Fifteen years after SR 11-7 taught the industry what a model risk programme should look like, the agencies withdrew it. On 17 April 2026 the Federal Reserve issued SR 26-2 and the OCC its Bulletin 2026-13, rescinding it and five other supervisory issuances alongside it on the same day.
SR 11-7 was rescinded in April 2026. The discipline was not.
Rescinded 17 April 2026, and with it the prescription and the enforceability - what survives is four areas and an argument you own.
Our promise
“An inventory is a list. Validation is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $25,000, and nothing is charged until you approve it.
- Each additional system
- $6,000
- Re-audit, same scope
- $16,000
- Renewal, every twelve months
- $21,000 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditUS model risk, in three chapters
Nothing you built is wasted — inventory, tiering, effective challenge, monitoring and documentation are all retained. What changed is the framing: tailoring throughout, no enforceable standard, four areas rather than three, and generative AI left outside the scope of the guidance altogether.
Our review reads the 2026 letters themselves rather than anybody’s summary of them. We take your estate through all four areas, say plainly what survives and what should now stop, and hand back the two artefacts that a 2011 programme could not have held at all.
Anything that turns data into an estimate.
A method turning theory and data into an estimate — and the arguments are always at the edges.
- Fed-supervised organisations above $30bn in total assets
- National banks, savings associations, branches and agencies
- Smaller firms whose model risk exposure is significant
- Anyone running a BSA/AML model, now SR 21-8 has gone
- The complex spreadsheet nobody has ever called a model
- A deterministic rules engine driving a real decision
- A vendor score you are not permitted to see inside
- Machine learning in - generative and agentic AI out
The duty is yours. The model may not be.
The banking organisation
The inventory, the tiering, the validation, the monitoring and the governance are yours, and so is the new one: the written argument for why your programme is scaled the way it is. Tailoring is on the face of the 2026 guidance, so the scaling is now yours to set out and yours to defend in writing.
The people who built the model
Answers to its own supervisors, not to yours. Many vendors do genuinely careful development work and will show you a validation report. The difficulty is not its quality - it is that it was written about their product rather than about your use of it, and on their own data rather than on yours.
When their validation is yours
Vendor and third-party products is now an area of the guidance in its own right, naming the validation of those products. You need documentation sufficient to validate without full disclosure, a position for when the vendor will not give it, and concentration risk written down where the board can see it.
“The vendor validated it, so it’s validated.”
Validating their product is now an area of yours.
It is the most common finding we write up.
- Who it is for
- Model risk management
- Independent validation
- Internal audit
- Risk & compliance
- Quant and data science teams
It sets no enforceable standard, and non-compliance alone draws no criticism. Safety and soundness still bites - the hook moved.
Generative and agentic AI are expressly out of scope here. Teams that folded them in anyway are validating what nobody has asked them for.
Three core elements became four areas. Vendor and third-party products is now one of the four, and it names their validation explicitly.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a supervisory call.
Your scope check
Four moves, and not in the order you’d guess.
Every one of these follows from a single April letter - so they run in sequence, and the third one is the one nobody budgets for.
-
Rescinded
17 April 2026SR 26-2 and OCC Bulletin 2026-13 replaced SR 11-7, SR 21-8, three OCC bulletins and a Handbook booklet.
-
Reconcile
First, not lastThe inventory against production. Every activity below it inherits its gaps and cannot be trusted until clean.
-
Re-tailor
The hard oneScale the programme to your risk profile and write down why. This is where the time goes: it means stopping.
-
Re-house AI
RFI to comeGenerative and agentic systems out of the model risk inventory and into a framework that actually fits.
Teams are comfortable adding controls and very uncomfortable removing them, so a 2011 control set survives intact under a 2026 framing. That is expensive - and now that tailoring is stated on the face of the guidance, it is harder to defend, not easier. Deciding what to stop is the work.
What the guidance asks, what we ship
12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.
- Firmwide model definition Area 3 - governance and controls
- A definition your teams can apply, with worked calls on the borderline cases - spreadsheets, rules engines, vendor scores, and where generative AI now sits.
- Model inventory Area 3 - reconciled to production
- A register with owner, rating, purpose, status, dependencies and vendor provenance against every entry - and reconciled, not merely maintained.
- Risk rating methodology Area 3 - and it must bite
- A rating scheme applied across the estate, with the treatment each tier actually receives written down rather than implied.
- Tailoring rationale New in 2026
- The written argument for why your programme is scaled as it is - which the revised guidance invites and which nobody can produce from a 2011 control set.
- Development standards Area 1 - development and use
- Data, testing, documentation and limitation standards, each with the evidence the stage has to leave behind while it is still obvious.
- Validation methodology Area 2 - validation and monitoring
- Conceptual soundness and outcomes analysis scaled by rating, plus the effective-challenge argument written down rather than asserted.
- Monitoring and thresholds Area 2 - after go-live
- Metrics per model with thresholds, owners and an escalation route - and for ML models, drift and data-quality checks that run unprompted.
- Governance and reporting Area 3 - board-visible
- Named accountability, a policy set proportionate to the profile, and a board pack that presents model risk as a risk rather than a project status.
- Vendor product validation Area 4 - new as an area
- A validation approach for bought models that works without full source disclosure, and a documented position where the vendor will not supply.
- BSA/AML models Folded in - SR 21-8 gone
- The AML model population brought onto the same inventory and the same validation cycle, rather than governed beside it as it was until April.
- AI scope position New in 2026
- A written line between the ML models inside the guidance and the generative and agentic systems outside it - plus what governs those instead.
- Transition assessment Readiness
- A findings list against the revised guidance, showing what your SR 11-7 programme already satisfies and what it now over- or under-does.
Model risk, independently reviewed
From a capital model to a spreadsheet nobody registered.
-
Intake
What is on the inventory, what is running, and where the two disagree.
-
Test
The four areas against your estate - development, validation, governance, vendor.
-
Sign off and re-tailor
You see the draft first. Then the findings, the gap list and the rationale - dated.
Why model risk teams choose iDharma for the transition
Genuinely independent
We build, resell and operate no models, and we take no fee tied to what the review concludes.
Written to the guidance
Every finding names the area of the guidance it sits in, so a validator can check it against the text.
We read the 2026 letters
Not a summary of them. The rescission list and the scope sentence came off the agencies' own pages.
We will tell you to stop
Most transition findings remove a control rather than add one. That is the saving nobody books.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Model risk readiness report
The full review against the revised guidance: what your programme already satisfies, what it now over-does, and what it never covered. Findings across all four areas, graded by consequence, plus the two things a 2011 programme cannot contain - a tailoring rationale and a written line around generative AI.
Model inventory and tiering
A firmwide register reconciled to production, every model rated against materiality and complexity, so governance scales with the risk carried.
Validation report set
Purpose and scope, conceptual soundness, data review, outcomes analysis, findings and conclusion - one fixed structure, evidence linked.
Monitoring plan
Process verification, benchmarking and outcomes analysis on a defined cadence, with warn, high and critical thresholds and an action per breach.
Vendor governance pack
The documentation to demand before deployment, the validation you must run yourself, and the contract hooks that make change notification enforceable.
Board and examiner pack
Per-tier status across inventory currency, validation coverage, monitoring and open findings - one pack for the board and the request list.
Transition gap list
What survives the rescission, what to stop doing, and what to build - ranked by consequence rather than by how easy each one is to close.
Real numbers, upfront.
- Scope
- Your model estate, counted
- Evidence
- Inventory, validations, policies
- Re-review
- Every rolling twelve months - $21,000 against your known baseline
The estate is counted on a scoping call, so the fee is flat - nothing to meter, nothing charged until you approve.
Request this review- Inventory reconciled and tiered
- All four areas reviewed
- Tailoring rationale, written
- Transition gap list, ranked
Four things you have to be able to produce
Principles-based does not mean unexamined. Each of these is either on the table on the day someone asks, or it is not.
The register,
reconciled
One inventory, checked against what is actually running, every entry owned. Vendor products and the deterministic tools nobody in the building calls a model included.
The rating,
applied
A tier on every model that visibly changes how much validation and monitoring it receives. A rating that changes nothing downstream is a label rather than a control.
The dissent,
real
Reviewers with the competence, incentive and influence to cause a change - and at least one occasion on record where one of them said no and the no was heard.
The scaling,
argued
The written rationale for why the programme is sized as it is against your model risk profile. New in 2026, and no control set built on the 2011 guidance contains one.
Four cards, and the fourth one is new since April.
Plain answers
What went, what survived, where AI sits now. Answered straight.
Request this reviewIs SR 11-7 still in force?
No. On 17 April 2026 the Federal Reserve issued SR 26-2 and the OCC issued Bulletin 2026-13, and between them they rescind SR 11-7, SR 21-8, three OCC bulletins and the Comptroller's Handbook MRM booklet.
Do we have to rebuild our programme?
Almost certainly not. The disciplines are retained - inventory, tiering, development standards, validation with effective challenge, monitoring, governance. What changed is that they are principles tailored to your risk profile rather than a prescriptive set.
What are the penalties for not meeting it?
None attached to the guidance itself - it states that it does not set forth enforceable standards and that non-compliance will not result in supervisory criticism. Supervisory action still reaches unsafe or unsound practices.
Does it apply to AI and machine learning models?
Partly, and the line matters. Traditional machine learning that meets the model definition is inside the guidance. Generative AI and agentic AI models are expressly outside it, with a separate request for information planned.
How long does a review take?
Typically four to eight weeks from hand-over, driven by the size of the model estate and how much of the inventory already exists. Scope is agreed with you before anything is charged.
Request your readiness review
Tell us about your model estate and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have, and nothing we cannot work around if a piece of it is missing - the state of the first item is usually the finding rather than the obstacle.
- Your model inventory, in whatever state it is in
- The rating scheme, and what each tier should receive
- Two or three recent validation reports
- Which models came from a vendor, and what you hold
- Whether generative or agentic systems sit on it
What happens next
- You send the five items we need.
- A scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- SR 26-2 - Revised Guidance (Fed)
- OCC Bulletin 2026-13 - Revised Guidance
- SR 11-7 - the 2011 guidance (rescinded)
- In force from
- 17 April 2026
- SR 11-7 rescinded
- 17 April 2026
What it means
- The dates, the rescission list, the scope sentence, the enforceability language and the AI carve-out were read from the two 2026 letters themselves — not from a summary of them.
- What each area asks for in practice is written from the discipline rather than quoted. Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- The revised guidance states that it does not set forth enforceable standards. Nothing on this page is legal advice, and none of it creates a professional relationship.
- It covers this guidance alone - the EU AI Act and state law reach the same models.
- Use it as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom