meilynx

Glossary

FS AI RMF (Financial Services AI Risk Management Framework)

A voluntary AI risk management framework for financial institutions, released by the U.S. Treasury in February 2026.

The Financial Services AI Risk Management Framework adapts the NIST AI Risk Management Framework to financial services. The U.S. Treasury released it on 19 February 2026; the Cyber Risk Institute developed it with the Financial Services Sector Coordinating Council and more than 100 financial institutions. Version 1.0 organizes 230 control objectives under the four NIST functions (Govern, Map, Measure, Manage) and 72 subcategories.

Each control objective is tagged to an adoption stage (Initial, Minimal, Evolving, Embedded), and a questionnaire places the institution at one, so the framework scales to how far a firm has taken AI. It ships with a guidebook and a control objective reference guide that gives example controls and the evidence that shows them working. It is voluntary and non-prescriptive.

For banks, it gives structure to the governance SR 26-2 leaves to the institution for generative and agentic AI. The Meilynx SR 26-2 examination package carries a crosswalk of all 72 subcategories, each classified by where its evidence comes from.

See it in practice

From definition to evidence.

See how Meilynx turns this into an examination-ready audit trail.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.