shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / AI Governance / post · -banks
AI GovernanceFinancial ServicesNIST AI RMFModel Risk Management

US Treasury Financial Services AI Risk Management Framework: A Practical Guide for Banks

The US Treasury FS AI RMF, issued in February 2026, gives banks a 230-control-objective matrix for governing AI. Here is how to prioritize it against SR 26-2 and your existing model risk program.

D
By the DSE practice team
Operator-led practice · how we research & review
August 1, 2026
15 min · 3,401 words

By the DSE practice team · published August 1, 2026 · reviewed August 1, 2026

The US Treasury Financial Services AI Risk Management Framework, published in February 2026, is the first sector-specific AI governance framework designed for banking and financial services. It gives a Head of Model Risk, Chief Risk Officer, or Chief Compliance Officer a structured 230-control-objective matrix aligned to the NIST AI Risk Management Framework and adapted to the supervisory environment banks already operate in. The framework is soft law: it does not create new regulatory mandates, but it is already shaping what examiners, internal auditors, and third-party oversight programs expect to find.

This guide explains what the Treasury FS AI RMF actually requires, how it maps to SR 26-2 and the NIST AI RMF your institution likely already references, which of the 230 control objectives to prioritize first, and what an audit-ready posture against the framework looks like in practice.

What the Treasury FS AI RMF Is and What It Is Not

The Financial Services AI Risk Management Framework was issued by the US Department of the Treasury in partnership with the Cyber Risk Institute. It was developed collaboratively with more than 100 financial institutions through the Financial Services Sector Coordinating Council (FSSCC). The framework consists of four components.

The AI adoption stage questionnaire helps an institution assess where it sits on the AI adoption continuum, from exploration through scaled production deployment. It is a starting-point diagnostic, not a compliance checklist.

The risk and control matrix is the operational core. It organizes 230 control objectives across governance domains, mapping each objective to a risk area and to the NIST AI RMF functions (GOVERN, MAP, MEASURE, MANAGE). This is the component most relevant to a model risk officer or compliance team preparing for examination.

The user guidebook provides implementation context, explaining the framework’s structure, the relationship between components, and how institutions at different adoption stages should sequence their work.

The control objective reference guide provides the detailed rationale behind each of the 230 objectives, linking them to existing regulatory expectations and supervisory guidance.

What the Treasury FS AI RMF is not: it is not a regulation and it does not supersede SR 26-2, the April 2026 interagency model risk guidance that replaced SR 11-7. It does not create a certification program, and no institution should claim FS AI RMF compliance as a regulatory posture. DSE prepares organizations for audit and examination; we do not certify, and we do not guarantee any exam or audit outcome. The framework’s own language characterizes it as soft law, intended to standardize how financial institutions address and document AI risk governance.

How the Treasury FS AI RMF Maps to SR 26-2 and the NIST AI RMF

The Treasury FS AI RMF extends the NIST AI RMF 1.0 (GOVERN, MAP, MEASURE, MANAGE) for the financial sector. If your institution already references NIST AI RMF, the four-function structure is familiar: the Treasury framework adds financial-services-specific control objectives inside each function and introduces adoption-stage weighting so the right controls surface at the right maturity level.

SR 26-2, the April 2026 Federal Reserve guidance with parallel OCC Bulletin 2026-13, is the binding model risk supervisory framework for US banks. The scope boundary matters here: SR 26-2 governs statistical and machine-learning models in the model risk perimeter. It explicitly excludes generative AI and agentic AI from its model-risk scope. Those systems fall outside SR 26-2 and are governed through the NIST AI RMF applied by analogy, the June 2023 Interagency Guidance on Third-Party Relationships: Risk Management (which updated and supplemented OCC Bulletin 2013-29), fair lending under ECOA and Regulation B, and UDAP/UDAAP prohibitions.

The Treasury FS AI RMF bridges this gap. Its 230 control objectives cover both traditional model AI (where SR 26-2 applies) and generative and agentic AI (where it does not). This is its primary additive value for a bank already running SR 26-2: it provides a structured control vocabulary for the AI systems that fall outside the model-risk perimeter.

Framework Scope Binding? Primary use for a US bank
SR 26-2 / OCC Bulletin 2026-13 Statistical and ML models; excludes GenAI and agentic AI Non-binding supervisory guidance, but examination-standard Model inventory, validation, effective challenge, monitoring for in-scope models
NIST AI RMF 1.0 All AI across the lifecycle Voluntary, no certification Shared governance language; organizes AI-specific risk beyond the model perimeter
Treasury FS AI RMF All AI in financial services, adoption-stage aware Soft law, not a regulation 230-objective control matrix for examination and audit readiness; bridges SR 26-2 and GenAI governance gap
ISO/IEC 42001:2023 All AI, certifiable management system Certifiable, not a US exam tool Procurement signaling, board and third-party assurance

The right division of labor: SR 26-2 governs your in-perimeter models; the Treasury FS AI RMF plus NIST AI RMF govern the rest of your AI footprint; ISO 42001 is your procurement and board-assurance posture. They are complementary, not competing.

Prioritizing the 230 Control Objectives

Two hundred and thirty control objectives is a large surface, and no institution should attempt to address them all simultaneously. The framework’s adoption-stage structure exists precisely to address this: control obligations scale with how far an institution has deployed AI into production.

A community bank or mid-size institution in early adoption should focus on the GOVERN and MAP objectives first. These establish the AI inventory, the risk-tiering standard, accountability assignments, and policy. Without MAP (the inventory), none of the downstream objectives can be applied to real systems. Without GOVERN (policy and accountability), no owner exists to act on what MAP surfaces.

The following priority sequence reflects the logical dependency of the framework:

Step 1: Inventory and tiering (MAP objectives). Build a current, risk-tiered AI inventory. Record each system, its owner, the data it handles, its place in a decision, and whether it has been reviewed. The Treasury FS AI RMF, like the NIST AI RMF, treats the inventory as the prerequisite for every downstream control objective.

Step 2: Policy and accountability (GOVERN objectives). Establish an AI use policy, a risk-tiering standard, and named accountable owners for each tier. Define the review cadence and the escalation path for flagged risks. Link the policy to your existing SR 26-2 model risk policy so the two programs share a common governance structure rather than operating in parallel silos.

Step 3: Third-party AI controls (MAP and GOVERN objectives for vendor AI). Map every third-party AI dependency, including foundation-model providers, AI-enabled SaaS, and API-connected AI services, to the June 2023 interagency third-party risk guidance. Document the due-diligence evidence, the contract rights (audit access, breach notification, exit plan), and the ongoing monitoring cadence. This cluster of objectives addresses the most common examiner finding in AI oversight: institutions know what internal AI they have built, but they cannot account for the AI embedded in their vendors.

Step 4: Testing and monitoring (MEASURE objectives). Extend your SR 26-2 validation discipline to cover drift detection for models that change over time, bias and fair-lending testing under ECOA and Regulation B for any AI touching credit decisions, and adversarial testing for generative and LLM-powered systems mapped to the OWASP LLM Top 10. These objectives build on what a strong SR 26-2 validation program already does; they add coverage for AI-specific failure modes.

Step 5: Response and remediation (MANAGE objectives). Define the response path when a test fails, the authority to restrict or retire a system, and the documented disposition for every accepted risk. Wire findings to action rather than letting them accumulate in a validation report.

What Soft Law Means for Your Examination Posture

Soft law in US financial services has a defined track record. Guidance that is not a rule still shapes examinations when it reflects what examiners believe prudent practice looks like. The Treasury FS AI RMF is already shaping that expectation for AI governance in three ways.

First, it provides a shared vocabulary. Examiners who reference the framework expect an institution to know its components. A Chief Risk Officer who cannot explain which of the 230 control objectives the institution has addressed will face a more pointed conversation than one who can explain where the program stands and what the remaining gaps are.

Second, it surfaces what is missing. The risk and control matrix was developed with more than 100 financial institutions, which means its objectives reflect what those institutions identified as actual gaps. An institution that works through the matrix honestly will find real gaps in its AI governance program, not a checklist exercise.

Third, it standardizes third-party negotiations. Institutions are already citing the Treasury FS AI RMF in AI vendor due-diligence questionnaires and in contract negotiations for foundation-model provider agreements. Vendors who have not engaged with the framework’s control objectives face increasingly pointed procurement conversations.

Building an Audit-Ready Posture Against the Treasury FS AI RMF

An audit-ready posture against the Treasury FS AI RMF is not a separate program. It is a layering exercise on top of the SR 26-2 and NIST AI RMF governance your institution should already be running.

The starting point is the AI inventory, tiered by risk. Without a current inventory, the 230 control objectives have no systems to attach to, and any readiness claim is indefensible. A tiered inventory connects each system to the tier-appropriate control objectives, makes the governance scope visible to an examiner, and is the first artifact an internal auditor or examiner will ask to see.

The second layer is evidence. For each control objective you claim to address, there should be a corresponding artifact: a validation report, a monitoring dashboard, a vendor due-diligence file, a committee minute recording an accepted risk, or a fair-lending test result. The goal of the evidence layer is traceability: showing the chain from a risk identified in MAP, measured in MEASURE, governed in GOVERN, and acted on in MANAGE.

The third layer is the honest gap register. No institution will have full coverage of 230 objectives, and an examiner does not expect perfection. What examiners look for is a program that knows where it stands. A documented gap register with a prioritized remediation plan is stronger evidence of a functioning program than a claim of complete coverage that falls apart under questioning.

Finally, the “document once, tag twice” principle applies here as it does across all AI governance frameworks. Controls your institution already maintains for SOC 2, ISO 27001, or internal audit can be tagged to the corresponding Treasury FS AI RMF objective without creating new documentation. The new work concentrates in the genuinely AI-specific places: drift monitoring, adversarial testing, fair-lending bias assessment, and foundation-model due diligence.

What this guide is / What it is not

What it is: A practitioner guide to the US Treasury Financial Services AI Risk Management Framework for banks and fintechs, explaining its four components, how it maps to SR 26-2 and the NIST AI RMF, how to prioritize the 230 control objectives, and what an audit-ready posture looks like in practice. Intended for Heads of Model Risk, Chief Risk Officers, and Chief Compliance Officers preparing for examination or internal audit.

What it is not: Legal or regulatory advice, a certification, a conformity assessment, or a guarantee of any exam or audit outcome. The Treasury FS AI RMF is soft law and does not create new regulatory mandates. DSE prepares organizations for audit and examination; we do not certify, and we do not guarantee any examination outcome. Any vendor promising guaranteed regulatory approval is selling certainty that does not exist.

FAQ

What is the US Treasury Financial Services AI Risk Management Framework? The Treasury Financial Services AI Risk Management Framework (FS AI RMF) is a sector-specific AI governance framework published by the US Department of the Treasury in February 2026, in partnership with the Cyber Risk Institute and developed with more than 100 financial institutions through the FSSCC. It consists of four components: an AI adoption stage questionnaire, a risk and control matrix with 230 control objectives, a user guidebook, and a control objective reference guide. It extends the NIST AI RMF for the specific supervisory environment of US banks and fintechs.

Is the Treasury FS AI RMF a regulation banks must comply with? No. The Treasury FS AI RMF is soft law: it does not create new legal obligations and is not a regulation. However, it is already shaping what examiners, internal auditors, and third-party oversight programs expect to find. Institutions that cannot explain which control objectives they have addressed will face more pointed examination conversations. DSE prepares organizations for audit and examination readiness; we do not certify and we do not guarantee any exam or audit outcome.

How does the Treasury FS AI RMF relate to SR 26-2? SR 26-2, the April 2026 interagency model risk guidance, governs statistical and machine-learning models and explicitly excludes generative AI and agentic AI from its model-risk scope. The Treasury FS AI RMF covers all AI in financial services, including systems that fall outside SR 26-2. The two frameworks are complementary: SR 26-2 governs in-perimeter models; the Treasury FS AI RMF plus NIST AI RMF governs the rest of the AI footprint.

Where should a bank start with the 230 control objectives? Start with MAP objectives to build a current, risk-tiered AI inventory. Without an inventory, none of the other control objectives can be applied to real systems. Then address GOVERN objectives to establish an AI use policy, risk-tiering standard, and named accountable owners. Third-party AI controls come next, because vendor AI is the most common examiner gap. Then extend testing and monitoring through MEASURE objectives, and finally wire MANAGE objectives so findings drive documented action rather than accumulating in reports.

What evidence does an examiner expect to find for the Treasury FS AI RMF? Examiners expect a current, risk-tiered AI inventory; an AI use policy with named owners; vendor due-diligence files for every third-party AI dependency; fair-lending test results for AI touching credit decisions; validation and monitoring evidence for in-perimeter models; and a documented gap register with a prioritized remediation plan. Complete coverage of all 230 objectives is not the standard; a program that knows where it stands and has a remediation plan is.

The Bottom Line

The US Treasury Financial Services AI Risk Management Framework matters for one reason above all others: it is the first sector-specific AI governance standard developed with the involvement of over 100 financial institutions and the backing of the US Treasury, and it is already influencing what examiners, auditors, and vendors expect from a bank’s AI program. A Chief Risk Officer who cannot account for the framework in an examination conversation is at a disadvantage compared to one who can.

For a bank already running SR 26-2 model risk governance and referencing the NIST AI RMF, the incremental work is manageable. The Treasury FS AI RMF fills the governance gap for generative and agentic AI that SR 26-2 explicitly excludes, provides a structured control vocabulary that examiners can reference, and creates a standard surface for vendor due-diligence negotiations. The 230 control objectives, sequenced by adoption stage and layered onto existing governance rather than rebuilt from scratch, are a realistic program for a mid-size institution that already has its model risk program in order.

The first move is the AI inventory. Every other control objective depends on knowing what systems exist, who owns them, and what data they touch. If your inventory is current and risk-tiered, you have the foundation. If it is not, that is where to start, because nothing downstream works without it. When you are ready to map your AI program to the Treasury FS AI RMF control objectives and build your audit-ready posture, the AI governance readiness engagement is built to do exactly that.


Use the AI governance maturity self-assessment to score your program against the NIST AI RMF functions that the Treasury framework extends, identify the priority gaps, and build the board-ready summary your committee needs before a readiness engagement. For a broader treatment of AI governance in financial services and how the Treasury FS AI RMF fits the full regulatory stack, see the banking AI governance hub.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly, or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter