Back to Blog
Hamza Farooq/September 1, 2026/6 min read

Treasury's FS AI RMF Explained: How to Map Your Agentic Deployment Across 230 Control Objectives Before Examiners Do

Treasury's FS AI RMF Explained: How to Map Your Agentic Deployment Across 230 Control Objectives Before Examiners Do
TL;DR: The Treasury AI risk framework organizes agentic deployment oversight into 230 control objectives across governance, model risk, data, and operational domains that financial institutions must map now, not when examiners arrive. Voluntary adoption status is a temporary condition, not a permanent exemption, because regulators and counterparties are already treating alignment as a baseline expectation. Map your agent deployment to the matrix proactively or inherit the risk of doing it reactively under pressure.

Key Takeaways

  • Built with 100+ financial institutions, the FS AI RMF is the primary AI governance reference for U.S. financial services; regulators increasingly treat alignment as a baseline expectation.
  • Its 230 control objectives span the full AI lifecycle, a concrete, stageable checklist, not vague principles.
  • "Voluntary" does not mean permanent exemption: voluntary guidance consistently moves toward exam expectation once it enters supervisory conversations.
  • SR 11-7 fails for agentic AI because it assumes static model boundaries and step-level human review, conditions autonomous, tool-chaining agents violate by design.
  • The adoption-stage questionnaire produces a defensible artifact for examiners and vendor negotiations when run as a pre-deployment self-assessment.
  • Third-party agents represent your institution's most common control gap and must be mapped with the same discipline as internal deployments.

Introduction

As of 2026, agentic AI deployments are moving from pilot to production across U.S. financial services, and the compliance infrastructure has not kept pace. This guide walks through a practical mapping approach built around the FS AI RMF's 230 control objectives, a matrix as useful for vendor negotiation as for regulatory compliance.


What Exactly Are the 230 Control Objectives and How Are They Organized?

The 230 control objectives span the full AI lifecycle, covering governance, risk, and operational considerations from initial use-case evaluation through enterprise scale. The framework adapts the NIST AI RMF for financial-services conditions, adding control vocabulary that NIST's general-purpose structure omits for regulated institutions.

The adoption-stage questionnaire functions as a maturity model: an institution deploying its first agent activates a different control subset than one scaling enterprise-wide. That staging prevents the matrix from becoming an undifferentiated wall that stops early-stage programs cold. The organizing concept for every mapping step below is that lifecycle-stage structure, consult the framework's own questionnaire to determine which controls apply at your deployment's current stage.


How Does the FS AI RMF Compare to SR 11-7 for Agentic Deployments?

The FS AI RMF directly addresses agentic behaviors that SR 11-7 has no vocabulary for. The table below is author synthesis built from the framework's published scope and the SR 11-7 supervisory letter.

DimensionSR 11-7 (Federal Reserve)FS AI RMF
Model boundary assumptionStatic inputs and outputs defined at build timeDynamic: agents retrieve context and select tools at runtime
Human-review modelStep-level human review treated as a core controlRequires explicit documentation of which decisions require human escalation
Third-party action chainsAccountability returns to institution; limited further guidanceSpecific control objectives for vendor-executed agentic actions
Lifecycle stagingApplied uniformly to model development and validationScales active controls to deployment maturity stage
Agentic vocabularyNone for tool-chaining or autonomous actionAddresses sequential decision-making, tool use, and action execution directly
Primary audienceModel risk management functionsGovernance, model risk, data, and operational functions jointly

Why Does SR 11-7 Fail for Agentic AI, and What Does the FS AI RMF Add?

SR 11-7 was written for static models; agentic systems violate its core assumptions by design. Three gaps matter most.

Model boundary problem. SR 11-7 assumes defined inputs and outputs. An agent retrieves context dynamically, selects tools at runtime, and its output is an action in an external system, a control surface SR 11-7 has no vocabulary for.

SR 11-7 is a building code written for houses. Agentic AI redesigns the house while building it. The FS AI RMF is the first code written for that kind of system in financial services.


How Should a Compliance Team Map an Existing Agent Deployment Onto the 230-Objective Matrix?

Run the adoption-stage questionnaire first, scope active controls to your lifecycle stage, then build a gap register against that subset, not all 230 at once.

Step 2: Scope the active controls. An early-stage pilot does not activate the same controls as an enterprise rollout. Correct scoping reduces 230 objectives to a manageable working subset.

Step 3: Assign control ownership. For each active objective, assign a named owner, internal team or named vendor. Any objective where the owner is "vendor" becomes a written representation requirement in the contract.

Step 4: Produce the dual-use artifact. The gap register serves simultaneously as an examiner-ready documentation file and a vendor pre-contract requirements document. Treating it as dual-use from the start prevents the common failure of building a compliance file that cannot translate into procurement language.


The Four-Stage Voluntary-to-Exam-Expectation Pathway

StageDescriptionFS AI RMF Position
1. ReleaseAgency publishes voluntary guidanceComplete
2. Supervisory referenceExaminers reference the framework; institutions without documentation face heightened scrutinyActive )
3. Implicit standard of careExam findings establish a de facto standard; undocumented institutions face elevated findingsApproaching
4. Formal expectationGuidance hardens into supervisory requirementsEmerging

An institution that cannot produce a documented agentic mapping faces the same dynamic as one that lacked model validation documentation when SR 11-7 became the de facto standard: not a formal penalty, but a supervisory posture that delays business approvals until the gap closes.


Side-by-side comparison table showing NIST AI RMF's four core functions mapped against the FS AI RMF's seven financial-services risk domains, highlighting where agentic AI adds new control requirements
Flowchart showing the four-step FS AI RMF mapping sprint: adoption-stage questionnaire → active domain scoping → control ownership assignment → dual-use gap register, with

Frequently Asked Questions

What is the Treasury FS AI RMF and who does it apply to? Developed with 100+ financial institutions and released by Treasury, it provides practical tools to evaluate AI use cases and manage risks across the full AI lifecycle, adapting the NIST AI RMF for U.S. financial services regulatory conditions. It is relevant to any institution deploying AI in a regulated U.S. financial services context.

How does the FS AI RMF's adoption-stage model differ from SR 11-7 for agentic systems? SR 11-7 applies requirements uniformly to static models and treats human review as a baseline control; the FS AI RMF scales controls to deployment maturity and directly addresses tool use, sequential decision-making, and action execution. Early-stage programs work against a scoped subset of the 230 objectives rather than the full matrix.

What control areas most commonly surface gaps in live agentic deployments? Third-party risk, operational resilience, and governance, because agentic systems cross vendor boundaries, operate without step-level human review, and execute actions at machine speed. Mapping vendor-executed actions to the FS AI RMF's third-party control objectives before contract signature is the highest-return starting point for most institutions.


Conclusion

The 230 control objectives are a structured instrument for allocating AI risk between your institution and your vendors, not a compliance wall to survive. The path from voluntary to exam expectation is already in motion.

Run the adoption-stage questionnaire this quarter. Scope active controls to your deployment's lifecycle stage. Generate the gap register and put it in front of your next vendor before contract signature.

The institution that documents its agentic deployment against the 230-objective matrix first does not just prepare for its next exam, it sets the terms of every AI vendor contract that follows.

Download the FS AI RMF matrix from the Cyber Risk Institute, run the adoption-stage questionnaire against your highest-priority agentic deployment, and schedule a control ownership session with AI governance, vendor management, and internal audit before end of quarter.


References

  1. cyberriskinstitute.org
  2. finsights.cooley.com
  3. grantthornton.com

Learn from me

Agentic AI for Product Managers

Agentic AI for Product Managers, my Maven cohort. Learn how to design, evaluate, and ship reliable AI systems: the technical fluency PMs need to lead agentic products, no engineering background required. Join the next cohort →

Hire us

Traversaal.ai. We're a team of forward deployed engineers solving the toughest AI problems for Fortune 100 companies: document intelligence, agentic data platforms, and real-time web intelligence, deployed in production. Work with our team to deploy your next agentic ecosystem. Talk to Traversaal.ai →

Join us

Want to solve these problems with us? We're always looking for forward deployed engineers who want to ship production AI. jobs@traversaal.ai

Hamza Farooq
Hamza Farooq

Former Senior Research Manager at Google and Walmart Labs, leading teams in optimization, NLP, recommender systems, and time series forecasting.