Summary: On 19 February 2026 the U.S. Department of the Treasury released an AI Lexicon and the Financial Services AI Risk Management Framework. The Cyber Risk Institute hosts that suite and expands it with 230 control objectives organized by adoption stage. Before you scale a first-agent pilot, apply the Initial-stage cut: inventory, named owners, data classes, human oversight, vendor access, and an incident path. Later-stage objectives apply after the public questionnaire shows the agent has left Initial. Named owners sit inside AI governance.
What Treasury released, and who owns the 230
That Treasury statement covers two resources developed through the Financial and Banking Information Infrastructure Committee and the Financial Services Sector Coordinating Council’s Artificial Intelligence Executive Oversight Group. The publications translate national AI priorities into tools for institutions, regulators, and technology providers.
The FS AI RMF adapts the NIST AI Risk Management Framework to the operational, regulatory, and consumer protection considerations of financial services. Treasury describes practical lifecycle tools that scale across institution size and complexity. It does not call the framework mandatory, and the statement never states a control count.
The Cyber Risk Institute hosts the suite. CRI says the framework is structurally aligned with the NIST AI RMF and expanded with 230 control objectives that help organizations of all sizes manage and govern AI risks. The 230 figure belongs to CRI’s matrix, never to Treasury’s press release.
The four public downloads and the Initial-stage Quick Start
FSSCC states that the FS AI RMF consists of four primary deliverables: an AI Adoption Stage Questionnaire, a Risk and Control Matrix, a User Guidebook, and a Control Objective Reference Guide. The same page points the suite to CRI.
CRI’s landing lists those four components and hosts the downloads, including a Quick Start Guide labeled Initial Adoption Stage Only. The matrix organizes 230 control objectives by adoption stage. The Guidebook and Reference Guide cover deployment steps and examples of effective evidence.
CRI’s Guidebook says the framework expands NIST’s functions through 230 control objectives and is a universal complement to existing risk programs. It does not replace those programs, serve as an all-inclusive repository, or prescribe use-case-specific guidance. That is why the first-agent cut stays on control posture rather than a product-line walkthrough.
Land one agent on a stage with the six questionnaire dimensions
CRI’s Adoption Stage Questionnaire classifies an institution into one of four stages. Initial features limited and protective methods. Minimal entails low-risk implementations. Evolving involves high-risk production applications. Embedded describes AI that is widely integrated across the organization.
The questionnaire evaluates six dimensions: Business Impact, Governance, Deployment Model, Third-Party AI Use, Organizational Goals, and Data Sensitivity and Criticality. Scoring starts at Embedded and stops at the first Yes. If at least one of the six statements aligns, that is the current stage.
A first-agent pilot is not automatically Initial. One Yes on an Evolving or Embedded statement, such as critical processes, sensitive data, enterprise governance, or deep vendor integration, lands the whole institution at that higher stage.
A vendor-hosted agent maps to CRI’s own statements. Exploring vendor-managed platforms or internally hosted models, without current deployment, sits at Initial. Limited production through vendor-managed platforms, with limited internal hosting and case-by-case oversight, sits at Minimal. CRI does not name a fifth stage called “pilot.”
The first-agent control cut before you scale
The cut below is an editorial operationalization of CRI’s Initial-stage Quick Start, the six questionnaire dimensions, and the NIST GOVERN, MAP, MEASURE, and MANAGE functions. It is not a CRI-named product.
Inventory. Name the agent, the workflow it touches, and whether it is vendor-hosted or internally hosted. That is MAP plus Business Impact and Deployment Model.
Owners. Name a business owner, a risk owner, and who can stop the agent. That is GOVERN plus the Governance dimension.
Data classes. Record what the agent can read and write, including whether regulated or customer data is in scope. That is Data Sensitivity and Criticality.
Human oversight. State which outputs a person must approve before they take effect, while oversight is still case-by-case. That sits under Governance and human-in-the-loop review.
Vendor access. Record what the vendor can see, which tools the agent can call, and what the institution can retrieve if the vendor fails. That is Third-Party AI Use and the category of third-party AI risk.
Incident path. Name who is called, what is frozen, and what evidence is kept when the agent is wrong. CRI’s Guidebook describes documenting and reviewing incident response for AI system components and third-party technologies.
Scale adds later-stage posture. Evolving and Embedded add external-facing use, sensitive data in critical decisions, internal model development, and enterprise-wide integration. Stay inside those CRI stage definitions until the questionnaire shows the agent has left Initial.