Reference · Model risk management
SR 11-7 to SR 26-2: What Changed
What changed, and what did not
SR 26-2 preserves the core principles of SR 11-7 while changing how they are applied. Programs built against SR 11-7 do not need wholesale redesign, but several assumptions embedded in most existing frameworks no longer hold.
What changed
- Binding character. SR 11-7 used directive language and was enforced as de facto binding, with deviations driving Matters Requiring Attention. SR 26-2 states directly that it does not set forth enforceable standards or prescriptive requirements, and that non-compliance will not on its own result in supervisory criticism.
- Definition of a model. SR 11-7's definition was expansive enough to pull end-user spreadsheets and simple rule engines into scope. SR 26-2 excludes simple arithmetic calculations such as those found in spreadsheets, along with deterministic rule-based processes and software. The definition adds the word complex and requires the system to apply statistical, economic, or financial theory.
- Oversight cadence. The de facto annual revalidation cycle is replaced by a risk-based approach tied to model materiality, change velocity, and data availability.
- Validator independence. SR 11-7 strongly preferred organizational separation between validation and development. SR 26-2 decouples validation quality from reporting structure — rigor and objectivity matter more than where the validator sits.
- Proportionality. Tailoring to institution size, complexity, and model footprint is now explicit rather than implied.
- Length and register. SR 11-7 ran roughly twenty pages of prescriptive expectations. SR 26-2 is about half that and reads as principles rather than procedure.
- AI. SR 11-7 predated generative and agentic systems entirely. SR 26-2 names them and places them out of scope.
What did not change
- The three validation components: conceptual soundness, ongoing monitoring, and outcomes analysis.
- Effective challenge as the organising principle of independent review.
- Clear accountability for model ownership, use, review, and remediation.
- The expectation that documentation is sufficient for a reviewer to reconstruct what was done and why.
The practical shift
Under SR 11-7 the examiner's question was procedural: did the institution follow the required process? Under SR 26-2 it is substantive: was the approach appropriate, and can the institution defend it?
Migration checklist
- Re-scope the inventory against the narrower model definition, and decide separately whether to retain governance over items that fall out.
- Replace calendar-driven revalidation with documented, risk-based triggers.
- Update every internal reference from SR 11-7 to SR 26-2, including policies, procedures, and vendor documentation.
- Establish a written governance approach for generative and agentic AI, since the guidance no longer covers it and supervisors still expect it.
Key dates
- 4 April 2011SR 11-7 issued.
- 17 April 2026SR 26-2 issued, superseding SR 11-7, SR 21-8, and the corresponding OCC and FDIC issuances.
Primary sources
Common gaps
What tends to be missed during migration.
- Stale citations. SR 11-7 appears in policies, charters, vendor questionnaires, audit programmes, and marketing. Firms update the policy and miss the rest. SR 21-8 is superseded too, and missed more often.
- Treating non-binding as optional. Disclaiming enforceable standards does not remove the supervisory expectation. Relaxing controls leaves less to show, not less to prove.
- Removing the annual cycle before the replacement works. Risk-based triggers need monitoring infrastructure; drop the calendar first and nothing initiates review.
- Reading the independence change as permission to merge functions. Decoupling quality from reporting lines raises the bar on evidencing objectivity in substance.
- No record of the transition. Migration decisions are examinable. A dated memo covering what was re-scoped, what was retained, and why is worth more than the changes alone.
Related
Last reviewed August 14, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.