Regulatory brief · Treasury FS AI RMF
230 controls, published two months before the gap opened.
Treasury released the Financial Services AI Risk Management Framework on 19 February 2026, adapting the NIST AI RMF into 230 operational control objectives for financial institutions. Two months later SR 26-2 placed generative and agentic AI outside model-risk guidance. The sequence is why this framework matters.
Status: not binding, and likely to be used anyway
The FS AI RMF is not a regulation and creates no new legal obligations. It was produced through public-private collaboration rather than rulemaking.
That is not the same as irrelevant. Voluntary sector frameworks developed with regulator involvement tend to become examination scaffolding — the reference an examiner reaches for when asking how you govern AI. Expect to be asked how your programme maps to it, even though non-conformance carries no direct penalty.
It covers AI broadly, including generative AI. That is precisely the ground SR 26-2 vacated, which makes this the strongest published answer to “what framework governs our agentic AI, then?”
What it contains
Four components: an AI Adoption Stage Questionnaire that scales control expectations to your deployment maturity, a Risk and Control Matrix, an Implementation Guidebook, and a Control Objective Reference Guide running past 400 pages.
The 230 control objectives span seven areas: governance, data, model development, validation, monitoring, third-party risk, and consumer protection. Each comes with compliance evidence examples — the framework specifies not only what to control but what artefact demonstrates the control is operating.
That last detail is the useful one. A control you cannot evidence is a control you cannot demonstrate in an examination, and most AI governance programmes fail on evidence rather than on intent.
Where Sentinel maps
| Control area | Evidence Sentinel produces |
|---|---|
| Governance | Policy versioning, RBAC, mode changes recorded as governance events with a named accountable owner |
| Data | Completeness, validity and consistency scored on every decision |
| Validation | Release-gated eval sets; held-out cases must pass before a policy change ships |
| Monitoring | Bias and drift monitoring; monthly QA sampling with disagreement rate as a board metric |
| Third-party risk | Vendor register inheriting materiality from the agent types each product feeds |
| Consumer protection | Disparate-impact detection, prohibited-factor checks, ECOA reason codes |
We map to control areas rather than claiming coverage of 230 objectives. Anyone claiming a product satisfies all 230 has not read the Reference Guide.
Sources
Check every claim above. We would rather you did.
If we have characterised any of this incorrectly, tell us and we will correct the page.
Design partners
Bring the questionnaire.
The Adoption Stage Questionnaire is a good first conversation. Tell us where you actually are and we will show you which controls we evidence and which we do not.