Feature AI Risk
FS AI RMF Gap Assessment: How to Score Your AI Program Against Treasury's 230 Control Objectives
Treasury's Financial Services AI Risk Management Framework gives financial institutions 230 control objectives across four maturity stages. Here's the gap assessment workflow your team should run before the next exam cycle.
Table of Contents
TL;DR
- Treasury and the Cyber Risk Institute published the FS AI RMF on February 19, 2026 — 230 control objectives across 7 domains, built with 108 financial institutions
- Four maturity stages: Initial (21 controls — the absolute floor), Minimal (126), Evolving (193), Embedded (all 230)
- The gap assessment workflow is: complete the questionnaire → determine your current stage → filter the RCM → score your gaps → build a remediation roadmap
- Examiners are already using FS AI RMF vocabulary during AI governance inquiries even without citing it as a formal requirement
- Most institutions deploying AI today are operating below Minimal stage — that gap is your exam risk
Four months ago, Treasury and the Cyber Risk Institute released a 230-control-objective framework representing the most specific AI governance guidance the US financial services sector has ever had. Built with 108 financial institutions over 18 months, the Financial Services AI Risk Management Framework (FS AI RMF) isn’t a federal regulation. It’s voluntary. And if you’re reading “voluntary” as “optional,” you’re setting up for an uncomfortable exam.
Examiners from the OCC, Fed, and FDIC have read this framework. When they ask how your institution governs AI — what framework you’re using, how you assess model risk for LLMs, what your third-party AI due diligence looks like — the FS AI RMF is the vocabulary they’ll use and the structure they’ll expect. “We follow NIST AI RMF” is a reasonable answer. “We also mapped our controls against the FS AI RMF” is a stronger one. “We haven’t heard of it” is a gap you’ll need to explain.
The framework is designed to be used as a gap assessment tool. The workflow is built in. Most institutions haven’t run it yet.
What the FS AI RMF Is — and What It Isn’t
The FS AI RMF is not another high-level principles document. It’s an operational framework: 230 specific control objectives, organized by domain and maturity stage, with implementation guidance attached to each one.
Four components:
- AI Adoption Stage Questionnaire — a structured assessment that classifies your institution into one of four stages based on the business impact of AI decisions, technological sophistication of your systems, and how broadly AI scales across the enterprise
- Risk and Control Matrix (RCM) — the 230 control objectives, tagged by domain and maturity stage, filterable to your current adoption profile
- Guidebook — implementation narrative explaining how to interpret and operationalize each control domain
- Control Objective Reference Guide — definitions, examples, and evidence descriptions for each control
What it isn’t: a replacement for OCC Bulletin 2026-13, SR 26-02, or NIST AI RMF 1.1. It’s a companion — one that fills the financial-services gap in those frameworks. Where OCC 2026-13 focuses on traditional predictive models and NIST provides general functions, the FS AI RMF gives you 230 control expectations that banking regulators and industry peers agreed are necessary for AI in regulated financial services. It also explicitly covers GenAI and third-party AI, which OCC 2026-13 excludes from scope.
For teams managing the GenAI governance gap while the OCC AI RFI is still pending, the FS AI RMF is the practical answer to “what framework are you applying?” See The GenAI Model Risk Gap for the full analysis of what OCC 2026-13’s GenAI exclusion means in practice.
The Four Maturity Stages
The FS AI RMF structures its 230 control objectives across four adoption stages. Your stage is determined by the questionnaire — not assigned by asset size or charter type, but scored based on how AI actually operates in your institution.
| Stage | Controls | What It Means |
|---|---|---|
| Initial | 21 | Absolute floor. Every institution deploying AI must meet these 21 controls regardless of scale or sophistication. If you’re not here, you have a finding. |
| Minimal | 126 | Move from ad-hoc to structured risk management: systematic validation, documented policies, formal review cycles, basic consumer protection controls. |
| Evolving | 193 | AI risk management integrates into your broader operational risk framework: advanced testing, cross-functional governance, proactive monitoring, third-party AI controls. |
| Embedded | 230 | Enterprise-embedded AI governance: board-level AI strategy, predictive monitoring, continuous improvement loops, enterprise risk appetite for AI. |
The 21 Initial-stage controls represent what the 108 institutions that built this framework collectively agreed is the absolute minimum for any institution deploying AI in any customer-impacting context. If your institution is running AI for credit decisioning, fraud detection, customer service, or compliance monitoring and hasn’t satisfied these 21 controls, you have gaps that examiners will find.
The gap between Initial and Minimal is where most community banks and mid-tier fintechs actively deploying AI sit today. Getting from wherever you are to Minimal — 126 controls — is the realistic 12-month target for institutions building AI governance programs in 2026.
The Seven Control Domains
The 230 control objectives span seven domains. A strong gap assessment covers all seven, because coverage gaps in any single domain create exam vulnerabilities even when every other domain is solid.
| Domain | What It Covers |
|---|---|
| Governance | Board oversight, AI strategy, roles and responsibilities, risk appetite for AI, accountability structures |
| Data | Training data sourcing, data quality validation, bias controls, data lineage, purpose limitation, privacy requirements at the data layer |
| Model Development | Development methodology documentation, testing protocols, conceptual soundness validation, development-stage controls |
| Validation | Independent validation, TEVV (testing, evaluation, validation, verification) approaches, challenge documentation, validation frequency and scope |
| Monitoring | Post-deployment performance tracking, drift detection, threshold-triggered review, escalation procedures when performance degrades |
| Third-Party AI | Vendor due diligence before deployment, contract requirements, ongoing monitoring of third-party AI tools, model update notification procedures |
| Consumer Protection | Adverse action handling, explainability requirements, human review triggers, non-discrimination controls, fairness testing |
Consumer Protection and Third-Party AI are where most institutions currently have the largest gaps. The traditional MRM framework under SR 11-7 didn’t address either at the level of specificity the FS AI RMF requires. Consumer protection controls — adverse action procedures, explainability documentation, human review triggers — are also where Colorado AI Act deployer obligations and CFPB adverse action guidance converge on your AI governance program. The FS AI RMF gives you a single control structure that addresses all of them.
The Gap Assessment Workflow
Running an FS AI RMF gap assessment takes four steps. The framework is designed for exactly this workflow — you’re not creating a process from scratch.
Step 1: Complete the AI Adoption Stage Questionnaire
The questionnaire scores three dimensions:
- Business impact: Are AI decisions low-touch (informational recommendations reviewed by humans before action) or high-stakes (autonomous credit decisions, fraud blocks, adverse action generation)?
- Technology sophistication: Are you using simple rule-based systems, conventional ML models, or large language models with generative capabilities?
- Enterprise scalability: Is AI deployed in one product line with one team, or deployed across multiple business lines, customer segments, and geographies?
Your score determines your stage. Be honest — underestimating your AI sophistication to land at a lower stage doesn’t reduce your risk. It just reduces your visibility into it and creates a documentation gap when an examiner asks about your AI inventory and your governance program doesn’t match what’s actually deployed.
Step 2: Filter the RCM to Your Stage
Once you have your current stage, use the RCM filter to generate the subset of control objectives applicable at that stage. Initial-stage institutions work through 21 controls. Minimal-stage institutions are looking at 126.
The RCM is already structured for this. Each control objective is tagged with the stage at which it becomes applicable. You’re not reading all 230 controls and deciding which apply — the framework tells you based on your questionnaire result.
Step 3: Score Your Current State
For each control in your filtered scope, assess your current state:
- In place: The control exists, is documented, and you have evidence it operates as intended
- Partial: The control exists informally or without documentation, or applies to some AI systems but not all
- Gap: The control doesn’t exist, isn’t documented, or lacks evidence of operation
Every “Partial” is a remediation item. Every “Gap” is a finding waiting to happen. The scoring produces your prioritized gap list.
Step 4: Build the Remediation Roadmap
Prioritize gaps by two factors: domain criticality and examiner visibility.
Highest priority: Consumer protection and governance gaps. These are where examiners look first and where regulatory consequences are most direct. An institution that can’t explain how it handles adverse action from an AI model, or that has no formal AI governance structure, has audit findings regardless of how strong its technical controls are.
Second priority: Third-party AI and monitoring gaps. The rapid proliferation of vendor AI tools — Microsoft Copilot, Salesforce Einstein, third-party fraud platforms — means most institutions are running AI they didn’t build and aren’t fully monitoring. The FS AI RMF’s Third-Party AI domain addresses exactly this.
Third priority: Data and validation gaps. These are technically significant but tend to be less immediately visible to examiners until they dig into specific model reviews.
Assign owners and target dates for each gap. The roadmap itself is an exam artifact — it demonstrates that your institution has assessed its gaps and has a credible, owned plan to close them.
What Examiners Are Actually Looking For
The FS AI RMF is voluntary, but its influence on examiner expectations is real. Institutions in AI-related exam inquiries since February 2026 have reported examiners asking questions that track directly to FS AI RMF structure:
- Does your institution have a formal AI inventory? (Governance domain, Initial stage)
- How do you assess third-party AI tools before deployment? (Third-Party AI domain, Minimal stage)
- What monitoring do you have on AI systems after deployment? (Monitoring domain, Minimal stage)
- How do you handle adverse actions generated or influenced by AI? (Consumer Protection domain, Minimal stage)
- Does your board have visibility into AI risk? (Governance domain, Evolving stage)
These questions aren’t random. They map directly to FS AI RMF domain and stage structure. An institution that has run the gap assessment and documented gaps and remediation plans can answer from a position of strength. An institution that hasn’t is answering from a blank page.
The Mondaq analysis of the FS AI RMF makes the stakes clear: the framework is designed to be “audit-ready” architecture, not aspirational guidance. The 230 control objectives aren’t aspirational — they’re what 108 financial institutions and their regulators agreed represents sound AI governance practice.
So What?
The gap between where most AI governance programs sit today and what the FS AI RMF defines as Minimal stage is real, measurable, and closeable. The framework gives you the tools: the questionnaire to determine your stage, the RCM to identify your gaps, and the Guidebook to tell you what good looks like.
What it can’t do is run the assessment or build the documentation for you.
A first-pass gap assessment against the 21 Initial-stage controls is the realistic first step for any institution with AI in production. If you’re not there, start there. The 126 Minimal-stage controls are the credible baseline for an institution that wants to answer exam questions from evidence rather than explanation.
The FS AI RMF assessment will surface gaps in your inventory documentation, vendor due diligence processes, consumer protection procedures, and monitoring frameworks. Those are also the gaps that the AI Risk Assessment Template & Guide is built to close — with a pre-deployment scorecard, vendor AI questionnaire, model inventory template, Shadow AI register, and eight worked examples for the use cases examiners scrutinize most.
Running the gap assessment is the diagnostic. Building the documentation is the treatment. Start the diagnostic now, before your next exam cycle makes it urgent.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Is the FS AI RMF mandatory or voluntary?
How long does a first-pass gap assessment take?
Which maturity stage should our institution be targeting?
How does the FS AI RMF relate to OCC Bulletin 2026-13 and SR 26-02?
Where do I get the actual questionnaire and Risk and Control Matrix?
What's the relationship between the FS AI RMF and NIST AI RMF?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026