A New Framework for AI Financial Services Audits
Banks and insurers are moving AI services into the hard mechanics of governance .

A New Framework for AI Financial Services Audits
Banks and insurers are moving AI services into the hard mechanics of governance .
In February 2026, the Cyber Risk Institute (CRI) in collaboration with the U.S. Treasury and over 100 financial institutions launched the Financial Services AI Risk Management Framework (FS AI RMF). Moving beyond theory, this framework provides a modular, audit-ready architecture of 230 control objectives. It offers banks, insurers, and asset managers a practical roadmap through the complexities of AI risk.
The FS AI RMF builds directly on NIST’s landmark 2023 AI Risk Management Framework, which established the canonical four-function structure: Govern, Map, Measure, and Manage. But NIST’s framework, intentionally written for broad applicability across industries, leaves significant implementation gaps when applied to the specific pressures of financial services.
The Architecture of Accountability
The FS AI RMF is composed of four interlocking components:
- An AI Adoption Stage Questionnaire that functions as a diagnostic tool, helping organizations honestly assess their current maturity before assigning control obligations.
- A Risk and Control Matrix (RCM) maps specific AI risk statements to Control Objectives across all four NIST functions.
- A Guidebook that explains how to implement and operationalize the framework within a real financial institution.
- A Control Objective Reference Guide that provides illustrative examples of both controls and “Effective Evidence”: the meeting minutes, model inventories, risk assessments, and policy artifacts that regulators and examiners expect to see.
That last component is the most important as it specifies what evidence looks like not just what controls should exist. This closes a loop that most governance frameworks leave open. An institution does not merely assert that it monitors model performance; it demonstrates it with logged artifacts tied to specific control objectives.
Proportional Risk Management
The FS AI RMF rejects a one-size-fits-all compliance. The framework classifies organizations into four AI Adoption Stages based on three dimensions: the business impact of AI, the sophistication of technology implementation, and the scalability of AI deployment across the enterprise.
A community bank using basic fraud-scoring rules operates in a different reality than a global asset manager deploying autonomous AI portfolio recommendations. The Adoption Stage Model addresses this gap by ensuring organizations only apply controls that match their specific risk profile.
The philosophy is simple:
- Targeted Oversight: Focus on control objectives that actually matter to your scale.
- Risk-Based Action: Avoid “one-size-fits-all” compliance.
- The Ultimate Goal: Achieve proportionality, not paralysis.

Table 1: FS AI RMF Adoption Stages
The Governance Gap That Opened
To understand why the FS AI RMF matters, it helps to understand precisely what NIST’s AI RMF and earlier model risk guidance such as SR 11–7 failed to address. Traditional model risk management was designed for predictive statistical models: logistic regression, gradient boosting, structured inputs, interpretable outputs. Now as financial firms begin deploying large language models for customer service, document summarization, and financial advice generation, the entire validation paradigm broke down.
Large Language Models (LLMs) lack clean feature importance scores. Their behavior is context-dependent, probabilistic, and highly sensitive to input perturbations . These are the model’s characteristics that classical validation processes were never designed to handle. A model that passes accuracy testing in development can fail unpredictably under adversarial conditions. In financial services, that is not a edge case. It is the operating environment. The FS AI RMF addresses this by embedding cybersecurity and adversarial robustness directly into the risk taxonomy, treating model manipulation as a first-class enterprise risk rather than an afterthought of the IT security team.
The Threat Environment: Applying MITRE ATLAS to LLM Risk

Table 2: FS AI RMF Controls Testability
Governance frameworks outline control requirements; attack taxonomies provide the testing methodology. In this ecosystem, MITRE ATLAS acts as the technical engine for the FS AI RMF
ATLAS is a knowledge base of real-world tactics, techniques, and procedures (TTPs) targeting AI systems. It uses the same matrix structure as MITRE ATT&CK, but focuses specifically on AI, machine learning attack surfaces. Version 4.5, catalogs 15 adversarial tactics and more than 60 techniques. This includes Data Poisoning (AML.T0020), Prompt Injection (AML.T0051), Inference API Exfiltration (AML.T0024), and LLM Goal Hijacking (AML.T0054).
The two frameworks are complementary by design. The FS AI RMF is top-down. It establishes governance structures, assigns accountability, defines evidence expectations, and maps to regulatory obligations. The MITRE ATLAS is bottom-up . It catalogs the specific attack patterns that governance controls must actually defeat. Together, they form what security practitioners call a “closed loop”: a continuous path from policy to threat scenario to validated control to documented evidence.
Consider a practical example. The FS AI RMF Control Objective GV-1.6 requires organizations to maintain a comprehensive AI inventory of every model, every data pipeline, every third-party AI service in use. Stress-testing that control against ATLAS Reconnaissance techniques (AML.T0001, AML.T0002) asks a sharper question. Could an internal or external adversary discover undocumented AI components “shadow AI” that do not appear in the inventory? If the answer is yes, the inventory control has failed, and the evidence artifact is invalid.
Similarly, the framework’s Incident Response controls (GV-1.5, GV-4.3) map to ATLAS exfiltration techniques. An institution that documents an AI incident response plan but has never exercised it against a realistic API exfiltration scenario cannot credibly assert that the control is effective under examination.
The Gaps Neither Framework Fills Alone
Practitioners who expect a single unified answer will be disappointed. Three persistent gaps emerge from careful analysis of how the FS AI RMF and MITRE ATLAS interact.
The governance gap runs in ATLAS’s direction: the adversarial ML knowledge base is a technical playbook. It cannot specify who sits on an AI Ethics Committee, what role the board plays in AI risk appetite statements, or what “effective evidence” looks like for a supervisory examination. For those answers, institutions must return to the FS AI RMF.
The technical gap runs the other way: the FS AI RMF mandates robustness but does not prescribe granular defensive techniques. It requires that models be resistant to adversarial manipulation but does not specify input sanitization pipelines, adversarial training methodologies, or red-team tooling. ATLAS mitigations fill that space.
The sectoral gap persists in ATLAS more than in the FS AI RMF. ATLAS is deliberately sector-agnostic — the same technique matrix applies to a weapons guidance system and a mortgage underwriting model. The FS AI RMF, by contrast, explicitly integrates consumer protection statutes such as the Equal Credit Opportunity Act, the Fair Credit Reporting Act, Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) into its control objectives. An LLM deployed for credit counseling faces regulatory exposure that MITRE ATLAS does not account for, even if the adversarial threat profile is identical.
Perhaps most consequentially for practitioners: the FS AI RMF’s adoption stage model defines clear maturity thresholds. However, MITRE ATLAS assigns no comparable priority weights to its techniques based on institutional maturity. A community bank at the Initial stage and a global trading firm at the Embedded stage face the same ATLAS technique catalog despite vastly different risk surfaces. The process of bridging adoption stages to technique prioritization remains an open gap, one that practitioners must currently resolve by hand.
What Examination-Ready Actually Means
The FS AI RMF’s ambition is practical in a specific regulatory sense: it is designed to hold up under examination. This means it is not sufficient to have a policy; the policy must be traceable to a control. The control must be testable. The test must produce evidence. The evidence must be durable.

Image 1: FS AI RMF Compliance Chain
Here is an example from the framework’s Governance function illustrates this chain. Control Objective GV-1.1.1, titled “AI Legal, Regulatory, and Policy Integration,” requires organizations to “identify, monitor, and integrate applicable laws, regulations, contractual obligations, and sector requirements into AI policies and operations, updating governance artifacts as requirements evolve”. The FS AI RMF’s accompanying Reference Guide then specifies what evidence satisfies that objective: updated policy documents, regulatory tracking logs, change management records, and meeting minutes from compliance review sessions.
This evidence-first design philosophy reflects a hard lesson from financial services cybersecurity: controls that cannot be evidenced do not exist in an examination context. The FS AI RMF operationalizes that lesson for AI. This helps to avoid the temptation to treat governance as a branding exercise, rather than a documented operational discipline.
Operational Mapping: FS AI RMF to MITRE ATLAS
To operationalize the framework effectively, institutions must correlate high-risk FS AI RMF Control Objectives with specific MITRE ATLAS Tactics and Techniques. This mapping enables security teams to define Threat Assumptions in risk registers and design Red-Teaming scenarios for AI validation processes.

This operational workflow closes the loop between policy and adversarial reality:
- Select Objectives by Adoption Stage: Focus on controls matching your maturity (e.g., Evolving stage focuses on external-facing APIs, mapped to ATLAS Initial Access tactics).
- Define Threat Scenarios: For each control, identify which ATLAS technique could bypass it (e.g., “Input Validation control must mitigate AML.T0051 Prompt Injection”).
- Execute Technical Validation: Use ATLAS Mitigations (model hardening, rate limiting) as technical specifications for implementation.
- Capture Effective Evidence: Red-team exercise results based on ATLAS case studies serve as evidence for FS AI RMF GV-1.1.3 (Compliance Validation).
Conclusion:
A Living Standard in a Fast-Moving Landscape
Despite its current gaps, the FS AI RMF is the most concrete map the sector has produced for navigating what comes next. The competitive advantage will belong not to the firms with the most powerful models, but to those whose governance can withstand scrutiny with secure, documented controls.
Firms that align to this structure now will be better positioned for examination readiness as regulatory expectations harden. The framework’s semi-annual review cycle signals that gaps will close. That readiness, however, requires a deliberate investment decision at the top.
The board-level question is no longer whether to invest in AI governance infrastructure. It’s whether you can afford to let a competitor build it first. This is the challenge today.
References
AlertAI. (2024, February 14). Adversarial threat landscape: MITRE ATLAS adversary tactics and techniques. https://alertai.com/mitre-atlas-llm-ai-security-adversarial/
Center for Threat-Informed Defense. (2025, May 9). Secure AI with threat-informed defense (Version 2). MITRE CTID. https://ctid.mitre.org/blog/2025/05/09/secure-ai-v2/
Cyber Risk Institute. (2026, February). CRI financial services AI risk management framework: Control objective reference guide (Version 1.0). Financial Services Sector Coordinating Council & U.S. Department of the Treasury. https://cyberriskinstitute.org
Cyber Risk Institute. (2026). Financial services AI risk management framework (FS AI RMF): Guidebook (Version 1.0). Financial Services Sector Coordinating Council & U.S. Department of the Treasury. https://cyberriskinstitute.org/artificial-intelligence-risk-management/
Emergent Mind. (2025, November 22). MITRE ATLAS adversarial ML taxonomy. https://www.emergentmind.com/topics/mitre-atlas-adversarial-ml-taxonomy
Lowenstein Sandler LLP. (2026, February 22). Financial services AI risk management framework: Operationalizing AI governance in banking. https://www.lowenstein.com/news-insights/publications/articles/financial-services-ai-risk-management-framework-operationalizing-ai-governance-in-banking
MITRE Corporation. (n.d.). MITRE ATT&CK® [Knowledge base]. https://attack.mitre.org
MITRE Corporation. (2020). Adversarial ML threat matrix [Software repository]. GitHub. https://github.com/mitre/advmlthreatmatrix
MITRE Corporation. (2023, March). Arsenal: AI red team automation plugin for CALDERA [Software]. MITRE & Microsoft. https://atlas.mitre.org/resources/arsenal
MITRE Corporation. (2025, September). MITRE ATLAS overview [Conference presentation]. National Institute of Standards and Technology Computer Security Resource Center. https://csrc.nist.gov/csrc/media/Presentations/2025/mitre-atlas/TuePM2.1-MITRE%20ATLAS%20Overview%20Sept%202025.pdf
MITRE Corporation. (2025, October). MITRE ATLAS: Adversarial threat landscape for artificial-intelligence systems (Version 4.5). https://atlas.mitre.org
National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100–1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1
Opaque Systems. (2026, March 6). MITRE ATLAS threat assessment for enterprise AI leaders [White paper]. https://www.opaque.co/resources/downloadables/mitre-atlas-confidential-ai-mitigation-by-opaque
Practical DevSecOps. (2025, July 9). MITRE ATLAS framework 2026: Guide to securing AI systems. https://www.practical-devsecops.com/mitre-atlas-framework-guide-securing-ai-systems/
Promptfoo. (2026, March 15). MITRE ATLAS [Documentation]. https://www.promptfoo.dev/docs/red-team/mitre-atlas/
Silberman, A. (2026, January 11). Advancing MITRE ATLAS AI security through Zenity’s contributions. Zenity. https://zenity.io/blog/current-events/mitre-atlas-ai-security
U.S. Department of the Treasury. (2026, February 18). Treasury releases two new resources to guide AI use in the financial sector (Press Release SB-0401). https://home.treasury.gov/news/press-releases/sb0401
Vectra AI. (2026, February 5). MITRE ATLAS explained: The complete guide to AI security threat intelligence. https://www.vectra.ai/topics/mitre-atlas
메타데이터
- post_id
- 911cdea4f6c2
- slug
- a-new-framework-for-ai-financial-services-audits-911cdea4f6c2
- url
- https://medium.com/@oracle_43885/a-new-framework-for-ai-financial-services-audits-911cdea4f6c2
- canonical_url
- https://medium.com/@oracle_43885/a-new-framework-for-ai-financial-services-audits-911cdea4f6c2
- author_url
- https://medium.com/@oracle_43885
- status
- ok
- fetched_at
- 2026-07-28 23:05:54