AIUC-1
ResearchAIUC-1 & CRI
Aug 7, 20265 min read

CRI and AIUC-1 collaborate to strengthen AI security for financial institutions

CRI and AIUC-1 collaborate to strengthen AI security for financial institutions

AIUC-1 and the Cyber Risk Institute (CRI) are collaborating to strengthen the AI security ecosystem for financial institutions - supporting the adoption and deployment of trusted agentic AI while preparing organizations to meet new AI compliance obligations.

Financial institutions are among the most ambitious adopters of AI agents, in an industry with little tolerance for error. Regulators are already asking what agents institutions are using, what those agents are permitted to do, and how their adoption fits within existing obligations, including SOX, fair lending laws, and CFPB data-sharing rules.

Both AIUC-1 and CRI already work closely with financial institutions to guide safe, secure, and compliant AI adoption. In February 2026, CRI, in collaboration with the US Treasury, released the Financial Services AI Risk Management Framework (FS AI RMF) - the sector’s common reference point for AI risk governance. AIUC-1, developed by a consortium of 250+ members - several from the largest financial institutions in the Fortune 500 - offers a certification standard for AI agent security, safety, and reliability.

"Financial institutions are being asked hard questions about the AI agents they deploy,” said Josh Magri, CEO of CRI. “Pairing CRI's risk framework with AIUC-1's certification standard gives them a defensible answer combining high-level governance objectives with prescriptive, technical controls. That’s the answer we want to develop together with this relationship.”

Spotlighting leading AI security practices in a series of case studies

The collaboration will kick off with a crosswalk between the FS AI RMF and AIUC-1. The FS AI RMF provides risk, compliance, and audit teams 230 testable control objectives for AI governance. The crosswalk with AIUC-1 controls will further operationalize and extend the FS AI RMF for enterprise agentic risks, such as preventing unauthorized AI agent actions, and restricting unsafe tool calls. Institutions can move directly from AI governance objectives to certifiable controls, assuring how specific agents meet these objectives.

"Trust is the bottleneck for AI adoption in financial services, and no single organization can solve it alone,” said Rajiv Dattani, co-founder of the Artificial Intelligence Underwriting Company. “CRI brings the governance the sector already relies on, while AIUC-1 brings the technical certification to prove agents meet it. Together we give institutions one coherent path from risk framework to certified control, so they can adopt agentic AI with confidence."

CRI and AIUC-1 will also publish a series of case studies of financial services organizations utilizing the FS AI RMF and AIUC-1 to strengthen AI security - creating practical guidance for banks, credit unions, insurers, investment firms, and their third parties.

Both organizations invite their members to take part - contact Emil Lassen (AIUC-1) at emil@aiuc.com or Josh Magri (CRI) at josh.magri@cyberriskinstitute.org to hear more.

About the Cyber Risk Institute

CRI’s mission is to advance the development and harmonization of cybersecurity, technology, and AI risk management standards for the financial services industry, and reduce the fragmentation of cybersecurity and AI regulatory requirements. CRI connects threats to mitigating controls and associated compliance to provide institutions with a comprehensive view of risk.

With membership that spans more than 165 financial institutions and trade associations, CRI built the NIST CSF "Profile" for financial services - now the benchmark risk framework used across the sector - and has since extended it to cloud and AI. Most recently, CRI released the Financial Services AI Risk Management Framework (FS AI RMF) in February 2026, developed in collaboration with the US Treasury.

About AIUC-1

AIUC-1 is a certification standard for the security, safety, and reliability of AI agents. Developed by a consortium of 250+ members, including several of the largest financial institutions in the Fortune 500, AIUC-1 translates high-level AI governance objectives into testable, certifiable controls, such as preventing unauthorized agent actions, protecting sensitive data, and restricting unsafe tool calls.

The standard gives enterprises and their vendors a common bar for deploying agentic AI, and gives risk, compliance, and audit teams the evidence they need to trust specific agents - and demonstrate it to regulators.