The FINOS AI Governance Framework, read against binding law
About this documentUpdated ShowHide
Sean McDermott, Co-Founder and CEO, UnGovr
Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.
Every law named here links to its summary page on lexlint.io, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.
© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same license. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.
Law library as of .
Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice in the footer says what that means.
FINOS, the Linux Foundation's foundation for open source in financial services, publishes an AI Governance Framework: 24 risks that AI brings into a financial institution and 25 mitigations for them, each tied to the standards, supervisory texts and laws its authors read. This page reads the same catalog against the LexLint law library: which binding laws bear on what each mitigation does, and in which jurisdictions; which of the framework's own references are law and which are guidance; and which legal responsibilities a bank or insurer carries out through software its suppliers build.
European UnionAI ActGDPRDORAMiFID II
United StatesGLBASEC Rule 17a-4CCPA
United KingdomFCA HandbookUK GDPR and DPA 2018Equality Act; Consumer Credit Act
CanadaNI 31-103 and the 81-seriesCIRO rulesPIPEDA; Quebec P-39.1Human rights acts
European UnionEBA guidelines
United StatesFFIEC handbookOCC Bulletin 2026-13
United KingdomFCA, PRA and Bank of England statementsICO guidance
CanadaCSA notices and CIRO guidanceOSFI E-23, B-10, B-13; AMF
1What this is
The Fintech Open Source Foundation (FINOS) is the Linux Foundation's home for open source in financial services. Its AI Governance Framework, published at air-governance-framework.finos.org, is maintained in the open on GitHub under Creative Commons Attribution 4.0 by contributors from banks and their technology suppliers. Version 1, of , held 17 risks and 17 mitigations; version 2, of , held 23 risks and 23 mitigations. This page reads the framework as it stood on , when its repository marked it an incubating FINOS project, with 3 items added since version 2 and 3 items marked as drafts.
The framework is a catalog. Each of its 24 risks (operational, security, and regulatory and compliance) links to the mitigations that address it, and each of its 25 mitigations is preventative or detective. Of its items, 15 were added for agentic systems and cover agent authority, tool chains, Model Context Protocol servers, multi-agent trust and human approval of actions. Each item lists the outside documents its authors mapped it to: 860 references in all, from NIST SP 800-53 and ISO/IEC 42001 to the EU AI Act, the UK Financial Conduct Authority's Handbook and Canadian securities rules.
In the terms LexLint uses for what kind of document something is, the framework is a framework: a set of practices, whoever publishes it. It binds no one. The laws it cites do, and so do laws it does not cite. This page reads it the way the AAIF page reads the sixteen themes of the Agentic AI Foundation's governance working group, whose charter names the FINOS framework as a specification for one end-user vertical.
2The crosswalk
One row per mitigation, the preventative ones first and then the detective ones as the framework groups them, each with the number of the framework's risks it addresses (hover for which). Its references counts the outside documents the framework attaches to the mitigation, and how many of them are a statute or regulation. The last line of each mitigation names the law library's obligation classes whose legal responsibilities have their natural home in the mitigation, mapped class by class. The laws column counts the laws whose own requirement lines carry one of those legal responsibilities, each line read against the NIST framework for its subject (the AI Risk Management Framework, the Privacy Framework or the Cybersecurity Framework), in force, not yet in force, blocked by a court or proposed. A law counts under every mitigation one of its classes reaches. The next four columns split the count by the four jurisdictions the framework's own references cover (a state's or a province's law counts under its country), and the last counts the other jurisdictions the laws come from. A row says that a law bears on what the mitigation does, never that running the mitigation satisfies the law.
| Mitigation, the risks it addresses and its obligation classes | Its references | Laws | Other jurisdictions | ||||
|---|---|---|---|---|---|---|---|
| AIR-PREV-002 · preventative · 2 risks Data Filtering From External Knowledge Bases no obligation class |
16 law 3 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-PREV-003 · preventative · 4 risks User/App/Model Firewalling/Filtering no obligation class |
11 law 0 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-PREV-005 · preventative · 6 risks System Acceptance Testing DPIA, governance, prohibition |
13 law 2 |
512 | 19 | 168 | 1 | 3 | 134 |
| AIR-PREV-006 · preventative · 8 risks Data Quality & Classification/Sensitivity biometric, data subject rights, governance |
22 law 1 |
396 | 17 | 19 | 1 | 0 | 131 |
| AIR-PREV-007 · preventative · 5 risks Legal and Contractual Frameworks for AI Systems TDM, attribution, contract terms, security, transfer |
20 law 2 |
283 | 5 | 28 | 2 | 0 | 120 |
| AIR-PREV-008 · preventative · 1 risk Quality of Service (QoS) and DDoS Prevention for AI Systems security |
13 law 0 |
154 | 1 | 26 | 1 | 0 | 92 |
| AIR-PREV-010 · preventative · 2 risks AI Model Version Pinning no obligation class |
15 law 0 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-PREV-012 · preventative · 3 risks Role-Based Access Control for AI Data security |
17 law 0 |
154 | 1 | 26 | 1 | 0 | 92 |
| AIR-PREV-014 · preventative · 2 risks Encryption of AI Data at Rest security |
9 law 0 |
154 | 1 | 26 | 1 | 0 | 92 |
| AIR-PREV-017 · preventative · 4 risks AI Firewall Implementation and Management security |
11 law 0 |
154 | 1 | 26 | 1 | 0 | 92 |
| AIR-PREV-018 · preventative · 2 risks Agent Authority Least Privilege Framework agentic access restriction |
12 law 0 |
134 | 0 | 21 | 0 | 0 | 87 |
| AIR-PREV-019 · preventative · 3 risks Tool Chain Validation and Sanitization agentic no obligation class |
11 law 0 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-PREV-020 · preventative · 3 risks MCP Server Security Governance agentic security |
13 law 0 |
154 | 1 | 26 | 1 | 0 | 92 |
| AIR-PREV-022 · preventative · 3 risks Multi-Agent Isolation and Segmentation agentic no obligation class |
11 law 0 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-PREV-023 · preventative · 3 risks Agentic System Credential Protection Framework agentic access restriction |
10 law 0 |
134 | 0 | 21 | 0 | 0 | 87 |
| AIR-PREV-024 · preventative · 3 risks Human-in-the-Loop Action Approval Gate agentic draft governance |
13 law 3 |
223 | 14 | 12 | 0 | 0 | 119 |
| AIR-PREV-025 · preventative · 3 risks Skill/Plugin Integrity and Governance agentic draft no obligation class |
12 law 1 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-DET-001 · detective · 1 risk AI Data Leakage Prevention and Detection breach notice, security |
22 law 3 |
229 | 2 | 40 | 2 | 0 | 101 |
| AIR-DET-004 · detective · 13 risks AI System Observability breach notice, governance, reporting, retention |
21 law 0 |
421 | 19 | 53 | 1 | 0 | 135 |
| AIR-DET-009 · detective · 1 risk AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring no obligation class |
11 law 0 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-DET-011 · detective · 6 risks Human Feedback Loop for AI Systems governance |
17 law 2 |
223 | 14 | 12 | 0 | 0 | 119 |
| AIR-DET-013 · detective · 4 risks Providing Citations and Source Traceability for AI-Generated Information attribution |
14 law 2 |
32 | 0 | 1 | 0 | 0 | 25 |
| AIR-DET-015 · detective · 7 risks Using Large Language Models for Automated Evaluation (LLM-as-a-Judge) no obligation class |
11 law 0 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-DET-016 · detective · 2 risks Preserving Source Data Access Controls in AI Systems no obligation class |
16 law 0 |
0 | 0 | 0 | 0 | 0 | 0 |
| AIR-DET-021 · detective · 3 risks Agent Decision Audit and Explainability agentic data subject rights, disclosure, governance, reporting, retention |
25 law 11 |
586 | 23 | 100 | 2 | 4 | 142 |
Binding law stands behind 16 of the 25 mitigations, 1,174 laws in all. The 9 with none are engineering controls: Data Filtering From External Knowledge Bases, User/App/Model Firewalling/Filtering, AI Model Version Pinning, Tool Chain Validation and Sanitization, Multi-Agent Isolation and Segmentation, Skill/Plugin Integrity and Governance, AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring, Using Large Language Models for Automated Evaluation (LLM-as-a-Judge) and Preserving Source Data Access Controls in AI Systems. No legal responsibility in the law library has its natural home in one of them, which says where the law speaks and where it does not, not that the controls matter less. The laws behind each mitigation are listed on the framework's page on the frameworks pages, one page per mitigation that has any.
3What the framework cites, and what the law library holds
The framework keeps its references in 13 collections, 5 of them tied to one jurisdiction: Canada AI & Financial-Sector Regulatory References (
Canada, 60 entries), EU AI Act (
European Union, 306 entries), FFIEC IT Examination Handbook (
United States, 109 entries), SR 11-7: Model Risk Management (
United States, 15 entries) and UK Financial Services AI Regulations (
United Kingdom, 20 entries). A collection of United States regulations had been proposed and was not merged when the framework was read, on . No risk or mitigation carries a jurisdiction of its own, and a reader who wants the law of one jurisdiction reads it out of those collections.
The 860 references name standards, supervisory texts and laws. Grouped by where each comes from, with its kind and whether the law library holds it, counted from the law library on the date in this page's byline:
| From | Cited | Kind | References | In the law library |
|---|---|---|---|---|
| Standards and frameworks | NIST (SP 800-53, 800-161, 800-63B, CSF, SSDF, AI 600-1) | framework | 224 | on the frameworks pages: NIST AI RMF, NIST AI 600-1, NIST Privacy Framework, NIST CSF 2.0 |
| ISO/IEC 42001 and ISO 27001 | framework | 53 | no | |
| OWASP (LLM, Agentic and ML Top 10s) | framework | 58 | on the frameworks pages: OWASP LLM Top 10, OWASP Agentic Top 10 | |
| MITRE ATLAS and ATT&CK, Agent Threat Rules, SOC 2, CISA | framework | 34 | no | |
| International bodies | IOSCO supervisory toolkit and final report on AI in capital markets | policy | 131 | no |
| Basel Committee | policy | 1 | no | |
| AI Act | law | 77 | yes, 28 provisions | |
| GDPR | law | 6 | yes, 7 provisions | |
| DORA | law | 2 | yes, 2 provisions | |
| MiFID II | law | 3 | not yet; by | |
| EBA guidelines | guidance | 2 | not yet; by | |
| FFIEC IT Examination Handbook | guidance | 66 | no | |
| OCC Bulletin 2026-13 | guidance | 2 | no | |
| GLBA | law | 3 | yes, 1 provision | |
| SEC Rule 17a-4 | law | 2 | not yet; by | |
| CCPA | law | 4 | yes, 5 provisions | |
| FCA Handbook (PRIN, PRIN 2A, SYSC, COBS, MIFIDPRU) and the Senior Managers regime | law | 27 | not yet; by | |
| FCA, PRA and Bank of England guidance and supervisory statements | guidance | 28 | not yet; by | |
| UK GDPR and Data Protection Act 2018 | law | 7 | yes, 7 provisions | |
| Equality Act 2010, Consumer Credit Act 1974 | law | 5 | not yet; by | |
| ICO guidance and risk toolkit | guidance | 12 | no | |
| National instruments (NI 31-103, 33-109, 81-102, 81-106, 81-107) | law | 26 | not yet; by | |
| CIRO rules | law | 10 | not yet; by | |
| CSA staff notices, Companion Policy 31-103CP, CIRO guidance and reports | guidance | 35 | no | |
| OSFI guidelines (E-23, B-10, B-13) and the AMF AI guideline | guidance | 18 | not yet; by | |
| PIPEDA, and Quebec's private-sector privacy act (P-39.1) | law | 10 | yes, 9 provisions | |
| Ontario Human Rights Code, Canadian Human Rights Act | law | 2 | no | |
| Other | 12 further sources, each cited a few times | · | 12 | · |
Two things follow from the table. The framework is already jurisdictional: past the European Union, it cites the Financial Conduct Authority's Handbook module by module and Canada's securities instruments section by section, which no general AI framework does. And the framework and the law library meet on general law and part ways on financial law: the law library holds the general laws the framework cites and, until the date in section 5, few of the financial rulebooks.
4Legal responsibilities a financial institution carries out through software
Some laws bind a bank, an insurer or a payment firm, and the firm carries them out through software it buys. The law library tags each requirement line by whose legal responsibility it is, and 73 lines in 25 instruments from 18 jurisdictions bind a regulated financial entity. A LexLint run says which side of that line its software is on. Software the financial entity runs takes the entity's lines, and those carried out through software, as its own. Software supplied to one reports the lines carried out through software as its customer's legal responsibilities, the supplier's own lines as its own, and the entity's other lines apart from both.
The three columns count lines by whose legal responsibility each is: the financial entity's own, the entity's but carried out through the software, and the supplier's own legal responsibility to the entity (the Digital Operational Resilience Act's contract terms for an ICT third-party provider are the clearest case). A run declares the sector in the declaration's regulated_sector field, described in the LexLint schema.
5What the law library will hold by
The law library is organized by subject (AI, privacy, cybersecurity, scraping, age assurance, news aggregation), and today financial law enters it only where it is also one of those. Its financial-services coverage will be complete by . Complete means that every item below is in the law library by that date, researched from its official text, dated and linked: the financial law and supervisory texts that the FINOS framework cites for the four jurisdictions it covers, and that the law library did not hold when this page was written.
| Jurisdiction | To be added | Kind |
|---|---|---|
| Consumer Credit Directive (EU) 2023/2225, Article 18: creditworthiness assessment, including automated processing and the right to human intervention | law | |
| AI Act, Annex III point 5(b): AI used to assess the creditworthiness of natural persons or establish their credit score, as its own row | law | |
| MiFID II: organizational requirements for algorithmic trading and investment firms' systems | law | |
| EBA Guidelines on loan origination and monitoring, on automated models in creditworthiness assessment | guidance | |
| Equal Credit Opportunity Act and Regulation B: adverse-action notices for decisions made with AI | law | |
| SEC Rule 17a-4 and the broker-dealer record rules; FINRA Rules 3110 and 2210, and Regulatory Notice 24-09 | law and guidance | |
| NYDFS Part 500 beyond section 500.17, and the 2024 industry letter on AI cybersecurity risks | law and guidance | |
| The interagency model risk management guidance (SR 11-7) as revised in April 2026 | guidance | |
| FCA Handbook: PRIN 2A (the Consumer Duty), SYSC and COBS 9 and 9A, as they bear on AI systems | law | |
| Consumer Credit Act 1974 and the Equality Act 2010, as they bear on automated credit decisions | law | |
| PRA Supervisory Statement SS1/23, model risk management principles for banks | guidance | |
| NI 31-103 (registrant obligations, including know your client and suitability) and the 81-series investment fund instruments | law | |
| CIRO rules on business conduct, supervision and recordkeeping | law | |
| OSFI Guidelines E-23 (model risk management), B-10 and B-13 | guidance |
Supervisory guidance will be shown beside the law it reads and, as everywhere in the law library, never counted as law and never raised in a run on its own. Payments law, and insurance law beyond the state statutes on AI in health insurance, are outside this commitment. Section 3's last column counts from the law library on every rebuild of this page, so each item shows there as it lands.
6The agentic items
The framework's items include 15 that address agents directly: agent authority, tool chains, Model Context Protocol servers, multi-agent trust and human approval of actions. They are where this framework and the subject of the AAIF page and the LexLint Legal Handbook meet. The laws column is the crosswalk's, for a mitigation; a risk has no laws of its own here, only through the mitigations that address it.
| Item | Kind | Obligation classes | Laws |
|---|---|---|---|
| AIR-PREV-018 Agent Authority Least Privilege Framework |
Mitigation | access restriction | 134 |
| AIR-PREV-019 Tool Chain Validation and Sanitization |
Mitigation | none | 0 |
| AIR-PREV-020 MCP Server Security Governance |
Mitigation | security | 154 |
| AIR-PREV-022 Multi-Agent Isolation and Segmentation |
Mitigation | none | 0 |
| AIR-PREV-023 Agentic System Credential Protection Framework |
Mitigation | access restriction | 134 |
| AIR-PREV-024 Human-in-the-Loop Action Approval Gate draft |
Mitigation | governance | 223 |
| AIR-PREV-025 Skill/Plugin Integrity and Governance draft |
Mitigation | none | 0 |
| AIR-DET-021 Agent Decision Audit and Explainability |
Mitigation | data subject rights, disclosure, governance, reporting, retention | 586 |
| AIR-SEC-024 Agent Action Authorization Bypass |
Risk | · | · |
| AIR-SEC-025 Tool Chain Manipulation and Injection |
Risk | · | · |
| AIR-SEC-026 MCP Server Supply Chain Compromise |
Risk | · | · |
| AIR-SEC-027 Agent State Persistence Poisoning |
Risk | · | · |
| AIR-OP-028 Multi-Agent Trust Boundary Violations |
Risk | · | · |
| AIR-SEC-029 Agent-Mediated Credential Discovery and Harvesting |
Risk | · | · |
| AIR-SEC-030 Skill/Plugin Supply Chain Compromise draft |
Risk | · | · |
7The files
- finos-crosswalk.csv: section 2 as a file, one row per mitigation, with its risks, the framework's references, and the law library's classes, laws and jurisdictions as counts.
- finos-sector-duties.csv: section 4 as a file, one row per instrument, with how many of its lines bind the entity, bind it through software, or bind its supplier.
Both files are cut from the same law library as this page, on the date in its byline, and are regenerated with it. They are licensed separately from the text and figures around them, under Creative Commons Attribution 4.0, the framework's own license, rather than the ShareAlike terms in the byline: use them for any purpose, including commercially, with credit to LexLint (UnGovr). The requirement lines behind section 4, with whose legal responsibility each is and why, are in My LexLint and the API.
8What this page does not claim
It does not say that any line binds any particular organization, and it does not say that running a mitigation satisfies a law: a row says a law bears on what the mitigation does, never more. Every law entry links to the source the law library researched it from. The commitment in section 5 is LexLint's, not FINOS's.
The framework's risk and mitigation titles are quoted from the FINOS AI Governance Framework (air-governance-framework.finos.org), copyright 2025 FINOS, licensed under Creative Commons Attribution 4.0, read at commit a149dd1e. FINOS has not reviewed or endorsed this page, and the reading of the framework against the law is LexLint's.