Last updated:
The Financial Services AI Risk Management Framework (FS AI RMF) is a voluntary, sector-specific framework published in February 2026 by the US Treasury with the Cyber Risk Institute. It aligns to the NIST AI RMF and provides a matrix of 230 control objectives across the AI lifecycle, covering banks, credit unions, insurers, investment firms and their third-party providers.
Who publishes the FS AI RMF, and is it mandatory?
The framework was published by the US Department of the Treasury in partnership with the Cyber Risk Institute, developed with input from more than 100 financial institutions alongside government agencies and standards bodies. It is voluntary and industry-led, not a supervisory rule, and non-adherence carries no direct penalty. Even so, a voluntary framework developed with Treasury and adopted widely across the sector tends to become the reference point examiners use when they ask how a firm governs AI.
What is in the framework?
The FS AI RMF is built to be operational, not principles-based. Firms work through three stages. An AI Adoption Stage Questionnaire classifies AI maturity. A Risk and Control Matrix (RCM) identifies which of the 230 control objectives apply at that stage. Implementation and documentation then follow the Guidebook and the Control Objective Reference Guide. The staged design means a community bank starting with a single vendor tool and a multinational running models across trading and underwriting are not held to the same control set.
How does it relate to the NIST AI RMF?
The FS AI RMF aligns to the NIST AI RMF and works as a sector overlay. It keeps NIST's structure while translating it into controls that reflect financial services obligations: explainability for credit decisions, bias monitoring across demographic groups, vendor and third-party inheritance risk, and operational risk from agentic systems in trading and underwriting. Firms already working to NIST are extending a programme they have, not starting a new one.
Why does it matter more after SR 26-2?
When SR 26-2 replaced SR 11-7 in April 2026, it placed generative AI and agentic AI outside the scope of model risk management guidance. That left US banks holding mature MRM frameworks which, by design, do not cover their fastest-growing category of AI. The FS AI RMF is currently the most developed sector framework that does cover it, so the two work together instead of overlapping: MRM guidance for models, and the FS AI RMF for the AI that MRM now expressly excludes.
Real world example:
A US regional bank runs a mature model risk management programme built for SR 11-7 and re-baselined against SR 26-2. Its GenAI customer-service assistant falls outside that guidance altogether. Instead of creating a second governance regime, the bank completes the AI Adoption Stage Questionnaire, identifies the FS AI RMF control objectives that apply at its maturity stage, and maps them onto its existing MRM evidence structure, reusing the same inventory, the same ownership records and the same review cadence. When examiners ask how AI is governed, there is one register covering models and AI systems together, with the applicable framework recorded against each entry.




