Financial Services AI Risk Management Framework (FS AI RMF)
Issued by
US Department of the Treasury, with the Cyber Risk Institute
- September 30, 2026 · Correction — Corrected the release date and authorship, and removed unsupported claims about supervisory use; the framework is voluntary. (Cody Maxwell)
- September 30, 2026 · Correction — Rewrote the FAQ, which invented an effective date, deadlines, examination use and SOC 2 integration for a voluntary framework (fact-check finding). (Cody Maxwell)
- October 1, 2026 · Correction — Rewrote the practical steps, newsletter hook, search description, and audience fields to match the entry's corrected content. (Cody Maxwell)
The US Treasury released the Financial Services AI Risk Management Framework on 19 February 2026, with the Cyber Risk Institute. It adapts the NIST AI RMF into 230 control objectives for financial institutions, organized by AI adoption stage. It is voluntary guidance, released alongside a shared AI lexicon.
Applies To
Overview
The US Department of the Treasury released the Financial Services AI Risk Management Framework (FS AI RMF) on 19 February 2026, developed with the Cyber Risk Institute. It was published alongside a Shared AI Lexicon for the sector. The framework adapts the NIST AI RMF's four functions, Govern, Map, Measure, and Manage, to financial services. It sets out 230 control objectives, organized by how far an institution has progressed in adopting AI. They cover governance, data management, model development and validation, monitoring, third-party risk, and consumer protection. It has four parts: an AI adoption stage questionnaire, a risk and control matrix, an implementation guidebook, and a control objective reference guide. Treasury describes it as voluntary, non-binding guidance. Institutions can use it to benchmark their AI risk programs and to show structured risk management to examiners and partners.
Key Requirements
- •Use the adoption stage questionnaire to find which of the 230 control objectives apply to your institution.
- •Map AI systems and controls to the risk and control matrix across Govern, Map, Measure, and Manage.
- •Cover governance, data management, model development and validation, monitoring, third-party risk, and consumer protection.
- •Adopt the Shared AI Lexicon so internal and external AI risk discussions use consistent terms.
- •The framework is voluntary and creates no new legal obligations.
What Your Organization Must Do
- →Complete the adoption stage questionnaire to see which of the 230 voluntary control objectives fit your institution.
- →Map your existing AI systems and controls to the risk and control matrix across Govern, Map, Measure, and Manage.
- →Check coverage of governance, data management, model validation, monitoring, third party risk, and consumer protection.
- →Adopt the Shared AI Lexicon so internal teams, vendors, and examiners use the same AI terms.
- →Use the published mappings to the NIST AI RMF, EU AI Act, Cyber Risk Institute Profile, and ISO/IEC 42001 to avoid duplicate work.
- →Treat adoption as optional, since the framework is voluntary and creates no new legal obligations.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Which financial institutions does the FS AI RMF apply to?
- No institution is legally subject to it, because the framework is voluntary. It is written for financial institutions of any size or type, including banks, credit unions, insurers, and investment firms, and for their AI vendors.
- Is the FS AI RMF legally binding or just guidance?
- It is voluntary, non-binding guidance that creates no new legal obligations. Treasury does not examine banks against it; bank supervision sits with the Federal Reserve, the OCC, and the FDIC.
- What are the 230 control objectives and where do they come from?
- They apply the NIST AI RMF's four functions (Govern, Map, Measure, Manage) to financial services. An adoption stage questionnaire decides which objectives fit an institution, so no firm is expected to apply all 230.
- How does the FS AI RMF relate to other frameworks?
- It publishes mappings to the NIST AI RMF, the EU AI Act, the Cyber Risk Institute Profile, and ISO/IEC 42001. Those mappings let institutions fold AI controls into programs they already run.
- Does the FS AI RMF set extra controls for credit underwriting or anti-money laundering models?
- It gives more detailed guidance for high-impact uses such as credit decisions and fraud and AML screening. Like the rest of the framework, that guidance is voluntary and has no effective date or deadline.
- How should a financial institution start with the FS AI RMF?
- Start with the adoption stage questionnaire to find your stage and the control objectives that apply. The Cyber Risk Institute also publishes a quick start for firms at the initial adoption stage.
