SR 11-7 RESCINDED · SR 26-2 AND OCC BULLETIN 2026-13 · ISSUED 17 APRIL 2026

Model risk management, run as one program.

US model risk guidance was rewritten in April 2026. The disciplines survive — a firmwide inventory, risk-based tiering, sound development, independent validation with effective challenge, and ongoing monitoring — but they are now principles tailored to your model risk profile, they are expressly not enforceable standards, and generative AI has been carved out of scope entirely.


A printed model analysis with charts and a summary table on a dark desk, beside a calculator and a pen Illustrative materials
The disciplines survived the rewrite. The framing did not.
Model inventory Risk rating Effective challenge Outcomes analysis Third-party models
Where it stands

What happened to SR 11-7

Fifteen years of supervisory practice were rewritten in a single April. Most of what you built survives — but not the reason you were told to build it.

SR 11-7 was rescinded on 17 April 2026. The Federal Reserve issued SR 26-2 and the OCC issued Bulletin 2026-13, and between them they withdraw the 2011 guidance along with SR 21-8 and OCC Bulletin 2021-19 on BSA/AML models, OCC Bulletin 1997-24 on credit scoring, and the Model Risk Management booklet of the Comptroller’s Handbook.

The disciplines are retained. A firmwide model inventory, risk-based rating, sound development and testing, independent validation with effective challenge, ongoing monitoring, and governance with real accountability all remain what the agencies expect to see. If you have been running a competent programme, you have not wasted the decade.

Three things did change, and each of them changes work. The guidance is now principles-based and explicitly tailored to your model risk profile and the size and complexity of your operations. It states that it does not set forth enforceable standards, and that non-compliance with it will not itself draw supervisory criticism. And it is organised around four areas rather than three core elements, with vendor and third-party products promoted to one of them.

The change most likely to catch a governance team is the last one in the comparison below: generative AI and agentic AI are outside the scope of this guidance. The agencies call them novel and rapidly evolving and have committed to a separate request for information. Traditional machine learning that meets the model definition is still in.

Rescinded 17 Apr 2026

SR 11-7 had stood since 4 April 2011. SR 26-2 and OCC Bulletin 2026-13 replace it and four other issuances.

Most relevant Over $30bn

In total assets — though the OCC allows relevance below that where model risk exposure is significant.

Who the guidance reaches

  • Fed-supervised banking organisations

    SR 26-2 is expected to be most relevant to organisations with over $30 billion in total assets regulated by the Federal Reserve.

  • National banks and federal savings associations

    OCC Bulletin 2026-13 addresses all national banks, federal savings associations and federal branches and agencies, with the same practical focus above $30 billion.

  • Smaller institutions with real model risk

    The OCC allows that the guidance may still be relevant below the threshold where an institution’s model risk exposure is significant. Size is the starting point, not the test.

  • Anyone running a BSA/AML model

    SR 21-8 and OCC Bulletin 2021-19 were rescinded too, so BSA/AML model risk now sits inside this single framework rather than beside it.

  • Firms relying on vendor models

    Vendor and third-party products are now their own area of the guidance, including their validation — a promotion from a paragraph to a heading.

  • Everyone with an SR 11-7 programme

    Which is most of the market. Nothing you built is wasted, but the framing it was written against no longer exists — see the comparison below.

Side by side

SR 11-7 vs SR 26-2: what changed

Twelve rows. Four of them change what a model risk team does on Monday; the rest are the context that explains why.

Comparison of SR 11-7 and the 2026 revised model risk management guidance
Attribute SR 11-7 2011 — rescinded SR 26-2 With OCC Bulletin 2026-13 — current
Instrument SR 11-7 (Fed) and OCC Bulletin 2011-12 SR 26-2 (Fed) and OCC Bulletin 2026-13
Issued 4 April 2011 17 April 2026
Status Rescinded Superseded in full Current The guidance in force
Also withdrawn SR 21-8 and OCC Bulletin 2021-19 (BSA/AML models), OCC Bulletin 1997-24 (credit scoring), and the Comptroller’s Handbook MRM booklet All of it folded into one framework
Character Widely read as prescriptive, and examined that way Principles-based, tailored to your model risk profile and the size and complexity of operations
Enforceability Guidance in form, treated as a standard in practice Does not set forth enforceable standards or prescriptive requirements; non-compliance will not itself result in supervisory criticism
Structure Three core elements: development, validation, governance Four areas — development and use, validation and monitoring, governance and controls, and vendor and third-party products
Vendor models Covered, inside the governance discussion Their own area, including validation of third-party products
Stated focus All models, with proportionality left largely to examiners Most relevant above $30 billion in total assets, with tailoring stated on the face of the guidance
Generative and agentic AI In scope where the tool met the model definition Out of scope Novel and rapidly evolving; a separate request for information is planned
Traditional ML In scope on the model definition Still in scope on the model definition
What survives Inventory, tiering, effective challenge, documentation, monitoring All of it. The disciplines are retained; what changed is how prescriptively they are expressed

The hardest part of this transition is deciding what to stop. Teams add controls comfortably and remove them reluctantly, so the usual outcome is a 2011 control set surviving intact under a 2026 heading. That is expensive, and now that tailoring is stated on the face of the guidance it is also harder to defend than it looks: “we do all of it” is no longer self-evidently the safe answer.

The framework

The four areas of the revised guidance

Three of them are SR 11-7’s core elements under new headings. The fourth is the promotion: vendor and third-party products, including their validation.

Area 1

Model development and use

Building the model well, testing it honestly, and being clear about what it may and may not be used for. Includes testing, which the 2026 guidance names explicitly.

  • Purpose and intended use documented before build
  • Data quality, relevance and lineage evidenced
  • Method selection with rejected alternatives recorded
  • Development testing against the intended use
  • Documentation a successor could rebuild from
  • Stated limitations and out-of-scope uses
Area 2

Model validation and monitoring

Conceptual soundness and outcomes analysis, carried out with effective challenge — and then monitoring that keeps answering the question after go-live.

  • Evaluation of conceptual soundness
  • Outcomes analysis, including back-testing where it applies
  • Ongoing monitoring and process verification
  • Benchmarking against alternatives
  • Effective challenge by competent, influential reviewers
  • Findings tracked to closure with owners and dates
Area 3

Governance and controls

Policies, roles, accountability and the reporting that lets a board see model risk as a risk rather than as a project status.

  • Board and senior management responsibilities defined
  • Policies and standards proportionate to the risk profile
  • A model inventory that is reconciled and owned
  • Risk ratings that change how a model is treated
  • Change control and re-approval triggers
  • Internal audit’s role in assessing the framework
Area 4

Vendor and third-party products

Promoted from a paragraph inside governance to an area of its own — including the validation of third-party products, which is the part firms most often assume the vendor has done.

  • Third-party models on the same inventory as your own
  • Documentation sufficient to validate without full disclosure
  • Validation of the vendor product, not just of your use of it
  • Contractual hooks for change and version notification
  • A position on what you do when the vendor will not supply
  • Concentration risk where one supplier serves many models
Expectations

What the guidance expects you to do

Eight practical asks behind the four areas. The chips are themes, not citations — the revised guidance is principles-based and does not number its expectations.

Inventory

Maintain a firmwide model inventory

Reconciled to what is actually running, owned entry by entry, and covering vendor products and the deterministic tools nobody calls a model.

Tailoring

Scale the programme to your risk profile

The 2026 guidance says tailoring on its face rather than leaving it to an examiner. That is an opportunity and a burden: you now have to be able to defend the scaling you chose.

Development

Build, test and document to a standard

Data, method, testing and limitations recorded while they are still obvious to the people who chose them — not reconstructed for a validation cycle two years later.

Validation

Validate with effective challenge

Critical analysis by objective, informed parties with the competence, incentive and influence to identify limitations and cause something to change.

Monitoring

Monitor after go-live

Process verification, benchmarking and outcomes analysis on a defined cadence, with thresholds that fire and a route from a breach to a decision.

Governance

Give model risk an owner and a report

Named accountability, policies proportionate to the profile, and reporting that reaches the board in a form it can act on.

Third party

Govern vendor models as your own

On the inventory, tiered, validated and monitored — and with the documentation secured before deployment rather than requested during an examination.

Evidence

Leave a record at every step

A control with no artefact is a control an examiner cannot see. This has not changed and it is not going to.

Risk rating

Tier your models, then calibrate the rigour

The revised guidance takes a risk-based approach tailored to your model risk profile. Tiering is how most firms operationalise that — and now they have to be able to justify it.

Tier 1

Highest model risk

Regulatory capital, financial reporting and anything whose failure moves a published number.

  • Full independent validation before use
  • Annual revalidation at minimum
  • Board-visible reporting
  • Tight change control and re-approval
Tier 2

Material but contained

Meaningful impact within a portfolio, product or process, without firmwide consequence.

  • Independent review scoped to the risk
  • Periodic revalidation on a defined cycle
  • Monitoring with escalation thresholds
  • Documented approval to deploy
Tier 3

Lower model risk

Limited impact, readily overridden, or informing a decision a person still owns.

  • Proportionate review, not full validation
  • Inventory entry with a named owner
  • Light monitoring against expectations
  • Re-tiered if the use changes

Three tiers is a pattern, and the 2026 guidance mandates no methodology at all. It asks for an approach tailored to your model risk profile and leaves the mechanism to you. Most firms land on three bands; if you do, the defensible part is not the number of bands but the written reasoning for where the boundaries sit and what each tier actually receives.

Gaps

Where most model risk programmes fall short

Six of these predate the rewrite. The last two are new, and both come from reading April 2026 too quickly in opposite directions.

The inventory is not reconciled

A register maintained by one person and never checked against production. Every downstream activity inherits its gaps, and none of them can be trusted.

Validation is a document review

Reading the developer’s work and agreeing with it is not effective challenge. The test is competence, incentive and influence — and whether anything has ever changed as a result.

Monitoring is annual and retrospective

Performance reviewed once a year in a committee pack. Without thresholds that fire, the first signal is a business outcome rather than a metric.

Tiering does not change the treatment

Every model rated and then every model governed identically. If Tier 3 receives the Tier 1 programme, the rating is a label rather than a control.

Vendor models are taken on trust

Now a sharper failure than it was: third-party products are their own area of the 2026 guidance, and their validation is explicitly your problem.

Documentation is written for the file

Documents produced to satisfy a checklist rather than to let a successor rebuild the model. The difference shows within ten minutes of an examiner opening one.

The programme is still built to 2011

Prescriptive controls carried forward without asking whether they fit the firm’s actual risk profile. Tailoring is now stated on the face of the guidance; not using it is a choice you should be making deliberately.

Generative AI got quietly folded in

Teams that added a GenAI validation track to the model risk programme are now governing something the guidance expressly excludes — without the AI-specific framework the agencies have said is coming.

How we help

How iDharma supports model risk management

Inventory, tiering, validation, monitoring, revalidation and reporting in one audit-logged workflow — each piece answering a named area of the guidance.

Model inventory and tiering

A firmwide inventory reconciled to production, every model rated against materiality and complexity, so the governance each one receives scales with the risk it carries.

Addresses: Area 3

Independent validation reports

A fixed report structure — purpose and scope, conceptual soundness, data review, outcomes analysis, findings and conclusion — with evidence links and findings logged by severity, produced with genuine effective challenge.

Addresses: Area 2

Ongoing monitoring

Process verification, benchmarking and outcomes analysis on a defined cadence, with warn, high and critical thresholds and a configured action per breach.

Addresses: Area 2

Revalidation triggers

A breach, a material change, a tier increase or a scheduled review opens a validation task on its own, with an append-only log of what changed and when.

Addresses: Areas 1 and 2

Vendor model governance

The documentation set to demand before deployment, the validation you must perform yourself, and the contractual hooks that make change notification enforceable.

Addresses: Area 4

Board and examiner reporting

A per-tier status across inventory currency, validation coverage, monitoring activity and open findings — the same pack that answers the board and the examination request.

Addresses: Area 3

Every rating decision, validation, breach and revalidation is timestamped and audit-logged. That matters more, not less, now that the guidance is principles-based: when the standard is “appropriate to your risk profile”, the record of what you decided and why is the whole of your answer.

Requirement & coverage

Expectations, mapped to what we build

Twelve requirements with the area each belongs to, and the artefact that discharges it — including the three that only exist because of the 2026 rewrite.

Firmwide model definition Area 3
A definition your teams can apply, with worked calls on the borderline cases — spreadsheets, rules engines, vendor scores, and where generative AI now sits.
Model inventory Area 3
A register reconciled to production, with owner, rating, purpose, status, dependencies and vendor provenance against every entry.
Risk rating methodology Area 3
A rating scheme applied across the estate, with the treatment each tier actually receives written down rather than implied.
Tailoring rationale New in 2026
The written argument for why your programme is scaled as it is — which the revised guidance invites and which nobody can produce from a 2011 control set.
Development standards Area 1
Data, testing, documentation and limitation standards, each with the evidence the stage has to leave behind.
Validation methodology Area 2
Conceptual soundness and outcomes analysis scaled by rating, plus the effective-challenge argument written rather than asserted.
Monitoring and thresholds Area 2
Metrics per model with thresholds, owners and an escalation route — and for ML models, drift and data-quality checks that run unprompted.
Governance and reporting Area 3
Named accountability, a policy set proportionate to the profile, and a board pack that presents model risk as a risk.
Vendor product validation Area 4
A validation approach for bought models that works without full source disclosure, and a documented position where the vendor will not supply.
BSA/AML models Folded in
The AML model population brought onto the same inventory and the same validation cycle, now that SR 21-8 has gone.
AI scope position New in 2026
A written line between the ML models inside the guidance and the generative and agentic systems outside it — plus what governs those instead.
Transition assessment Readiness
A findings list against the revised guidance, showing what your SR 11-7 programme already satisfies and what it now over- or under-does.
AI and ML

Where AI sits after the rewrite

This is the part most pages about SR 11-7 now state backwards. The line runs between traditional machine learning and generative systems, and it is worth getting right.

Traditional ML is still in scope

A gradient-boosted credit model or a churn classifier is a model on the definition, and the four areas apply to it exactly as they apply to a regression.

Generative and agentic AI are not

The 2026 guidance places them outside its scope as novel and rapidly evolving, and the agencies have committed to a separate request for information first.

The gap is yours to fill

Out of scope is not ungoverned. Safety and soundness, consumer protection and your own risk appetite all still reach a generative system — just not through this guidance.

The generative AI carve-out, in both directions

The 2026 guidance places generative AI and agentic AI models outside its scope, describing them as novel and rapidly evolving, and the agencies have committed to a separate request for information before addressing them. That is a deliberate gap, not an oversight — and it can be misread two ways.

Read one way, a firm keeps a generative assistant inside its model risk inventory and spends validation capacity on something no supervisor is currently asking it to validate that way. Read the other, a firm hears “out of scope” and stops governing it — when safety and soundness, consumer protection, fair lending and third-party risk all still reach the same system.

The useful position is a written line: which systems are models under this guidance, which are generative systems governed under something else, and what that something else is until the agencies publish.

Supervision

How it is supervised now

The old answer was MRAs and MRIAs for failing to follow the guidance. That answer is no longer right, and the new one is less comfortable than it first sounds.

Not this

Not through the guidance

The revised guidance says in terms that it does not set forth enforceable standards or prescriptive requirements, and that non-compliance with it will not itself result in supervisory criticism.

But this

Through safety and soundness

Supervisory action remains available where weak model risk management amounts to an unsafe or unsound practice. The hook moved; it did not disappear.

And this

Through the consequences of a bad model

A mispriced portfolio, a misstated capital number or a discriminatory outcome is examined on its own terms — and the state of your model risk programme is the first thing anyone asks about afterwards.

“Not enforceable” is not the relief it sounds like. Under SR 11-7 you could satisfy an examiner by pointing at the guidance and showing you had done what it said. Under principles tailored to your own risk profile, the thing being examined is your judgement — and judgement is only defensible if you wrote down what you decided and why at the time.

The target state

What examiner-ready looks like

Four tests, phrased the way an examiner asks them. Deliberately not four percentages — a coverage score in this position is a claim about a product, and none of these four is ours to score.

Inventory

Complete and reconciled

One register, reconciled to production, every entry owned — vendor products and deterministic tools included.

Tiering

Applied and consequential

A rating on every model, visibly changing how much validation and monitoring each one receives.

Validation

Challenging, not confirming

Effective challenge you can evidence, findings tracked to closure, and an occasion where validation changed an outcome.

Tailoring

Chosen and defensible

A written rationale for why the programme is scaled as it is against your model risk profile.

Questions

Frequently asked questions

What is in force, what it costs to get wrong, and where AI actually sits.

1 What the guidance is now
Is SR 11-7 still in force?

No. On 17 April 2026 the Federal Reserve issued SR 26-2 and the OCC issued Bulletin 2026-13, and between them they rescind SR 11-7, SR 21-8 on BSA/AML models, OCC Bulletins 2011-12, 2021-19 and 1997-24, and the Model Risk Management booklet of the Comptroller’s Handbook.

Do we have to rebuild our programme?

Almost certainly not. The disciplines are retained — inventory, tiering, development standards, validation with effective challenge, monitoring, governance. What changed is that they are now expressed as principles tailored to your risk profile rather than as a prescriptive set. Most firms need a re-framing and a tailoring rationale, not a rebuild.

Who does the revised guidance apply to?

It is expected to be most relevant to banking organisations with more than $30 billion in total assets. The OCC bulletin addresses all national banks, federal savings associations and federal branches and agencies, and allows that it may still be relevant below the threshold where model risk exposure is significant.

What happened to the three core elements?

They became four areas. Development and use, validation and monitoring, and governance and controls survive; vendor and other third-party products was promoted from a discussion inside governance to an area of its own, including the validation of those products.

2 Enforcement and AI
What are the penalties for not meeting it?

There are none attached to the guidance itself. It states that it does not set forth enforceable standards or prescriptive requirements and that non-compliance will not result in supervisory criticism. That is a real change from how SR 11-7 was examined — but supervisory action remains available where weak model risk management is an unsafe or unsound practice, and a bad model outcome is still examined on its own terms.

Does it apply to AI and machine learning models?

Partly, and the line matters. Traditional machine learning that meets the model definition is inside the guidance like anything else. Generative AI and agentic AI models are expressly outside it — the agencies describe them as novel and rapidly evolving and have committed to a separate request for information before addressing them.

So generative AI is unregulated?

No — it is unaddressed by this particular guidance. Safety and soundness, consumer protection, fair lending, third-party risk management and your own risk appetite all still reach a generative system. What you do not yet have is a model-risk-shaped framework telling you how to validate one.

Should we stop governing our GenAI systems then?

Certainly not, and this is the mistake we expect to see most. Take them out of the model risk inventory if that is where they were forced, govern them under a framework that actually fits, and be ready to move again when the agencies publish. Building a validation programme for something nobody is asking you to validate is expensive; assuming a control exists when it does not is worse.

3 The engagement
How does this compare with SS1/23 and OSFI E-23?

They are the same object for three supervisors, and the US has just moved furthest towards principles. SS1/23 keeps a named senior manager and an annual self-assessment; OSFI E-23 keeps a five-stage lifecycle. A firm running any one of them is most of the way to the others.

Where do transition programmes lose time?

Deciding what to stop doing. Teams are comfortable adding controls and very uncomfortable removing them, so a 2011 control set survives intact under a 2026 framing — which is expensive and, since tailoring is now explicit, harder to defend than it looks.

What does an iDharma review cost and how long does it take?

It is scoped before you are charged. The variables are the size of the model estate, how much of the inventory already exists, and whether generative systems have been folded into the model risk programme; we tell you the shape of all three after a short scoping call.

Ready when you are

Run your model risk program the way examiners expect

A review gives you the inventory, the rating scheme with its treatment set, the validation methodology, a written tailoring rationale and a clear line around generative AI — scoped before you are charged.

This page is guidance on how we scope a model risk review, not regulatory advice. The revised guidance is principles-based and expressly not a set of enforceable standards, which makes more of it arguable rather than less; where a call is genuinely open we say so in writing rather than pick the convenient answer.