NIST AI RMF

Continuous, auditable behavioral monitoring across the framework.

Compiled maps to the NIST AI Risk Management Framework — Govern, Map, Measure, Manage — with continuous, explainable monitoring of AI-agent behavior and communications, generated inside your environment.

NIST AI RMF 1.0Treasury FS AI RMFGovernMapMeasureManageContinuous monitoringIn-tenantExplainable
~230
Control objectives in Treasury FS AI RMF (Feb 2026)
De-facto financial-sector benchmark
4
Core functions mapped — Govern · Map · Measure · Manage
Real-time
Continuous behavioral monitoring — not periodic review
100%
Of AI-agent actions inspected inline, before completion
Framework overview

What the NIST AI RMF requires — and where it is heading

NIST AI RMF 1.0, released January 2023, provides a voluntary framework for identifying, assessing, and managing risks across the AI system lifecycle. It is structured around four core functions — Govern, Map, Measure, and Manage — each with subcategories and suggested actions. The framework is explicitly designed to be used alongside existing risk management programs, not to replace them.

For financial services organizations, the more operationally relevant benchmark is the Department of the Treasury's Financial Services AI Risk Management Framework (FS AI RMF), published February 19, 2026. With approximately 230 control objectives spanning all four core functions, the FS AI RMF is becoming the de-facto exam benchmark for AI controls in banking and financial services — the standard against which examiners will evaluate whether an organization's AI governance program is adequate.

The rescission of SR 11-7 (effective April 17, 2026, via SR 26-2 / OCC 2026-13 / FDIC FIL-15-2026) removed the prior model-risk management template for generative AI and agentic systems — explicitly carving them out. The FS AI RMF fills that gap. Examiners are asking what controls organizations built for generative and agentic AI systems, even without a formal mandate. The organizations that can point to a continuous, operational behavioral monitoring program are better positioned in those conversations.

Framework mapping

How Compiled maps to Govern, Map, Measure, Manage

The following maps Compiled's operational controls to the relevant subcategories of the NIST AI RMF core functions and corresponding FS AI RMF control objectives.

GovernGV.1 — Organizational policies, processes, and accountability for AI risk
  • Acceptable-use and behavioral policies encoded as antibodies — enforced in real time, not reviewed after the fact
  • Policy-linked findings provide continuous evidence that governance policies are operational
  • Enterprise subscribers compile their own policies into antibodies; the governance program becomes technically enforced rather than advisorily stated
  • FS AI RMF: maps to control objectives under GV-1 (AI risk management policies) and GV-5 (accountability)
MapMP.2 — AI risk categorization and context assessment
  • Compiled continuously identifies which agent actions and communications carry risk, providing a live view of where risk is materializing — not a periodic self-assessment
  • Finding patterns surface risk concentrations by channel, agent, or policy category, supporting ongoing risk categorization
  • FS AI RMF: maps to MP-2 (AI risk context) and MP-4 (risk identification)
  • Supports documentation of which AI systems are in scope for high-risk classification under EU AI Act and FS AI RMF
MeasureMS.2 — AI risk measurement, monitoring, and evaluation
  • Behavioral risk scores on every finding provide quantified, continuous measurement of AI system risk
  • Aggregate finding data is exportable for trend analysis, supporting ongoing measurement of whether risk is increasing or decreasing over time
  • Time-stamped, policy-attributed findings are the audit trail that makes measurement auditable rather than self-assessed
  • FS AI RMF: maps to MS-1 (AI risk assessment) and MS-2 (AI performance monitoring)
ManageMG.2 — AI risk treatment and incident response
  • Inline allow, flag, or block decisions are the operational risk treatment — risk identified in the Map and Measure functions is managed before impact, not after
  • Flagged actions route to human review, with the reviewer's decision logged — implementing the human oversight that the Manage function requires
  • Findings route to SIEM and SOAR for integration with your broader incident response program
  • FS AI RMF: maps to MG-1 (AI risk treatment plans) and MG-3 (incident response for AI systems)
Treasury FS AI RMF

The de-facto financial-sector benchmark

The Department of the Treasury's Financial Services AI Risk Management Framework, published February 19, 2026, provides approximately 230 control objectives across the four NIST AI RMF functions, tailored to the financial services sector. It is the most operationally specific AI risk management reference available to financial firms and is increasingly the lens through which federal and state banking examiners assess AI governance programs.

The FS AI RMF explicitly addresses agentic AI systems — AI that autonomously selects tools, invokes APIs, and takes actions — as a distinct risk category. The control objectives for agentic systems emphasize continuous behavioral monitoring, human oversight at decision points, and audit trails that demonstrate the monitoring was operational and not merely documented.

With SR 11-7 rescinded for generative and agentic AI, the FS AI RMF is the closest thing financial firms have to an examiner-endorsed template for governing these systems. Organizations that can map their operational controls to the FS AI RMF's control objectives — and demonstrate those controls are continuous, not periodic — are in the strongest position for examiner conversations in 2026 and beyond.

Risk scenarios

Where RMF gaps create exam exposure

Agentic system operating outside defined scope (Manage gap)Flag

An AI agent deployed for customer service begins responding to questions about investment products in a way that implies portfolio advice. No real-time control exists on the agent's output. The action is only identified in a post-hoc log review. Under MG-3, the risk treatment was not operational at the time of the action — a gap an examiner will surface.

AI system exhibiting drift from expected behavior (Measure gap)Block

An AI credit-decisioning system begins producing outputs that deviate from its validated behavior in ways that are not detected by periodic monitoring. The FS AI RMF's MS-2 control objective requires continuous performance monitoring. Compiled's real-time behavioral assessment detects the deviation at the point of action, not in the next monthly review.

Policy without technical enforcement (Govern gap)Flag

An organization has documented acceptable-use policies for its AI systems but has no technical mechanism to enforce them. An agent violates the policy; the violation is discovered in a quarterly audit. Under GV-1, a governance policy with no operational enforcement does not constitute an adequate control. Compiled closes this gap by encoding the policy as an enforced antibody.

Risk not mapped to live system behavior (Map gap)Block

An organization's AI risk assessment identifies the risk of sensitive data exfiltration by AI agents but has no system that continuously monitors whether that risk is materializing. Under MP-4, risk identification must connect to ongoing monitoring. Compiled provides the live view of where identified risks are or are not appearing in actual agent behavior.

Examination readiness

What you produce for an examiner asking about AI controls

When an examiner asks how your organization governs its AI systems — and asks for evidence that governance is operational, not merely documented — Compiled produces a structured record from inside your environment that addresses the operational question directly.

Continuous operationEvery AI-agent action is inspected in real time, 24/7 — demonstrating that monitoring is continuous rather than periodic
TimestampUTC timestamp of each agent action and its verdict, providing a complete timeline of system behavior for any period the examiner specifies
Policy attributionEach finding cites the specific governance policy, framework control objective, or your own acceptable-use policy that was matched
Verdict recordAllow, flag, or block — with the decision recorded before the action completed, demonstrating operational risk treatment under Manage / MG-2
Human oversight logFor flagged findings: the human reviewer's outcome, demonstrating that oversight was applied — not just that a process existed for it
FS AI RMF mappingFindings can be categorized by FS AI RMF control objective, providing a structured response to examiner requests for control evidence
Trend dataAggregate behavioral data exportable to demonstrate the Measure function — showing whether AI risk is increasing, stable, or declining over time
FAQ

Questions from AI risk and compliance teams

Chat with usBook a 30-minute walkthroughAI-agent governance