QIS-S-112 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-02 · BUILD 13.0
Standards register · Cyber Risk Institute · FSSCC · US Treasury (AIEOG)

Financial Services AI Risk Management Framework (FS AI RMF)

An operationalisation of the NIST AI Risk Management Framework tailored to financial services, version 1.0 dated 9 February 2026. Comprises an AI Adoption Stage Questionnaire, a Risk and Control Matrix, a User Guidebook and a Control Objective Reference Guide. The matrix contains 230 control objectives across four functions — Govern (81), Map (47), Measure (59) and Manage (43) — each paired with a named risk statement and mapped to maturity stages from Initial to Embedded.

QIS-S-112·Addresses 4 of 8 MARQUE questions

Why it matters for autonomous finance

The most operationally specific document in agentic finance governance, and the least discussed. It is where abstractions become auditable line items: MG-2.4.3 requires technical mechanisms for system shutdown and disconnection, regularly tested; MP-3.5.3 requires documented criteria and thresholds for human intervention. Those are kill criteria and oversight, written by an industry body and ready to cite. We have cross-walked all 230 against MARQUE — see the mapping.

What it does not cover

Designed as a complement rather than a replacement for existing frameworks, and built for AI risk generally rather than for agents acting with capital. Of the 230 objectives, the overwhelming majority sit under a single principle — Accountable & Transparent — which tells you where the drafting energy went and where it did not. Coverage of delegated authority and agent identity is thin to absent.

No agent-specific authority model; no provenance or chain-of-title representation. Every entry in this register carries this section. A standard read past its scope is worse than no standard, because it produces confidence without coverage.

Read it