meilynx

Framework · Model risk

SR 26-2, applied to the models you actually run.

Since April 2026, SR 26-2 has defined how U.S. banking organizations inventory, monitor, document, and govern their models. It asks firms to defend their approach rather than follow a checklist, and Meilynx produces the evidence that defense needs.

What changed in April 2026

Principles over procedure.

The Federal Reserve, OCC, and FDIC issued SR 26-2 jointly on 17 April 2026, superseding the 2011 guidance. The three validation components, effective challenge, and documentation for independent review are unchanged; the burden moved from following a fixed process to defending an appropriate one.

What SR 26-2 changed

  • The fixed annual revalidation cycle gives way to a risk-based cadence tied to materiality, change velocity, and data availability.
  • A narrower model definition. Simple spreadsheets and deterministic rule engines fall out of scope.
  • Generative and agentic AI sit outside the formal scope, with institutions directed to govern them under existing risk-management principles anyway.
  • Proportionality is explicit. The letter is most relevant to banking organizations over $30 billion in total assets.
What the guidance expects

Inventory, monitor, document, govern.

A firm should know which models it runs, watch how they behave, document them well enough for independent review, and govern their use with real controls.

  • A complete, current model inventory.
  • Ongoing monitoring of how models are used and how they perform.
  • Documentation sufficient for an independent validator to review.
  • Governance and controls over model access and use, with effective challenge.
How Meilynx maps

Each expectation, to a control.

A specific Meilynx control for each expectation and the artifact it produces.

SR 26-2 → Meilynx controls

Maintain a complete inventory of models in use

SR 26-2 · Governance

Maps to · The model inventory is populated from live proxy traffic: every model, version, and the team calling it. A model in use cannot be missing from the list.

Examination artifact · Model inventory, generated from traffic

Ongoing monitoring of model use and performance

SR 26-2 · Ongoing monitoring

Maps to · The proxy records model, tokens, cost, latency, and governance findings on every call and surfaces anomalies as they appear.

Examination artifact · Monitoring telemetry and findings log

Controls and policy over model usage

SR 26-2 · Governance and controls

Maps to · Policy-as-code decides which models each team may use, enforced inline with role-based access, and readable by the people who own the control.

Examination artifact · Policy snapshot and access matrix

Documentation sufficient for independent review

SR 26-2 · Documentation

Maps to · A hash-chained, tamper-evident record of model use and every governance decision gives an independent validator or examiner durable documentation to review.

Examination artifact · Examination-ready audit trail

Effective challenge and change tracking

SR 26-2 · Effective challenge

Maps to · Versioned policy and an immutable record of what changed, when, and what it affected support the effective-challenge expectation around model controls.

Examination artifact · Versioned policy history

The examination artifact

What you hand to a validator.

The audit trail renders into a package built around the model risk reflex: a model inventory drawn from live traffic, the controls in force, and a tamper-evident record an independent reviewer can verify.

In the package

  • Model inventory, populated from traffic.
  • Control coverage across the monitoring period.
  • Versioned governance policy snapshot.
  • SHA-256 integrity hash over the audit chain.
FAQ

Model risk guidance and AI.

What is SR 26-2?

SR 26-2, Revised Guidance on Model Risk Management, was issued jointly by the Federal Reserve, OCC, and FDIC on 17 April 2026. It replaced SR 11-7 and SR 21-8 after fifteen years. The three validation components, effective challenge, and documentation sufficient for independent review all carried forward. The fixed annual revalidation cycle gave way to a risk-based cadence, and the definition of a model narrowed.

Are LLMs in scope for the model risk guidance?

SR 26-2 places generative and agentic AI outside its formal scope and directs institutions to govern them anyway, using existing risk-management principles: materiality, ongoing monitoring, and effective challenge. In practice an examiner still expects a written governance approach for LLM use, a current inventory, monitoring evidence, and a rationale you can defend. Meilynx produces the inventory, monitoring, and documentation evidence that approach requires.

Does Meilynx validate my models?

No. Statistical model validation stays with your model risk team. Meilynx supplies the inventory, monitoring telemetry, controls, and documentation that validation and examination depend on. It makes the evidence complete and tamper-evident; it does not replace the validator.

How does the model inventory stay current?

Meilynx sits inline in the request path, so every model call is observed as it happens. The inventory is derived from real traffic, which closes the gap manual inventories leave.

Examination package

See exactly what an examiner receives

Download a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.