MiddlebrookData & AI Governance← All insights
Insight · Frameworks

Operationalizing the Treasury FS AI RMF: what your bank does next

By Barry Middlebrook · Middlebrook Data & AI Governance

On February 19, 2026, the U.S. Treasury released the Financial Services AI Risk Management Framework (FS AI RMF) — the sector's first finance-specific, operational playbook for AI risk. It was developed through the AI Executive Oversight Group (a public-private partnership of Treasury's FBIIC and the Financial Services Sector Coordinating Council) and executed by the Cyber Risk Institute, with input from more than a hundred financial institutions. It takes the NIST AI RMF and translates it into something an examiner can actually review: 230 control objectives, each tied to a risk statement and a trustworthy-AI principle.

It's voluntary today. But frameworks built this way — sector-specific, examination-shaped, backed by Treasury — don't stay voluntary in practice for long. They become the spreadsheet your examiner brings to the next review. The institutions that win are the ones already aligned when that happens.

What's actually in it

The FS AI RMF has four parts that work together:

The FS AI RMF isn't another policy PDF to file. Its controls are meant to live in your data layer, your model lifecycle, your access controls, and your vendor stack — not a binder.

How it's organized

The 230 control objectives aren't a brand-new taxonomy. The FS AI RMF builds directly on the NIST AI RMF's four functions and makes each one finance-specific. Read them as the table of contents for your AI governance program:

Those four functions break down into 19 categories, 72 subcategories, and 230 control objectives (IDs like GV-1.1.1). Every objective is tagged to one of seven AI Trustworthy Principles — Accountable & Transparent, Valid & Reliable, Explainable & Interpretable, Fair, Secure & Resilient, Privacy-Enhanced, and Safe — and is filterable by your AI Adoption Stage (Initial, Minimal, Evolving, Embedded), so the effort stays proportionate to where you actually are.

What you actually do with it

A framework is only as good as the program you build from it. The path is the same one disciplined institutions already know — applied to AI:

Where most institutions are exposed

If you run a mature model-risk program, you already have real coverage in Measure and parts of Map — model validation and monitoring. The exposure tends to concentrate in three places: Govern (no named owner for AI specifically), third-party risk (GenAI bought, not built, and never run through vendor diligence), and explainability (a generative model touching a customer decision that no one can explain after the fact). That's also the gap your SR 11-7 program was never designed to reach — the OCC's revised guidance explicitly excludes generative and agentic AI. The FS AI RMF is the instrument that closes it.

Why this can't wait

The FS AI RMF is voluntary today — but it's the framework your next examiner will reach for, and the gap only widens: every copilot, assistant, and agent you ship adds ungoverned surface. Aligning to it now is a project you control; waiting lets an exam finding set the timeline instead. And regulators already write nine-figure checks for ungoverned data — the OCC and Federal Reserve fined Citibank about $536 million between 2020 and 2024 for exactly that kind of failure. The institutions that map to the 230 controls before their next exam decide how this goes. The rest explain to a board why they didn't.

A brand-new framework is a project. An examiner finding you unaligned to it is a crisis.

See where you stand against the FS AI RMF — before your examiner does

Take the free 4-minute risk assessment for an instant maturity read, or book a call to scope a full, expert-led review benchmarked against the FS AI RMF's questionnaire and 230 control objectives.

Take the free assessment See consulting & engagement →