FluxForce AI Blog | Secure AI Agents, Compliance & Fraud Insights

SR 11-7 for AI Models: 2026 Examiner Guide

Written by Sahil Kataria | Oct 7, 2026, 5:03:46β€―PM

Listen To Our Podcast🎧

β€’ 2:15
SR 11-7 Model Risk Management for AI Models: What Examiners Ask for in 2026
Secure. Automate. – The FluxForce Podcast
Your browser does not support audio.

How should a bank classify AI before preparing its model risk file?

SR 11-7 is no longer the current interagency model risk guidance. On April 17, 2026, the Federal Reserve, OCC and FDIC issued revised model risk guidance that superseded SR 11-7 and SR 21-8. The revised document covers traditional statistical and quantitative models and non-generative, non-agentic AI. Generative and agentic AI are outside its scope.

That change does not remove the need to govern AI. It changes the first question. Before preparing a validation file, decide what the system is, how it is used, which decisions depend on it and which risk framework applies. An examiner-ready program can explain that classification, show the evidence behind it and prove that governance follows the actual risk rather than an old label.

In This Article, You'll Learn
  • Understand the 2026 replacement of SR 11-7.
  • Separate in-scope models from generative and agentic AI.
  • Build an examiner-ready evidence chain.
  • Prepare one inventory with visible classifications and owners.

Request a model governance review

Bring one mixed AI workflow and its inventory entry to a. Review the evidence your analysts need, existing controls and data-access limits before choosing the next step.
scoped AI Model Governance demo

The classify, bound, validate, challenge, monitor and evidence model

Start with classification, then connect approved use, proportionate testing, objective challenge, monitoring and replayable evidence.

  1. Classify the system. Record whether it is a quantitative model, non-generative AI, generative AI, agentic AI, deterministic rules, software or a combination.
  2. Bound the use. State the intended purpose, users, decisions supported, prohibited uses, exposure and materiality.
  3. Validate what is validatable. Test performance, reliability, limitations and use conditions with rigor proportionate to the risk.
  4. Challenge the design and use. Give objective experts enough authority and standing to question assumptions, data, methods, outputs and controls.
  5. Monitor change. Track performance, input shifts, overrides, incidents, vendor changes and use outside approved boundaries.
  6. Preserve evidence. Keep the inventory record, approvals, tests, limitations, issues, actions and human decisions in a form a reviewer can replay.
"
Direct answer

SR 26-2 replaced SR 11-7 on April 17, 2026. It covers traditional models and non-generative, non-agentic AI, while generative and agentic AI require other governance controls.

What replaced SR 11-7 in 2026?

The joint revised guidance replaced SR 11-7 and SR 21-8. The Federal Reserve's SR 26-2 letter says it is expected to be most relevant to Federal Reserve-regulated banking organizations with over $30 billion in total assets. The guidance also says it may be useful for smaller organizations with significant model use or higher risk.

  • The reviewed route is Classify the system β†’ Bound the use β†’ Validate what is validatable β†’ Challenge the design and use β†’ Monitor change β†’ Preserve evidence.
The reviewed route connects classification and evidence to an authorized human decision.

The revised guidance is principles-based. It says it does not create enforceable standards or prescriptive requirements, and it says non-compliance with the guidance alone will not produce supervisory criticism. Violations of law or unsafe or unsound practices remain separate matters.

The biggest AI change is scope. The revised guidance covers traditional statistical and quantitative models plus non-generative, non-agentic AI models. It excludes generative AI and agentic AI because the agencies describe those technologies as novel and fast-changing. Federal Reserve Vice Chair for Supervision Michelle W. Bowman later explained that banks were relying on existing risk-management frameworks for AI and that the revised guidance was intentionally narrowed to traditional models and basic AI applications.

Key Insight: A 2026 review should therefore avoid saying that every AI system is an SR 11-7 model. That statement is now wrong. The institution needs a documented classification and a governance path for each system.

System type Primary 2026 treatment Review focus
Traditional statistical or quantitative model Revised SR 26-2 guidance Purpose, materiality, development, use, validation, monitoring, challenge and governance
Non-generative, non-agentic AI model Revised SR 26-2 guidance The same principles, scaled to use, exposure, complexity and materiality
Generative AI Outside SR 26-2 scope Existing enterprise risk, AI governance, information security, privacy, vendor, human oversight and incident controls
Agentic AI Outside SR 26-2 scope Authority boundaries, human decision rights, tool access, monitoring, rollback, evidence and kill controls
Deterministic rule-based process without statistical, economic or financial theory Excluded from the guidance definition of model Change control, testing, data quality, policy ownership and operational risk controls

This table is a practical interpretation of the agencies' scope language. It is not a legal classification for every institution or use case.

Why does classification come before validation?

The old habit was to start with a model inventory and ask whether an item belonged on it. The 2026 approach should start one step earlier. Use six connected decisions.

The reviewed route is Classify the system β†’ Bound the use β†’ Validate what is validatable β†’ Challenge the design and use β†’ Monitor change β†’ Preserve evidence. The sequence matters. A technically strong validation cannot repair a system that was classified incorrectly or used outside its approved purpose.

What will examiners ask about classification and scope?

Expect the discussion to begin with purpose and use, not the product label. "AI," "machine learning" and "assistant" do not answer whether the system fits the revised guidance.

  • The fraud investigation workflow routes to the scored model, deterministic policy rules, generative summarizer and agent that gathers evidence.
The reviewed route connects classification and evidence to an authorized human decision.

The revised model definition covers a complex quantitative method, system or approach that applies statistical, economic or financial theories to input data and produces quantitative estimates. It excludes simple arithmetic and deterministic rule-based software without those theories. That wording creates a practical need to separate components inside a larger AI-enabled workflow.

A fraud investigation workflow may contain a scored model, deterministic policy rules, a generative summarizer and an agent that gathers evidence. The fraud investigation workflow routes to the scored model, deterministic policy rules, generative summarizer and agent that gathers evidence. Those components should not inherit one classification merely because they appear in one interface. The inventory record should connect purpose and approved use to exposure and materiality, validation or testing status, human oversight and authority, then exceptions and remediation. It should show the components, their roles, dependencies and governing controls.

An examiner-ready scope record should answer:

  • What does the system produce?
  • Which business decision uses the output?
  • Can the output change a customer, credit, fraud, AML or financial result?
  • Is the output advisory, or can it trigger an automated action within approved policy?
  • What theory or statistical method underpins it?
  • Does it generate content, plan actions or use tools?
  • Which human role owns the final decision?
  • What happens if the system is unavailable or wrong?

These are not quoted examination questions. They are a practical review set derived from the guidance's definitions, materiality discussion and governance principles.

What evidence supports purpose, materiality and approved use?

The revised guidance links model risk to inherent risk, exposure, purpose and use. It describes materiality as a product of purpose and exposure, and it allows organizations to tailor model risk practices to the risk posed by the model.

That makes the approved-use statement one of the most useful records in the file. It should identify the business process, population, decisions, limits and users. It should also state what the model does not do.

For an AI model used in transaction monitoring, the record might say that the model ranks alerts for investigator review. It does not close alerts, decide whether activity is suspicious or file a report. The institution defines the threshold, the investigator reviews the evidence and the MLRO retains reporting authority.

The same record should cover use outside the original purpose. SR 26-2 says extending a model beyond its intended use introduces uncertainty and risk and may require more analysis, a review of controls and explicit treatment of limitations.

A clean evidence pack contains:

  • a current purpose and approved-use statement;
  • the owner, business sponsor and accountable risk role;
  • intended users and affected decisions;
  • exposure and materiality rationale;
  • data and dependency summary;
  • known limitations and prohibited uses;
  • approval date, version and review trigger;
  • exceptions, compensating controls and expiry dates.

What does validation need to prove?

Validation should show whether the model performs as expected, how reliable it is and where it fails. The revised guidance says validation includes an assessment of reliability and limitations, with nature and rigor tied to approach, use and materiality.

A useful validation plan is built around the decision risk. It does not stop at one performance score.

For a non-generative AI model, the plan may include conceptual review, data suitability, implementation verification, outcomes analysis, sensitivity testing, segment analysis and tests for use outside expected conditions. The exact mix depends on the model and the harm that a bad output could cause.

Validation also needs a response path. If performance moves outside an approved range, the file should show who investigates, who can restrict use, what interim control applies and who approves recalibration or redevelopment.

A vendor model does not remove the institution's responsibility. SR 26-2 says third-party products can limit access to code, data or methods, but the model risk principles still apply. The institution needs enough understanding to manage the risk, and it needs monitoring or controls when full transparency is unavailable.

What counts as effective challenge in 2026?

Effective challenge is still central. SR 26-2 defines it as critical analysis by objective experts across the lifecycle. Those experts need the knowledge, independence, standing and influence required to change the model or its use when the evidence calls for it.

A committee signature is weak evidence if the record shows no disagreement, testing request or change. A stronger trail shows what the challenger questioned and what happened next.

Useful records include:

  • written challenge to an assumption, data source, threshold or use condition;
  • management's response and supporting evidence;
  • a changed limit, test, control or monitoring rule;
  • a documented risk acceptance with owner and expiry;
  • an unresolved issue with restrictions on use;
  • confirmation that the challenger had access to the needed information.

Independence should be judged in context. The guidance allows different organizational structures, but it expects objectivity. If the same team builds, approves and monitors a material model, the institution should be able to explain how challenge remains credible.

Illustrative scenario: how are the four components controlled?

A bank uses an AI-enabled workflow to help investigate transaction monitoring alerts. The AI-enabled workflow connects the statistical model, deterministic rules, generative component and evidence-gathering agent to an analyst or MLRO decision, without giving any component independent authority. The workflow contains four parts.

First, a statistical model scores alert priority. That component fits the revised guidance if it meets the model definition. Its file covers purpose, materiality, development, validation, monitoring and effective challenge.

Second, deterministic rules apply institution policy, such as routing certain alerts to a specialist queue. Those rules are outside the model definition, but they still need owners, testing and change control.

Third, a generative component drafts a case summary from approved evidence. SR 26-2 does not directly govern that component. The institution instead applies its AI, information security, privacy, vendor and human-review controls. The analyst checks the draft against source evidence before it enters the case record.

Fourth, an agent gathers approved records and prepares a recommendation. It cannot close the case or file a report. The customer sets its allowed actions, the analyst makes the call and the workflow has a kill switch.

The main lesson is simple. One workflow can contain several technologies with different governance paths. The evidence map should preserve the relationships without pretending one guidance document covers everything.

Review the illustrative workflow by component

Illustrative scenario, not a customer result.

Use the four components in the scenario to check that governance follows each component rather than the shared interface.

  1. Apply SR 26-2 principles to the in-scope scored model.
  2. Apply change control to deterministic policy rules.
  3. Apply AI, data, vendor and human-review controls to generative and agentic components.
  4. Keep the investigator or MLRO as the decision owner.

How should generative and agentic AI be governed outside SR 26-2?

Outside SR 26-2 does not mean outside governance. It means the institution should choose controls based on actual risks and existing obligations.

  • The AI-enabled workflow connects the statistical model, deterministic rules, generative component and evidence-gathering agent to an analyst or MLRO decision, without giving any component independent authority.
The reviewed route connects classification and evidence to an authorized human decision.

NIST's AI Risk Management Framework organizes AI risk work around Govern, Map, Measure and Manage. It calls for an AI system inventory, documented roles and responsibilities, executive accountability and defined human oversight. The NIST Generative AI Profile adds practical focus on governance, content provenance, pre-deployment testing and incident disclosure.

For a bank, that can translate into a control pack covering:

  • an AI system inventory with model, vendor and version details;
  • approved data sources and restricted data classes;
  • human oversight roles and decision authority;
  • tool and system permissions;
  • pre-deployment tests tied to real use cases;
  • content provenance and source traceability;
  • monitoring for incidents, drift and unexpected behavior;
  • rollback, disablement and kill-switch procedures;
  • vendor changes, dependency changes and exit plans;
  • retention of test, approval and incident evidence.

These are risk-management recommendations, not a claim that NIST rules are binding banking requirements. Institutions should map them to their own regulator, laws, policies and risk appetite.

What should the model inventory contain?

SR 26-2 describes a model inventory as common industry practice and says it should hold enough information to understand model risk at both the individual and aggregate levels. NIST separately calls for mechanisms to inventory AI systems according to organizational risk priorities.

  • The inventory record should connect purpose and approved use to exposure and materiality, validation or testing status, human oversight and authority, then exceptions and remediation.
The reviewed route connects classification and evidence to an authorized human decision.

A combined inventory can support both needs if it keeps classification visible. At minimum, include:

Field Why it matters
System and component name Prevents a large workflow from hiding several governed components
Classification and rationale Shows whether SR 26-2 applies and why
Purpose and prohibited use Defines the boundary for testing and monitoring
Owner and accountable decision role Makes responsibility visible
Business process and decisions affected Connects technical behavior to actual risk
Exposure and materiality Supports proportional governance
Data, vendors and dependencies Shows concentration and third-party risk
Version and change history Supports testing, approval and incident review
Validation or testing status Shows what evidence exists and what remains open
Human oversight and authority Prevents an agent or model from inheriting an undefined decision right
Monitoring and review triggers Connects use to ongoing control
Exceptions and remediation Makes accepted risk and unfinished work visible

Do not force every field into one crowded spreadsheet. The inventory can link to validation files, architecture records, incidents and approvals. What matters is a stable identity and a clear evidence trail.

What should happen before an examination?

Start with a classification review, then sample the evidence. A large policy rewrite is less useful than proving that the controls work for selected systems.

  • The examination-readiness route is Reconcile inventories β†’ Split mixed workflows β†’ Confirm applicability β†’ Sample evidence β†’ Trace one issue β†’ Test rollback and kill-switch procedures β†’ Authorized human sign-off.
The reviewed route connects classification and evidence to an authorized human decision.
  1. Reconcile procurement, technology, data science, compliance and business inventories.
  2. Split mixed AI workflows into governed components.
  3. Confirm whether SR 26-2 applies to each component.
  4. Check purpose, materiality and approved-use records.
  5. Sample validation, challenge and monitoring evidence for in-scope models.
  6. Sample testing, human oversight, permissions and incident evidence for generative and agentic AI.
  7. Trace one issue from detection through restriction, remediation and closure.
  8. Confirm that the analyst, risk owner or MLRO retains every defined high-risk decision.
  9. Test rollback and kill-switch procedures rather than relying on policy text. The examination-readiness route is Reconcile inventories β†’ Split mixed workflows β†’ Confirm applicability β†’ Sample evidence β†’ Trace one issue β†’ Test rollback and kill-switch procedures β†’ Authorized human sign-off.

Useful metrics include inventory coverage, overdue review count, open high-severity findings, time to restrict a system after a failed control, percentage of changes reviewed before use and sampled evidence completeness. Define each metric before reporting it. A count without a denominator or an owner is hard to act on.

How should mixed AI workflows be governed?

Classify each component and connect it to the correct risk framework, evidence and human authority.

ComponentResponsibilityBoundary
Model Risk ManagementOwns classification, materiality, validation, challenge and monitoring for in-scope models.Does not treat every AI tool as an SR 26-2 model.
AI and Enterprise Risk GovernanceOwns controls for generative and agentic AI outside SR 26-2 scope.Does not remove legal, privacy, security, vendor or operational obligations.
Authorized human reviewerApproves use, restrictions, exceptions, remediation and defined risk decisions.Does not delegate material accountability to an agent.

The Model Risk Lead, CRO, analyst or MLRO retains the defined decision and can restrict, roll back or stop the workflow.

Which sources support the 2026 governance boundary?

Federal Reserve SR 26-2

Replacement of SR 11-7 and current applicability statement.

U.S. interagency supervisory guidance.

2026-10-07

Revised Model Risk Management Guidance

Model definition, scope, materiality, validation, challenge, inventory and vendor principles.

Traditional quantitative models and non-generative, non-agentic AI.

2026-10-07

NIST AI RMF 1.0

AI inventory, accountability, human oversight and Govern-Map-Measure-Manage structure.

Voluntary risk-management framework, not banking regulation.

2026-10-07

NIST Generative AI Profile

Governance, provenance, pre-deployment testing and incident disclosure for generative AI.

Voluntary profile, not banking regulation.

2026-10-07

How FluxForce fits the governance workflow

FluxForce is an Agentic OS for Regulated Industries. AI agents that investigate AML, sanctions, fraud and KYC alerts and prepare the case. Your analyst makes the call, with evidence an examiner can replay. You decide how much each agent does on its own, and every one has a kill switch. AI Model Governance addresses the model-risk team's need to understand model behavior and prepare examiner evidence.

For this use case, a scoped design would need to gather approved model records, connect versions to tests and monitoring events, flag missing evidence and prepare a review packet. The institution still owns classification, validation acceptance, use restrictions, risk acceptance and regulatory responses. Teams should confirm data, vendor and connection fit during a scoped review.

Discuss your AI Model Governance workflow

FluxForce does not decide whether a specific system is legally in scope. It does not replace independent validation, internal audit, legal advice, regulator communication or the institution's model risk policy.

How should examination readiness be measured?

  1. Assign an owner and review period to each metric.
  2. Record the denominator and inspect the evidence behind the count.
MetricDefinitionDecision guardrail
Inventory coverageGoverned systems with a current classified inventory entry divided by systems identified through reconciliation.Report missing and disputed classifications separately.
Evidence completenessSampled systems containing the required purpose, approval, test, monitoring and issue records.Inspect the linked evidence rather than relying on inventory fields.
Restriction response timeTime from a failed control or material issue to an effective use restriction.Measure from detected evidence, not ticket creation.
Key takeaways
  • Classify each AI component before choosing its governance path.
  • Tie validation rigor to purpose, use, exposure and materiality.
  • Keep challenge objective and able to change use or controls.
  • Retain authorized human decisions, evidence and rollback controls.

Conclusion

The weakest record is often the best place to begin. Pick one AI-enabled workflow that crosses model, rule, generative and agentic components. Classify each part. Name the human decision owner. Link the purpose, tests, issues, monitoring and approvals.

If the file cannot explain why a system sits inside or outside SR 26-2, another validation report will not solve the problem. Fix the boundary first. Then validate, challenge and monitor the parts that need it.

Request a model governance review

Bring one mixed AI workflow and its inventory entry to a. Review the evidence your analysts need, existing controls and data-access limits before choosing the next step.
scoped AI Model Governance demo

Frequently Asked Questions

No. The Federal Reserve, OCC and FDIC issued revised model risk guidance on April 17, 2026. The Federal Reserve's SR 26-2 letter says the new guidance supersedes and replaces SR 11-7 and SR 21-8.

No. The revised guidance states that generative AI and agentic AI are outside its scope. It says banking organizations should still use risk-management and governance practices to determine suitable controls for tools, systems and processes not covered by the document.

It can. The guidance applies to non-generative, non-agentic AI models that meet its model definition. The institution should assess the component's quantitative method, purpose, use and outputs rather than relying on the label "machine learning."

A current inventory entry with a clear classification, purpose, owner, materiality rationale, approved use, limitations and links to supporting evidence is a strong starting point. The right first document may differ by institution and examination scope.

A vendor report can provide evidence, but it does not remove the bank's need to understand and manage the model's risk. The revised guidance says model risk principles remain relevant even when proprietary limits restrict access to code, data or methodology.

The institution's policy should assign approval to an authorized human role with enough information and authority to accept, restrict or reject the use. NIST's AI RMF also calls for documented roles, executive accountability and defined human oversight.

No. An agent can route evidence or update administrative fields only within customer-configured boundaries. An authorized person closes material issues, accepts risk and approves use restrictions or examination responses. FluxForce keeps that human decision point explicit.

About the author

Sahil Kataria

Founder and CEO of FluxForce

Sahil works on secure AI and financial technology for regulated industries. His engineering background spans identity verification, payment security and compliance automation. He has led teams across Africa, the United States, Europe and India.

At FluxForce.ai, his focus is on explainable AI and auditable financial workflows. He writes for banking and compliance teams about the practical decisions behind these systems: how to assess risk, keep controls visible and introduce automation without losing accountability.

View Sahil Kataria author profile β†’
Model risk management and AI governance

Primary governance pillar.

FluxForce templates

Governance and model inventory resources.

SR 11-7 model risk management

Existing canonical merge target.