SR 11-7 is no longer the current interagency model risk guidance. On April 17, 2026, the Federal Reserve, OCC and FDIC issued revised model risk guidance that superseded SR 11-7 and SR 21-8. The revised document covers traditional statistical and quantitative models and non-generative, non-agentic AI. Generative and agentic AI are outside its scope.
That change does not remove the need to govern AI. It changes the first question. Before preparing a validation file, decide what the system is, how it is used, which decisions depend on it and which risk framework applies. An examiner-ready program can explain that classification, show the evidence behind it and prove that governance follows the actual risk rather than an old label.
Start with classification, then connect approved use, proportionate testing, objective challenge, monitoring and replayable evidence.
SR 26-2 replaced SR 11-7 on April 17, 2026. It covers traditional models and non-generative, non-agentic AI, while generative and agentic AI require other governance controls.
The joint revised guidance replaced SR 11-7 and SR 21-8. The Federal Reserve's SR 26-2 letter says it is expected to be most relevant to Federal Reserve-regulated banking organizations with over $30 billion in total assets. The guidance also says it may be useful for smaller organizations with significant model use or higher risk.
The revised guidance is principles-based. It says it does not create enforceable standards or prescriptive requirements, and it says non-compliance with the guidance alone will not produce supervisory criticism. Violations of law or unsafe or unsound practices remain separate matters.
The biggest AI change is scope. The revised guidance covers traditional statistical and quantitative models plus non-generative, non-agentic AI models. It excludes generative AI and agentic AI because the agencies describe those technologies as novel and fast-changing. Federal Reserve Vice Chair for Supervision Michelle W. Bowman later explained that banks were relying on existing risk-management frameworks for AI and that the revised guidance was intentionally narrowed to traditional models and basic AI applications.
Key Insight: A 2026 review should therefore avoid saying that every AI system is an SR 11-7 model. That statement is now wrong. The institution needs a documented classification and a governance path for each system.
| System type | Primary 2026 treatment | Review focus |
|---|---|---|
| Traditional statistical or quantitative model | Revised SR 26-2 guidance | Purpose, materiality, development, use, validation, monitoring, challenge and governance |
| Non-generative, non-agentic AI model | Revised SR 26-2 guidance | The same principles, scaled to use, exposure, complexity and materiality |
| Generative AI | Outside SR 26-2 scope | Existing enterprise risk, AI governance, information security, privacy, vendor, human oversight and incident controls |
| Agentic AI | Outside SR 26-2 scope | Authority boundaries, human decision rights, tool access, monitoring, rollback, evidence and kill controls |
| Deterministic rule-based process without statistical, economic or financial theory | Excluded from the guidance definition of model | Change control, testing, data quality, policy ownership and operational risk controls |
This table is a practical interpretation of the agencies' scope language. It is not a legal classification for every institution or use case.
The old habit was to start with a model inventory and ask whether an item belonged on it. The 2026 approach should start one step earlier. Use six connected decisions.
The reviewed route is Classify the system β Bound the use β Validate what is validatable β Challenge the design and use β Monitor change β Preserve evidence. The sequence matters. A technically strong validation cannot repair a system that was classified incorrectly or used outside its approved purpose.
Expect the discussion to begin with purpose and use, not the product label. "AI," "machine learning" and "assistant" do not answer whether the system fits the revised guidance.
The revised model definition covers a complex quantitative method, system or approach that applies statistical, economic or financial theories to input data and produces quantitative estimates. It excludes simple arithmetic and deterministic rule-based software without those theories. That wording creates a practical need to separate components inside a larger AI-enabled workflow.
A fraud investigation workflow may contain a scored model, deterministic policy rules, a generative summarizer and an agent that gathers evidence. The fraud investigation workflow routes to the scored model, deterministic policy rules, generative summarizer and agent that gathers evidence. Those components should not inherit one classification merely because they appear in one interface. The inventory record should connect purpose and approved use to exposure and materiality, validation or testing status, human oversight and authority, then exceptions and remediation. It should show the components, their roles, dependencies and governing controls.
An examiner-ready scope record should answer:
These are not quoted examination questions. They are a practical review set derived from the guidance's definitions, materiality discussion and governance principles.
The revised guidance links model risk to inherent risk, exposure, purpose and use. It describes materiality as a product of purpose and exposure, and it allows organizations to tailor model risk practices to the risk posed by the model.
That makes the approved-use statement one of the most useful records in the file. It should identify the business process, population, decisions, limits and users. It should also state what the model does not do.
For an AI model used in transaction monitoring, the record might say that the model ranks alerts for investigator review. It does not close alerts, decide whether activity is suspicious or file a report. The institution defines the threshold, the investigator reviews the evidence and the MLRO retains reporting authority.
The same record should cover use outside the original purpose. SR 26-2 says extending a model beyond its intended use introduces uncertainty and risk and may require more analysis, a review of controls and explicit treatment of limitations.
A clean evidence pack contains:
Validation should show whether the model performs as expected, how reliable it is and where it fails. The revised guidance says validation includes an assessment of reliability and limitations, with nature and rigor tied to approach, use and materiality.
A useful validation plan is built around the decision risk. It does not stop at one performance score.
For a non-generative AI model, the plan may include conceptual review, data suitability, implementation verification, outcomes analysis, sensitivity testing, segment analysis and tests for use outside expected conditions. The exact mix depends on the model and the harm that a bad output could cause.
Validation also needs a response path. If performance moves outside an approved range, the file should show who investigates, who can restrict use, what interim control applies and who approves recalibration or redevelopment.
A vendor model does not remove the institution's responsibility. SR 26-2 says third-party products can limit access to code, data or methods, but the model risk principles still apply. The institution needs enough understanding to manage the risk, and it needs monitoring or controls when full transparency is unavailable.
Effective challenge is still central. SR 26-2 defines it as critical analysis by objective experts across the lifecycle. Those experts need the knowledge, independence, standing and influence required to change the model or its use when the evidence calls for it.
A committee signature is weak evidence if the record shows no disagreement, testing request or change. A stronger trail shows what the challenger questioned and what happened next.
Useful records include:
Independence should be judged in context. The guidance allows different organizational structures, but it expects objectivity. If the same team builds, approves and monitors a material model, the institution should be able to explain how challenge remains credible.
A bank uses an AI-enabled workflow to help investigate transaction monitoring alerts. The AI-enabled workflow connects the statistical model, deterministic rules, generative component and evidence-gathering agent to an analyst or MLRO decision, without giving any component independent authority. The workflow contains four parts.
First, a statistical model scores alert priority. That component fits the revised guidance if it meets the model definition. Its file covers purpose, materiality, development, validation, monitoring and effective challenge.
Second, deterministic rules apply institution policy, such as routing certain alerts to a specialist queue. Those rules are outside the model definition, but they still need owners, testing and change control.
Third, a generative component drafts a case summary from approved evidence. SR 26-2 does not directly govern that component. The institution instead applies its AI, information security, privacy, vendor and human-review controls. The analyst checks the draft against source evidence before it enters the case record.
Fourth, an agent gathers approved records and prepares a recommendation. It cannot close the case or file a report. The customer sets its allowed actions, the analyst makes the call and the workflow has a kill switch.
The main lesson is simple. One workflow can contain several technologies with different governance paths. The evidence map should preserve the relationships without pretending one guidance document covers everything.
Illustrative scenario, not a customer result.
Use the four components in the scenario to check that governance follows each component rather than the shared interface.
Outside SR 26-2 does not mean outside governance. It means the institution should choose controls based on actual risks and existing obligations.
NIST's AI Risk Management Framework organizes AI risk work around Govern, Map, Measure and Manage. It calls for an AI system inventory, documented roles and responsibilities, executive accountability and defined human oversight. The NIST Generative AI Profile adds practical focus on governance, content provenance, pre-deployment testing and incident disclosure.
For a bank, that can translate into a control pack covering:
These are risk-management recommendations, not a claim that NIST rules are binding banking requirements. Institutions should map them to their own regulator, laws, policies and risk appetite.
SR 26-2 describes a model inventory as common industry practice and says it should hold enough information to understand model risk at both the individual and aggregate levels. NIST separately calls for mechanisms to inventory AI systems according to organizational risk priorities.
A combined inventory can support both needs if it keeps classification visible. At minimum, include:
| Field | Why it matters |
|---|---|
| System and component name | Prevents a large workflow from hiding several governed components |
| Classification and rationale | Shows whether SR 26-2 applies and why |
| Purpose and prohibited use | Defines the boundary for testing and monitoring |
| Owner and accountable decision role | Makes responsibility visible |
| Business process and decisions affected | Connects technical behavior to actual risk |
| Exposure and materiality | Supports proportional governance |
| Data, vendors and dependencies | Shows concentration and third-party risk |
| Version and change history | Supports testing, approval and incident review |
| Validation or testing status | Shows what evidence exists and what remains open |
| Human oversight and authority | Prevents an agent or model from inheriting an undefined decision right |
| Monitoring and review triggers | Connects use to ongoing control |
| Exceptions and remediation | Makes accepted risk and unfinished work visible |
Do not force every field into one crowded spreadsheet. The inventory can link to validation files, architecture records, incidents and approvals. What matters is a stable identity and a clear evidence trail.
Start with a classification review, then sample the evidence. A large policy rewrite is less useful than proving that the controls work for selected systems.
Useful metrics include inventory coverage, overdue review count, open high-severity findings, time to restrict a system after a failed control, percentage of changes reviewed before use and sampled evidence completeness. Define each metric before reporting it. A count without a denominator or an owner is hard to act on.
Classify each component and connect it to the correct risk framework, evidence and human authority.
| Component | Responsibility | Boundary |
|---|---|---|
| Model Risk Management | Owns classification, materiality, validation, challenge and monitoring for in-scope models. | Does not treat every AI tool as an SR 26-2 model. |
| AI and Enterprise Risk Governance | Owns controls for generative and agentic AI outside SR 26-2 scope. | Does not remove legal, privacy, security, vendor or operational obligations. |
| Authorized human reviewer | Approves use, restrictions, exceptions, remediation and defined risk decisions. | Does not delegate material accountability to an agent. |
The Model Risk Lead, CRO, analyst or MLRO retains the defined decision and can restrict, roll back or stop the workflow.
Replacement of SR 11-7 and current applicability statement.
U.S. interagency supervisory guidance.
2026-10-07
Model definition, scope, materiality, validation, challenge, inventory and vendor principles.
Traditional quantitative models and non-generative, non-agentic AI.
2026-10-07
AI inventory, accountability, human oversight and Govern-Map-Measure-Manage structure.
Voluntary risk-management framework, not banking regulation.
2026-10-07
Governance, provenance, pre-deployment testing and incident disclosure for generative AI.
Voluntary profile, not banking regulation.
2026-10-07
| Metric | Definition | Decision guardrail |
|---|---|---|
| Inventory coverage | Governed systems with a current classified inventory entry divided by systems identified through reconciliation. | Report missing and disputed classifications separately. |
| Evidence completeness | Sampled systems containing the required purpose, approval, test, monitoring and issue records. | Inspect the linked evidence rather than relying on inventory fields. |
| Restriction response time | Time from a failed control or material issue to an effective use restriction. | Measure from detected evidence, not ticket creation. |
The weakest record is often the best place to begin. Pick one AI-enabled workflow that crosses model, rule, generative and agentic components. Classify each part. Name the human decision owner. Link the purpose, tests, issues, monitoring and approvals.
If the file cannot explain why a system sits inside or outside SR 26-2, another validation report will not solve the problem. Fix the boundary first. Then validate, challenge and monitor the parts that need it.
No. The Federal Reserve, OCC and FDIC issued revised model risk guidance on April 17, 2026. The Federal Reserve's SR 26-2 letter says the new guidance supersedes and replaces SR 11-7 and SR 21-8.
No. The revised guidance states that generative AI and agentic AI are outside its scope. It says banking organizations should still use risk-management and governance practices to determine suitable controls for tools, systems and processes not covered by the document.
It can. The guidance applies to non-generative, non-agentic AI models that meet its model definition. The institution should assess the component's quantitative method, purpose, use and outputs rather than relying on the label "machine learning."
A current inventory entry with a clear classification, purpose, owner, materiality rationale, approved use, limitations and links to supporting evidence is a strong starting point. The right first document may differ by institution and examination scope.
A vendor report can provide evidence, but it does not remove the bank's need to understand and manage the model's risk. The revised guidance says model risk principles remain relevant even when proprietary limits restrict access to code, data or methodology.
The institution's policy should assign approval to an authorized human role with enough information and authority to accept, restrict or reject the use. NIST's AI RMF also calls for documented roles, executive accountability and defined human oversight.
No. An agent can route evidence or update administrative fields only within customer-configured boundaries. An authorized person closes material issues, accepts risk and approves use restrictions or examination responses. FluxForce keeps that human decision point explicit.