← FS AI RMF overview

FS AI RMF controls mapping (draft)

Grounded mapping (Jul 2026), crosswalked to the official Risk & Control Matrix v1.0. Voluntary framework — produces evidence for; not certified by. Scope: SDLC, change-management, and audit-trail themes for agent-assisted software changes.

Framework: FS AI RMF (Feb 2026, CRI/FSSCC). Mapped to official FS AI RMF Risk & Control Matrix v1.0 reference IDs — scoped to the SDLC/change-management slice, not the full 230 objectives.

What SSX360 covers

ThemeFunctionRCM refControl needSSX360 artifact
Change authorizationManageMG-4.1.4Agent-assisted merges to protected branches are authorized and attributableSigned commit envelope (provenance.actor, provenance.tool, provenance.scope)
Integrity before deployManageMG-1.1.2Changes are verified before production paths updateScroll Gate CI result per PR (ssx360 check --pr)
Tamper-evident recordGovernGV-1.4.3Audit trail survives independent reviewEd25519 signature on envelope — offline verify in CLI or browser
Export for reviewGovernGV-1.4.2Evidence consumable without trusting SSX360ssx360-ledger --export → ssx360.evidence-pack.v1 JSON
Agent registryGovernGV-1.6.1Declared agents/tools tracked over timeApproved-agent registry snapshot in evidence pack
Payments / ledger pathsGovernGV-1.6.2Financial-infra code paths gatedPolicy preset financial-infra on payments/**, ledger/**

Representative mapping rows (SDLC slice)

RCM IDs are real Risk & Control Matrix v1.0 control-objective references. The theme column is SSX360's own paraphrase of each control's scope, not a verbatim quote of CRI's text.

RCM IDControl objective themeEvidence SSX360 produces
MG-4.1.4Change management for AI systems — updates run through structured, documented, trackable processesEnvelope provenance.actor_type, provenance.tool on every agent-assisted merge
MG-1.1.2Go/No-Go decision criteria — clear thresholds gate whether a change proceeds, pauses, or is rejectedScroll Gate blocked / review events in ledger
GV-1.4.3Documentation repository with access controls, kept ready for oversight and auditSigned evidence pack + detached signature
GV-1.6.1Inventory of systems/tooling with responsible owners and dependencies trackedMCP / hook metadata in envelope (declared tool identity)
GV-1.6.2High-risk / mission-critical systems get enhanced oversight, control, and reportingfinancial-infra policy rule outcomes on payments/**, ledger/**
GV-1.4.2Documentation standards covering monitoring and change-management activitycompliance_mappings[] includes FS AI RMF entry
MS-2.1.3Centralized, version-controlled, access-controlled repository enabling independent reviewmatrixscroll verify / browser verifier at ssx360.com/verify

PCI DSS v4.0.1 Req 6.5.1 pairing

Same change-management evidence class — FS AI RMF opens the conversation; PCI and SOC 2 close where assessors write the invoice.

PCI needSSX360 evidence
Authorized custom software changesProtected-branch Scroll Gate
Trace agent-assisted editsSigned envelope per commit
Assessor reviewEvidence pack sample + offline verify

Claims ladder

Allowed

  • produces evidence aligned to FS AI RMF
  • readiness for voluntary control objectives
  • scoped SDLC / change-management slice

Not allowed

  • FS AI RMF certified
  • required by FS AI RMF
  • covers all 230 objectives

Explicitly out of scope

  • Model risk management and training-data governance
  • Board-level AI governance programs
  • Third-party AI vendor due diligence (beyond your code changes)
  • Full 230 FS AI RMF control objectives

We welcome feedback on this draft mapping — email mission@ssx360.com or use the contact form.

Send mapping feedback