Explore Enzai’s full suite of AI governance products designed to help organizations manage, monitor, and scale AI with confidence. From structured intake and centralized AI inventories to automated assessments and real-time oversight, Enzai provides the building blocks to embed governance directly into everyday AI workflows - without slowing innovation.

Enzai

Last updated:

SR 26-2 (Revised Guidance on Model Risk Management)

SR 26-2 (Revised Guidance on Model Risk Management)

SR 26-2 is the revised US supervisory guidance on model risk management, issued jointly by the Federal Reserve, OCC and FDIC on 17 April 2026. It supersedes SR 11-7 and SR 21-8, sets out a risk-based approach tailored to a banking organisation's model risk profile, and expressly excludes generative and agentic AI from its scope.

What is SR 26-2 and what did it replace?

SR 26-2 is the Supervisory Guidance on Model Risk Management issued jointly by the Board of Governors of the Federal Reserve System, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation on 17 April 2026. It supersedes and replaces SR 11-7, Guidance on Model Risk Management (4 April 2011), and SR 21-8, the interagency statement on model risk management for bank systems supporting Bank Secrecy Act and anti-money laundering compliance (9 April 2021). On the same date, OCC Bulletin 2026-13 rescinded OCC Bulletins 2011-12, 1997-24 and 2021-19, together with the Model Risk Management booklet of the Comptroller's Handbook. The agencies describe the revision as reflecting supervisory experience and industry feedback gathered over the past fifteen years.

Who does SR 26-2 apply to?

The guidance is expected to be most relevant to banking organisations with over $30 billion in total assets. Organisations at or below that threshold are generally excluded, which the agencies describe as consistent with a tailored supervisory approach, on the basis that their models are usually covered by internal risk management appropriate to their size and risk profile. That exclusion is not absolute. The guidance may still be relevant to a smaller organisation with significant model risk exposure, either because of the prevalence and complexity of its models or because of activities outside traditional community banking.

What counts as a model under SR 26-2?

The guidance defines a model as a complex quantitative method, system or approach that applies statistical, economic or financial theories to process input data into quantitative estimates. That definition carries three explicit exclusions: simple arithmetic calculations such as those found in spreadsheets, deterministic rule-based processes, and software where no statistical, economic or financial theory underpins the design or use. Banks re-baselining their inventories often find the scope narrows, and that tools which sat inside the model inventory under SR 11-7 now fall outside it.

Does SR 26-2 cover AI models?

Partly. The guidance states that generative AI and agentic AI models "are novel and rapidly evolving" and "are not within the scope of this guidance", while confirming that its principles do apply to traditional statistical and quantitative models and to non-generative, non-agentic AI models. The exclusion is not permission to leave those systems ungoverned. The agencies add that a banking organisation's risk management and governance practices should still guide the controls applied to any tool, process or system the document does not cover. The effect is to push generative and agentic AI into a separate framework, commonly the FS AI RMF or the NIST AI RMF, supported by an AI inventory that covers both populations.

Is SR 26-2 enforceable?

No. The guidance states that it does not set out enforceable standards or prescriptive requirements, and that non-compliance will not by itself result in supervisory criticism against a banking organisation. That is a notable shift from the way SR 11-7 came to be treated in practice. The qualifier carries equal weight: supervisory action can still follow from violations of law, or from unsafe or unsound practices stemming from insufficient management of model risk. Firms gain flexibility in how they evidence model risk management, and no relief from the underlying obligation to manage it.

Real world example:

A US bank with $60 billion in assets re-scopes its model inventory against SR 26-2. A deterministic rule-based fee calculator drops out of scope under the narrower model definition, so the bank retires its validation schedule for that tool and records the rationale. Its ML credit scoring model stays in scope as a non-generative AI model and keeps full validation. Its generative AI assistant falls outside the guidance altogether, so the bank governs it under a separate AI framework and documents that decision, on the basis that the agencies still expect appropriate controls for systems the guidance does not cover.

“What used to take weeks of manual reviews and policy work is now structured and auditable in Enzai within minutes. It’s the first time AI governance has felt operational, not theoretical.”

Ready to get started

with your AI governance program?

Enzai provides an AI governance and enablement platform that will help your organisation maximise AI adoption, while minimising AI risk.

Hear back in 24 hours

Frosted glass visual with warm amber and gold light. Enzai provides a lawyer-led platform for AI governance and trust.

Customer Support Ticket Classification

Draft Use Case

5 requested AI solutions

Requested on: 7 Nov 2026

Requested by: Enzai

Reviewers:

Automated Contract Risk Review

Draft Use Case

5 requested AI solutions

Requested on: 7 July 2026

Requested by: Enzai

Reviewers:

Sales Forecasting & Demand Prediction

Draft Use Case

5 requested AI solutions

Requested on: 18 August 2026

Requested by: Enzai

Reviewers:

Employee Resume Screening Assistant

Draft Use Case

5 requested AI solutions

Requested on: 19 June 2026

Requested by: Enzai

Reviewers:

Ready to get started

with your AI governance program?

Enzai provides an AI governance and enablement platform that will help your organisation maximise AI adoption, while minimising AI risk.

Hear back in 24 hours

Dark frosted glass with a vertical golden glow. Enzai offers comprehensive AI governance and compliance solutions.

Customer Support Ticket Classification

Draft Use Case

5 requested AI solutions

Requested on: 7 Nov 2026

Requested by: Enzai

Reviewers:

Automated Contract Risk Review

Draft Use Case

5 requested AI solutions

Requested on: 7 July 2026

Requested by: Enzai

Reviewers:

Sales Forecasting & Demand Prediction

Draft Use Case

5 requested AI solutions

Requested on: 18 August 2026

Requested by: Enzai

Reviewers:

Employee Resume Screening Assistant

Draft Use Case

5 requested AI solutions

Requested on: 19 June 2026

Requested by: Enzai

Reviewers:

“What used to take weeks of manual reviews and policy work is now structured and auditable in Enzai within minutes. It’s the first time AI governance has felt operational, not theoretical.”

Ready to get started

with your AI governance program?

Hear back in 24 hours

Dark frosted glass with a vertical golden glow. Enzai offers comprehensive AI governance and compliance solutions.

Customer Support Ticket Classification

Draft Use Case

5 requested AI solutions

Requested on: 7 Nov 2026

Requested by: Enzai

Reviewers:

Automated Contract Risk Review

Draft Use Case

5 requested AI solutions

Requested on: 7 July 2026

Requested by: Enzai

Reviewers:

Sales Forecasting & Demand Prediction

Draft Use Case

5 requested AI solutions

Requested on: 18 August 2026

Requested by: Enzai

Reviewers:

Employee Resume Screening Assistant

Draft Use Case

5 requested AI solutions

Requested on: 19 June 2026

Requested by: Enzai

Reviewers: