AI Regulation Tracker · Federal Reserve · Guidance

What does SR 11-7 say about AI in banking?

Published Apr 4, 2011 · Last reviewed Aug 26, 2026

SR 11-7, issued jointly by the Federal Reserve and OCC on April 4, 2011, was the foundational US framework for bank model risk management for fifteen years and the de facto global template for validating quantitative models, including early machine-learning models. It defined a model as a quantitative method that processes input data into estimates, required independent validation and 'effective challenge', and made the board and senior management accountable for a model inventory and governance framework. It was superseded on April 17, 2026 by revised interagency guidance (Fed SR 26-2 / OCC Bulletin 2026-13).

DocumentSR 11-7Supervisory Guidance on Model Risk Management
Issued byBoard of Governors of the Federal Reserve System
TypeGuidance
StatusSuperseded
PublishedApr 4, 2011
EffectiveApr 4, 2011
Applies toAll banking organizations supervised by the Federal Reserve (issued jointly with the OCC as Bulletin 2011-12); most relevant to institutions with material model use
Superseded bySR 26-2
Official sourcefederalreserve.gov
Use casesModel risk management · Credit scoring & underwriting · AML / KYC · Fraud detection · AI governance (general) · Third-party & vendor AI

What are the key points of SR 11-7?

  • Defines a 'model' as a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates — a definition banks applied to ML and AI models
  • Defines model risk as the potential for adverse consequences from decisions based on incorrect or misused model outputs, arising from fundamental errors or from misuse
  • Requires sound model development, implementation, and use, with documentation sufficient for independent review
  • Requires validation comprising conceptual soundness review, ongoing monitoring (including benchmarking), and outcomes analysis (including back-testing)
  • Introduced 'effective challenge' — critical analysis by objective, informed parties with the incentives, competence, and influence to force changes
  • Requires a governance framework: board and senior management oversight, policies and procedures, a model inventory, and internal audit assessment
  • Extends expectations to vendor and third-party models, requiring banks to validate and understand models they did not build

What did SR 11-7 change for banks?

SR 11-7 turned model governance into an examinable discipline with formal roles (developers, validators, internal audit) and a comprehensive model inventory. Because its model definition was technology-neutral, banks used it for machine-learning credit, fraud, and AML models throughout the 2010s and early 2020s, and its validation language was borrowed by regulators worldwide. Its 2026 replacement keeps the same architecture but narrows scope, adds materiality-based tailoring, and explicitly carves out generative and agentic AI.

Is SR 11-7 still in effect?

No. SR 11-7 was superseded on April 17, 2026 by SR 26-2, the revised interagency model risk management guidance issued by the Federal Reserve, OCC, and FDIC. Its core disciplines (validation, effective challenge, governance, model inventory) carry over into the new guidance.

Did SR 11-7 apply to machine-learning models?

Yes in practice. Its technology-neutral definition of a model covered any quantitative method processing inputs into estimates, so banks and examiners applied it to ML underwriting, fraud, and AML models. SR 26-2 now covers AI/ML models explicitly but excludes generative and agentic AI.

What does 'effective challenge' mean under SR 11-7?

Critical analysis of a model by objective, informed parties who have the incentives, competence, and organizational influence to identify limitations and force changes. It is the central validation principle and survives in the 2026 revision.

DateDocumentStatus
Apr 17, 2026SR 26-2Revised Guidance on Model Risk ManagementIn force
May 27, 2026Cook: Opportunities and Risks of AI (May 2026)The Opportunities and Risks AI Presents for the Economy and Financial System — Governor Lisa D. CookFinal
May 1, 2026Bowman: AI in the Financial System (May 2026)Artificial Intelligence in the Financial System — Vice Chair for Supervision Michelle W. BowmanFinal
Jun 7, 2023SR 23-4Interagency Guidance on Third-Party Relationships: Risk ManagementIn force
Apr 9, 20212021 BSA/AML Model Risk StatementInteragency Statement on Model Risk Management for Bank Systems Supporting BSA/AML ComplianceSuperseded
Mar 31, 20212021 Interagency AI RFIRequest for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine LearningFinal

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →