AI Compliance

SR 26-2 Model Risk Management: What Changed for Bank AI

SR 26-2 replaced SR 11-7 in April 2026. What changed, which banks are in scope, and why generative and agentic AI were deliberately left outside it.

Cover image for an article about the SR 26-2 revised model risk management guidance and what it means for banks using AI
In this article
  1. What SR 26-2 is and what it replaced
  2. Who SR 26-2 model risk management guidance actually covers
  3. What changed from SR 11-7, section by section
  4. The footnote that matters most: generative and agentic AI are out of scope
  5. What the narrower definition of "model" does to your inventory
  6. The BSA/AML gap nobody is talking about
  7. A governance framework for the AI systems SR 26-2 leaves to you
  8. What banks under $30 billion should do now
  9. What examiners are likely to ask
  10. What to watch next
  11. Where this leaves you
  12. Frequently asked questions
  13. Sources

SR 26-2 model risk management guidance replaced SR 11-7 on April 17, 2026, and if your bank is using AI, the most important thing in it is a footnote. The revised interagency guidance is shorter, more principles-based, and aimed squarely at banking organizations holding more than $30 billion in total assets. It narrows the definition of a "model," drops most of the prescriptive machinery from 2011, and states plainly that it creates no enforceable standards. Then, in footnote 3, it removes generative AI and agentic AI from its scope entirely.

That leaves banks in an unusual position. The systems getting the most board attention are the ones the new guidance declines to cover, and the AI-specific request for information the agencies promised had still not appeared as of late September 2026.

This article walks through what changed, counts how many banks the new threshold actually reaches, explains what the AI carve-out does and does not mean, and gives you a governance framework for the AI systems that now sit outside model risk management. It is a practitioner's summary, not legal advice; confirm any scope decision with your compliance team and counsel.

What SR 26-2 is and what it replaced

SR 26-2 is the Federal Reserve supervisory letter that transmits the revised interagency Supervisory Guidance on Model Risk Management, dated April 17, 2026. The same document was issued by the OCC as Bulletin 2026-13 and by the FDIC as FIL-15-2026. One text, three agencies.

It is a clearance event as much as a publication. The letter supersedes SR 11-7, Guidance on Model Risk Management (April 4, 2011), and SR 21-8, the Interagency Statement on Model Risk Management for Bank Systems Supporting Bank Secrecy Act/Anti-Money Laundering Compliance (April 9, 2021). The OCC simultaneously rescinded Bulletin 2011-12, Bulletin 2021-19, Bulletin 1997-24 on credit scoring models, and the Model Risk Management booklet of the Comptroller's Handbook. The FDIC rescinded FIL-22-2017 and FIL-27-2021.

The framing is deregulatory. The agencies say the revision reflects "supervisory experience and industry feedback accumulated over the past fifteen years, as well as significant advancements in modeling practices," and that the aim is "a risk-based approach to model risk management that is tailored to a banking organization's model risk profile and the size and complexity of its operations."

The most consequential sentence for anyone who has lived through a model risk exam sits in the introduction: "This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization." A footnote immediately qualifies it: "supervisory action may result for any violations of law or unsafe or unsound practices stemming from insufficient management of model risk."

Key takeaway: SR 26-2 lowers the floor on documentation, not the floor on safety and soundness. You can retire paperwork. You cannot retire the underlying risk.

Who SR 26-2 model risk management guidance actually covers

The applicability line reads: "This letter is expected to be most relevant to banking organizations with over $30 billion in total assets regulated by the Federal Reserve." The attached guidance explains the reasoning: models at organizations of $30 billion or less "typically are subject to internal risk management and governance practices appropriate for the size and risk profile of these banking organizations, and generally excluding them from this guidance is consistent with a tailored supervisory approach."

There is a carve-back. The guidance "also may be relevant to banking organizations with total assets of $30 billion or less that have significant exposure to model risk because of the prevalence and complexity of their models or because of activities outside the scope of traditional community banking."

To see how much this narrows things, we counted. The Federal Reserve's Large Commercial Banks release, with data as of March 31, 2026, ranks 3,798 U.S. domestically chartered commercial banks by consolidated assets. Sixty-six of them hold $30 billion or more. Eight hundred ninety-five hold $1 billion or more, which is the threshold the FDIC used when it adopted the 2011 guidance in FIL-22-2017: that letter said the guidance was not expected to pertain to institutions under $1 billion in total assets unless their model use was significant, complex, or posed elevated risk.

Bar chart comparing the number of US commercial banks above the one billion dollar and thirty billion dollar asset thresholds against the full list of 3,798 banks
Counted from the Federal Reserve's Large Commercial Banks release, data as of March 31, 2026. The list covers bank charters, so organization-level counts differ.

So the population the guidance points at shrank from roughly 895 banks to roughly 66, with about 829 banks sitting between the two thresholds. Those 66 banks still hold about 82 percent of the $24.9 trillion on that list, so the change reaches almost all of the system's assets and almost none of its institutions.

Two caveats on those numbers. The Fed's list ranks commercial bank charters, not holding companies or thrifts, so an organization-level count will differ. And "generally excluded" is not "exempt." Examiners at a $4 billion bank running a heavy analytics stack can still ask how its models are governed.

What changed from SR 11-7, section by section

The 2011 guidance was a detailed manual. The 2026 guidance is a set of principles. The differences worth mapping are mostly the sentences that quietly disappeared.

Area SR 11-7 (2011) SR 26-2 (2026)
Stated audience Adopted by the FDIC for institutions with $1 billion or more in assets "Expected to be most relevant" above $30 billion
Legal status Widely examined against as if binding States it sets no enforceable standards and that non-compliance alone brings no criticism
Definition of a model Quantitative method applying statistical, economic, financial or mathematical theories Adds "complex"; drops mathematical; excludes spreadsheet arithmetic and deterministic rules
Validation cadence Commonly read as requiring annual validation No cadence stated; timing varies with purpose, methodology and change frequency
Validation independence Detailed expectations on structure, incentives and reporting lines Quality "depends on the rigor and effectiveness of the review rather than on organizational structure"
Board and management duties Enumerated responsibilities and approvals Principles: clear roles, defined accountability, effective policies
Internal audit Enumerated tasks Evaluates whether model risk management practices are rigorous and effective, and generally does not duplicate them
Model inventory Expected Described as "common industry practice"
Vendor models Covered within the text Given its own section, acknowledging that code, data and methodology may not be available
BSA/AML systems Addressed by the separate SR 21-8 statement SR 21-8 rescinded, no standalone replacement
Generative and agentic AI Did not exist in 2011 Explicitly outside scope

Analyses of the revision from Sullivan & Cromwell, Orrick and Davis Polk reach the same conclusion from different angles: the substance of sound model risk management survives, but the checklist that grew up around it does not.

Three ideas in the new text are worth internalizing, because they shape how you will argue your position in an exam.

Materiality became the organizing concept

The guidance says "Model purpose, together with model exposure, determines model materiality," and that models a bank deems immaterial may warrant only identification and monitoring of the conditions under which they could become material. That is an invitation to tier your inventory honestly and spend effort where the exposure is, rather than applying one procedure to everything.

Effective challenge is defined by capability, not org chart

Effective challenge is performed by people with "the appropriate expertise," "sufficient independence to maintain objectivity," and "the organizational standing and influence to effect any change." A small bank without a separate validation department can still meet that description. A large bank with one can still fail it.

Validation timing became a judgment call

The guidance says validation "generally occurs prior to a model's first use," then allows for an urgent business need, provided the bank pays closer attention to the model's limitations, informs relevant stakeholders, and applies compensating controls such as usage limits or closer monitoring. Write that trade-off into your policy before you need it.

The footnote that matters most: generative and agentic AI are out of scope

Footnote 3 of the guidance is short and load-bearing:

"Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document."

The footnote closes by confirming that the guidance's principles "apply to traditional statistical and quantitative models and non-generative, non-agentic AI models." Read together, it is doing four things at once.

  1. Generative AI is out. A retrieval assistant over your policy manuals, a document summarizer, a drafting tool in loan operations: none of these are governed by SR 26-2.
  2. Agentic AI is out. Systems that plan and take actions across your applications are also outside it. If you are considering that class of system, our guide to how long it takes to build an AI agent covers the control work that tends to dominate the schedule.
  3. Conventional machine learning is in. A gradient-boosted credit scorecard, a deposit attrition model, a fraud classifier: non-generative, non-agentic AI models are explicitly covered by the principles.
  4. The obligation does not vanish. The footnote hands the decision back to you, and says your own risk management and governance practices should guide it.

Use the questions below to sort a given system quickly.

Decision tree with three questions determining whether a system is a model under SR 26-2, is excluded as generative or agentic AI, or falls below the thirty billion dollar threshold
Three questions drawn from the text of the revised guidance. The result tells you which governance track a system belongs in, not whether it is safe.

The OCC set out its own view of the risk in the Spring 2026 Semiannual Risk Perspective, published May 7, 2026. It reports that banks are "taking a measured approach to the adoption of generative AI (genAI) and agentic AI, with usage generally limited to specific use cases with guardrails and human-in-the-loop accountability," that observed use cases are "primarily productivity and customer experience enhancement tools," and that the unique challenges include "lack of explainability, data privacy and data poisoning issues, cybersecurity threats, and validation challenges where industry approaches are evolving."

Key takeaway: The carve-out is a statement about which document applies, not a statement that the risk is acceptable. A supervisor who finds an ungoverned generative AI system influencing customer outcomes will not be reassured that SR 26-2 does not cover it.

What the narrower definition of "model" does to your inventory

The revised definition is deliberately tighter. A model is "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates." It excludes "simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use."

Two edits did the work. Adding "complex" raises the bar. Dropping "mathematical" from the list of theories removes the hook that pulled a great deal of ordinary calculation into scope.

For most inventories, three groups now come out:

  • Spreadsheet arithmetic. A workbook that totals exposures is not a model. A workbook implementing a prepayment curve still is, because the theory sits underneath it.
  • Deterministic rule engines. A rule that fires on a fixed threshold is not applying a statistical or economic theory. A rules engine whose thresholds were calibrated from a statistical estimate is a different matter.
  • Plain software. Systems that move, format or reconcile data are IT assets, not models.

Do not delete those entries. Move them. An end-user computing register, a change-management process and a named operational risk owner are still the right controls for a spreadsheet that prices a portfolio, even when it is not a model. Reclassification that quietly removes oversight is the failure mode supervisors will look for first.

The same logic runs in reverse for AI. A generative AI system is out of scope of SR 26-2, but it does not become ungoverned; it moves to a different register with a different control set. That is the subject of the next two sections.

The BSA/AML gap nobody is talking about

SR 21-8 was rescinded alongside SR 11-7, and the agencies did not issue a standalone replacement for it. That statement had done useful work: it gave banks room to reason about whether BSA/AML transaction monitoring systems were models, to avoid duplicative testing across model validation and independent testing, and to update detection scenarios quickly.

Those clarifications now have to be rebuilt inside your own policy, from the general principles in SR 26-2 and your existing BSA program. Three practical consequences:

  • Classification is yours to defend. A scenario-based monitoring rule set with fixed thresholds looks a lot like the deterministic rule-based processes the new definition excludes. A segmentation or risk-scoring engine built from statistical estimates does not. Write down which of your AML components are models and why, at the time you decide.
  • Testing overlap needs an explicit rule. Independent testing of the BSA program and validation of a model are different exercises with different objectives. Say in your policy how evidence is shared between them, so neither team duplicates the other's work by default.
  • Tuning cadence needs a stated standard. Without SR 21-8's flexibility language, your policy should define what size of change to a detection scenario triggers what level of review.

None of this changes the underlying Bank Secrecy Act program obligations, which live in FinCEN's rules rather than in supervisory guidance. What changed is the supervisory commentary about how model risk management interacts with them.

A governance framework for the AI systems SR 26-2 leaves to you

This is the part the guidance hands back to each bank, so here is a concrete framework. It is built from the structure of the revised guidance, the four functions of the NIST AI Risk Management Framework (govern, map, measure, manage), which NIST published as AI RMF 1.0 in January 2023 for voluntary use, and the Generative AI Profile NIST released as AI 600-1 in July 2024.

Twelve controls, in the order we would build them:

  1. Inventory every AI system, including embedded ones. The hardest entries to find are AI features switched on inside software you already bought. Ask each vendor in writing.
  2. Name one accountable owner per system. Not a committee. A person who can stop it.
  3. Classify by decision influence, not by technology. Three tiers work: informs an employee, drafts something a human approves, or affects a customer outcome directly. Controls scale with tier, mirroring the materiality logic in SR 26-2.
  4. Write down the permitted data. Which systems of record the tool may read, which customer data classes are prohibited, and whether outputs may leave your tenant. Our comparison of private LLM deployments and ChatGPT Enterprise covers how much of this is a procurement decision rather than an engineering one. Regulated firms outside banking face the same exercise under a different rulebook; our HIPAA-compliant AI development checklist shows what that permitted-data list looks like when the data is protected health information.
  5. Define the human checkpoint precisely. "Human in the loop" means nothing unless you can say what the human sees, what they are accountable for, and how often they override.
  6. Build an evaluation set before launch. A few hundred real cases with agreed correct answers. Without it you cannot answer the first question any reviewer asks: how do you know it works?
  7. Set thresholds and a rollback path. What accuracy or complaint rate triggers withdrawal, who decides, and how fast the system can be switched off.
  8. Log enough to reconstruct any output. Input or prompt, retrieved context, model and version, output, the action taken and who approved it. This is the control most often missing and the hardest to add later.
  9. Monitor for drift in behavior, not just uptime. Hosted models change underneath you. Version pinning plus periodic re-runs of the evaluation set catch it.
  10. Put vendor AI through third-party risk management. The 2023 Interagency Guidance on Third-Party Relationships, issued by the Fed as SR 23-4, applies to all banking organizations supervised by the Federal Reserve, with no asset threshold. Contract terms on training data use, retention, subcontractors and incident notification belong here.
  11. Report to the board on a schedule. Inventory by tier, incidents, evaluation results and material changes. Quarterly is a reasonable starting cadence.
  12. Review the policy when the rules move. The agencies have promised a request for information on AI. Treat its publication as a trigger to revisit everything above.

The mapping below is the artifact we would take into a supervisory conversation.

System type Governed under Primary evidence to keep
Credit scorecard, fraud classifier, forecasting model SR 26-2 principles Materiality assessment, validation report, ongoing monitoring results
Generative assistant over internal documents Your AI policy, plus IT and operational risk Data scope, evaluation results, access logs, human review records
Agentic system that takes actions in applications Your AI policy, plus change and access management Permission scope per action, approval records, full action log, kill-switch test
AI feature inside a purchased platform SR 23-4 third-party risk management Vendor due diligence, contract terms, notification of model changes
Spreadsheet or deterministic rule set End-user computing and operational risk Owner, change control, periodic review

Key takeaway: The framework above is not an SR 26-2 requirement, because SR 26-2 does not reach these systems. It is how you demonstrate that your risk management and governance practices actually did guide the determination, which is exactly what the footnote asks for.

What banks under $30 billion should do now

If you are below the threshold, the temptation is to file this under "not our problem." Two reasons not to.

First, the OCC has already been explicit with community banks. Bulletin 2025-26, issued October 6, 2025, applies to institutions up to $30 billion in assets and states that banks may tailor their model risk management practices, including the frequency and nature of validation activities, commensurate with their risk exposures and the complexity of their model use. It adds that the OCC will not provide negative supervisory feedback to a bank solely for the frequency or scope of model validation the bank reasonably determines. That is a real reduction in burden, and it only helps you if your own policy reflects it. A policy that still promises annual validation of every model commits you to work no supervisor is asking for.

Second, the parts of the landscape that do reach you have not moved. Third-party risk management applies at every size. Consumer protection and fair lending law applies regardless of the technology behind a decision. And an AI system that influences customer outcomes will attract questions whether or not a model risk document covers it.

The proportionate version of the framework above is short: a one-page inventory, a named owner per system, a written data boundary, logging, and an annual review. For most community banks that is a few days of work, not a program.

What examiners are likely to ask

Given how the guidance is written, the questions cluster in four places. Prepare answers to these and you have covered most of the surface.

  • "Show me your model inventory and how you tiered it." Materiality is the new organizing idea. Expect to justify why a model is immaterial, not just assert it.
  • "How did you decide this system is not a model?" The narrowed definition invites reclassification, so the reasoning needs to be written down at the time, not reconstructed a year later.
  • "Who performs effective challenge, and what changed as a result?" Naming the function is not enough. Keep examples where challenge altered a model or restricted its use.
  • "What governs your AI tools, given that the guidance excludes them?" This is the question the footnote creates. Silence is the worst available answer.

Each of those is a documentation problem more than an engineering one, which is good news: documentation is the cheapest category of work in the whole program.

What to watch next

The agencies were unusually specific about their next step. The OCC news release accompanying Bulletin 2026-13 stated that the OCC, Federal Reserve Board and FDIC "plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks' use of AI, including generative AI and agentic AI." The Spring 2026 Semiannual Risk Perspective repeated the commitment and added AI-based models to the list.

As of September 25, 2026, a search of the Federal Register for notices from the three banking agencies published since April 17, 2026 returns no such request for information. The commitment stands; the document has not arrived. When it does, it will be the clearest signal yet of where supervisory expectations for generative and agentic AI are heading, and comment letters will be worth filing.

Until then, the honest summary is that banks are operating in a gap. The old model risk manual has been retired, the new one deliberately excludes the technology everyone is deploying, and the replacement guidance for that technology does not exist yet. Governance you design yourself is the only thing filling it.

Where this leaves you

SR 26-2 gives you room. It narrows what counts as a model, ties rigor to materiality, disclaims enforceability, and points itself at 66 large banks rather than nearly 900. Used well, that is a genuine reduction in low-value work.

It also hands you a decision the 2011 guidance never asked you to make. Generative and agentic AI are yours to govern, with no supervisory template, at exactly the moment those systems are moving from pilots into customer-facing work. The banks that handle this well will not be the ones with the longest AI policy. They will be the ones that can produce an inventory, an owner, an evaluation result and a log for any AI system a supervisor points at.

Three things to do this quarter: reclassify your inventory against the new definition and write down the reasoning; rebuild the BSA/AML clarifications you lost with SR 21-8 inside your own policy; and stand up the twelve controls above for every AI system you run, in proportion to what it touches.

Fleurant AI builds AI for regulated industries, including the evaluation harnesses, audit logging and control documentation that make an AI system defensible in an exam, alongside custom AI and AI agent work. If you are weighing what governance a specific system needs, talk to a specialist and we will work through it with you. For anything that turns on legal interpretation, your counsel and compliance team make the call.

Frequently asked questions

What is SR 26-2?

SR 26-2 is the Federal Reserve's supervisory letter transmitting the revised interagency Supervisory Guidance on Model Risk Management, issued April 17, 2026 by the Federal Reserve, OCC and FDIC. It supersedes SR 11-7 from 2011 and SR 21-8 on BSA/AML systems from 2021. The OCC issued the same guidance as Bulletin 2026-13 and the FDIC as FIL-15-2026.

Does SR 26-2 apply to generative AI?

No. A footnote states that generative AI and agentic AI models are novel and rapidly evolving and are not within the scope of the guidance. The same footnote says a bank's own risk management and governance practices should determine the controls for tools not covered, and that the guidance's principles do apply to traditional quantitative models and to non-generative, non-agentic AI models.

Which banks does SR 26-2 apply to?

The guidance says it is expected to be most relevant to banking organizations with over $30 billion in total assets, and that models at organizations of $30 billion or less are generally excluded. The exception is smaller organizations with significant model risk exposure because of heavy or complex model use, or because of activities outside traditional community banking.

Is SR 26-2 enforceable?

The guidance states that it does not set forth enforceable standards or prescriptive requirements, and that non-compliance alone will not result in supervisory criticism. A footnote adds that supervisory action may still follow from violations of law, or from unsafe or unsound practices stemming from insufficient management of model risk. Treat it as expectations, not a rulebook.

What happened to the BSA/AML model risk statement?

SR 21-8, the 2021 interagency statement on model risk management for BSA/AML systems, was rescinded alongside SR 11-7 and was not replaced with a standalone successor. Banks running transaction monitoring and sanctions screening now work from the general principles in SR 26-2 plus their own BSA program requirements rather than from AML-specific model risk guidance.

Do spreadsheets count as models under SR 26-2?

Not on their own. The revised definition excludes simple arithmetic calculations such as those found within spreadsheets, as well as deterministic rule-based processes and software with no statistical, economic or financial theories underpinning their design or use. A spreadsheet that implements a statistical model is still a model; a spreadsheet that adds numbers is not.

What should a bank under $30 billion do about AI governance?

Keep an inventory of AI systems, name one owner for each, set written limits on the data they touch and the decisions they influence, and log enough to reconstruct any output. The 2023 interagency third-party risk management guidance applies to banking organizations of every size, so vendor AI is squarely in scope regardless of asset size.

When will the agencies issue AI-specific guidance?

The agencies said in April 2026 that they plan to issue a request for information in the near future, covering model risk management generally and banks' use of generative AI, agentic AI and AI-based models. As of September 25, 2026 no such request for information from the three banking agencies had appeared in the Federal Register. Watch for it before assuming today's expectations are settled.

Sources

  1. SR 26-2: Revised Guidance on Model Risk Management, Board of Governors of the Federal Reserve System
  2. Revised Guidance on Model Risk Management (letter and attachment, PDF), Board of Governors of the Federal Reserve System
  3. OCC Bulletin 2026-13: Model Risk Management: Revised Guidance, Office of the Comptroller of the Currency
  4. OCC Issues Updated Model Risk Management Guidance (News Release 2026-29), Office of the Comptroller of the Currency
  5. FIL-15-2026: Agencies Revise the Interagency Model Risk Management Guidance, Federal Deposit Insurance Corporation
  6. FIL-22-2017: Adoption of Supervisory Guidance on Model Risk Management, Federal Deposit Insurance Corporation
  7. OCC Bulletin 2025-26: Model Risk Management: Clarification for Community Banks, Office of the Comptroller of the Currency
  8. Semiannual Risk Perspective, Spring 2026, Office of the Comptroller of the Currency
  9. SR 23-4: Interagency Guidance on Third-Party Relationships: Risk Management, Board of Governors of the Federal Reserve System
  10. Large Commercial Banks, data as of March 31, 2026, Board of Governors of the Federal Reserve System
  11. Federal Banking Agencies Issue Revised Guidance on Model Risk Management, Sullivan & Cromwell LLP
  12. Agencies Overhaul Model Risk Management Guidance for Banks: Here's What Changed, Orrick
  13. Visual Memo: Key Changes Under the Federal Banking Agencies' Revised Model Risk Management Guidance, Davis Polk
  14. AI Risk Management Framework, National Institute of Standards and Technology
  15. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1), National Institute of Standards and Technology

Free, no-obligation consultation

Have a question about SR 26-2 and AI governance?

Tell us what you're working on or what you'd like to know. A specialist will get back to you with practical next steps, whether or not we end up working together.

  1. 1Send your question or project details (takes 2 minutes)
  2. 2A specialist reviews it and replies within 1 business day
  3. 3Get clear, practical next steps, free