AI regulation tracker · Topic hub

Model risk management in banking: the framework, the rules, and where AI fits.

Last updated Sep 19, 2026 · 71 model-risk documents across 18 authorities

What is model risk management?

Model risk management (MRM) is how a bank controls the risk that a model is wrong or misused: disciplined model development and use, independent validation and ongoing monitoring, and governance through policies, a model inventory, defined roles and internal audit. The US framework was SR 11-7 and OCC Bulletin 2011-12 until April 17, 2026; it is now SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026, which keep machine-learning models in scope and leave generative and agentic AI outside.

This page maps each part of the framework to the document that sets it out: SR 11-7 and OCC Bulletin 2011-12 for the 2011 text, SR 26-2 and OCC Bulletin 2026-13 for the guidance now in force, and the UK, euro-area and Basel documents that sit beside them. For the wider governance picture see AI governance in banking.

What is the model risk management framework for US banks?

Since April 17, 2026 it is one interagency text issued under three numbers: the Federal Reserve's SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026. It replaced the 2011 guidance (SR 11-7 / OCC Bulletin 2011-12) and keeps its architecture: sound model development and use, independent validation and ongoing monitoring, and governance and controls, with a separate section on vendor and other third-party products. What changed is the footing. The guidance is risk-based and scaled to model materiality, is expected to be most relevant above $30 billion in total assets, defines a model as a 'complex' quantitative method, and says non-compliance will not by itself draw supervisory criticism.

RuleAuthorityWhat it requiresApplies
SR 26-2 (Federal Reserve)Federal ReserveRevised Guidance on Model Risk Management for Fed-supervised organisations; supersedes SR 11-7 and SR 21-8.In force from Apr 17, 2026
OCC Bulletin 2026-13OCCThe same guidance for national banks and federal savings associations; rescinds Bulletins 2011-12, 1997-24 and 2021-19 and the Comptroller's Handbook 'Model Risk Management' booklet.In force from Apr 17, 2026
FDIC FIL-15-2026FDICThe same guidance for FDIC-supervised institutions; rescinds FIL-22-2017 and FIL-27-2021.In force from Apr 17, 2026
SR 11-7 (2011 guidance)Federal ReserveThe original three elements: development, implementation and use; validation; governance, policies and controls. Introduced 'effective challenge' and the firm-wide model inventory.Superseded Apr 17, 2026
OCC Bulletin 2011-12OCCThe OCC's issuance of the same 2011 guidance, 'Sound Practices for Model Risk Management'.Rescinded Apr 17, 2026
OCC Bulletin 1997-24 (credit scoring models)OCCThe OCC's first examination guidance on models: validation, monitoring and fair-lending risk in credit scoring.Rescinded Apr 17, 2026
2021 BSA/AML model risk statement (SR 21-8 / OCC 2021-19 / FIL-27-2021)Federal ReserveHow model risk principles apply to transaction monitoring, sanctions screening and customer risk rating, including machine-learning systems.Superseded Apr 17, 2026
SR 23-4 / OCC 2023-17 / FIL-29-2023 (third-party risk)Federal ReserveThe lifecycle guidance for the vendor relationship behind a bought model: due diligence, contracting, ongoing monitoring, termination.In force from Jun 7, 2023

What goes in a model inventory, and how are models tiered?

A model inventory is the firm-wide record of every model in use or under development, with enough information to understand each model's risk and the bank's model risk in aggregate. The 2011 guidance listed what it should hold: purpose and products, actual and expected use, restrictions, inputs and outputs, responsible individuals, and the dates of completed and planned validation. Tiering decides how much scrutiny each entry gets. SR 26-2 builds it on materiality, which it defines as model exposure together with model purpose: models a bank deems immaterial may only need identifying and monitoring, while higher-materiality models 'warrant more comprehensive and rigorous oversight'. The UK's SS1/23 makes model identification and risk classification its first principle.

RuleAuthorityWhat it requiresApplies
SR 26-2: materiality and the inventoryFederal ReserveMateriality is model exposure plus purpose; risk is assessed per model and in aggregate; the inventory holds sufficient information to understand model risks at both levels.In force from Apr 17, 2026
SR 11-7: what an inventory recordsFederal ReserveModels in use, under development or recently retired: purpose, products, usage and restrictions, inputs and outputs, whether the model is functioning properly, owners and validators, validation dates.Superseded Apr 17, 2026
PRA SS1/23, Principle 1UK (BoE / PRA / FCA)The first of the five principles is 'Model identification and model risk classification': identify what counts as a model, then classify each by risk.In force from May 17, 2024
PRA AI/ML model-risk roundtableUK (BoE / PRA / FCA)The PRA's thinking on risk appetite and model tiering for AI and machine-learning models under SS1/23.Published Nov 24, 2025

What does model validation involve?

Validation is the set of activities that verify a model performs as expected for its design objectives and business use. Under both the 2011 and 2026 US guidance it has three components: conceptual soundness (design, assumptions, data and developmental testing), outcomes analysis (comparing outputs with real-world outcomes, including back-testing) and ongoing monitoring (whether the model still performs as products, data and markets change). SR 26-2 says validation generally occurs before first use, that its timing and depth vary with purpose, methodology and materiality, and that its quality 'depends on the rigor and effectiveness of the review rather than on organizational structure'. Effective challenge needs expertise, independence and the standing to effect change.

RuleAuthorityWhat it requiresApplies
SR 26-2: validation and monitoringFederal ReserveConceptual soundness, outcomes analysis and ongoing monitoring, scaled to materiality; interpretability measures or benchmarking may substitute for theoretical review where more practical.In force from Apr 17, 2026
SR 11-7: the three core elementsFederal ReserveEvaluation of conceptual soundness, ongoing monitoring with process verification and benchmarking, outcomes analysis with back-testing; periodic review of each model at least annually.Superseded Apr 17, 2026
PRA SS1/23, Principle 4UK (BoE / PRA / FCA)The fourth of the five principles is 'Independent model validation'; it sits alongside governance, development and use, and model risk mitigants.In force from May 17, 2024
ECB Guide to internal models, ML sectionECBMachine-learning capital models must be adequately explainable and their complexity justified by performance.In force from Jul 28, 2025
EBA follow-up report on ML for IRB modelsEBAPrinciple-based recommendations on understanding, documenting, validating and monitoring machine-learning capital models.Published Aug 4, 2023

What are the three lines of defense in model risk management?

The three lines of defense assign model risk to three groups: the business units that own, develop and use models (first line), an independent model risk management and validation function that controls that risk and provides effective challenge (second line), and internal audit, which tests whether the whole framework works (third line). US model risk guidance does not use the phrase. SR 11-7 divides the roles among 'ownership, controls, and compliance' and gives internal audit its own section; the OCC's heightened standards for large banks name front line units, independent risk management and internal audit; and the Basel Committee's corporate governance principles describe business units, risk management and internal audit as 'the three lines of defence'.

LineWhoRole in model risk managementWhere it comes from
First lineBusiness units, model owners, developers and usersAccountable for model use and performance; ensure models are properly developed, implemented and used, have been validated and approved, and that new or changed models are identified.SR 11-7, Section VI: 'Business units are generally responsible for the model risk associated with their business strategies.'
Second lineIndependent model risk management and validation (risk-control staff)Manages independent validation and review so that effective challenge takes place; sets limits and monitors them; can restrict the use of a model; reports issues to senior management with a corrective-action plan.SR 11-7, Section VI: 'Control staff should have the authority to restrict the use of models.' OCC heightened standards: independent risk management.
Third lineInternal auditAssesses the overall effectiveness of the framework; verifies policies are followed and the inventory is accurate and complete; does not duplicate validation.SR 11-7, Section VI ('Internal Audit'); SR 26-2, 'Roles and Responsibilities'; OCC heightened standards: internal audit.
Above the linesBoard of directors and senior managementSet the framework, approve model risk policies and review them annually, and receive reporting on aggregate model risk and on validation and audit findings.SR 11-7, Section VI ('Board of Directors and Senior Management').

SOURCES: SR 11-7 attachment: Supervisory Guidance on Model Risk Management (PDF) · SR 26-2 attachment: revised guidance (PDF) · OCC heightened standards, 12 CFR Part 30, Appendix D · BCBS, Corporate governance principles for banks (2015)

How does model risk management apply to AI, machine learning and generative AI?

In the US the line runs between predictive and generative systems. SR 26-2 states that its principles apply to 'traditional statistical and quantitative models and non-generative, non-agentic AI models', so a machine-learning credit, fraud or AML model is validated like any other model, in proportion to its materiality. Generative AI and agentic AI models are 'novel and rapidly evolving' and 'not within the scope of this guidance'; a bank's broader risk management and governance practices decide their controls, and the agencies plan a request for information on model risk management and banks' use of AI. The UK runs the other way: the PRA's SS1/23 keeps AI and machine learning inside model risk management.

RuleAuthorityWhat it requiresApplies
SR 26-2, footnote 3Federal ReserveNon-generative, non-agentic AI models are in scope; generative and agentic AI are outside it and governed through the bank's broader risk management and governance practices.In force from Apr 17, 2026
PRA SS1/23UK (BoE / PRA / FCA)A sub-principle on identifying and managing the risks of AI and machine-learning techniques within model risk management.In force from May 17, 2024
PRA AI/ML model-risk roundtableUK (BoE / PRA / FCA)Explainability and interpretability, data and overfitting, independent validation and ongoing monitoring of AI models.Published Nov 24, 2025
BCBS AI/ML newsletterBasel CommitteeModel complexity and interpretability, data quality and bias, and governance and accountability named as the supervisory concerns with AI/ML models.Published Mar 16, 2022
2021 Interagency AI RFIFederal ReserveThe agencies' questions on explainability, overfitting, dynamic updating and third-party AI under existing model risk guidance.Comments closed Jul 1, 2021
NIST AI RMF 1.0NISTVoluntary Govern, Map, Measure, Manage framework widely used for the systems model risk guidance leaves out.Voluntary
NIST AI 600-1 (Generative AI Profile)NISTTwelve generative-AI risks with suggested actions mapped to the AI RMF.Voluntary

What do examiners ask to see in a model risk management review?

The evidence trail the guidance describes: a model inventory with owners and materiality tiers; board-approved policies that define what a model is and who does what; development documentation that an outsider could follow; validation reports covering conceptual soundness, outcomes analysis and ongoing monitoring; the record of issues, exceptions and limits on model use; due diligence and performance evidence for vendor models; and internal audit's assessment of the framework. The 2026 guidance says it sets no enforceable standards and that non-compliance will not by itself draw supervisory criticism, so the conversation is about whether practices are sound for the bank's risk, not about a checklist.

What is requestedWhat it showsBasis in the guidance
Model inventory with owners, purpose, status and materiality tierThat the bank knows what it runs and where its model risk concentrates, per model and in aggregateSR 26-2 'Model Inventory'; SR 11-7 Section VI
Model risk policy and procedures, with the definition of a modelScope decisions: what is in the inventory, what left it under the 2026 definition, and how generative AI is governed outside itSR 26-2 'Governance and Controls' and footnote 3
Development documentation and testing evidencePurpose, design, data and assumptions are stated and the developmental evidence supports themSR 26-2 'Model Development'; SR 11-7 Section IV
Validation reports and ongoing-monitoring resultsIndependent, expert challenge took place and performance is tracked against thresholdsSR 26-2 'Model Validation and Monitoring'; SR 11-7 Section V
Issue, exception and model-use-limit logFindings lead to change: recommendations, responses and exceptions are tracked to closureSR 26-2 'Documentation'; SR 11-7 Section VI (authority to restrict model use)
Vendor model filesThe bank understands the vendor model's design, data and performance and validates its own use of itSR 26-2 'Vendor and Other Third-Party Products'; SR 23-4
Internal audit reports on model risk managementThe third line has tested whether practices are rigorous and policies are followedSR 26-2 'Roles and Responsibilities'; SR 11-7 Section VI

SOURCES: SR 26-2 attachment: revised guidance (PDF) · SR 11-7 attachment (PDF) · OCC Bulletin 2026-13

Which model risk documents has each authority published?

AuthorityModel-risk documents in the tracker
Federal ReserveBowman: AI in the Financial System (May 2026) Final · SR 26-2 In force · SR 23-4 In force · 2021 BSA/AML Model Risk Statement Superseded · 2021 Interagency AI RFI Final · SR 11-7 Superseded
OCCOCC Bulletin 2026-13 In force · Acting Comptroller Hood, 'AI in Financial Services' (Apr 2025) Final · OCC Bulletin 2023-17 In force · OCC Bulletin 2021-19 Superseded · OCC Bulletin 2011-12 Superseded · OCC Bulletin 1997-24 Superseded
FDICHill House oversight testimony (Jun 2026) Final · FDIC FIL-15-2026 In force · FDIC FIL-27-2021 Superseded · FDIC FIL-20-2021 Final
NCUANCUA Board AI briefing (Jul 2025) Final · 2021 Interagency AI RFI Final
CFPBRegulation B final rule on disparate impact (April 2026) In force · CFPB Circular 2022-03 Withdrawn · ECOA / Regulation B adverse action (15 U.S.C. 1691(d); 12 CFR 1002.9) In force
SECDelphia / Global Predictions AI-washing settlements Final · Gensler 'AI washing' remarks at Yale (Feb 2024) Final · SEC Predictive Data Analytics proposal (34-97990) Withdrawn
CFTCJohnson RegHub Summit Remarks (Jun 2025) Final · CFTC Staff Advisory 24-17 on AI In force · CFTC TAC Responsible AI Report Final · CFTC AI Request for Comment (2024) Final
FinCEN2026 AML/CFT Program Proposed Rule Proposed · 2021 BSA/AML Model Risk Management Statement Withdrawn · Anti-Money Laundering Act of 2020 In force · 2018 Joint Statement on BSA/AML Innovation In force
U.S. TreasuryTreasury FS AI RMF and AI Lexicon (Feb 2026) Final · FSOC 2024 Annual Report Superseded · FSOC 2023 Annual Report Superseded
NY DFSInsurance Circular Letter No. 7 (2024) In force
Colorado AI ActSB 24-205 Superseded
NISTNIST AI 100-2e2025 (Adversarial ML) Final · NIST AI RMF 1.0 In force · NIST AI RMF Playbook In force
EU AI ActRegulation (EU) 2026/1744 (Digital Omnibus on AI) In force · Draft Commission guidelines on high-risk classification Proposed · EBA factsheet on the AI Act Final · General-Purpose AI Code of Practice In force · Regulation (EU) 2024/1689 In force
ECBMachado speech: 'Technology is neutral, governance is not' (Feb 2026) Final · Supervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025) Final · ECB Guide to internal models (July 2025, ML section) In force · ECB digitalisation sound practices report (July 2024) In force
EBAEBA factsheet: AI Act implications for the EU banking and payments sector Final · EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384) Final · EBA follow-up report on machine learning for IRB models (EBA/REP/2023/28) Final · EBA discussion paper on machine learning for IRB models Superseded · EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06) In force · EBA Report on Big Data and Advanced Analytics (EBA/REP/2020/01) Final
UK (BoE / PRA / FCA)2026 BoE/FCA AI survey Final · BoE response to Treasury Committee AI inquiry (Apr 2026) Final · BoE/PRA plan for safe AI innovation (Apr 2026) Final · PRA AI/ML model-risk roundtable (Nov 2025) Final · FS2/23 Final · PRA SS1/23 In force · DP5/22 Final · 2022 BoE/FCA ML survey Superseded
FSBFSB AI sound practices consultation (June 2026) Proposed · FSB AI monitoring report (Oct 2025) Final · FSB AI financial stability report (Nov 2024) Final · FSB 2017 AI/ML report Final
Basel CommitteeBCBS 239 Implementation Newsletter (Jan 2026) Final · BCBS Digitalisation of finance report (May 2024) Final · BCBS AI/ML Newsletter (March 2022) Final · BCBS 239 In force
DateEventDocument
Apr 17, 2026SR 26-2 / OCC 2026-13 / FIL-15-2026 replace the 2011 guidance; generative and agentic AI out of scopeSR 26-2
Nov 24, 2025PRA publishes its AI/ML model-risk roundtable slidesPRA AI/ML model-risk roundtable (Nov 2025)
Jul 28, 2025ECB Guide to internal models adds a machine-learning sectionECB Guide to internal models (July 2025, ML section)
Jun 7, 2023Interagency third-party risk guidance covers vendor modelsSR 23-4
May 17, 2023PRA SS1/23 published: five model risk principles, AI inside the perimeterPRA SS1/23
Mar 16, 2022Basel Committee newsletter on AI and machine learningBCBS AI/ML Newsletter (March 2022)
Apr 9, 2021Interagency statement applies model risk principles to BSA/AML systems2021 BSA/AML Model Risk Statement
Mar 31, 2021Interagency request for information on banks' use of AI, including model risk questions2021 Interagency AI RFI
Apr 4, 2011SR 11-7 / OCC Bulletin 2011-12: Supervisory Guidance on Model Risk ManagementSR 11-7
May 20, 1997OCC Bulletin 1997-24: first examination guidance on credit scoring modelsOCC Bulletin 1997-24

Which of the 100 largest US banks have disclosed model risk work on AI?

6 of the 100 bank pages on this site record a model-risk activity tied to AI. Each links to the bank's page, where the claim is sourced.

BankWhat the record showsStatus
M&TAI Risk Oversight (second line): Independent oversight program for responsible AI adoption.In production
SouthStatePer-use-case model testing: Expert Q&A sets for accuracy, privacy, security, toxicity and jailbreaks; retested as models change.In production
FNBDecisioning, forecasting and regulatory models: Data-science team under Tangirala maintains strategic decisioning systems and regulatory models.In production
Atlantic UnionAI and machine-learning models in use: Disclosed in the 10-K with training-data, bias and interpretability risks.In production
Axos BankAI risk-factor disclosure: 10-K covers agentic and generative AI, third-party model dependence, bias, explainability and evolving regulation.In production
Sallie MaeAI as a credit-risk variable: Management analysis of AI's effect on graduate employment and cosigner strength.In production

What is model risk?

Model risk is the potential for adverse consequences from decisions based on a model that is wrong or is used in the wrong way. The 2011 US guidance named two sources: a model may have fundamental errors and produce inaccurate outputs, or it may be used incorrectly or outside its limitations. The 2026 guidance adds that the magnitude of model risk reflects a model's inherent risk together with its materiality, meaning its exposure and purpose, and that risk should be assessed for each model and in aggregate.

Is SR 11-7 still the model risk management standard?

No. SR 11-7 and OCC Bulletin 2011-12 were replaced on April 17, 2026 by SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026. The structure they established carries over; the definition of a model, the scaling to materiality and the treatment of generative AI changed.

What is a model risk management policy?

The board-approved document that defines what counts as a model, sets the tiering method, assigns roles across model owners, validators and internal audit, fixes validation and monitoring expectations by tier, and governs vendor models, exceptions and reporting. The 2011 guidance expected the board or its delegates to approve model risk policies and review them annually.

Does model risk management cover generative AI?

Not in the US guidance. SR 26-2 says generative AI and agentic AI models are not within its scope and leaves their controls to the bank's broader risk management and governance practices, while non-generative machine-learning models stay in scope. In the UK, SS1/23 keeps AI and machine learning inside model risk management.

Which banks does the US model risk guidance apply to?

All banking organisations supervised by the Federal Reserve, OCC and FDIC, but the agencies expect it to be most relevant to those with more than $30 billion in total assets, and to smaller banks only where model use is prevalent and complex or activities go beyond traditional community banking.

Which of the largest US banks have disclosed model risk work on AI?

Only a handful say so publicly. The bank pages on this site record a second-line AI risk oversight programme at M&T, per-use-case model testing at SouthState and 10-K disclosure of AI model risks at Atlantic Union, among others; the table above lists each with its source.

When model risk guidance moves, you'll read it the next morning.

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning