# SR 11-7 vs SR 26-2: What Changed in Bank Model Risk Guidance

Source: https://www.bankingnewsai.com/ai-regulation/compare/sr-11-7-vs-sr-26-2
Last updated: Sep 24, 2026

## What is the difference between SR 11-7 and SR 26-2?

SR 26-2, issued April 17, 2026 by the Federal Reserve, OCC (Bulletin 2026-13) and FDIC (FIL-15-2026), supersedes SR 11-7. The biggest change is scope: a model is now a "complex" quantitative method, spreadsheet arithmetic and deterministic rule-based processes with no underpinning theory are excluded, generative and agentic AI are "not within the scope of this guidance", and it is "expected to be most relevant" to banks with over $30 billion in assets. Validation, effective challenge, governance, inventory and vendor-model expectations carry over, and non-compliance "will not result in supervisory criticism". [1][2][3][4]

## At a glance

|  | SR 11-7 (2011) | SR 26-2 (2026) |
| --- | --- | --- |
| Instrument | Supervisory Guidance on Model Risk Management — Federal Reserve SR 11-7 / OCC Bulletin 2011-12 (April 4, 2011); FDIC FIL-22-2017 | Revised Guidance on Model Risk Management — Federal Reserve SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026 (April 17, 2026) |
| Status | Superseded Apr 17, 2026 | In force since Apr 17, 2026 |
| In the tracker | [SR 11-7](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-11-7), [OCC Bulletin 2011-12](https://www.bankingnewsai.com/ai-regulation/documents/occ-bulletin-2011-12) ([Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve), [OCC](https://www.bankingnewsai.com/ai-regulation/occ), [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic)) | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2), [OCC Bulletin 2026-13](https://www.bankingnewsai.com/ai-regulation/documents/occ-bulletin-2026-13), [FDIC FIL-15-2026](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-15-2026) ([Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve), [OCC](https://www.bankingnewsai.com/ai-regulation/occ), [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic)) |

## How do SR 11-7 and SR 26-2 differ, point by point?

| Dimension | SR 11-7 (2011) | SR 26-2 (2026) |
| --- | --- | --- |
| Status | Issued April 4, 2011 by the Federal Reserve and the OCC. Superseded and replaced on April 17, 2026. [5][1] | Issued April 17, 2026 by the Federal Reserve, OCC and FDIC; "supersedes and replaces" SR 11-7 and SR 21-8, the 2021 BSA/AML model risk statement. [1] |
| Issued as | Federal Reserve SR 11-7 and OCC Bulletin 2011-12. The FDIC adopted the same guidance "with technical conforming changes" in FIL-22-2017 (June 7, 2017). [6] | Federal Reserve SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026. The OCC rescinded Bulletins 2011-12, 1997-24 and 2021-19 and its "Model Risk Management" Handbook booklet; the FDIC rescinded FIL-22-2017 and FIL-27-2021. [3][4] |
| Who it applies to | "Banks" meant institutions primarily supervised by the OCC or the Federal Reserve, with application "commensurate with a bank's risk exposures, its business activities, and the complexity and extent of its model use". The FDIC's adoption generally pertained to institutions with $1 billion or more in total assets. [5][6] | "Expected to be most relevant to banking organizations with over $30 billion in total assets"; it may also be relevant to smaller banks with "significant exposure to model risk because of the prevalence and complexity of their models" or activities outside traditional community banking. [2] |
| Definition of a model | "A quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates"; also covers approaches whose inputs are "partially or wholly qualitative or based on expert judgment". [5] | "A complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates"; excludes "simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use". [2] |
| AI and generative AI | Does not mention artificial intelligence or machine learning; the definition is technology-neutral. [5] | "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." The principles "apply to traditional statistical and quantitative models and non-generative, non-agentic AI models". [2] |
| Model risk | "The potential for adverse consequences from decisions based on incorrect or misused model outputs and reports". [5] | "The potential for adverse financial consequences associated with models", influenced by a model's inherent risk, exposure, purpose and use. [2] |
| Materiality and tailoring | The rigor of validation "should be commensurate with the bank's overall use of models, the complexity and materiality of its models, and the size and complexity of the bank's operations". [5] | Model purpose and exposure determine "model materiality". Banks "may deem certain models immaterial", where model risk management "may consist of identifying those models and monitoring model performance"; higher-materiality models "warrant more comprehensive and rigorous oversight". [2] |
| Validation | Three core elements: "Evaluation of conceptual soundness, including developmental evidence", "Ongoing monitoring, including process verification and benchmarking" and "Outcomes analysis, including back-testing". [5] | Components: conceptual soundness (where "interpretability measures or benchmarking to other models" may be more practical), outcomes analysis and ongoing monitoring. "Validation generally occurs prior to a model's first use", but a model may be used first in cases such as "an urgent business need", with added controls. [2] |
| Validation frequency | "A periodic review—at least annually but more frequently if warranted—of each model"; a full validation "at some fixed interval" is "generally good practice". [5] | "The timing, nature, and frequency of validation activities vary based on model purpose, model methodology, frequency and scope of model changes, data limitations, and other practical constraints." [2] |
| Effective challenge | "Critical analysis by objective, informed parties who can identify model limitations and assumptions and produce appropriate changes"; it "depends on a combination of incentives, competence, and influence". [5] | Critical analysis by "objective experts" with "appropriate expertise", "sufficient independence to maintain objectivity" and "the organizational standing and influence to effect any change". Validation quality "depends on the rigor and effectiveness of the review rather than on organizational structure". [2] |
| Board and senior management | Governance is "provided at the highest level by the board of directors and senior management"; "Board members should ensure that the level of model risk is within their tolerance". [5] | Governance is described through policies, procedures, roles and responsibilities and internal audit; the guidance text does not assign specific duties to the board of directors or senior management. [2] |
| Model inventory | "A specific party should also be charged with maintaining a firm-wide inventory of all models", covering models in use, under development or recently retired. [5] | Called "common industry practice"; an effective inventory "includes sufficient information to understand model risks", with "varying levels of information" by complexity. [2] |
| Internal audit | "Internal audit's role is not to duplicate model risk management activities. Instead, its role is to evaluate whether model risk management is comprehensive, rigorous, and effective." [5] | Where internal audit is part of model risk management, it "would generally not duplicate" development or validation; its role is "to evaluate whether the model risk management practices are rigorous and effective". [2] |
| Vendor models | Vendor products "should nevertheless be incorporated into a bank's broader model risk management framework following the same principles as applied to in-house models"; banks "are expected to validate their own use of vendor products". [5] | Despite limited access to proprietary components, "the principles of model risk management remain applicable". Sound practice is understanding the vendor model's "conceptual soundness, design, development data, and performance", ongoing monitoring and outcomes analysis, and documenting customizations. [2] |
| Supervisory force | Asks that all banks keep internal policies "consistent with the risk management principles and supervisory expectations contained in this guidance". [5] | The guidance "does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism"; supervisory action may still follow violations of law or "unsafe or unsound practices stemming from insufficient management of model risk". [2] |
| Structure | Sections on model development, implementation and use (IV), model validation (V), and governance, policies and controls (VI). [5] | Sections on model development and model use (IV), model validation and monitoring (V), governance and controls (VI), and vendor and other third-party products (VII). [2] |

## What must a bank change when it moves from SR 11-7 to SR 26-2?

- Re-cite policies: SR 11-7, OCC Bulletin 2011-12 and FDIC FIL-22-2017 are superseded or rescinded, so model risk policies, validation standards and audit programmes should reference SR 26-2, OCC Bulletin 2026-13 or FDIC FIL-15-2026. [1][3][4]
- Re-baseline the inventory against the narrower definition: simple spreadsheet arithmetic and deterministic rule-based processes without statistical, economic or financial theory are not models under the revised guidance. [2]
- Tier by materiality: models deemed immaterial can be identified and monitored rather than fully validated, while higher-materiality models warrant more rigorous oversight. [2]
- Give generative and agentic AI a governance home outside the model risk policy: the guidance excludes them and says a bank's risk management and governance practices "should guide the determination of appropriate governance and controls" for tools it does not cover. [2]
- Keep non-generative machine-learning models (credit, fraud, AML) in the programme: the principles apply to "non-generative, non-agentic AI models". [2]
- Banks at or below $30 billion: the FDIC says the guidance "generally does not apply" to their models unless they have significant model risk exposure, and the OCC said in October 2025 that its guidance does not require community banks to perform annual model validation. [4][7]
- Keep validating vendor models: the revised guidance still expects banks to understand and monitor vendor products and to document and evaluate customizations. [2]
- Watch for the interagency request for information on model risk management and banks' use of AI, including generative and agentic AI, which the agencies said they plan to issue "in the near future". [3]

## Timeline

- Apr 4, 2011 — SR 11-7 (2011): Federal Reserve and OCC issue the Supervisory Guidance on Model Risk Management (SR 11-7 / OCC Bulletin 2011-12). [5][1]
- Jun 7, 2017 — SR 11-7 (2011): FDIC adopts the 2011 guidance with technical conforming changes (FIL-22-2017), generally for institutions with $1 billion or more in assets. [6]
- Apr 9, 2021 — SR 11-7 (2011): SR 21-8, the interagency statement on model risk management for BSA/AML systems. [1]
- Oct 6, 2025 — SR 11-7 (2011): OCC Bulletin 2025-26: OCC model risk guidance does not require community banks to perform annual model validation; described as a first step in a broader review. [7]
- Apr 17, 2026 — SR 26-2 (2026): Federal Reserve (SR 26-2), OCC (Bulletin 2026-13) and FDIC (FIL-15-2026) issue the revised guidance; SR 11-7 and SR 21-8 superseded. [1][3][4]
- Apr 17, 2026 — SR 26-2 (2026): Agencies say they plan to issue "in the near future" a request for information on model risk management and banks' use of AI, including generative and agentic AI. (pending) [3]

## What is still open?

- Generative and agentic AI have no model risk guidance of their own: SR 26-2 places them out of scope, and the promised interagency request for information is the stated next step. [2][3]

## FAQ

### Is SR 11-7 still in effect?

No. SR 26-2, issued April 17, 2026, supersedes and replaces SR 11-7 (April 4, 2011). The OCC rescinded its twin, Bulletin 2011-12, the same day, and the FDIC rescinded FIL-22-2017. [1][3][4]

### Does SR 26-2 apply to generative AI?

No. The guidance says "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." Non-generative, non-agentic AI models remain in scope, and a bank's broader risk management and governance practices should set controls for the tools the guidance does not cover. [2]

### Does SR 26-2 apply to banks under $30 billion?

It is "expected to be most relevant" to banking organizations with over $30 billion in total assets. Smaller banks' models are typically covered by their own internal risk management, but the guidance may be relevant to a smaller bank with significant model risk exposure because of the prevalence and complexity of its models or non-traditional activities. [2]

### How did the definition of a model change from SR 11-7 to SR 26-2?

SR 11-7 covered any quantitative method applying statistical, economic, financial or mathematical theories to produce quantitative estimates. SR 26-2 covers "a complex quantitative method" applying statistical, economic or financial theories, and excludes simple spreadsheet arithmetic and deterministic rule-based processes and software with no statistical, economic or financial theory underpinning their design or use. [5][2]

### Does SR 26-2 require annual model validation?

No fixed frequency is set: the timing, nature and frequency of validation vary with model purpose, methodology, changes, data limitations and other constraints. SR 11-7 had asked for a periodic review of each model at least annually. [2][5]

### Is SR 26-2 the same as OCC Bulletin 2026-13?

Yes. The Federal Reserve, OCC and FDIC issued one Revised Guidance on Model Risk Management on April 17, 2026: the Fed as SR 26-2, the OCC as Bulletin 2026-13 and the FDIC as FIL-15-2026. [1][3][4]

### Does SR 26-2 still cover vendor models?

Yes. It has a section on vendor and other third-party products: the principles of model risk management "remain applicable", and sound practice includes validating vendor products, monitoring them and documenting any customization. [2]

## Sources

1. [SR 26-2: Revised Guidance on Model Risk Management](https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm) — Board of Governors of the Federal Reserve System, Apr 17, 2026
2. [Supervisory Guidance on Model Risk Management (SR 26-2 attachment)](https://www.federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf) — Federal Reserve Board, FDIC and OCC, Apr 17, 2026
3. [OCC Bulletin 2026-13, Model Risk Management: Revised Guidance](https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html) — Office of the Comptroller of the Currency, Apr 17, 2026
4. [FIL-15-2026, Agencies Revise the Interagency Model Risk Management Guidance](https://www.fdic.gov/news/financial-institution-letters/2026/agencies-revise-interagency-model-risk-management-guidance) — Federal Deposit Insurance Corporation, Apr 17, 2026
5. [Supervisory Guidance on Model Risk Management (SR 11-7 attachment)](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) — Board of Governors of the Federal Reserve System; Office of the Comptroller of the Currency, Apr 4, 2011
6. [FIL-22-2017, Adoption of Supervisory Guidance on Model Risk Management](https://www.fdic.gov/news/inactive-financial-institution-letters/2017/adoption-supervisory-guidance-model-risk-management) — Federal Deposit Insurance Corporation, Jun 7, 2017
7. [OCC Bulletin 2025-26, Model Risk Management: Clarification for Community Banks](https://www.occ.gov/news-issuances/bulletins/2025/bulletin-2025-26.html) — Office of the Comptroller of the Currency, Oct 6, 2025

Other comparisons: [OCC vs CFPB on AI lending](https://www.bankingnewsai.com/ai-regulation/compare/occ-vs-cfpb-ai-lending), [EU AI Act vs Colorado AI Act](https://www.bankingnewsai.com/ai-regulation/compare/eu-ai-act-vs-colorado-ai-act), [PRA SS1/23 vs SR 26-2](https://www.bankingnewsai.com/ai-regulation/compare/pra-ss1-23-vs-sr-26-2), [NIST AI RMF vs ISO 42001](https://www.bankingnewsai.com/ai-regulation/compare/nist-ai-rmf-vs-iso-42001). [All comparisons](https://www.bankingnewsai.com/ai-regulation/compare).

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/compare/sr-11-7-vs-sr-26-2
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (19 authorities, 167 documents) and AI-strategy profiles of the 100 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
