AI Regulation Tracker · Federal Reserve · Guidance

What does SR 11-7 say about AI in banking?

Published Apr 4, 2011 · Last reviewed Sep 10, 2026

SR 11-7, issued jointly by the Federal Reserve and OCC on April 4, 2011, was the foundational US framework for bank model risk management for fifteen years and the de facto global template for validating quantitative models, including early machine-learning models. It defined a model as a quantitative method that processes input data into estimates, required independent validation and 'effective challenge', and made the board and senior management accountable for a model inventory and governance framework. It was superseded on April 17, 2026 by revised interagency guidance (Fed SR 26-2 / OCC Bulletin 2026-13).

OFFICIAL TEXT: federalreserve.gov · SUPERSEDED · FEDERAL RESERVE

DocumentSR 11-7Supervisory Guidance on Model Risk Management
Issued byBoard of Governors of the Federal Reserve System
TypeGuidance
StatusSuperseded
PublishedApr 4, 2011
EffectiveApr 4, 2011
Applies toAll banking organizations supervised by the Federal Reserve (issued jointly with the OCC as Bulletin 2011-12); most relevant to institutions with material model use
Superseded bySR 26-2
Official sourcefederalreserve.gov
Use casesModel risk management · Credit scoring & underwriting · AML / KYC · Fraud detection · AI governance (general) · Third-party & vendor AI

What are the key points of SR 11-7?

  • Defines a 'model' as a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates — a definition banks applied to ML and AI models
  • Defines model risk as the potential for adverse consequences from decisions based on incorrect or misused model outputs, arising from fundamental errors or from misuse
  • Requires sound model development, implementation, and use, with documentation sufficient for independent review
  • Requires validation comprising conceptual soundness review, ongoing monitoring (including benchmarking), and outcomes analysis (including back-testing)
  • Introduced 'effective challenge' — critical analysis by objective, informed parties with the incentives, competence, and influence to force changes
  • Requires a governance framework: board and senior management oversight, policies and procedures, a model inventory, and internal audit assessment
  • Extends expectations to vendor and third-party models, requiring banks to validate and understand models they did not build

What did SR 11-7 change for banks?

SR 11-7 turned model governance into an examinable discipline with formal roles (developers, validators, internal audit) and a comprehensive model inventory. Because its model definition was technology-neutral, banks used it for machine-learning credit, fraud, and AML models throughout the 2010s and early 2020s, and its validation language was borrowed by regulators worldwide. Its 2026 replacement keeps the same architecture but narrows scope, adds materiality-based tailoring, and explicitly carves out generative and agentic AI.

What is SR 11-7 and is it still in effect?

SR 11-7 is the Federal Reserve's April 4, 2011 Supervisory Guidance on Model Risk Management, issued jointly with the OCC as Bulletin 2011-12 and adopted by the FDIC in 2017. It defined a model as a quantitative method that processes input data into estimates, and built model risk management on three pillars: sound development, implementation and use; independent validation with 'effective challenge'; and governance through board oversight, policies, a model inventory and internal audit. It is no longer in effect: on April 17, 2026 the Fed, OCC and FDIC replaced it with revised interagency guidance (SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026), which keeps the same architecture, narrows what counts as a model, ties the intensity of validation to materiality, and places generative and agentic AI outside its scope.

RuleAuthorityWhat it requiresApplies
SR 11-7 / OCC Bulletin 2011-12 (2011 guidance)Federal ReserveModel definition, the three pillars (development and use, validation, governance), effective challenge, a comprehensive model inventory and coverage of vendor models.Superseded Apr 17, 2026
SR 26-2 (Fed)Federal ReserveThe replacement: a risk-based, materiality-driven framework; narrower model definition that excludes simple arithmetic and deterministic rules; generative and agentic AI out of scope; most relevant above $30 billion in assets.In force from Apr 17, 2026
OCC Bulletin 2026-13OCCSame text for national banks; rescinds Bulletins 2011-12, 1997-24 and 2021-19 and the Comptroller's Handbook booklet; states non-compliance is not by itself a basis for criticism.In force from Apr 17, 2026
FDIC FIL-15-2026FDICSame text for state non-member banks; rescinds FIL-22-2017, the FDIC's 2017 adoption of the 2011 guidance, and FIL-27-2021.In force from Apr 17, 2026
SR 23-4 (third-party risk)Federal ReserveVendor and cloud-hosted models: due diligence and ongoing monitoring, with validation consistent with model risk management guidance.In force
PRA SS1/23 (UK counterpart)UK (BoE / PRA / FCA)Five principles covering all models that inform business decisions, including vendor models, with a sub-principle on AI and machine-learning risks and a named senior manager accountable.In force from May 17, 2024

The 2011 guidance answered a question the financial crisis had exposed: banks were making capital, pricing and credit decisions on models nobody outside the modelling team had tested. Its answer was a discipline rather than a rule. Development had to be documented well enough for an outsider to review; validation had to cover conceptual soundness, ongoing monitoring (process verification and benchmarking) and outcomes analysis (back-testing); and 'effective challenge' had to come from people with the incentives, competence and organisational standing to force a change. Every model went into an inventory, the board and senior management owned the framework, and internal audit checked that it worked. Purchased models were not exempt: a bank had to understand and validate what it bought.

Because the definition of a model was technology-neutral, SR 11-7 became the framework US banks applied to machine-learning credit, fraud and anti-money-laundering models through the 2010s and early 2020s, and its validation vocabulary was borrowed by supervisors worldwide, from the PRA's SS1/23 to the EBA's work on machine learning in internal ratings-based models. The 2021 interagency statement on model risk in BSA/AML systems (SR 21-8) extended it to compliance models.

The April 2026 revision kept the architecture and changed the perimeter. A model is now a 'complex' quantitative method, so spreadsheets and deterministic rule engines drop out of the inventory; validation effort follows materiality rather than a single standard; the guidance is expected to matter most to banking organisations above $30 billion in assets; and generative and agentic AI are declared 'novel and rapidly evolving' and outside its scope, with the agencies promising a request for information on AI and model risk. Anything a bank built on SR 11-7 still stands; what changed is how much of it examiners expect for a given model, and the explicit gap around generative systems.

WHAT THIS MEANS IN PRACTICE

  • Cite SR 26-2, OCC Bulletin 2026-13 or FDIC FIL-15-2026 in new policies; SR 11-7 is the history, not the standard.
  • Re-tier the inventory against the narrower model definition and document what left it and why: the validation budget freed is the point of the revision.
  • Keep the SR 11-7 disciplines for machine-learning models in credit, fraud and AML; they remain inside the 2026 guidance and its validation expectations.
  • Generative and agentic AI need a governance home outside the model policy, because the new guidance explicitly declines to be one; enterprise risk, third-party risk (SR 23-4) and data governance are what examiners will ask about until the promised request for information becomes guidance.

How does SR 11-7, and now SR 26-2, apply to machine-learning and AI models?

Under SR 11-7 a machine-learning model was a model like any other: if it processed input data into quantitative estimates it needed documented development, independent validation with conceptual-soundness review, ongoing monitoring and outcomes analysis, an inventory entry and board-level governance, and banks applied exactly that to ML underwriting, fraud and AML models for a decade. SR 26-2 keeps machine-learning models in scope on a materiality basis but states that generative AI and agentic AI models are 'not within the scope of this guidance', directing banks to broader risk-management and governance practices for them. Two things do not change with the model type: a credit model that produces an adverse decision must still yield the specific principal reasons ECOA and FCRA require, and a model bought from a vendor is still the bank's to understand and validate under SR 23-4.

RuleAuthorityWhat it requiresApplies
SR 26-2 / OCC 2026-13 / FDIC FIL-15-2026Federal ReserveMachine-learning models that meet the 'complex quantitative method' definition are in scope, with validation and monitoring proportionate to materiality; generative and agentic AI are outside scope and left to broader governance pending an interagency request for information.In force from Apr 17, 2026
SR 11-7 validation elementsFederal ReserveConceptual soundness (including the quality and relevance of input data), ongoing monitoring with benchmarking, and outcomes analysis with back-testing: the three tests still applied to ML models under the 2026 guidance.Superseded Apr 17, 2026; disciplines retained
ECOA / Regulation B adverse actionCFPBA credit decision made or informed by a model must be explainable to the applicant as specific principal reasons; model complexity is not a defence.In force
FCRA adverse action and key factorsCFPBWhere a credit score is used, the key factors that adversely affected it must be disclosed, which constrains opaque feature sets.In force
SR 23-4 (third-party risk)Federal ReserveVendor ML and foundation-model access fall under third-party risk management, with validation consistent with model-risk guidance and monitoring through the relationship's life.In force
NIST AI RMF 1.0NISTVoluntary Govern-Map-Measure-Manage framework and seven trustworthiness characteristics that many banks use to govern generative AI where model-risk guidance now stops.Voluntary
PRA SS1/23UK (BoE / PRA / FCA)UK equivalent that keeps AI and machine-learning models explicitly inside model risk management through a dedicated sub-principle.In force from May 17, 2024
ECB Guide to internal models, ML sectionECBFor euro-area capital models: ML techniques must be adequately explainable and their added complexity justified by performance.In force from Jul 28, 2025

The practical translation of SR 11-7 to machine learning was worked out by validators rather than regulators. Conceptual soundness became a review of feature engineering, training data quality and the choice of algorithm against simpler alternatives; ongoing monitoring became drift detection on inputs and outputs with a champion-challenger benchmark; outcomes analysis became back-testing against realised defaults, fraud losses or alert dispositions. The hard part was always explainability: a gradient-boosted credit model can pass every statistical test and still fail the requirement to tell a declined applicant the principal reasons, which is why post-hoc explanation methods and constrained model forms became part of validation in US retail credit.

SR 26-2 draws a line that SR 11-7 never had to. Predictive machine-learning models stay inside model risk management, scaled to materiality. Generative models and agents are outside it, not because they are low-risk but because the agencies judged the 2011 toolkit, built around estimates that can be back-tested, a poor fit for systems that produce text or take actions. The guidance tells banks to rely on broader risk-management and governance practices for those systems and promises a request for information; until that arrives, the working answer in most large banks is an AI governance framework alongside the model policy, often built on the NIST AI Risk Management Framework, with third-party risk management covering the vendor and data governance covering the inputs.

Outside the US the perimeter runs the other way. The PRA's SS1/23 keeps AI and machine learning explicitly inside model risk management through a dedicated sub-principle, the ECB's 2025 Guide to internal models tests ML capital models for explainability and justified complexity, and the EBA's guidelines on loan origination require staff who can interpret and override automated credit models. A bank operating on both sides of the Atlantic therefore governs the same model under two different assumptions about where model risk management ends.

WHAT THIS MEANS IN PRACTICE

  • For predictive ML in credit, fraud and AML, keep the full SR 11-7 validation stack and document the materiality tier that sets its depth under SR 26-2.
  • Test adverse-action explainability as a validation gate, not a compliance afterthought: if the model cannot produce specific principal reasons, it is not deployable for credit decisions.
  • Put generative and agentic systems under a written AI governance standard that names an owner, an inventory, an approval gate, monitoring and a human-oversight rule; cite the NIST AI RMF and SR 23-4 as the basis while the interagency RFI is pending.
  • Read the SR 26-2 carve-out as temporary. The agencies asked for information on AI and model risk in the near future; the request will show where guidance is heading.

Is SR 11-7 still in effect?

No. SR 11-7 was superseded on April 17, 2026 by SR 26-2, the revised interagency model risk management guidance issued by the Federal Reserve, OCC, and FDIC. Its core disciplines (validation, effective challenge, governance, model inventory) carry over into the new guidance.

Did SR 11-7 apply to machine-learning models?

Yes in practice. Its technology-neutral definition of a model covered any quantitative method processing inputs into estimates, so banks and examiners applied it to ML underwriting, fraud, and AML models. SR 26-2 now covers AI/ML models explicitly but excludes generative and agentic AI.

What does 'effective challenge' mean under SR 11-7?

Critical analysis of a model by objective, informed parties who have the incentives, competence, and organizational influence to identify limitations and force changes. It is the central validation principle and survives in the 2026 revision.

DateDocumentStatus
Apr 17, 2026SR 26-2Revised Guidance on Model Risk ManagementIn force
May 27, 2026Cook: Opportunities and Risks of AI (May 2026)The Opportunities and Risks AI Presents for the Economy and Financial System — Governor Lisa D. CookFinal
May 1, 2026Bowman: AI in the Financial System (May 2026)Artificial Intelligence in the Financial System — Vice Chair for Supervision Michelle W. BowmanFinal
Jun 7, 2023SR 23-4Interagency Guidance on Third-Party Relationships: Risk ManagementIn force
Apr 9, 20212021 BSA/AML Model Risk StatementInteragency Statement on Model Risk Management for Bank Systems Supporting BSA/AML ComplianceSuperseded
Mar 31, 20212021 Interagency AI RFIRequest for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine LearningFinal

Which banks' AI programmes does SR 11-7 reach?

43 of the 100 largest US banks profiled on this site cite SR 11-7 among the documents their AI work answers to.

Follow every document these regulators publish

the daily brief · six sourced stories · in your inbox by 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning