Operationalizing the Treasury FS AI RMF: what your bank does next
On February 19, 2026, the U.S. Treasury released the Financial Services AI Risk Management Framework (FS AI RMF) — the sector's first finance-specific, operational playbook for AI risk. It was developed through the AI Executive Oversight Group (a public-private partnership of Treasury's FBIIC and the Financial Services Sector Coordinating Council) and executed by the Cyber Risk Institute, with input from more than a hundred financial institutions. It takes the NIST AI RMF and translates it into something an examiner can actually review: 230 control objectives, each tied to a risk statement and a trustworthy-AI principle.
It's voluntary today. But frameworks built this way — sector-specific, examination-shaped, backed by Treasury — don't stay voluntary in practice for long. They become the spreadsheet your examiner brings to the next review. The institutions that win are the ones already aligned when that happens.
What's actually in it
The FS AI RMF has four parts that work together:
- An AI Adoption Stage Questionnaire — pinpoints where you are on the AI-maturity curve, so the rest of the framework scales to your reality instead of dumping 230 controls on a bank running two pilots.
- A Risk & Control Matrix — the 230 control objectives themselves, each mapped to a risk and a principle.
- A Guidebook — the background, glossary, and sources.
- A Control Objective Reference Guide — illustrative controls and, crucially, the audit evidence an examiner expects to see.
The FS AI RMF isn't another policy PDF to file. Its controls are meant to live in your data layer, your model lifecycle, your access controls, and your vendor stack — not a binder.
How it's organized
The 230 control objectives aren't a brand-new taxonomy. The FS AI RMF builds directly on the NIST AI RMF's four functions and makes each one finance-specific. Read them as the table of contents for your AI governance program:
- Govern (GV) — policies and decision rights, roles and accountability, the AI inventory, a risk-aware culture, and third-party risk management. Who owns AI risk and the rules that bound it.
- Map (MP) — understanding the operating context, the AI system and the data it runs on, its components, and its real-world impacts before you rely on it.
- Measure (MS) — evaluating the system: validity and reliability, security, privacy, nondiscrimination, explainability, and monitoring it once it's live.
- Manage (MG) — prioritizing and responding to risk, managing third-party and pre-trained-model risk, and ongoing post-deployment response.
Those four functions break down into 19 categories, 72 subcategories, and 230 control objectives (IDs like GV-1.1.1). Every objective is tagged to one of seven AI Trustworthy Principles — Accountable & Transparent, Valid & Reliable, Explainable & Interpretable, Fair, Secure & Resilient, Privacy-Enhanced, and Safe — and is filterable by your AI Adoption Stage (Initial, Minimal, Evolving, Embedded), so the effort stays proportionate to where you actually are.
What you actually do with it
A framework is only as good as the program you build from it. The path is the same one disciplined institutions already know — applied to AI:
- Start with the questionnaire, not the controls. Establish your adoption stage first. It tells you which controls are load-bearing now and which are aspirational — and keeps the effort proportionate.
- Inventory the AI and risk-tier it. You can't govern what you haven't found. The gap between the AI your teams told you about and the AI in your model inventory is usually the headline.
- Run a gap assessment against the 230 objectives. Score your coverage function by function (Govern, Map, Measure, Manage), find where you'd fail an exam today, and rank the gaps by exposure — not by how easy they are to fix.
- Operationalize the gaps into real controls. Turn "we have no use-case intake" into an intake process; "no decision rights" into a matrix; "no vendor standard" into procurement criteria. Each control tagged to its FS AI RMF objective so the evidence trail is examiner-ready.
- Keep it current. The framework will evolve, and so will your AI footprint. Governance is a cadence, not a project.
Where most institutions are exposed
If you run a mature model-risk program, you already have real coverage in Measure and parts of Map — model validation and monitoring. The exposure tends to concentrate in three places: Govern (no named owner for AI specifically), third-party risk (GenAI bought, not built, and never run through vendor diligence), and explainability (a generative model touching a customer decision that no one can explain after the fact). That's also the gap your SR 11-7 program was never designed to reach — the OCC's revised guidance explicitly excludes generative and agentic AI. The FS AI RMF is the instrument that closes it.
Why this can't wait
The FS AI RMF is voluntary today — but it's the framework your next examiner will reach for, and the gap only widens: every copilot, assistant, and agent you ship adds ungoverned surface. Aligning to it now is a project you control; waiting lets an exam finding set the timeline instead. And regulators already write nine-figure checks for ungoverned data — the OCC and Federal Reserve fined Citibank about $536 million between 2020 and 2024 for exactly that kind of failure. The institutions that map to the 230 controls before their next exam decide how this goes. The rest explain to a board why they didn't.
A brand-new framework is a project. An examiner finding you unaligned to it is a crisis.
See where you stand against the FS AI RMF — before your examiner does
Take the free 4-minute risk assessment for an instant maturity read, or book a call to scope a full, expert-led review benchmarked against the FS AI RMF's questionnaire and 230 control objectives.
Take the free assessment See consulting & engagement →