SR 26-2 · OCC 2026-13 · MODEL RISK

SR 11-7 was rescinded in April 2026. The discipline was not.

Rescinded 17 April 2026, and with it the prescription and the enforceability - what survives is four areas and an argument you own.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
The rating has to change the treatment
Model inventory Tiering Effective challenge Monitoring Vendor models

Our promise

“An inventory is a list. Validation is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $25,000, and nothing is charged until you approve it.

Each additional system
$6,000
Re-audit, same scope
$16,000
Renewal, every twelve months
$21,000 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

US model risk, in three chapters

The Rescission

Fifteen years after SR 11-7 taught the industry what a model risk programme should look like, the agencies withdrew it. On 17 April 2026 the Federal Reserve issued SR 26-2 and the OCC its Bulletin 2026-13, rescinding it and five other supervisory issuances alongside it on the same day.

The Gap

Nothing you built is wasted — inventory, tiering, effective challenge, monitoring and documentation are all retained. What changed is the framing: tailoring throughout, no enforceable standard, four areas rather than three, and generative AI left outside the scope of the guidance altogether.

The Office

Our review reads the 2026 letters themselves rather than anybody’s summary of them. We take your estate through all four areas, say plainly what survives and what should now stop, and hand back the two artefacts that a 2011 programme could not have held at all.

What counts as a model?

Anything that turns data into an estimate.

A method turning theory and data into an estimate — and the arguments are always at the edges.

Who the guidance reaches № 01
  • Fed-supervised organisations above $30bn in total assets
  • National banks, savings associations, branches and agencies
  • Smaller firms whose model risk exposure is significant
  • Anyone running a BSA/AML model, now SR 21-8 has gone
SR 26-2 · iDharma · Presented for review
Where the calls get argued № 02
  • The complex spreadsheet nobody has ever called a model
  • A deterministic rules engine driving a real decision
  • A vendor score you are not permitted to see inside
  • Machine learning in - generative and agentic AI out
SR 26-2 · iDharma · Presented for review
Whose duty is it

The duty is yours. The model may not be.

You

The banking organisation

The inventory, the tiering, the validation, the monitoring and the governance are yours, and so is the new one: the written argument for why your programme is scaled the way it is. Tailoring is on the face of the 2026 guidance, so the scaling is now yours to set out and yours to defend in writing.

Your model vendor

The people who built the model

Answers to its own supervisors, not to yours. Many vendors do genuinely careful development work and will show you a validation report. The difficulty is not its quality - it is that it was written about their product rather than about your use of it, and on their own data rather than on yours.

The catch

When their validation is yours

Vendor and third-party products is now an area of the guidance in its own right, naming the validation of those products. You need documentation sufficient to validate without full disclosure, a position for when the vendor will not give it, and concentration risk written down where the board can see it.

What most teams assume

“The vendor validated it, so it’s validated.”

What the 2026 guidance says

Validating their product is now an area of yours.

It is the most common finding we write up.

  • Who it is for
  • Model risk management
  • Independent validation
  • Internal audit
  • Risk & compliance
  • Quant and data science teams
Why this matters in 2026
A black archive binder closed on a dark desk under a low lamp, a blank brass label plate screwed to its spine and a wax seal holding the page block shut, with a clipped sheet of figures, reading glasses and a fountain pen beside it: a supervisory letter closed for the last time.
01 SR 11-7 was rescinded on 17 April 2026, along with SR 21-8, three OCC bulletins and a Handbook booklet. A programme written to a withdrawn letter is not a compliant programme. It is a museum.
02

It sets no enforceable standard, and non-compliance alone draws no criticism. Safety and soundness still bites - the hook moved.

03

Generative and agentic AI are expressly out of scope here. Teams that folded them in anyway are validating what nobody has asked them for.

04

Three core elements became four areas. Vendor and third-party products is now one of the four, and it names their validation explicitly.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a supervisory call.

0 of 3

Supervised -

Size is the starting point, not the test. The revised guidance is expected to be most relevant above $30bn in total assets - and the OCC allows that it stays relevant below that where model risk exposure is significant.

The estate -

The line moved in April. Traditional machine learning that meets the model definition is inside the guidance. Generative and agentic AI are expressly outside it, with a separate request for information planned.

Written to -

Tailoring is now on the face of the guidance. That is an opportunity and a burden at once: the scaling you chose is yours to defend, and no 2011 control set contains the argument for it.

The transition

Four moves, and not in the order you’d guess.

Every one of these follows from a single April letter - so they run in sequence, and the third one is the one nobody budgets for.

  1. Rescinded

    17 April 2026

    SR 26-2 and OCC Bulletin 2026-13 replaced SR 11-7, SR 21-8, three OCC bulletins and a Handbook booklet.

  2. Reconcile

    First, not last

    The inventory against production. Every activity below it inherits its gaps and cannot be trusted until clean.

  3. Re-tailor

    The hard one

    Scale the programme to your risk profile and write down why. This is where the time goes: it means stopping.

  4. Re-house AI

    RFI to come

    Generative and agentic systems out of the model risk inventory and into a framework that actually fits.

The trap

Teams are comfortable adding controls and very uncomfortable removing them, so a 2011 control set survives intact under a 2026 framing. That is expensive - and now that tailoring is stated on the face of the guidance, it is harder to defend, not easier. Deciding what to stop is the work.

Requirement & coverage

What the guidance asks, what we ship

12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.

Firmwide model definition Area 3 - governance and controls
A definition your teams can apply, with worked calls on the borderline cases - spreadsheets, rules engines, vendor scores, and where generative AI now sits.
Model inventory Area 3 - reconciled to production
A register with owner, rating, purpose, status, dependencies and vendor provenance against every entry - and reconciled, not merely maintained.
Risk rating methodology Area 3 - and it must bite
A rating scheme applied across the estate, with the treatment each tier actually receives written down rather than implied.
Tailoring rationale New in 2026
The written argument for why your programme is scaled as it is - which the revised guidance invites and which nobody can produce from a 2011 control set.
Development standards Area 1 - development and use
Data, testing, documentation and limitation standards, each with the evidence the stage has to leave behind while it is still obvious.
Validation methodology Area 2 - validation and monitoring
Conceptual soundness and outcomes analysis scaled by rating, plus the effective-challenge argument written down rather than asserted.
Monitoring and thresholds Area 2 - after go-live
Metrics per model with thresholds, owners and an escalation route - and for ML models, drift and data-quality checks that run unprompted.
Governance and reporting Area 3 - board-visible
Named accountability, a policy set proportionate to the profile, and a board pack that presents model risk as a risk rather than a project status.
Vendor product validation Area 4 - new as an area
A validation approach for bought models that works without full source disclosure, and a documented position where the vendor will not supply.
BSA/AML models Folded in - SR 21-8 gone
The AML model population brought onto the same inventory and the same validation cycle, rather than governed beside it as it was until April.
AI scope position New in 2026
A written line between the ML models inside the guidance and the generative and agentic systems outside it - plus what governs those instead.
Transition assessment Readiness
A findings list against the revised guidance, showing what your SR 11-7 programme already satisfies and what it now over- or under-does.
The engagement

Model risk, independently reviewed

From a capital model to a spreadsheet nobody registered.

  1. Intake

    What is on the inventory, what is running, and where the two disagree.

  2. Test

    The four areas against your estate - development, validation, governance, vendor.

  3. Sign off and re-tailor

    You see the draft first. Then the findings, the gap list and the rationale - dated.

Request your review
An auditor in a royal-blue suit and open-collared white shirt, with a trimmed beard, standing against a warm pale wall and pointing into the open space alongside.
Model risk presented as a risk - not as a project status.
Struck in your favour

Why model risk teams choose iDharma for the transition

Genuinely independent

We build, resell and operate no models, and we take no fee tied to what the review concludes.

Written to the guidance

Every finding names the area of the guidance it sits in, so a validator can check it against the text.

We read the 2026 letters

Not a summary of them. The rescission list and the scope sentence came off the agencies' own pages.

We will tell you to stop

Most transition findings remove a control rather than add one. That is the saving nobody books.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Model risk readiness report

The full review against the revised guidance: what your programme already satisfies, what it now over-does, and what it never covered. Findings across all four areas, graded by consequence, plus the two things a 2011 programme cannot contain - a tailoring rationale and a written line around generative AI.

Workbook

Model inventory and tiering

A firmwide register reconciled to production, every model rated against materiality and complexity, so governance scales with the risk carried.

Reports

Validation report set

Purpose and scope, conceptual soundness, data review, outcomes analysis, findings and conclusion - one fixed structure, evidence linked.

Workbook

Monitoring plan

Process verification, benchmarking and outcomes analysis on a defined cadence, with warn, high and critical thresholds and an action per breach.

Memo

Vendor governance pack

The documentation to demand before deployment, the validation you must run yourself, and the contract hooks that make change notification enforceable.

HTML + PDF

Board and examiner pack

Per-tier status across inventory currency, validation coverage, monitoring and open findings - one pack for the board and the request list.

Ranked

Transition gap list

What survives the rescission, what to stop doing, and what to build - ranked by consequence rather than by how easy each one is to close.

Format & fee

Real numbers, upfront.

Scope
Your model estate, counted
Evidence
Inventory, validations, policies
Re-review
Every rolling twelve months - $21,000 against your known baseline

The estate is counted on a scoping call, so the fee is flat - nothing to meter, nothing charged until you approve.

Request this review
SR 26-2 · Named engagement $25,000 flat
  • Inventory reconciled and tiered
  • All four areas reviewed
  • Tailoring rationale, written
  • Transition gap list, ranked
Show your hand

Four things you have to be able to produce

Principles-based does not mean unexamined. Each of these is either on the table on the day someone asks, or it is not.

The register,
reconciled

One inventory, checked against what is actually running, every entry owned. Vendor products and the deterministic tools nobody in the building calls a model included.

The rating,
applied

A tier on every model that visibly changes how much validation and monitoring it receives. A rating that changes nothing downstream is a label rather than a control.

The dissent,
real

Reviewers with the competence, incentive and influence to cause a change - and at least one occasion on record where one of them said no and the no was heard.

The scaling,
argued

The written rationale for why the programme is sized as it is against your model risk profile. New in 2026, and no control set built on the 2011 guidance contains one.

Four cards, and the fourth one is new since April.

FAQ

Plain answers

What went, what survived, where AI sits now. Answered straight.

Request this review
Is SR 11-7 still in force?

No. On 17 April 2026 the Federal Reserve issued SR 26-2 and the OCC issued Bulletin 2026-13, and between them they rescind SR 11-7, SR 21-8, three OCC bulletins and the Comptroller's Handbook MRM booklet.

Do we have to rebuild our programme?

Almost certainly not. The disciplines are retained - inventory, tiering, development standards, validation with effective challenge, monitoring, governance. What changed is that they are principles tailored to your risk profile rather than a prescriptive set.

What are the penalties for not meeting it?

None attached to the guidance itself - it states that it does not set forth enforceable standards and that non-compliance will not result in supervisory criticism. Supervisory action still reaches unsafe or unsound practices.

Does it apply to AI and machine learning models?

Partly, and the line matters. Traditional machine learning that meets the model definition is inside the guidance. Generative AI and agentic AI models are expressly outside it, with a separate request for information planned.

How long does a review take?

Typically four to eight weeks from hand-over, driven by the size of the model estate and how much of the inventory already exists. Scope is agreed with you before anything is charged.

Get started

Request your readiness review

Tell us about your model estate and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have, and nothing we cannot work around if a piece of it is missing - the state of the first item is usually the finding rather than the obstacle.

  1. Your model inventory, in whatever state it is in
  2. The rating scheme, and what each tier should receive
  3. Two or three recent validation reports
  4. Which models came from a vendor, and what you hold
  5. Whether generative or agentic systems sit on it

What happens next

  1. You send the five items we need.
  2. A scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request your readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

What it means

  • The dates, the rescission list, the scope sentence, the enforceability language and the AI carve-out were read from the two 2026 letters themselves — not from a summary of them.
  • What each area asks for in practice is written from the discipline rather than quoted. Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • The revised guidance states that it does not set forth enforceable standards. Nothing on this page is legal advice, and none of it creates a professional relationship.
  • It covers this guidance alone - the EU AI Act and state law reach the same models.
  • Use it as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us