meilynx

Reference · Model risk management

SR 26-2: Revised Guidance on Model Risk Management

Revised Guidance on Model Risk Management

Last reviewed August 14, 2026

SR 26-2 is the supervisory guidance governing how U.S. banking organizations identify, validate, monitor, and govern the models they rely on for credit decisions, capital calculations, regulatory reporting, stress testing, and BSA/AML compliance. It was issued jointly on 17 April 2026 by the Federal Reserve, the OCC, and the FDIC, and replaces SR 11-7 after fifteen years.

Who it applies to

Banking organizations supervised by the Federal Reserve, OCC, or FDIC. The guidance was published simultaneously by the three agencies — the first time they have issued a single model risk framework together — with the Federal Reserve's letter stating it is most relevant to banking organizations with over $30 billion in total assets.

Expectations scale to each institution's size, complexity, and model risk profile. Proportionality is stated explicitly, which matters most for mid-size and regional institutions that had been applying large-bank practices by default.

What it requires

  • A model inventory covering systems that meet the revised definition of a model.
  • Validation addressing conceptual soundness, ongoing monitoring, and outcomes analysis — the three components carried forward from SR 11-7.
  • Validation timing and intensity set by model materiality, change velocity, and data availability rather than a fixed annual cycle.
  • Effective challenge by parties with the competence, influence, and incentive to question model design and use.
  • Clear accountability for model ownership, use, review, and remediation.
  • Governance over models supplied by third parties, including documentation sufficient to support independent review.

What it does not cover

Generative AI and agentic AI are placed explicitly outside the scope of the guidance. The agencies direct institutions to apply existing risk management principles — materiality, ongoing monitoring, and effective challenge — to those systems instead.

This is the most consequential line in the document for anyone deploying LLMs or agents in a bank. There is no model risk rulebook for these systems. Institutions are expected to govern them anyway, using principles written for statistical models, and to be able to defend the approach they chose.

Control mapping

What a reviewer expects to be able to see.

ObligationWhat the system must doEvidence a reviewer expects
Model inventoryMaintain a current record of in-scope models with owner, purpose, materiality tier, and dependenciesInventory export with tiering rationale and change history
ValidationRecord conceptual soundness review, ongoing monitoring results, and outcomes analysis per modelValidation reports with dates, scope, findings, and remediation status
Risk-based cadenceTrigger review by materiality, model change, or data drift rather than calendar dateDocumented cadence policy and evidence the triggers fired as designed
Effective challengeCapture who reviewed, what they questioned, and how it was resolvedChallenge records showing substantive objections and their disposition
Third-party modelsTrack vendor models on the same inventory with documentation adequate for reviewVendor model documentation, validation scope, and limitation disclosures
GenAI and agentic systemsGovern under existing principles despite falling outside the guidanceA written governance approach, its rationale, and evidence it operates

Key dates

  • 4 April 2011SR 11-7 issued.
  • 9 April 2021SR 21-8, the interagency statement on BSA/AML model risk, issued.
  • 17 April 2026SR 26-2 issued, superseding SR 11-7 and SR 21-8, alongside companion issuances from the OCC (Bulletin 2026-13) and FDIC.

Primary sources

Common gaps

Where institutions most often struggle when examined against this guidance.

  • Scope drift. The narrower definition removes spreadsheets and rule engines, but dropping them without recording the decision leaves the change unexplainable. Document what left the inventory and why.
  • Triggers with no firing history. Risk-based cadence is only defensible with records showing the triggers were monitored and acted on. A trigger policy with no evidence reads worse than a calendar.
  • Challenge that leaves no trace. Minutes showing a committee met do not evidence challenge. Records of objections raised and how they were resolved do.
  • No stated position on generative and agentic AI. Out of scope does not mean ungoverned. With no written approach there is neither a rulebook to cite nor a decision to defend.
  • Vendor models held to a lower standard. They sit on the same inventory, and missing provider documentation is the institution's problem.

Last reviewed August 14, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.