Zuletzt aktualisiert am:
Model risk management is the discipline of identifying, measuring and controlling the risk that a model produces incorrect or misused output. In US banking it is set by SR 26-2, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026, which supersedes SR 11-7 and expressly excludes generative and agentic AI from its scope.
What replaced SR 11-7?
SR 26-2, Revised Guidance on Model Risk Management, was issued on April 17, 2026, by the Federal Reserve, the OCC and the FDIC together. It supersedes SR 11-7 from April 2011 and SR 21-8 from April 2021. On the OCC side, Bulletin 2026-13 rescinds the earlier OCC issuances and the model risk management booklet of the Comptroller's Handbook. Material still describing SR 11-7 as current guidance is out of date, and that includes a large amount of vendor and consultancy content published before spring 2026.
Which institutions does SR 26-2 apply to?
The agencies state the guidance is most relevant to banking organizations with more than 30 billion US dollars in total assets. Smaller institutions are not required to apply it wholesale, and the guidance is explicit that practices should scale to the size, complexity and model risk profile of the firm. This is a change of emphasis from SR 11-7, which was read as a uniform standard and drove a good deal of proportionality argument between banks and examiners.
Does SR 26-2 cover generative and agentic AI?
No, and this is the most consequential detail for anyone governing modern AI. The agencies state that generative AI and agentic AI models are novel and rapidly evolving and are not within the scope of this guidance. A bank deploying a large language model or an autonomous agent cannot point to SR 26-2 as the controlling standard, and cannot assume its existing model risk framework covers those systems. The gap has to be filled from elsewhere, typically the NIST AI Risk Management Framework, ISO/IEC 42001, sector guidance, and the firm's own policy.
What are the core components?
The guidance keeps the structure supervisors have used for fifteen years. Firms maintain an inventory of models with ownership and risk tiering. Development and implementation are documented so that a third party can understand the design choices, data and limitations. Validation is performed independently of the developers, covering conceptual soundness, ongoing monitoring and outcomes analysis. Governance sits above all of it, with board-approved policy, defined roles and reporting that reaches senior management. What SR 26-2 adds is a stronger risk-based framing of how much of this to apply to any given model.
How does it relate to AI governance?
Model risk management and AI governance overlap but are not the same thing. Model risk management asks whether a model is fit for its purpose and whether the firm can defend it. AI governance covers a wider surface: intake and approval of new use cases, third-party and vendor AI, agent permissions and action controls, regulatory mapping across several regimes at once, and evidence that can be reused across frameworks. Firms with mature model risk functions usually find they have the validation muscle and lack the inventory breadth, because shadow AI and vendor-embedded AI never entered the model inventory.
Praxisbeispiel:
A US bank with 60 billion dollars in assets holds 400 models in its inventory. Under SR 26-2 it tiers them by risk, applies full independent validation to the tier one models used for credit and capital, and applies proportionate review to the rest. It then finds 30 newer systems that use large language models for document summarization and customer correspondence. Because SR 26-2 puts generative AI out of scope, these cannot simply be added to the model inventory and validated the same way. The bank governs them under a separate AI policy mapped to the NIST AI RMF, with its own intake, evaluation and monitoring, while keeping both records in one system of record so examiners can see the whole estate.




