Table of Contents
On February 19, 2026, the U.S. Department of the Treasury announced two resources for the financial sector: an Artificial Intelligence Lexicon and the Financial Services AI Risk Management Framework (FS AI RMF). The framework adapts the structure of NIST's AI Risk Management Framework to financial-services operations, regulation, consumer protection, cybersecurity, and resilience.
The FS AI RMF is a voluntary risk-management resource, not a new regulation or a substitute for applicable law, supervisory guidance, model-risk management, privacy obligations, or an institution's existing controls.
What the Treasury announcement introduced
The resources were developed through a public-private initiative involving the Financial Services Sector Coordinating Council, the Financial and Banking Information Infrastructure Committee, and the Artificial Intelligence Executive Oversight Group. The FS AI RMF workstream and the nonprofit Cyber Risk Institute produced the framework with participation from more than 100 financial institutions and input from U.S. and international agencies, including NIST.
The Treasury's official announcement says the shared terminology and sector-specific framework are intended to support more consistent governance, cybersecurity, operational resilience, accountability, and transparency.

The four FS AI RMF resources
The framework is a set of connected tools rather than a single list of mandatory requirements:
- AI Adoption Stage Questionnaire: helps an organization assess how extensively it uses AI and identify a relevant starting point.
- Risk and Control Matrix: pairs risk statements with control objectives and organizes them by adoption stage.
- User Guidebook: explains how to apply the framework and operationalize the selected objectives.
- Control Objective Reference Guide: gives examples of controls and effective evidence that may support an assessment.
The Cyber Risk Institute describes 230 control objectives across the framework. That number should not be treated as a requirement to implement every control in the same way. Institutions are expected to tailor the matrix to their adoption stage, use cases, risk profile, size, complexity, and existing governance. The full set of FS AI RMF resources and downloads is available from the institute.
How it relates to the NIST AI RMF
The FS AI RMF follows the four functions in NIST's voluntary AI framework:
| Function | Practical question for a financial institution |
|---|---|
| Govern | Who owns AI decisions, policies, risk tolerance, oversight, and accountability? |
| Map | Where is AI used, who can be affected, what data and vendors are involved, and what can go wrong? |
| Measure | How will the institution test performance, fairness, security, explainability, privacy, and reliability? |
| Manage | Which risks will be mitigated, transferred, accepted, or avoided, and how will the response be monitored? |
NIST stresses that these functions support continuous risk management across the AI lifecycle; they are not a fixed sequence or a universal checklist. The NIST AI Risk Management Framework remains the broader cross-sector foundation, while the FS AI RMF adds financial-services context and implementation material.
Why financial services needs sector-specific guidance
Financial institutions already manage technology, model, vendor, compliance, fraud, privacy, and operational risks. AI can cut across all of them. A model may influence lending, fraud detection, customer support, trading, claims, or employee decisions, while relying on sensitive data and third-party infrastructure.
Important risk areas include:
- Consumer and fairness risk: an automated decision may create or reinforce unequal outcomes.
- Opacity and explainability: staff may be unable to justify a result or reconstruct how it was produced.
- Data risk: training, retrieval, prompts, and logs may contain inaccurate, restricted, or sensitive information.
- Cybersecurity risk: attackers may manipulate inputs, extract information, abuse tools, or exploit connected systems.
- Third-party concentration: several important services may depend on the same model, cloud, or data provider.
- Operational resilience: variable output, service interruption, model changes, or weak human escalation can disrupt critical work.
- Legal and regulatory risk: an AI use case remains subject to the laws and obligations that govern the underlying activity.
Recognizing that a model can produce a fluent but unsupported answer is part of this work. TipsMake's guide to recognizing AI hallucinations and limitations offers a useful starting point for individual users, but an institution also needs documented testing, controls, ownership, and evidence.
How an institution can use the framework
1. Establish an AI inventory
Record each use case, owner, business purpose, affected people, data sources, model or vendor, integrations, decision authority, deployment status, and criticality. Include employee tools and embedded vendor features, not only systems built by the institution.
2. Assess the adoption stage
Complete the questionnaire using evidence from technology, risk, compliance, legal, procurement, security, data, and business teams. A single department should not assign the institution's stage without cross-functional review.
3. Map material risks and obligations
Describe the potential harm, likelihood, exposure, and existing safeguards for each use case. Identify applicable laws, contracts, supervisory expectations, recordkeeping duties, and customer-communication requirements with qualified counsel and compliance staff.
4. Select and tailor control objectives
Use the Risk and Control Matrix to identify relevant objectives. Map them to existing enterprise-risk, model-risk, cybersecurity, privacy, change-management, and third-party programs so teams do not create a disconnected AI-control process.
5. Define tests and evidence
For each control, name the owner, frequency, threshold, escalation path, and evidence retained. Evidence might include approvals, model cards, validation reports, data lineage, access reviews, vendor assessments, test results, monitoring records, incident tickets, or change logs, depending on the use case.
6. Monitor and reassess
Review material changes to models, prompts, retrieval sources, tools, vendors, and user populations. Track incidents and near misses in a central process, test whether mitigations work, and revisit the adoption assessment as AI use expands.
Questions leaders should ask before approving an AI use case
- What decision or task will the system influence, and who is accountable for the outcome?
- Can a person meaningfully review, override, or appeal a consequential result?
- What data enters the system, where does it go, and how long is it retained?
- How were accuracy, fairness, security, resilience, and explainability tested for this specific use?
- What changes when the model or third-party service is updated?
- What is the fallback when the system is unavailable or produces an unsafe result?
- Which evidence demonstrates that the control is operating, not merely documented?
A risk-based approach also means choosing appropriate tasks. Low-impact drafting or classification may need lighter controls than a system affecting credit, identity, fraud, or access to funds. See the practical criteria for choosing suitable AI tasks.
What the framework does not do
The FS AI RMF does not certify a system as safe, guarantee regulatory compliance, or eliminate the need for independent validation and professional judgment. It also should not be used to justify deploying a high-risk system simply because a set of boxes was checked.
Its main value is organizational: it gives financial institutions a shared vocabulary, a structured way to assess AI adoption, and a body of control objectives that can be integrated with existing governance. The strongest implementation will tie each selected control to a real risk, named owner, measurable test, retained evidence, and clear response when performance falls outside tolerance.
Reader Comments 0
Sign in with email or Google to join the discussion.