NIST is not a regulator, but its AI Risk Management Framework (AI RMF 1.0, January 2023) has become the de facto template US banks use to structure AI governance — especially since the April 2026 interagency model-risk guidance left generative and agentic AI to banks' broader risk programs. The framework's four functions (Govern, Map, Measure, Manage) plus its July 2024 Generative AI Profile give banks an examiner-legible way to demonstrate control over AI that formal model-risk rules no longer cover.
| Full name | National Institute of Standards and Technology — AI Risk Management Framework |
| Role | Standards body |
| Force on banks | Voluntary framework |
| Applies to | Any organization; widely adopted by US banks as the scaffold for AI governance programs |
| Key document | AI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024) |
| Latest move | Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI |
The AI RMF is voluntary, but voluntary frameworks harden fast in banking: when examiners ask how a bank governs its generative AI and there is no binding rule to point to, institutions answer with NIST-aligned programs. The Generative AI Profile (NIST AI 600-1) enumerates risks specific to generative systems — confabulation, data leakage, prompt injection — with suggested actions that map cleanly onto bank control frameworks.
For banks operating internationally, the RMF also functions as a crosswalk: its categories align with the FSB's sound-practices work and provide a defensible baseline for the governance the EU AI Act requires of high-risk system deployers.
| Date | Type | Document / event |
|---|---|---|
| Jan 26, 2023 | Framework | AI Risk Management Framework 1.0 released. Voluntary framework organizing AI risk management into four functions: Govern, Map, Measure, Manage. |
| Jul 26, 2024 | Framework | Generative AI Profile (NIST AI 600-1). Companion profile enumerating generative-AI-specific risks — confabulation, information leakage, prompt injection — with suggested mitigations. |
| Apr 17, 2026 | Milestone | US model-risk revision amplifies the RMF's role. With generative and agentic AI excluded from formal interagency model-risk guidance (SR 26-2), NIST's framework becomes the leading reference for how banks govern those systems. |
- Whether US banking agencies formally reference the AI RMF in the AI governance guidance the OCC has signalled
- Updates to the Generative AI Profile as agentic AI risks crystallize
- Use of the RMF as an EU AI Act compliance crosswalk by global banks
Is the NIST AI RMF mandatory for banks?
No — it is voluntary. But it has become the standard scaffold US banks use for AI governance, particularly for generative and agentic AI, which the April 2026 interagency model-risk guidance deliberately left to banks' broader risk-management programs.
How does the NIST AI RMF relate to bank model risk management?
Model risk guidance covers validation of quantitative models; the AI RMF covers organization-wide AI risk governance, including systems outside formal model-risk scope. Most banks run them side by side: revised interagency guidance for traditional/ML models, NIST-aligned governance for generative AI.
Follow every move these regulators make
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →