SR 11-7 was the Federal Reserve's supervisory letter on model risk management, issued in 2011 and for over a decade the reference text for how US banks inventory, validate and monitor the models they rely on. It is no longer current. On 17 April 2026 the Federal Reserve issued SR 26-2, Revised Guidance on Model Risk Management, which supersedes and replaces both SR 11-7 and SR 21-8. The OCC issued Bulletin 2026-13 the same day, rescinding Bulletin 2011-12; the FDIC rescinded FIL-22-2017.
Note also that SR 11-7 is frequently misattributed to the OCC. It was a Federal Reserve supervisory letter. The OCC's parallel document was Bulletin 2011-12.
The substance carried forward. A firm is expected to know which models it uses, to validate them by evaluating conceptual soundness and comparing outputs against real-world outcomes, to monitor them on an ongoing basis, and to govern all of it with clear policies, defined roles and accountable owners. Scope tightened in places — the model definition now turns on complexity, excluding simple arithmetic and deterministic rule-based processes — and loosened in others.
What changed for AI is the more consequential point. SR 26-2 states that generative AI and agentic AI models "are novel and rapidly evolving" and "are not within the scope of this guidance," while the principles it sets out "apply to traditional statistical and quantitative models and non-generative, non-agentic AI models." The supervisors looked at this class of system and declined to write rules for it.
The exclusion is not permission. The same paragraph instructs that "a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document." The obligation did not disappear. It relocated onto the institution, which now has to answer for what its agents did without a framework to point at while doing so.
Two further points that are routinely missed. SR 26-2 states that it "does not set forth enforceable standards or prescriptive requirements" and that non-compliance "will not result in supervisory criticism." And it is "expected to be most relevant to banking organizations with over $30 billion in total assets." Anyone presenting model risk guidance as a compliance mandate, before or after April 2026, was overstating what it was.
How it differs from FINRA Rule 3110. Model risk guidance asks whether a model is sound. FINRA 3110 asks whether the firm supervised the conduct, and it is an enforceable rule. A model can be well validated and still be used in a way no one supervised.
Ready to govern your AI infrastructure?
See how Smartflow gives regulated industries complete AI sovereignty.
Request a Demo View Documentation