What is model risk management?
Model risk management (MRM) is how a bank controls the risk that a model is wrong or misused: disciplined model development and use, independent validation and ongoing monitoring, and governance through policies, a model inventory, defined roles and internal audit. The US framework was SR 11-7 and OCC Bulletin 2011-12 until April 17, 2026; it is now SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026, which keep machine-learning models in scope and leave generative and agentic AI outside.
This page maps each part of the framework to the document that sets it out: SR 11-7 and OCC Bulletin 2011-12 for the 2011 text, SR 26-2 and OCC Bulletin 2026-13 for the guidance now in force, and the UK, euro-area and Basel documents that sit beside them. For the wider governance picture see AI governance in banking.
What is the model risk management framework for US banks?
Since April 17, 2026 it is one interagency text issued under three numbers: the Federal Reserve's SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026. It replaced the 2011 guidance (SR 11-7 / OCC Bulletin 2011-12) and keeps its architecture: sound model development and use, independent validation and ongoing monitoring, and governance and controls, with a separate section on vendor and other third-party products. What changed is the footing. The guidance is risk-based and scaled to model materiality, is expected to be most relevant above $30 billion in total assets, defines a model as a 'complex' quantitative method, and says non-compliance will not by itself draw supervisory criticism.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2 (Federal Reserve) | Federal Reserve | Revised Guidance on Model Risk Management for Fed-supervised organisations; supersedes SR 11-7 and SR 21-8. | In force from Apr 17, 2026 |
| OCC Bulletin 2026-13 | OCC | The same guidance for national banks and federal savings associations; rescinds Bulletins 2011-12, 1997-24 and 2021-19 and the Comptroller's Handbook 'Model Risk Management' booklet. | In force from Apr 17, 2026 |
| FDIC FIL-15-2026 | FDIC | The same guidance for FDIC-supervised institutions; rescinds FIL-22-2017 and FIL-27-2021. | In force from Apr 17, 2026 |
| SR 11-7 (2011 guidance) | Federal Reserve | The original three elements: development, implementation and use; validation; governance, policies and controls. Introduced 'effective challenge' and the firm-wide model inventory. | Superseded Apr 17, 2026 |
| OCC Bulletin 2011-12 | OCC | The OCC's issuance of the same 2011 guidance, 'Sound Practices for Model Risk Management'. | Rescinded Apr 17, 2026 |
| OCC Bulletin 1997-24 (credit scoring models) | OCC | The OCC's first examination guidance on models: validation, monitoring and fair-lending risk in credit scoring. | Rescinded Apr 17, 2026 |
| 2021 BSA/AML model risk statement (SR 21-8 / OCC 2021-19 / FIL-27-2021) | Federal Reserve | How model risk principles apply to transaction monitoring, sanctions screening and customer risk rating, including machine-learning systems. | Superseded Apr 17, 2026 |
| SR 23-4 / OCC 2023-17 / FIL-29-2023 (third-party risk) | Federal Reserve | The lifecycle guidance for the vendor relationship behind a bought model: due diligence, contracting, ongoing monitoring, termination. | In force from Jun 7, 2023 |
What goes in a model inventory, and how are models tiered?
A model inventory is the firm-wide record of every model in use or under development, with enough information to understand each model's risk and the bank's model risk in aggregate. The 2011 guidance listed what it should hold: purpose and products, actual and expected use, restrictions, inputs and outputs, responsible individuals, and the dates of completed and planned validation. Tiering decides how much scrutiny each entry gets. SR 26-2 builds it on materiality, which it defines as model exposure together with model purpose: models a bank deems immaterial may only need identifying and monitoring, while higher-materiality models 'warrant more comprehensive and rigorous oversight'. The UK's SS1/23 makes model identification and risk classification its first principle.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2: materiality and the inventory | Federal Reserve | Materiality is model exposure plus purpose; risk is assessed per model and in aggregate; the inventory holds sufficient information to understand model risks at both levels. | In force from Apr 17, 2026 |
| SR 11-7: what an inventory records | Federal Reserve | Models in use, under development or recently retired: purpose, products, usage and restrictions, inputs and outputs, whether the model is functioning properly, owners and validators, validation dates. | Superseded Apr 17, 2026 |
| PRA SS1/23, Principle 1 | UK (BoE / PRA / FCA) | The first of the five principles is 'Model identification and model risk classification': identify what counts as a model, then classify each by risk. | In force from May 17, 2024 |
| PRA AI/ML model-risk roundtable | UK (BoE / PRA / FCA) | The PRA's thinking on risk appetite and model tiering for AI and machine-learning models under SS1/23. | Published Nov 24, 2025 |
What does model validation involve?
Validation is the set of activities that verify a model performs as expected for its design objectives and business use. Under both the 2011 and 2026 US guidance it has three components: conceptual soundness (design, assumptions, data and developmental testing), outcomes analysis (comparing outputs with real-world outcomes, including back-testing) and ongoing monitoring (whether the model still performs as products, data and markets change). SR 26-2 says validation generally occurs before first use, that its timing and depth vary with purpose, methodology and materiality, and that its quality 'depends on the rigor and effectiveness of the review rather than on organizational structure'. Effective challenge needs expertise, independence and the standing to effect change.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2: validation and monitoring | Federal Reserve | Conceptual soundness, outcomes analysis and ongoing monitoring, scaled to materiality; interpretability measures or benchmarking may substitute for theoretical review where more practical. | In force from Apr 17, 2026 |
| SR 11-7: the three core elements | Federal Reserve | Evaluation of conceptual soundness, ongoing monitoring with process verification and benchmarking, outcomes analysis with back-testing; periodic review of each model at least annually. | Superseded Apr 17, 2026 |
| PRA SS1/23, Principle 4 | UK (BoE / PRA / FCA) | The fourth of the five principles is 'Independent model validation'; it sits alongside governance, development and use, and model risk mitigants. | In force from May 17, 2024 |
| ECB Guide to internal models, ML section | ECB | Machine-learning capital models must be adequately explainable and their complexity justified by performance. | In force from Jul 28, 2025 |
| EBA follow-up report on ML for IRB models | EBA | Principle-based recommendations on understanding, documenting, validating and monitoring machine-learning capital models. | Published Aug 4, 2023 |
What are the three lines of defense in model risk management?
The three lines of defense assign model risk to three groups: the business units that own, develop and use models (first line), an independent model risk management and validation function that controls that risk and provides effective challenge (second line), and internal audit, which tests whether the whole framework works (third line). US model risk guidance does not use the phrase. SR 11-7 divides the roles among 'ownership, controls, and compliance' and gives internal audit its own section; the OCC's heightened standards for large banks name front line units, independent risk management and internal audit; and the Basel Committee's corporate governance principles describe business units, risk management and internal audit as 'the three lines of defence'.
| Line | Who | Role in model risk management | Where it comes from |
|---|---|---|---|
| First line | Business units, model owners, developers and users | Accountable for model use and performance; ensure models are properly developed, implemented and used, have been validated and approved, and that new or changed models are identified. | SR 11-7, Section VI: 'Business units are generally responsible for the model risk associated with their business strategies.' |
| Second line | Independent model risk management and validation (risk-control staff) | Manages independent validation and review so that effective challenge takes place; sets limits and monitors them; can restrict the use of a model; reports issues to senior management with a corrective-action plan. | SR 11-7, Section VI: 'Control staff should have the authority to restrict the use of models.' OCC heightened standards: independent risk management. |
| Third line | Internal audit | Assesses the overall effectiveness of the framework; verifies policies are followed and the inventory is accurate and complete; does not duplicate validation. | SR 11-7, Section VI ('Internal Audit'); SR 26-2, 'Roles and Responsibilities'; OCC heightened standards: internal audit. |
| Above the lines | Board of directors and senior management | Set the framework, approve model risk policies and review them annually, and receive reporting on aggregate model risk and on validation and audit findings. | SR 11-7, Section VI ('Board of Directors and Senior Management'). |
SOURCES: SR 11-7 attachment: Supervisory Guidance on Model Risk Management (PDF) ↗ · SR 26-2 attachment: revised guidance (PDF) ↗ · OCC heightened standards, 12 CFR Part 30, Appendix D ↗ · BCBS, Corporate governance principles for banks (2015) ↗
How does model risk management apply to AI, machine learning and generative AI?
In the US the line runs between predictive and generative systems. SR 26-2 states that its principles apply to 'traditional statistical and quantitative models and non-generative, non-agentic AI models', so a machine-learning credit, fraud or AML model is validated like any other model, in proportion to its materiality. Generative AI and agentic AI models are 'novel and rapidly evolving' and 'not within the scope of this guidance'; a bank's broader risk management and governance practices decide their controls, and the agencies plan a request for information on model risk management and banks' use of AI. The UK runs the other way: the PRA's SS1/23 keeps AI and machine learning inside model risk management.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2, footnote 3 | Federal Reserve | Non-generative, non-agentic AI models are in scope; generative and agentic AI are outside it and governed through the bank's broader risk management and governance practices. | In force from Apr 17, 2026 |
| PRA SS1/23 | UK (BoE / PRA / FCA) | A sub-principle on identifying and managing the risks of AI and machine-learning techniques within model risk management. | In force from May 17, 2024 |
| PRA AI/ML model-risk roundtable | UK (BoE / PRA / FCA) | Explainability and interpretability, data and overfitting, independent validation and ongoing monitoring of AI models. | Published Nov 24, 2025 |
| BCBS AI/ML newsletter | Basel Committee | Model complexity and interpretability, data quality and bias, and governance and accountability named as the supervisory concerns with AI/ML models. | Published Mar 16, 2022 |
| 2021 Interagency AI RFI | Federal Reserve | The agencies' questions on explainability, overfitting, dynamic updating and third-party AI under existing model risk guidance. | Comments closed Jul 1, 2021 |
| NIST AI RMF 1.0 | NIST | Voluntary Govern, Map, Measure, Manage framework widely used for the systems model risk guidance leaves out. | Voluntary |
| NIST AI 600-1 (Generative AI Profile) | NIST | Twelve generative-AI risks with suggested actions mapped to the AI RMF. | Voluntary |
What do examiners ask to see in a model risk management review?
The evidence trail the guidance describes: a model inventory with owners and materiality tiers; board-approved policies that define what a model is and who does what; development documentation that an outsider could follow; validation reports covering conceptual soundness, outcomes analysis and ongoing monitoring; the record of issues, exceptions and limits on model use; due diligence and performance evidence for vendor models; and internal audit's assessment of the framework. The 2026 guidance says it sets no enforceable standards and that non-compliance will not by itself draw supervisory criticism, so the conversation is about whether practices are sound for the bank's risk, not about a checklist.
| What is requested | What it shows | Basis in the guidance |
|---|---|---|
| Model inventory with owners, purpose, status and materiality tier | That the bank knows what it runs and where its model risk concentrates, per model and in aggregate | SR 26-2 'Model Inventory'; SR 11-7 Section VI |
| Model risk policy and procedures, with the definition of a model | Scope decisions: what is in the inventory, what left it under the 2026 definition, and how generative AI is governed outside it | SR 26-2 'Governance and Controls' and footnote 3 |
| Development documentation and testing evidence | Purpose, design, data and assumptions are stated and the developmental evidence supports them | SR 26-2 'Model Development'; SR 11-7 Section IV |
| Validation reports and ongoing-monitoring results | Independent, expert challenge took place and performance is tracked against thresholds | SR 26-2 'Model Validation and Monitoring'; SR 11-7 Section V |
| Issue, exception and model-use-limit log | Findings lead to change: recommendations, responses and exceptions are tracked to closure | SR 26-2 'Documentation'; SR 11-7 Section VI (authority to restrict model use) |
| Vendor model files | The bank understands the vendor model's design, data and performance and validates its own use of it | SR 26-2 'Vendor and Other Third-Party Products'; SR 23-4 |
| Internal audit reports on model risk management | The third line has tested whether practices are rigorous and policies are followed | SR 26-2 'Roles and Responsibilities'; SR 11-7 Section VI |
SOURCES: SR 26-2 attachment: revised guidance (PDF) ↗ · SR 11-7 attachment (PDF) ↗ · OCC Bulletin 2026-13 ↗
Which model risk documents has each authority published?
| Date | Event | Document |
|---|---|---|
| Apr 17, 2026 | SR 26-2 / OCC 2026-13 / FIL-15-2026 replace the 2011 guidance; generative and agentic AI out of scope | SR 26-2 |
| Nov 24, 2025 | PRA publishes its AI/ML model-risk roundtable slides | PRA AI/ML model-risk roundtable (Nov 2025) |
| Jul 28, 2025 | ECB Guide to internal models adds a machine-learning section | ECB Guide to internal models (July 2025, ML section) |
| Jun 7, 2023 | Interagency third-party risk guidance covers vendor models | SR 23-4 |
| May 17, 2023 | PRA SS1/23 published: five model risk principles, AI inside the perimeter | PRA SS1/23 |
| Mar 16, 2022 | Basel Committee newsletter on AI and machine learning | BCBS AI/ML Newsletter (March 2022) |
| Apr 9, 2021 | Interagency statement applies model risk principles to BSA/AML systems | 2021 BSA/AML Model Risk Statement |
| Mar 31, 2021 | Interagency request for information on banks' use of AI, including model risk questions | 2021 Interagency AI RFI |
| Apr 4, 2011 | SR 11-7 / OCC Bulletin 2011-12: Supervisory Guidance on Model Risk Management | SR 11-7 |
| May 20, 1997 | OCC Bulletin 1997-24: first examination guidance on credit scoring models | OCC Bulletin 1997-24 |
Which of the 100 largest US banks have disclosed model risk work on AI?
6 of the 100 bank pages on this site record a model-risk activity tied to AI. Each links to the bank's page, where the claim is sourced.
| Bank | What the record shows | Status |
|---|---|---|
| M&T | AI Risk Oversight (second line): Independent oversight program for responsible AI adoption. | In production |
| SouthState | Per-use-case model testing: Expert Q&A sets for accuracy, privacy, security, toxicity and jailbreaks; retested as models change. | In production |
| FNB | Decisioning, forecasting and regulatory models: Data-science team under Tangirala maintains strategic decisioning systems and regulatory models. | In production |
| Atlantic Union | AI and machine-learning models in use: Disclosed in the 10-K with training-data, bias and interpretability risks. | In production |
| Axos Bank | AI risk-factor disclosure: 10-K covers agentic and generative AI, third-party model dependence, bias, explainability and evolving regulation. | In production |
| Sallie Mae | AI as a credit-risk variable: Management analysis of AI's effect on graduate employment and cosigner strength. | In production |
What is model risk?
Model risk is the potential for adverse consequences from decisions based on a model that is wrong or is used in the wrong way. The 2011 US guidance named two sources: a model may have fundamental errors and produce inaccurate outputs, or it may be used incorrectly or outside its limitations. The 2026 guidance adds that the magnitude of model risk reflects a model's inherent risk together with its materiality, meaning its exposure and purpose, and that risk should be assessed for each model and in aggregate.
Is SR 11-7 still the model risk management standard?
No. SR 11-7 and OCC Bulletin 2011-12 were replaced on April 17, 2026 by SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026. The structure they established carries over; the definition of a model, the scaling to materiality and the treatment of generative AI changed.
What is a model risk management policy?
The board-approved document that defines what counts as a model, sets the tiering method, assigns roles across model owners, validators and internal audit, fixes validation and monitoring expectations by tier, and governs vendor models, exceptions and reporting. The 2011 guidance expected the board or its delegates to approve model risk policies and review them annually.
Does model risk management cover generative AI?
Not in the US guidance. SR 26-2 says generative AI and agentic AI models are not within its scope and leaves their controls to the bank's broader risk management and governance practices, while non-generative machine-learning models stay in scope. In the UK, SS1/23 keeps AI and machine learning inside model risk management.
Which banks does the US model risk guidance apply to?
All banking organisations supervised by the Federal Reserve, OCC and FDIC, but the agencies expect it to be most relevant to those with more than $30 billion in total assets, and to smaller banks only where model use is prevalent and complex or activities go beyond traditional community banking.
Which of the largest US banks have disclosed model risk work on AI?
Only a handful say so publicly. The bank pages on this site record a second-line AI risk oversight programme at M&T, per-use-case model testing at SouthState and 10-K disclosure of AI model risks at Atlantic Union, among others; the table above lists each with its source.
When model risk guidance moves, you'll read it the next morning.
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning