Avoided-Incident Attribution for AI Physical Security: A 2026 ROI Framework on the Counterfactual Methodology Boards, Insurers, and Procurement Teams Now Demand
An ROI methodology briefing on the federal evidence hierarchy, the three attribution traps, and the six-input counterfactual decomposition that produces auditable security-AI return claims.
The Attribution Question: Why Security ROI Demands a Counterfactual Framework
Why this report covers the methodology question every security AI ROI model already assumes
Every business case for AI physical security ultimately argues that fewer incidents will occur, that incidents will be less severe, or that response times will compress in ways that reduce loss costs. Each of those arguments rests on the same underlying claim: an incident that did not happen would have happened, but for the detection capability. That claim is a counterfactual, and it is the single hardest claim to defend in any security investment evaluation.
This report does not propose a new ROI formula. It documents the federal evidence hierarchy that boards, insurers, government procurement offices, and external auditors now use to assess attribution rigor, identifies the three structural failure modes that defeat most security ROI presentations, and provides a six-input decomposition model that buyers and vendors can use to make attribution claims defensible before they reach a CFO, a procurement officer, or an underwriter.
Every AI physical security ROI methodology rests on a counterfactual claim that an incident which did not occur would have occurred, but for the detection capability. In February 2026 the Bureau of Labor Statistics released the 2024 Census of Fatal Occupational Injuries and the 2024 Survey of Occupational Injuries and Illnesses. Together those primary-source datasets recorded 470 workplace homicides and 77,780 serious nonfatal workplace violence injuries, a 165 to 1 ratio between the visible top of the workplace violence problem and the substantially larger injury population sitting beneath it. Against that incident universe, the U.S. Occupational Safety and Health Administration's Recommendations for Workplace Violence Prevention Programs documents an annual employer cost burden in the tens of billions, with insurer, litigation, and operational disruption components that compound the direct medical and indemnity expense.
The economic case for AI physical security is built against those numbers. But the case is only as defensible as its attribution methodology, and attribution is where the typical security ROI argument breaks down. Most vendor-supplied ROI calculators count incidents that did not occur and multiply them by an average incident cost. They almost never specify how the "incidents that did not occur" figure was estimated, whether secular trends were controlled for, whether comparison sites were used, or whether the underlying methodology would survive scrutiny from an underwriter applying a standard evidence rubric.
That methodological gap matters more in 2026 than it did even two years ago. The National Institute of Standards and Technology released its AI Risk Management Framework in January 2023 and a Generative AI Profile in July 2024, both of which place Test, Evaluation, Validation, and Verification (TEVV) at the center of trustworthy AI deployment. NIST followed with a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure on April 7, 2026, expanding the rigor expected for AI systems deployed in physical security and other critical contexts. Insurance underwriters, federal grant administrators, and corporate boards increasingly require attribution evidence that conforms to a recognizable evidence hierarchy. Vendor calculators that produce a single "$X return" number with no underlying methodology no longer satisfy the buyer-side documentation standard.
This report assembles the federal evidence hierarchy that defines attribution rigor, identifies the three traps that defeat most security ROI presentations, presents a six-input decomposition that produces a defensible counterfactual estimate, and explains how insurance underwriters already conduct the attribution analysis that procurement teams are now learning to require. The companion Four-Variable ROI Framework for AI Physical Security establishes the variables; the present report focuses on the methodology that makes those variables credible.
Why Attribution Is the Central Methodological Question in AI Physical Security ROI
Security investments occupy an unusual category in capital allocation: their value manifests as the absence of an event. A marketing campaign produces leads that can be counted. A manufacturing investment produces output that can be measured. A security investment produces incidents that did not happen, which by definition leave no observable trace. Demonstrating that an absence is causally attributable to a specific investment, rather than to a coincidental change in the underlying risk environment, is the canonical counterfactual problem economists have studied for decades.
The counterfactual problem becomes more acute as the underlying risk environment changes. The Federal Bureau of Investigation's preliminary 2025 Uniform Crime Reporting data showed a 9.3% year-over-year decline in violent crime. If a security buyer installed an AI detection platform in early 2025 and recorded fewer incidents through the calendar year, what proportion of the reduction is attributable to the detection platform and what proportion is attributable to the national secular trend? Without explicit attribution methodology, the typical security ROI presentation conflates the two.
The same conflation can run in the opposite direction. The BLS Census of Fatal Occupational Injuries records that workplace homicide rates have fluctuated between 3.0 and 3.7 per 100,000 full-time equivalent workers over the past decade without a sustained downward trend, distinguishing workplace violence from the broader violent crime decline. An organization that observed an incident increase after installing a new platform might mistakenly attribute the increase to the platform's failure, when in fact the platform was operating against a sectoral risk pattern that was already on an upward trajectory independent of the deployment.
The methodological consequence is that any attribution argument requires three explicit ingredients: a defined counterfactual against which observed outcomes are compared, a control for the secular trend that would have affected outcomes independent of the intervention, and a statement of the residual uncertainty in the resulting estimate. The federal evidence hierarchy formalizes those three ingredients into a four-tier ranking that underpins most government and major insurer attribution decisions.
The Three Attribution Traps Security Buyers Most Often Miss
Before turning to the federal evidence hierarchy, it is worth naming the three structural patterns that defeat the typical security ROI presentation when an underwriter, procurement officer, or board audit committee applies the standard attribution rubric.
The survivorship trap. Vendors collecting customer case studies preferentially keep accounts that produced clean before-and-after incident comparisons and quietly drop accounts that did not. The published case study sample is therefore not the deployment sample; it is the post-selection sample of accounts where the methodology happened to favor the observed outcome. A buyer evaluating vendor claims based on published case studies is observing the right tail of a distribution rather than its central tendency. The methodological correction is to require attribution analyses across the full deployment population, not the curated subset that produced quotable results.
The regression-to-the-mean trap. Organizations frequently invest in physical security after an incident or a cluster of incidents. The incident or cluster is itself a deviation from the long-run mean for that facility's risk profile. Even with no intervention at all, the next observation period will tend toward the historical baseline simply because extreme values are followed by less extreme values in series with any noise component. A security deployment that follows a peak incident period will therefore show favorable post-period outcomes whether the deployment is effective, partially effective, or completely ineffective. The methodological correction is to compare the post-deployment outcome against a counterfactual that incorporates the expected regression, not against the immediate pre-deployment peak.
The substitution trap. A detection platform that successfully prevents one category of incident may push perpetrator behavior toward a different category, geography, or time window. A weapon detection deployment at a primary entrance may shift drawn-weapon events to a service entrance. A perimeter intrusion alert system may shift trespass events from the protected perimeter to an unprotected adjacent property. Attribution analyses that look only at the specific incident type the platform targets, in the specific geography the platform covers, in the specific time window the platform was active, will systematically overstate the platform's true net effect because substitution is unobserved. The methodological correction is to define the relevant outcome universe broadly enough that displacement effects show up in the analysis rather than disappearing into an unmeasured category.
The federal evidence hierarchy was developed specifically to discipline analyses against these three traps. Its four tiers correspond to increasing levels of attribution rigor and to decreasing vulnerability to the survivorship, regression, and substitution effects that defeat weaker designs.
The Federal Evidence Hierarchy: Four Tiers of Attribution Rigor
The U.S. Department of Justice Office of Justice Programs commissioned the foundational federal review of crime prevention evidence in the mid-1990s. The resulting 1997 report from the University of Maryland, Preventing Crime: What Works, What Doesn't, What's Promising, evaluated more than five hundred crime prevention program evaluations and codified the four-tier evidence hierarchy that has since structured most federal funding decisions, the National Institute of Justice's CrimeSolutions evidence platform, and the methodological standards of evaluation work conducted by the RAND Corporation, the National Institute for Occupational Safety and Health, and major reinsurance carriers.
The four tiers correspond to four discrete methodological designs for estimating a counterfactual outcome. They are ranked by the rigor with which they control for confounders, the strength of the causal inference they support, and the cost and complexity of executing them in operational security contexts.
The Four-Tier Attribution Methodology Hierarchy for Security Investments
Ranked by causal-inference rigor, derived from the DOJ/NIJ Maryland Report (Sherman et al., 1997), the NIOSH Guide to Evaluating the Effectiveness of Strategies for Preventing Work Injuries (DHHS Publication 2001-119), and the RAND Corporation evaluation methodology series
Randomized Controlled Experimental Design
Sites randomly assigned to detection deployment or non-deployment control. Provides the strongest available causal inference because random assignment eliminates self-selection bias and balances unobserved confounders between groups.
Best fit: multi-site enterprise buyers with comparable facility profiles
Quasi-Experimental Design With Matched Controls
Deployment sites compared to non-deployment sites matched on key risk variables (industry, facility size, incident history, geography). Inference weaker than randomization but acceptable when matching variables are comprehensive and well-measured.
Best fit: enterprise buyers with portfolios of similar facilities
Before-and-After With External Trend Controls
Pre-deployment and post-deployment incident rates compared, with explicit adjustment for sectoral and geographic secular trends drawn from BLS, BJS, and FBI data. Vulnerable to regression-to-the-mean unless the pre-period extends across multiple risk cycles.
Best fit: single-site buyers and post-incident deployment scenarios
Observational Pre-Post or Cross-Sectional Comparison
Simple before-and-after comparison or cross-section of deployed vs. non-deployed sites, without trend adjustment or matching. Useful for descriptive purposes but does not support causal attribution and should not anchor an ROI claim presented to a board or underwriter.
Best fit: descriptive reporting only — not a procurement attribution standard
Procurement Standard
Government grant administrators, major reinsurance underwriters, and increasingly corporate audit committees now expect Tier 2 evidence or better for any security AI investment exceeding meaningful capital thresholds. Tier 4 evidence, which dominates vendor-supplied ROI calculators, is no longer accepted as the standalone basis for a documented business case.
Each tier maps to a specific deployment context. A large hospital system installing AI detection across thirty similar facilities can credibly execute a Tier 2 design by deploying to half the facilities in a staggered rollout and treating the un-deployed half as a matched comparison group during the rollout window. A single-site retail operator cannot. A federal grant recipient working under the U.S. Department of Education's school safety programs faces an explicit attribution documentation requirement, frequently Tier 2 or better, as a condition of grant renewal. A self-insured employer evaluating workers' compensation loss-cost impact will, in many states, face an NCCI-defined attribution requirement at the carrier level before any modification to the experience modification factor is approved.
The Counterfactual Decomposition: A Six-Input Attribution Model for AI Detection
Once the methodology tier is selected, the attribution analysis itself decomposes into six inputs. Each input has a defensible measurement protocol, a sourcing standard, and a known set of failure modes. The six inputs are not interchangeable; an ROI argument that omits any of them is incomplete and will not survive an underwriter audit.
The Six-Input Counterfactual Decomposition Model for Security AI Attribution
| Input | What It Measures | Primary Data Source | Common Failure Mode |
|---|---|---|---|
| Baseline Incident Rate | Pre-deployment incident frequency adjusted for the multi-year facility average to remove peak-period anchoring | BLS SOII or CFOI, OSHA 300 logs, internal incident management system, insurance claims history | Anchoring on a single high-incident year rather than the long-run mean |
| Counterfactual Trend Adjustment | Expected change in incident rate during the post-period, absent any deployment, based on sectoral and geographic secular trends | BLS sectoral injury data, FBI UCR violent crime trend, state-level workplace violence data | Failing to apply secular adjustment, attributing all observed change to the deployment |
| Avoided Incidents Estimate | Observed post-period incident count subtracted from the trend-adjusted counterfactual expectation | Internal incident logs, alert acknowledgment records, security operations dispatch logs | Counting alerts as incidents, double-counting the same incident under multiple alert types |
| Severity Compression | Distribution shift in incident severity (injury class, downtime, claim cost) between baseline and post-period | Workers' compensation claim distributions, BLS DART case data, internal HR records | Comparing post-period averages to pre-period averages without controlling for incident type mix |
| Response Interval Reduction | Compressed time from incident onset to first response, monetized via per-second loss-cost models | Alert timestamps, dispatch logs, PSAP transfer records, security audit data | Measuring detection latency without measuring downstream response action timing |
| System-Level Effects | Insurance premium adjustments, regulatory compliance posture, third-party audit outcomes, and avoided litigation exposure | NCCI experience modification factor, carrier renewal documentation, SOC 2 / NIST AI RMF audit reports | Omitting second-order effects entirely, or counting them without supporting carrier documentation |
The decomposition produces an attribution claim that an underwriter can audit input by input. An attribution analysis that establishes a Baseline Incident Rate of twelve serious incidents per year across a multi-year average, applies a Counterfactual Trend Adjustment of negative 4% based on the relevant BLS sectoral data, observes seven incidents in the post-period, and reports five Avoided Incidents trend-adjusted, is making a structured claim that can be checked against each underlying data source. A vendor calculator that reports "Saved $X by preventing N incidents" with no decomposition cannot be audited at all.
The detection-to-response compression component connects directly to the work covered in the Detection-to-Response Latency Economics ROI Framework, which documents the per-second loss-cost model that monetizes the Response Interval Reduction input. The severity compression component connects to the workers' compensation loss-cost mechanics analyzed in the Workers' Compensation Economics briefing. The system-level effects category draws directly on the carrier mechanics documented in the Insurers Underwriting AI Physical Security market intelligence report. The six-input decomposition is therefore not an alternative to the existing ROI frameworks in the Intelligence library; it is the attribution methodology that makes the variables in those frameworks defensible.
How Insurance Underwriters Actually Do Attribution: The NCCI Model Translated
The National Council on Compensation Insurance has been performing attribution analysis on workplace safety interventions for more than seventy years. The methodology that produces an employer's experience modification factor is, at its core, a counterfactual attribution model, and the procurement framework that physical security buyers now face increasingly mirrors the NCCI approach.
The experience modification factor compares an employer's actual workers' compensation losses to expected losses for an employer of the same size, in the same industry classification, in the same geography. The expected loss is the counterfactual: it is what a typical employer matching the subject employer's risk profile would experience in the same period. Actual losses below expected produce a modification factor below 1.00, lowering the premium. Actual losses above expected raise the factor above 1.00, raising the premium. The mechanism is, in attribution terms, a structured comparison between an observed outcome and a counterfactual benchmark constructed from a peer comparison group.
NCCI updated its experience modification methodology in 2024 to incorporate a state-specific split point that adjusts the primary/excess loss boundary based on each state's claim severity profile. Under the prior nationwide split point of $18,500, an employer in a high-severity state was effectively compared against a benchmark inappropriate for its risk environment. The revised methodology, rolled out state by state through 2024 with effective dates aligned to each state's loss-cost filing, sets state-specific split points ranging from approximately $15,000 in lower-severity states to $25,000 in higher-severity states. The methodological intent is to standardize the average D-ratio (the ratio of primary to total losses by classification) across states at approximately 40%, producing a more accurate counterfactual benchmark for each employer.
The translation for security AI buyers. The NCCI methodology demonstrates that defensible attribution requires three structural elements that vendor-supplied calculators routinely omit. First, the counterfactual must be constructed from a peer comparison group with similar risk characteristics, not from a single facility's historical baseline. Second, the comparison must control for the sectoral and geographic risk environment in which the facility operates, recognizing that the same intervention performs differently in different risk contexts. Third, the methodology must be transparent and auditable, because the entire downstream insurance calculation depends on the credibility of the counterfactual. Procurement organizations that wish to satisfy modern audit standards for security AI investments can adapt the NCCI structural template directly: define the counterfactual peer set, apply the contextual trend adjustment, and document the methodology in a form an auditor can verify.
Beyond NCCI, major property and casualty reinsurers have begun publishing attribution guidance specifically for AI physical security investments. The carrier underwriting analyses documented in IntelliSee's Insurers Underwriting AI Physical Security market intelligence brief show that carriers increasingly require Tier 2 or better attribution evidence as a precondition for premium-credit recognition. The Factor Analysis of Information Risk (FAIR) methodology, originally developed for cybersecurity risk quantification, has been adapted by several major carriers to handle physical security AI investments under the same probabilistic loss exceedance framework, with Annual Loss Expectancy calculations applied to the pre-deployment baseline and the post-deployment trend-adjusted estimate. Organizations using structured risk quantification methods demonstrate measurably more effective security resource allocation than those relying on qualitative assessments alone, according to FAIR Institute published research.
Writing the Attribution Requirement Into Procurement
For security buyers translating this methodology into a procurement requirement, the operational question is how to write attribution standards into a request for proposal or a vendor evaluation rubric. The pattern that satisfies modern audit standards has four components.
Specify the evidence tier. The RFP should explicitly state the minimum evidence tier the buyer expects vendors to support. For most enterprise buyers with multi-site portfolios, Tier 2 (quasi-experimental with matched controls) is the appropriate floor. Single-site buyers may need to accept Tier 3, but should require vendors to identify the specific trend-adjustment data sources the vendor will use rather than producing an unadjusted before-and-after comparison. Tier 4 should not be accepted as the basis for any documented business case exceeding a meaningful capital threshold.
Require the six-input decomposition. The RFP should require vendors to present any ROI projection as a six-input decomposition matching the framework above. Each input must be sourced to a primary data set (BLS, NCCI, OSHA 300 logs, internal incident management records, carrier underwriting documentation), and the methodology for each must be sufficiently documented to permit an external auditor to reconstruct the calculation.
Identify the counterfactual data sources by name. Vendors that cannot identify the specific external data sources they will use for trend adjustment are not equipped to deliver Tier 2 evidence. The BLS Survey of Occupational Injuries and Illnesses, the BLS Census of Fatal Occupational Injuries, the FBI Uniform Crime Reporting violent crime trend, the Bureau of Justice Statistics workplace violence series, and (for healthcare buyers) the Joint Commission's NPG 2a sentinel event database are the canonical sources. A vendor that does not name them is producing unadjusted comparisons.
Specify the audit posture. The RFP should specify that the buyer reserves the right to audit attribution claims using an independent reviewer applying the federal evidence hierarchy and the six-input decomposition. The audit posture matters less for the audits actually conducted than for the methodological discipline it imposes on the vendor's underlying analysis. Vendors expecting potential audit will not produce unauditable attribution claims.
Government procurement teams operating under federal grant frameworks face additional documentation requirements. The U.S. Department of Justice's CrimeSolutions evidence platform and the Office of Justice Programs' Evidence Integration Initiative both apply the four-tier hierarchy explicitly when evaluating program funding. Security AI grant applicants seeking renewal must increasingly produce attribution evidence at Tier 2 or better as a condition of continued funding. Detailed funding guidance is documented in IntelliSee's Federal and State Grant Funding for AI Physical Security procurement intelligence briefing.
What an Attribution-Ready Detection Platform Looks Like
The methodology described above places technical requirements on the detection platform itself. A platform that cannot produce the timestamp, alert, and disposition data the six-input decomposition requires cannot support a Tier 2 evidence claim, regardless of how effective its underlying detection capability may be. Three categories of platform capability are functionally required for attribution-ready deployments.
The platform must produce auditable alert telemetry. Every detection event must generate a timestamped record that includes the originating camera identifier, the detection type, the confidence score, the alert routing destination, and the acknowledgment timeline. This is the raw data that supports the Response Interval Reduction input in the six-input decomposition, and without it the input is not measurable. IntelliSee's platform architecture exports this telemetry through the platform's audit log and integration APIs.
The platform must support multi-site deployment under controlled rollout patterns. Tier 2 attribution evidence frequently requires staged deployments in which half of a portfolio is enrolled in an initial wave while the remaining half operates as a comparison group during the same period. Platforms that require all-or-nothing rollout, or that bundle facility-level deployment with shared infrastructure that confounds the comparison, cannot support the quasi-experimental design.
The platform must preserve attribution-relevant data without creating new privacy or compliance exposure. The platform should not require facial recognition, video retention beyond the immediate detection window, or collection of protected health information to operate. The attribution-relevant data is the alert telemetry, not the underlying video frames. Platforms that conflate the two create attribution capabilities at the cost of compliance posture, an exchange that the standards-compliance framework documented in the NIST AI RMF Standards-Compliance Briefing increasingly disfavors. IntelliSee's detection platform is engineered to produce the telemetry the attribution methodology requires without storing video, performing facial recognition, or collecting PHI.
For organizations evaluating their detection platform against the attribution-readiness standard, IntelliSee provides a structured risk and procurement assessment that maps platform capabilities against the six-input decomposition and the federal evidence hierarchy. The assessment is the deliverable that procurement teams, audit committees, and risk officers can use as the methodology document for board, underwriter, and grant administrator review.
Frequently Asked Questions
Why is attribution methodology more important for security AI than for other capital investments?
Most capital investments produce outcomes that can be measured directly. A marketing campaign produces leads, a manufacturing line produces units, a software deployment produces transactions. Security investments produce the absence of incidents that would have occurred, which by definition leave no observable trace. Demonstrating that the absence is causally attributable to the specific investment, rather than to a coincidental change in the underlying risk environment, requires explicit counterfactual methodology that most capital allocation processes have never been asked to support. The methodology is what distinguishes a defensible business case from a directionally plausible argument that will not survive an external audit.
What is the federal evidence hierarchy and where did it come from?
The federal evidence hierarchy is a four-tier ranking of attribution methodologies developed primarily through the 1997 University of Maryland report Preventing Crime: What Works, What Doesn't, What's Promising, commissioned by the U.S. Department of Justice and the National Institute of Justice. The hierarchy ranks methodologies by their causal inference rigor, from randomized controlled experimental designs (Tier 1) through observational pre-post comparisons (Tier 4). The four tiers now structure most federal funding decisions, the National Institute of Justice's CrimeSolutions evidence platform, NIOSH program evaluation guidance, and the methodological standards used by major insurance carriers when evaluating prevention investments.
What evidence tier should a security buyer require from vendors?
For enterprise buyers with multi-site portfolios, Tier 2 quasi-experimental designs with matched controls are the appropriate procurement floor. Single-site buyers should accept Tier 3 before-and-after with external trend controls but should require vendors to identify specific BLS, BJS, or FBI data sources for the trend adjustment. Tier 4 observational pre-post comparisons, which dominate vendor-supplied ROI calculators, should not anchor a documented business case for any meaningful capital investment because they do not support a causal attribution claim. Federal grant administrators and major reinsurance carriers increasingly require Tier 2 or better as a precondition for funding renewal or premium credit recognition.
What is regression to the mean and why does it defeat most security ROI presentations?
Regression to the mean is the statistical tendency for extreme observations to be followed by less extreme observations in any series with a noise component. Organizations frequently invest in security after an incident or incident cluster, which is by definition a deviation from the long-run mean for that facility's risk profile. The post-deployment period will tend toward the historical baseline whether the deployment is effective or not, because extreme periods are followed by less extreme periods independent of any intervention. Attribution analyses that compare the post-deployment outcome against the immediate pre-deployment peak will systematically overstate the deployment's true effect. The correction is to compare the post-deployment outcome against a counterfactual that incorporates the expected regression, typically by using a multi-year baseline average rather than the most recent year alone.
How do insurance underwriters perform attribution analysis on workers' compensation losses?
The National Council on Compensation Insurance experience modification factor is the most widely used insurance attribution mechanism in the United States. It compares an employer's actual workers' compensation losses to expected losses for an employer of the same size, industry classification, and geography. The expected loss is the counterfactual. Actual losses below expected lower the premium through a modification factor below 1.00. NCCI updated its methodology in 2024 to use state-specific split points ranging from approximately $15,000 to $25,000, replacing the prior nationwide $18,500 split point and producing more accurate counterfactual benchmarks for employers in states with diverse claim severity profiles.
What is the six-input decomposition and what does it produce?
The six-input decomposition is an attribution model that breaks a security ROI claim into six measurable components: Baseline Incident Rate, Counterfactual Trend Adjustment, Avoided Incidents Estimate, Severity Compression, Response Interval Reduction, and System-Level Effects. Each input is sourced to a primary data set and has a defensible measurement protocol. The decomposition produces an attribution claim that an external auditor can verify input by input, in contrast to vendor calculators that report a single aggregated return number with no underlying methodology. The decomposition is not an alternative to existing ROI frameworks. It is the methodology that makes the variables in those frameworks defensible.
What technical capabilities does a detection platform need to support attribution-ready deployment?
Three capabilities are functionally required. First, the platform must produce auditable alert telemetry with timestamped records including originating camera identifier, detection type, confidence score, alert routing destination, and acknowledgment timeline. Second, the platform must support multi-site deployment under controlled rollout patterns, including staged deployments in which a portion of a portfolio operates as a comparison group during the initial wave. Third, the platform must preserve attribution-relevant data without creating new privacy or compliance exposure, which means producing alert telemetry rather than storing video, performing facial recognition, or collecting protected health information. Platforms that conflate attribution capability with privacy-invasive data collection create methodology evidence at the cost of compliance posture.
Continue the Research
This report provides the attribution methodology that underlies every quantitative ROI argument in the Intelligence library. The companion reports apply the methodology to specific variable categories. Buyers building a comprehensive business case should read the attribution framework above alongside the variable-specific frameworks below.
The Four-Variable ROI Framework for AI Physical Security establishes the four economic variables every business case must address: incident frequency reduction, severity compression, response interval shortening, and system-level insurance and compliance effects. The framework defines the variables; the present report defines the attribution methodology that makes the variables credible.
The Detection-to-Response Latency Economics ROI Framework provides the per-second loss-cost model that monetizes the Response Interval Reduction input of the six-input decomposition. It is the quantitative companion to the methodology document.
The Seven-Tier Workplace Violence Cost Decomposition establishes the cost layers an Avoided Incidents Estimate is converted into, from direct medical and indemnity through litigation exposure and brand impact. The seven cost tiers are the multipliers; the attribution methodology produces the count to multiply.
For the primary-source incident data that anchors the Baseline Incident Rate and Counterfactual Trend Adjustment inputs across most U.S. industries, see Workplace Violence in America: The 2025 BLS Threat Intelligence Analysis. For the carrier-side mechanics that govern the System-Level Effects input, see Insurers Underwriting AI Physical Security.
For practitioners who want to evaluate IntelliSee's platform against the attribution-readiness standard, the structured risk and procurement assessment maps platform capabilities to the six-input decomposition and produces the methodology document a board, underwriter, or grant administrator can review. For ongoing primary-source data tracking, the workplace violence tracker aggregates BLS, BJS, and OSHA data on a continuous basis.
Primary Sources
- Sherman, L. W., Gottfredson, D. C., MacKenzie, D. L., Eck, J., Reuter, P., & Bushway, S. Preventing Crime: What Works, What Doesn't, What's Promising: A Report to the United States Congress. Washington, DC: National Institute of Justice / Office of Justice Programs, 1997. ojp.gov/library/publications
- U.S. Bureau of Labor Statistics. Survey of Occupational Injuries and Illnesses, 2024 Data and Census of Fatal Occupational Injuries Summary, 2024. Washington, DC: BLS, 2026. bls.gov/iif/soii-data.htm and bls.gov/iif/oshcfoi1.htm
- National Institute for Occupational Safety and Health. How to Show Whether a Safety Intervention Really Works: A Guide to Evaluating the Effectiveness of Strategies for Preventing Work Injuries. DHHS (NIOSH) Publication 2001-119. Cincinnati, OH: NIOSH, 2001. cdc.gov/niosh/docs/2001-119
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. Gaithersburg, MD: NIST, January 2023. nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
- National Institute of Standards and Technology. Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure. Gaithersburg, MD: NIST, April 7, 2026.
- National Council on Compensation Insurance. Experience Rating Plan Methodology Update FAQs. Boca Raton, FL: NCCI. ncci.com
- U.S. Occupational Safety and Health Administration. Recommendations for Workplace Violence Prevention Programs. OSHA Publication 3148. Washington, DC: OSHA. osha.gov/publications/OSHA3153
- Bureau of Justice Statistics. Indicators of Workplace Violence, 2019. Washington, DC: U.S. Department of Justice, BJS. bjs.ojp.gov
More intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Request a Risk and Procurement Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment