What changed in 2026?
SR 11-7, formally titled “Guidance on Model Risk Management,” was Federal Reserve supervisory guidance issued on April 4, 2011, alongside OCC Bulletin 2011-12. On April 17, 2026, the Federal Reserve, OCC, and FDIC replaced that baseline with revised interagency guidance. The Federal Reserve identifies it as SR 26-2; OCC Bulletin 2026-13 rescinded OCC Bulletin 2011-12 and several related issuances.
Regulatory definition of a model
SR 11-7 defines a model with three components:
“The term ’model’ refers to a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates.”
A model consists of three components: (1) an information input component, (2) an estimation component that transforms inputs into estimates, and (3) a reporting component that translates estimates into useful business information.
The 2026 definition is narrower than that formulation. It covers a complex quantitative method, system, or approach applying statistical, economic, or financial theories to produce quantitative estimates. It excludes simple arithmetic and deterministic rule-based processes, and it expressly excludes generative and agentic AI. Non-generative, non-agentic AI can be in scope when it meets the definition.
Applicability
Historically, SR 11-7 was directed to Federal Reserve-supervised institutions, including:
- Bank holding companies (BHCs)
- Savings and loan holding companies (SLHCs)
- State member banks
- Foreign banking organizations (US operations)
Historically, OCC Bulletin 2011-12 carried the 2011 guidance to national banks and federal savings associations. OCC Bulletin 2026-13 rescinded that bulletin when the agencies issued the replacement guidance.
Why the 2011 baseline still matters, and where it stops
When SR 11-7 was issued in 2011, banks primarily deployed traditional statistical models: credit scorecards, loss forecasting models, stress testing frameworks. The guidance focused on validating linear assumptions, parameter stability, and economic theory.
By 2025, the model landscape has fundamentally changed. Banks now deploy:
- Fraud detection ML models that analyze transaction patterns in real-time
- Large language models for customer service, compliance monitoring, and document generation
- Neural networks for credit underwriting, trading algorithms, and anti-money laundering (AML)
- Third-party AI APIs where the bank has no visibility into training data or model architecture
The current 2026 guidance states the actual boundary: its principles apply to traditional statistical and quantitative models and non-generative, non-agentic AI models that meet the definition. Generative and agentic AI are not within its scope. Their exclusion is not an exemption from risk management; the guidance directs banks to use other appropriate governance and control practices for systems it does not cover.
The AI validation challenge
Traditional model validation relies on three pillars: conceptual soundness review, ongoing performance monitoring, and outcomes analysis. These work well for transparent models with documented assumptions.
AI introduces fundamental challenges:
Traditional models vs. AI systems
| Dimension | Traditional Models | AI/ML Systems |
|---|---|---|
| Explainability | Coefficients interpretable; economic theory clear | Black-box; feature interactions opaque |
| Stability | Parameters fixed unless manually updated | Continuous learning; drift over time |
| Training Data | Documented, version-controlled | Often proprietary; internet-scale corpora |
| Validation | Hold-out testing; sensitivity analysis | Adversarial testing; bias metrics; hallucination rates |
| Vendor Models | Source code review possible | API access only; no code visibility |
For a non-generative, non-agentic AI model that falls within the current definition, the revised guidance retains effective challenge: critical analysis by objective experts with appropriate expertise, sufficient independence, and enough standing to effect change. That statement should not be extended to say SR 26-2 governs generative or agentic AI, which the guidance expressly excludes.
Risk-based practices in the current guidance
The 2011 guidance organized model risk management around development and implementation, validation, and use. The 2026 guidance retains development and use, validation and monitoring, governance and controls, and vendor products, but expressly makes the approach risk-based and tailored.
1. Model Development, Implementation, and Use
The guidance describes sound development practices whose rigor should reflect the model’s complexity, use, and materiality:
Design and Construction
Development starts with a clear purpose and considers conceptual design, inputs, assumptions, methodology, intended use, and limitations. The depth of documentation and analysis should match the model’s risk.
Testing Prior to Implementation
Testing evaluates whether a model performs as intended. The current guidance gives examples such as out-of-sample or out-of-time testing, comparing assumptions or methodologies, and assessing data quality, relevance, and inputs.
Implementation and Integration
A model should be used with a clear understanding of its limitations and intended purpose. Extending use beyond the original application warrants analysis of the new use and a review of relevant controls.
Ongoing Monitoring
Ongoing monitoring evaluates whether performance remains consistent with expectations as products, exposures, activities, clients, data relevance, or market conditions change. Its frequency and scope depend on model nature, new data or methods, and materiality.
2. Model Validation
Validation remains a core component for models within the current guidance’s scope. The 2011 guidance described validation as:
The revised guidance describes validation as evaluating expected performance, reliability, and limitations. Its components include conceptual soundness, outcomes analysis, and ongoing monitoring, tailored to the model’s approach, use, and materiality.
Validation quality turns on rigor and effectiveness. The current guidance emphasizes appropriate expertise, objectivity, sufficient independence, and organizational influence; it does not prescribe one reporting structure.
3. Governance, Policies, and Controls
Model-risk governance benefits from clear policies, roles, responsibilities, accountability, and escalation. The current guidance leaves the exact structure to the institution’s size, complexity, and risk profile; the 2011 framework emphasized:
- Board oversight: understanding the nature and extent of model risk exposure
- Senior management accountability: establishing the MRM framework and ensuring compliance
- Policies and procedures: documented standards for model development, validation, and use
- Model inventory: comprehensive catalog of all models in use
- Contingency plans: procedures for model failure or performance degradation
Model validation and effective challenge
The current guidance retains effective challenge: critical analysis by objective experts with appropriate expertise, sufficient independence, and enough organizational standing to effect change.
Three components of validation
Conceptual Soundness
Assess whether the model design is appropriate for its intended purpose. Review the theoretical basis, modeling assumptions, mathematical structure, choice of inputs, and development evidence appropriate to the model.
Ongoing Monitoring
Evaluate whether the model continues to perform as expected as its data and operating conditions change. Establish risk-based triggers for overlays, adjustment, recalibration, redevelopment, or constraints on use.
Outcomes Analysis
Compare model outputs with corresponding real-world outcomes using methods suited to the objective, methodology, and available data, such as back-testing or outlier analysis.
Independence requirements
The 2011 guidance emphasized validation independent of development. The current guidance focuses on technical expertise, objective challenge, sufficient independence, and effectiveness rather than requiring one fixed reporting structure.
Institutions may use different structures to create objective challenge. Examples include:
- Internal validation team: a separate unit within the bank that reports independently of business lines
- Third-party validators: external consultants or specialized firms providing validation services
- Hybrid approach: internal teams validate most models; external experts validate the most complex or material models
What matters under the revised guidance is the rigor and effectiveness of the review, supported by technical knowledge, objectivity, sufficient independence, and enough influence to effect appropriate change.
Validation frequency
The current guidance does not mandate a universal validation interval. Timing, nature, and frequency vary with purpose, methodology, materiality, model changes, data limitations, and practical constraints. Relevant factors include:
- Materiality of model’s business impact
- Model complexity and uncertainty
- Changes in market conditions or business environment
- Observed performance degradation
There is no universal calendar in the revised guidance. Each institution should document a risk-based validation and monitoring schedule, then revisit it when model purpose, methodology, data, performance, use, or materiality changes.
Model inventory and documentation
The current guidance describes a model inventory as common industry practice that can support risk management at individual and aggregate levels. Inventory depth can vary with model complexity, materiality, and the organization’s model usage.
Inventory requirements
A risk-based inventory can capture systems meeting the current model definition regardless of an internal product label. Useful fields may include:
Model inventory data elements
| Element | Description |
|---|---|
| Model Name / ID | Unique identifier and descriptive name |
| Business Purpose | Intended use; business decisions supported |
| Model Type | Algorithm/methodology (e.g., neural network, LLM, regression) |
| Risk Tier | Classification (high/medium/low) based on materiality |
| Owner | Business unit and individual responsible for model use |
| Developer | Internal team or third-party vendor |
| Validation Status | Date of last validation; next validation due |
| Documentation | Links to model documentation, validation reports, approvals |
Documentation standards
The current guidance says adequate documentation supports continuity, tracking of recommendations and exceptions, and remediation. The depth should fit the model’s risk and use. Useful documentation can include:
- Model development documentation: detailed description of model theory, assumptions, data sources, variable selection, and mathematical specifications
- Testing and performance results: evidence of pre-implementation testing, sensitivity analysis, benchmarking, and limitations analysis
- Validation reports: independent assessment of conceptual soundness, performance monitoring results, and outcomes analysis findings
- Ongoing monitoring documentation: performance tracking metrics, exception reports, and evidence of corrective actions
- Change logs: version control records documenting model modifications, recalibrations, and updates
For AI systems, documentation should additionally address training data provenance, feature engineering decisions, hyperparameter tuning, and explainability analysis.
Three lines of defense
Many institutions implemented the 2011 baseline through a three-lines model. That remains an organizational option, not a structure mandated by the 2026 guidance:
First line: model developers and owners
In one common arrangement, business units and development teams own model use, document purpose and assumptions, conduct development testing, and monitor performance under the institution’s policies.
Second line: independent model validation
A validation function can provide objective assessment and effective challenge by examining conceptual soundness, outcomes analysis, monitoring, limitations, and appropriate use.
Third line: internal audit
Where internal audit forms part of the model-risk program, the revised guidance says its role is generally to evaluate whether practices are rigorous and effective and whether policies are implemented, rather than duplicate development or validation.
This is an illustrative governance pattern, not a 2026 mandate. An institution should choose roles and reporting lines that manage conflicts and produce credible, objective challenge for the risks involved.
Governance and oversight
The current guidance calls for policies, controls, and clearly assigned roles and responsibilities that fit the institution’s model-risk profile and operating complexity. Governance should address conflicts and give objective challenge enough standing to effect change.
Board responsibilities
The board is responsible for:
- Approving model risk appetite: establishing tolerance for model-related losses and performance degradation
- Ensuring adequate resources: allocating budget and staff for validation, monitoring, and governance functions
- Receiving regular reporting: understanding model inventory, validation findings, incidents, and risk trends
- Approving MRM policies: reviewing and approving the model risk management framework
Senior management responsibilities
Senior management is tasked with implementing the board’s directives:
- Establishing MRM framework: developing policies, standards, and procedures for model development, validation, and use
- Building validation capability: hiring qualified validators; providing training and tools
- Maintaining model inventory: ensuring all models are identified, cataloged, and risk-tiered
- Remediating issues: tracking validation findings and ensuring timely corrective action
Model risk committee
Many banks establish a Model Risk Management Committee to oversee governance. The committee typically includes:
- Chief Risk Officer (chair)
- Head of Model Validation
- Business unit representatives
- Chief Data Officer or Chief Analytics Officer
- Compliance and internal audit, where relevant
The committee reviews model inventory, approves high-risk models for production, tracks validation findings, and escalates material issues to the board risk committee.
AI-specific considerations
For non-generative, non-agentic AI that meets the current definition, model characteristics can create validation challenges that warrant a tailored approach. Generative and agentic AI require analysis under other applicable governance and risk-management frameworks.
1. Explainability and Interpretability
Traditional models use interpretable coefficients. Neural networks and large language models operate as black boxes where decision paths are opaque. Validators must assess:
- Can the model provide explanations for individual predictions?
- Are explanations accurate reflections of model logic?
- Can business users understand the model’s purpose, output, and limitations?
Techniques like SHAP values, LIME, and attention visualization help but don’t fully solve the explainability gap for complex models.
2. Model Drift and Continuous Learning
Traditional models remain static until manually recalibrated. AI models can drift as data distributions change. Continuous learning systems go further, updating their parameters automatically without any human intervention.
Validators must monitor:
- Data drift: has the distribution of input features changed?
- Concept drift: have relationships between inputs and outputs shifted?
- Performance degradation: are relevant performance measures changing over time?
Banks should establish automated drift detection with thresholds that trigger model review or recalibration when exceeded.
3. Bias and Fairness
AI models trained on historical data can perpetuate or amplify societal biases. For credit underwriting, hiring, or fraud detection models, biased outcomes create regulatory, reputational, and legal risk.
For an in-scope model, a tailored validation plan can include:
- Disparate impact testing: do model predictions differ systematically across protected classes?
- Fairness metrics: assess demographic parity, equalized odds, or predictive parity
- Decision impact: identify applicable legal and policy obligations for the actual use, including adverse-action requirements where relevant
4. Third-Party and Vendor Models
Banks increasingly rely on third-party AI providers such as OpenAI APIs, fraud detection SaaS platforms, and credit scoring vendors. These models present validation challenges:
Vendor Model Challenge
For an in-scope vendor model, proprietary code or data does not remove the need for appropriate validation and oversight. The current guidance calls for understanding vendor-model design, data and performance to the extent needed for risk-based validation; it does not bring every software or AI system into scope.
Acceptable validation approaches for vendor models include:
- Benchmarking vendor model outputs against alternative models or expert judgment
- Outcomes analysis comparing vendor predictions to actual results
- Sensitivity testing using edge cases and adversarial inputs
- Relevant third-party validation evidence provided by the vendor
5. Hallucinations and Output Reliability
Large language models produce plausible but factually incorrect outputs, known as “hallucinations.” For use cases like regulatory compliance, customer communications, or loan documentation, hallucinations create material risk.
Validators should assess:
- Hallucination rates across different prompt types
- Controls to detect and prevent hallucinated outputs from reaching customers
- Human-review workflows appropriate to consequential outputs
Practical review questions
The revised guidance does not publish a universal deficiency checklist. The following questions translate its current development, validation, monitoring, governance, inventory, documentation, and vendor-product principles into a practical internal review.
Incomplete Model Inventory
Does the inventory contain enough information about in-scope models under development or in use to support risk management at both individual and aggregate levels?
Insufficient Validation Documentation
Does the validation record demonstrate a rigorous assessment of reliability, limitations, conceptual soundness, outcomes, and monitoring appropriate to the model?
Weak Ongoing Monitoring
Does monitoring evaluate whether performance remains consistent with expectations as use, data, clients, products, exposures, activities, or market conditions change?
Inadequate Third-Party Model Oversight
For an in-scope vendor model, has the institution developed enough understanding of design, data, performance, conceptual soundness, and limitations to validate and monitor it?
Lack of Independence
Do reviewers have the expertise, objectivity, sufficient independence, and organizational influence needed to conduct effective challenge and effect change?
Failure to Remediate Findings
Are limitations, recommendations, responses, exceptions, overlays, adjustments, recalibration, redevelopment, and other corrective actions documented and followed through?
What the guidance does and does not do
SR 26-2 says it does not establish enforceable standards or prescriptive requirements, and non-compliance with the guidance alone will not result in supervisory criticism. Its footnote separately states that supervisory action may result from violations of law or unsafe or unsound practices stemming from insufficient management of model risk. Those are different claims and should not be collapsed into a generic statement that the guidance itself carries fines.
Implementation roadmap
Building risk-based model governance for in-scope AI models requires a phased approach aligned to the institution’s risk profile, the model’s materiality, and the current guidance.
Illustrative risk-based implementation sequence
Phase 1: Define scope and inventory
Apply the current definition and scope boundary first. Record which systems are in scope, which are excluded, and which other risk frameworks govern excluded generative, agentic, deterministic, or non-model systems.
Deliverable: Documented scope decision and risk-based inventory
Phase 2: Assign governance and accountability
Define roles, policies, conflicts, escalation, exceptions, and accountability in a structure proportionate to the institution and its model risk. A three-lines model is optional, not prescribed.
Deliverable: Approved roles, policies, and escalation path
Phase 3: Establish effective challenge
Match expertise, objectivity, independence, methodology, and organizational influence to each in-scope model’s approach, use, materiality, and limitations.
Deliverable: Documented validation approach and accountable reviewers
Phase 4: Implement monitoring and evidence
Choose monitoring that reflects model nature, data availability, materiality, and use. Preserve validation, monitoring, limitation, exception, and remediation evidence; where Glacis covers an action, signed records can show what configured controls reported.
Deliverable: Risk-based monitoring plan and scoped evidence
Phase 5: Prioritize validation and remediation
Sequence work by inherent risk, exposure, purpose, use, and materiality. Track limitations, exceptions, corrective actions, and decisions to adjust, overlay, recalibrate, redevelop, constrain, or retire a model.
Deliverable: Risk-ranked work plan and owned remediation record
Phase 6: Reassess as risk changes
Revisit scope, purpose, use, data, methodology, materiality, performance, dependencies, and controls when conditions change. Set cadence through policy rather than assuming a universal annual cycle.
Deliverable: Current decisions and evidence proportionate to risk
Critical boundary: An operational record can help show what a configured control reported for a covered action. It does not determine SR 26-2 scope, validate a model, prove control effectiveness, or establish compliance or examiner acceptance.
Resource requirements
The revised guidance does not prescribe a staffing ratio. Resourcing should reflect the institution’s size and complexity, the prevalence and complexity of its models, model materiality, internal expertise, and any use of outside resources. At minimum, make ownership explicit for model development and use, objective validation and monitoring, governance and remediation, and internal audit where it forms part of the program. External work still requires institutional oversight and integration into the broader model-risk process.
Frequently asked questions
Who is the 2026 guidance for?
SR 26-2 is the current revised interagency guidance. OCC Bulletin 2026-13 rescinded OCC Bulletin 2011-12. The guidance is expected to be most relevant to banking organizations over $30 billion in assets, while also identifying circumstances in which it may be relevant to smaller organizations with significant model-risk exposure. Vendors are not made subject to it merely because they sell AI, although a bank may require evidence needed for its own oversight.
How do I validate a vendor AI model when they won’t share source code?
For an in-scope vendor model, proprietary code or data does not remove the need for validation. The current guidance points to developing an understanding of conceptual soundness, design, development data, and performance, then using ongoing monitoring and outcomes analysis to assess continuing fitness and reliability. The exact evidence and testing should be tailored to risk and access.
What happens if we do not follow SR 26-2?
The current guidance says it does not create enforceable standards or prescriptive requirements and that non-compliance with the guidance alone will not result in supervisory criticism. Supervisory action can still arise from a violation of law or from unsafe or unsound practices associated with inadequate model-risk management.
Can model developers also perform validation?
The current guidance focuses on the rigor and effectiveness of validation, appropriate expertise, objectivity, sufficient independence, and the ability to effect change. It does not prescribe one organizational chart. An institution should structure development, validation, monitoring, and audit roles to manage conflicts and deliver credible challenge for the model’s risk.
How often must AI models be revalidated?
The current guidance does not prescribe a universal calendar. Timing, nature, and frequency depend on model purpose, methodology, materiality, changes, data limitations, performance, and practical constraints. Ongoing monitoring and revalidation should follow the institution’s risk-based policy and the model’s actual use.
References
- Board of Governors of the Federal Reserve System. “Supervisory Guidance on Model Risk Management” (SR 26-2). April 17, 2026.
- Office of the Comptroller of the Currency. “OCC Bulletin 2026-13: Model Risk Management: Revised Guidance.” April 17, 2026.
- Board of Governors of the Federal Reserve System. “SR 11-7: Guidance on Model Risk Management” (historical PDF). April 4, 2011.