NIST AI RMF 1.0, released January 2023, provides a voluntary framework for identifying, assessing, and managing risks across the AI system lifecycle. It is structured around four core functions — Govern, Map, Measure, and Manage — each with subcategories and suggested actions. The framework is explicitly designed to be used alongside existing risk management programs, not to replace them.
For financial services organizations, the more operationally relevant benchmark is the Department of the Treasury's Financial Services AI Risk Management Framework (FS AI RMF), published February 19, 2026. With approximately 230 control objectives spanning all four core functions, the FS AI RMF is becoming the de-facto exam benchmark for AI controls in banking and financial services — the standard against which examiners will evaluate whether an organization's AI governance program is adequate.
The rescission of SR 11-7 (effective April 17, 2026, via SR 26-2 / OCC 2026-13 / FDIC FIL-15-2026) removed the prior model-risk management template for generative AI and agentic systems — explicitly carving them out. The FS AI RMF fills that gap. Examiners are asking what controls organizations built for generative and agentic AI systems, even without a formal mandate. The organizations that can point to a continuous, operational behavioral monitoring program are better positioned in those conversations.
The following maps Compiled's operational controls to the relevant subcategories of the NIST AI RMF core functions and corresponding FS AI RMF control objectives.
The Department of the Treasury's Financial Services AI Risk Management Framework, published February 19, 2026, provides approximately 230 control objectives across the four NIST AI RMF functions, tailored to the financial services sector. It is the most operationally specific AI risk management reference available to financial firms and is increasingly the lens through which federal and state banking examiners assess AI governance programs.
The FS AI RMF explicitly addresses agentic AI systems — AI that autonomously selects tools, invokes APIs, and takes actions — as a distinct risk category. The control objectives for agentic systems emphasize continuous behavioral monitoring, human oversight at decision points, and audit trails that demonstrate the monitoring was operational and not merely documented.
With SR 11-7 rescinded for generative and agentic AI, the FS AI RMF is the closest thing financial firms have to an examiner-endorsed template for governing these systems. Organizations that can map their operational controls to the FS AI RMF's control objectives — and demonstrate those controls are continuous, not periodic — are in the strongest position for examiner conversations in 2026 and beyond.
When an examiner asks how your organization governs its AI systems — and asks for evidence that governance is operational, not merely documented — Compiled produces a structured record from inside your environment that addresses the operational question directly.