portfolio: Annex III §5(b) credit fairness disparity; Article 73 serious-incident late reporting; foundation-model vendor upstream regression; agent tool-misuse generating unjustified refunds; ISO 42001 Stage 2 major finding causing certificate suspension: each with triangular distributions on TEF, Vulnerability, Primary Loss, and Secondary Loss components.
- Reserve modeling answers the CFO's question: ALE_95 minus existing insurance minus existing capital = incremental reserve requirement; the audit-committee briefing presents loss-exceedance curve + scenario decomposition + sensitivity + insurance gap + capital allocation recommendation.
- Calibration discipline is the input-quality control: Hubbard-style 90% confidence interval training for every SME; documented expert elicitation with named SME, input, and rationale; Delphi method for high-stakes divergent scenarios; quarterly re-run tied to red-team reporting cadence.
- Six common 2026 FAIR-AI mistakes: using cyber FAIR templates without AI adjustments; ignoring Secondary Loss for consumer AI; point estimates without intervals; not refreshing as red-team changes Vulnerability; ignoring Annex III §4-§8 sector-specific exposure; ignoring Article 99 penalty caps when drawing fine distributions, each fixable in a single Monte Carlo refresh cycle.
Skill.re