Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

FS AI RMF Gap Assessment: How to Score Your AI Program Against Treasury's 230 Control Objectives

Treasury's Financial Services AI Risk Management Framework gives financial institutions 230 control objectives across four maturity stages. Here's the gap assessment workflow your team should run before the next exam cycle.

By Rebecca Leung · June 8, 2026 ·
Table of Contents

TL;DR

  • Treasury and the Cyber Risk Institute published the FS AI RMF on February 19, 2026 — 230 control objectives across 7 domains, built with 108 financial institutions
  • Four maturity stages: Initial (21 controls — the absolute floor), Minimal (126), Evolving (193), Embedded (all 230)
  • The gap assessment workflow is: complete the questionnaire → determine your current stage → filter the RCM → score your gaps → build a remediation roadmap
  • Examiners are already using FS AI RMF vocabulary during AI governance inquiries even without citing it as a formal requirement
  • Most institutions deploying AI today are operating below Minimal stage — that gap is your exam risk

Four months ago, Treasury and the Cyber Risk Institute released a 230-control-objective framework representing the most specific AI governance guidance the US financial services sector has ever had. Built with 108 financial institutions over 18 months, the Financial Services AI Risk Management Framework (FS AI RMF) isn’t a federal regulation. It’s voluntary. And if you’re reading “voluntary” as “optional,” you’re setting up for an uncomfortable exam.

Examiners from the OCC, Fed, and FDIC have read this framework. When they ask how your institution governs AI — what framework you’re using, how you assess model risk for LLMs, what your third-party AI due diligence looks like — the FS AI RMF is the vocabulary they’ll use and the structure they’ll expect. “We follow NIST AI RMF” is a reasonable answer. “We also mapped our controls against the FS AI RMF” is a stronger one. “We haven’t heard of it” is a gap you’ll need to explain.

The framework is designed to be used as a gap assessment tool. The workflow is built in. Most institutions haven’t run it yet.

What the FS AI RMF Is — and What It Isn’t

The FS AI RMF is not another high-level principles document. It’s an operational framework: 230 specific control objectives, organized by domain and maturity stage, with implementation guidance attached to each one.

Four components:

  • AI Adoption Stage Questionnaire — a structured assessment that classifies your institution into one of four stages based on the business impact of AI decisions, technological sophistication of your systems, and how broadly AI scales across the enterprise
  • Risk and Control Matrix (RCM) — the 230 control objectives, tagged by domain and maturity stage, filterable to your current adoption profile
  • Guidebook — implementation narrative explaining how to interpret and operationalize each control domain
  • Control Objective Reference Guide — definitions, examples, and evidence descriptions for each control

What it isn’t: a replacement for OCC Bulletin 2026-13, SR 26-02, or NIST AI RMF 1.1. It’s a companion — one that fills the financial-services gap in those frameworks. Where OCC 2026-13 focuses on traditional predictive models and NIST provides general functions, the FS AI RMF gives you 230 control expectations that banking regulators and industry peers agreed are necessary for AI in regulated financial services. It also explicitly covers GenAI and third-party AI, which OCC 2026-13 excludes from scope.

For teams managing the GenAI governance gap while the OCC AI RFI is still pending, the FS AI RMF is the practical answer to “what framework are you applying?” See The GenAI Model Risk Gap for the full analysis of what OCC 2026-13’s GenAI exclusion means in practice.

The Four Maturity Stages

The FS AI RMF structures its 230 control objectives across four adoption stages. Your stage is determined by the questionnaire — not assigned by asset size or charter type, but scored based on how AI actually operates in your institution.

StageControlsWhat It Means
Initial21Absolute floor. Every institution deploying AI must meet these 21 controls regardless of scale or sophistication. If you’re not here, you have a finding.
Minimal126Move from ad-hoc to structured risk management: systematic validation, documented policies, formal review cycles, basic consumer protection controls.
Evolving193AI risk management integrates into your broader operational risk framework: advanced testing, cross-functional governance, proactive monitoring, third-party AI controls.
Embedded230Enterprise-embedded AI governance: board-level AI strategy, predictive monitoring, continuous improvement loops, enterprise risk appetite for AI.

The 21 Initial-stage controls represent what the 108 institutions that built this framework collectively agreed is the absolute minimum for any institution deploying AI in any customer-impacting context. If your institution is running AI for credit decisioning, fraud detection, customer service, or compliance monitoring and hasn’t satisfied these 21 controls, you have gaps that examiners will find.

The gap between Initial and Minimal is where most community banks and mid-tier fintechs actively deploying AI sit today. Getting from wherever you are to Minimal — 126 controls — is the realistic 12-month target for institutions building AI governance programs in 2026.

The Seven Control Domains

The 230 control objectives span seven domains. A strong gap assessment covers all seven, because coverage gaps in any single domain create exam vulnerabilities even when every other domain is solid.

DomainWhat It Covers
GovernanceBoard oversight, AI strategy, roles and responsibilities, risk appetite for AI, accountability structures
DataTraining data sourcing, data quality validation, bias controls, data lineage, purpose limitation, privacy requirements at the data layer
Model DevelopmentDevelopment methodology documentation, testing protocols, conceptual soundness validation, development-stage controls
ValidationIndependent validation, TEVV (testing, evaluation, validation, verification) approaches, challenge documentation, validation frequency and scope
MonitoringPost-deployment performance tracking, drift detection, threshold-triggered review, escalation procedures when performance degrades
Third-Party AIVendor due diligence before deployment, contract requirements, ongoing monitoring of third-party AI tools, model update notification procedures
Consumer ProtectionAdverse action handling, explainability requirements, human review triggers, non-discrimination controls, fairness testing

Consumer Protection and Third-Party AI are where most institutions currently have the largest gaps. The traditional MRM framework under SR 11-7 didn’t address either at the level of specificity the FS AI RMF requires. Consumer protection controls — adverse action procedures, explainability documentation, human review triggers — are also where Colorado AI Act deployer obligations and CFPB adverse action guidance converge on your AI governance program. The FS AI RMF gives you a single control structure that addresses all of them.

The Gap Assessment Workflow

Running an FS AI RMF gap assessment takes four steps. The framework is designed for exactly this workflow — you’re not creating a process from scratch.

Step 1: Complete the AI Adoption Stage Questionnaire

The questionnaire scores three dimensions:

  • Business impact: Are AI decisions low-touch (informational recommendations reviewed by humans before action) or high-stakes (autonomous credit decisions, fraud blocks, adverse action generation)?
  • Technology sophistication: Are you using simple rule-based systems, conventional ML models, or large language models with generative capabilities?
  • Enterprise scalability: Is AI deployed in one product line with one team, or deployed across multiple business lines, customer segments, and geographies?

Your score determines your stage. Be honest — underestimating your AI sophistication to land at a lower stage doesn’t reduce your risk. It just reduces your visibility into it and creates a documentation gap when an examiner asks about your AI inventory and your governance program doesn’t match what’s actually deployed.

Step 2: Filter the RCM to Your Stage

Once you have your current stage, use the RCM filter to generate the subset of control objectives applicable at that stage. Initial-stage institutions work through 21 controls. Minimal-stage institutions are looking at 126.

The RCM is already structured for this. Each control objective is tagged with the stage at which it becomes applicable. You’re not reading all 230 controls and deciding which apply — the framework tells you based on your questionnaire result.

Step 3: Score Your Current State

For each control in your filtered scope, assess your current state:

  • In place: The control exists, is documented, and you have evidence it operates as intended
  • Partial: The control exists informally or without documentation, or applies to some AI systems but not all
  • Gap: The control doesn’t exist, isn’t documented, or lacks evidence of operation

Every “Partial” is a remediation item. Every “Gap” is a finding waiting to happen. The scoring produces your prioritized gap list.

Step 4: Build the Remediation Roadmap

Prioritize gaps by two factors: domain criticality and examiner visibility.

Highest priority: Consumer protection and governance gaps. These are where examiners look first and where regulatory consequences are most direct. An institution that can’t explain how it handles adverse action from an AI model, or that has no formal AI governance structure, has audit findings regardless of how strong its technical controls are.

Second priority: Third-party AI and monitoring gaps. The rapid proliferation of vendor AI tools — Microsoft Copilot, Salesforce Einstein, third-party fraud platforms — means most institutions are running AI they didn’t build and aren’t fully monitoring. The FS AI RMF’s Third-Party AI domain addresses exactly this.

Third priority: Data and validation gaps. These are technically significant but tend to be less immediately visible to examiners until they dig into specific model reviews.

Assign owners and target dates for each gap. The roadmap itself is an exam artifact — it demonstrates that your institution has assessed its gaps and has a credible, owned plan to close them.

What Examiners Are Actually Looking For

The FS AI RMF is voluntary, but its influence on examiner expectations is real. Institutions in AI-related exam inquiries since February 2026 have reported examiners asking questions that track directly to FS AI RMF structure:

  • Does your institution have a formal AI inventory? (Governance domain, Initial stage)
  • How do you assess third-party AI tools before deployment? (Third-Party AI domain, Minimal stage)
  • What monitoring do you have on AI systems after deployment? (Monitoring domain, Minimal stage)
  • How do you handle adverse actions generated or influenced by AI? (Consumer Protection domain, Minimal stage)
  • Does your board have visibility into AI risk? (Governance domain, Evolving stage)

These questions aren’t random. They map directly to FS AI RMF domain and stage structure. An institution that has run the gap assessment and documented gaps and remediation plans can answer from a position of strength. An institution that hasn’t is answering from a blank page.

The Mondaq analysis of the FS AI RMF makes the stakes clear: the framework is designed to be “audit-ready” architecture, not aspirational guidance. The 230 control objectives aren’t aspirational — they’re what 108 financial institutions and their regulators agreed represents sound AI governance practice.

So What?

The gap between where most AI governance programs sit today and what the FS AI RMF defines as Minimal stage is real, measurable, and closeable. The framework gives you the tools: the questionnaire to determine your stage, the RCM to identify your gaps, and the Guidebook to tell you what good looks like.

What it can’t do is run the assessment or build the documentation for you.

A first-pass gap assessment against the 21 Initial-stage controls is the realistic first step for any institution with AI in production. If you’re not there, start there. The 126 Minimal-stage controls are the credible baseline for an institution that wants to answer exam questions from evidence rather than explanation.

The FS AI RMF assessment will surface gaps in your inventory documentation, vendor due diligence processes, consumer protection procedures, and monitoring frameworks. Those are also the gaps that the AI Risk Assessment Template & Guide is built to close — with a pre-deployment scorecard, vendor AI questionnaire, model inventory template, Shadow AI register, and eight worked examples for the use cases examiners scrutinize most.

Running the gap assessment is the diagnostic. Building the documentation is the treatment. Start the diagnostic now, before your next exam cycle makes it urgent.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Is the FS AI RMF mandatory or voluntary?
Technically voluntary — it's an industry-led framework published by Treasury and the Cyber Risk Institute, not a federal regulation. But 'voluntary' doesn't mean 'ignorable.' Examiners from the OCC, Fed, and FDIC are already using its vocabulary and structure during AI governance inquiries. If your institution deploys AI, examiners will ask what framework you're using, and the FS AI RMF is the most credible domestic answer for financial services.
How long does a first-pass gap assessment take?
For a mid-size institution with 10-30 AI use cases, a first-pass gap assessment against Initial and Minimal stage controls typically takes 3-5 days of focused work. The questionnaire takes a few hours; scoring your gaps against the filtered Risk and Control Matrix is the main time investment. A full Evolving-stage assessment for an institution with 100+ AI systems might take 2-4 weeks, including validation with model owners.
Which maturity stage should our institution be targeting?
Your target depends on your AI adoption profile, not asset size alone. The questionnaire scores three dimensions: business impact of AI decisions, technological sophistication of your AI systems, and enterprise scalability of your AI deployment. An institution running AI for one customer-facing product should target Minimal (126 controls). An institution running AI across credit decisioning, fraud detection, compliance monitoring, and customer service should be working toward Evolving (193 controls).
How does the FS AI RMF relate to OCC Bulletin 2026-13 and SR 26-02?
Complementary, not a replacement. OCC 2026-13 covers traditional predictive models with specific validation, documentation, and governance requirements. The FS AI RMF covers the full AI lifecycle — including GenAI and third-party AI — with 230 control objectives that go deeper on data governance, consumer protection, and third-party risk than the agency MRM guidance. You need both.
Where do I get the actual questionnaire and Risk and Control Matrix?
The full framework — AI Adoption Stage Questionnaire, Risk and Control Matrix (all 230 objectives), Guidebook, and Control Objective Reference Guide — is available free from the Cyber Risk Institute at cyberriskinstitute.org/artificial-intelligence-risk-management/.
What's the relationship between the FS AI RMF and NIST AI RMF?
The FS AI RMF is a financial-services-specific adaptation of the NIST AI RMF. NIST provides general governance functions (GOVERN, MAP, MEASURE, MANAGE). The FS AI RMF translates those into 230 sector-specific control objectives calibrated for the credit, payments, lending, fraud, and compliance contexts of regulated financial institutions.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.