Reference · Model risk management
SR 26-2: Revised Guidance on Model Risk Management
Revised Guidance on Model Risk Management
SR 26-2 is the supervisory guidance governing how U.S. banking organizations identify, validate, monitor, and govern the models they rely on for credit decisions, capital calculations, regulatory reporting, stress testing, and BSA/AML compliance. It was issued jointly on 17 April 2026 by the Federal Reserve, the OCC, and the FDIC, and replaces SR 11-7 after fifteen years.
Who it applies to
Banking organizations supervised by the Federal Reserve, OCC, or FDIC. The guidance was published simultaneously by the three agencies — the first time they have issued a single model risk framework together — with the Federal Reserve's letter stating it is most relevant to banking organizations with over $30 billion in total assets.
Expectations scale to each institution's size, complexity, and model risk profile. Proportionality is stated explicitly, which matters most for mid-size and regional institutions that had been applying large-bank practices by default.
What it requires
- A model inventory covering systems that meet the revised definition of a model.
- Validation addressing conceptual soundness, ongoing monitoring, and outcomes analysis — the three components carried forward from SR 11-7.
- Validation timing and intensity set by model materiality, change velocity, and data availability rather than a fixed annual cycle.
- Effective challenge by parties with the competence, influence, and incentive to question model design and use.
- Clear accountability for model ownership, use, review, and remediation.
- Governance over models supplied by third parties, including documentation sufficient to support independent review.
What it does not cover
Generative AI and agentic AI are placed explicitly outside the scope of the guidance. The agencies direct institutions to apply existing risk management principles — materiality, ongoing monitoring, and effective challenge — to those systems instead.
Control mapping
What a reviewer expects to be able to see.
| Obligation | What the system must do | Evidence a reviewer expects |
|---|---|---|
| Model inventory | Maintain a current record of in-scope models with owner, purpose, materiality tier, and dependencies | Inventory export with tiering rationale and change history |
| Validation | Record conceptual soundness review, ongoing monitoring results, and outcomes analysis per model | Validation reports with dates, scope, findings, and remediation status |
| Risk-based cadence | Trigger review by materiality, model change, or data drift rather than calendar date | Documented cadence policy and evidence the triggers fired as designed |
| Effective challenge | Capture who reviewed, what they questioned, and how it was resolved | Challenge records showing substantive objections and their disposition |
| Third-party models | Track vendor models on the same inventory with documentation adequate for review | Vendor model documentation, validation scope, and limitation disclosures |
| GenAI and agentic systems | Govern under existing principles despite falling outside the guidance | A written governance approach, its rationale, and evidence it operates |
Key dates
- 4 April 2011SR 11-7 issued.
- 9 April 2021SR 21-8, the interagency statement on BSA/AML model risk, issued.
- 17 April 2026SR 26-2 issued, superseding SR 11-7 and SR 21-8, alongside companion issuances from the OCC (Bulletin 2026-13) and FDIC.
Primary sources
Common gaps
Where institutions most often struggle when examined against this guidance.
- Scope drift. The narrower definition removes spreadsheets and rule engines, but dropping them without recording the decision leaves the change unexplainable. Document what left the inventory and why.
- Triggers with no firing history. Risk-based cadence is only defensible with records showing the triggers were monitored and acted on. A trigger policy with no evidence reads worse than a calendar.
- Challenge that leaves no trace. Minutes showing a committee met do not evidence challenge. Records of objections raised and how they were resolved do.
- No stated position on generative and agentic AI. Out of scope does not mean ungoverned. With no written approach there is neither a rulebook to cite nor a decision to defend.
- Vendor models held to a lower standard. They sit on the same inventory, and missing provider documentation is the institution's problem.
Related
Last reviewed August 14, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.