Developer docs
API playgroundTry for free, no card

Search company profiles

Cyber Risk Institute

Full company profile

uuid000hxvf

Namestring
Cyber Risk Institute
Legal namestring
Cyber Risk Institute
Company typeenum
Private
Founded yearint
2022
Descriptiontext

Cyber Risk Institute (CRI) is a Washington, D.C.-based not-for-profit 501(c)(6) standards development organization that builds and maintains cybersecurity and AI risk frameworks for the global financial services industry. CRI originated as a Profile development effort under the Financial Services Sector Coordinating Council (FSSCC) beginning in 2016 and was spun out as an independent entity in 2022. Its core asset is the CRI Profile, a streamlined version of the NIST Cybersecurity Framework v2.0 comprising 318 diagnostic statements with 40 mappings to global regulatory and supervisory references. The product family has expanded to include the Cloud Profile (cloud security extension), the Financial Services AI Risk Management Framework (FS AI RMF) with 230 control objectives, a member-exclusive Maturity Model for benchmarking, and translations in Japanese, Spanish, and Portuguese.

The platform architecture is framework-centric rather than software-centric: CRI packages curated control catalogs, diagnostic questions, regulatory mappings, and assessment instruments that financial institutions map their internal controls and audit processes to. Supporting tools include an AI Adoption Stage Questionnaire, a Risk and Control Matrix, and integrations with standards such as MITRE ATT&CK. CRI distributes the core framework as a free download to drive adoption and operates member-exclusive products and a forthcoming CRI Marketplace for aligned third-party products, plus Innovator and Affiliate licensing programs.

CRI's revenue mechanics are diversified across membership dues (annual subscriptions from financial institutions and trade associations), commissions from CRI Marketplace, and licensing fees from the Innovator and Affiliate programs. It serves 130+ member organizations spanning large U.S. and global banks, payment networks and issuers, capital markets and trust firms, exchanges, crypto/fintech, and major industry associations (SIFMA, FS-ISAC, ABA, Bank Policy Institute). CRI is governed by a cross-industry board and operates with a small (1–10) staff footprint, with senior leadership and contributor participation drawn from member institutions.

Short descriptiontext

Cyber Risk Institute is a Washington, D.C.-based non-profit standards body that develops the CRI Profile and related frameworks (Cloud, FS AI RMF, Maturity Model) to help global financial institutions manage cyber and AI risk under recognized regulatory mappings.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersWashington, United States
HQ citystring
Washington
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cybersecurity risk management, financial sector frameworks, regulatory compliance standards, AI risk management, cyber assessment frameworks
Industry6 codes
1AI Governance, Risk & Compliance (GRC) Platforms
CodeHDAAAMAAPrimaryYes
2Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies)
CodeHDAEANAEPrimaryNo
3Model Governance, Risk & Compliance (GRC) Platforms
CodeHDAAAKAAPrimaryNo
4Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001)
CodeHDAAAMAEPrimaryNo
5Responsible AI, AI Governance & Compliance Services
CodeBPAEAHAJPrimaryNo
6Critical Infrastructure Protection (CIP) & NERC-CIP Compliance
CodeHDADAJACPrimaryNo
NAICS code1 code
  • Security Systems Services (except Locksmiths)561621
Product category
Cybersecurity Risk Management Frameworks
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model3 records
1Membership Dues
TypeSubscription Recurring
Description

CRI generates revenue through annual membership dues paid by financial institutions. Membership is at the organizational level. Annual participation dues are set by the Board of Directors and available upon request. Explorer tier is free, Full Member has a low-cost annual fee.

cyberriskinstitute.org
2CRI Marketplace
TypeMarketplace Commission
Description

The CRI Marketplace is a hub for tools, products, and services designed to help financial institutions adopt and implement CRI resources. Third-party tool providers and consulting firms offer products through this marketplace.

cyberriskinstitute.org
3Innovator and Affiliate Programs
TypeLicensing Royalties
Description

Non-financial institutions can join as Innovators (Basic or Premium levels) or Affiliates, gaining rights to integrate CRI tools into their offerings for a fee.

cyberriskinstitute.org
Marketing channels6 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Pricing details2 tiers
1Free tier with basic access to CRI Profile
ModelFreemiumBilling cadenceOthers
Notes

Free access to the CRI Profile for download. Includes access to the Profile but not the Maturity Model or member-only resources.

cyberriskinstitute.org
2Full Member with comprehensive access and participation rights
ModelSubscriptionBilling cadenceAnnual
Notes

Annual fee set by Board of Directors, available upon request. Includes Maturity Model, exclusive member workshops, participation in working groups, and access to member-only mappings and tools.

cyberriskinstitute.org
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 4 records shown
1CRI Profile
Description

Cybersecurity and technology framework built by and for the financial sector, based on NIST CSF, connecting cyber best practices with regulatory expectations from around the world.

cyberriskinstitute.org
+3 more records
Core offering1 text field

CIRI develops and maintains cybersecurity, cloud security, and AI risk management frameworks tailored for the global financial services industry. The core CRI Profile harmonizes 3,500+ regulatory expectations into 318 diagnostic statements mapped to 40+ standards and regulations. Complementary offerings include the Cloud Profile (cloud security extension), the FS AI RMF (230 Control Objectives for AI risk), and the member-exclusive Maturity Model for peer benchmarking.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 58% reduction in assessment questions for Impact Tier 4 firms compared to other widely used assessments
+3 more records
Product overview1 text field

The Cyber Risk Institute offers a suite of cybersecurity, technology, and AI risk management products for the financial services industry. The core offering consists of the CRI Profile (a NIST-based cybersecurity framework harmonizing 3,500+ regulatory expectations), the Cloud Profile (an extension for cloud security), and the FS AI RMF (an AI risk management framework with 230 control objectives). Supporting products include the Maturity Model (for peer benchmarking, member-exclusive), Profile Translations (Japanese, Spanish, Portuguese), and various companion guides and mapping documents. The products work together as an integrated risk management ecosystem, enabling financial institutions to assess, benchmark, and report on cybersecurity and AI risks across global regulatory jurisdictions.

Product and service7 records
1CRI Profile
CategoryCybersecurity Risk Management Framework
Description

A financial-sector-specific cybersecurity and technology risk management framework built on NIST Cybersecurity Framework v2.0, harmonizing 3,500+ regulatory expectations into 318 diagnostic statements with approximately 40 mappings to global standards and regulations. For financial institutions of all sizes.

2Cloud Profile
CategoryCloud Security Framework
Description

An extension of the CRI Profile developed in collaboration with Cloud Service Providers and the Cloud Security Alliance, providing actionable cloud security guidance including a shared responsibility checklist implementation tool. Aligned with NIST CSF v2.0 and integrated with the CSA Cloud Control Matrix. For financial institutions implementing or strengthening cloud technologies.

3Financial Services AI Risk Management Framework (FS AI RMF)
CategoryAI Risk Management Framework
Description

An industry-led, sector-specific AI risk management framework with 230 Control Objectives developed through public-private collaboration with 100+ financial institutions. Includes an AI Adoption Stage Questionnaire, Risk and Control Matrix, Guidebook, and Control Objective Reference Guide. For financial institutions deploying or overseeing AI systems.

4CRI Maturity Model
CategoryCybersecurity Assessment Tool
Description

An assessment tool aligned with the CRI Profile and NIST CSF that quantitatively scores responses at the diagnostic-statement level, enabling structured benchmarking of cybersecurity maturity across institutions. Available exclusively to CRI Full Members.

5CRI Profile Translations
CategoryFramework Localization
Description

Translated versions of the CRI Profile and Guidebook in Japanese, Spanish, and Brazilian Portuguese to enable consistent adoption across Asia-Pacific and Latin America. Includes Japanese translation by NRI Secure Technologies and Spanish/Portuguese translations sponsored by Mastercard.

6CRI Marketplace
CategoryMarketplace Platform
Description

A hub that aggregates tools, products, and services from third-party providers and consulting firms to help financial institutions adopt and implement CRI resources at every stage of their cybersecurity program. For financial institutions seeking implementation support and the partner firms that serve them.

7CRI Membership Program
CategoryMembership Subscription
Description

Annual organizational membership providing access to the Maturity Model, exclusive member workshops, participation in working groups, and member-only mappings and tools. Includes Explorer (free) and Full Member (paid) tiers. For financial institutions.

Scale indicator8 records

Each record includes

Type, Value, Description, Source

Partnership11 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-02-12
Description

CRI developed the FS AI RMF in coordination with FSSCC as part of a larger sector-wide initiative focused on responsible AI adoption and governance. The FS AI RMF was developed through a collaborative effort by more than 100 financial institutions coordinated through FSSCC.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Collaboration with CSA to integrate the Cloud Security Alliance's Cloud Control Matrix (CCM) into the CRI Cloud Profile. CSA collaborated with financial institutions and major cloud service providers to develop the Cloud Profile.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Collaboration to develop mapping connecting CRI Profile to MITRE ATT&CK Framework, helping financial institutions bring together governance, regulatory expectations, and threat mitigations.

Strategic tierCoreTypeImplementation/ SI/ Consulting Partner
Description

EY provided expert support in updating Profile v2.1 and developing the DORA implementation guide for CRI Profile users.

Strategic tierCoreTypeImplementation/ SI/ Consulting Partner
Description

KPMG contributed to the development of the CRI Maturity Model, which provides a mechanism to quantitatively score responses at the diagnostic statement level.

Strategic tierCoreTypeImplementation/ SI/ Consulting Partner
Description

NRI Secure Technologies translated the CRI Profile v2.0 into Japanese, helping financial institutions in Japan leverage the benefits of the streamlined self-assessment framework.

Strategic tierCoreTypeImplementation/ SI/ Consulting Partner
Description

Mastercard sponsored the Spanish and Portuguese translations of the CRI Profile and Guidebook, supporting broader adoption and consistent implementation across Latin America.

Strategic tierCoreTypeImplementation/ SI/ Consulting Partner
Description

BGBG, a Mexican law firm, completed the Spanish and Portuguese translations of the CRI Profile and Guidebook, released at a launch event in Mexico City.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Treasury, as Sector Risk Management Agency for financial services, collaborated with CRI on developing precision time resiliency controls into the CRI Profile to facilitate meeting requirements in Executive Order 13905. Treasury also acknowledged CRI's work in AI risk management frameworks.

Strategic tierCoreTypeImplementation/ SI/ Consulting Partner
Description

CRI works with BCG Platinion to identify priority integration opportunities and map regulations and frameworks to the Profile on a rolling basis.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

The FS AI RMF was developed in coordination with U.S. Treasury, which released it as part of the President's AI Action Plan. Treasury released two AI risk management tools including the FS AI RMF developed through public-private partnership.

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight7 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Nonprofit 501(c)(6)-style global standards body that develops and maintains the PCI DSS for payment security — the closest analog to CRI in business model (standards development organization governed by members), funding mechanism (membership dues + fees), and role (harmonizing regulatory and industry expectations into a single actionable framework adopted by financial-adjacent institutions).

TypeDirect peer
Description

Nonprofit organization that maintains the Cloud Controls Matrix (CCM) and STAR program; CRI's Cloud Profile was co-developed with CSA, and the two compete/collaborate in defining authoritative cloud-security control sets for regulated industries including financial services.

TypeDirect peer
Description

Nonprofit that publishes the CIS Critical Security Controls (now mapped into CRI Profile v2.1) and operates a community-driven model similar to CRI's 500+ contributors and working-group approach to voluntary consensus standards.

TypeDirect peer
Description

Nonprofit standards and certification organization that harmonizes multiple regulatory frameworks (HIPAA, HITECH, NIST, ISO) into a single assurance framework — analogous to CRI doing the same for the financial services sector, with a similar revenue model of membership, certification, and licensing.

TypeBroad incumbent
Description

U.S. government agency that authored the Cybersecurity Framework (the foundation on which the CRI Profile is built); CRI operates as a sector-specific overlay/customization layer above NIST CSF, complementing rather than competing but representing the most direct upstream alternative framework.

TypeBroad incumbent
Description

Global nonprofit association that publishes COBIT and related IT/governance/risk frameworks used by financial institutions; serves overlapping CISO/GRC audiences with comparable certifications (CISM, CRISC held by CRI SVP John Goodman) and competes for governance framework budget.

TypeDirect peer
Description

Financial Services Information Sharing and Analysis Center — member-based nonprofit serving the same 130+ FI constituency as CRI on cyber threat intelligence; recent CRI Profile mapping to FS-ISAC Sector Risk Advisory signals operational collaboration around AI-enabled vulnerability scenarios.

TypeBroad incumbent
Description

Publisher of ISO 27001/27002 (information security) and the new ISO/IEC 42001 (AI management systems); these represent globally adopted substitutes for parts of CRI's stack and CRi publishes mappings to several ISO standards as part of the harmonization effort.

TypeDirect peer
Description

Member-driven nonprofit that develops third-party risk management assessment tools (SIG, AUP) widely used by financial institutions — overlapping with CRI's third-party risk and vendor assessment use cases for FI members.

TypeOthers
Description

The industry-coordinating body from which CRI was spun off in 2022; FSSCC still coordinates sector-wide policy efforts and co-developed the FS AI RMF with CRI, providing the institutional umbrella under which CRI's standards operate.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers29 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment5 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles6 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Cyber Risk Institute

Cybersecurity Risk Management Frameworkscyberriskinstitute.org

Cyber Risk Institute is a Washington, D.C.-based non-profit standards body that develops the CRI Profile and related frameworks (Cloud, FS AI RMF, Maturity Model) to help global financial institutions manage cyber and AI risk under recognized regulatory mappings.

What Cyber Risk Institute does

Cyber Risk Institute (CRI) is a Washington, D.C.-based not-for-profit 501(c)(6) standards development organization that builds and maintains cybersecurity and AI risk frameworks for the global financial services industry. CRI originated as a Profile development effort under the Financial Services Sector Coordinating Council (FSSCC) beginning in 2016 and was spun out as an independent entity in 2022. Its core asset is the CRI Profile, a streamlined version of the NIST Cybersecurity Framework v2.0 comprising 318 diagnostic statements with 40 mappings to global regulatory and supervisory references. The product family has expanded to include the Cloud Profile (cloud security extension), the Financial Services AI Risk Management Framework (FS AI RMF) with 230 control objectives, a member-exclusive Maturity Model for benchmarking, and translations in Japanese, Spanish, and Portuguese.

The platform architecture is framework-centric rather than software-centric: CRI packages curated control catalogs, diagnostic questions, regulatory mappings, and assessment instruments that financial institutions map their internal controls and audit processes to. Supporting tools include an AI Adoption Stage Questionnaire, a Risk and Control Matrix, and integrations with standards such as MITRE ATT&CK. CRI distributes the core framework as a free download to drive adoption and operates member-exclusive products and a forthcoming CRI Marketplace for aligned third-party products, plus Innovator and Affiliate licensing programs.

CRI's revenue mechanics are diversified across membership dues (annual subscriptions from financial institutions and trade associations), commissions from CRI Marketplace, and licensing fees from the Innovator and Affiliate programs. It serves 130+ member organizations spanning large U.S. and global banks, payment networks and issuers, capital markets and trust firms, exchanges, crypto/fintech, and major industry associations (SIFMA, FS-ISAC, ABA, Bank Policy Institute). CRI is governed by a cross-industry board and operates with a small (1–10) staff footprint, with senior leadership and contributor participation drawn from member institutions.

Cyber Risk Institute firmographics

Firmographics
Name
Cyber Risk Institute
Legal name
Cyber Risk Institute
Website
https://cyberriskinstitute.org
Company type
Private
Founded year
2022
Operating status
Operating
Headcount range
1–10 employees
Short description
Cyber Risk Institute is a Washington, D.C.-based non-profit standards body that develops the CRI Profile and related frameworks (Cloud, FS AI RMF, Maturity Model) to help global financial institutions manage cyber and AI risk under recognized regulatory mappings.
Ownership category
akta.pro rank

Cyber Risk Institute industry classification

Industry
Product category
Cybersecurity Risk Management Frameworks
NAICS
Security Systems Services (except Locksmiths) (561621)
akta.pro primary industry
AI Governance, Risk & Compliance (GRC) Platforms (HDAAAMAA)
akta.pro secondary industries
Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE), Model Governance, Risk & Compliance (GRC) Platforms (HDAAAKAA), Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) (HDAAAMAE), Responsible AI, AI Governance & Compliance Services (BPAEAHAJ), Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)

Keywords

  • Cybersecurity risk management
  • Financial sector frameworks
  • Regulatory compliance standards
  • AI risk management
  • Cyber assessment frameworks

Where Cyber Risk Institute is headquartered

Location

Headquarters

HQ city
Washington
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Cyber Risk Institute business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Marketing or Sales, Operations, Others

Revenue model

  1. Membership Dues: CRI generates revenue through annual membership dues paid by financial institutions. Membership is at the organizational level. Annual participation dues are set by the Board of Directors and available upon request. Explorer tier is free, Full Member has a low-cost annual fee.
  2. CRI Marketplace: The CRI Marketplace is a hub for tools, products, and services designed to help financial institutions adopt and implement CRI resources. Third-party tool providers and consulting firms offer products through this marketplace.
  3. Innovator and Affiliate Programs: Non-financial institutions can join as Innovators (Basic or Premium levels) or Affiliates, gaining rights to integrate CRI tools into their offerings for a fee.

Pricing tiers

ModelBillingPrice
FreemiumOthersFree tier with basic access to CRI Profile
SubscriptionAnnualFull Member with comprehensive access and participation rights

Go-to-market motion2 records

Distribution channels4 records

Marketing channels6 records

Cyber Risk Institute product offering

Product offering

Core offering

CIRI develops and maintains cybersecurity, cloud security, and AI risk management frameworks tailored for the global financial services industry. The core CRI Profile harmonizes 3,500+ regulatory expectations into 318 diagnostic statements mapped to 40+ standards and regulations. Complementary offerings include the Cloud Profile (cloud security extension), the FS AI RMF (230 Control Objectives for AI risk), and the member-exclusive Maturity Model for peer benchmarking.

Product overview

The Cyber Risk Institute offers a suite of cybersecurity, technology, and AI risk management products for the financial services industry. The core offering consists of the CRI Profile (a NIST-based cybersecurity framework harmonizing 3,500+ regulatory expectations), the Cloud Profile (an extension for cloud security), and the FS AI RMF (an AI risk management framework with 230 control objectives). Supporting products include the Maturity Model (for peer benchmarking, member-exclusive), Profile Translations (Japanese, Spanish, Portuguese), and various companion guides and mapping documents. The products work together as an integrated risk management ecosystem, enabling financial institutions to assess, benchmark, and report on cybersecurity and AI risks across global regulatory jurisdictions.

Differentiator

Problem solved

Functional benefit

Brands

  • CRI Profile: Cybersecurity and technology framework built by and for the financial sector, based on NIST CSF, connecting cyber best practices with regulatory expectations from around the world.
  • Cloud Profile
  • Financial Services AI Risk Management Framework (FS AI RMF)
  • Maturity Model

Products and services

  • CRI Profile A financial-sector-specific cybersecurity and technology risk management framework built on NIST Cybersecurity Framework v2.0, harmonizing 3,500+ regulatory expectations into 318 diagnostic statements with approximately 40 mappings to global standards and regulations. For financial institutions of all sizes.
  • Cloud Profile An extension of the CRI Profile developed in collaboration with Cloud Service Providers and the Cloud Security Alliance, providing actionable cloud security guidance including a shared responsibility checklist implementation tool. Aligned with NIST CSF v2.0 and integrated with the CSA Cloud Control Matrix. For financial institutions implementing or strengthening cloud technologies.
  • Financial Services AI Risk Management Framework (FS AI RMF) An industry-led, sector-specific AI risk management framework with 230 Control Objectives developed through public-private collaboration with 100+ financial institutions. Includes an AI Adoption Stage Questionnaire, Risk and Control Matrix, Guidebook, and Control Objective Reference Guide. For financial institutions deploying or overseeing AI systems.
  • CRI Maturity Model An assessment tool aligned with the CRI Profile and NIST CSF that quantitatively scores responses at the diagnostic-statement level, enabling structured benchmarking of cybersecurity maturity across institutions. Available exclusively to CRI Full Members.
  • CRI Profile Translations Translated versions of the CRI Profile and Guidebook in Japanese, Spanish, and Brazilian Portuguese to enable consistent adoption across Asia-Pacific and Latin America. Includes Japanese translation by NRI Secure Technologies and Spanish/Portuguese translations sponsored by Mastercard.
  • CRI Marketplace A hub that aggregates tools, products, and services from third-party providers and consulting firms to help financial institutions adopt and implement CRI resources at every stage of their cybersecurity program. For financial institutions seeking implementation support and the partner firms that serve them.
  • CRI Membership Program Annual organizational membership providing access to the Maturity Model, exclusive member workshops, participation in working groups, and member-only mappings and tools. Includes Explorer (free) and Full Member (paid) tiers. For financial institutions.

Quantifiable outcome

  • 58% reduction in assessment questions for Impact Tier 4 firms compared to other widely used assessments
  • +3 more outcomes

Companies that use Cyber Risk Institute

Customer profile

Named customers29 records

Segments5 records

Ideal customer profiles3 records

Cyber Risk Institute technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature6 records

Cyber Risk Institute partnerships and signals

Strategic signal

Partnerships

Eleven partnerships are on record, tiered core.

  • Financial Services Sector Coordinating Council (FSSCC)coreStrategic or Co-development Partner · 12 February 2026CRI developed the FS AI RMF in coordination with FSSCC as part of a larger sector-wide initiative focused on responsible AI adoption and governance. The FS AI RMF was developed through a collaborative effort by more than 100 financial institutions coordinated through FSSCC.
  • Cloud Security Alliance (CSA)coreStrategic or Co-development PartnerCollaboration with CSA to integrate the Cloud Security Alliance's Cloud Control Matrix (CCM) into the CRI Cloud Profile. CSA collaborated with financial institutions and major cloud service providers to develop the Cloud Profile.
  • MITRE's Center for Threat-Informed Defense (CTID)coreStrategic or Co-development PartnerCollaboration to develop mapping connecting CRI Profile to MITRE ATT&CK Framework, helping financial institutions bring together governance, regulatory expectations, and threat mitigations.
  • EY (Ernst & Young)coreImplementation/ SI/ Consulting PartnerEY provided expert support in updating Profile v2.1 and developing the DORA implementation guide for CRI Profile users.
  • KPMGcoreImplementation/ SI/ Consulting PartnerKPMG contributed to the development of the CRI Maturity Model, which provides a mechanism to quantitatively score responses at the diagnostic statement level.
  • NRI Secure TechnologiescoreImplementation/ SI/ Consulting PartnerNRI Secure Technologies translated the CRI Profile v2.0 into Japanese, helping financial institutions in Japan leverage the benefits of the streamlined self-assessment framework.
  • MastercardcoreImplementation/ SI/ Consulting PartnerMastercard sponsored the Spanish and Portuguese translations of the CRI Profile and Guidebook, supporting broader adoption and consistent implementation across Latin America.
  • BGBGcoreImplementation/ SI/ Consulting PartnerBGBG, a Mexican law firm, completed the Spanish and Portuguese translations of the CRI Profile and Guidebook, released at a launch event in Mexico City.
  • U.S. Department of the TreasurycoreStrategic or Co-development PartnerTreasury, as Sector Risk Management Agency for financial services, collaborated with CRI on developing precision time resiliency controls into the CRI Profile to facilitate meeting requirements in Executive Order 13905. Treasury also acknowledged CRI's work in AI risk management frameworks.
  • BCG PlatinioncoreImplementation/ SI/ Consulting PartnerCRI works with BCG Platinion to identify priority integration opportunities and map regulations and frameworks to the Profile on a rolling basis.
  • U.S. Department of the TreasurycoreStrategic or Co-development PartnerThe FS AI RMF was developed in coordination with U.S. Treasury, which released it as part of the President's AI Action Plan. Treasury released two AI risk management tools including the FS AI RMF developed through public-private partnership.

Scale indicators8 records

Recent moves7 records

Expansion highlights7 records

Cyber Risk Institute competitors and assessment

Company assessment

Direct peers

  • PCI Security Standards Council: Nonprofit 501(c)(6)-style global standards body that develops and maintains the PCI DSS for payment security — the closest analog to CRI in business model (standards development organization governed by members), funding mechanism (membership dues + fees), and role (harmonizing regulatory and industry expectations into a single actionable framework adopted by financial-adjacent institutions).
  • Cloud Security Alliance: Nonprofit organization that maintains the Cloud Controls Matrix (CCM) and STAR program; CRI's Cloud Profile was co-developed with CSA, and the two compete/collaborate in defining authoritative cloud-security control sets for regulated industries including financial services.
  • Center for Internet Security (CIS): Nonprofit that publishes the CIS Critical Security Controls (now mapped into CRI Profile v2.1) and operates a community-driven model similar to CRI's 500+ contributors and working-group approach to voluntary consensus standards.
  • HITRUST: Nonprofit standards and certification organization that harmonizes multiple regulatory frameworks (HIPAA, HITECH, NIST, ISO) into a single assurance framework — analogous to CRI doing the same for the financial services sector, with a similar revenue model of membership, certification, and licensing.
  • FS-ISAC: Financial Services Information Sharing and Analysis Center — member-based nonprofit serving the same 130+ FI constituency as CRI on cyber threat intelligence; recent CRI Profile mapping to FS-ISAC Sector Risk Advisory signals operational collaboration around AI-enabled vulnerability scenarios.
  • Shared Assessments: Member-driven nonprofit that develops third-party risk management assessment tools (SIG, AUP) widely used by financial institutions — overlapping with CRI's third-party risk and vendor assessment use cases for FI members.

Broad incumbents

  • National Institute of Standards and Technology (NIST): U.S. government agency that authored the Cybersecurity Framework (the foundation on which the CRI Profile is built); CRI operates as a sector-specific overlay/customization layer above NIST CSF, complementing rather than competing but representing the most direct upstream alternative framework.
  • ISACA: Global nonprofit association that publishes COBIT and related IT/governance/risk frameworks used by financial institutions; serves overlapping CISO/GRC audiences with comparable certifications (CISM, CRISC held by CRI SVP John Goodman) and competes for governance framework budget.
  • ISO (International Organization for Standardization): Publisher of ISO 27001/27002 (information security) and the new ISO/IEC 42001 (AI management systems); these represent globally adopted substitutes for parts of CRI's stack and CRi publishes mappings to several ISO standards as part of the harmonization effort.

Others

  • Financial Services Sector Coordinating Council (FSSCC): The industry-coordinating body from which CRI was spun off in 2022; FSSCC still coordinates sector-wide policy efforts and co-developed the FS AI RMF with CRI, providing the institutional umbrella under which CRI's standards operate.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks5 records

Key highlights7 records

Customer concentration

Cyber Risk Institute social profiles

Digital presence

Cyber Risk Institute financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Cyber Risk Institute leadership team

Management profile

Number of profiles

Profiles6 records

Cyber Risk Institute funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Cyber Risk Institute M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Cyber Risk Institute

What does Cyber Risk Institute do?

CIRI develops and maintains cybersecurity, cloud security, and AI risk management frameworks tailored for the global financial services industry. The core CRI Profile harmonizes 3,500+ regulatory expectations into 318 diagnostic statements mapped to 40+ standards and regulations. Complementary offerings include the Cloud Profile (cloud security extension), the FS AI RMF (230 Control Objectives for AI risk), and the member-exclusive Maturity Model for peer benchmarking.

Is Cyber Risk Institute a public or private company?

Cyber Risk Institute is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was Cyber Risk Institute founded?

Cyber Risk Institute was founded in 2022. It employs 1 to 10 people.

Where is Cyber Risk Institute based?

Cyber Risk Institute is headquartered in Washington, United States, in the North America region.

How does Cyber Risk Institute make money?

Three revenue lines are on record. Membership Dues are the primary driver. The others are CRI Marketplace and innovator and Affiliate Programs.

Who are Cyber Risk Institute's main competitors?

Direct peers on record are PCI Security Standards Council, Cloud Security Alliance, Center for Internet Security (CIS), HITRUST, FS-ISAC and Shared Assessments. Broad incumbents are National Institute of Standards and Technology (NIST), ISACA and ISO (International Organization for Standardization). Financial Services Sector Coordinating Council (FSSCC) is listed as an others.

Does Cyber Risk Institute have an API?

No public API is recorded for Cyber Risk Institute.

What industry is Cyber Risk Institute in?

Cyber Risk Institute's product category is Cybersecurity Risk Management Frameworks. Its primary akta.pro industry code is HDAAAMAA, AI Governance, Risk & Compliance (GRC) Platforms, with a secondary code of HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies). Its NAICS code is 561621.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
CroweCrowe joins the Cyber Risk Institute as a Premium InnovatorCrowe LLP, a public accounting and consulting firm, has joined the Cyber Risk Institute (CRI) as a Premium Innovator to expand its cyber and technology risk services for financial institutions. Through this collaboration, Crowe will integrate CRI\u2019s regulatory compliance tools\u2014including the Profile, Cloud Profile, and Maturity Model\u2014into its client offerings, helping financial institutions streamline cybersecurity requirements and improve regulatory readiness. The partnership reinforces Crowe\u2019s position serving over 2,900 financial services clients and more than 75% of the top 100 U.S. banks.Lowenstein Sandler LLPFinancial Services AI Risk Management Framework: Operationalizing the 230 Control Objectives Before the Market Wakes Up (Data Privacy)The U.S. Department of the Treasury released the Financial Services AI Risk Management Framework on February 19, 2026, introducing 230 control objectives for AI governance across financial institutions, developed in coordination with over 100 financial institutions, the Financial Services Sector Coordinating Council, and the Cyber Risk Institute. The framework reframes AI governance from policy documentation to infrastructure-level controls requiring embedding directly into CI/CD and MLOps pipelines, and maps to existing NIST standards to integrate with existing governance programs. The article warns that institutions treating this as a documentation refresh rather than architectural modernization will face significant remediation challenges as supervisory examination of AI systems matures.CyberriskinstituteCyber Risk Institute – Don't risk risk.The Cyber Risk Institute's (CRI) Cyber Profile is widely recognized by major financial regulators and international bodies as a standardized tool for assessing cybersecurity preparedness in the financial services sector. The profile, which aligns with NIST, ISO, and other core standards, is cited by entities including the FFIEC, US Treasury, and ENISA as a benchmark for regulatory harmonization and risk management.