The AI Governance Shift Financial Services Can’t Ignore

The Monetary Authority of Singapore (MAS) has long been regarded as one of the most forward-thinking and tech-literate financial regulators in the world. So, it was no surprise to see it launch the Safeguards for Agentic Finance at Runtime (SAFR) initiative in early July. Developed in coordination with industry practitioners under MAS’ BuildFin.ai working group, this framework helps financial services (FS) institutions govern agentic AI as it proliferates across the enterprise.
But the release of SAFR is not an isolated event. It is the latest in a steady wave of legal, regulatory, and mandatory guidance published over the past two years to keep pace with a technology that is being adopted faster than almost any before it. Similar efforts have emerged across nearly every region of the globe, from the EU AI Act in Europe to the NIST AI Risk Management Framework (AI RMF) in the United States, both aimed at ensuring the safe and secure use of AI.
What separates these initiatives is their degree of enforcement, which ranges from binding laws that carry legal obligations and penalties to voluntary frameworks. Voluntary, however, does not mean optional in practice. Frameworks developed alongside major institutions and endorsed by influential regulators have a way of becoming the de facto expectation that examiners, auditors, and business partners come to assume.
The Direction of Travel
FS institutions are adopting AI with enthusiasm. According to one global study, 81% of companies in the sector are using the technology at some level, while agentic AI is already being rolled out by more than half (52%). This adoption spans the full spectrum of AI use, from LLMs and predictive models embedded in business decisions such credit approvals and fraud detection through to the agentic systems now taking actions on a firm’s behalf.
As adoption has spread, so too has supervisory oversight. What began as isolated guidance is now effectively omnipresent, with authorities across every major jurisdiction turning their attention to AI. That leaves GRC teams to manage a growing patchwork of frameworks concurrently, reconciling the areas of overlap and divergence. Each carries its own language, evidence expectations, and cadence, and is usually assessed by a different team against a specific, logically separated boundary, such as business unit or product line. Yet this burden carries a hidden upside for those able to navigate it successfully. Accelerating compliance with new frameworks can open access to new markets, turning a defensive obligation into a competitive advantage.
Yet most teams are already stretched thin. We found that 72% of organizations increased their GRC team’s headcount or budget over the past year, and only 15% avoided delaying or eliminating any GRC activities due to resource constraints. Against that backdrop, every newly published framework lands as additional weight on a function that is already operating at capacity.
This is the position many cyber and GRC professionals now find themselves in, overwhelmed by the number of emerging frameworks and unsure how the standards they have spent years benchmarking against relate to the new ones arriving each quarter. What they need is a Rosetta Stone for compliance. A multi-framework mapping capability that translates the controls they already know into the language of every new framework, showing how far their existing maturity carries toward each new requirement and precisely where the gaps remain.
Why Point-in-Time Compliance Breaks Down
There is a deeper problem too. Existing compliance processes are often ill-suited to address the dynamic risks that AI introduces. Models drift as data changes. Agents make decisions on behalf of humans, operating across environments with new access paths and entitlement structures. These are new risks, and they move at machine speed.
The consequences of this shift are already surfacing. On July 21, 2026, OpenAI disclosed that during an internal test, its models broke out of an isolated research environment, exploited a previously unknown vulnerability, and used stolen credentials to reach a partner’s production database. The breach was caught by real-time detection and telemetry, not a scheduled review. It is a clear signal of why controls and guardrails must be enforced and monitored at machine speed, the same speed at which models and agents now make autonomous decisions. Static, periodic governance, using point-in-time screenshots and spreadsheets, is simply no longer fit for purpose. Moving forward, GRC must be facilitated through compliance as code, ensuring evidence is continuously gathered directly from the systems and agents that run the business. Control drift can then be detected and remediated at the moment it occurs.
Achieving this requires a technical foundation, built and maintained by a new discipline of GRC engineers, that rests on a handful of open standards working in concert. Three are worth understanding:
- OSCAL (the Open Security Controls Assessment Language, a NIST standard) expresses controls, mappings, and assessment results as structured, machine-readable data format.
- OCSF (the Open Cybersecurity Schema Framework) does the same for security telemetry and events, giving disparate tools a common language for what is happening in the environment.
- OPA (Open Policy Agent) evaluates rules as code, checking real-world state against policy and flagging when the two diverge.
Together, they transform compliance from a periodic, manual write-up into a living, automated system of record.
How the CRI Can Help
None of this has to be built from a blank page. In fact, much of the hardest work has already been done. Enter the Cyber Risk Institute (CRI), a coalition of financial institutions, trade associations, and technology partners who banded together to build a metadata-rich framework purpose-built for their industry. Rather than each firm reinventing the same control mappings in isolation, the sector pooled its expertise to address a shared challenge.
The result is the CRI Profile, a meta-framework that consolidates central guidelines into a single, common control set. It is built on an extended version of the NIST Cybersecurity Framework (CSF) and mapped against a comprehensive set of industry-specific regulations, standards, and guidance. It also offers example evidence packages, dynamic tiering based on sector impact, and mappings to threat scenarios from the MITRE ATT&CK framework. Crucially, the way its metadata is written makes it an ideal launchpad for automating compliance with OSCAL, so a program anchored on the CRI Profile is already positioned for the compliance-as-code foundation described above.
The coalition is now extending this model to AI directly. Released in February 2026, the CRI Financial Services AI Risk Management Framework (FS AI RMF) is the financial-services-specific implementation of the NIST AI RMF, mapped into and structured as part of the CRI framework. That means an institution can govern its AI risk using the same control language, mappings, and tooling it already uses for cybersecurity and technology risk, rather than standing up a separate, disconnected program for AI.
This is what makes the CRI Profile more than a convenient catalog. It is the natural backbone for the modern GRC program. Harmonized across banking regulations, OSCAL-ready, and now extended to AI through the FS AI RMF, CRI serves as the Rosetta Stone for financial institutions.
Making Compliance Simpler
This is exactly the approach RegScale is built around. We provide native support for the CRI Profile and soon the FS AI RMF, enabling the “comply-once, satisfy-many” control mapping that takes the pain out of overlapping frameworks. Combined with our OSCAL-native, compliance-as-code approach, the RegScale platform enables FS institutions to gain an edge in GRC, staying ahead of the inevitable audit demands rather than perpetually reacting to them.
The RegScale way is straightforward. FS Institutions anchor their program on the CRI Profile and assess each common control once, accelerated by AI capabilities native to the platform. RegScale can then map that implementation to every downstream framework they must comply with, so a control assessed once automatically satisfies every mapped control across the portfolio. The same model flexes to real-world enterprise structure, letting firms define audit boundaries that inherit shared enterprise controls while isolating the business-unit or product-specific controls that must be assessed independently. The result is a central and continuously updated source of truth, kept current by ongoing monitoring rather than left to decay between audits.
Your organization does not need a presence in Singapore to understand the significance of SAFR. Where MAS goes, other authorities tend to follow. The frameworks will keep coming, and the technology will keep changing. Building the foundation to address both today is a far better position than waiting for tomorrow.
Ready to get started?
Choose the path that is right for you!
Skip the line
My organization doesn’t have GRC tools yet and I am ready to start automating my compliance with continuous monitoring pipelines now.
Supercharge
My organization already has legacy compliance software, but I want to automate many of the manual processes that feed it.
