web analytics
AI Governance

SR 11-7 and the 2026 Model Risk Guidance

Superseded April 2026 by SR 26-2 and OCC 2026-13

The one-paragraph answer

SR 11-7 has been superseded. On April 17, 2026 the Federal Reserve, the OCC, and the FDIC issued revised interagency model risk management guidance: Federal Reserve SR 26-2 and OCC Bulletin 2026-13. It rescinds OCC Bulletin 2011-12, the OCC counterpart to SR 11-7, along with the Comptroller's Handbook Model Risk Management booklet. The core discipline survives, model inventory, independent validation, effective challenge, board oversight, but three things changed that matter for AI: the guidance now states explicitly that it is not enforceable and that noncompliance will not by itself draw supervisory criticism; it states primary relevance for banks above $30 billion in assets; and it narrows the definition of a model to complex quantitative methods, expressly excluding simple arithmetic and deterministic rule-based processes. The agencies have also signalled a forthcoming request for information specifically on banks' use of AI, including generative and agentic AI.

The pain SR 11-7 is causing our customers

Banks did not think SR 11-7 applied to AI. For a decade, model risk management meant credit-scoring models, capital-adequacy models, and stress-test models. Then the bank rolled out an AI tool for fraud detection, or an LLM assistant for customer service, or a machine-learning model for compliance monitoring. The chief risk officer got a call from the examiner. "What is the model inventory entry? Where is the validation? Who owns this?" And the bank realized the AI was, by regulatory definition, a model, and the model risk framework never captured it.

This is the pain SR 11-7 is causing right now. Regulators have been consistent since 2011 about what a model is: a quantitative method that processes input data into output for decision-making. Every AI system meets that definition. Every one. So the model inventory, the validation, the monitoring, and the governance obligations that SR 11-7 established for statistical models fifteen years ago now apply to AI. Most banks are still catching up.

What SR 11-7 actually is

SR 11-7 was Supervisory Letter 11-7, "Guidance on Model Risk Management," issued by the Federal Reserve Board on April 4, 2011. Its OCC counterpart was Bulletin 2011-12, "Sound Practices for Model Risk Management," issued the same day. (Note: earlier versions of this page cited OCC Bulletin 2013-29 as the counterpart. That was an error. 2013-29 is Third-Party Relationships risk management guidance, a different document.) The FDIC adopted the same framework in 2017, which made it the universal US banking standard for fifteen years.

On April 17, 2026 the three agencies replaced it. Federal Reserve SR 26-2 and OCC Bulletin 2026-13 issue revised interagency guidance and rescind the 2011 documents outright, along with OCC Bulletin 2021-19 (the BSA/AML model risk statement), OCC Bulletin 1997-24 (credit scoring models), and the Model Risk Management booklet of the Comptroller's Handbook.

The FDIC adopted the same framework in 2017. For fifteen years the three regulators spoke with one voice on model risk management, and examiners cited SR 11-7 across the entire regulated banking system. That is what changed in April 2026.

The framework is still technology-neutral, which is why AI remains in scope where an AI system meets the (now narrower) definition of a model. What changed is that scope is no longer automatic. Under the 2011 definition, the honest answer to "is our AI a model?" was almost always yes. Under the 2026 definition, it is a question with a real answer, and the answer has to be documented.

What changed in April 2026

Four changes matter, and two of them cut directly against the assumption that every AI system is automatically in scope.

The guidance says it is not enforceable

The revised text states explicitly that it is non-enforceable and that noncompliance will not, by itself, result in supervisory criticism. SR 11-7 contained no equivalent statement. This is a real shift in posture. It does not mean model risk is unsupervised: supervisory action can still follow from violations of law or from unsafe and unsound practices arising out of poor model risk management. But the guidance is now framed as principles rather than as an examination checklist.

A $30 billion relevance threshold

Primary relevance is stated for banking organisations above $30 billion in total assets, with possible relevance for smaller institutions carrying significant model risk exposure. The agencies are explicitly reining in the practice of applying large-bank model risk expectations to community institutions.

The definition of "model" narrowed

This is the change with the sharpest AI consequence. The revised guidance adds the qualifier complex to the definition of a model and expressly excludes simple arithmetic calculations and deterministic rule-based processes. Under the old SR 11-7 definition, essentially any quantitative method producing an estimate was a model, which is why the honest reading was that every AI system was in scope. That reading no longer holds automatically. A deterministic rules engine dressed as AI is not a model. A complex machine-learning model driving credit decisions plainly still is.

A clearer risk taxonomy

The revised guidance distinguishes inherent risk, exposure, and purpose and use, and links materiality to exposure and purpose rather than treating all models alike. It also states more clearly that using a model beyond its intended purpose introduces additional risk and may require additional controls, which is precisely the failure mode that AI tools invite.

The AI-specific guidance is still coming

The agencies stated that the OCC, the Federal Reserve Board, and the FDIC plan to issue a request for information addressing model risk management generally and, in particular, banks' use of AI, including generative AI, agentic AI, and AI-based models.

That is the sentence to watch. The 2026 guidance is deliberately technology-neutral and does not attempt to answer the AI-specific questions. The RFI is where the agencies will ask them, and the answers the industry gives will shape whatever comes next. Banks with material AI deployments should plan to respond rather than watch.

What SR 11-7 requires you to do

SR 11-7 is organized around three pillars: model development and use, model validation, and governance and controls. Here is what each pillar asks for.

Pillar 1: Model development, implementation, and use

Every model has to be built for a specific purpose, developed with documented data, and implemented with controls that check whether it is being used within its intended scope. Documentation must be thorough enough that an independent reviewer could reproduce the model's construction. For AI, this means training data documentation, feature engineering choices, hyperparameter selection rationale, and model-selection reasoning are all required.

Pillar 2: Model validation

Independent validation is the heart of SR 11-7. Every model must be validated by a party who did not develop it, before it is used in production. Validation covers three tests: conceptual soundness (does the theory make sense), ongoing monitoring (is it still working), and outcomes analysis (are actual results consistent with expected). For AI, validation includes bias testing, robustness testing, adversarial evaluation, and drift monitoring. The validator must have the authority, expertise, and independence to challenge the model developers.

Pillar 3: Governance, policies, and controls

Model risk management must be a written program with board oversight, senior management accountability, defined roles, model inventory, risk tiering, policies for approval and use, and change control. The model inventory is the specific artifact examiners ask for. It must list every model in use, its purpose, its risk tier, its owner, its validation status, its last review date, and its performance history.

Third-party model risk under SR 11-7

If a bank uses a model built by a vendor, the model risk framework still applies. This is the most common gotcha for AI. Buying an LLM from OpenAI, a fraud model from a fintech, or an AI decisioning platform from a large software vendor does not shift model risk management responsibility to the vendor. The bank remains accountable for the model's performance, controls, and governance. Vendor contracts must include information sharing, validation cooperation, incident notification, and audit rights. Vendor management under SR 11-7 is a full discipline of its own.

Why SR 11-7 matters to you

If you are a bank, SR 11-7 is not optional. Examiners will ask about your AI model inventory at the next exam. Missing model inventory entries lead to Matters Requiring Attention (MRA) or Matters Requiring Immediate Attention (MRIA) findings. Repeat findings escalate to consent orders. Getting ahead of this is significantly cheaper than responding to it.

If you are a bank vendor, SR 11-7 flows to you through contracts. Your bank customers are asking for validation cooperation, model documentation, and audit rights. Vendors who can produce this cleanly win procurement. Vendors who cannot get replaced.

If you are a non-bank fintech, insurance company, or credit-adjacent firm, SR 11-7 is becoming the reference framework by analogy. Insurance regulators (NAIC) and state financial regulators are increasingly asking for SR 11-7-style model governance even where the letter does not formally apply. It is spreading beyond banking.

What the research says about SR 11-7

The academic literature on SR 11-7 is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“ML can be less transparent and explainable than traditional regression models, which may raise unique questions about compliance”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“regulators demand these models to be transparent and auditable”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about SR 11-7 arrives from the board, the buyer, or the regulator.

How to get compliant with SR 11-7 and OCC 2013-29: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under SR 11-7. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities SR 11-7 reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation SR 11-7 expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, SR 11-7 becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about SR 11-7

Does the 2026 guidance apply to my community bank?

Primary relevance is stated for institutions above $30 billion in total assets. Smaller institutions with significant model risk exposure may still find it relevant, but the agencies were explicit that they are correcting the over-application of large-bank model risk expectations to community banks. If your prior model risk programme was built by copying a large-bank framework, this is the moment to right-size it.

What is the difference between this and the NIST AI RMF?

The banking guidance is sector-specific and focused on model risk. NIST AI RMF is horizontal, voluntary, and covers AI-specific risk categories the banking guidance does not address at all, including bias, explainability, and AI-specific security. Banks generally run the banking guidance as the primary framework and NIST AI RMF as the AI overlay. The 2026 revision, being explicitly non-enforceable and technology-neutral, makes the AI overlay more important, not less: it is now the place where the AI-specific questions actually get answered.

What counts as a "model" now?

Under the 2026 guidance, a complex quantitative method grounded in statistical, economic, or financial theory. Simple arithmetic calculations and deterministic rule-based processes are expressly excluded. This is narrower than the 2011 definition, under which arguably every AI system and every decisioning spreadsheet qualified. A complex ML model driving credit decisions is still a model. A deterministic rules engine with an AI label on the box is not.

How does SR 11-7 interact with ISO/IEC 42001?

ISO/IEC 42001 alignment supports SR 11-7 compliance but does not substitute for it. ISO/IEC 42001 gives you the AI management system structure; SR 11-7 gives you the specific model risk management practices banking examiners will check. Banks using AI should build both.

Where does SR 11-7 show up in SRJ's work?

Volume III of The Operating Discipline for AI Library™ includes an SR 11-7 crosswalk in Appendix L, mapping every SRJ artifact (Accountability Matrix, AI Vendor Risk Inventory™, dossiers, Board Reporting Package™) to specific SR 11-7 requirements. Banks pursuing the AI Business Enablement Audit™ get the SR 11-7 gap analysis included.

Primary sources on SR 11-7

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning SR 11-7 that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including SR 11-7 and the 2026 Model Risk Guidance, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation