Financial Services

More than half of Treasury's AI framework is evidence you have to defend.

On February 9, 2026 the U.S. Treasury, the Cyber Risk Institute, and more than 100 financial institutions published the Financial Services AI Risk Management Framework: 230 control objectives adapting the NIST AI RMF to banks, insurers, and investment firms. It is voluntary today, and built to become what examiners reference tomorrow.

126 of 230
control objectives call for evidence artifacts

We read the Risk and Control Matrix. Over half of its control objectives are satisfied not by having a policy, but by producing evidence — documentation, records, logs, artifacts expected to withstand audit and supervisory review. The framework is, in its own reviewers' words, an information governance engineering exercise.

Most of that evidence is ordinary. A versioned policy with approval signatures satisfies dozens of controls, and a document repository handles it. But a specific set of controls asks for something a repository cannot honestly give: evidence carrying provenance, verifiable timestamps, and data lineage. A repository can display a timestamp. It cannot prove it did not backdate one. That is the gap, and it is exactly the gap Rubric Custody closes.

Where Custody is the answer, not a repository

FS AI RMF v1.0 — control objectives quoted verbatim
GV-1.1.4 — AI Compliance Documentation
"...documentation to demonstrate how AI systems comply... includes risk assessments, compliance reviews, audits, corrective actions... generated throughout the AI lifecycle." Evidence examples call explicitly for "provenance (timestamps, approver names)."
Custody anchors each artifact's provenance to a public ledger. The timestamp is set by a network the institution does not control, so "when was this generated" is answerable to an examiner without trusting the institution's own clock.
MP-1.6.2 — Data Interdependency and Provenance Documentation
"The organization documents the AI system's internal and external data interdependencies, including data provenance..."
Custody binds the exact inputs to each AI decision by hash. Data provenance stops being a document that asserts lineage and becomes a commitment an examiner can recompute and verify.
GV-6.1.5 / GV-6.1.10 — Third-Party AI Risk & Incident Documentation
Documentation of third-party AI risks "including... data provenance," and incident protocols "addressing data provenance issues" for vendor AI.
The hardest evidence to produce is about someone else's AI. Custody records the provenance of a third party's agent activity in a form verifiable without the third party's cooperation — the basis of Rubric's counterparty and agent-record checks.
MS-2.9.1 / MG-3.2.1 — Explainability, Validation & Remediation
Structured explanations with "training data sources... decision pathways," and validation protocols producing reports with provenance and benchmark metrics.
Custody does not validate a model or judge its fairness. It captures tamper-evident proof that the validation ran, when, and produced the recorded result — the evidence dimension of the control, in a form that survives review.
The honest scope. Custody is the evidence layer, not an AI governance platform. It does not write your policies, validate your models, or detect bias, and it does not satisfy the many controls a document repository already covers. It wins one specific, difficult class: the controls whose evidence must carry provenance, an authoritative timestamp, or independent verifiability — because those are the properties a system you control cannot credibly assert about itself. For those, a self-kept record is the weakest evidence in the room, and an anchored one is the strongest.

The established Profile carries the same demand

CRI Profile v2.2 — mapped to DORA, FFIEC, GLBA, MAS, APRA, HKMA

The AI framework is new. The obligation is not. The CRI Profile — the financial sector's established control standard, mapped to the regulators above — already requires it: RS.AN-06, "actions performed during an investigation are recorded, and the records' integrity and provenance are preserved"; RS.AN-07.01, forensic data "preserved in a manner supporting integrity, provenance, and evidentiary value"; DE.CM-09.01, "integrity checking mechanisms to verify... information integrity and provenance." Custody satisfies the evidence dimension of each, and exceeds the checksums the last one names — because its integrity check does not depend on the institution's own systems staying honest.

The EU now names this as a trust service

eIDAS 2.0 — Regulation (EU) 2024/1183, mandatory rollout by December 2026

The revised eIDAS regulation expands the EU's roster of recognised trust services beyond signatures, seals, and timestamps. Among the new categories is the electronic ledger: a trust service that records sequences of electronic data while ensuring their integrity and accurate chronological ordering. That is a legal description of what Rubric Custody does. Every record is hash-committed in sequence, its integrity checkable by any party, its chronological position fixed by public consensus rather than by the operator's clock.

Rubric is aligned with the electronic ledger trust service category. It is not a qualified trust service provider under eIDAS, and does not claim qualified status. What the framework establishes is that the property Custody delivers, tamper-evident chronological ordering verifiable by a third party, is now a recognised category of trust service across all 27 member states, with legal weight attaching to records that carry it. For EU deployers of AI systems, that is the difference between evidence that is technically sound and evidence a regulator has a legal vocabulary for.

Both frameworks are voluntary today. Legal analysts covering the FS AI RMF note that examiners may ask for evidence of these controls before any formal rule requires it. The institutions that build verifiable evidence now have smooth examinations. The ones that wait have findings.

See a record verify against a public ledger, in your browser, with no account and no trust in us.

Verify a record →
Control language quoted from the CRI Financial Services AI RMF v1.0 (Feb 2026) and CRI Profile v2.2. Electronic ledger trust service per Regulation (EU) 2024/1183 (eIDAS 2.0). Frameworks at cyberriskinstitute.org. Rubric is not affiliated with or endorsed by the Cyber Risk Institute or the U.S. Treasury.