The FINOS AI Governance Framework, read against binding law

About this documentUpdated ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.

Every law named here links to its summary page on lexlint.io, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same license. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.

Law library as of .

Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice in the footer says what that means.

FINOS, the Linux Foundation's foundation for open source in financial services, publishes an AI Governance Framework: 24 risks that AI brings into a financial institution and 25 mitigations for them, each tied to the standards, supervisory texts and laws its authors read. This page reads the same catalog against the LexLint law library: which binding laws bear on what each mitigation does, and in which jurisdictions; which of the framework's own references are law and which are guidance; and which legal responsibilities a bank or insurer carries out through software its suppliers build.

LexLint.io Where the FINOS framework sits
The FINOS framework is one framework among several, and it cites all four kinds of document, sorted here by who can hold a reader to them. LexLint reads each framework against the law beneath it: 1,174 laws in the law library bear on the FINOS framework's mitigations, each counted only where the law's own requirement lines, read against the NIST framework for its subject, bear it out. Each item links to its page on lexlint.io, or to where this page lists it.

1What this is

The Fintech Open Source Foundation (FINOS) is the Linux Foundation's home for open source in financial services. Its AI Governance Framework, published at air-governance-framework.finos.org, is maintained in the open on GitHub under Creative Commons Attribution 4.0 by contributors from banks and their technology suppliers. Version 1, of , held 17 risks and 17 mitigations; version 2, of , held 23 risks and 23 mitigations. This page reads the framework as it stood on , when its repository marked it an incubating FINOS project, with 3 items added since version 2 and 3 items marked as drafts.

The framework is a catalog. Each of its 24 risks (operational, security, and regulatory and compliance) links to the mitigations that address it, and each of its 25 mitigations is preventative or detective. Of its items, 15 were added for agentic systems and cover agent authority, tool chains, Model Context Protocol servers, multi-agent trust and human approval of actions. Each item lists the outside documents its authors mapped it to: 860 references in all, from NIST SP 800-53 and ISO/IEC 42001 to the EU AI Act, the UK Financial Conduct Authority's Handbook and Canadian securities rules.

In the terms LexLint uses for what kind of document something is, the framework is a framework: a set of practices, whoever publishes it. It binds no one. The laws it cites do, and so do laws it does not cite. This page reads it the way the AAIF page reads the sixteen themes of the Agentic AI Foundation's governance working group, whose charter names the FINOS framework as a specification for one end-user vertical.

2The crosswalk

One row per mitigation, the preventative ones first and then the detective ones as the framework groups them, each with the number of the framework's risks it addresses (hover for which). Its references counts the outside documents the framework attaches to the mitigation, and how many of them are a statute or regulation. The last line of each mitigation names the law library's obligation classes whose legal responsibilities have their natural home in the mitigation, mapped class by class. The laws column counts the laws whose own requirement lines carry one of those legal responsibilities, each line read against the NIST framework for its subject (the AI Risk Management Framework, the Privacy Framework or the Cybersecurity Framework), in force, not yet in force, blocked by a court or proposed. A law counts under every mitigation one of its classes reaches. The next four columns split the count by the four jurisdictions the framework's own references cover (a state's or a province's law counts under its country), and the last counts the other jurisdictions the laws come from. A row says that a law bears on what the mitigation does, never that running the mitigation satisfies the law.

Mitigation, the risks it addresses and its obligation classesIts referencesLawsEUUSUKCanadaOther jurisdictions
AIR-PREV-002 · preventative · 2 risks
Data Filtering From External Knowledge Bases
no obligation class
16
law 3
0 0000 0
AIR-PREV-003 · preventative · 4 risks
User/App/Model Firewalling/Filtering
no obligation class
11
law 0
0 0000 0
AIR-PREV-005 · preventative · 6 risks
System Acceptance Testing
DPIA, governance, prohibition
13
law 2
512 1916813 134
AIR-PREV-006 · preventative · 8 risks
Data Quality & Classification/Sensitivity
biometric, data subject rights, governance
22
law 1
396 171910 131
AIR-PREV-007 · preventative · 5 risks
Legal and Contractual Frameworks for AI Systems
TDM, attribution, contract terms, security, transfer
20
law 2
283 52820 120
AIR-PREV-008 · preventative · 1 risk
Quality of Service (QoS) and DDoS Prevention for AI Systems
security
13
law 0
154 12610 92
AIR-PREV-010 · preventative · 2 risks
AI Model Version Pinning
no obligation class
15
law 0
0 0000 0
AIR-PREV-012 · preventative · 3 risks
Role-Based Access Control for AI Data
security
17
law 0
154 12610 92
AIR-PREV-014 · preventative · 2 risks
Encryption of AI Data at Rest
security
9
law 0
154 12610 92
AIR-PREV-017 · preventative · 4 risks
AI Firewall Implementation and Management
security
11
law 0
154 12610 92
AIR-PREV-018 · preventative · 2 risks
Agent Authority Least Privilege Framework agentic
access restriction
12
law 0
134 02100 87
AIR-PREV-019 · preventative · 3 risks
Tool Chain Validation and Sanitization agentic
no obligation class
11
law 0
0 0000 0
AIR-PREV-020 · preventative · 3 risks
MCP Server Security Governance agentic
security
13
law 0
154 12610 92
AIR-PREV-022 · preventative · 3 risks
Multi-Agent Isolation and Segmentation agentic
no obligation class
11
law 0
0 0000 0
AIR-PREV-023 · preventative · 3 risks
Agentic System Credential Protection Framework agentic
access restriction
10
law 0
134 02100 87
AIR-PREV-024 · preventative · 3 risks
Human-in-the-Loop Action Approval Gate agentic draft
governance
13
law 3
223 141200 119
AIR-PREV-025 · preventative · 3 risks
Skill/Plugin Integrity and Governance agentic draft
no obligation class
12
law 1
0 0000 0
AIR-DET-001 · detective · 1 risk
AI Data Leakage Prevention and Detection
breach notice, security
22
law 3
229 24020 101
AIR-DET-004 · detective · 13 risks
AI System Observability
breach notice, governance, reporting, retention
21
law 0
421 195310 135
AIR-DET-009 · detective · 1 risk
AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring
no obligation class
11
law 0
0 0000 0
AIR-DET-011 · detective · 6 risks
Human Feedback Loop for AI Systems
governance
17
law 2
223 141200 119
AIR-DET-013 · detective · 4 risks
Providing Citations and Source Traceability for AI-Generated Information
attribution
14
law 2
32 0100 25
AIR-DET-015 · detective · 7 risks
Using Large Language Models for Automated Evaluation (LLM-as-a-Judge)
no obligation class
11
law 0
0 0000 0
AIR-DET-016 · detective · 2 risks
Preserving Source Data Access Controls in AI Systems
no obligation class
16
law 0
0 0000 0
AIR-DET-021 · detective · 3 risks
Agent Decision Audit and Explainability agentic
data subject rights, disclosure, governance, reporting, retention
25
law 11
586 2310024 142

Binding law stands behind 16 of the 25 mitigations, 1,174 laws in all. The 9 with none are engineering controls: Data Filtering From External Knowledge Bases, User/App/Model Firewalling/Filtering, AI Model Version Pinning, Tool Chain Validation and Sanitization, Multi-Agent Isolation and Segmentation, Skill/Plugin Integrity and Governance, AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring, Using Large Language Models for Automated Evaluation (LLM-as-a-Judge) and Preserving Source Data Access Controls in AI Systems. No legal responsibility in the law library has its natural home in one of them, which says where the law speaks and where it does not, not that the controls matter less. The laws behind each mitigation are listed on the framework's page on the frameworks pages, one page per mitigation that has any.

3What the framework cites, and what the law library holds

The framework keeps its references in 13 collections, 5 of them tied to one jurisdiction: Canada AI & Financial-Sector Regulatory References (Canada, 60 entries), EU AI Act (European Union, 306 entries), FFIEC IT Examination Handbook (United States, 109 entries), SR 11-7: Model Risk Management (United States, 15 entries) and UK Financial Services AI Regulations (United Kingdom, 20 entries). A collection of United States regulations had been proposed and was not merged when the framework was read, on . No risk or mitigation carries a jurisdiction of its own, and a reader who wants the law of one jurisdiction reads it out of those collections.

The 860 references name standards, supervisory texts and laws. Grouped by where each comes from, with its kind and whether the law library holds it, counted from the law library on the date in this page's byline:

FromCitedKindReferencesIn the law library
Standards and frameworks NIST (SP 800-53, 800-161, 800-63B, CSF, SSDF, AI 600-1) framework 224 on the frameworks pages: NIST AI RMF, NIST AI 600-1, NIST Privacy Framework, NIST CSF 2.0
ISO/IEC 42001 and ISO 27001 framework 53 no
OWASP (LLM, Agentic and ML Top 10s) framework 58 on the frameworks pages: OWASP LLM Top 10, OWASP Agentic Top 10
MITRE ATLAS and ATT&CK, Agent Threat Rules, SOC 2, CISA framework 34 no
International bodies IOSCO supervisory toolkit and final report on AI in capital markets policy 131 no
Basel Committee policy 1 no
European Union AI Act law 77 yes, 28 provisions
GDPR law 6 yes, 7 provisions
DORA law 2 yes, 2 provisions
MiFID II law 3 not yet; by
EBA guidelines guidance 2 not yet; by
United States FFIEC IT Examination Handbook guidance 66 no
OCC Bulletin 2026-13 guidance 2 no
GLBA law 3 yes, 1 provision
SEC Rule 17a-4 law 2 not yet; by
CCPA law 4 yes, 5 provisions
United Kingdom FCA Handbook (PRIN, PRIN 2A, SYSC, COBS, MIFIDPRU) and the Senior Managers regime law 27 not yet; by
FCA, PRA and Bank of England guidance and supervisory statements guidance 28 not yet; by
UK GDPR and Data Protection Act 2018 law 7 yes, 7 provisions
Equality Act 2010, Consumer Credit Act 1974 law 5 not yet; by
ICO guidance and risk toolkit guidance 12 no
Canada National instruments (NI 31-103, 33-109, 81-102, 81-106, 81-107) law 26 not yet; by
CIRO rules law 10 not yet; by
CSA staff notices, Companion Policy 31-103CP, CIRO guidance and reports guidance 35 no
OSFI guidelines (E-23, B-10, B-13) and the AMF AI guideline guidance 18 not yet; by
PIPEDA, and Quebec's private-sector privacy act (P-39.1) law 10 yes, 9 provisions
Ontario Human Rights Code, Canadian Human Rights Act law 2 no
Other 12 further sources, each cited a few times · 12 ·

Two things follow from the table. The framework is already jurisdictional: past the European Union, it cites the Financial Conduct Authority's Handbook module by module and Canada's securities instruments section by section, which no general AI framework does. And the framework and the law library meet on general law and part ways on financial law: the law library holds the general laws the framework cites and, until the date in section 5, few of the financial rulebooks.

4Legal responsibilities a financial institution carries out through software

Some laws bind a bank, an insurer or a payment firm, and the firm carries them out through software it buys. The law library tags each requirement line by whose legal responsibility it is, and 73 lines in 25 instruments from 18 jurisdictions bind a regulated financial entity. A LexLint run says which side of that line its software is on. Software the financial entity runs takes the entity's lines, and those carried out through software, as its own. Software supplied to one reports the lines carried out through software as its customer's legal responsibilities, the supplier's own lines as its own, and the entity's other lines apart from both.

JurisdictionInstrumentThe entityThrough softwareThe supplier
Dominican Republic Ley No. 172-13 sobre Protección Integral de los Datos Personales
Ley No. 172-13, Gaceta Oficial No. 10737, 15 de diciembre de 2013, arts. 1-6, 27-28, 42-43, 60 y 63
1 1
Ley No. 172-13 sobre Protección Integral de los Datos Personales, rights of data subjects and habeas data
Ley No. 172-13, arts. 7-26, 44, 71 (rights of data subjects and habeas data)
2
Ley No. 172-13 sobre Protección Integral de los Datos Personales, special and sensitive categories of data
Ley No. 172-13, arts. 66, 75-79 (special categories of data)
1
Ley No. 172-13 sobre Protección Integral de los Datos Personales, supervision, administrative sanctions, and offences
Ley No. 172-13, arts. 29, 81-88 (supervision, administrative sanctions, and offences)
1
European Union DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301
Regulation (EU) 2022/2554, Article 19
6
DORA, Articles 28-30 (ICT Third-Party Risk Management)
Regulation (EU) 2022/2554, Arts. 28-30
2 1 2
Haiti BRH Circulaire 126, Information Security Rules for Financial Institutions
Banque de la République d'Haïti, Circulaire 126, Sur les règles en matière de sécurité informatique, 13 janvier 2022, arts. 1-5
5 2
Lebanon Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts)
Banque du Liban Basic Decision No. 12725 of (Basic Circular No. 144 to Banks, also addressed to Financial Institutions), Prevention of Electronic Criminal Acts, Arts. 1-6
2 2
Qatar Qatar Central Bank Artificial Intelligence Guideline
Qatar Central Bank Artificial Intelligence Guideline (2024)
1 2
Serbia Law on Information Security, ICT Systems of Special Importance and Security Measures
Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 5-12
1
Law on Information Security, Incident Reporting Obligations
Zakon o informacionoj bezbednosti ("Sl. glasnik RS", br. 91/2025), čl. 13-14, 24-25
1
State of Palestine Law by Decree No. 41 of 2022 concerning National Payments, Licensing and Security-Systems Duty
Law by Decree No. 41 of 2022 concerning National Payments, Art. 8
1
Taiwan Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit
Arts. 24-25 of the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries (金融控股公司及銀行業內部控制及稽核制度實施辦法), full-text revision promulgated (Financial Supervisory Commission Order Jin-Guan-Yin-Guo-Zi No. 11502710961), effective on promulgation for the articles cited here
4 1
United States Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers
12 CFR Part 53 (OCC); 12 CFR Part 225, Subpart N (Federal Reserve Board); 12 CFR Part 304, Subpart C (FDIC)
1 2
GLBA Safeguards Rule Breach Notification Amendment
16 CFR Section 314.4(j)
1
US-Alabama SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization
Ala. SB 63, 2026 Regular Session
4
US-Arizona Denial of claims; individualized review requirement
A.R.S. § 20-3103
2
US-Colorado Amended Regulation 10-1-1 (2025), Governance and Risk Management Framework for Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models
3 CCR 702-10, Regulation 10-1-1
1 3
SB 21-169 (2021), Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models
C.R.S. 10-3-1104.9
3
US-Maryland HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review
Md. Code Ann., Ins. §15-10B-05.1
5
US-Minnesota Utilization Review, AI-Only Adverse Determination Prohibition
Minn. Stat. § 62M.09, subd. 3(f) (2026 Minn. Laws ch. 124, art. 3, § 6)
1
US-Missouri Genetic information, insurer and employer restrictions, confidentiality duty
Mo. Rev. Stat. Secs. 375.1300, 375.1303, 375.1306, 375.1309
1
US-New York New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent
23 NYCRR 500.17
4
US-Utah Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session)
Utah Code 31A-22-650, as amended
4
Yemen Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality Duty
Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations, art. 27
1 1

The three columns count lines by whose legal responsibility each is: the financial entity's own, the entity's but carried out through the software, and the supplier's own legal responsibility to the entity (the Digital Operational Resilience Act's contract terms for an ICT third-party provider are the clearest case). A run declares the sector in the declaration's regulated_sector field, described in the LexLint schema.

5What the law library will hold by

The law library is organized by subject (AI, privacy, cybersecurity, scraping, age assurance, news aggregation), and today financial law enters it only where it is also one of those. Its financial-services coverage will be complete by . Complete means that every item below is in the law library by that date, researched from its official text, dated and linked: the financial law and supervisory texts that the FINOS framework cites for the four jurisdictions it covers, and that the law library did not hold when this page was written.

JurisdictionTo be addedKind
European Union Consumer Credit Directive (EU) 2023/2225, Article 18: creditworthiness assessment, including automated processing and the right to human intervention law
AI Act, Annex III point 5(b): AI used to assess the creditworthiness of natural persons or establish their credit score, as its own row law
MiFID II: organizational requirements for algorithmic trading and investment firms' systems law
EBA Guidelines on loan origination and monitoring, on automated models in creditworthiness assessment guidance
United States Equal Credit Opportunity Act and Regulation B: adverse-action notices for decisions made with AI law
SEC Rule 17a-4 and the broker-dealer record rules; FINRA Rules 3110 and 2210, and Regulatory Notice 24-09 law and guidance
NYDFS Part 500 beyond section 500.17, and the 2024 industry letter on AI cybersecurity risks law and guidance
The interagency model risk management guidance (SR 11-7) as revised in April 2026 guidance
United Kingdom FCA Handbook: PRIN 2A (the Consumer Duty), SYSC and COBS 9 and 9A, as they bear on AI systems law
Consumer Credit Act 1974 and the Equality Act 2010, as they bear on automated credit decisions law
PRA Supervisory Statement SS1/23, model risk management principles for banks guidance
Canada NI 31-103 (registrant obligations, including know your client and suitability) and the 81-series investment fund instruments law
CIRO rules on business conduct, supervision and recordkeeping law
OSFI Guidelines E-23 (model risk management), B-10 and B-13 guidance

Supervisory guidance will be shown beside the law it reads and, as everywhere in the law library, never counted as law and never raised in a run on its own. Payments law, and insurance law beyond the state statutes on AI in health insurance, are outside this commitment. Section 3's last column counts from the law library on every rebuild of this page, so each item shows there as it lands.

6The agentic items

The framework's items include 15 that address agents directly: agent authority, tool chains, Model Context Protocol servers, multi-agent trust and human approval of actions. They are where this framework and the subject of the AAIF page and the LexLint Legal Handbook meet. The laws column is the crosswalk's, for a mitigation; a risk has no laws of its own here, only through the mitigations that address it.

ItemKindObligation classesLaws
AIR-PREV-018
Agent Authority Least Privilege Framework
Mitigation access restriction 134
AIR-PREV-019
Tool Chain Validation and Sanitization
Mitigation none 0
AIR-PREV-020
MCP Server Security Governance
Mitigation security 154
AIR-PREV-022
Multi-Agent Isolation and Segmentation
Mitigation none 0
AIR-PREV-023
Agentic System Credential Protection Framework
Mitigation access restriction 134
AIR-PREV-024
Human-in-the-Loop Action Approval Gate draft
Mitigation governance 223
AIR-PREV-025
Skill/Plugin Integrity and Governance draft
Mitigation none 0
AIR-DET-021
Agent Decision Audit and Explainability
Mitigation data subject rights, disclosure, governance, reporting, retention 586
AIR-SEC-024
Agent Action Authorization Bypass
Risk · ·
AIR-SEC-025
Tool Chain Manipulation and Injection
Risk · ·
AIR-SEC-026
MCP Server Supply Chain Compromise
Risk · ·
AIR-SEC-027
Agent State Persistence Poisoning
Risk · ·
AIR-OP-028
Multi-Agent Trust Boundary Violations
Risk · ·
AIR-SEC-029
Agent-Mediated Credential Discovery and Harvesting
Risk · ·
AIR-SEC-030
Skill/Plugin Supply Chain Compromise draft
Risk · ·

7The files

  • finos-crosswalk.csv: section 2 as a file, one row per mitigation, with its risks, the framework's references, and the law library's classes, laws and jurisdictions as counts.
  • finos-sector-duties.csv: section 4 as a file, one row per instrument, with how many of its lines bind the entity, bind it through software, or bind its supplier.

Both files are cut from the same law library as this page, on the date in its byline, and are regenerated with it. They are licensed separately from the text and figures around them, under Creative Commons Attribution 4.0, the framework's own license, rather than the ShareAlike terms in the byline: use them for any purpose, including commercially, with credit to LexLint (UnGovr). The requirement lines behind section 4, with whose legal responsibility each is and why, are in My LexLint and the API.

8What this page does not claim

It does not say that any line binds any particular organization, and it does not say that running a mitigation satisfies a law: a row says a law bears on what the mitigation does, never more. Every law entry links to the source the law library researched it from. The commitment in section 5 is LexLint's, not FINOS's.

The framework's risk and mitigation titles are quoted from the FINOS AI Governance Framework (air-governance-framework.finos.org), copyright 2025 FINOS, licensed under Creative Commons Attribution 4.0, read at commit a149dd1e. FINOS has not reviewed or endorsed this page, and the reading of the framework against the law is LexLint's.