Regulatory & Framework Readiness

CRI AI RMF: Applying AI Risk Management Inside Connected GRC

Learn how CRI AI RMF works in Connected GRC by linking AI inventories, use cases, controls, evidence, privacy, cyber, vendors, issues, and executive oversight.
Category
Regulatory & Framework Readiness
Stage
Assess
Product Group
GRC & Resilience

AI governance is moving from policy discussion to operating discipline.

Organizations are no longer only asking whether AI is useful.

They are asking:

  • Which AI systems are in use?
  • Who owns them?
  • What data do they use?
  • Which vendors are involved?
  • Which business processes depend on them?
  • Which risks do they create?
  • Which controls reduce those risks?
  • Which evidence proves the controls operate?
  • Which issues remain open?
  • Which decisions need escalation?
  • Which AI use cases should be approved, restricted, monitored, or retired?

That is a different conversation.

AI risk management cannot remain a committee discussion, a spreadsheet inventory, or a policy document.

It needs workflow.

The Financial Services AI Risk Management Framework, developed by the Cyber Risk Institute, gives financial institutions a sector-specific framework for AI risk management. CRI says the FS AI RMF is aligned structurally with the NIST AI RMF, includes 230 Control Objectives, and helps organizations assess AI adoption stages, customize control objectives, and integrate AI risk outcomes into existing governance, risk, and compliance programs.  

That last point is important.

AI risk should not sit outside GRC.

AI risk touches cyber, privacy, third-party risk, model governance, compliance, legal, operational resilience, customer outcomes, vendor management, data governance, internal audit, board oversight, and enterprise risk.

That is why the CRI AI RMF belongs inside Connected GRC.

In a Connected GRC program, CRI AI RMF is not a standalone AI checklist. It is a connected workflow that links AI use cases, model inventories, adoption stages, control objectives, policies, risks, data, vendors, cyber exposure, privacy reviews, incidents, issues, evidence, monitoring, and executive reporting.

The goal is not to slow down responsible AI adoption.

The goal is to make AI adoption governed, traceable, and defensible.

What is CRI AI RMF in Connected GRC?

CRI AI RMF in Connected GRC is the process of applying CRI’s Financial Services AI Risk Management Framework through connected workflows that link AI inventories, use cases, adoption stages, control objectives, risk assessments, policies, controls, evidence, vendors, incidents, issues, monitoring, and executive oversight.

A connected CRI AI RMF program should help answer:

  • Which AI systems and use cases exist?
  • Which AI adoption stage applies?
  • Which control objectives are relevant?
  • Which business processes use AI?
  • Which data is used?
  • Is personal, sensitive, regulated, or confidential data involved?
  • Which vendors or third-party model providers are involved?
  • Which risks have been assessed?
  • Which controls are required?
  • Which evidence proves the controls operate?
  • Which AI use cases are approved, conditionally approved, restricted, or retired?
  • Which issues remain open?
  • Which incidents or performance concerns have occurred?
  • Which monitoring thresholds are defined?
  • Which AI risks require executive or board visibility?

A disconnected AI governance program can show that AI reviews are happening.

A connected CRI AI RMF program can show whether AI risk is being governed.

That is the difference.

Why AI risk management becomes disconnected

AI risk management becomes disconnected because AI touches many parts of the organization.

Technology teams may build or deploy AI systems.
Business teams may adopt AI tools.
Data teams may manage training, prompts, outputs, and data pipelines.
Cyber teams may review security exposure.
Privacy teams may review personal data use.
Legal teams may review obligations, contracts, intellectual property, and customer commitments.
Procurement may buy AI-enabled vendor tools.
Third-party risk may review AI vendors.
Compliance may interpret regulatory requirements.
Model risk teams may validate models.
Internal audit may ask for assurance.
Executives and boards may need oversight.

Each team has a legitimate role.

But when those roles are not connected, AI governance becomes fragmented.

Common symptoms include:

  • AI use cases tracked in spreadsheets
  • shadow AI use not tied to business owners
  • AI vendor reviews disconnected from third-party risk
  • privacy reviews disconnected from AI inventories
  • cyber reviews disconnected from AI risk assessments
  • model documentation stored separately from controls
  • policies not linked to AI approval workflows
  • issues tracked in email
  • monitoring results not linked to risk ratings
  • incidents not reflected in AI governance records
  • board reporting assembled manually
  • regulatory evidence reconstructed after the request arrives

The organization may have AI governance activity.

But activity is not the same as accountable AI risk management.

Connected GRC helps close that gap.

The CRI AI RMF Connected GRC map

AI governance depends on relationships.

CRI AI RMF recordShould connect to
AI use caseBusiness owner, purpose, process, data, model, vendor, risk tier
AI system / modelOwner, lifecycle stage, data, vendor, controls, monitoring, incidents
Adoption stageApplicable control objectives, maturity, scope, roadmap
Control objectivePolicy, control, evidence, owner, test, issue
Risk assessmentAI risk, impact, likelihood, controls, decision, remediation
Data recordData category, sensitivity, source, owner, privacy review, retention
Vendor / model providerContract, data use, cyber review, privacy review, issue, renewal
PolicyAI use rules, approval workflow, exceptions, attestation, training
ControlAI risk, evidence, test result, owner, issue
EvidenceAssessment, approval, monitoring, testing, vendor evidence, audit trail
IssueAI gap, owner, remediation, evidence, validation, escalation
IncidentAI system, data, output, vendor, root cause, remediation
DashboardCoverage, risk, monitoring, issues, evidence, decisions needed

This map turns CRI AI RMF from framework guidance into an operating workflow.

1. Start with an AI inventory

AI governance starts with visibility.

The organization needs to know what AI systems, tools, models, and use cases exist.

A connected AI inventory should include:

  • AI system or model name
  • use case
  • business purpose
  • business owner
  • technical owner
  • model owner
  • deployment status
  • lifecycle stage
  • internal or vendor-provided
  • vendor or model provider
  • business process supported
  • users or affected stakeholders
  • data used
  • personal or sensitive data involvement
  • decision impact
  • automation level
  • human oversight
  • risk tier
  • assessment status
  • approval status
  • monitoring status
  • issues
  • incidents
  • evidence

SmartSuite’s AI Governance page describes a centralized AI model inventory with owners, use cases, lifecycle stages, linked business processes, assessments, monitoring cycles, issues, controls, evidence, and dashboards.  

That inventory is the foundation.

If the organization does not know where AI is being used, it cannot govern AI risk.

The inventory should not be a static list.

It should be a living governance record.

2. Connect AI inventory to adoption stage

CRI’s FS AI RMF begins with an AI Adoption Stage Questionnaire, which helps determine the organization’s current adoption stage and map to relevant control objectives. The framework then uses a Risk & Control Matrix with risk statements and 230 Control Objectives organized by adoption stage.  

That stage-based approach matters because AI governance should be proportional.

An organization experimenting with low-risk internal AI tools does not need the same governance depth as an organization deploying AI in customer-impacting decisions, regulated workflows, critical operations, or high-volume automation.

A connected adoption-stage record should show:

  • current AI adoption stage
  • target adoption stage
  • applicable control objectives
  • business units in scope
  • AI systems in scope
  • risk profile
  • governance gaps
  • implementation roadmap
  • control owners
  • evidence requirements
  • issues and remediation

Adoption stage should not be only a maturity label.

It should drive which controls, assessments, evidence, monitoring, and approvals are required.

3. Connect CRI AI control objectives to controls

A control objective is not the same as an operating control.

The control objective describes what the organization needs to achieve.

The operating control describes how the organization does it.

A connected CRI AI RMF workflow should map each relevant control objective to:

  • control owner
  • control description
  • policy or standard
  • assessment requirement
  • evidence requirement
  • test procedure
  • monitoring metric
  • issue workflow
  • reviewer
  • approval criteria

For example:

AI governance objectivePossible operating control
AI use cases are inventoriedNew AI use cases must be registered before deployment
AI risks are assessedTier-based AI risk assessment required before approval
Data use is reviewedPrivacy and data review required for personal or sensitive data
Vendor AI is governedAI vendors must complete cyber, privacy, and contract review
Human oversight is definedHigh-impact use cases must document oversight roles
AI performance is monitoredMonitoring thresholds and review cadence are defined
Issues are remediatedAI issues require owners, due dates, evidence, and validation

CRI’s AI resources are intended to provide practical control objectives and implementation guidance, not replace existing enterprise policies. CRI states the FS AI RMF is complementary to existing risk frameworks and regulatory guidance, and is designed to facilitate harmonized implementation across jurisdictions.  

That is exactly how Connected GRC should use it.

Map CRI AI RMF to the common control framework.

Do not create a disconnected AI control silo.

4. Connect CRI AI RMF to the NIST AI RMF

The CRI FS AI RMF is structurally aligned with the NIST AI RMF. CRI built the framework to adapt AI risk-management concepts to the specific operational, regulatory, and consumer-protection considerations of financial services.  

NIST describes the AI RMF as a voluntary framework intended to improve organizations’ ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI systems.  

That means a Connected GRC program should treat CRI AI RMF and NIST AI RMF as related, not competing.

A connected framework record should show:

  • CRI AI RMF control objective
  • NIST AI RMF function, category, or subcategory
  • internal control
  • policy mapping
  • evidence requirement
  • reviewer
  • risk owner
  • issue status
  • maturity target

This helps organizations use CRI AI RMF for financial-sector specificity while maintaining alignment with the broader AI risk-management language used by NIST.

5. Connect CRI AI RMF to existing CRI Profile activity

CRI released additional AI implementation resources that map relevant FS AI RMF Control Objectives to CRI Profile Diagnostic Statements. CRI says these resources are designed to help CISOs and CTOs integrate AI risk management into existing cyber and technology risk programs instead of introducing duplicative or disconnected efforts.  

That point is central to Connected GRC.

AI governance should not create another parallel framework if existing CRI Profile controls, cybersecurity controls, risk assessments, and evidence workflows can support part of the AI risk-management model.

A connected mapping should answer:

  • Which FS AI RMF control objectives relate to existing CRI Profile statements?
  • Which existing cyber or technology controls can be extended?
  • Which controls are new?
  • Which evidence can be reused?
  • Which assessments need updating?
  • Which owners are already accountable?
  • Which issues should be tracked in the existing issue workflow?

This is how AI governance becomes practical.

Extend the current governance model where possible.

Add new controls only where the AI risk truly requires them.

6. Connect AI use cases to business process context

AI risk depends heavily on context.

The same model may carry different risk depending on how it is used.

For example:

  • AI used to summarize meeting notes is different from AI used to approve credit.
  • AI used for internal productivity is different from AI used for customer interaction.
  • AI used for anomaly detection is different from AI used to make employment decisions.
  • AI used with public data is different from AI used with sensitive customer data.
  • AI used as decision support is different from AI used for automated decisioning.

A connected AI use-case record should show:

  • business process
  • business owner
  • purpose
  • users
  • affected stakeholders
  • decision impact
  • automation level
  • data used
  • vendor involvement
  • regulatory relevance
  • risk tier
  • required reviews
  • approval decision
  • monitoring requirements
  • issues

This helps the governance team avoid both extremes:

  • over-governing low-risk use cases
  • under-governing high-impact use cases

AI risk management should be proportional to use-case context.

Connected GRC gives that context a place to live.

7. Connect AI to data governance and privacy risk

AI governance depends on data governance.

An AI use case may involve:

  • customer data
  • employee data
  • sensitive data
  • confidential business data
  • transaction data
  • behavioral data
  • biometric data
  • health data
  • financial data
  • prompts
  • outputs
  • embeddings
  • training data
  • retrieval data
  • vendor-managed data

A connected AI data review should answer:

  • What data is used?
  • Where does the data come from?
  • Who owns the data?
  • Is personal or sensitive data involved?
  • Is customer or employee data involved?
  • Is data used for training?
  • Are prompts or outputs retained?
  • Is a vendor or model provider involved?
  • Which retention rules apply?
  • Which privacy obligations apply?
  • Which controls protect the data?

A Connected GRC approach links CRI AI RMF to Privacy Risk Management, Enterprise Assets & Structure, and Policy Management.

This is especially important because AI privacy risk is often not obvious at the start.

A team may see an AI tool as productivity software.

The privacy team may see personal data, retention, disclosure, automated decisioning, and vendor-processing implications.

Connected GRC brings those views together.

8. Connect AI to cyber and technology risk

AI introduces cyber and technology risks.

Examples include:

  • prompt injection
  • data leakage
  • insecure plugins or integrations
  • model or API abuse
  • identity and access exposure
  • vulnerable AI infrastructure
  • vendor platform risk
  • shadow AI use
  • model output manipulation
  • insecure data pipelines
  • AI-assisted phishing or social engineering
  • model supply-chain risk
  • inadequate logging
  • monitoring gaps

CRI’s additional AI resources are specifically designed to help CISOs and CTOs identify where cybersecurity and IT teams have primary responsibility or meaningful contribution, and to map relevant FS AI RMF control objectives to existing CRI Profile statements.  

A Connected GRC approach links CRI AI RMF to:

  • Cyber Threat Management
  • Vulnerability Management (GRC)
  • Incident Management
  • Enterprise Assets & Structure
  • Control Framework & Regulatory Libraries

This helps answer:

  • Which AI systems are exposed to cyber threats?
  • Which AI infrastructure has vulnerabilities?
  • Which cyber controls apply?
  • Which vendor systems are involved?
  • Which incidents involved AI?
  • Which evidence supports the cyber review?
  • Which issues remain open?

AI governance should not sit apart from cyber risk.

If AI changes the attack surface, cyber risk needs to be connected.

9. Connect AI vendors to third-party risk

Many AI use cases involve third parties.

Examples include:

  • AI model providers
  • SaaS platforms with embedded AI
  • cloud AI services
  • analytics vendors
  • customer-support AI tools
  • HR AI tools
  • fraud detection vendors
  • marketing AI platforms
  • document automation vendors
  • AI agent platforms
  • model validation vendors
  • data enrichment providers

A connected AI vendor record should include:

  • vendor
  • AI functionality
  • data used
  • model provider
  • subprocessors
  • security review
  • privacy review
  • contract terms
  • data-use restrictions
  • training-data restrictions
  • retention terms
  • monitoring requirements
  • incident notification
  • audit rights
  • open issues
  • renewal impact

A Connected GRC approach links CRI AI RMF to Third Party Risk, Vendor Portal, and Contract Lifecycle Management.

This helps answer:

  • Which AI vendors are in use?
  • Which vendors process sensitive data?
  • Which vendors use data for model training?
  • Which vendors rely on other model providers?
  • Which contracts include AI terms?
  • Which vendor risks remain open?
  • Which renewals require updated AI review?

AI vendor risk should not be discovered after implementation.

It should be routed during intake, assessed before approval, monitored during use, and considered at renewal.

10. Connect AI governance to contracts

Contracts are a major AI risk control.

AI contract terms may address:

  • permitted AI use
  • prohibited data use
  • model training restrictions
  • data retention
  • confidentiality
  • ownership of outputs
  • intellectual property
  • human oversight
  • auditability
  • vendor transparency
  • subprocessors
  • incident notification
  • security requirements
  • privacy obligations
  • regulatory cooperation
  • change notification
  • model provider dependencies
  • termination and data return
  • liability and indemnity

A Connected GRC approach links CRI AI RMF to Contract Lifecycle Management.

That helps answer:

  • Which AI use cases require contract review?
  • Which vendors use customer or company data?
  • Which contracts restrict training use?
  • Which contract obligations require evidence?
  • Which contract exceptions create risk?
  • Which AI vendor issues affect renewal?
  • Which incidents trigger contractual obligations?

AI governance should not rely only on policy.

Contract terms are part of the control environment when vendors are involved.

11. Connect AI policies to operating controls

AI policies define expectations.

But policies alone do not govern AI.

A connected AI policy should link to:

  • AI use-case inventory
  • approval workflow
  • prohibited uses
  • acceptable uses
  • data-use rules
  • vendor requirements
  • human oversight requirements
  • monitoring requirements
  • incident reporting
  • exceptions
  • training
  • attestations
  • controls
  • evidence
  • issues

A Connected GRC approach links CRI AI RMF to Policy Management and Control Framework & Regulatory Libraries.

This helps answer:

  • Which policy governs this AI use case?
  • Which controls enforce the policy?
  • Which employees or vendors need attestation?
  • Which exceptions are approved?
  • Which issues show the policy is not being followed?
  • Which evidence proves policy operation?

An AI policy that is not connected to workflow becomes guidance.

An AI policy connected to intake, review, controls, evidence, issues, and monitoring becomes governance.

12. Connect AI assessments to approval decisions

AI risk assessments should produce decisions.

A connected AI assessment should include:

  • use case
  • business owner
  • model or system owner
  • data used
  • vendor involvement
  • risk tier
  • decision impact
  • affected stakeholders
  • privacy review
  • cyber review
  • legal review
  • compliance review
  • model performance review
  • human oversight
  • required controls
  • approval decision
  • approval conditions
  • monitoring requirements
  • issues
  • evidence

Possible decisions include:

  • approve
  • approve with conditions
  • require remediation before approval
  • require additional review
  • restrict use
  • reject use
  • pause use
  • retire use
  • accept residual risk with approval

The assessment should not be a form that disappears.

It should become the governance record for the AI use case.

That record should show why the decision was made and what conditions apply.

13. Connect AI controls to evidence

AI governance needs evidence.

Evidence may include:

  • AI inventory record
  • use-case assessment
  • adoption-stage questionnaire
  • risk assessment
  • model documentation
  • data review
  • privacy assessment
  • cyber review
  • vendor assessment
  • contract terms
  • human oversight documentation
  • testing results
  • monitoring reports
  • performance metrics
  • bias or fairness review
  • explainability documentation
  • incident records
  • issue remediation evidence
  • approval record
  • exception approval
  • board or committee reporting

CRI’s FS AI RMF includes companion documents such as a Guidebook and Control Objective Reference Guide that provide implementation detail, control examples, and effective evidence to support AI risk and governance practices.  

A connected evidence record should show:

  • control objective
  • AI use case or model
  • evidence owner
  • period covered
  • reviewer
  • acceptance status
  • issue link, if insufficient
  • audit or regulatory relevance

AI evidence should not be rebuilt when audit, regulators, executives, or customers ask for it.

It should be created as the AI governance workflow operates.

14. Connect AI issues to remediation and validation

AI governance will identify issues.

Examples include:

  • incomplete AI inventory
  • missing business owner
  • missing data review
  • privacy assessment overdue
  • vendor review incomplete
  • contract language insufficient
  • unapproved AI use
  • high-risk use case lacking oversight
  • monitoring threshold undefined
  • model drift detected
  • bias or performance concern
  • security review incomplete
  • incident involving AI output
  • unsupported approval decision
  • insufficient evidence
  • policy exception not approved

A Connected GRC approach links CRI AI RMF to Issues Management.

Each AI issue should include:

  • AI use case or model
  • control objective
  • affected risk
  • owner
  • severity
  • root cause
  • remediation plan
  • due date
  • evidence required
  • validation method
  • escalation status
  • residual risk decision

SmartSuite’s AI Governance page describes integrated issue registers connecting AI issues to models, risks, controls, corrective actions, evidence, verification workflows, and executive dashboards.  

AI issues should not remain comments in an assessment.

They should become governed remediation records.

15. Connect AI to ongoing monitoring

AI risk changes over time.

A model may drift.
Data may change.
A vendor may update a model.
A business process may expand usage.
A use case may become customer-facing.
An AI tool may add new features.
Regulatory expectations may change.
Performance may degrade.
New incidents may occur.
Risk appetite may change.

A connected monitoring workflow should include:

  • monitoring owner
  • metric or signal
  • threshold
  • review cadence
  • alert rule
  • evidence
  • reviewer
  • issue trigger
  • reassessment trigger
  • escalation path
  • retirement or suspension criteria

Monitoring may include:

  • performance
  • drift
  • accuracy
  • bias or fairness
  • security alerts
  • data-quality issues
  • user complaints
  • incident signals
  • vendor change notices
  • output review
  • human override rates
  • exception trends

AI approval is not the end.

Ongoing monitoring is where AI governance becomes sustainable.

16. Connect AI incidents to the governance model

AI incidents can take many forms.

Examples include:

  • incorrect AI output used in a decision
  • unauthorized AI tool use
  • sensitive data entered into an AI system
  • AI vendor incident
  • prompt injection
  • model performance failure
  • biased or unfair output
  • automated decision issue
  • AI hallucination affecting customer communication
  • AI-generated phishing
  • data leakage
  • human oversight failure
  • policy violation
  • monitoring threshold breach

A Connected GRC approach links CRI AI RMF to Incident Management, Privacy Risk Management, and Cyber Threat Management.

An AI incident should show:

  • AI system or use case
  • business owner
  • data involved
  • vendor involved
  • control failure
  • policy violation
  • affected stakeholders
  • root cause
  • evidence
  • remediation issue
  • monitoring change
  • reassessment decision
  • reporting requirement

AI incidents should not be treated as one-off exceptions.

They should update the AI governance record.

If the same type of incident repeats, the risk rating, controls, monitoring, policy, or approval decision should change.

17. Connect AI risk to operational resilience

AI can affect operational resilience when it supports critical processes, customer-facing services, fraud detection, security monitoring, decision support, data processing, operational workflows, or crisis response.

A Connected GRC approach links CRI AI RMF to Operational Resilience, Business Impact Analysis, and Enterprise Assets & Structure.

That helps answer:

  • Which critical services use AI?
  • Which processes depend on AI outputs?
  • Which AI vendors support critical services?
  • What happens if the AI system fails?
  • Is there a manual workaround?
  • Are recovery expectations defined?
  • Has the failure scenario been tested?
  • Which issues remain open?

AI resilience is not only model performance.

It is also dependency management.

If a critical service depends on an AI system, the AI system belongs in the service map.

18. Connect AI governance to enterprise risk and board reporting

AI risk can become enterprise risk.

AI may affect:

  • customer trust
  • regulatory exposure
  • cyber risk
  • privacy risk
  • third-party risk
  • operational resilience
  • financial crime
  • fair treatment
  • model performance
  • legal exposure
  • reputational risk
  • strategic execution
  • board oversight

Treasury’s 2026 release on financial-sector AI resources notes that inconsistent terminology and uneven risk-management practices can create governance and oversight challenges, and that the FS AI RMF provides tools to evaluate AI use cases, manage risks across the AI lifecycle, and embed accountability, transparency, and resilience into AI deployment decisions.  

A Connected GRC approach links CRI AI RMF to Enterprise Risk Management and GRC Dashboards.

Executive reporting should show:

  • AI inventory coverage
  • high-risk AI use cases
  • AI use cases involving sensitive data
  • AI vendors
  • approval status
  • open issues
  • incidents
  • monitoring exceptions
  • residual risk
  • decisions needed

The board does not need every model detail.

It needs a clear view of AI posture, material risk, exceptions, incidents, and decisions.

19. Connect CRI AI RMF to internal audit and assurance

Internal audit can provide assurance over AI governance.

Audit may review:

  • AI inventory completeness
  • policy adherence
  • use-case approval process
  • risk assessment quality
  • control design and operation
  • vendor AI governance
  • privacy and cyber review
  • monitoring evidence
  • issue remediation
  • incident handling
  • executive reporting
  • board oversight

A Connected GRC approach links CRI AI RMF to Internal Audit Management, Compliance Assessments & Testing, and Evidence Management.

That helps audit teams answer:

  • Which AI systems are in scope?
  • Which controls apply?
  • Which evidence exists?
  • Which issues remain open?
  • Which approvals were conditional?
  • Which monitoring exceptions occurred?
  • Which risks need assurance coverage?

AI assurance should not begin by rebuilding the AI inventory.

The inventory, controls, evidence, issues, and decisions should already be connected.

20. Build CRI AI RMF dashboards that show AI governance posture

AI dashboards should not show only the number of models.

They should show governance coverage, risk, evidence, monitoring, issues, and decisions.

Useful CRI AI RMF dashboard views include:

Dashboard viewWhy it matters
AI use cases by risk tierShows prioritization
AI systems by adoption stageShows maturity and rollout scope
AI use cases by business unitShows where AI is used
AI systems lacking ownersShows accountability gaps
AI systems involving sensitive dataShows privacy exposure
AI vendors by risk tierShows third-party exposure
Assessments overdueShows governance backlog
Control objectives without evidenceShows readiness gaps
Open AI issuesShows remediation needs
AI incidentsShows realized risk
Monitoring exceptionsShows emerging risk
Conditional approvalsShows open commitments
AI use cases requiring privacy reviewShows data-risk work
AI use cases requiring cyber reviewShows security work
Executive decisions neededShows where leadership must act

The dashboard should answer:

  • What AI is in use?
  • Which AI matters most?
  • Which AI has not been reviewed?
  • Which AI uses sensitive data?
  • Which vendors create exposure?
  • Which controls lack evidence?
  • Which issues are overdue?
  • Which monitoring signals require action?
  • Which decisions need escalation?

That is AI governance reporting in Connected GRC.

How Connected GRC changes the CRI AI RMF conversation

A disconnected AI governance conversation sounds like this:

“We have an AI policy, an AI inventory, and a review process. Teams submit use cases for assessment, and governance reviews are being tracked.”

A connected CRI AI RMF conversation sounds like this:

“We have 42 AI use cases in inventory. Seven are high risk, five involve sensitive customer data, and four depend on third-party model providers. Three FS AI RMF control objectives lack accepted evidence. Two vendor AI reviews are overdue. One monitoring exception created an issue, and a high-impact use case requires executive approval before deployment.”

The second conversation is more useful.

It connects AI use cases, risk tier, data, vendors, control objectives, evidence, monitoring, issues, and decisions.

That is what CRI AI RMF should do in Connected GRC.

Where to start applying CRI AI RMF inside Connected GRC

Organizations do not need to implement every AI governance workflow at once.

Start where visibility and risk are weakest.

Start with the AI inventory if use is unclear

Create a centralized inventory of AI use cases, owners, business processes, data, vendors, lifecycle status, and approval status.

Relevant links:

  • AI Governance
  • CRI AI RMF
  • Enterprise Assets & Structure
  • Privacy Risk Management

Start with adoption stage if governance maturity is unclear

Use the AI adoption stage concept to identify applicable control objectives and maturity gaps.

Relevant links:

  • CRI AI RMF
  • Enterprise Risk Management
  • GRC Dashboards
  • Evidence Management in GRC

Start with control mapping if AI governance is disconnected

Map FS AI RMF control objectives to internal controls, policies, evidence, issues, and existing CRI Profile or cyber controls.

Relevant links:

  • Control Framework & Regulatory Libraries
  • CRI Compliance
  • Compliance Assessments & Testing
  • Policy Management

Start with privacy and data if sensitive information is involved

Connect AI use cases to data categories, processing activities, retention, privacy assessments, and vendor data use.

Relevant links:

  • Privacy Risk Management
  • Enterprise Assets & Structure
  • Contract Lifecycle Management
  • Regulatory Change Management

Start with vendors if AI tools are third-party provided

Connect AI vendors to contracts, cyber reviews, privacy reviews, data use, model providers, incidents, issues, and renewals.

Relevant links:

  • Third Party Risk Management
  • Vendor Portal
  • Contract Lifecycle Management
  • Cyber & IT Risk

Start with monitoring if AI use is already deployed

Define monitoring metrics, thresholds, review cadence, issue triggers, and escalation rules.

Relevant links:

  • AI Governance
  • Issues Management
  • Incident Management
  • GRC Dashboards

The best starting point is where AI use is already moving faster than governance visibility.

Common CRI AI RMF mistakes to avoid

Mistake 1: Treating AI governance as an inventory only

An inventory is necessary, but not enough.

AI governance needs assessments, controls, evidence, monitoring, issues, and decisions.

Mistake 2: Creating a separate AI control silo

Use CRI AI RMF to extend existing GRC controls where possible.

Do not duplicate cyber, privacy, vendor, policy, or issue workflows unnecessarily.

Mistake 3: Approving AI use cases without evidence

AI approvals should be supported by assessment evidence, review decisions, controls, and conditions.

Mistake 4: Ignoring vendor AI risk

Many AI systems are vendor-provided or vendor-enabled.

Vendor data use, model providers, contracts, privacy, security, and incident obligations matter.

Mistake 5: Treating AI risk as only a technology issue

AI risk also involves legal, privacy, compliance, operations, customer impact, resilience, third parties, ethics, and board oversight.

Mistake 6: Skipping monitoring after approval

AI risk changes over time.

Approved use cases need ongoing monitoring and reassessment triggers.

Mistake 7: Reporting AI activity instead of AI posture

Dashboards should show governance coverage, high-risk use cases, open issues, evidence gaps, incidents, monitoring exceptions, and decisions needed.

A practical test for your CRI AI RMF workflow

Pick one AI use case.

Then ask whether your current GRC model can quickly show:

  • business owner
  • technical owner
  • model or system owner
  • business process supported
  • adoption stage
  • risk tier
  • data used
  • sensitive data involvement
  • vendor or model provider
  • contract terms
  • privacy review
  • cyber review
  • legal or compliance review
  • relevant FS AI RMF control objectives
  • mapped controls
  • evidence submitted
  • approval decision
  • approval conditions
  • monitoring metrics
  • open issues
  • remediation owners
  • incident history
  • residual risk
  • executive decisions needed

If answering those questions requires spreadsheets, AI intake forms, vendor files, privacy assessments, cyber reviews, contracts, policy documents, evidence folders, and meetings, the CRI AI RMF workflow is not connected enough.

That is common.

It is also the opportunity.

Final thought

CRI AI RMF should not become another AI governance checklist.

It should become a connected operating workflow.

That means linking AI use cases to owners, owners to assessments, assessments to control objectives, control objectives to controls, controls to evidence, evidence to review decisions, vendors to contracts, data to privacy reviews, systems to cyber risk, incidents to issues, issues to remediation, monitoring to escalation, and reporting to executive decisions.

Connected GRC gives CRI AI RMF that structure.

It helps AI teams innovate responsibly.

It helps risk and compliance teams apply control discipline.

It helps privacy and cyber teams review the right use cases earlier.

It helps vendor managers govern AI providers.

It helps internal audit and regulators find evidence.

It helps executives understand AI posture and material risk.

That is the practical value of CRI AI RMF inside Connected GRC.

It applies AI risk management through connected controls, evidence, accountability, and decisions.

Table of Contents
Related Product Areas

Linked Articles

GRC & Resilience
AI Governance: Connecting Model Risk, Policy, Controls, Evidence, and Accountability

Learn how AI Governance works in Connected GRC by linking AI inventories, model risk, policies, data, vendors, controls, evidence, issues, monitoring, and accountability.

Read Article
arrow_forward
GRC & Resilience
NIST AI RMF vs ISO 42001 vs CRI AI RMF: What AI Governance Teams Need to Know

Compare NIST AI RMF, ISO/IEC 42001, and CRI AI RMF, and learn how Connected GRC turns AI frameworks into inventories, controls, evidence, issues, monitoring, and dashboards.

Read Article
arrow_forward
GRC & Resilience
ISO/IEC 42001 and Connected AI Governance: Building an AI Management System That Works

Learn how ISO/IEC 42001 works inside Connected GRC by linking AI policy, inventory, risk, controls, vendors, evidence, monitoring, audit, and continual improvement.

Read Article
arrow_forward
GRC & Resilience
EU AI Act Readiness in Connected GRC: Inventory, Risk, Controls, Evidence, and Monitoring

Learn how to prepare for EU AI Act readiness in Connected GRC by linking AI inventories, risk classification, obligations, controls, evidence, vendors, monitoring, issues, and dashboards.

Read Article
arrow_forward
GRC & Resilience
How to Build an AI Use Case Intake Workflow

Learn how to build an AI use case intake workflow that captures owners, data, vendors, risk tiers, reviews, controls, evidence, approvals, monitoring, and issues.

Read Article
arrow_forward
GRC & Resilience
How to Classify AI Use Cases by Risk Tier

Learn how to classify AI use cases by risk tier using data sensitivity, decision impact, vendor exposure, human oversight, monitoring, controls, and evidence.

Read Article
arrow_forward
GRC & Resilience
AI Governance Evidence: What to Collect Before Approval and After Deployment

Learn what AI governance evidence to collect before approval and after deployment, including intake, data, vendor, risk, controls, monitoring, issues, and approvals.

Read Article
arrow_forward
GRC & Resilience
How to Monitor AI Systems After Approval

Learn how to monitor AI systems after approval by tracking performance, drift, bias, human oversight, vendor changes, incidents, issues, evidence, and reassessment.

Read Article
arrow_forward
GRC & Resilience
AI Vendor Risk Management: How to Govern Third-Party AI Tools

Learn how to govern third-party AI tools by connecting vendors, model providers, data, contracts, cyber reviews, privacy reviews, evidence, monitoring, issues, and dashboards.

Read Article
arrow_forward
GRC & Resilience
How to Connect AI Governance to Privacy and Cyber Reviews

Learn how to connect AI governance to privacy and cyber reviews by linking AI use cases, data, systems, vendors, controls, evidence, issues, and monitoring.

Read Article
arrow_forward
GRC & Resilience
Privacy Risk Management: Connecting Data, Obligations, Incidents, and Controls

Learn how privacy risk management works in Connected GRC by linking data inventories, obligations, DPIAs, incidents, controls, vendors, AI, issues, and evidence.

Read Article
arrow_forward
GRC & Resilience
Third-Party Risk Management: Connecting Vendors to Controls, Issues, and Resilience

Learn how third-party risk management works in Connected GRC by linking vendors, due diligence, contracts, controls, cyber, privacy, resilience, issues, evidence, and monitoring.

Read Article
arrow_forward
GRC & Resilience
Cyber Threat Management: Connecting Security Risk to Enterprise Risk

Learn how Cyber Threat Management works in Connected GRC by linking threats, assets, vulnerabilities, controls, incidents, issues, vendors, resilience, and enterprise risk.

Read Article
arrow_forward
GRC & Resilience
Evidence Management in GRC: Building an Audit-Ready Evidence Trail

Learn how evidence management works in Connected GRC by linking evidence to controls, obligations, tests, audits, issues, remediation, owners, periods, and approvals.

Read Article
arrow_forward
GRC & Resilience
Issue Remediation and Validation: How to Prove the Fix Worked

Learn how issue remediation and validation work in Connected GRC by linking findings, root cause, owners, remediation plans, evidence, retesting, validation, and risk reduction.

Read Article
arrow_forward

Frequently Asked Questions

Answers to common questions about SmartSuite’s pricing models, plan options, and onboarding programs.

What is CRI AI RMF in Connected GRC?

CRI AI RMF in Connected GRC is the process of applying CRI’s Financial Services AI Risk Management Framework through connected workflows that link AI inventories, use cases, adoption stages, control objectives, risk assessments, policies, controls, evidence, vendors, incidents, issues, monitoring, and executive oversight.

What is the Financial Services AI Risk Management Framework?

The Financial Services AI Risk Management Framework, or FS AI RMF, is an industry-led, sector-specific AI risk management framework developed by CRI through public-private collaboration. CRI says it is structurally aligned with the NIST AI RMF and includes 230 Control Objectives for financial-services AI governance.

How does CRI AI RMF connect to NIST AI RMF?

CRI’s FS AI RMF is structurally aligned with the NIST AI RMF but adapted for financial-services operational, regulatory, and consumer-protection considerations. The NIST AI RMF is a voluntary framework intended to help organizations manage AI risks and incorporate trustworthiness into AI systems.

Why does CRI AI RMF need Connected GRC?

CRI AI RMF needs Connected GRC because AI risk crosses inventories, policies, controls, evidence, privacy, cyber, vendors, contracts, incidents, issues, monitoring, audit, compliance, and executive oversight. Connected GRC keeps those records linked.

What should an AI governance record connect to?

An AI governance record should connect to the AI use case, business owner, model owner, data used, vendor, contract, privacy review, cyber review, risk assessment, control objectives, controls, evidence, approval decision, monitoring, incidents, issues, and remediation.

How does CRI AI RMF connect to CRI Compliance?

CRI released resources that map selected FS AI RMF Control Objectives to CRI Profile Diagnostic Statements, helping organizations integrate AI risk into existing cybersecurity and technology risk programs instead of creating disconnected work.

How should AI issues be managed?

AI issues should be managed as structured remediation records with the AI use case or model, affected control objective, affected risk, owner, severity, root cause, remediation plan, due date, evidence requirement, validation method, and escalation status.

What should a CRI AI RMF dashboard include?

A CRI AI RMF dashboard should include AI use cases by risk tier, adoption stage, business unit, data sensitivity, vendor involvement, assessment status, control objectives without evidence, open issues, incidents, monitoring exceptions, conditional approvals, and executive decisions needed.

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.