NIST AI RMF, ISO 42001 & the EU AI Act: what a finance leader actually has to do
A handful of names dominate every AI-governance conversation, and they're easy to conflate. Here's the plain-English version, and — more usefully — what they actually require you to do. One of them — the Treasury's new FS AI RMF — was written specifically for financial institutions, so that's where a finance leader should start.
The frameworks, demystified
- FS AI RMF — the Financial Services AI Risk Management Framework, released by the U.S. Treasury in February 2026 and executed by the Cyber Risk Institute. It translates the NIST AI RMF into 230 finance-specific control objectives, built on NIST's four functions — Govern, Map, Measure, and Manage — and each tagged to one of seven AI Trustworthy Principles. Voluntary today, but examiner-facing — think of it as the recipe written for your kitchen.
- NIST AI RMF — a voluntary U.S. framework for managing AI risk, organized around four functions: Govern, Map, Measure, Manage. Think of it as the general-purpose recipe the FS AI RMF builds on.
- ISO/IEC 42001 — an international, certifiable standard for running an "AI management system" (the AI cousin of ISO 27001). Think of it as the gold-star checklist you can be audited against.
- EU AI Act — an actual law that sorts AI by risk (prohibited / high / limited / minimal) and imposes obligations accordingly. Think of it as the rules you must follow if you're in scope.
Some are voluntary maps; one is law; the FS AI RMF is the finance-specific translation that ties them together. They converge on the same handful of disciplines — which is good news, because you can satisfy all of them with one program.
What you actually have to do
Strip away the acronyms and the practical work is consistent:
- Inventory your AI — you can't govern what you haven't catalogued.
- Risk-tier each use — not every model needs the same scrutiny; the ones touching credit, reporting, or customers do.
- Govern the data — quality, lineage, lawful basis, and a semantic layer so outputs are trustworthy.
- Keep humans in the loop for high-stakes decisions, and make outputs transparent.
- Document and evidence as you go — the audit trail that proves all of the above.
Do that, and you're substantially aligned to all of them at once. The frameworks aren't separate projects — they're one governance program, described in several vocabularies, with the FS AI RMF mapping it onto the controls your examiners already speak.
Choose your timeline — or have one handed to you
The frameworks are converging, and the finance-specific one just landed: the Treasury's FS AI RMF arrived in February 2026 with 230 examiner-facing control objectives written for your kitchen. It's voluntary today — which is exactly the window. The institutions that move now build to it on their own schedule, on their own terms. The ones that wait don't escape the work; they get the timeline handed to them by an examiner, at the worst possible moment, with the controls due immediately.
Voluntary today is the only window you get to set the pace yourself.
Is your data ready for AI reporting — on your timeline, not your examiner's?
Take the free 4-minute risk assessment and get your maturity level with prioritized fixes — instantly.
Take the free assessment See pricing & engagement →