Compliance billing layer · voluntary framework

FS AI RMF checklist for AI-assisted code changes

FS AI RMF maps evidence for regulated fintech — a door-opener, not the spearhead. Lead with agent authorization; use this checklist when your buyer asks about Treasury-endorsed AI governance. Matrix Scroll signs merges locally; SSX360 hosts authorization records, Scroll Gate CI, and audit packs assessors verify offline. We map a deliberate SDLC / change-management slice of FS AI RMF — the part institutions struggle to defend when agents land on protected branches.

Voluntary framework — produces evidence aligned to FS AI RMF control objectives; not certified by CRI or Treasury. Scoped to SDLC / change-management only (not all 230 objectives).

Three artifacts examiners ask for

Commit envelopes

Matrix Scroll signs every agent-assisted merge — actor, tool, and scope in an Ed25519 envelope your assessor verifies offline.

PyPI SDK

Scroll Gate (CI)

Protected branches gate merges before deploy. Copilot, Cursor, and agent tools on main need examiner-ready proof — not policy slides alone.

CI integration

Audit packs

Export ssx360.evidence-pack.v1 JSON with compliance_mappings for FS AI RMF — verify in browser or CLI without trusting SSX360.

Sample pack

Scoped control mapping (SDLC slice)

Mapped to official FS AI RMF Risk & Control Matrix v1.0 reference IDs for AI-authored code changes — scoped to the SDLC slice, not the full 230 objectives. Full draft mapping · feedback welcome at mission@ssx360.com

RCM IDControl themeSSX360 evidence
MG-4.1.4Change management for AI systems — updates run through structured, documented, trackable processesEnvelope provenance.actor_type, provenance.tool on every agent-assisted merge
MG-1.1.2Go/No-Go decision criteria — clear thresholds gate whether a change proceeds, pauses, or is rejectedScroll Gate blocked / review events in ledger
GV-1.4.3Documentation repository with access controls, kept ready for oversight and auditSigned evidence pack + detached signature
GV-1.6.1Inventory of systems/tooling with responsible owners and dependencies trackedMCP / hook metadata in envelope (declared tool identity)
GV-1.6.2High-risk / mission-critical systems get enhanced oversight, control, and reportingfinancial-infra policy rule outcomes on payments/**, ledger/**
GV-1.4.2Documentation standards covering monitoring and change-management activitycompliance_mappings[] includes FS AI RMF entry
MS-2.1.3Centralized, version-controlled, access-controlled repository enabling independent reviewmatrixscroll verify / browser verifier at ssx360.com/verify
Read full mapping with PCI pairing →

What SSX360 maps

  • Signed commit envelopes with declared actor, tool, and scope
  • Scroll Gate CI on protected branches
  • Offline-verifiable evidence pack export
  • FS AI RMF and PCI DSS v4.0.1 Req 6.5.1 compliance_mappings
  • Financial-infra policy preset for payments and ledger paths

Out of scope

  • Model risk management and training-data governance
  • Board-level AI governance programs
  • Third-party AI vendor due diligence (beyond your code changes)
  • Full 230 FS AI RMF control objectives

FS AI RMF checklist — common questions

Voluntary framework guidance for fintech and regulated teams evaluating agent-assisted code change evidence in the United States. Not legal advice; not certification.

What is FS AI RMF?
The Financial Services AI Risk Management Framework (FS AI RMF) is a voluntary framework published in February 2026 by the Cyber Risk Institute (CRI) and FSSCC. It defines 230 control objectives for institutions building or deploying AI systems. SSX360 maps a scoped SDLC and change-management slice — not the full framework.
Is FS AI RMF mandatory for fintech companies?
No. FS AI RMF is voluntary. Banks and enterprise counterparties may send AI governance questionnaires derived from it, but there is no universal mandate. SSX360 helps teams produce evidence aligned to relevant control objectives — not claim certification.
Does SSX360 certify FS AI RMF compliance?
No. SSX360 produces evidence aligned to FS AI RMF control objectives for software change management. It does not certify, attest, or replace assessor or regulator review.
What part of FS AI RMF does SSX360 cover?
A deliberate SDLC slice: signed commit envelopes, Scroll Gate CI on protected branches, and offline-verifiable evidence pack export. Out of scope: model risk, bias testing, board governance, and full 230-objective coverage.
How does FS AI RMF relate to PCI DSS v4.0.1 Req 6.5.1?
Both concern custom software change control. FS AI RMF is a fintech door-opener; PCI Req 6.5.1 is the defined-approach requirement under secure change management for payment software. SSX360 produces the same class of signed change-management evidence for assessor review.
How do I verify SSX360 evidence without trusting SSX360?
Download ssx360.evidence-pack.v1 JSON and verify Ed25519 signatures offline via matrixscroll verify, the browser verifier at ssx360.com/verify, or Scroll Gate in CI. No SSX360 uptime required in the trust path.