Superseded April 2026 by SR 26-2 and OCC 2026-13
The one-paragraph answer
SR 11-7 has been superseded. On April 17, 2026 the Federal Reserve, the OCC, and the FDIC issued revised interagency model risk management guidance: Federal Reserve SR 26-2 and OCC Bulletin 2026-13. It rescinds OCC Bulletin 2011-12, the OCC counterpart to SR 11-7, along with the Comptroller's Handbook Model Risk Management booklet. The core discipline survives, model inventory, independent validation, effective challenge, board oversight, but three things changed that matter for AI: the guidance now states explicitly that it is not enforceable and that noncompliance will not by itself draw supervisory criticism; it states primary relevance for banks above $30 billion in assets; and it narrows the definition of a model to complex quantitative methods, expressly excluding simple arithmetic and deterministic rule-based processes. The agencies have also signalled a forthcoming request for information specifically on banks' use of AI, including generative and agentic AI.
Banks did not think SR 11-7 applied to AI. For a decade, model risk management meant credit-scoring models, capital-adequacy models, and stress-test models. Then the bank rolled out an AI tool for fraud detection, or an LLM assistant for customer service, or a machine-learning model for compliance monitoring. The chief risk officer got a call from the examiner. "What is the model inventory entry? Where is the validation? Who owns this?" And the bank realized the AI was, by regulatory definition, a model, and the model risk framework never captured it.
This is the pain SR 11-7 is causing right now. Regulators have been consistent since 2011 about what a model is: a quantitative method that processes input data into output for decision-making. Every AI system meets that definition. Every one. So the model inventory, the validation, the monitoring, and the governance obligations that SR 11-7 established for statistical models fifteen years ago now apply to AI. Most banks are still catching up.
SR 11-7 was Supervisory Letter 11-7, "Guidance on Model Risk Management," issued by the Federal Reserve Board on April 4, 2011. Its OCC counterpart was Bulletin 2011-12, "Sound Practices for Model Risk Management," issued the same day. (Note: earlier versions of this page cited OCC Bulletin 2013-29 as the counterpart. That was an error. 2013-29 is Third-Party Relationships risk management guidance, a different document.) The FDIC adopted the same framework in 2017, which made it the universal US banking standard for fifteen years.
On April 17, 2026 the three agencies replaced it. Federal Reserve SR 26-2 and OCC Bulletin 2026-13 issue revised interagency guidance and rescind the 2011 documents outright, along with OCC Bulletin 2021-19 (the BSA/AML model risk statement), OCC Bulletin 1997-24 (credit scoring models), and the Model Risk Management booklet of the Comptroller's Handbook.
The FDIC adopted the same framework in 2017. For fifteen years the three regulators spoke with one voice on model risk management, and examiners cited SR 11-7 across the entire regulated banking system. That is what changed in April 2026.
The framework is still technology-neutral, which is why AI remains in scope where an AI system meets the (now narrower) definition of a model. What changed is that scope is no longer automatic. Under the 2011 definition, the honest answer to "is our AI a model?" was almost always yes. Under the 2026 definition, it is a question with a real answer, and the answer has to be documented.
Four changes matter, and two of them cut directly against the assumption that every AI system is automatically in scope.
The revised text states explicitly that it is non-enforceable and that noncompliance will not, by itself, result in supervisory criticism. SR 11-7 contained no equivalent statement. This is a real shift in posture. It does not mean model risk is unsupervised: supervisory action can still follow from violations of law or from unsafe and unsound practices arising out of poor model risk management. But the guidance is now framed as principles rather than as an examination checklist.
Primary relevance is stated for banking organisations above $30 billion in total assets, with possible relevance for smaller institutions carrying significant model risk exposure. The agencies are explicitly reining in the practice of applying large-bank model risk expectations to community institutions.
This is the change with the sharpest AI consequence. The revised guidance adds the qualifier complex to the definition of a model and expressly excludes simple arithmetic calculations and deterministic rule-based processes. Under the old SR 11-7 definition, essentially any quantitative method producing an estimate was a model, which is why the honest reading was that every AI system was in scope. That reading no longer holds automatically. A deterministic rules engine dressed as AI is not a model. A complex machine-learning model driving credit decisions plainly still is.
The revised guidance distinguishes inherent risk, exposure, and purpose and use, and links materiality to exposure and purpose rather than treating all models alike. It also states more clearly that using a model beyond its intended purpose introduces additional risk and may require additional controls, which is precisely the failure mode that AI tools invite.
The agencies stated that the OCC, the Federal Reserve Board, and the FDIC plan to issue a request for information addressing model risk management generally and, in particular, banks' use of AI, including generative AI, agentic AI, and AI-based models.
That is the sentence to watch. The 2026 guidance is deliberately technology-neutral and does not attempt to answer the AI-specific questions. The RFI is where the agencies will ask them, and the answers the industry gives will shape whatever comes next. Banks with material AI deployments should plan to respond rather than watch.
SR 11-7 is organized around three pillars: model development and use, model validation, and governance and controls. Here is what each pillar asks for.
Every model has to be built for a specific purpose, developed with documented data, and implemented with controls that check whether it is being used within its intended scope. Documentation must be thorough enough that an independent reviewer could reproduce the model's construction. For AI, this means training data documentation, feature engineering choices, hyperparameter selection rationale, and model-selection reasoning are all required.
Independent validation is the heart of SR 11-7. Every model must be validated by a party who did not develop it, before it is used in production. Validation covers three tests: conceptual soundness (does the theory make sense), ongoing monitoring (is it still working), and outcomes analysis (are actual results consistent with expected). For AI, validation includes bias testing, robustness testing, adversarial evaluation, and drift monitoring. The validator must have the authority, expertise, and independence to challenge the model developers.
Model risk management must be a written program with board oversight, senior management accountability, defined roles, model inventory, risk tiering, policies for approval and use, and change control. The model inventory is the specific artifact examiners ask for. It must list every model in use, its purpose, its risk tier, its owner, its validation status, its last review date, and its performance history.
If a bank uses a model built by a vendor, the model risk framework still applies. This is the most common gotcha for AI. Buying an LLM from OpenAI, a fraud model from a fintech, or an AI decisioning platform from a large software vendor does not shift model risk management responsibility to the vendor. The bank remains accountable for the model's performance, controls, and governance. Vendor contracts must include information sharing, validation cooperation, incident notification, and audit rights. Vendor management under SR 11-7 is a full discipline of its own.
If you are a bank, SR 11-7 is not optional. Examiners will ask about your AI model inventory at the next exam. Missing model inventory entries lead to Matters Requiring Attention (MRA) or Matters Requiring Immediate Attention (MRIA) findings. Repeat findings escalate to consent orders. Getting ahead of this is significantly cheaper than responding to it.
If you are a bank vendor, SR 11-7 flows to you through contracts. Your bank customers are asking for validation cooperation, model documentation, and audit rights. Vendors who can produce this cleanly win procurement. Vendors who cannot get replaced.
If you are a non-bank fintech, insurance company, or credit-adjacent firm, SR 11-7 is becoming the reference framework by analogy. Insurance regulators (NAIC) and state financial regulators are increasingly asking for SR 11-7-style model governance even where the letter does not formally apply. It is spreading beyond banking.
The academic literature on SR 11-7 is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“ML can be less transparent and explainable than traditional regression models, which may raise unique questions about compliance”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“regulators demand these models to be transparent and auditable”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about SR 11-7 arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, SR 11-7 becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
Primary relevance is stated for institutions above $30 billion in total assets. Smaller institutions with significant model risk exposure may still find it relevant, but the agencies were explicit that they are correcting the over-application of large-bank model risk expectations to community banks. If your prior model risk programme was built by copying a large-bank framework, this is the moment to right-size it.
The banking guidance is sector-specific and focused on model risk. NIST AI RMF is horizontal, voluntary, and covers AI-specific risk categories the banking guidance does not address at all, including bias, explainability, and AI-specific security. Banks generally run the banking guidance as the primary framework and NIST AI RMF as the AI overlay. The 2026 revision, being explicitly non-enforceable and technology-neutral, makes the AI overlay more important, not less: it is now the place where the AI-specific questions actually get answered.
Under the 2026 guidance, a complex quantitative method grounded in statistical, economic, or financial theory. Simple arithmetic calculations and deterministic rule-based processes are expressly excluded. This is narrower than the 2011 definition, under which arguably every AI system and every decisioning spreadsheet qualified. A complex ML model driving credit decisions is still a model. A deterministic rules engine with an AI label on the box is not.
ISO/IEC 42001 alignment supports SR 11-7 compliance but does not substitute for it. ISO/IEC 42001 gives you the AI management system structure; SR 11-7 gives you the specific model risk management practices banking examiners will check. Banks using AI should build both.
Volume III of The Operating Discipline for AI Library™ includes an SR 11-7 crosswalk in Appendix L, mapping every SRJ artifact (Accountability Matrix, AI Vendor Risk Inventory™, dossiers, Board Reporting Package™) to specific SR 11-7 requirements. Banks pursuing the AI Business Enablement Audit™ get the SR 11-7 gap analysis included.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning SR 11-7 that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including SR 11-7 and the 2026 Model Risk Guidance, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →