CSBS Did Not Invent This. It Assembled It: The Frameworks Behind the CSBS AI Framework
The CSBS Artificial Intelligence Supervisory Framework did not come out of nowhere, and it is not one state group’s opinion about technology. It is built on three published resources that financial institutions can read, map to, and cite.
Understanding those three resources is the quickest way to understand what examiners will expect, and to avoid building an AI governance program twice.
Key Takeaways
- CSBS identifies three resources underneath its AI framework: the NIST AI Risk Management Framework, the Cyber Risk Institute Financial Services AI Risk Management Framework, and the U.S. Department of the Treasury AI Lexicon.
- NIST organizes AI risk management around four functions: Govern, Map, Measure, and Manage. Governance runs across the other three.
- The CRI framework adapts NIST for financial services with 230 control objectives, scaled to an institution’s stage of AI adoption.
- Treasury’s AI Lexicon gives every department the same vocabulary, which removes a surprising amount of confusion.
- Mortgage lenders and servicers should map to the Fannie Mae and Freddie Mac AI requirements in the same exercise, not as a separate project.
What Frameworks Is the CSBS AI Framework Built On?
CSBS specifically identifies three resources underneath its approach:
| Resource | Published by | What it does |
|---|---|---|
| AI Risk Management Framework (AI RMF) | National Institute of Standards and Technology (NIST) | Sets the overall structure for managing AI risk through four functions: Govern, Map, Measure, Manage |
| Financial Services AI Risk Management Framework (FS AI RMF) | Cyber Risk Institute (CRI) | Translates the NIST approach into 230 control objectives designed for financial institutions |
| AI Lexicon | U.S. Department of the Treasury | Provides common definitions so regulators, institutions, and vendors use AI terms the same way |
Each resource answers a different question. NIST answers “how should AI risk be organized.” CRI answers “which controls apply to a financial institution.” Treasury answers “what do we mean when we say AI.”
How Does the NIST AI Risk Management Framework Work?
NIST organizes AI risk management around four functions:
- Govern: the policies, accountability, and culture that guide how AI is used.
- Map: understanding where AI is used and the context it operates in.
- Measure: assessing and tracking the risks each AI use creates.
- Manage: prioritizing and acting on those risks.
Governance is meant to run across the other three rather than sit off to the side as a separate compliance exercise. That distinction is worth remembering. A governance function that only produces documents, without follow-through into mapping, measuring, and managing, is not doing what NIST describes.
What Is the CRI Financial Services AI Risk Management Framework?
The Cyber Risk Institute takes the NIST concept further for financial services. Its framework includes 230 control objectives and is designed so institutions can adjust their approach based on their stage of AI adoption and their risk profile. Tiering each AI use by risk is the practical way to decide which objectives apply first.
In other words, no one expects an institution to adopt all 230 on day one. The expectation is to adopt the ones that make sense at the time of implementation, document why, and expand as AI use grows.
For a community institution, that is the difference between a framework that is usable and one that sits on a shelf.
Why Does the Treasury AI Lexicon Matter?
Treasury’s AI Lexicon does something less exciting and just as useful. It gives everyone the same vocabulary.
That matters more than it sounds. A fair amount of the confusion inside institutions comes from four different departments using the word “AI” to mean four different things. IT may mean machine learning models. Compliance may mean anything automated. The business line may mean a chatbot. Marketing may mean the generative AI tool used to draft emails.
When the definitions differ, the inventory comes back incomplete and the risk assessment measures the wrong things. Agreeing on terms first is a small step that makes everything after it more accurate.
What Do These Frameworks Expect From Management?
Read together, the message behind all three resources is simple:
- Know what you are using.
- Know the risk.
- Know who owns it.
- Put controls around it.
- Be able to prove that those controls exist and operate.
That fifth point is where most programs fall short. Controls that exist on paper but cannot be evidenced will not hold up in an examination. It is the same discipline auditors apply to control design and operating effectiveness in financial reporting: a control only counts if you can show it works.
What This Means for Mortgage Lenders and Servicers
Mortgage lenders and servicers have a fourth reference point that banks do not: the Fannie Mae and Freddie Mac AI requirements. Freddie Mac’s requirements took effect on March 3, 2026 (Guide Bulletin 2025-16, Section 1302.8), and Fannie Mae’s Lender Letter LL-2026-04 took effect on August 6, 2026.
The GSE requirements are contractual, not supervisory, and that changes what a gap costs. A supervisory finding leads to corrective action on the regulator’s timeline. A gap against the Seller/Servicer Guide can affect a company’s ability to sell loans into the secondary market.
The practical answer is to map once, not twice. Any institution working through the NIST and CRI frameworks should map to the Fannie Mae and Freddie Mac requirements in the same exercise. The control language overlaps a great deal, and running two separate projects wastes time and money.
How Cathedral Maps Institutions Against Published Frameworks
At Cathedral, we map institutions against these published frameworks rather than against something we made up ourselves. The reason is simple. When an examiner asks where a control expectation came from, a published source is a much better answer than a consultant’s opinion. That principle sits behind every framework mapping engagement at Cathedral CPAs & Advisors.
A typical mapping engagement includes:
- Building or validating the AI inventory using common Treasury definitions.
- Mapping existing controls to the NIST functions and relevant CRI control objectives.
- For mortgage clients, adding the Fannie Mae and Freddie Mac requirements to the same control map.
- Identifying gaps and ranking them by risk and examination priority.
