Glossary

SR 11-7 and SR 26-2 (Model Risk Management)

SR 11-7 was superseded on 17 April 2026 by SR 26-2, which excludes generative and agentic AI from scope while requiring the institution’s own governance to cover them.

SR 11-7 was the Federal Reserve's supervisory letter on model risk management, issued in 2011 and for over a decade the reference text for how US banks inventory, validate and monitor the models they rely on. It is no longer current. On 17 April 2026 the Federal Reserve issued SR 26-2, Revised Guidance on Model Risk Management, which supersedes and replaces both SR 11-7 and SR 21-8. The OCC issued Bulletin 2026-13 the same day, rescinding Bulletin 2011-12; the FDIC rescinded FIL-22-2017.

Note also that SR 11-7 is frequently misattributed to the OCC. It was a Federal Reserve supervisory letter. The OCC's parallel document was Bulletin 2011-12.

The substance carried forward. A firm is expected to know which models it uses, to validate them by evaluating conceptual soundness and comparing outputs against real-world outcomes, to monitor them on an ongoing basis, and to govern all of it with clear policies, defined roles and accountable owners. Scope tightened in places — the model definition now turns on complexity, excluding simple arithmetic and deterministic rule-based processes — and loosened in others.

What changed for AI is the more consequential point. SR 26-2 states that generative AI and agentic AI models "are novel and rapidly evolving" and "are not within the scope of this guidance," while the principles it sets out "apply to traditional statistical and quantitative models and non-generative, non-agentic AI models." The supervisors looked at this class of system and declined to write rules for it.

The exclusion is not permission. The same paragraph instructs that "a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document." The obligation did not disappear. It relocated onto the institution, which now has to answer for what its agents did without a framework to point at while doing so.

Two further points that are routinely missed. SR 26-2 states that it "does not set forth enforceable standards or prescriptive requirements" and that non-compliance "will not result in supervisory criticism." And it is "expected to be most relevant to banking organizations with over $30 billion in total assets." Anyone presenting model risk guidance as a compliance mandate, before or after April 2026, was overstating what it was.

How it differs from FINRA Rule 3110. Model risk guidance asks whether a model is sound. FINRA 3110 asks whether the firm supervised the conduct, and it is an enforceable rule. A model can be well validated and still be used in a way no one supervised.

Examination readiness

What the carve-out means operationally

An institution running generative or agentic AI in 2026 has an obligation with no framework attached to it. The practical consequence is that the institution has to define its own controls and be able to show they operated — which is a heavier evidentiary burden than following a prescribed standard, not a lighter one. The supervisor did not lower the bar; it declined to say where the bar is.

What fills the gap is the institution’s own record: which models were in use, under which policy, with what authority granted to which agent. That is the subject of the examination readiness suite and sample examination reports. Supervision of conduct remains enforceable under FINRA Rule 3110, and the NIST AI RMF is the structure most institutions reach for in the absence of prescribed guidance. Agent authority is covered in the AI agent governance guide, and the sector view on the financial services page.

FINRA Rule 3110 · NIST AI RMF · Policy as code · FFIEC · Model drift · Full glossary

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs