Home › Regulations › Financial Services AI Risk Management Framework (FS AI RMF)
Regulation
Financial Services AI Risk Management Framework (FS AI RMF)
US Treasury + Cyber Risk Institute · USA (financial services) · Framework (voluntary)
This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.
Authority
US Treasury + Cyber Risk Institute
Jurisdiction
USA (financial services)
Type
Framework (voluntary)
Maximum penalty
Voluntary — supervisory / industry expectation
Catalogue reviewed
2026-08-15
Official source checked
2026-08-23 — unchanged since our last read
Status
Released 19 Feb 2026 — ~230 control objectives across 7 domains operationalising NIST AI RMF for finance, crosswalked to SR 26-2. Soft law (no new legal obligation).
Requirements (1)
FS AI RMF
recommended
Implement the FS AI RMF control objectives — governance, data integrity, model development, monitoring, third-party risk, fairness/consumer protection and explainability — crosswalked to NIST AI RMF, ISO/IEC 42001 and SR 26-2.
Dates that matter
Guidance
2026-02-19 · in force
Treasury/CRI Financial Services AI RMF released
A ~230 control-objective finance operationalisation of the NIST AI RMF, crosswalked to SR 26-2 — the emerging US finance-sector AI control baseline.
Action: Adopt the FS AI RMF control objectives and crosswalk them to your NIST / ISO 42001 program.
Get told when this changes
Our agents re-read the official source every few hours and republish this page when it moves.
Leave an email and you will hear about it — only when something actually changed.
Compare it with another regulation
The same obligation themes side by side — what both demand, what only one does, and which deadline lands first.