# SR 11-7: Supervisory Guidance on Model Risk Management

Source: https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-11-7
Last updated: Sep 19, 2026

SR 11-7, issued jointly by the Federal Reserve and OCC on April 4, 2011, was the foundational US framework for bank model risk management for fifteen years and the de facto global template for validating quantitative models, including early machine-learning models. It defined a model as a quantitative method that processes input data into estimates, required independent validation and 'effective challenge', and made the board and senior management accountable for a model inventory and governance framework. It was superseded on April 17, 2026 by revised interagency guidance (Fed SR 26-2 / OCC Bulletin 2026-13).

## At a glance

| Field | Value |
| --- | --- |
| Authority | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) |
| Type | Guidance |
| Status | Superseded |
| Published | Apr 4, 2011 |
| Effective | Apr 4, 2011 |
| Applies to | All banking organizations supervised by the Federal Reserve (issued jointly with the OCC as Bulletin 2011-12); most relevant to institutions with material model use |
| Official text | https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf |

## Key points

- Defines a 'model' as a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates — a definition banks applied to ML and AI models
- Defines model risk as the potential for adverse consequences from decisions based on incorrect or misused model outputs, arising from fundamental errors or from misuse
- Requires sound model development, implementation, and use, with documentation sufficient for independent review
- Requires validation comprising conceptual soundness review, ongoing monitoring (including benchmarking), and outcomes analysis (including back-testing)
- Introduced 'effective challenge' — critical analysis by objective, informed parties with the incentives, competence, and influence to force changes
- Requires a governance framework: board and senior management oversight, policies and procedures, a model inventory, and internal audit assessment
- Extends expectations to vendor and third-party models, requiring banks to validate and understand models they did not build

## What changed for banks

SR 11-7 turned model governance into an examinable discipline with formal roles (developers, validators, internal audit) and a comprehensive model inventory. Because its model definition was technology-neutral, banks used it for machine-learning credit, fraud, and AML models throughout the 2010s and early 2020s, and its validation language was borrowed by regulators worldwide. Its 2026 replacement keeps the same architecture but narrows scope, adds materiality-based tailoring, and explicitly carves out generative and agentic AI.

## Use cases it governs

- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Credit scoring & underwriting](https://www.bankingnewsai.com/ai-regulation/by-use-case#credit-underwriting)
- [AML / KYC](https://www.bankingnewsai.com/ai-regulation/by-use-case#aml-kyc)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)

> Superseded by [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2).

## What is SR 11-7 and is it still in effect?

SR 11-7 is the Federal Reserve's April 4, 2011 Supervisory Guidance on Model Risk Management, issued jointly with the OCC as Bulletin 2011-12 and adopted by the FDIC in 2017. It defined a model as a quantitative method that processes input data into estimates, and built model risk management on three pillars: sound development, implementation and use; independent validation with 'effective challenge'; and governance through board oversight, policies, a model inventory and internal audit. It is no longer in effect: on April 17, 2026 the Fed, OCC and FDIC replaced it with revised interagency guidance (SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026), which keeps the same architecture, narrows what counts as a model, ties the intensity of validation to materiality, and places generative and agentic AI outside its scope.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| SR 11-7 / OCC Bulletin 2011-12 (2011 guidance) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Model definition, the three pillars (development and use, validation, governance), effective challenge, a comprehensive model inventory and coverage of vendor models. | Superseded Apr 17, 2026 | [SR 11-7](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-11-7) |
| SR 26-2 (Fed) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | The replacement: a risk-based, materiality-driven framework; narrower model definition that excludes simple arithmetic and deterministic rules; generative and agentic AI out of scope; most relevant above $30 billion in assets. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| OCC Bulletin 2026-13 | [OCC](https://www.bankingnewsai.com/ai-regulation/occ) | Same text for national banks; rescinds Bulletins 2011-12, 1997-24 and 2021-19 and the Comptroller's Handbook booklet; states non-compliance is not by itself a basis for criticism. | In force from Apr 17, 2026 | [OCC Bulletin 2026-13](https://www.bankingnewsai.com/ai-regulation/documents/occ-bulletin-2026-13) |
| FDIC FIL-15-2026 | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | Same text for state non-member banks; rescinds FIL-22-2017, the FDIC's 2017 adoption of the 2011 guidance, and FIL-27-2021. | In force from Apr 17, 2026 | [FDIC FIL-15-2026](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-15-2026) |
| SR 23-4 (third-party risk) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Vendor and cloud-hosted models: due diligence and ongoing monitoring, with validation consistent with model risk management guidance. | In force | [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) |
| PRA SS1/23 (UK counterpart) | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Five principles covering all models that inform business decisions regardless of technology, including vendor models, with AI-relevant tiering factors (unstructured data, explainability, bias) and a named senior manager accountable. | In force from May 17, 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |

The 2011 guidance answered a question the financial crisis had exposed: banks were making capital, pricing and credit decisions on models nobody outside the modelling team had tested. Its answer was a discipline rather than a rule. Development had to be documented well enough for an outsider to review; validation had to cover conceptual soundness, ongoing monitoring (process verification and benchmarking) and outcomes analysis (back-testing); and 'effective challenge' had to come from people with the incentives, competence and organisational standing to force a change. Every model went into an inventory, the board and senior management owned the framework, and internal audit checked that it worked. Purchased models were not exempt: a bank had to understand and validate what it bought.

Because the definition of a model was technology-neutral, SR 11-7 became the framework US banks applied to machine-learning credit, fraud and anti-money-laundering models through the 2010s and early 2020s, and its validation vocabulary was borrowed by supervisors worldwide, from the PRA's SS1/23 to the EBA's work on machine learning in internal ratings-based models. The 2021 interagency statement on model risk in BSA/AML systems (SR 21-8) extended it to compliance models.

The April 2026 revision kept the architecture and changed the perimeter. A model is now a 'complex' quantitative method, so spreadsheets and deterministic rule engines drop out of the inventory; validation effort follows materiality rather than a single standard; the guidance is expected to matter most to banking organisations above $30 billion in assets; and generative and agentic AI are declared 'novel and rapidly evolving' and outside its scope, with the agencies promising a request for information on AI and model risk. Anything a bank built on SR 11-7 still stands; what changed is how much of it examiners expect for a given model, and the explicit gap around generative systems.

### What this means in practice

- Cite SR 26-2, OCC Bulletin 2026-13 or FDIC FIL-15-2026 in new policies; SR 11-7 is the history, not the standard.
- Re-tier the inventory against the narrower model definition and document what left it and why: the validation budget freed is the point of the revision.
- Keep the SR 11-7 disciplines for machine-learning models in credit, fraud and AML; they remain inside the 2026 guidance and its validation expectations.
- Generative and agentic AI need a governance home outside the model policy, because the new guidance explicitly declines to be one; enterprise risk, third-party risk (SR 23-4) and data governance are what examiners will ask about until the promised request for information becomes guidance.

## What are the three pillars of SR 11-7 model risk management?

The three pillars of SR 11-7 are (1) robust model development, implementation and use, (2) a sound model validation process and (3) governance, policies and controls. The guidance itself calls them elements, not pillars: 'Model risk management begins with robust model development, implementation, and use. Another essential element is a sound model validation process. A third element is governance.' Each has its own section of the 21-page Supervisory Guidance on Model Risk Management (Sections IV, V and VI), and one principle runs through all three: effective challenge by objective, informed parties. The 2026 replacement, SR 26-2, keeps the same three-part structure and adds a separate section on vendor and other third-party products.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Pillar 1: model development, implementation and use (Section IV) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | A clear statement of purpose; design, theory and logic supported by research and sound practice; rigorous assessment of data quality and relevance; testing of accuracy, robustness and stability; documentation; and use that respects the model's stated limitations and assumptions. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| Pillar 2: model validation (Section V) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Independent verification that models perform as expected, through three core elements: evaluation of conceptual soundness, ongoing monitoring (process verification and benchmarking) and outcomes analysis (back-testing); applies equally to vendor models; periodic review of each model at least annually. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| Pillar 3: governance, policies and controls (Section VI) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Board and senior-management responsibility for the framework; policies and procedures reviewed annually; defined roles and responsibilities; internal audit's assessment of the framework; use of external resources; a firm-wide model inventory; documentation. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| SR 26-2: the same structure, revised | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Model development and model use; model validation and monitoring; governance and controls; plus a stand-alone section on vendor and other third-party products, all applied on a risk-based, materiality-driven footing. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| OCC Bulletin 2011-12 (same text for national banks) | [OCC](https://www.bankingnewsai.com/ai-regulation/occ) | The identical three elements for national banks and federal savings associations. | Rescinded Apr 17, 2026 | [OCC Bulletin 2011-12](https://www.bankingnewsai.com/ai-regulation/documents/occ-bulletin-2011-12) |
| PRA SS1/23 (UK): five principles instead of three pillars | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Model identification and risk classification, governance, development and use, independent validation, and model risk mitigants. | In force from May 17, 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |

The three-pillar shorthand is a practitioner's summary of how the guidance is organised. Section IV covers how a model is built and used, Section V how it is independently tested, and Section VI who is accountable for the whole. The guidance is explicit that the third matters as much as the first two: 'Even if model development, implementation, use, and validation are satisfactory, a weak governance function will reduce the effectiveness of overall model risk management.'

The three pillars of the framework should not be confused with the three core elements of validation, which sit inside pillar two: evaluation of conceptual soundness, including developmental evidence; ongoing monitoring, including process verification and benchmarking; and outcomes analysis, including back-testing. Nor are they the 'three lines of defense', a governance model SR 11-7 does not name, although its split between model owners, an independent validation and control function, and internal audit maps onto it closely.

Materiality scales all three. Where models are less pervasive and have less impact on a bank's financial condition, SR 11-7 accepts a less complex approach; where model failure would be particularly harmful, the framework 'should be more extensive and rigorous'.

### What this means in practice

- Organise the model risk policy, the validation report template and the audit programme around the three pillars: the structure survived the 2026 revision unchanged.
- Keep the pillar-two validation elements distinct in validation reports: a finding on conceptual soundness is not cured by good back-testing.

## What counts as a model under SR 11-7, and what did it expect of validation, effective challenge and vendor models?

SR 11-7 defines a model as 'a quantitative method, system, or approach that applies statistical, economic, financial, or mathematical theories, techniques, and assumptions to process input data into quantitative estimates', made up of an information input component, a processing component and a reporting component. Approaches with qualitative or judgmental inputs count if the output is quantitative. Validation must cover all three components, be performed with a degree of independence from development and use, and include conceptual-soundness review, ongoing monitoring and outcomes analysis. Effective challenge, 'critical analysis by objective, informed parties who can identify model limitations and assumptions and produce appropriate changes', depends on incentives, competence and influence. Vendor models are in scope: banks are expected to validate their own use of vendor products.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Definition of a model (Section III) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | A quantitative method, system or approach that processes input data into quantitative estimates, with input, processing and reporting components; covers approaches whose inputs are partly or wholly qualitative or judgmental when the output is quantitative. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| Definition of model risk (Section III) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | The potential for adverse consequences from decisions based on incorrect or misused model outputs and reports, arising from fundamental errors or from incorrect or inappropriate use; to be managed for individual models and in the aggregate. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| Validation: three core elements (Section V) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Evaluation of conceptual soundness, including developmental evidence; ongoing monitoring, including process verification and benchmarking; outcomes analysis, including back-testing. Rigor commensurate with model use, complexity and materiality. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| Independence and effective challenge | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Validation generally by people not responsible for development or use and with no stake in the outcome; independence judged by actions and outcomes, not reporting lines alone; challengers need incentives, competence and influence. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| Vendor and other third-party products (Section V) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Require developmental evidence and ongoing performance information from the vendor; validate the bank's own use; justify customisation; rely more on sensitivity analysis and benchmarking where code is proprietary; keep a contingency plan if the vendor model becomes unavailable. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| Model inventory (Section VI) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | A firm-wide inventory of models in use, under development or recently retired, recording purpose, products, usage and restrictions, inputs and outputs, responsible individuals, and dates of completed and planned validation. | 2011 to Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| SR 26-2 definition (the 2026 change) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | A model is now a 'complex' quantitative method; simple arithmetic calculations such as those in spreadsheets and deterministic rule-based processes are excluded; generative and agentic AI models are outside scope. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| SR 23-4 (third-party risk management) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | The lifecycle guidance for the vendor relationship itself: due diligence, contracting, ongoing monitoring and termination. | In force | [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) |

Two timing expectations in SR 11-7 are often misquoted. The guidance asks for a periodic review of each model, at least annually, to decide whether it is working as intended and whether existing validation is sufficient; that review 'could simply affirm previous validation work'. Separately, it calls it 'generally good practice' for all models to undergo the full validation process at some fixed interval. It does not set that interval.

On independence the text is more flexible than its reputation. Some validation work 'may be most effectively done by model developers and users', provided it is subject to critical review by an independent party. What the guidance will not bend on is influence: effective challenge requires that the people challenging a model have the standing to get it changed, which is why it ties validation quality to compensation, performance evaluation and corporate culture.

For large language models the 2011 definition raised a question it could not settle: a model that generates text does not obviously produce 'quantitative estimates'. Many banks inventoried generative systems under SR 11-7 anyway. SR 26-2 answered the question the other way in April 2026: generative AI and agentic AI models are 'novel and rapidly evolving' and not within the scope of the guidance, while traditional statistical models and non-generative, non-agentic AI models remain inside it.

### What this means in practice

- Record for every inventory entry why it is, or is not, a model under the definition in force; the 2026 definition removes spreadsheets and rule engines that the 2011 one arguably captured.
- For vendor models, ask for developmental evidence and ongoing performance results at contract stage; SR 11-7's expectation that banks validate their own use of vendor products carries into SR 26-2.
- Treat effective challenge as a test of outcomes: count the models changed, restricted or rejected because of validation, not the number of reports issued.

## How does SR 11-7, and now SR 26-2, apply to machine-learning and AI models?

Under SR 11-7 a machine-learning model was a model like any other: if it processed input data into quantitative estimates it needed documented development, independent validation with conceptual-soundness review, ongoing monitoring and outcomes analysis, an inventory entry and board-level governance, and banks applied exactly that to ML underwriting, fraud and AML models for a decade. SR 26-2 keeps machine-learning models in scope on a materiality basis but states that generative AI and agentic AI models are 'not within the scope of this guidance', directing banks to broader risk-management and governance practices for them. Two things do not change with the model type: a credit model that produces an adverse decision must still yield the specific principal reasons ECOA and FCRA require, and a model bought from a vendor is still the bank's to understand and validate under SR 23-4.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| SR 26-2 / OCC 2026-13 / FDIC FIL-15-2026 | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Machine-learning models that meet the 'complex quantitative method' definition are in scope, with validation and monitoring proportionate to materiality; generative and agentic AI are outside scope and left to broader governance pending an interagency request for information. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| SR 11-7 validation elements | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Conceptual soundness (including the quality and relevance of input data), ongoing monitoring with benchmarking, and outcomes analysis with back-testing: the three tests still applied to ML models under the 2026 guidance. | Superseded Apr 17, 2026; disciplines retained | [SR 11-7](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-11-7) |
| ECOA / Regulation B adverse action | [CFPB](https://www.bankingnewsai.com/ai-regulation/cfpb) | A credit decision made or informed by a model must be explainable to the applicant as specific principal reasons; model complexity is not a defence. | In force | [ECOA / Regulation B adverse action (15 U.S.C. 1691(d); 12 CFR 1002.9)](https://www.bankingnewsai.com/ai-regulation/documents/cfpb-ecoa-regulation-b-adverse-action) |
| FCRA adverse action and key factors | [CFPB](https://www.bankingnewsai.com/ai-regulation/cfpb) | Where a credit score is used, the key factors that adversely affected it must be disclosed, which constrains opaque feature sets. | In force | [FCRA adverse action and credit-score disclosures (15 U.S.C. 1681m, 1681g(f))](https://www.bankingnewsai.com/ai-regulation/documents/cfpb-fcra-adverse-action-key-factors) |
| SR 23-4 (third-party risk) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Vendor ML and foundation-model access fall under third-party risk management, with validation consistent with model-risk guidance and monitoring through the relationship's life. | In force | [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) |
| NIST AI RMF 1.0 | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | Voluntary Govern-Map-Measure-Manage framework and seven trustworthiness characteristics that many banks use to govern generative AI where model-risk guidance now stops. | Voluntary | [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) |
| PRA SS1/23 | [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | UK equivalent that keeps AI and machine-learning models inside model risk management by covering all models regardless of technology, with tiering factors for unstructured data, explainability and bias. | In force from May 17, 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |
| ECB Guide to internal models, ML section | [ECB](https://www.bankingnewsai.com/ai-regulation/ecb) | For euro-area capital models: ML techniques must be adequately explainable and their added complexity justified by performance. | In force from Jul 28, 2025 | [ECB Guide to internal models (July 2025, ML section)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-guide-to-internal-models-2025-machine-learning) |

The practical translation of SR 11-7 to machine learning was worked out by validators rather than regulators. Conceptual soundness became a review of feature engineering, training data quality and the choice of algorithm against simpler alternatives; ongoing monitoring became drift detection on inputs and outputs with a champion-challenger benchmark; outcomes analysis became back-testing against realised defaults, fraud losses or alert dispositions. The hard part was always explainability: a gradient-boosted credit model can pass every statistical test and still fail the requirement to tell a declined applicant the principal reasons, which is why post-hoc explanation methods and constrained model forms became part of validation in US retail credit.

SR 26-2 draws a line that SR 11-7 never had to. Predictive machine-learning models stay inside model risk management, scaled to materiality. Generative models and agents are outside it, not because they are low-risk but because the agencies judged the 2011 toolkit, built around estimates that can be back-tested, a poor fit for systems that produce text or take actions. The guidance tells banks to rely on broader risk-management and governance practices for those systems and promises a request for information; until that arrives, the working answer in most large banks is an AI governance framework alongside the model policy, often built on the NIST AI Risk Management Framework, with third-party risk management covering the vendor and data governance covering the inputs.

Outside the US the perimeter runs the other way. The PRA's SS1/23 keeps AI and machine learning inside model risk management by covering all models regardless of technology, the ECB's 2025 Guide to internal models tests ML capital models for explainability and justified complexity, and the EBA's guidelines on loan origination require staff who can interpret and override automated credit models. A bank operating on both sides of the Atlantic therefore governs the same model under two different assumptions about where model risk management ends.

### What this means in practice

- For predictive ML in credit, fraud and AML, keep the full SR 11-7 validation stack and document the materiality tier that sets its depth under SR 26-2.
- Test adverse-action explainability as a validation gate, not a compliance afterthought: if the model cannot produce specific principal reasons, it is not deployable for credit decisions.
- Put generative and agentic systems under a written AI governance standard that names an owner, an inventory, an approval gate, monitoring and a human-oversight rule; cite the NIST AI RMF and SR 23-4 as the basis while the interagency RFI is pending.
- Read the SR 26-2 carve-out as temporary. The agencies asked for information on AI and model risk in the near future; the request will show where guidance is heading.

## Where is the official SR 11-7 PDF?

The official SR 11-7 PDF is the attachment to the letter, 'Supervisory Guidance on Model Risk Management', dated April 4, 2011 and hosted by the Federal Reserve at federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf. It runs to 21 pages in seven sections: introduction; purpose and scope; overview of model risk management; model development, implementation, and use; model validation; governance, policies, and controls; and conclusion. The OCC publishes the identical guidance as Bulletin 2011-12 in its rescinded-bulletins archive. Since SR 26-2 superseded the letter on April 17, 2026, the Federal Reserve's web page for the SR 11-7 letter itself no longer resolves (checked September 19, 2026); the attachment PDF remains available, and the current guidance is the SR 26-2 attachment.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| SR 11-7 attachment: Supervisory Guidance on Model Risk Management (official PDF) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | The full 2011 guidance as issued by the Board of Governors and the OCC; 21 pages. | Superseded Apr 17, 2026 | [official text](https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) |
| OCC Bulletin 2011-12 (official PDF, rescinded archive) | [OCC](https://www.bankingnewsai.com/ai-regulation/occ) | The same guidance as published by the OCC; 25 pages, stamped 'Rescinded' and 'Replaced - See OCC 2026-13'. | Rescinded Apr 17, 2026 | [official text](https://www.occ.gov/static/rescinded-bulletins/bulletin-2011-12.pdf) |
| SR 26-2 attachment: revised guidance (official PDF) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | The guidance now in force; 12 pages, with sections on model development and use, validation and monitoring, governance and controls, and vendor and other third-party products. | In force from Apr 17, 2026 | [official text](https://www.federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf) |
| SR 26-2 letter | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | The Federal Reserve letter that supersedes SR 11-7 and SR 21-8. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |

### What this means in practice

- Cite the federalreserve.gov or occ.gov copy in policies and validation reports; third-party mirrors do not show that the guidance has been superseded.

## FAQ

### Is SR 11-7 still in effect?

No. SR 11-7 was superseded on April 17, 2026 by SR 26-2, the revised interagency model risk management guidance issued by the Federal Reserve, OCC, and FDIC. Its core disciplines (validation, effective challenge, governance, model inventory) carry over into the new guidance.

### Did SR 11-7 apply to machine-learning models?

Yes in practice. Its technology-neutral definition of a model covered any quantitative method processing inputs into estimates, so banks and examiners applied it to ML underwriting, fraud, and AML models. SR 26-2 now covers AI/ML models explicitly but excludes generative and agentic AI.

### What does 'effective challenge' mean under SR 11-7?

Critical analysis of a model by objective, informed parties who have the incentives, competence, and organizational influence to identify limitations and force changes. It is the central validation principle and survives in the 2026 revision.

### What are the three pillars of SR 11-7?

Robust model development, implementation and use; a sound model validation process; and governance, policies and controls. SR 11-7 calls them elements rather than pillars, and gives each its own section (IV, V and VI). Effective challenge is the principle that runs through all three.

### Is SR 11-7 the same as OCC Bulletin 2011-12?

Yes. The Federal Reserve and the OCC issued one document, the Supervisory Guidance on Model Risk Management, on April 4, 2011; the Fed transmitted it as SR 11-7 and the OCC as Bulletin 2011-12. The FDIC adopted it in June 2017 as FIL-22-2017. All three were replaced on April 17, 2026.

### Does SR 11-7 apply to large language models and generative AI?

SR 11-7 predates them and no longer applies to anything: it was superseded on April 17, 2026. Its replacement, SR 26-2, states that generative AI and agentic AI models are not within the scope of the guidance and leaves them to a bank's broader risk management and governance practices, while non-generative machine-learning models remain in scope. The agencies said they plan a request for information on model risk management and banks' use of AI.

### Does SR 11-7 cover vendor models?

Yes. The guidance says validation 'applies equally to models developed in-house and to those purchased from or developed by vendors or consultants', expects banks to obtain developmental evidence and ongoing performance information from vendors, to validate their own use of the product, and to keep a contingency plan in case the vendor model becomes unavailable.

### Where can I download the SR 11-7 PDF?

The official 21-page PDF is the letter's attachment on federalreserve.gov (boarddocs/srletters/2011/sr1107a1.pdf). The OCC's copy, Bulletin 2011-12, is in the rescinded-bulletins archive on occ.gov. Both are linked in the official-PDF section of this page.

## Compare

- [SR 11-7 vs SR 26-2](https://www.bankingnewsai.com/ai-regulation/compare/sr-11-7-vs-sr-26-2): SR 11-7 vs SR 26-2: What Changed in Bank Model Risk Guidance

## Related documents

- [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) — Revised Guidance on Model Risk Management (Apr 17, 2026)
- [Cook: Opportunities and Risks of AI (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fed-cook-speech-ai-economy-financial-system-2026) — The Opportunities and Risks AI Presents for the Economy and Financial System — Governor Lisa D. Cook (May 27, 2026)
- [Bowman: AI in the Financial System (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fed-bowman-speech-ai-financial-system-2026) — Artificial Intelligence in the Financial System — Vice Chair for Supervision Michelle W. Bowman (May 1, 2026)
- [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) — Interagency Guidance on Third-Party Relationships: Risk Management (Jun 7, 2023)
- [2021 BSA/AML Model Risk Statement](https://www.bankingnewsai.com/ai-regulation/documents/fed-bsa-aml-model-risk-statement-2021) — Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance (Apr 9, 2021)
- [2021 Interagency AI RFI](https://www.bankingnewsai.com/ai-regulation/documents/fed-interagency-ai-rfi-2021) — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning (Mar 31, 2021)
- [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Jul 24, 2026)
- [RBI draft Guidance on Regulatory Principles for Model Risk Management](https://www.bankingnewsai.com/ai-regulation/documents/rbi-model-risk-management-guidance-2026) — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) (Jun 24, 2026)

Last reviewed Sep 19, 2026. Cite the official text (https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-11-7
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
