What Is the Financial Services AI Risk Management Framework (FS AI RMF)?

The FS AI RMF is an industry-led framework for managing AI risk in financial institutions. Released by the U.S. Treasury and authored by the Cyber Risk Institute in coordination with the Financial Services Sector Coordinating Council, it builds on the NIST AI RMF and tailors it to financial services industry. It’s a substantial document, but it’s not a one-size-fits-all mandate. It’s a flexible starting point that institutions scale to their own size and risk level.

A sector-specific framework, built on NIST

In February 2026, the U.S. Treasury released the FS AI RMF in support of President Trump’s AI Action Plan. The FS AI RMF was developed by the Cyber Risk Institute in coordination with the Financial Services Sector Coordinating Council through collaboration with more than 100 financial institutions. The headline for any governance team already working with NIST: it doesn’t replace the NIST AI RMF, it builds on it. The framework keeps NIST’s structure and translates it into control objectives specific to financial services, addressing risks traditional frameworks tend to miss in the sector, including bias, model opacity, and AI-specific cybersecurity exposures.

If you’ve already documented practices against the NIST AI RMF, you’re not starting from zero.

FS AI RMF: Who it’s for

The framework was designed for the full range of financial institutions, from community banks and credit unions to multinational banks, insurers, and investment firms, along with the third-party providers that serve them. Within those organizations, it targets the people responsible for oversight including risk, compliance, legal, and technology leaders.

Adoption is voluntary. The FS AI RMF complements existing frameworks and regulatory guidance rather than adding a new mandate, and it’s built to slot into governance programs you already run.

Substantial, and meant to be filtered

This is the part to plan for. With more than 200 control objectives, the FS AI RMF is a big document, and no institution is expected to implement all of it at once.

That’s by design. Like the NIST AI RMF it builds on, the framework rejects the single-checklist approach. What applies to you depends on your AI adoption stage and your risk level. A community bank early in its AI journey doesn’t carry the same load as a multinational running AI across critical decisions. The framework’s job is to help you determine what’s relevant, apply the right controls to the right use cases, document the evidence, and reassess as your AI footprint changes.

In other words, it’s a foundation for building a risk-based governance function, rather than a compliance burden to absorb wholesale.

Why it matters now

The FS AI RMF gives risk and compliance teams a credible, sector-specific structure to point to, shaped by practitioners who understand real operational constraints.

But a framework this large only delivers value if you can map it to your actual AI portfolio, figure out what applies at your risk level, and prove the controls are working. That’s the gap between having a framework and running a program against it.

This is where purpose-built governance infrastructure earns its place. The FS AI RMF is now available as a compliance framework in Trustible, mapped and ready to use alongside the NIST AI RMF it builds on. So instead of translating 200-plus control objectives into a workable program by hand, you document governance practices once and map them across frameworks, without starting over each time a new one lands. Trustible triages use cases by risk level, which is exactly the filtering the FS AI RMF asks for, and turns control objectives into audit-ready evidence rather than claims on a spreadsheet.

The framework gives financial institutions a strong starting point. Turning it into governance you can prove is the work that follows.

Want to see how Trustible maps to the NIST AI RMF and sector frameworks like the FS AI RMF? Request a demo.

FAQ

How do you get started with the FS AI RMF?


The framework has a built-in sequence, and it isn’t “start reading at control one.” First, complete the AI Adoption Stage Questionnaire, a self-assessment that places your organization into one of four maturity levels based on business impact, technology implementation, and scalability. That stage then determines which controls in the Risk & Control Matrix actually apply to you, since the objectives are cumulative and organized by stage rather than presented as one flat list. From there, the Guidebook and the companion Control Objective Reference Guide walk you through implementing and documenting each relevant control, including what counts as acceptable evidence. Scope and prioritize first; implement second.

What are the four components of the FS AI RMF?


The framework is made up of four coordinated pieces: the AI Adoption Stage Questionnaire, which classifies your organization’s maturity; the Risk and Control Matrix (RCM), which contains the 230 control objectives organized by stage; the Guidebook, which provides step-by-step implementation guidance; and the Control Objective Reference Guide, which gives worked examples of controls and the “effective evidence” examiners and auditors would expect to see for each one.

What are the AI adoption stages, and how do I know which one applies to us?


The Questionnaire sorts institutions into four stages, cumulative from least to most mature: Initial, Minimal, Evolving, and Embedded. Classification is based on business impact, technology implementation, and scalability, not simply how much AI you’ve deployed. Each stage inherits the requirements of the one before it, so an Embedded-stage institution is expected to meet all 230 control objectives, while an Initial-stage institution starts with a much smaller, baseline set. Practically, this means smaller or earlier-stage institutions aren’t expected to build Embedded-level governance on day one. The framework scales the workload to match where you actually are.

How does the FS AI RMF relate to model risk management and SR 26-2?


The FS AI RMF doesn’t replace SR 26-2 or other model risk management (MRM) guidance that examiners already anchor to. It’s designed to sit alongside it. Where SR 26-2 sets expectations around model inventory, validation, and ongoing monitoring, the FS AI RMF extends those same governance disciplines to AI-specific concerns, like foundation models, LLM behavior, and vendor-supplied AI tools. For institutions that already run a mature MRM program, the practical move is to treat the FS AI RMF’s control objectives as an AI-specific layer on top of existing model risk governance rather than a parallel, competing process.

Is the FS AI RMF mandatory, and will examiners hold us to it?


No, the framework itself creates no new legal obligation. Treasury and CRI describe it as voluntary and complementary to existing frameworks. That said, “voluntary” and “irrelevant to exams” aren’t the same thing. Because it’s the first sector-specific, practitioner-built AI framework of its kind for financial services, it’s likely to become a reference point in examinations, internal audit expectations, and third-party due diligence, even in the absence of a regulator formally requiring it. Institutions that treat it purely as optional reading, rather than as a framework worth having a documented position on, are taking on unnecessary exam risk.

How many control objectives are there, and what categories do they cover?


There are 230 control objectives, organized across categories including governance, data, model development, validation, monitoring, third-party risk, and consumer protection. They’re also mapped to the four NIST AI RMF functions, Govern, Map, Measure, and Manage, so institutions already working from that structure can see where each new control fits.

What’s the difference between the FS AI RMF and the NIST AI RMF?


The FS AI RMF keeps NIST’s four-function structure but fills in the sector-specific detail: concrete control objectives tied to financial services risks like algorithmic bias and fair lending, model opacity, AI-specific cybersecurity exposures, and third-party or vendor AI risk. It also adds a mechanism NIST doesn’t have, the adoption-stage scaling model, so institutions can tell not just what the principles mean but which controls apply to them right now.

In this article

    AI Clarity Starts Here

    AI clarity is a growth strategy

    See how Trustible helps governance teams approve more AI, faster.